ISC StormCast for Tuesday, October 17th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 17 October 2023
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, October 17, 2023 edition of the Sandinand Storm Center's Stormcast. |
| 0:08.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Quick diary today by Jan about some developments with fishing. |
| 0:19.1 | There's a lot of talk, of course, also about the use of AI in creating fishing campaigns. |
| 0:25.3 | Personally, haven't really seen much here. |
| 0:28.2 | A lot of dubious numbers being spread in that respect. |
| 0:32.0 | Jan looked in particular at, you know, two typos still happen in fishing? Because if attackers are using AI tools in order |
| 0:39.9 | to create those phishing emails, well, you're less likely going to see these typos. You still see |
| 0:46.0 | them. They're still pretty common. Of course, they're common in some normal email as well. And that |
| 0:53.0 | just leads to this being not necessarily a great distinguishing |
| 0:56.4 | feature here, but still something that still happens with current fishing attacks, AI or no AI. |
| 1:05.8 | Also, one thing Jan points out here is the increasing use of the interplanetary file system or IPFS |
| 1:12.5 | URLs in these phishing emails. I've seen this for quite a while now. And this is certainly |
| 1:18.2 | something that you probably want to look for because that may be actually a little bit better |
| 1:23.9 | and easier to detect a kind of artifact of phishing emails these days. |
| 1:30.4 | And Cisco is reporting that they're seeing active exploitation of thus far unpatched vulnerability |
| 1:37.6 | in Cisco iOS XE. This vulnerability affects the web management user interface. |
| 1:46.7 | It does allow an unauthenticated user to add an arbitrary user to the system with level 15, |
| 1:54.2 | which is, well, the highest level that you can get on a Cisco iOS device like this. |
| 2:01.1 | Best guidance here from Cisco is, well, don't be stupid and expose this stuff to the Internet. |
| 2:07.2 | If you have these web-based management interfaces, please set up a VPN or restrict access to them in some way. |
| 2:19.8 | Turn them off and then maybe have a little script via S-H or so to turn them on again and hopefully you have your S-H authentication under control. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

