meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, November 5th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 November 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Bluekeep Exploit Update; ClamAV Vuln; XCode Patch; MikroTik DNS Cache Poison

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, November 5th, 2019 edition of the Sandsenet Storm Center's Stormcast.

0:07.2

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.0

I want to start out with a couple of observations about the mass exploitation of the Blue Keep vulnerability.

0:19.8

I don't have a link for this, at least not yet,

0:22.9

but it's just some internal discussions we had here. First of all, it does appear to be quite

0:29.1

efficient. We have seen some numbers that pretty much all machines that were exposed got taken

0:37.0

over by this crypto miner.

0:39.7

Another little note here is also that once these systems are infected and are running the

0:46.2

crypto miner, you may get some false negatives from vulnerability scanners.

0:52.9

One of our handlers observed in his environment that all for a sudden all of the machines

0:58.0

that he had still registered as Blue Keep vulnerable appear to be patched.

1:03.0

What was actually happened was that they had been infected by this crypto coin miner,

1:10.0

and now his scan timed out and came back as a negative. So make

1:16.1

sure that whatever scanning tool you use does wait long enough for the replies to come back.

1:21.1

Otherwise, once the system is infected with this crypto coin miner, it may actually show up as

1:27.1

patched.

1:28.2

The bot itself doesn't patch the system, also doesn't block RDP access.

1:33.3

It just keeps the machine busy, so your response times from RDP are slow.

1:40.7

And then we got a vulnerability in ClamBC, the bytecode compiler for the Clam AV open source antivirus engine.

1:49.9

Now, typically vulnerabilities in antivirus engines aren't really all that uncommon, sadly, and certainly an important problem.

1:58.0

But in this case, it's probably less often an issue.

2:02.7

The more severe class of vulnerabilities in antivirus engines is triggered when the engine

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.