meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 4th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 4 October 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Exchange Fix Bypass; Schneider UMAS Patch Bypass; Comm100 Compromise

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, October 4, 2020 edition of the Sansonet Stormer's Stormcast.

0:09.1

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.5

Yep and we are still not done with the Microsoft Exchange Serer Days.

0:20.2

Turns out that the workaround that Microsoft

0:24.3

published is not really effective in actually blocking all variations of the exploit.

0:33.3

The pattern that Microsoft recommended blocking is Auditiscover.Json at PowerShell.

0:40.4

Well, it turns out the ad simple here is overly specific according to some, and it may lead to a bypass if another character, for example, is being used here.

0:54.1

I would still recommend applying that workaround.

0:57.6

Not sure if there is a more generic one that won't cause any problems.

1:03.1

So if you have already deployed it, definitely don't undo it.

1:06.4

It does protect against some attacks, just not against all attacks. And as usual, be aware of

1:14.1

any exploits that you see out there apparently on GitHub. There are a number of fake exploits.

1:20.4

I haven't run into one myself yet, but haven't really been looking for these exploits either.

1:26.7

There are also apparently some fake exploits for sale.

1:30.3

Just like whenever we have a high profile vulnerability like this,

1:33.3

you have the usual fake exploits, you have the exploits that are probably just going to

1:39.3

rig roll you or in a verse case erase your system if you are running the exploit.

1:46.0

So caution as usual.

1:50.2

And talking about patches that didn't quite get the job done,

1:54.1

well turns out that Schneider Electric had this problem with a patch.

1:59.3

They released in 2020.

2:01.6

The CVE number for the vulnerability was 2020, 28212, and it was a vulnerability in the Unified

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.