meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 28th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 28 February 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Ubiquity Takedown Aftermath; New Govt Botnet Advisory; SVR Cloud Attacks; Hugging Face ML Models

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, February 28, 2024 edition of the Sands and its Storm Center's

0:07.6

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. A little bit

0:15.0

over a week ago, the Department of Justice published a press release stating that they actually took action

0:22.5

against a botnet that infected home routers in the US.

0:27.5

Apparently, this botnet was associated with the Russian intelligence services, and it

0:34.5

specialized in infecting ubiquity edge routers that were still configured with the default password of UBNT.

0:43.5

So username and password were both UBNT, which is the default username and password for most equipment made by ubiquity,

0:51.8

like for example their cameras, switches, routers typically start out

0:56.5

with this username and password.

0:58.6

Now, the press release didn't state exactly when this happened, but they also said that

1:04.3

they got the court order that allowed them to do this.

1:08.0

In January, there was also a redacted copy of the court order. Also,

1:13.6

didn't really exactly say which exact commands. They ran to then later block reinfection.

1:19.9

Apparently, they were adjusting firewall rules for that. And also, how many of these bots

1:26.5

were exactly eliminated.

1:28.6

But I took a look at our data to see if we saw any change in scanning for these default

1:35.9

credentials, UBNT, UBNT, which are typical for OPEVIDE equipment.

1:41.8

Well, it turns out, didn't really see much of a change here.

1:45.6

Now, I looked at the number of sources that are actually scanning for these credentials.

1:51.7

They don't look like they change much at all.

1:55.0

There is a small sort of drop if you sort of draw linear regression, but it's anything but significant. Also, if you're

2:03.7

looking at the total number of reports, there is a small drop, but it's a very odd kind of spike

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.