meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, October 22nd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 22 October 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Agent Tesla Shipping Emails; CN Exploits Usual Vulns; URL Bar Spoofing; Oracle CPU

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, October 22nd, 2020 edition of the Sandstone Storm Center's Stormcast. My name is Johannes Ulrich, and that I'm recording from Jacksonville, Florida.

0:14.3

Our handler, Daniel, has been tracking some fairly peculiar, malicious emails. Now, they come in the form of, well, it looks sort of like

0:22.5

a shipping notice. Many of them are in all caps and attempt to impersonate logistics or

0:31.0

shipping a company that actually exists. So that's usually used as the from address. Also,

0:37.0

a couple of sort of details within these

0:39.0

emails appear to be correct or somewhat legitimate, like, for example, the name of particular

0:45.4

ships that are being mentioned in these emails, as well as sort of the ports that these

0:51.2

ships frequent. Also, it's interesting that these emails are typically sent on weekdays from 2 to 4 AM UTC,

1:00.8

which Daniels suggest may indicate that these emails were sent in the morning in Bangkok,

1:06.0

Shanghai, sort of these time zones, but a lot of the mail servers being used are located in Malaysia,

1:14.6

and of course, a sort of globally distributed set of mail servers.

1:19.5

Otherwise, the attachment that comes with these emails typically is ancient Tesla, so that's

1:25.5

spyware that typically does exfiltrate stolen data via HTTP or over email.

1:32.4

Now, the email here uses SMTP over TLS or SMTPs on port 587 TCP.

1:42.5

And the NSA released a report this week of the exploits being known by Chinese state-sponsored

1:49.8

actors. Another name for the report may have been that, well, Chinese state-sponsored actors

1:55.6

are using the same vulnerabilities that everybody else is using. And of course,

2:00.2

Wal-a-Blis we have talked about here at LinkedIn this year,

2:04.2

like for example, all these perimeter security devices that I keep talking about,

2:09.0

Pulse Secure VPN, F5 Big IP, Citrix, ADC,

2:13.8

ADC vulnerabilities, and then of course the standard set of sort of client side of vulnerabilities as well.

2:21.3

But maybe you can take a look at the report and double check your organization for these

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.