meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, March 30th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 March 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Twitter Abuse; Firewall Vuln Correction; UPS Attacks; MFA Bypass Attacks; Mars Stealer; Hacker Subpoena

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, March 30th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:14.6

Post an update earlier on a story that we had two weeks ago about fake accounts on Twitter soliciting donations in

0:24.8

cryptocurrencies for Ukraine.

0:28.0

Well, there are quite a few more of them since we originally saw the first accounts here.

0:34.8

One of our undergraduate interns, Jesse LaCruh, did write a quick

0:41.3

script to search for some of them, found very quickly 10 and actually since then a few more

0:48.0

accounts that are peddling the same crypto coin addresses as the initial accounts.

0:54.8

Sadly, many of them are still online and are still collecting money,

1:00.9

even though at least as far as Bitcoin goes, this attack hasn't really been all that

1:08.0

successful so far as we can tell.

1:11.8

And then yesterday I covered a number of different firewall vulnerabilities.

1:16.9

Apparently I may have said and I have to go back to listen to it again that the Sonic

1:21.8

Wall vulnerability was already exploited.

1:24.4

That's not true.

1:25.7

The Sonic Wall vulnerability has not yet been exploited.

1:30.8

The vulnerability that is already being exploited is the Saufos vulnerability. That's CVE 2020-1040,

1:40.8

and it does affect the Sophos firewall.

1:44.9

I'll link in to Sawfoss's advisory just to make sure that you got the right one.

1:51.8

And talking about vulnerabilities that are being exploited, SISA is reporting that they're

1:59.9

observing attacks against management interfaces for UPSs, the

2:05.6

uninterruptible power supply and not the shipping company being actively exploited.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.