meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, November 6th, 2025: Domain API Update; Teams Spoofing; VShell Report

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 6 November 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary


Updates to Domainname API
Some updates to our domainname API will make it more flexible and make it easier and faster to get the complete dataset.
https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452
Microsoft Teams Impersonation and Spoofing Vulnerabilities
Checkpoint released details about recently patched spoofing and impersonation vulnerabilities in Microsoft Teams
https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/
NViso Report: VSHELL
NViso published an amazingly detailed report describing the remote control implant VSHELL. The report includes details about the inner workings of the tool as well as detection ideas.
https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, November 6, 2025 edition of the Sands Internet Storm Centers.

0:11.5

Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:16.7

And this episode is brought you by the Sands.edu Undergraduate Certificate Program in Cybersecurity Fundamentals.

0:25.1

Today I made life some changes to our new domain API. This is an API that basically delivers

0:32.0

newly registered domains for the last day. This particular API had a problem that has been going on for a while

0:40.8

where often pretty much always only returned a partial result. So basically the results were cut off.

0:47.8

Well, fix that two different ways. First of all, if you just want all the domains, all the domain names,

0:53.9

then the easiest solution

0:55.4

is just download a static file that I'm offering now. That file is being updated once an hour

1:01.2

and should download really quickly because, well, it's just static. It doesn't have to be

1:06.1

created on the fly. Also with that, it doesn't run into the problems where you only get a partial result back.

1:13.3

The second option is, if you still want to use the API, you will now have pageination

1:18.0

where you can just download a part of the results. You can also do some filtering for keywords

1:24.6

if you don't really want the entire list.

1:30.7

But really the easiest way is just download the static file and then do whatever filtering you need or so at your end.

1:34.2

That probably will be the simplest, fastest solution for this.

1:39.1

This list also includes our sort of still experimental scoring system where we sort of try to assign

1:47.7

anomaly scores to the domains. If you have any feedback on that, please let me know.

1:54.6

And Checkpoint published an interesting blog post showing some vulnerabilities that Microsoft

1:59.8

recently patched in its teams platform.

2:03.7

One of the ways teams, of course, is often used is for communication internal to a company.

2:10.4

And with that, users tend to have quite a bit of trust in the platform, unlike with email,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.