meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, May 19th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 19 May 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Multi Detection Confusion; O365 Mixes up Users; Apple BT Issues; #BIAS Bluetooth Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, May 19th, 2020 edition of the Sans and it's Storm Center's

0:06.1

Stormcast. My name is Johannes Ulrich. And then I'm recording from Jacksonville, Florida.

0:13.5

DDA did an interesting test, creating a SIP file with two malicious files. First of all, the ACAR signature, which is just the

0:23.5

signature used to debug antivirus, and secondly with the well-known tool mimicats. And then

0:31.4

he ran it through various antivirus engines and actually also uploaded to Virus Total.

0:38.5

And it turned out that it's a little bit hit and miss which signature triggers.

0:44.1

Most tools just sort of looking at it quickly seem to trigger actually on the ACAR signature,

0:51.2

which I believe also showed up first.

0:56.8

And it's a very typical behavior that we also have like a network inclusion detection where whatever signature triggers first is the one

1:02.5

that really matters, that then creates the alert. Of course, the trick here is that yes,

1:08.7

you know the file is potentially malicious, but seeing the ACAR signature

1:13.9

trigger, do you think, hey, this may just have been a antivirus test file or such, maybe from a

1:19.4

born-a-blis scan or a pen test, and you may ignore it, not notice that there's actually additional

1:25.8

more malicious payloads lurking in the same file.

1:30.6

And yesterday I mentioned how Edison Mail for iOS did mix up users or give users access

1:37.8

to other users' accounts. Well, looks like Edison Mail wasn't the only one this weekend to mix up users.

1:46.4

Outlook 365 apparently had a problem as well.

1:50.3

Now, doesn't look quite as severe as Edison Mail, but still, if you did perform searches on your Outlook 365 account, you may have retrieved data from other organizations,

2:05.4

Outlook 365 accounts. So interesting, but not sure exactly how widespread it was,

2:13.2

appears to have affected only a few users according to Microsoft, but really not a lot published

2:21.2

about the exact extent of this problem. And a couple of years ago, Apple introduced magic pairing

2:29.3

for Bluetooth devices that use Apple's proprietary chips.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.