meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, July 6th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 6 July 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DShield pfSense Client; Exposed ICS; Custom Encoding; SNAPPY; RUSTBUCKET

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, July 6, 2020,

0:04.2

edition of the Sansonet Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida.

0:14.1

For the PFCense users out here, you probably noted that there is a new version of a PF 2.7 if you're using the Community Edition or 2301 if you're using PFSense Plus.

0:29.5

We have an update for the client, for the D-Shield client if you're using PFSense.

0:35.4

So please update it.

0:37.4

That way you'll continue to submit logs to our database.

0:42.9

And thanks to Yishin, who has taken over the update of the client, so he'll be able to make

0:51.0

any additional changes as they may be necessary.

0:55.7

And Manuel took a look at industrial control systems exposed to the Internet in particular.

1:01.4

Manuel focused on HMI's.

1:03.7

These are these human management interface.

1:05.8

Essentially computers being used to control, industrial control systems.

1:10.5

He found about 500 exposed systems.

1:14.2

I'm actually surprised the number so low.

1:15.8

I would have expected more of them,

1:17.7

but then realized that each one of those systems

1:20.2

probably has many, many different actual systems,

1:23.6

actual industrial systems connected to them.

1:33.4

VNC is one of the big culprits here that is being used to expose these systems, almost half of them, and that without authentication. A couple more details in

1:40.6

Manuel's diary. And then DDA again shows how to use his Python scripts in order to some malware analysis.

1:49.9

The latest problem that DDA is trying to tackle is how to deal with custom encoding.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.