SANS Stormcast Thursday, September 25th, 2025: Hikvision Exploits; Cisco Patches; Sonicawall Anit-Rootkit Patch; Windows 10 Support
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 September 2025
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, September 25th, 2025 edition of the Sands International |
| 0:10.8 | Storm Centers, Stormcast. |
| 0:12.8 | My name is Johannes Ulrich, recording today from Las Vegas, Nevada. |
| 0:18.9 | And this episode is brought you by the sands.edu credit certificate program in |
| 0:23.5 | cybersecurity engineering. Today I wrote up a diary about some recent attacks that we have seen |
| 0:29.8 | against Hickvision camera systems. These usually target DVRs, network connected video recorders |
| 0:37.1 | that various analog cameras connect to. |
| 0:40.8 | You have written well as early as back in 2014 about vulnerabilities in these systems. |
| 0:47.2 | This latest rash of exploit attempts that I've seen, I would probably qualify it more as |
| 0:53.7 | a brute force attempt. |
| 0:55.6 | They're using the username admin and the password 1-1. So not even 1-2, 3, 4, 5, 6, |
| 1:02.5 | which tends to be the default password for many of these equation systems, at least |
| 1:08.6 | the older ones. One of the problems with these systems is that |
| 1:12.4 | they often don't come with a full keyboard, but you basically use a mouse and an on-screen |
| 1:18.4 | keyboard that usually defaults to a numeric keypad in order to change your password. Haven't looked |
| 1:24.9 | at more recent devices and what changes have been made, it's usually |
| 1:29.0 | easier to change the password via the web application, but in order to get to that point, |
| 1:34.8 | you first have to set a password using that on-screen keyboard. Anyway, if you have a Hakevision |
| 1:41.6 | system still around, make sure you secure and patch it properly. |
| 1:45.8 | There is a possibility that this also attempts to exploit some older specific vulnerabilities. |
| 1:51.8 | But at this point, I really think it's just essentially proof-forcing, |
| 1:56.2 | which also is a little bit simpler here because the username and password is just encoded in Base 64 |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

