meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, February 8th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 8 February 2024

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Possible Balena Scans; Critical shim vulnerability; Volt Typhoon Living of the Land

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, February 8th,

0:03.0

2004 edition of the Sansonet Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.6

Well, I have a little bit of mystery today that I hope some listener will be able to help with,

0:19.5

and that's a URL that showed up in our first

0:24.0

seen URL list. That's the list where all URLs show up that have been seen for the first

0:29.5

time in our honeypots, at least in some quantity. This particular list, URL is slash V5 slash

0:37.3

device slash heartbeat.

0:39.5

And the only thing I sort of could find about this particular URL is that it's very likely associated with Balena.

0:48.6

I think that's how you pronounce it.

0:50.2

This is a platform to manage IoT devices.

0:59.0

And the API contains requests like that.

1:00.8

So it may be related to it.

1:07.9

There is no obvious big vulnerability in this particular system that sort of was disclosed lately.

1:11.8

But these requests look, and I think someone on Twitter also out like someone is trying to enumerate any systems running Balena.

1:18.9

There are a couple of vulnerabilities on LinkedIn.

1:22.0

For example, someone pointed to a PNG vulnerability that affected versions of Belina because they include an older Node.js.

1:31.5

This PNG vulnerability does not appear to be exploitable in this particular system.

1:37.7

So unlikely it's this vulnerability, but I think it sort of is pointing to the right direction.

1:43.1

Like many modern applications, this

1:46.1

application is including lots and lots of libraries and components, so it's very much

1:53.0

possible that some component that is vulnerable could be exploited in this particular API.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.