meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 28th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 28 October 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SonarQube Exploited; MSFT Edge/Chrome Updates; Flash Removal Tool; MSFT Teams

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, October 28, 2020 edition of the Sansanet Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.7

The FBI today released an interesting flash bulletin stating that they identified actors that started actually back

0:23.6

in April to exfiltrate source code using vulnerable Sonor Cube instances.

0:30.6

Sonor Cube is typically used to check code quality and do static code analysis.

0:43.1

As such, the tool shouldn't really be exposed to the public, but apparently exposed instances that are also badly configured are then being exploited to exfiltrate code.

0:50.1

So it is not necessarily a vulnerability in Sonor Cube per se, but more a vulnerability in how it is

0:57.8

configured.

0:59.0

They're not going into too many details here as to what the exact vulnerability is that's

1:04.5

being exploited, but SonorCube comes pre-configured with well-known credentials, username admin and password admin.

1:14.4

Also, there have been problems in the past, for example, with Jenkins integrations and such

1:20.1

that did reveal the SonorCube password.

1:25.7

It is my guess that this is probably all about default credentials or credentials

1:30.3

that have been leaked before. So essentially, credential stuffing. And if you receive today an

1:37.7

update from Microsoft for Microsoft's Edge browser, don't be too surprised. This is actually a chromium update.

1:47.4

Microsoft Edge is now based, of course, on the Chromium project, just like Google Chrome.

1:54.4

And as such, well, whenever there are chromium patches, you will see Microsoft Edge patches,

2:00.6

which of course is not necessarily

2:02.8

aligned with Microsoft's Patch Tuesday.

2:05.8

The highest severity of the fixes that were released today in a total of five vulnerabilities

2:12.0

were fixed is high, and one particular vulnerability CVE 2020 15999 has already been exploited in the wild.

2:26.9

And while it is not patched Tuesday today, it is the fourth Tuesday in the month, and that means

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.