meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 24th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 February 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Malicious FD Reply; Firefox Cookies Protection; VMWare Update; Signed PDFs

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 24th, 2021 edition of the Sandtonet Storm Center's Stormcast.

0:08.6

My name is Johannes Ulrich, and the damn recording from Jacksonville, Florida.

0:14.5

The full disclosure mailing list is one of the probably most prominent mailing lists around where researchers do post

0:24.8

information about recent vulnerabilities. Like all mailing lists, it has sort of a simple

0:30.8

web component, but for the most part, it really just forwards emails to its members.

0:37.4

So it's not really a big surprise that mailing lists like this are being harvested and also being

0:43.0

used for malicious purposes.

0:45.8

Our handler Jan, for example, this week received a reply to a post that he sent to the

0:53.3

post full disclosure list two years ago, I believe, and this reply

0:58.9

contained a malicious attachment. Now, it did appear to be a genuine reply, so it wasn't just

1:05.3

that they harvested his email address from the list. It used the same message ID that he used when he

1:13.3

posted to the list and also the subject, of course, was maintained. This may of course be a nice

1:20.2

way to target security researchers overall, however, the attachment and the malicious email itself was everything but sophisticated. It was a simple

1:32.5

zip file and then Excel file that did try to install Quagbot. So really more something

1:40.0

that probably goes after all kinds of mailing lists and just happened to also come across

1:46.4

full disclosure. And I believe I spotted on Twitter a couple of replies of other posters

1:53.1

to full disclosure reporting similar emails. And thanks to everybody who reported a mistake I made yesterday, I stated that the Brave

2:04.0

browser is based on Firefox.

2:06.3

It's actually based on chromium, not Firefox.

2:11.0

But, well, let's make that up to Firefox and talk a little bit about some of the improvements

2:16.0

that we got in the latest version of Firefox,

2:21.3

and that would be Firefox 86.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.