meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packdets; Android Update; Long Game Malicious Browser Ext.

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 2 December 2025

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packdets; Android Update; Long Game Malicious Browser Ext.

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, December 2nd, 2025 edition of the Sands Internet Storm Centers.

0:11.8

Stormcast, my name is Johannes Ulrich, recording today from Dallas, Texas.

0:17.6

And this episode is brought you by the Sands.edu, graduate certificate program in cybersecurity leadership.

0:25.4

Well, today's diary is yet another contribution by our undergraduate interns.

0:31.6

This time James Whitworth is talking about analyzing tool shell payloads.

0:36.9

This is the SharePoint vulnerability that came out a month or two months ago

0:41.8

and has been quite busy since then.

0:44.7

There are still plenty of scans for this vulnerability.

0:48.8

And James is explaining a little bit how to analyze the payloads

0:53.3

that you can extract from packet captures.

0:56.9

James is going over all the details here, how to extract the required PCAP files from SEAC,

1:04.9

and then how to get the payloads from those PCAP files,

1:09.4

and then later analyzing the deserilization payloads from

1:13.9

these extracts. There are a couple interesting newer exploits or variations of this exploit

1:22.9

that James found, for example, one that actually delivers a nucleus scanner template,

1:30.9

and then a second one that includes encoded power shell commands,

1:35.5

and of course James will show how to decode these power shell commands

1:40.9

and get to the bottom of what this particular payload is trying to accomplish.

1:45.9

Very nice technical deep dive into the analysis of this vulnerability and hopefully something that can be used by others

1:53.4

in order to discover what's going on currently with this tool shell vulnerability.

1:59.6

And Google today announced its security update for Android for

2:04.0

December 2025. This update as usual fixes a large number of different vulnerabilities. Noteworthy

...

Transcript will be available on the free plan in 17 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.