meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, January 21st, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 21 January 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SolarWinds Updates; Cisco Advisories; WebRTC State Issues; Oracle BI XSS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, January 21st, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.3

Well, one item, of course, that's still sort of dominating a lot of the news is solar winds and solarigate or the sunburst and various other piece of matter

0:25.8

that have been found since then. Microsoft has a real good write-up by the Microsoft 365

0:35.0

Defender Research Team in association with their threat intelligence center

0:40.3

and their Cyber Defense Operations Center.

0:43.2

And they're sort of going step by step over how the attack worked and also what steps

0:49.5

the attacker took to evade detection.

0:51.8

Plus, of course, how you are able to detect these kinds of attacks,

0:57.0

which to summarize in short isn't really easy. And one thing I found really interesting

1:04.0

is a lot of people always talk about indicators of compromise, hashes and the like. And that's

1:10.0

something that specifically fails here because

1:12.9

the attacker took the time to custom develop payloads for individual victims. So if you're just

1:20.6

relying on hashes and the like, that's really not going to cut it in this case. Well, it's

1:26.7

really about good TTPs, techniques,

1:29.5

tactics, and procedures. How did the attacker operate? And that's sort of what this blog post

1:35.7

by Microsoft goes over. In addition, there are also new victims coming forward. With that,

1:41.9

we do have a little bit name confusion between like

1:45.5

teardrop, rain drop, and of course the Cobalt Strike Backdoor.

1:51.5

Various names being used for very similar really functionality.

1:56.2

But then again, because we have these custom payloads being deployed, everybody that's affected sort of finds

2:03.2

something that's a little bit different. Malware Bites, the anti-malware company, also came

2:09.6

forward that its Office 365 environment was attacked and breached by the same actor.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.