4.9 • 696 Ratings
🗓️ 13 March 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, March 13th, 2025 edition of the Sands Internet Storm Center's Stormcast. |
0:09.7 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:14.8 | One more ability that's just not going away is Log 4J. |
0:19.5 | The latest example are some scans that I observed today |
0:24.0 | against the VMware Hyper Cloud extension or HCX API. |
0:30.2 | This is a Rest API, and at first I thought it was just a brute force attempt I saw because the end point that the request was directed at, well, was used for login. |
0:44.2 | It's the session and you just post username and password to it, and you'll get back a session key that's then being used as a bearer token. |
0:53.5 | However, looking at the payload closer, |
0:56.0 | well, the username was actually a log for J payload. This makes perfect sense, sort of in hindsight, |
1:02.8 | that an attacker would use a username to inject a log for J payload, because, well, that's the part |
1:08.9 | that's usually logged from a request like this. |
1:12.0 | And interestingly, the IP that was going after these VMware systems also went after a couple |
1:18.6 | other login pages, like some Cisco login pages and others that I yet have to identify. |
1:24.7 | They're sort of just generic, like some just login. |
1:28.7 | So could be various applications that are being attacked here. |
1:33.7 | And then we got a little bit patched Tuesday cleanup. |
1:36.5 | First of all, the Apple update released yesterday |
1:40.2 | that fixed the surrogate vulnerability in macOS and iOS. |
1:46.2 | Apparently after applying this update, some users reported that Apple Intelligence |
1:52.0 | is being re-enabled. |
1:54.0 | If they had it disabled first, that's Apple's artificial intelligence feature that typically is enabled by default, but you are able to disable it. |
2:05.2 | Well, in Europe, I don't think it's available, so no issue with Europe here. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.