meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 3rd, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 3 March 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Recognizing Biased/Fake News; FortiMail Bug; IBM; Google Chrome; Conti Leak; Middlebox DDoS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 3, 2020 edition of the Santernut Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich.

0:09.8

And today I'm recording from Jacksonville, Florida.

0:14.0

I wrote a quick diary today about some of the fake news and tainted and biased news that you will see with the war in Ukraine.

0:24.9

Couple tips on how to recognize some of the issues here, but I think the main takeaway, I guess,

0:31.9

is particular as it comes to social media, not to overwhelm and flood yourself with various news tidbits

0:40.4

that don't really mean much in the end.

0:44.2

And secondly, not to be part of the problem and not to amplify questionable items.

0:51.3

And well, then you also have patches.

0:53.3

And the first one I want to point out, again, parameter security devices, 40 mail by 40 guard laps, has an update for you, fixing a critical vulnerability that allows for an administrative authentication bypass.

1:09.8

An exploit doesn't seem to be as straightforward as a simple default password.

1:15.2

Instead, it says that observing some system properties, you may be able to guess the

1:23.5

authentication token.

1:25.2

So this would be something along the lines of like looking at timestamps,

1:28.8

version numbers, maybe Mac address and such that are often used to derive some of this

1:34.9

authentication data. I suspect vulnerability along those lines. Freda Guard also released an update

1:41.8

for 40 WLC.

1:49.8

That's of the traffic optimizer, but the risk here is only high.

1:53.4

It does state that it fixes issue with the random number generator,

1:57.4

which of course may be related to the problem with 40 mail.

2:00.2

Other 40Guard products also received updates, so double-checked none of them,

2:02.4

overly critical. There is a path reversal vulnerability also in 40WLM. Some clear text passwords

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.