ISC StormCast for Wednesday, May 1st 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 May 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 1st, 2019 edition of the Sansa and the Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich and I'm recording from Augusta, Georgia. |
| 0:12.0 | Still got another update regarding CVE 2019, 2725. |
| 0:19.0 | This is the WebLogic deserilization vulnerability that was discovered late last week. |
| 0:26.6 | Cisco's Talis research team is now confirming that exploits against this vulnerability are active. |
| 0:34.6 | In particular, Cisco did spot the Sotomay |
| 0:38.4 | Ransomare being installed via this vulnerability. This particular |
| 0:44.2 | ransomware is specific to Windows. It will encrypt the user's |
| 0:48.8 | files and also delete shadow and backup copies of any files. |
| 0:59.9 | Now, this ransomware, just like the Unix, Cryptocoin miners that we have seen over the weekend, |
| 1:02.6 | are pretty well recognized by antivirus. |
| 1:09.1 | This is commodity malware, so nothing here is really targeted anymore at this point. |
| 1:13.7 | Every Weblogic instance that is exposed and is vulnerable is actively being abused by these exploits. Now, Facebook's marketplace apparently had a very |
| 1:24.0 | classic flaw in that it leaked the exact location of sellers. This is actually a vulnerability |
| 1:31.0 | that has happened to various similar sites. Now in the case of Facebook, when you place an item |
| 1:37.2 | for sale, you can specify how closely you would like to let buyers know your location. |
| 1:45.5 | So you can, for example, specify, hey, just say that I'm within that city or that part of the city. |
| 1:51.3 | But apparently what's actually being sent back by Facebook's API as part of a JSON encoded response |
| 1:59.6 | is the exact location of the seller when the ad was placed. |
| 2:05.6 | This is not the first time something like this happened. |
| 2:08.6 | Probably the largest sort of leak like this that I'm aware of was with Craigslist back in the day. |
| 2:15.6 | Now with Craigslist you upload your own pictures and Craigslist |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

