meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, December 5th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 5 December 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Zarya Hacktivists; ICAN RDRS; Android and Gitlab Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, December 5, 2020,

0:04.6

edition of the Sansonet Storm Center's Stormcast.

0:08.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

Spend some time today following up on an observation that I wrote up last week about a pro-Russian hacktivist group going after

0:24.2

SharePoint vulnerabilities. I looked at a particular IP address that was used in these scans

0:30.4

and well, they have changed their targets. They're now looking for a number of other

0:36.8

vulnerabilities, like for example leaked environment files and other, well, essentially, credential files that may accidentally leak also exposed admin APIs.

0:50.3

So wrote up a little bit more about this.

0:52.4

A couple vulnerabilities that sort of stuck out that they're looking for.

0:56.0

One looked like a directory traversal vulnerability in a captive portal that's often

1:02.1

installed with OpenWRT, the open source router software.

1:07.4

Name of the portal is No Dog Splash.

1:14.4

Haven't seen this particular vulnerability documented.

1:20.6

Doesn't mean that it's real and just some zero day or so could be just some attempt to exploit things that don't really work. There's also some checks for like Cold Fusion admin URLs.

1:28.7

And another one that sort of stuck out was scans for an artifacts file in ML flow.

1:36.5

ML flow describes itself as a unified platform to navigate the maze of model development, deployment, and management for machine learning.

1:46.7

So certainly interesting piece of software being exploited here.

1:51.7

Also identified a couple other IP addresses that are likely associated with that activity

1:57.2

because the URLs that are being scanned by this particular host and then also

2:02.4

the other host that I saw are reasonably unique. There are not a lot of hosts really scanning

2:07.3

for these specific vulnerabilities, which again could mean that, well, these exploits actually

2:13.0

don't really work all that well. There are also some interesting geolocation challenges here that I outlined.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.