ISC StormCast for Tuesday, June 27th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 27 June 2023
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, June 27, 2023 edition of the Sands and at Stormtunners Stormcast. |
| 0:08.3 | My name is Johannes Ulrich and then I'm recording from Stockholm, Germany. |
| 0:13.9 | The NSA has published a mitigation guide for Black Lotus. |
| 0:19.0 | Not sure if you remember, but this sort of was revealed last year. Black |
| 0:25.1 | Lotus is malware that does infect UFI firmware. In order for Black Lotus to work, it |
| 0:33.8 | typically needs two vulnerabilities that were patched by Microsoft in January, I believe, |
| 0:40.4 | early this year. |
| 0:43.0 | What the NSA points out in their mitigation guide is that patching these vulnerabilities |
| 0:50.2 | may not necessarily solve the entire Black Lotus problem. |
| 0:54.2 | The issue that they're pointing out is that there are vulnerable firmware images that are still valid, |
| 1:03.4 | meaning they're still validly signed, they have not been revoked. |
| 1:07.8 | So an attacker could do something, well, as we sort of seen sometimes with the |
| 1:12.4 | Bring Your Own driver kind of attacks, for an attacker is first essentially downgrading |
| 1:18.8 | or installing a version of the bootloader that is known to be vulnerable, that is still |
| 1:25.8 | properly signed. So the user may not necessarily be warned that |
| 1:29.7 | this is a malicious bootloader, which it isn't. It is not malicious. It's just vulnerable and |
| 1:35.6 | then allows for the install of additional matter. That's sort of what Black Lotus is all about. |
| 1:43.2 | So if you're worried about this, take a look at the full NSA |
| 1:46.8 | mitigation guide for Black Lotus with more details about how the attack works and how you |
| 1:53.2 | protect yourself from it. But some of the highlights here specifically regarding this issue is |
| 2:00.4 | that first of all, you should monitor device integrity |
| 2:03.6 | measurements and the boot configuration, so detect any change whether or not it's malicious |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

