ISC StormCast for Wednesday, July 20th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 July 2022
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, July 20th, 2020 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.4 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.1 | Our honeypods recently started recording a significant number of requests for beak.hp dash get. |
| 0:21.6 | No idea really what this URL is about. |
| 0:26.6 | These scans are a bit odd in that they overwhelmingly came from machines hosted with low-cost |
| 0:32.6 | hosting provider OVH, and the machines scanning from the URL do not appear to be involved in any |
| 0:40.1 | other activity. Now, a little bit Googling shows that the URL may be associated with |
| 0:44.9 | Cobalt Strike, but it isn't clear if a scan for this URL at all is meaningful to detect |
| 0:51.4 | a Cobalt Strike control servers. If you have any idea what's going on, let us know this is a bit of a puzzle right now. |
| 1:01.5 | And Oracle today released its quarterly critical patch update or short CPU. |
| 1:06.6 | It addresses 349 different vulnerabilities. Large number, but not unusual for this update from Oracle |
| 1:17.4 | as it covers the vast Oracle application portfolio, not just a well-known database. For example, |
| 1:25.7 | MySQL, Java, various middleware applications, they're all |
| 1:29.4 | included in this update. The update fixes quite a number of log-4J issues, for example, in Oracle's |
| 1:37.1 | communication instant messaging server and in Oracle's e-business suite. Oracle communication |
| 1:43.8 | software sticks out with four vulnerabilities |
| 1:47.3 | due to the Spring Cloud Gateway vulnerability, reaching a CVSS score of a perfect 10. |
| 1:54.5 | These vulnerabilities in open source components are well known at this point and have been around for a few months, so exploits |
| 2:03.0 | are available with these Oracle components now being marked as possible targets. |
| 2:09.4 | Attackers may just have to make some modifications to existing exploit code to attack |
| 2:14.4 | these Oracle products. |
| 2:16.7 | You should expedite patching or at least ensure that the vulnerable products are not exposed if patching. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

