meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, October 24th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 October 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SIM Swapping; Discord Infostealer; Cisco Exploit Code; Tails 4.0 Released

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, October 24, 2019 edition of the Sancton Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich, and I'm recording from Santa Monica, California.

0:14.0

Phone calls and SMS messages remain an important second factor to authenticate users, even though organizations like,

0:24.1

for example, NIST have advised against doing so for a few years now.

0:30.8

As a result, we had a number of high-profile attacks over the last year or so, where sim swapping was used in order to impersonate

0:41.4

users. Sim-swapping typically refers to an attacker registering a new or a second phone

0:49.1

with a particular target's account, so they're able to receive phone calls or SMS messages

0:57.6

in addition or instead of the victim. In response to these attacks, the Federal Trade

1:04.6

Commission now came up with a brief guidance for consumers on how to protect themselves from these type of attacks.

1:13.6

First of all, they recommend not necessarily to reply to calls and emails with personal information,

1:21.6

also to limit the personal information that's shared online, particular phone numbers, of course,

1:26.6

and probably most

1:28.3

importantly to set up a pin or a password for a cellular account.

1:34.3

They also recommend just not to use a phone as a second factor, but of course you don't always

1:41.3

have the option to do so.

1:43.3

It's a fairly nice brief and to the point blog post,

1:47.3

so something good to share with relatives and others

1:50.5

that may not quite be as aware of this particular tactic.

1:57.1

A lot of modern applications take advantage of the electron framework. Electron applications are

2:04.9

written essentially using web technologies like HTML, style sheets and JavaScript, and then

2:12.8

execute it on a system just like any other native application.

2:19.0

A couple notable examples of, for example, Skype and Slack, but also Discord.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.