ISC StormCast for Thursday, October 26th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 October 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, October 26, 2017 edition of the Sandtonet Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich. |
| 0:09.5 | And the I'm recording from Berlin, Germany. |
| 0:12.8 | Coin Hive, the company behind the crypto coin mining JavaScript, has had a setback in its quest to clean up and present itself as a more |
| 0:24.5 | reputable company. |
| 0:26.3 | In this latest incident, sometime late on Monday, Coin Hive's Cloudflare account was compromised |
| 0:34.5 | and requests for its popular cryptocurrency mining script were redirected to a modified |
| 0:41.5 | version with a fixed side key, giving the owner of that particular side key exclusive credit |
| 0:48.3 | for any cryptocurrency mine. The root cause of this issue was apparently a breach of Kickstarter. Kickstarter's username and |
| 0:57.7 | password database was leaked a couple years ago, and Coin Hive used the same username and password |
| 1:04.4 | that they used for Kickstarter for its Cloudflare account, which then of course led to its compromise. |
| 1:12.4 | So lesson learned here, do not use the same password on different sites, |
| 1:17.7 | and of course, if possible, use to factor. |
| 1:21.1 | And I think I have said similar words a few times before. |
| 1:25.9 | And if you own a Dell PC, then you may be familiar with Dell's backup and recovery service. |
| 1:33.3 | This is a service that you can use to restore your system to factory default. |
| 1:39.3 | And essentially what it does is it does backup recovery disk for your operating system and |
| 1:47.9 | pre-installed software well sadly softthings.com a company that operates the service for del apparently |
| 1:57.3 | lost control of the domain del backup and recovery cloud storage.com. |
| 2:04.0 | Now, if you have Dell's software installed, then it will periodically check that domain |
| 2:10.5 | and potentially install updates from it. With losing control of the domain, a typo typo squatting company took it over and |
| 2:20.3 | registered it and then apparently malware was later served from that domain it isn't |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

