meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, July 2nd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 2 July 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Maldoc Payloads; Zyxel Patches; AMD Secure Memory Patch; Card Encrollment

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, July 2nd, 2019 edition of the Sandton and Storm Center's Stormcast.

0:07.2

My name is Johannes Ulrich, and the time I'm recording from Riyadh, Saudi Arabia.

0:12.9

In Diaries today, we got a quick tip from Dede for everybody who needs to analyze malicious office documents.

0:21.9

The feature he's looking at today is how Malware authors are able to hide malicious payloads in

0:29.7

user forms.

0:30.9

This is nothing really new, but the DA walks us through how to extract these payloads using his OLLI Dump tool.

0:39.6

And to help you even further to deal with this particular common feature in malicious office documents,

0:46.7

DDA also has a plug-in, the Stream O plugin, that can be used to extract data from these user forms like an example

0:56.7

that he used a text box that contains a URL of course the neat thing about

1:02.8

Oli Dump and all these plugins is that this allows you to easily analyze these

1:08.6

documents safely on the command line and even script and automate some of these analysis steps.

1:17.6

And Motor Maker Sychcel did release an update for its hotspot that include the free time feature.

1:26.6

Free time Wi-Fi hotspots are free hotspots that you can set up.

1:31.3

And the vulnerability being addressed here is first of all a reflective cross-sad scripting vulnerability.

1:38.3

And secondly, maybe even more interesting, something that Sykesil calls a security misconfiguration

1:45.4

vulnerability that would allow anybody to set up guest accounts.

1:50.4

These guest accounts then, of course, could be used to use the free hotspot.

1:57.6

These days, with all the various hardware attacks and abilities of processes to read each other's memory,

2:06.2

one feature that has come into focus, in particular on systems that are used for virtualization, is encrypted memory.

2:14.8

And A&D's solution here is what they're calling SEV or secure encrypted virtualization.

2:22.3

Well, AMD now patched a vulnerability in this important security feature.

2:28.0

The Google Cloud Security team found a way how an attacker could read the secret key from a system protected with

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.