PLAY PODCASTS
SANS Internet Storm Center's Daily Network Security News Podcast

SANS Internet Storm Center's Daily Network Security News Podcast

1,099 episodes — Page 21 of 22

Network Security News Summary for Thursday July 7th, 2022

Max SANs; Fortinet July Updates; Ouch Phishing; Quantum Safe Ciphers; Apple Lockdown How Many SANs are Insane https://isc.sans.edu/forums/diary/How+Many+SANs+are+Insane/28820/ Fortinet July Updates https://fortiguard.fortinet.com/psirt?date=07-2022 Phishing Attacks Getting Trickier https://www.sans.org/newsletters/ouch/phishing-attacks-getting-trickier Quantum Safe Ciphers https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4 Apple Proposes Lockdown Mode https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/ keywords: apple; lockdown; ciphers; quantum safe; phsihing; ouch; fortinet; sans;

Jul 6, 20227 min

Network Security News Summary for Wednesday July 6th, 2022

EternalBlue Retrospective; OpenSSL Update; Keystroke Logging NPM Packages EternalBlue 5 Years After WannaCry and NotPetya https://isc.sans.edu/forums/diary/EternalBlue+5+years+after+WannaCry+and+NotPetya/28816/ OpenSSL Patches Two Vulnerabilities https://www.openssl.org/news/secadv/20220705.txt Iconburst NPM Software Supply Chain Attack https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites keywords: iconburst; npm; openssl; eternalblue; wannacry; notpetya

Jul 5, 20226 min

Network Security News Summary for Tuesday July 5th, 2022

7-Zip and MotW; Session Manager Backdoor; Chrome 0Day Patch 7Zip Mark of the Web For Office Files https://isc.sans.edu/forums/diary/7Zip+MoW+For+Office+files/28812/ SessionManager Backdoor Seen with IIS https://securelist.com/the-sessionmanager-iis-backdoor/106868/ Googe Chrome Stable Channel Update https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html keywords: google; chrome; 0day; sessionmanager; iis; 7zip; motw; office

Jul 4, 20225 min

Network Security News Summary for Friday July 1st, 2022

Cobalt Strike Domain Suspension; ManageEngine Vuln Details; CWE Top 25 Update Case Study: Cobalt Strike Server Lives on After its Domain is Suspended https://isc.sans.edu/forums/diary/Case+Study+Cobalt+Strike+Server+Lives+on+After+Its+Domain+Is+Suspended/28804/ CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus https://www.horizon3.ai/red-team-blog-cve-2022-28219/ CWE Top 25 Update https://cwe.mitre.org/top25/archive/2022/2022_cwe_top25.html#analysis keywords: cwe; cve; xxe; rce; cobalt strike; quakbot; manageengine

Jun 30, 20226 min

Network Security News Summary for Thursday June 30th, 2022

Moving MFA; Managing Human Risk Report; Service Fabric PoC; Zimbra RCE; Deepfake Interviews; Its New Phone Day: Time to Migrate Your MFA https://isc.sans.edu/forums/diary/Its+New+Phone+Day+Time+to+migrate+your+MFA/28800/ Managing Human Risk Security Awareness Report https://go.sans.org/lp-wp-2022-sans-security-awareness-report Microsoft Azure Service Fabric Container Elevation of Privilege Vulnerability https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/#The-Vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30137 Zimbra RCE Vulnerability https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/ FBI Warns of Deep Fakes Beeing Used in Job Interviews https://www.ic3.gov/Media/Y2022/PSA220628 keywords: deepfake; fbi; job interview; zimbra; webmail; service fabric; container; escape; ssa; human risk; moving mfa; mfa

Jun 29, 20226 min

Network Security News Summary for Wednesday June 29th, 2022

HiByMusic Scans; OpenSSL Heap Overflow; ZuoRat; Possible Scans for HiByMusic Devices https://isc.sans.edu/forums/diary/Possible+Scans+for+HiByMusic+Devices/28796/ OpenSSL Heap Overflow https://guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption/ https://github.com/openssl/openssl/issues/18625#issuecomment-1165012549 ZuoRat MalwareHijacking Home Office Routers https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/ keywords: zuorat; openssl; hibymusic; radio.txt

Jun 28, 20225 min

Network Security News Summary for Tuesday June 28th, 2022

Encrypted Client Hello; Jenkins Patches; Instagram Age Verification; CodeSys Vuln Encrypted Client Hello: Anybody Using it Yet? https://isc.sans.edu/forums/diary/Encrypted+Client+Hello+Anybody+Using+it+Yet/28792/ Jenkins Advisory https://www.jenkins.io/security/advisory/2022-06-22/ Instagram Age Verification https://about.fb.com/news/2022/06/new-ways-to-verify-age-on-instagram/ CodeSys V2 Vulnerability https://github.com/ic3sw0rd/Codesys_V2_Vulnerability keywords: codesys; ics; ech; jenkins; tls;

