meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, September 27th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 27 September 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. ZeroFont Phishing; Apple Updates;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, September 27, 2020,

0:04.6

3 edition of the Sansonet Stormontas.

0:07.6

Stormcast, my name is Johannes Ulrich,

0:10.0

and I'm recording from Jacksonville, Florida.

0:14.4

Xerofan fishing is a technique that has been around for a few years.

0:19.4

Typically, the way it's used is that NetHacker is inserting text into a fishing email

0:25.0

with a font size of zero.

0:27.8

The usual goal of this text is to just break up the fishing text with that making it more

0:36.0

difficult for systems that are trying to detect fishing

0:40.0

to identify a particular email as a fish. The automatic systems won't really recognize that

0:47.1

the font size is zero, so they consider this text valid, but a human user will not see this text, so they'll just basically see the text

0:56.9

that the attacker wants them to see, and that's then the phishing email.

1:01.8

Jan today wrote up a diary that looks at a new way how zero-size fonts are being used.

1:09.4

In particular, this variety of the attack appears to target

1:13.5

common mail clients that do have essentially sort of a little preview pane where they list

1:19.4

the subject, the sender of emails, and then typically like the first line of an email.

1:26.1

And that, of course, is often used by users to quickly scan

1:30.0

through their email and, well, hopefully like delete some emails like phishing emails

1:35.4

before they even sort of bother to open it. In this case, the attacker inserted a zero font size line as a first line in the email that basically sort of

1:49.9

seemed to indicate that this email was scanned by some advanced threat protection.

1:56.1

So this first line indicating that it was scanned by some kind of security gateway is using a font

2:02.9

size of zero. It's only visible in that preview list so that ignores the font size. It's not

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.