meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 18th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 May 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 2FA vs Ransomware; Ransomware and Cyber Insurance; http.sys PoC; Browser HTML Sanitizer API; SANS.edu Research

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 18, 2021 edition of the Sandcent Storm Center's Stormcast. My name is

0:08.8

Johannes Ulrich, and I'm recording from Jacksonville, Florida. In Diaries today, we have a plea by

0:16.4

Daniel about two-factor of occasion for webmail or email in general, which is in particular

0:25.3

important as email still remains to be one of the preferred attack factors and, well,

0:32.6

ransomware, of course, being the goal these days that attackers are going for.

0:38.5

And there's nothing better to craft a plausible email if it's possible to compromise an email

0:46.6

of an insider or a trusted external source.

0:51.6

So as Daniel puts it, don't be the company that emails the ransomware to the victim

0:58.9

implement two-factor authentication, in particular with everybody moving to web-based email systems.

1:07.3

Well, it's just a matter of time until your users will get fished and two-factor authentication is probably the simplest defense that actually works in this particular case.

1:21.7

And talking about ransomware, you better check your cyber security insurance. Axa, one of the biggest insurance

1:31.0

companies out there, just announced that they will no longer cover ransom payments. Interestingly,

1:39.1

they made that move after becoming a victim themselves. Haven't seen anything from other insurances, but of course, as so often, I would expect

1:48.7

other insurances to pull along as a big player like AXA is making this move.

1:57.8

And one of the war on abilities highlighted in last week's Microsoft Patch Tuesday was CVE 2021-31-166.

2:07.0

This was the remote code execution vulnerability in HEP.Sys.

2:13.6

This is not yet a full remote code execution exploit.

2:17.9

It just triggers a blue screen of death and, well, it only works against specific versions

2:25.7

of Windows in particular, the latest version of Windows server core, so the version without

2:31.7

GUI.

2:33.1

But this certainly highlights the need to start patching these affected machines.

2:38.2

Again, only the most recent versions of Windows server, and again, only the core versions,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.