meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, March 8th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 8 March 2017

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. #CIA Leak; #Shamoon now #Stonedrill;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, March 8th, 2017 edition of the Sands and the Storm Center's

0:06.8

Stormcast. My name is Johannes Orich, and I am recording from Jacksonville, Florida.

0:12.5

Wikileaks today released a substantial collection of documents that apparently were stolen from

0:18.6

the CIA. The documents are in line with what should be expected

0:24.4

from a sophisticated offensive cyber operation. A number of interesting details emerged.

0:31.4

For example, a large part of the leaked data deals with mobile devices, in particular

0:37.4

exploits for various versions

0:39.7

of iOS are discussed many of the files also deal with persistence on OS 10 systems for

0:47.9

example by injecting code into the EFI firmware that you typically find on modern Apple computers. Exploids for Samsung TVs

0:59.0

also caught the attention of many commenting on the files from a defensive point of view.

1:05.0

The data dump includes some operating procedures on how to develop and deploy these tools

1:10.8

while evading detection.

1:13.2

So these guides provide some insight into how more sophisticated attackers deploy tools

1:20.3

and they make you some hints in how to detect them and what to look for.

1:26.6

The documents also outline how to make it more difficult to attribute tools to this particular

1:33.5

group.

1:34.8

This leak yet again demonstrates the risk of cyber warfare in that weapons once leaked can be used

1:42.9

by anybody, but it should be noted that at this point

1:45.8

at least, the documents, they include code snippets and such, but the actual exploit tools

1:52.9

are not included yet.

1:55.6

And as part of the press release, WikileLeaks stated that they may release them at a later point.

2:05.0

They're still sort of vetting those tools and looking for ways to actually publish them

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.