ISC StormCast for Thursday, June 8th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 June 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, June 8, 2020, |
| 0:04.0 | edition of the Sansonet Storm Center's Stormcast. |
| 0:08.2 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Quick diary today from Manuel about the DMARC records in Colombian domain. So that's dot CO, Manuel, of course, being from |
| 0:25.4 | Colombia. And he compares here also how the government domains that Gov.co and the university |
| 0:33.4 | domains, edu.c.O. Do and how they compare? Well, a common wisdom would sort of assume that |
| 0:40.7 | government domains are probably better about setting up demarc records than educational or |
| 0:47.8 | university domains. Turns out the opposite is true, while neither does terribly well. |
| 0:54.7 | The universities are actually here a little bit better than government websites, with 92.4% having no demarc protection for government websites and 91%. |
| 1:09.1 | So just a percent less for educational for university domains. |
| 1:15.2 | We do keep getting questions about DM, D.M.D. Kim, SPF and the like from readers, |
| 1:22.2 | which is why we do focus in some of these diaries on these numbers. It is something that you certainly should |
| 1:30.0 | investigate. It's not perfect. It has problems, but it does prevent a significant part of |
| 1:38.4 | the impersonation problem. And one of the biggest problems of Demarc, which I think is actually its biggest advantage |
| 1:46.1 | is that it forces you to find sort of all these rogue IT systems that people set up, those |
| 1:53.3 | third-party vendors that they contracted with to send emails on your behalf. |
| 2:00.9 | And VMware released an update for VMware Area Operations for Networks that fixes three |
| 2:07.5 | vulnerabilities, two of them critical, one of them. |
| 2:11.4 | High the critical vulnerabilities. |
| 2:13.8 | First one, CFSS score of 9.8, which is a command injection vulnerability. |
| 2:20.1 | We also have an authenticated deseralization vulnerability, CFSS score of 9.1. |
| 2:26.2 | And then the not quite critical one, CSS score 8.8 is an information disclosure vulnerability. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

