ISC StormCast for Tuesday, July 9th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 July 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, July 9th, 2019 edition of the San San Bernard Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich. |
| 0:08.5 | And today I'm recording from London, England. |
| 0:12.6 | This weekend, credentials for a GitHub account associated with canonical were apparently compromised, |
| 0:20.2 | and this account was then used to add a number |
| 0:23.6 | of repository as well as adding a few issues to canonical projects. |
| 0:30.6 | This is important because Canonical is the company behind Ubuntu, one of the more commonly used Linux distributions. |
| 0:40.0 | Now, the entire impact isn't clear yet, and as a canonical employee stated, |
| 0:46.4 | an investigation is still underway. |
| 0:49.0 | Doesn't appear like anything too critical, got modified. |
| 0:53.7 | Launchpad, which is sort of the distribution system |
| 0:56.4 | that canonical uses for Bantu was not affected by this compromise of the GitHub |
| 1:04.0 | account so right now it doesn't look like you have to do anything if you're using |
| 1:09.6 | Ubuntu maybe if you're using GitHub make sure |
| 1:12.3 | that you're enabling two-factor authentication and that you are regularly reviewing any accounts |
| 1:18.7 | associated with your projects and I'm looking forward to find out what exactly happened here |
| 1:24.8 | in canonical's case and how they detected the compromise and |
| 1:30.3 | how they actually then responded in terms of figuring out what this rogue user may have |
| 1:36.3 | possibly done to their software and Midgecard attacks are in the news again. |
| 1:45.1 | This time Sanquin Security Labs, a company that specializes in responding to these type |
| 1:50.6 | of attacks, detected, 962, preached web stores on July 4th last week. |
| 1:59.4 | This, they say, is part of a larger automated campaign. They're scanning |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

