meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, August 24th 2016

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 24 August 2016

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Voicemail/CC Dispute Malspam; #hostoftroubles; Open Source #BTS Vulnerabilities

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, August 24, 2016 edition of the Sans and it's Storms and as Stormcast.

0:07.0

My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida.

0:12.0

As general awareness items, we got two different email scams that are going around right now, distributing Malware.

0:20.0

First one, Xavier wrote up and that pretends to be a voice message.

0:24.9

We have seen these before in particular sort of trying to customize themselves a little bit

0:29.4

look like voice messages that come from popular voicemail systems.

0:35.3

Not quite familiar with the one that we received here, but certainly

0:40.0

looks quite convincing and of course does trigger the user to click on the voicemail in order

0:46.7

to replay it. The second one we haven't written up, that's just an email that claims to be

0:53.9

a credit card dispute.

0:56.0

Essentially they're using your domain name and then claim that they received a credit

1:00.0

card charge from you and then they include an attachment with a VIRT document as proof.

1:06.0

Again, I can see a particular small business and such fall very easily for this particular scam.

1:13.5

The result in either way is that you'll be infected with malware.

1:18.7

For the most part, these scams do download generic downloaders, so the actual malware could

1:25.7

change at any time.

1:35.5

And if you saw an update message from Microsoft for Microsoft Office, this is actually legit.

1:38.6

You may have seen it yesterday or today.

1:43.9

This is an update that was originally released earlier this month on patch Tuesday, but it now also

1:46.0

patches Mac Office 2011, as well as some 64-bit versions of Office for Windows that

1:53.4

weren't patched originally, so just apply this as any other Office update.

2:00.0

The bulletin affected by this is MS-1699 and again

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.