meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, November 19th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 November 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Controls Less Security; Google Chrome Update; Firefox HTTPS Only; Windows Kerberos

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, November 19th, 2020 edition of the Santernut Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:14.2

Quick tip from Xavier today.

0:15.9

He found on Virus Total, actually, some emails from users that apparently try to bypass some security

0:23.6

controls. A lot of companies make it difficult to attach files to email, so users try to find

0:31.4

alternative ways to transmit files. They need to transmit for business. In this particular case, a user did upload it

0:40.0

to an own cloud account, which in itself is not bad, but apparently the recipient didn't have access

0:45.8

to the own cloud system. And as a result, the sender just sent their credentials along and essentially shared the account.

0:56.8

Shared accounts are always bad.

0:59.1

I've seen it similarly happen actually in one organization that had a big breach.

1:06.4

As a result, didn't allow any email attachments, which then of course led to everybody using their

1:12.8

personal email address in order to receive email, which now totally went outside any kind

1:21.1

of corporate email policy enforcement.

1:25.2

Then a couple of updates about browsers.

1:28.9

Google released a new version of Chrome fixing 11 vulnerabilities rated as high and

1:35.3

a number of other medium and low vulnerabilities.

1:39.8

Secondly, we do have an update for Firefox, Firefox,

1:43.6

and it takes the interesting step to introduce a Secondly, we do have an update for Firefox, Firefox 83,

1:45.0

and it takes the interesting step to introduce an HTTP only mode.

1:50.0

Now, similar behavior has been available in the past as plugins for your browser,

1:56.0

but what essentially does is when you're connecting to a website,

2:00.0

it will connect to HTTPDPS by default,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.