meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday, November 11th, 2025: 3CX Related Scans; Watchguard Default Password;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 11 November 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary


It isn t always defaults: Scans for 3CX Usernames
Our honeypots detected scans for usernames that may be related to 3CX business phone systems
https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464
Watchguard Default Password Controversy
A CVE number was assigned to a default password commonly used in Watchguard products. This was a documented username and password that was recently removed in a firmware upgrade.
https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt
https://nvd.nist.gov/vuln/detail/CVE-2025-59396
JavaScript expr-eval Vulnerability
The JavaScript expr-eval library was vulnerable to a code execution issue.
https://www.kb.cert.org/vuls/id/263614

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, November 11th,

0:07.7

2025 edition of the Sands Internet Storm Center's Stormcast.

0:13.1

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:18.1

And this episode is brought you by the sands.edu master's degree program in

0:22.8

information security engineering. Today's diary is about an odd username that I spotted in our

0:29.7

Honeypod logs. The username is FTP underscore 3CX. Now, the 3CX part likely refers to the maker of business phone systems 3CX.

0:41.1

A couple of years ago, they sort of went through the news for being the victim of a big supply chain attack.

0:47.7

But what we are seeing here is likely unrelated.

0:50.8

I did, of course, do a quick search trying to figure out, is this some kind of

0:55.1

default username, maybe going with a default password? Doesn't look like it. And actually,

1:01.1

3CX, their product does not really come with an FTP server. And our Honeypot actually is looking

1:07.7

for Telnet and ZH credentials.

1:13.3

So we're actually not emulating FTP.

1:20.4

I believe what's happening here is that if you're using these business phone systems from 3CX,

1:24.9

one of the options you have to create backups is FTP.

1:30.8

And they're talking the documentation about setting up an FTP server that will receive these backups. So again, the product itself doesn't come with an FTP server. It's something

1:36.9

that you're setting up separately. And they're offering a couple popular sort of FTP server options here and walking you through how to set them up correctly.

1:47.3

But there are a couple issues here.

1:49.3

First of all, that the username, well, people are likely going to use a username related to the product.

1:55.9

There is a comment here to the diary by Stephen who says, well, it's just human nature to use names like

2:01.8

Stephen is using, for example, VIM,

2:04.7

like VIM user, VIM backup and such.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.