meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 7th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 December 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Gafgyt/Mirai Sample; Packet Tuesday; Defcon Skimming; Fake D-Link Vuln; Android Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, December 7th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:09.0

My name is Johannes Orich, and today I'm recording from San Francisco, California.

0:14.0

In Diaries today, we do have a quick write-up by one of our under-graded interns.

0:20.0

Brock Perry is writing about one of those bigwittes IoT router, whatever you want to call it, attacks that are calmly attributed to the Gafgit and Mirai botnets.

0:32.8

Hard to actually tell the two apart these days with them sort of boring features from each other

0:38.4

and lots and lots of sort of various hybrid

0:41.5

malware like this evolving

0:43.8

and also the next episode of Packet Tuesday

0:48.6

is out and available for you

0:51.7

if you're interested in it. This time I'm talking

0:54.1

about TLS and I'm taking a client hello packet apart.

1:00.0

Well, have you ever deployed sort of a JavaScript library on your website,

1:05.0

maybe to track users, some free open source stuff,

1:09.0

but then kind of lost interest in really looking at all the stats,

1:13.9

and so you really just forgot about it.

1:16.1

Apparently, that's something that happened to users of the free JavaScript library cockpit.

1:23.7

Cockpit has been discontinued in December 2014, and recently Group re-registered a domain name used by Cockpit.

1:36.8

The domain name Web DashCockpit.jp.j.jp.j. was then used to serve malicious JavaScript,

1:45.1

very much sort of what we know calmly as Magecard group,

1:49.4

in that this JavaScript was then used to collect keystrokes on websites

1:55.5

that still were loading that now defunct for multiple years tracking a script. Apparently 40 different

2:04.7

e-commerce sites were compromised or data from those websites was compromised via this malicious script.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.