meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 11th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 11 November 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Shadow IT and Phishing; PaloAlto GlobalProtect Vuln; Citrix DoS Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, November 11, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.0

Have you ever found yourself in a situation where you had a large file that you needed to exchange. And, well, it was too large for email.

0:22.2

So you need to find some other way,

0:24.1

but you didn't really have a good, approved way

0:26.4

to exchange large files like this.

0:28.9

You may have found yourself using a private Dropbox account

0:33.6

or something similar to exchange this file.

0:36.2

And what Xavier is observing is that this shadow

0:40.9

IT, where employees are coming up with their own ad hoc solutions, often using free sites,

0:47.4

sometimes sites that charge a small nominal fee, are now impersonated by fissures, where a phishing email arrives claiming to try to

0:58.4

exchange a file, and when you're clicking on the link, you are seeing, well, not a well-known,

1:04.2

but what looks like a legitimate file exchange site, that then, of course, asks you for a

1:09.6

username and password. Pretty sneaky and

1:13.1

certainly something where it's important that you proactively provide your employees with tools

1:19.5

that work in order for them to avoid having to use their own tools that then of course are not

1:26.3

monitored and are not sort of integrated

1:28.4

in your overall security architecture.

1:32.5

And if you are using a Palo Alto firewall, including the Global Protect VPN feature,

1:40.3

well, it's urgent for you to patch.

1:43.6

A new vulnerability is patched in the latest release of PanOS, and you are vulnerable if you

1:51.5

are running any 8.1 version before 8.1.17.

1:58.5

Patched are two vulnerabilities, a buffer overflow and HDP request smuggling vulnerability.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.