meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 18th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 18 June 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Odd Protest Spam; Zoom E2EE; Linux ACPI Bug; ISC Tech Tuesday Workshop

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 18th, 2020 edition of the Sansonet Storms and Stormcast.

0:07.6

My name is Johannes Ulrich.

0:09.1

And I am recording from Jacksonville, Florida.

0:13.0

Yesterday, I received an interesting email where when I looked at it first, I thought, hey, this has to be a scam.

0:20.3

It was sort of one of those very clumsy

0:22.6

done scams. It claimed that apparently I shot someone at a recent protest and that I should

0:30.4

go to a website to learn more about the charges. Now, what was sort of odd about this is that while all of this looked like your

0:39.6

standard scam or fishing attempt, it actually directed to a legitimate website. The website

0:46.4

in question here was the Atlanta Police Foundation, which is a not-for-profit working with the Atlanta Police.

0:55.5

And of course, if you watched the news at all the last week or so,

1:00.2

the Atlanta Police has a huge spotlight shining on them recently.

1:05.5

So the question I had, and said I don't really have a full answer for it,

1:18.1

is why would someone be doing this if there is sort of no obvious profit from this particular scam? And the best explanation that I could come up with is something that I have seen being referred to as a Joe shop, which is often used in spam. We're using a fake from address.

1:31.4

And the goal here is essentially to defame the fake sender of the message. So to claim that

1:38.9

whoever sent the message is sending spam and then to hope that spam filters and such will block any legitimate messages from that source.

1:49.2

Similar things could be happening here, but as far as I can tell, have not been successful.

1:55.1

For example, if people are reporting this email, that may actually lead to the Atlanta Police Foundation's website

2:03.1

being shut down or blocked by anti-malware filters.

2:08.5

So sometimes it's not really a technical exploit, but what I usually call a layer 8 problem,

2:14.8

which means it's really sort of a people social engineering style

2:20.1

exploit rather than some kind of matter.

2:25.6

And I think it was a couple of months ago that Zoom announced its intent to develop an

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.