Jun 27, 20226 min

Network Security News Summary for Monday June 27th, 2022

Python GUI Malware; Pasting Malcode; WebView2 Risks; Pretend Ransomware Python Abusing the Windows GUI https://isc.sans.edu/forums/diary/Python+abusing+The+Windows+GUI/28780/ Malicious Code Passed to PowerShell via the Clipboard https://isc.sans.edu/forums/diary/Malicious+Code+Passed+to+PowerShell+via+the+Clipboard/28784/ Attacking With WebView2 Applications https://mrd0x.com/attacking-with-webview2-applications/ Bronze Starlight Ransomware Operations Use Hui Loaders https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader Novel Exploit Detected in Mitel VoIP Appliance https://www.crowdstrike.com/blog/novel-exploit-detected-in-mitel-voip-appliance/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29499 keywords: python; gui; powershell; clipboard; webview2; starlight; ransomware; hui loaders; mitel

Jun 26, 20227 min

Network Security News Summary for Thursday June 23rd, 2022

Coin Stealing Powershell; NSA PS Guidance; MageCart Update; Script Kiddies Hacked; Israeli Air Raid Sirens Hacked; Malicious PowerShell Targeting Cryptocurrency Browser Extensions https://isc.sans.edu/forums/diary/Malicious+PowerShell+Targeting+Cryptocurrency+Browser+Extensions/28772/ Keeping PowerShell: Security Measures to Use and Embrace https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF Client-Side Magecart Attacks Still Around, But More Covert https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert/ Chinese actor takes aim, armed with Nim Language and Bizarro AES https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes/ Israeli Air Raid Sirens Hacked https://twitter.com/Israel_Cyber/status/1538821467785265153 keywords: israel; air raid; siren; hacked; chinese; nim; aes; magecart; powershell; crypto coin;

Jun 22, 20225 min

Network Security News Summary for Wednesday June 22nd, 2022

Domain Age API; OT Vulnerablities; Cloudflare Outage; Acrobat Blocks AV; 7zip MOTW; Experimental New Domain / Domain Age API https://isc.sans.edu/forums/diary/Experimental+New+Domain+Domain+Age+API/28770/ Forescout Vedere Labs Discovers 56 OT Vulnerabilities https://www.forescout.com/resources/ot-icefall-report/ Cloudflare Outage https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/ Does Acrobat Reader Unload Injection of Security Products https://blog.minerva-labs.com/does-acrobat-reader-unload-injection-of-security-products 7-Zip Mark-of-the-Web Support https://www.7-zip.org/history.txt keywords: 7zip; motw; acrobat; pdf; anti-virus; cloudflare; outage; forescout; ot; vulnerabilities; new domain; domain age; api

Jun 22, 20226 min

Network Security News Summary for Tuesday June 21st, 2022

TCP Fast Open Oddities; DFSCoerce NTLM Relay; Windows ARM Update; Safari Exploit; MSIE Remnants; Odd TCP Fast Open Packets https://isc.sans.edu/forums/diary/Odd+TCP+Fast+Open+Packets+Anybody+understands+why/28766/ DFSCoerce NTLM Relay Attack https://github.com/Wh04m1001/DFSCoerce https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429 Windows Emergency Update Fixes Microsoft 365 Issues on ARM Devices https://www.bleepingcomputer.com/news/microsoft/windows-emergency-update-fixes-microsoft-365-issues-on-arm-devices/ Safari Vulnerability Analysis https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html Internet Explorer Remnants Still an Issue https://www.darkreading.com/vulnerabilities-threats/internet-explorer-will-likely-remain-an-attacker-target-for-some-time keywords: tcp; fast open; tfo; ntlm; relay; dfscoerce; ARM; windows; update; safari; vulnerablity; internet explorer; mshtml

Jun 20, 20225 min

Network Security News Summary for Monday June 20th, 2022

Splunk Vulnerability; Matanbuchus Malware; Office 365 Ransomware Critical Vulnerability in Splunk Enterprise Deployment Server Functionality https://isc.sans.edu/forums/diary/Critical+vulnerability+in+Splunk+Enterprises+deployment+server+functionality/28760/ Malspam Pushes Matanbuchus Malware Leads to Cobalt Strike https://isc.sans.edu/forums/diary/Malspam+pushes+Matanbuchus+malware+leads+to+Cobalt+Strike/28752/ Proofpoint Discovers Potentially Dangerous Office 365 Functionality https://www.proofpoint.com/us/blog/cloud-security/proofpoint-discovers-potentially-dangerous-microsoft-office-365-functionality keywords: malspam; malware; matanbuchus; cobalt strike; splunk; sharepoint; ransomware; office 365

Jun 19, 20228 min

Network Security News Summary for Friday June 17th, 2022

Houdini is Back; Drifting Cloud; FreeBSD Wifi Xploit; Csico Email Insecurity; Fastjson RCE Houdini is Back Delivered Through a JavaScript Dropper https://isc.sans.edu/forums/diary/Houdini+is+Back+Delivered+Through+a+JavaScript+Dropper/28746/ Drifting Cloud: Zero-Day Sophos Firewall Exploitation https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/ Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack https://www.zerodayinitiative.com/blog/2022/6/15/cve-2022-23088-exploiting-a-heap-overflow-in-the-freebsd-wi-fi-stack Cisco Email Security Appliance and Cisco Secure Email and Web Manager https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-esa-auth-bypass-66kEcxQD Analyzing the Fastjson "Auto Type Bypass" RCE vulnerability https://jfrog.com/blog/cve-2022-25845-analyzing-the-fastjson-auto-type-bypass-rce-vulnerability/ keywords: houdini; cisco; email; freebsd; wifi; exploit; sophos; firewall; fastjson; rce;

