meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, June 23rd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 23 June 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Coin Stealing Powershell; NSA PS Guidance; MageCart Update; Script Kiddies Hacked; Israeli Air Raid Sirens Hacked;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, June 23rd, 2020 edition of the Sands and its Storm Center's

0:06.7

Stormcast. My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida.

0:13.1

But remember, I'll be traveling tomorrow, so there will be no Friday edition of this podcast.

0:21.4

PowerShell, everybody's favorite tool and Xavier ran into an interesting piece of malware

0:27.2

written in PowerShell that is going after cryptocoins.

0:33.2

Cryptocoins, even though their value has declined quite a bit, well, if you can get them for free, they're still worth something, so attackers are still going after them.

0:44.2

This particular PowerShell script also has a very low virus total score. Only one out of the 53 engines' virus total uses, did detect the script as malicious.

0:57.1

The particular script is first of all enumerating crypto coin-related browser extensions and

1:05.2

then exfiltrating them to the attacker together with any crypto coin looking information that it finds in the clipboard.

1:14.8

So knowing what extensions are running, meaning what exchanges and such the user is probably

1:20.0

participating in and then knowing any crypto coin addresses and possibly usenames and passwords

1:25.5

being copy-pasted, the attacker may be able to get access

1:30.0

to the account of the victim here. Now, talking about PowerShell, of course, lots of Malar these

1:37.4

days is written in PowerShell, but PowerShell is also an important defensive tool and typically

1:43.4

cannot easily and probably shouldn't

1:45.6

just be disabled.

1:47.7

In order to help you better secure PowerShell, we now have a new cybersecurity information

1:54.9

sheet, as they call it, that was created by the NSA, the cybersecurity infrastructure

2:00.7

security agency or SISA, as well as the government

2:04.3

communication security bureau in New Zealand and the national cybersecurity center in the

2:10.7

UK. So three countries, four agencies came together and created a guide helping you to secure PowerShell.

2:19.9

The guide includes tips how to use PowerShell securely.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.