meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 15 December 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, December 15th, 2025 edition of the Sands Internet Storm Center's Stormcast.

0:12.4

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.0

And this episode is brought you by the Sands.edu undergraduate certificate program in applied cyber security.

0:25.7

Well, this Monday, we have a number of diaries to talk about. The first one comes from Xavier,

0:30.9

and as typical for Xavier is of interest to anybody reverse analyzing Malver.

0:37.0

Xavier is taking a closer look at DLLs.

0:39.7

Now DLs, libraries, of course, in Windows are loaded by software in order to provide additional

0:46.6

functionality.

0:48.5

As any kind of library, of course, there are certain features that are being exposed by the

0:53.2

library, but one thing that's often overlooked here is the entry point. And what's happening here

1:00.1

is that a developer can define an entry point that's being executed as the library is being

1:08.3

loaded. There are a couple different options, how it can be executed,

1:12.1

and XIV is explaining this.

1:14.0

The reason is important for Malar Analysis

1:15.8

is that you may see a library being loaded,

1:19.9

a DLL being loaded,

1:21.1

but then actually no function in that DL is being ever executed.

1:26.5

Well, then you have to take a look at the entry

1:28.9

point to see if it contains any code of interest because that was executed just as DL was

1:35.9

loaded without any specific function actually being called.

1:40.8

And the next diary comes from Brad.

1:43.1

Brad wrote about, well, two particular examples of a recent

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.