Jun 16, 20225 min

Network Security News Summary for Thursday June 16th, 2022

Terraforming Honeypots; Zimbra Vulnerability; Cloud Middleware; Windows NFS Details; Citrix ADC; Nexans Switches Terraforming Honeypots: Using IaaC & Cloud to Attract Attacks https://isc.sans.edu/forums/diary/Terraforming+Honeypots+Installing+DShield+Sensors+in+the+Cloud/28748/ Zimbra Email - Stealing Clear=Text Credenitals via Memcache Injection https://blog.sonarsource.com/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/ Cloud Middleware Dataset https://github.com/wiz-sec/cloud-middleware-dataset CVE-2022-26937 Windows Network File System NLM Portmap Stack Buffer Overflow https://www.zerodayinitiative.com/blog/2022/6/7/cve-2022-26937-microsoft-windows-network-file-system-nlm-portmap-stack-buffer-overflow Citrix Application Delivery Management Security Bulletin https://support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512 Hardcoded Backdoor User and Outdated Software Components in Nexans FTTO GigaSwitch https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/ keywords: nexans; citrix; ftto; adm; nfs; windows; cloud; middleware; zimbra; terraform; honeypot; azure; aws

Jun 16, 20225 min

Network Security News Summary for Wednesday June 15th, 2022

Microsoft Patch Tuesday; Adobe Patches; Synlaps Azure Vuln; Hetzbleed Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+June+2022+Patch+Tuesday/28742/ Adobe Patches https://helpx.adobe.com/security/security-bulletin.html SynLapse Vulnerability https://orca.security/resources/blog/synlapse-critical-azure-synapse-analytics-service-vulnerability/ Hertzbleed Attack https://www.hertzbleed.com keywords: adobe; microsoft; follina; synlapse; hertzbleed

Jun 15, 20227 min

Network Security News Summary for Tuesday June 14th, 2022

Decoding Saitama; Travis CI Leaks; Syslogk Rootkit; Mitel Backdoor Translating Saitama's DNS Tunneling https://isc.sans.edu/forums/diary/Translating+Saitamas+DNS+tunneling+messages/28738/ Travis CI Logs Expose Users to Cyber Attacks https://blog.aquasec.com/travis-ci-security Linux Threat Hunting: "Syslogk" a kernel rootkit found under development in the wild https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/ Mitel Desk Phone Backdoor https://blog.syss.com/posts/rooting-mitel-desk-phones-through-the-backdoor/ keywords: mitel; phone; linux; syslogk; rootkit; travis ci; saitama

Jun 14, 20225 min

Network Security News Summary for Monday June 13rd, 2022

Exploit Prediction; PACMAN Attack; Carrier Access Panels; Malicious PyPi; EPSScall: An Exploit Prediction Scoring System App https://isc.sans.edu/forums/diary/EPSScall+An+Exploit+Prediction+Scoring+System+App/28732/ PACMan Attack https://pacmanattack.com https://twitter.com/wdormann/status/1535245913857351680 Carrier LenelS2 HID Mercury access panel vulnerability https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-01 Malicious Python Modules https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer/ keywords: python; keep; request; requests; carrier; mercury; lenels2; pacman; epsscall

Jun 12, 20226 min

Network Security News Summary for Friday June 10th, 2022

QBot/TA570 Follina Attempt; Facebook Phishing; Zyxel Adv; Fijuisu Centricstor Vuln; Meeting Owl Vuln TA570 QBot attempts to exploit CVE-2022-30190 (Follina) https://isc.sans.edu/forums/diary/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt/28728/ Analysis of a Facebook Phishing Campaign https://pixmsecurity.com/blog/blog/phishing-tactics-how-a-threat-actor-stole-1m-credentials-in-4-months/ Zyxel Security Advisory https://www.zyxel.com/support/Zyxel-security-advisory-for-CRLF-injection-vulnerability-in-some-legacy-firewalls.shtml Fujitsu Centricstor Vulnerability https://research.nccgroup.com/2022/05/27/technical-advisory-fujitsu-centricstor-control-center-v8-1-unauthenticated-command-injection/ Meeting Owl Vulnerablities https://www.modzero.com/static/meetingowl/Meeting_Owl_Pro_Security_Disclosure_Report_RELEASE.pdf keywords: meetig owl; fujisu; centricstor; zyxel; facebook; phishing; qbot; follina; ta570

