meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Monday, August 11th, 2025: Fake Tesla Preorders; Bad USB Cameras; Win-DoS Epidemic

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 11 August 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary


Google Paid Ads for Fake Tesla Websites
Someone is setting up fake Tesla lookalike websites that attempt to collect credit card data from unsuspecting users trying to preorder Tesla products.
https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186
Compromising USB Devices for Persistent Stealthy Access
USB devices, like Linux-based web cams, can be compromised to emulate malicious USB devices like keyboards that inject malicious commands.
https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/
Win-DoS Epidemic: A crash course in abusing RPC for Win-DoS & Win-DDoS
Internet-exposed DCs can be used in very powerful DoS attacks.
https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, August 11th,

0:07.4

2025 edition of the Sands and the Net Storm Center's Stormcast. My name is Johannes Ulrich,

0:14.2

recording today from Jacksonville, Florida. And this episode is brought you by the SandsSyskot

0:19.5

EDU graduate certificate program in Purple Team Operations.

0:24.1

This weekend's diary was about an at least new to me scam targeting,

0:29.3

well, a Tesla users or Tesla enthusiasts,

0:32.4

trying to pre-order some Tesla products,

0:35.3

in particular the Tesla Optimus robot. If you're searching for

0:40.2

Tesla Optimus pre-orders on Google, you're being confronted with a number of, well,

0:46.9

links that are sponsored, so they're paid for it, but they're not paid for by Tesla. If you're

0:52.7

clicking on any of these links, you are ending up on a lookalike

0:57.6

side that looks like a little bit older design of the Tesla website, but the latest domain name

1:03.1

being used here and that has been changing over the last few days is offers dash Tesla.com.

1:09.3

And now you're able here to pre-order some yet unreleased products,

1:14.7

for example, the Optimus robot, which of course has been sort of heavily featured in the news,

1:21.1

and it will happily allow you to pay for this robot using your credit card.

1:30.2

I went through the checkout process here and using just a fake credit card number.

1:37.8

And it let me go through so it didn't attempt to charge the number because that would

1:42.3

have failed.

1:43.9

It may use those numbers later to maybe resell them, use them on other websites.

1:51.3

That's not really clear what the real endgame here is of this particular scam,

1:56.8

but likely thereafter stealing the credit card data.

...

Transcript will be available on the free plan in 20 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.