ISC StormCast for Tuesday, June 1st, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 June 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, June 1st, 2021 edition of the Sandton and Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:10.2 | And I'm recording from Jacksonville, Florida. Public cloud services, of course, remain a preferred option to host various malicious content. And one of the reasons it often goes |
| 0:24.7 | undetected is that it's not always clear what particular host names or domains are actually |
| 0:31.9 | provided by the cloud company or what content is user provided. Xavier has a recent example of malicious |
| 0:42.7 | code hosted on scripts.gov.com. Much of content hosted by users on Google, of course, |
| 0:50.4 | uses Google user content.com and that has also often been used to distribute |
| 0:56.7 | malware scripts.gov.com a little bit less obvious that the content isn't actually provided by |
| 1:04.8 | Google but by users that are depositing their content on that particular site. |
| 1:13.0 | And we got a new security advisory from Sonic Wall. |
| 1:16.2 | Sonic Wall warrants that it's Sonic Wall Network Security Manager, if deployed on |
| 1:21.6 | premise, is vulnerable to command injection. |
| 1:26.0 | However, this vulnerability is only exploitable post-offication, |
| 1:31.4 | so an attacker would first need valid credentials to log in, but any credentials will do |
| 1:37.7 | and will allow execution of code with full admin privileges or route. |
| 1:44.2 | Sonic Wall made a patch available. |
| 1:47.2 | The unpatched version is 2.2.0. |
| 1:51.3 | The patched version 2.2.1 and for details, please refer to Sonic Wall's advisory. |
| 1:58.6 | And then we got an updated advisory from Yulad Packard Enterprise regarding remote code execution |
| 2:06.2 | vulnerability in their systems inside manager or SIM. |
| 2:10.6 | The root cause here is deserilization vulnerability. |
| 2:16.3 | The advisory itself is not new, but definitely you shouldn't |
| 2:21.1 | sort of just skip over it because you already saw it. It was originally published mid-December |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

