meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, March 3rd, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 3 March 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Qakbot+Cobalt Strike; Exchange Server 0-Day; Google Chrome 0-Day; iOS Jailbreak

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, March 3, 2021 edition of the Sandton and Storm Center's Stormcast. My name's Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.9

Well, today we do have a podcast full with currently exploited serenaries and emergency patches, but I decided to first talk about something

0:23.6

very regular, and that's today's diary by Brad about a quagbot infection, because with all

0:31.7

the seradase, this is probably the most likely mode how your network will get compromised, and that's the good old

0:41.1

user clicking on an attachment, running a macro, and triggering quagbot. What Brad was looking

0:49.4

here in particular was, what if the system that's infected is connected to an active directory domain and

0:57.0

that's something that has really been shown up more and more lately where malware behaves

1:04.0

different in these sort of more corporate environments and yet again Brad saw Cobalt

1:10.0

strike being installed for follow-up activity.

1:13.6

If you're interested in the indicators of compromise and to walk through traffic yourself,

1:19.6

Brad, as usual, has the packet captures for you.

1:24.6

But let's say that you don't trust the cloud.

1:28.6

You want full control over your email in order to prevent attachments like this from being

1:35.5

received by your users.

1:37.2

Then you may still be running your own exchange server.

1:41.8

And this is where probably the biggest story for today comes in, and that's Microsoft

1:47.7

releasing a special update for exchange after also stating that these vulnerabilities

1:55.2

have already been actively exploited by what Microsoft calls the Haphnium group and currently associated

2:03.0

with the Chinese government.

2:04.9

Now, this has been exploited only against the very limited number of targets, according to

2:10.8

Microsoft and Microsoft's blog post has additional details about the particular vulnerability and how this particular group

2:20.7

exploited it and used it to install web shells.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.