meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 13th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 13 October 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft Patch Tuesday; Adobe Patches; PyPi Removes Malicious mitmproxy2 Module

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, October 13, 2021 edition of the Sansonet Stormsendors Stormcast.

0:07.9

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.3

And of course, it's patched Tuesday, and with that you got fixes for, well, 74-81 vulnerabilities, depending on how you count. Three of them are

0:23.9

critical. Three were previously disclosed and one has already been exploited. And that's

0:30.7

probably the big one here. It's CVE 2021-44-49. It's an elevation of privilege's vulnerability, and it's affecting Wynne 32K.

0:42.2

We usually get like one or two elevation of privilege vulnerabilities in Wynn 32K each month,

0:49.4

but this one has already been exploited by a Chinese-speaking advanced persistent threat actor,

0:57.4

typically labeled as Iron Husky.

1:00.7

The particular Malver that used it was labeled Mystery Snail and its remote access tool.

1:08.9

Aside from taking advantage of that vulnerability, mystery snail is sort of your standard remote access tool. Aside from taking advantage of that vulnerability,

1:11.7

Mystery Snail is sort of your standard remote access tool.

1:15.4

It infiltrates data, allows remote execution of commands.

1:20.0

And of course, because it takes advantage of this privilege escalation,

1:24.0

it can do all of that as a system.

1:27.2

Now, out of the three critical vulnerabilities, there are two in HyperV, and then we have

1:33.3

a third one that affects VIRD and could be leveraged for code execution, so this would

1:40.3

then be sort of the one-to-punch where an attacker would use the

1:44.8

VIRC vulnerability in order to execute code and then the Burge Escalation vulnerability

1:50.6

in order to gain system access.

1:53.7

We also have yet another print spooler spoofing vulnerability that's being addressed in this

1:58.6

update.

1:59.4

Not sure if that's related to the print nightmare

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.