meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, November 23rd, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 23 November 2021

⏱️ 4 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Office Macro YARA Rules; Magento Exploits; Exchange PoC (CVE-2021-42321); Windows PrivEsc 0-Day PoC; CloudLinux RCE

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, November 23rd, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. And today I'm quoting from Jacksonville, Florida. Apparently, office documents with malicious macros are still a problem, so Dede gave you a quick set of Yara rules in order

0:26.4

to find office documents quickly.

0:30.4

One is looking for Visual Basic code that's compressed and generated with the Visual Basic

0:36.1

for Application IDE.

0:38.3

So this is raw code that hasn't been modified yet.

0:43.3

The second one looks for Office document in the newer XML format.

0:50.3

That's of course then compressed as SIPP and then includes a VBA project.bin. So both of these

1:00.7

rules are looking for different types of office documents with macros. Sure, there are quite a few

1:06.6

documents that probably don't match, but for some quick triage, I'm sure you'll find these

1:12.4

rules helpful.

1:14.6

The British National Cyber Security Center released a notice asking retailers to double-check

1:21.4

their Magento installs.

1:23.9

Magento is Adobe's e-commerce platform, and it had a rich history of vulnerabilities,

1:31.2

including some relatively recent one that have often been exploited, for example, in order

1:37.6

to install credit card skimmers and the like. Well, if it's not too late for you, if you aren't

1:43.7

already sort of in your patch freeze for the like. Well, if it's not too late for you, if you aren't already sort of in your

1:44.9

patch freeze for the holiday business, double check whatever e-commerce platform you're

1:51.7

using, not just Magento. Make sure that you are up to date. I'm sure as business heats up,

1:59.6

ransomware will probably try to take advantage of that in order to add additional pressure to their demands.

2:07.6

Well, and then some news for the exchange users out there. We now have a public exploit for CVE 2021, 42, 321.

2:18.3

This vulnerability affects Exchange Server 2016 and 2019,

2:24.3

including if you're running it in hybrid mode.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.