meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 28th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 28 January 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Coronavirus Preparedness; RD Gateway; Mitsubishi Compromise

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, January 28, 2020 edition of the Sands and its Storm Center's Stormcast.

0:07.9

My name is Johannes Ulrich.

0:09.3

And I'm recording from Augusta, Georgia.

0:13.2

Over the last week or so, the developing coronavirus situation in China, of course,

0:19.8

has gotten a lot of news attention whenever we do see

0:24.5

a topic like this being heavily covered. There is always a good chance that we will see some

0:31.6

fraud associated with the issue. Now, historically, the two top things we have seen here are websites that

0:39.7

are popping up that either sort of collect fraudulent donations or are offering other kind

0:47.1

of fraudulent content. We also have seen Malver typically that uses, for example, news

0:53.7

about the event to trick users into

0:56.7

open malicious attachments in particular videos. If you see anything like this, please let us know.

1:04.1

Now, one thing we have observed is there are certainly a lot of domain names related to the virus being registered.

1:12.3

At this point, haven't really seen anything sort of malicious on these domains yet.

1:17.9

Most of them are just parked or have some blank sort of placeholder page at this point.

1:24.8

Of course, I don't really have any insight in what could happen with this situation,

1:31.3

but this is probably not a bad time to dust off your business continuity and disaster recovery plans

1:39.3

to take a look if they are still current. At the time when you know you need those plans, it's probably too late to review them and

1:50.4

to actually correct any problems that they may have.

1:57.0

Just a couple days after denial of service, proof of concept was released for the Remote Desktop Gateway Vulnerably CBE 2020-0609 and 0610.

2:10.1

Security researcher Luca Marcelli posted a video of a demonstration of an exploit that he wrote that actually achieve his remote code execution.

2:22.5

This exploit has not been made public yet.

2:26.1

Lucas states that he may post a plot post about this in the future.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.