4.9 • 696 Ratings
🗓️ 21 July 2025
⏱️ 8 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, July 21st, 2025 edition of the Sands Enanded Storm Centers. |
0:07.7 | Stormcast, my name is Johannes Orich, recording today from Jacksonville, Florida. |
0:13.3 | And this episode is brought to you by the Sands.edu Master's Degree program in information security engineering. |
0:21.7 | The top news today is a new actively exploited SharePoint vulnerability. |
0:26.1 | Microsoft published a special bulletin over the weekend to alert of this vulnerability, |
0:30.3 | but has not yet released a patch. |
0:33.9 | Microsoft's advice at this point is twofold. |
0:39.8 | First of all, deploy Antimalver on your SharePoint server. If you're unable to do so, block access to the SharePoint server, |
0:45.3 | basically take down your SharePoint site. Need of workaround is great. At this point, |
0:51.4 | the attackers exploiting this vulnerability have been deploying web shells. |
0:56.6 | Webshells are the preferred payload, of course, for exploits like this, |
1:00.8 | and Microsoft's anti-malware tools will detect web shells currently deployed by the group |
1:06.7 | attacking vulnerable SharePoint servers. |
1:09.4 | But it is likely only a matter of time for the web shells to emerge that will bypass current detection rules. |
1:17.7 | If you are operating a SharePoint server that is currently exposed to the internet, assume compromise. |
1:24.2 | There is no patch. |
1:25.5 | The vulnerability does not appear to be linked to a particular configuration. |
1:29.4 | Any currently deployed SharePoint server should be considered vulnerable, |
1:33.4 | and given the widespread exploitation of the vulnerability, should be considered compromise. |
1:40.4 | The exploit targets the toolpane.aspx script. |
1:51.0 | First evidence of the vulnerability was made public by researchers with Code White last week. But initially, no proof of concept, exploit or additional details were released. |
1:57.0 | The new vulnerability is a variant of an older vulnerability patch that this July is part |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.