meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, April 23rd, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 23 April 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Exposed ICS; Evil XDR; GitLab Comment Bug;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, April 23rd, 2004 edition of the Sansonet Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich.

0:10.4

And today I'm recording from Jacksonville, Florida.

0:14.4

In today's diary, Jan is updating some work that he did three years ago.

0:20.4

Three years ago, Jan reported about a slight

0:23.5

decrease in the number of industrial control systems that were exposed to the internet.

0:29.9

Now, measuring that number isn't easy, and Jan is going through some details here in how he

0:37.4

compared and analyzed and weighted different measurements here.

0:41.6

In particular, Jan looked at the differences between census, Shadow Server, and Shodan,

0:46.6

who are three well-intended and very qualified organizations who are collecting the data.

0:53.4

But of course, they all have their own

0:55.5

methodology in how they collect the data and what they collect the data for. And that explains

1:01.8

some of the differences between Shadow Server on the low end with 60,000 devices and, well,

1:09.4

Senses and Shodan being somewhat close around 100,000 devices,

1:12.5

but only after Jan removed some of the devices from Senses, because, well, Senses has a

1:18.7

slightly different definition of what they consider an ICS device.

1:23.8

Well, long story short, the number of IS devices is increasing. It's increasing by about

1:31.2

30,000 devices over the last three years since Jan wrote up this initial sort of noted decrease

1:39.1

in devices. What's also interesting is that the increase and decrease is actually dependent on the country you're looking at.

1:48.1

So there appears to be some effect of national policy and also just the attention being spent in different countries on securing these devices better.

2:05.8

And currently, Blackhead Asia is going on and a talk by Schmull Cohen from Safebreach has caught some attention regarding turning an XDR into

2:13.1

a malicious tool. The goal here is essentially using the XDR for privilege escalation. The XDR

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.