meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, September 17th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 17 September 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Encrypted Sextortion; Simjacker; LassPass Fix

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, September 17th, 2019 edition of the Sands and the Storms anders

0:07.8

Stormcast. My name is Johannes Ulrich. And I'm recording from Stockholm, Germany.

0:15.2

One of the ways how attackers are often evading antivirus and malvare engines is just to encrypt in their malicious

0:25.0

attachments and of course encrypted zip files have been around for a long time and many other

0:30.4

file formats also do support some form of encryption that is often used for this purpose.

0:38.3

Latest example is good old by now sextortion emails.

0:43.3

These emails, of course, have been flooding us for over a year now,

0:48.3

and the attackers are slowly, I think, running out of targets,

0:53.3

and also mail filters are getting better in identifying

0:57.0

these emails. So the latest example that DDA came across actually used an encrypted PDF.

1:04.2

This, of course, makes it more difficult to filter these malicious attachments unless you're able to just outright filter

1:14.2

encrypted PDFs, which may or may not work in your environment.

1:21.2

And adaptive mobile security broke a story that I probably should have covered yesterday,

1:26.7

just sort of missed it, and

1:30.0

they're calling it Sim Jacker.

1:32.3

Now, this particular attack is interesting in so far in that it really uses more a feature

1:38.3

of SIM cards than actually exploiting any features. Sim cards, as they're used in devices ever since GSM networks

1:49.6

introduced them are actually quite sophisticated little computers so it's yet another

1:55.5

processor yet another code environment that attacker can leverage to execute code and access features

2:04.4

in the phone. In particular, as far as Sim Jacker is concerned, SMS messages can be sent

2:11.2

to a phone and they can contain instructions that are then executed within the SIM card.

2:18.6

All this happens via a Sim Alines Toolkit browser or short SAT browser.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.