Jun 9, 20228 min

Network Security News Summary for Thursday June 9th, 2022

SANS RSA Panel; More Confluence; Fake CCleaner; Vebatim USB Drive Weakness SANS RSA Panel (sorry, video no longer available) Atlassian Confluence Attacks https://isc.sans.edu/forums/diary/Atlassian+Confluence+Exploits+Seen+By+Our+Honeypots+CVE202226134/28722/ Fake CClenaer Malvertisements https://blog.avast.com/fakecrack-campaign Weakness in Verbatim Keypad Secure USB Drive https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/ keywords: verbatim; keypad; secure; usb; drive; ccleaner; fake; rsa; panel; atlassian; confluence

Jun 9, 20225 min

Network Security News Summary for Thursday June 9th, 2022

DogWalk Windows 0-Day; QBot uses Follina; Deadbolt Update; Android Patches The Trouble With Microsoft's Troubleshooters https://irsl.medium.com/the-trouble-with-microsofts-troubleshooters-6e32fc80b8bd QBot Uses Follina https://twitter.com/threatinsight/status/1534227444915482625 Deadbolt Ransomware https://www.trendmicro.com/en_us/research/22/f/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-mult.html Google Android Updates https://source.android.com/security/bulletin/2022-06-01?hl=en keywords: dogwalk; windows; qbot; follina; deadbolt; android;

Jun 8, 20225 min

Network Security News Summary for Tuesday June 7th, 2022

Follina Analysis Helper; Obscured Phishing; Unpatched Horde RCE; Passwordstate Looses Priv. Key MS-MSDT RTF Maldocs Analysis oledump Plugins https://isc.sans.edu/forums/diary/msmsdt+RTF+Maldoc+Analysis+oledump+Plugins/28718/ Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/ Unpatched Horde Webmail Bug https://blog.sonarsource.com/horde-webmail-rce-via-email/ Clickstudio (Passwordstate) Code Signing Cert Used by Follina Malware https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/ keywords: clickstudio; passwordstate; horde; webmail; phishing; ms-msdt; rtf; maldocs; oledump; follina;

Jun 7, 20226 min

Network Security News Summary for Monday June 6th, 2022

Simple Analysis Evasion; Confluence Exploit; Gitlab Patch; u-boot Vuln; Unisoc Vuln Sandbox Evasion... With Just a Filename! https://isc.sans.edu/forums/diary/Sandbox+Evasion+With+Just+a+Filename/28708/ Atlassian Exploit Released https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/ GitLab Critical Security Release https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/ U-Boot Vulnerablities https://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/ Unisoc Baseband Chip Vulnerability https://research.checkpoint.com/2022/vulnerability-within-the-unisoc-baseband/ keywords: sandbox; filename, gitlab; uboot; unisoc; atlasian; confluence

Jun 5, 20225 min

Network Security News Summary for Friday June 3rd, 2022

Intro to RECmd.exe; Confluence 0-Day; JetPort Backdoor; Elasticsearch Wiper; Quick Answers in Incident Response RECmd.exe https://isc.sans.edu/forums/diary/Quick+Answers+in+Incident+Response+RECmdexe/28706/ Zero-Day Exploitation of Atlassian Confluence https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/ https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html Korenix Technology JetPort Backdoor https://sec-consult.com/vulnerability-lab/advisory/backdoor-account-in-korenix-technology-jetport-series/ Elasticsearch Data Wiped https://www.secureworks.com/blog/unsecured-elasticsearch-data-replaced-with-ransom-note keywords: elasticsearch; korenix; jetport; zero-day; atlassian; confluence; redmd.exe

Jun 2, 20226 min

Network Security News Summary for Friday June 3rd, 2022

Better HTML Phishing; Follina Update; Windows Search Vuln; WhatsApp Takeover; Weak RSA Keys HTML Phishing Attachments - Now With Anti-Analysis Features https://isc.sans.edu/forums/diary/HTML+phishing+attachments+now+with+antianalysis+features/28702/ Unofficial Patch for CVE-2022-30190 (Follina) https://blog.0patch.com/2022/06/free-micropatches-for-follina-microsoft.html Windows Search Vulnerability https://www.bleepingcomputer.com/news/security/new-windows-search-zero-day-added-to-microsoft-protocol-nightmare/ Call Forwarding Used to Compromise WhatsApp Accounts https://www.linkedin.com/posts/fb1h2s_beware-here-is-how-whatsapp-accounts-are-activity-6934386561048264704-NnFf/?utm_source=linkedin_share&utm_medium=member_desktop_web Badkeys in Fuji Xerox and Canon Printers https://fermatattack.secvuln.info keywords: badkeys; fuji; xeros; canon; rsa; fermat; whatsapp; windows; search; follina; phishing; html; obfuscation

Jun 2, 20225 min

Network Security News Summary for Wednesday June 1st, 2022

Follina Update; OAS Platform Vuln; Exposed MySQL; Follina Update https://isc.sans.edu/forums/diary/First+Exploitation+of+Follina+Seen+in+the+Wild/28698/ https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme+CVE202230190/28694/ Open Automation Software Platform Vulnerability https://blog.talosintelligence.com/2022/05/vuln-spotlight-open-automation-platform.html Over 3.6 million MySQL servers found exposed on the Internet https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/ keywords: follina; ms-msdt; oas; open automation software; mysql

