meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 17th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 17 January 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Malicious Google Ads; NortonLifeLock Password Manager Bruteforcing; nftables vulnerability; MSI insecure boot;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, January 17, 2023 edition of the Sands and its Storm Center's Stormcast. My name is Johannes Ulrich and then I'm a recording from Jacksonville, Florida.

0:15.2

Very quick diary today, really a story that I have covered already a couple weeks ago here, and this is

0:23.3

the need to run an ad blocker if you are using Google. It has become so bad about malware

0:32.6

being advertised if you're trying to search for software download sites.

0:40.9

In particular, some open source projects were recently hit,

0:45.3

like, for example, OBS Studio, VLC, Audacity,

0:48.7

the software I'm using here to record this podcast. All of these software packages were hit by look-alike sites that weren't just sort of organic search results,

0:58.5

but paid ads with Google.

1:01.7

So there is really no good alternative right now because it can be very difficult to distinguish

1:08.9

valid from invalid search results. For example, for Audacity,

1:14.7

the valid site is audacityteam.org, not just audacity.org or audacity.com. So very possible

1:24.5

for an attacker to come up with something like Audacity Dash Team and such.

1:30.0

That's the type of lookalike domains that you often see here.

1:33.3

They're not using fancy things like international characters and such.

1:36.6

Just the variations of the valid domain name in order to trick you into downloading malicious software.

1:44.9

On Twitter, Malvern Hunter team has sort of taking a lead here in uncovering many of

1:51.8

these fake sites and they daily almost publish new sites that are impersonating valid

2:00.7

software, open source or commercial, and then

2:05.2

the malware is being advertised via Google Ads.

2:10.1

And well, password managers are in the news again and not in a good way.

2:14.7

This time it's Norton LifeLog's turn. The password manager that the Norton

2:21.7

Lifelock uses is accessible via a webpage and well requires just a username and password. Imagine

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.