meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, November 20th, 2025: Unicode Issues; FortiWeb More Vulns; DLink DIR-878 Vuln; Operation WrtHug and ASUS Routers

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 20 November 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary


Unicode: It is more than funny domain names.
Unicode can cause a number of issues due to odd features like variance selectors and text direction issues.
https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472
FortiWeb Multiple OS command injection in API and CLI
A second silently patched vulnerability in FortiWeb is already being exploited in the wild.
https://fortiguard.fortinet.com/psirt/FG-IR-25-513
DLink DIR-878 Vulnerability
DLink disclosed four different vulnerabilities in its popular DIR-878 router. The router is end-of-life and DLink will not release patches
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475
Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router
A new report, Operation WrtHug, has uncovered a massive, coordinated effort that has compromised thousands of ASUS routers worldwide.
https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, November 20th,

0:07.7

20th, 2025 edition of the Sands Inlet Storm Center's Stormcast.

0:12.3

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.1

And this episode is brought you by the sands.edu undergraduate certificate program in Applied Cybersecurity.

0:24.9

Today's diary was inspired by the classwarm malware that we had a couple weeks ago.

0:31.0

This was this set of digital studio code extensions that injected malware. and the malware was sort of invisible

0:40.9

because it used these Unicode variance selectors, which is one of those features that people

0:46.6

aren't really aware of that it even exists in Unicode. And then I wanted to summarize some of these

0:53.1

often overlooked security issues when it comes to Unicode. And then I wanted to summarize some of these sort of often overlooked security issues

0:55.4

may come to Unicode, people usually focus more on things like, lookalike domain names, which

1:02.8

personally I actually don't really consider such a big deal. Many browsers, like in particular,

1:07.3

Chrome, is pretty good about not displaying many of these domain names,

1:14.2

but instead we also have the same issue in applications.

1:18.2

We do have some character conversions that can cause issues like cross-ed scripting and SQL injection,

1:24.8

and then, yeah, variance selectors that may appear to display a different

1:31.1

text than is then actually being interpreted by your system. Same with left to right versus right

1:37.8

to left text directions that can also cause issues with visual code reviews.

1:46.1

So just want to summarize this quickly,

1:47.7

there isn't really that much to it.

1:52.6

But if you have any other ideas about important things with Unicode,

1:53.2

let me know.

1:56.4

I'm thinking about doing at least one more follow-up on this with regular expressions and Unicode,

...

Transcript will be available on the free plan in 5 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.