meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 25 March 2026

⏱️ 12 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, March 25th, 2006 edition of the Sands Internet Storm Center's Stormcast.

0:11.9

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:16.9

And this episode is brought you by the Sands.edu bachelor's degree program in applied cyber security.

0:24.3

Well, in diaries today, just one quick diary about detecting IPKVMs.

0:29.1

I've spoken and written about these IPKVMs a couple times in the past.

0:34.1

This was a little bit inspired by some news coverage that the North Koreans that are getting hired here in the U.S. as IT help are often using IPKDMs to then connect the laptops that these companies are sending to U.S. addresses.

0:52.5

So they're using it basically as a remote access tool. And one of the

0:57.5

reasons they're using IPKBMs is that you don't have to install any software, which of course

1:01.6

makes them a bit more difficult to detect. So I looked at some of the detection options with

1:08.5

USB, in particular the Saipid nano-KBM that I tested, has a USB device that's outright called Cypeat Nano-KVM.

1:18.6

For the Pi-KVM, that's the other device I tested. It's a tiny little bit more difficult in the sense that the USB devices are a little bit more

1:29.6

generic in their strings. However, there's also an HTML interface that emulates a monitor,

1:35.5

and monitors are sending extended display identification data, and that lists as identifier and

1:42.4

model name Pi KVM for the Pi KVM.

1:46.2

Now, of course, attackers can adjust it,

1:48.7

but there's certainly something that you may want to look for.

1:52.4

For the Pi KVM, actually, I believe there's a simple configuration file

1:56.4

where you can adjust some of these strings.

2:00.3

And next we do have a little bit of lengthy story, a supply chain story in part.

2:06.2

It's a long story because I've been neglecting some of these supply chain stories lately.

2:11.6

Well, I'm kind of a bit bored of them, to be honest.

2:14.4

You know, there's sort of one NPM, Pi Pi, GitHub repo that gets compromised after the other.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.