meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, September 17th, 2025: Phishing Resistants; More npm Attacks; ChatGPT MCP abuse

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 17 September 2025

⏱️ 9 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, September 17th, 2025: Phishing Resistants; More npm Attacks; ChatGPT MCP abuse

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, September 17, 2025 edition of the Sands and then at Storm Center's StormCast.

0:12.6

My name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:17.6

And this episode is brought to you by the Sands.edu graduate certificate program in cyber security engineering.

0:26.2

Well, we have today a little bit of different diary, not so far our usual deep technical diary, but something a little bit lighter from a technical point of view, but still very, very important.

0:37.7

And that's the idea of fishing-resistant authentication. A lot of the fishing advice given

0:44.4

these days doesn't really sort of consider that really well. And authentication is very focused

0:49.9

on multi-factor authentication, which is a good thing, but it does often not protect against

0:56.7

fishing. So the idea of fishing-resistant authentication is that the user is no longer in charge

1:04.9

what credentials to provide to a particular website. Whenever you have any scheme where the user decides what credentials

1:12.4

to provide, the user could be fooled into providing those credentials to the wrong websites,

1:18.3

and then you have tools like Evil EngineX and such that allow these machine-the-middle attacks

1:24.3

that will take those credentials, retrieve a session ID from the application

1:29.3

the user is attempting to connect to, and with that the attacker is authenticated. So that has to be

1:36.3

avoided. You must remove the ability from the user to provide the credentials to the wrong website.

1:44.1

An initial start, and that's probably the simplest way to get started, but far from perfect,

1:49.2

is a password manager.

1:51.8

Password managers tend to be pretty good in setting up the right credentials for the right

1:57.9

websites.

1:58.4

They have been born abilities in the past and password managers,

2:01.5

but for the most part, they get that right.

2:03.9

They get it better, typically, than a user would.

2:07.2

The ultimate fix is really something like certificates,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.