meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 16th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 16 November 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSIX to Redline; ChatGPT Code Interpreter vuln; Aruba and Netty Vulns; HARArmor @FronteggForSaaS

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, November 16th, 2020,

0:04.6

edition of the Sansonet Stormontas Stormcast.

0:08.4

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.5

Xavier today wrote up a sample that he found via virus total,

0:19.2

and he did so after reading the ghost pulse report. That's Malver

0:24.8

that has been going around lately and one of the interesting aspects of it is that it uses

0:31.1

MSI packages so dot MSI X files in order to spread itself.

0:37.5

These are really SIP archives, so good DDA's tools like SIPDump.PY are ideal to really figure out what's going on here.

0:48.0

And inside this particular file that Xavier found, there is a PowerShell script that in this case acts as an installer.

0:58.1

In the end, the victim will end up with the Red Line Info Steeler.

1:04.5

The other interesting part here is that the actual Info Steeler executable is downloaded as a fake image, so it's called

1:13.3

it this case dd-sert.jepak, but yes, it's just a plain executable that's then just being

1:22.1

executed on the victim's system. So watch out for dot ms.x files, probably nothing that you should ever really see in email,

1:31.4

and even having them downloaded to a workstation from a website should probably trigger

1:36.9

some alarms, even if it is a legitimate installer.

1:39.9

You probably still want to know that your users are installing software.

1:49.0

And we have some interesting new attacks against ChatGPT. The issue here is that recently ChadGPD added a feature that they call Code Analyzer,

1:56.0

and this feature does allow you to upload some code to chat GPT.

2:02.8

And chat GPT will basically tell you what it does, but it will also execute the code.

2:07.8

The code is executed in a dedicated virtual machine.

2:11.4

So each user is getting a different virtual machine to prevent codes from polluting each other. But the trick here is that you

2:21.9

may, for example, use that code to extract data from a webpage. If an attacker now has control

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.