May 31, 20225 min

Network Security News Summary for Tuesday May 31st, 2022

Microsoft Office MS-MSDT URL Scheme Exploit (0-Day) #follina New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme/28694/ keywords: microsoft; ms-msdt; debug tool; follina; office

May 30, 20227 min

Network Security News Summary for Friday May 27th, 2022

Huge Signed PE Files; CVE-2022-22972 PoC; BMC Vuln.; Trend Micro vs. MSFT Patch; Nate Street @sans_edu Huge Signed PE Files https://isc.sans.edu/forums/diary/Huge+Signed+PE+File/28686/ VMWare Authentication Bypass PoC https://www.horizon3.ai/vmware-authentication-bypass-vulnerability-cve-2022-22972-technical-deep-dive/ Quanta Server BMC Vulnerability https://eclypsium.com/2022/05/26/quanta-servers-still-vulnerable-to-pantsdown/ Windows 11 and Server 2022 Update Prevent Trend Micro Ransomware Protection https://success.trendmicro.com/dcx/s/solution/000291066?language=en_US Nate Street: Advancing SIEM Log Management Strategies through Vendor-Agnostic Measurement https://www.sans.edu/cyber-research/38685/ keywords: siem; sans_edu; windows 11; server 2022; quanta; bmc; huge file; vmware

May 26, 202215 min

Network Security News Summary for Thursday May 26th, 2022

nmap resolve all; Unethical Research; Heroku GibHub Update; Tails Vuln; Chrome Bugs Using NMAP to Assess Hosts in Load Balanced Clusters https://isc.sans.edu/forums/diary/Using+NMAP+to+Assess+Hosts+in+Load+Balanced+Clusters/28682/ Attacker Modifying Libraries Claims "Research" https://www.bleepingcomputer.com/news/security/hacker-says-hijacking-libraries-stealing-aws-keys-was-ethical-research/ Heroku GitHub Integration Re-Enabled Again https://blog.heroku.com/github-integration-update Serious security vulnerablity in Tails 5.0 https://tails.boum.org/security/prototype_pollution/index.en.html Google Chrome Update https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html keywords: google; chrome; tail; firefox; github; heroku; nmap

May 26, 20225 min

Network Security News Summary for Wednesday May 25th, 2022

Python/PHP Library Backdoor; Zoom Patches; VMWare Exploit; Zyxel Patches ctx Python Library Updated with "Extra" Features https://isc.sans.edu/forums/diary/ctx+Python+Library+Updated+with+Extra+Features/28678/ Zoom Updates https://explore.zoom.us/en/trust/security/security-bulletin/ VMWare Exploit About to Be Released https://twitter.com/Horizon3Attack/status/1528935531333177344 Zyxel Firewalls, AP Controllers, APs Patch https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml keywords: zyxel; vmware; horizon3; zoom; ctx; php; python; pypi;

May 24, 20225 min

Network Security News Summary for Tuesday May 24th, 2022

jQuery-File-Upload Scans; Oracle OOB Patch; NPM Hijack Detection; Account Pre-Hijacking Attacker Scanning for jQuery-File-Upload https://isc.sans.edu/forums/diary/Attacker+Scanning+for+jQueryFileUpload/28674/ Oracle Security Alert Advisory - CVE-2022-21500 https://www.oracle.com/security-alerts/alert-cve-2022-21500.html How to find NPM dependencies vulnerable to account hijacking https://www.theregister.com/2022/05/23/npm_dependencies_vulnerable/ Pre-hijacked accounts https://arxiv.org/pdf/2205.10174.pdf keywords: jquery; hijacking; file upload; oracle; npm

May 24, 20225 min

Network Security News Summary for Monday May 23rd, 2022

Zip bomb AV Evasion; Cisco Redis Patch; pwn2own Results; Cobalt Strike via PyPi; Netgear No Patch; A "Zip Bomb" to Bypass Security Controls & Sandboxes https://isc.sans.edu/forums/diary/A+Zip+Bomb+to+Bypass+Security+Controls+Sandboxes/28670/ Cisco IOS XR Software Health Check Open Port Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-redis-ABJyE5xK pwn2own Vancouver 2022 Results https://www.zerodayinitiative.com/blog/2022/5/18/pwn2own-vancouver-2022-the-results#three Malicious PyPi Packages Drop Cobalt Strike https://blog.sonatype.com/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux Security Advisory for BR200, BR500 and PSV-2021-0286 https://kb.netgear.com/000064712/Security-Advisory-for-Multiple-Security-Vulnerabilities-on-BR200-and-BR500-PSV-2021-0286 keywords: netgear; br200; br500; pypi; cobalt strike; pwn2own; zipbomb; cisco

