ISC StormCast for Wednesday, March 20th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 March 2024
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, March 20, 2024 edition of the Sanchez in Storm Center's |
| 0:07.1 | Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. |
| 0:14.0 | I wrote up a quick case study today about an IP address that is hunting firewalls. I should probably |
| 0:20.8 | say more correctly, |
| 0:22.7 | parameter secure devices. There are also some Zell gateways and the like part of this. |
| 0:29.1 | This is, of course, something that we have been talking about for a couple of years now, |
| 0:34.3 | that these devices and their vulnerabilities are a prime target for attackers. This |
| 0:41.2 | particular IP address has been added since about December 7th last year, started looking |
| 0:48.5 | for 40-net device at first. Actually, interestingly, a couple days before a patch was released for a |
| 0:56.3 | particular vulnerability there. And more recently in the last few days, really sort of spread |
| 1:02.2 | out and looking now for vulnerabilities in like watch guard, Palo Alto, Imanti or Pulse |
| 1:09.3 | secure, F5, Citrix, and Cisco. |
| 1:13.7 | So really sort of your full set of devices. |
| 1:18.1 | There was a question from one of the handlers, |
| 1:21.1 | if there's any 40-gate devices here, |
| 1:24.3 | didn't see any attacks against those specific devices, but really what this |
| 1:30.2 | attacker is doing is more scanning for potential vulnerable devices to possibly then exploit |
| 1:37.0 | them once exploit becomes available for one of these devices. And this has been a little bit sort of a challenge for attackers, because typically after |
| 1:49.7 | a new exploit is released, well, devices are pretty much being exploited within sort of a |
| 1:56.6 | day or so. |
| 1:57.9 | So I wrote about this, I think, last week as well. You don't really have time |
| 2:04.8 | to patch, but attackers also don't have time to attack these devices because otherwise |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

