meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 11th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 11 February 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Greedy Paypal Phish; SupportAssist Vuln; Lock My PC Scam; Docker Registries @unit42_intel

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, February 11th, 2020 edition of the Santernet Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.6

And I'm recording from Jacksonville, Florida.

0:13.8

Jan today documented one of the little bit better, smarter PayPal fishing attempts.

0:19.7

The lure is very typical for these kind of fishing attempts

0:24.5

where it claims that someone else try to log into your account. Now, when you're trying now

0:31.0

to log into the fishing site, it's not going to redirect you to the real PayPal side like

0:36.7

some of these fishing attempts.

0:39.0

Instead, it's actually telling you that, well, your username and password was blocked.

0:45.6

The account is locked.

0:46.8

And then it's asking you for a bunch of other personal information to verify your identity.

0:53.9

Now, I believe that most users will probably

0:58.0

sort of halfway through this process figure out that something isn't quite right, but the trick is

1:04.2

that at this point, the attacker already collected a bunch of useful information, good one to possibly include sort of in your

1:14.7

awareness brief or whatever you do to train your users not to fall for these tricks. And if you

1:22.5

use a fishing attack like this, I think one of the important things to stress is that people shouldn't

1:29.8

be ashamed of falling for the initial fish, but report if they then sort of halfway through

1:37.5

figured out that they probably entered too much information. And Dell patched uncontrolled search path vulnerability in its support assist software.

1:51.8

This software is often pre-installed on Dell computers in order to help you debug issues

1:58.1

on the system and interact with Dell support via this vulnerability.

2:04.1

It's possible to elevate privileges by getting Dell support assist to execute arbitrary code on the system.

2:14.1

Now, this software has sort of a rich, recent security history for vulnerabilities just last year.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.