May 23, 20226 min

Network Security News Summary for Friday May 20th, 2022

Bumblebee via TransferXL; MSFT OOB Update; SonicWall SMA1000; QNAP Deadbolt; DOJ Policy Update; Exposed Kubernetes Bumblebee Malware from TransferXL URLs https://isc.sans.edu/forums/diary/Bumblebee+Malware+from+TransferXL+URLs/28664/ Microsoft Out-of-Band Update fixes Authentication Issues https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#you-might-see-authentication-failures-on-the-server-or-client-for-services Sonicwall Patch for SMA 1000 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0010 QNAP NAS Deadbolt Ransomware https://www.qnap.com/en/security-news/2022/take-immediate-actions-to-secure-qnap-nas-and-update-qts-to-the-latest-available-version 380,000 open Kubernetes API Servers https://www.shadowserver.org/news/over-380-000-open-kubernetes-api-servers/ Doj Annnounces New Polciy for Charging Cases under the Computer Fraud and Abuse Act https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act keywords: Bumblebee; sonicwall; windows; patch; AD; qnap; deadbolt; kubernetes; doj;

May 20, 20226 min

Network Security News Summary for Thursday May 19th, 2022

VMWare Flaws; Tesla BLE Attacks; Credit Card Scraping; MSFT DAP to GDAP Update VMWare Flaws https://core.vmware.com/vmsa-2022-0014-questions-answers-faq https://blog.barracuda.com/2022/05/17/threat-spotlight-attempts-to-exploit-new-vmware-vulnerabilities/ Tesla BLE Proximity Authentication Vulnerable to Relay Attacks https://research.nccgroup.com/2022/05/15/technical-advisory-ble-proximity-authentication-vulnerable-to-relay-attacks/ Credit Card Scraping via Malicious PHP Code https://www.ic3.gov/Media/News/2022/220516.pdf Microsoft updating Delegated Admin Privileges https://docs.microsoft.com/en-gb/partner-center/announcements/2022-may#13 keywords: microsoft; credit card; php; tesla; bluetooth; ble; vmware

May 19, 20226 min

Network Security News Summary for Wednesday May 18th, 2022

Chrome Browser Wallet; SQL Server Attacks; macOS Malware; Spring/Zyxel Exploited Use Your Browser Internal Password Vault... or Not? https://isc.sans.edu/forums/diary/Use+Your+Browser+Internal+Password+Vault+or+Not/28658/ SQL Server Brute Forcing https://twitter.com/MsftSecIntel/status/1526680337216114693 UpdateAgent Adapts Again https://www.jamf.com/blog/updateagent-adapts-again/ Updated Exploited Vulnerabilities https://www.cisa.gov/uscert/ncas/current-activity/2022/05/10/cisa-adds-one-known-exploited-vulnerability-catalog keywords: spring; zyxel; updateagent; macos; sql server; browser; chrome

May 18, 20226 min

Network Security News Summary for Tuesday May 17th, 2022

Apple Updates; Evil Never Sleeps; JS Tracker Keystroke Logging Apple Patches Everything https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28654/ Evil Never Sleeps: When Wireless Malware Stays on After Turning Off iPhones https://arxiv.org/pdf/2205.06114.pdf Third-Party Web Trackers Log What You Type Before Submitting https://homes.esat.kuleuven.be/~asenol/leaky-forms/ keywords: web trackers; javascript; keystroke logging; bluetooth; iphone; uwb; patches; apple

May 17, 20226 min

Network Security News Summary for Monday May 16th, 2022

BIG-IP Review; Sonicwall Patch; Zonealarm Priv Esc Vuln; Taking over npm account From 0-Day to Mirai: 7 days of BIG-IP Exploits https://isc.sans.edu/forums/diary/From+0Day+to+Mirai+7+days+of+BIGIP+Exploits/28644/ Sonicwall Vulnerabilities Patched https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0009 Zonealarm Patch https://www.zonealarm.com/software/extreme-security/release-history Taking over npm account https://thehackerblog.com/zero-days-without-incident-compromising-angular-via-expired-npm-publisher-email-domains-7kZplW4x/ keywords: npm; zonealarm; sonicwall; big-ip; f5; mirai

May 16, 20226 min

Network Security News Summary for Friday May 13rd, 2022

Get-WebRequest Fails; HP BIOS Patch; INTEL BIOS Patch; Zyxel RCE; When Get-WebRequest Fails You https://isc.sans.edu/forums/diary/When+GetWebRequest+Fails+You/28640/ HP PC BIOS Security Updates https://support.hp.com/us-en/document/ish_6184733-6184761-16/hpsbhf03788 INTEL BIOS Advisory https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.html Zyxel RCE Vulnerability https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/ keywords: get-webrequest; bios; hp; intel; zyxel; firewall; rce

May 13, 20224 min

Network Security News Summary for Thursday May 12nd, 2022

ISO Bumblebee Files; Google Drive Malware; Vanity URL Abuse; not so advanced npm attack TA578 Using Thread-Hijacked Emails to Push ISO Files for Bumblebee Malware https://isc.sans.edu/forums/diary/TA578+using+threadhijacked+emails+to+push+ISO+files+for+Bumblebee+malware/28636/ Google Drive Emerges as Top App for Malware Downloads https://www.helpnetsecurity.com/2022/05/11/malicious-pdf-search-engines/ Vanity URL Abuse https://www.varonis.com/blog/url-spoofing npm Supply Chain Attack Turns Out to be Part of Penetration Test https://jfrog.com/blog/npm-supply-chain-attack-targets-german-based-companies/ keywords: npm; vanity; url; google drive; malware; pdf; ta578; iso; bumblebee

