meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, April 27th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 27 April 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. WSO2 Vuln Exploited; Core Impact via VMware; VirusTotal Update;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, April 27, 22 edition of the Sansonet Storm Center's Stormcast.

0:09.1

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.0

On April 1st, WSO2, a company that deals with platforms and APIs, including an open banking and

0:25.6

open medical records API, release details regarding a vulnerability that was originally discovered

0:33.3

by Orange Tsai.

0:34.9

Orange Tsai, of course, famous for discovering a number of high-profile vulnerabilities in

0:41.1

the past.

0:42.5

The vulnerability CVE 222-29-464 that affects multiple products does allow arbitrary file uploads

0:51.4

and with that also remote code execution.

0:56.1

These products are quite popular even if you may not necessarily have heard of them.

1:00.8

And earlier this week, Sisa announced that they added this vulnerability to their list of

1:07.5

already exploited vulnerabilities.

1:10.6

Well, and one of our handlers, Renato, did actually run into an exploit for this vulnerability

1:17.2

in an incident that he was dealing with, and it was, of course, a crypto mining case.

1:24.5

So, Ronado did write up what he found and how the exploit was delivered in this

1:31.4

particular case, a web shell was installed, and then the web shell was used to download

1:38.8

XMRick, the good old crypto coin miner, and then executed. Proof for concept exploits have actually been made available

1:45.8

on April 1st when the patch was originally released, so no big surprise here that we see this

1:51.8

exploited. And we have some news about the VMware workspace One Access vulnerability. This

1:59.6

vulnerability was first identified and patched on

2:04.5

April 6th. Now on April 11th, there was then an initial Proof Concept release. Then two days later,

2:12.8

actually exploitation was spotted in the wild. Now, typically when it comes to new vulnerabilities, you

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.