meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, December 11th, 2025: Possible CVE-2024-9042 variant; react2shell exploits; notepad++ update hijacking; macOS priv escalation

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 11 December 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, December 11th, 2025: Possible CVE-2024-9042 variant; react2shell exploits; notepad++ update hijacking; macOS priv escalation

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, December 11th,

0:07.9

2025 edition of the Sands and then at Storm Center's Stormcast.

0:12.9

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:18.0

And this episode is brought you by the sands.edu master's degree program in

0:22.8

information security engineering. Well, in diaries today, we do have a detect that I associate

0:31.2

with a Kubernetes vulnerability that was patched last year, an OS command injection vulnerability.

0:39.3

This vulnerability was a fairly straightforward OS command injection in the node log query feature.

0:45.3

Wasn't widely exploited in part because at least at a time, this feature was still in beta and wasn't enabled by default.

1:02.0

Also, the user in order to attack this feature must have the privileges to actually query logs. Now, the way the export works was, you just sent essentially data to the logs endpoint,

1:08.0

and the pattern parameter was injectable.

1:12.0

Now, the OS command injection, there are a couple different ways how to often do that with

1:16.0

like backtakes or pipes or ampersand.

1:19.2

In this case, the attack worked by enclosing the operating system commands in parentheses,

1:25.7

leading with a dollar simple.

1:28.0

So that very common shell extrapolation that is often used for these types of attacks.

1:35.3

Well, today I was actually looking for some React exploits.

1:40.8

And while sort of going to my logs, I found this other request that, well,

1:47.8

reminded me a little bit of this particular Kubernetes vulnerability.

1:52.5

So I wonder if it's related.

1:54.9

However, in this case, the OS command injection is not a command line parameter.

1:59.9

Instead, it's part of the URL.

2:03.1

But it still uses that same dollar parentheses pattern.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.