SANS Stormcast Monday, September 15th, 2025: More Archives; Salesforce Attacks; White Cobra; BSides Augusta
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 September 2025
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Monday, September 15th, |
| 0:07.9 | 2000-25 edition of the Sands and under the Storm centers, Stormcast. |
| 0:12.6 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.6 | And this episode is brought you by the sands.edu undergraduate certificate program in applied |
| 0:23.6 | cyber security. Did he this weekend published a brief post just confirming some of the scans |
| 0:32.9 | that I've observed for archives and also filling in a couple of other archive types that are being searched for. |
| 0:39.7 | Just a quick recap, this is all about our web honeypots. |
| 0:44.1 | What we are seeing is, or the last few months at least, an increase in scans for dot-sip |
| 0:50.2 | and similar archive files, often pointing that attackers are looking, for example, to retrieve |
| 0:57.7 | backups or such of configuration files that the system administrators may have left in the document |
| 1:06.2 | route. |
| 1:07.1 | Well, in addition to SIP files, Didi also saw dotRar, 7CGC and TAR files being looked for, |
| 1:15.8 | and the file names being, well, backup mostly, but we have also seen a couple of other |
| 1:22.3 | file names, so backup.back, backup.jsH, various files that basically point to the attacker, |
| 1:29.3 | hoping that careless administrators left these backup files behind. |
| 1:34.8 | And of course, they often contain credentials and other goodies. |
| 1:37.9 | So that's probably what they're ultimately after. |
| 1:42.4 | And on Friday, the FBI released another one of its flash alerts focusing on particular |
| 1:48.1 | threat actors. |
| 1:49.0 | There are actually two distinct threat actors that this latest flash alert does focus on both |
| 1:55.7 | Salesforce related. |
| 1:58.0 | The first one is just sort of your classic Salesforce, social engineering and |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