May 12, 20225 min

Network Security News Summary for Wednesday May 11st, 2022

Microsoft Patch Tuesday; Adobe Updates; npm foreach; Microsoft May 2022 Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+May+2022+Patch+Tuesday/28632/ Adobe Updates https://helpx.adobe.com/security/security-bulletin.html npm "foreach" package domain takeover https://www.theregister.com/2022/05/10/security_npm_email/ keywords: npm; foreach; domain; email; adobe; microsoft; may; patches

May 11, 20225 min

Network Security News Summary for Tuesday May 10th, 2022

Octopus Backdoor is Back; CVE-2022-1388 (BIG-IP) Exploits; Trend Micro Fix; Azure RCE Vuln; Octopus Backdoor is Back with a New Embedded Obfuscated Bat File https://isc.sans.edu/forums/diary/Octopus+Backdoor+is+Back+with+a+New+Embedded+Obfuscated+Bat+File/28628/#comments CVE-2022-1388 (BIG-IP) Exploits https://twitter.com/sans_isc/status/1523741896707043328 https://github.com/horizon3ai/CVE-2022-1388 Trend Micro False Positive Aftermath https://success.trendmicro.com/dcx/s/solution/000290966?language=en_US Microsoft Azure https://orca.security/resources/blog/azure-synapse-analytics-security-advisory/ https://msrc-blog.microsoft.com/2022/05/09/vulnerability-mitigated-in-the-third-party-data-connector-used-in-azure-synapse-pipelines-and-azure-data-factory-cve-2022-29972/ keywords: orca; msrc; microsoft; azure; synapse; trend micro; big-ip; bigip; f5; octopus; backdoor

May 10, 20225 min

Network Security News Summary for Monday May 9th, 2022

BIG IP Vuln; QNAP Update; Raspberry Robin; rubygems flaw; F5 BIG-IP Unauthenticated RCE Vulnerability (CVE-2022-1388) https://isc.sans.edu/forums/diary/F5+BIGIP+Unauthenticated+RCE+Vulnerability+CVE20221388/28624/ QNAP QVR Update https://www.qnap.com/de-de/security-advisory/qsa-22-07 Raspberry Robin Worm https://redcanary.com/blog/raspberry-robin/ rubygems CVE-2022-29176 explained https://greg.molnar.io/blog/rubygems-cve-2022-29176/ What is the simples malware in the world? https://isc.sans.edu/forums/diary/What+is+the+simplest+malware+in+the+world/28620/ keywords: fork bomb; malware; windows; ruby; gems; raspberry; robin; worm; usb; qnap; big-ip; f5

May 9, 20225 min

Network Security News Summary for Friday May 6th, 2022

Excel to Remcos RAT; FIDO Support; Heroku Breach Password-protected Excel Spreadsheet Pushes Remcos RAT https://isc.sans.edu/forums/diary/Passwordprotected+Excel+spreadsheet+pushes+Remcos+RAT/28616/ Microsoft, Apple, Google Accelated FIDO Standard Implementation https://www.theregister.com/2022/05/05/microsoft-apple-google-fido/ Heroku Admits Breach https://status.heroku.com/incidents/2413 keywords: heroku; microsoft; apple; google; heroku; excel; remcos rat;

May 6, 20225 min

Network Security News Summary for Thursday May 5th, 2022

Windows Last Patched Day; Fake Updates; Malvuln; Cisco Patches; F5 Big IP iControl REST Finding the Real "Last Patched" Day (Interim Version) https://isc.sans.edu/forums/diary/Finding+the+Real+Last+Patched+Day+Interim+Version/28610/ Fake Windows Updates Install Ransomware https://www.bleepingcomputer.com/news/security/fake-windows-10-updates-infect-you-with-magniber-ransomware/ Vulnerablities in Ransomware https://www.malvuln.com Heroku Forces Password Reset https://status.heroku.com/incidents/2413 Cisco Patches Enterprise NFV Infrastructure Software https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9 Big-IP iControl REST Vulnerability https://support.f5.com/csp/article/K23605346 keywords: f5; big-ip; cisco; heroku; malvuln; ransomware; patches; windows; fake updates

May 5, 20225 min

Network Security News Summary for Wednesday May 4th, 2022

Honeypot Updates; NanoSSL Vuln; uClibc DNS Bugs; AV Exploits; Trend Micro Flase Positive #GOSENTINELS Some Honeypot Updates https://isc.sans.edu/forums/diary/Some+Honeypot+Updates/28608/ TLStorm 2 - NanoSSL TLS Library Misuse https://www.armis.com/blog/tlstorm-2-nanossl-tls-library-misuse-leads-to-vulnerabilities-in-common-switches/ Unpatched DNS Bug in uClibc and uClibc-ng Library https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-DNS-bug-in-popular-c-standard-library-putting-iot-at-risk/ Abusing Security Software to Sideload PlugX and ShadowPad https://www.sentinelone.com/labs/moshen-dragons-triad-and-error-approach-abusing-security-software-to-sideload-plugx-and-shadowpad/ Microsoft Edge Update Triggers Trend Micro AV https://success.trendmicro.com/forum/s/question/0D54T00001QDqzgSAD/we-are-getting-this-message-from-every-client-since-several-minutesis-it-a-false-positiv-error-or-do-we-have-a-real-trojaner-problem- keywords: edge; trend micro; microsoft; plugx; shadowpad; dns; queryid; uclibc; tlstorm; nanossl; honeypot

