meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, May 18th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 May 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. NIST Password Guidance; Exploiting PeopleSoft XXE;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, May 18th, 2017 edition of the Sancent Storm Center's Stormcast.

0:08.5

My name is Johannes Ulrich, and today I'm recording from San Diego, California.

0:13.6

Last week I mentioned how the OS10 video conversion application handbrake was compromised and then infected with a version of the

0:24.6

proton backdoor. Well, often these incidents are very abstract and impact isn't really all that

0:31.8

clear. In this case, however, there is a nice follow-up from Panic Incorporated, or well, maybe not

0:40.4

so nice for these people, because while they develop various iOS apps, the developer

0:47.6

at Panic downloaded one of the compromised versions of handbrake during the time that it was infected.

0:56.7

And before the infection was made public, someone had already downloaded his source code using compromised git credentials.

1:07.7

The attacker who stole the source code then demanded a ransom to not release it to the public.

1:14.6

Now, Panic isn't too concerned about such a release, but is somewhat concerned about possible backdoor versions of its software, given the history of this particular group.

1:30.5

Now, Panic has decided not to pay the ransom, probably a smart move on their part, because

1:36.1

little really confirmation here that the attacker will not do anything bad with the code

1:42.0

after the ransom is paid.

1:45.0

But they already have invalidated the old developer ID so it can no longer be used to, for

1:51.7

example, sign any malicious software.

1:56.8

And missed recently updated its password guidance.

2:00.3

You may have seen this in the news last week.

2:03.3

Something many felt was long overdue as past guidance, for example, did not address adequately

2:11.1

how really passwords are compromised these days.

2:14.1

And one of the big problems, of course course these days are passwords shared between sites.

2:20.0

Richard today wrote a post summarizing some of these changes. One of the most publicized

2:26.9

and probably most important issue that was addressed in this new guidance is that regular

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.