meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, September 19th, 2025: Honeypot File Analysis (@sans_edu); SonicWall Breach; DeepSeek Bias; Chrome 0-day

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 19 September 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Friday, September 19th, 2025: Honeypot File Analysis (@sans_edu); SonicWall Breach; DeepSeek Bias; Chrome 0-day

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Friday, September 19th, 2025 edition of the Sands Internet Storm Center's Stormcast.

0:12.7

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.8

And this episode is brought you by the Sands.edu graduate certificate program in penetration testing and ethical hacking.

0:26.4

In diaries today, we have a post by one of our undercredited interns, Nathan Smithen, who did look at the download directory in our curry honeypot.

0:37.6

That directory can be a little bit overwhelming for someone new to investigating Honeypots.

0:43.0

It's really important to sort of find quick methods to triage what's there and quickly

0:48.9

find patterns.

0:50.0

One of the very common patterns is something that Nathan is looking at here, and that's where

0:56.3

the bot has a small bash script that first downloads the actual bot then for multiple

1:04.0

architectures and executes them, hoping that one of those will work on the architecture on

1:10.3

the particular attacked victims' system.

1:14.1

Overall, this is something that you'll see a lot in honeypots and definitely something to sort of be

1:19.4

familiar with if you're trying to sort of work your way through a lot of these detects.

1:25.3

And in the past, we had a lot of sonic wall news and suggestions that it may be

1:30.7

zero days or that maybe firewalls were re-exploited after being exploited in the past and,

1:38.5

well, credentials being leaked by the firewall. Turns out that there was another thing that, well, we didn't quite consider yet.

1:48.3

And Sonic Wall published an advisory now that they found a good number, like 5% of their

1:56.5

customers, had their My Sonic Wall account compromised.

2:01.7

This was, again, a password brute force,

2:04.6

so not real vulnerability, I guess you could argue,

2:08.3

within My Sonic Wall other than maybe preventing brute forcing.

2:12.7

I'm not sure what mitigations they had in place for that.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.