meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 18th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 January 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Smarter Log4Shell; Special MSFT Update; Cisco CCMP Patch; Zoho Patch; Google Chrome Private Network Restriction

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, January 18th, 2020 edition of the Sans and the Storm Center's Stormcast.

0:08.5

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:13.0

A quick reminder today that log for shell attacks, attacks that are attempting to exploit. The recent vulnerability in Log 4J are still a

0:24.5

thing. Well, it sort of has fallen off the radar after this initial barrage of attacks that

0:32.3

typically just sort of took a prey and spray kind of approach to just throwing the string all over the place.

0:40.1

Well, now what we're seeing is attempts to tailor the exploit two particular systems.

0:47.1

Have one here that I wrote up today that looks like it's going a bit after Tomcat and trying

0:53.7

to do sort of some bypass here

0:56.8

in order to inject code into Tomcat.

1:00.5

So don't stop looking for vulnerable systems here if you haven't been hit yet by any compromises.

1:07.3

We definitely have seen sort of more targeted hacks against, for example,

1:13.3

Unify controllers as well as VMware.

1:17.9

And of course, over time, attackers will get better at exploiting this vulnerability against

1:23.2

specific systems.

1:26.2

Microsoft today released a special set of updates to deal with some of the failures that

1:32.3

came up with last week's January cumulative patches.

1:37.6

As quoted here by a pleading computer, this update addresses issues related to VPN connectivity,

1:43.2

Windows server domain controllers, restarting

1:45.7

virtual machines, start failures, and REFS formatted, removable media failing to mount.

1:53.5

So let's hope that with this update, all the Windows patches for this month can finally

1:59.9

be applied. And remember, there's still sort of that

2:02.6

HTTP.sys issue that hasn't really been exploited yet, but is still sort of looming. And Cisco

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.