meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, December 17th, 2025: Beyond RC4; Forticloud SSO Vuln Exploited; FortiGate SSO Exploited;

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 17 December 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, December 17th, 2025: Beyond RC4; Forticloud SSO Vuln Exploited; FortiGate SSO Exploited;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, December 17th, 2025 edition of the Sands Internet Storm Centers

0:11.1

Stormcast. My name is Johannes Ulrich, recording today from Jacksonville, Florida. And this episode

0:17.6

is brought you by the Sands.edu graduate certificate program in cybersecurity leadership.

0:24.1

I want to start today's podcast, not sort of with breaking news, but with an issue that has come up beginning of the month and is something that you probably should address early next year.

0:37.4

So now is the time kind of to get ready and get organized to get this worked out.

0:41.6

And that's Microsoft discontinuing RC4 for all the occasion.

0:47.6

Hopefully for your organization, this will be really a non-event.

0:51.6

The last version of Windows that did require R-S4 was Windows Server 2003, if I

0:59.3

remember correctly, so hopefully don't have 20-plus year-old systems around, but we all know

1:05.6

it's easier set than done, and yes, sometimes these legacy systems are hanging around.

1:12.2

So what Microsoft did in order to support this transition is that they came up with an

1:18.8

extensive blog, a website here, Beyond RC4 for Windows authentication, that goes over some

1:26.4

of the steps that you can take in order to make sure

1:28.9

that you won't be affected once RC4 will at least by default be disabled for authentication

1:35.5

with Active Directory. Now that turnover will be mid next year, so again, you still have some time.

1:42.8

And what they did now to get ready for it was to

1:45.9

enable additional logging in the security events that basically log what authentication

1:51.5

mechanisms are used and what are available. If you do have one of the newers like ES and such

1:59.5

available and you still use RC4, well, in this case,

2:04.6

it may just be as easy as changing the particular user's password, which again may not necessarily

2:09.7

be easy. They also do provide PowerShell scripts to search your logs for any accounts that may

2:16.9

need to be updated

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.