meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 1st, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 1 February 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. RPMSG Phishing; QNAP Auto Update; Samba Vuln; Datacenter Managment Exposed; XML Parser Vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, February 1st, 2022 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.0

We've got a quick post today by Xavier about RPMSG files or restricted permission messages. These are essentially email messages with digital rights management,

0:23.8

so the sender can restrict what you're doing with this message.

0:29.1

And, well, it's sort of part of the Microsoft messaging ecosystem.

0:34.0

So in order to send the message, you have to have an Outlook account and also the

0:40.3

recipient typically needs to use Outlook in order to see the message. At least within Outlook,

0:46.4

the messages are opened automatically. The reason these are used maliciously is fishing. Remember

0:53.0

yesterday I talked about how Microsoft is reporting about fishing campaigns

0:57.7

where the sender is joining your Asia Active Directory domain.

1:03.5

Well, this could be then used with these RPMSG emails in order to appear more legitimate and also to possibly bypass certain security

1:16.2

tools.

1:18.3

And yesterday I mentioned how QNAP got some heat for automatically updating certain QNAP devices.

1:26.1

Well, today QNAP did a press release clarifying some of this in order

1:31.5

to be actually automatically updated. You have to enable the auto update feature. Auto update will

1:38.9

also not apply all updates. It will apply what QNAP calls the recommended version.

1:45.3

So if there's just a simple feature update or so it will not be applied,

1:50.1

they restrict that to significant updates of their operating system.

1:55.6

And what happened in this particular case is that the particular version of the QNAP operating system was

2:04.5

released a few weeks ago, but on January 27th QNAP set it as the recommended version in order

2:14.1

to counter this most recent attack of ransomware against the older versions of the QTS operating system.

2:25.3

And talking about network storage devices, we do have new vulnerability in Samba.

2:31.1

The SMB implementations used by many Unix systems, in particular by a lot of these network storage devices.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.