May 4, 20226 min

Network Security News Summary for Tuesday May 3rd, 2022

VSTO Office Files; Gmail SMTP Relay; OpenSSF Package Analysis; M1 Prefetcher Leak Detecting VSTO Office Files with ExifTool https://isc.sans.edu/forums/diary/Detecting+VSTO+Office+Files+With+ExifTool/28604/ The Gmail SMTP Relay Service Exploit https://www.avanan.com/blog/the-gmail-smtp-relay-service-exploit OpenSSF Package Analysis https://openssf.org/blog/2022/04/28/introducing-package-analysis-scanning-open-source-packages-for-malicious-behavior/ M1 Prefetcher Data Leak https://www.prefetchers.info keywords: M1; apple; prefetcher; openssf; gmail; smtp; vsto; office

May 3, 20225 min

Network Security News Summary for Monday May 2nd, 2022

Passive DNS; Microsoft Edge "VPN"; Weibo Making IPs Public; SonicWall Vuln; Using Passive DNS Sources for Reconnaissance and Enumeration https://isc.sans.edu/forums/diary/Using+Passive+DNS+sources+for+Reconnaissance+and+Enumeration/28596/ Microsoft Edge Secure Network https://support.microsoft.com/en-gb/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318 Sina Weibo Making Users IPs and Location Public https://www.theregister.com/2022/04/29/weibo_location_services_default/ https://weibo.com/u/1934183965?layerid=4763194269108760 SonicWall Global VPN Client DLL Search Order Hijacking https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0036 Zoom Updated https://explore.zoom.us/en/trust/security/security-bulletin/ keywords: zoom; sonicwall; vpn; dll hijack; sina; weibo; edge secure network; microsoft; passive dns

May 1, 20224 min

Network Security News Summary for Friday April 29th, 2022

SMB/RPC Honeypot Results; Azure PostgreSQL Priv Esc; GitHub Update A Day of SMB: What does our SMB/RPC Honeypot see? CVE-2022-26809 https://isc.sans.edu/forums/diary/A+Day+of+SMB+What+does+our+SMBRPC+Honeypot+see+CVE202226809/28594/ Azure PostgreSQL Privilege Escalation https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/ Security alert: Attack campaign involving stolen OAuth user tokens https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens Netatalk Vulnerability Affecting Synology, QNAP, Others? https://www.synology.com/en-global/security/advisory/Synology_SA_22_06 keywords: netatalk; linux; qnap; synology; oauth; travis ci; postgrasql; heroku; azure; smb; rpc; honeypot

Apr 29, 20226 min

Network Security News Summary for Thursday April 28th, 2022

MITRE ATT&CK Update; MSFT Ukraine Report; Nimuspwn; npm Package Planting MITRE ATT&CK v11 https://isc.sans.edu/forums/diary/MITRE+ATTCK+v11+a+small+update+that+can+help+not+just+with+detection+engineering/28590/ Microsoft Special Report: Ukraine https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Vwwd Linux Privilege Escalation Nimbuspwn https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/ npm Package Planting https://blog.aquasec.com/npm-package-planting keywords: npm; linux; nimbuspwn; privilege escalation; ukraine; microsoft; att&ck;

Apr 27, 20226 min

Network Security News Summary for Wednesday April 27th, 2022

WSO2 Vuln Exploited; Core Impact via VMware; VirusTotal Update; WSO2 Vuln Exploited to Install Crypto Coin Miners https://isc.sans.edu/forums/diary/WSO2+RCE+exploited+in+the+wild/28586/ Core Impact Backdoor Delivered Via VMware Vulnerablity https://blog.morphisec.com/vmware-identity-manager-attack-backdoor VirusTotal Exploit Update https://twitter.com/bquintero/status/1518738072820670464 Emotet Experimenting With New Delivery Techniques https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques keywords: wso2; xmrig; vmware; iran; core impact; virustotal; emotet;

Apr 27, 20226 min

Network Security News Summary for Tuesday April 26th, 2022

PDF leads to PPT; VirusTotal Vuln; Apple Private Relay; Emotet fixes broken installer Simple PDF Linking to Malicious Content https://isc.sans.edu/forums/diary/Simple+PDF+Linking+to+Malicious+Content/28582/ VirusTotal Remote Code Execution https://www.cysrc.com/blog/virus-total-blog Apple's Private Relay can Cause the System to Ignore Firewall Rules https://mullvad.net/en/blog/2022/4/25/apples-private-relay-can-cause-the-system-to-ignore-firewall-rules/ Emotet Breaks and Later Fixes Installer https://www.bleepingcomputer.com/news/security/emotet-malware-infects-users-again-after-fixing-broken-installer/ keywords: emotet; apple; private relay; firewall; virustotal; pdf; link; malware

Apr 25, 20226 min