ISC StormCast for Wednesday, January 24th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 24 January 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, January 24th, 2024 edition of the Sands and the Storms and its Stormcast. |
| 0:09.0 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:15.3 | I post a quick update today with some of the exploit activity we are seeing against adlation. And well, |
| 0:22.8 | the quick summaries, we are sort of seeing the usual suspects. There is sort of your |
| 0:28.5 | Mirai style attacks. There are a couple of sort of crypto coin miner likely attacks in there. |
| 0:34.8 | Haven't analyzed all of the binaries being sent here. Also a lot of |
| 0:38.7 | scans that pretty much just try to figure out if a particular system is vulnerable. I noted a couple |
| 0:46.5 | of in the case of compromise, kind of that we are seeing. Now, one tool that is used quite |
| 0:53.4 | frequently here is OAST. that's short for out-of-band application security testing. |
| 1:01.0 | And there are a couple of domains that are being used here, OST.life.fun.com. |
| 1:06.0 | Site, typically to retrieve specific URLs in order to identify vulnerable hosts, but also to identify |
| 1:14.7 | them via DNS lookups and such. So if you are seeing these particular domain names in your |
| 1:22.9 | environment, double check could be part of authorized penetration test, |
| 1:28.5 | but definitely something that you probably should alert on. |
| 1:33.1 | And while we keep getting interesting new vulnerabilities, |
| 1:38.4 | Horizon 3 AI published a blog post with details regarding a vulnerability that was recently patched in |
| 1:46.9 | Florida's Go Anywhere, MFT, MFT standing for their file upload tool. |
| 1:54.6 | This application has been vulnerable to past now. |
| 1:57.0 | This recently patched vulnerability allows the attacker to add arbitrary admin users to |
| 2:04.2 | the system. |
| 2:05.6 | The patch fixes the vulnerability. |
| 2:08.1 | Like I said, the patch was actually released back in December, but we do have proof-of-concept |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

