meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, May 10th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 May 2018

⏱️ 4 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Loyds Bank Phishing; Firefox Group Policy; OS Vendors Fix Intel Debug Flaw

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, May 10th, 2018 edition of the Santernet Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Indianapolis, Indiana.

0:13.1

Xavier today came across a little bit of better-than-usual email that is spreading trick-bot right now. The email claimed to come from Lloyd's Bank.

0:24.4

Now, what made it even more believable is that it actually linked to a domain called

0:28.8

Lloyd'sbank docks.com. The email claimed to link to a document. The user had to review.

0:36.3

The website popping up when you clicked on the link

0:39.2

made it actually look like it is a PDF document.

0:43.5

Interestingly, the links actually in this document didn't do anything,

0:47.7

but what triggered further action was scrolling down in the document.

0:52.8

That triggered a pop-up that would then advise the user

0:56.6

to install a plugin, which then led to Trickpot.

1:01.6

What makes it probably more likely for users to fall

1:04.5

for this kind of fishing attempt is that many legitimate companies

1:08.2

are not just using one domain name, but often have multiple

1:12.3

domain names that they're using in email links that are derived from their main domain.

1:17.9

So something like Lloyd's Bank docks may very well look plausible and a likely link to show

1:25.0

up in email.

1:26.8

One problem with third-party browsers like Firefox in Windows has been

1:31.2

that it has been difficult to remotely manage these browsers across an enterprise.

1:38.0

Well, Firefox is going to fix this in Firefox 60.

1:42.7

Firefox 60 is going to include a group policy engine that allows you to

1:48.2

manage several security relevant settings in Firefox via group policies. Of course, Firefox has been

1:55.9

struggling somewhat for market share in recent years. that's probably one reason why they're implementing

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.