YARA and CyberChef https://isc.sans.edu/forums/diary/YARA+and+CyberChef/27180/ Apple Updates Everything https://support.apple.com/en-us/HT201222 Google Adds Port 554 to "Restricted Ports" https://chromium.googlesource.com/chromium/src.git/+/refs/heads/master/net/base/port_util.cc Yet Another Intel Side Channel Attack https://arxiv.org/pdf/2103.03443.pdf
Update on Microsoft Exchange Vulnerability https://github.com/microsoft/CSS-Exchange/tree/main/Security https://github.com/nccgroup/Cyber-Defence/tree/master/Intelligence/Exchange https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b Microsoft Adding Excel 4.0 Macro Hooks to AMSI https://www.microsoft.com/security/blog/2021/03/03/xlm-amsi-new-runtime-defense-against-excel-4-0-macro-malware/ Apple Find My Device Leak https://arxiv.org/pdf/2103.02282.pdf
From VBS, PowerShell, C Sharp, Process Hollowing to RAT https://isc.sans.edu/forums/diary/From+VBS+PowerShell+C+Sharp+Process+Hollowing+to+RAT/27168/ Cisco Patches Snort Related Vulnerabilities https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ethernet-dos-HGXgJH8n VMWare View Planner Update https://www.vmware.com/security/advisories/VMSA-2021-0003.html Google's FLoC Algorithm https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-idea Supermicro Trickbot Patch https://www.supermicro.com/en/support/security/trickbot
In Episode 219, Ben and Scott discuss the announcements and news from Microsoft's Spring Ignite event for Microsoft 365 and Azure. Sponsors Sperry Software – Powerful Outlook Add-ins developed to make your email life easy even if you’re too busy to manage your inbox ShareGate - ShareGate's industry-leading products help IT Read More
Fun with DNS over TLS and https://isc.sans.edu/forums/diary/Fun+with+DNS+over+TLS+DoT/27150/ Gootloader Update https://news.sophos.com/en-us/2021/03/01/gootloader-expands-its-payload-delivery-options/ AOL Phishing https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/ Spectre Exploit in the Wild https://dustri.org/b/spectre-exploits-in-the-wild.html
Pretending to be an Outlook Version Update https://isc.sans.edu/forums/diary/Pretending+to+be+an+Outlook+Version+Update/27144/ Geolocating Satori Botnet Scanning Port 26 https://isc.sans.edu/forums/diary/So+where+did+those+Satori+attacks+come+from/27140/ Alexa Skill Security https://www.ndss-symposium.org/wp-content/uploads/ndss2021_5A-1_23111_paper.pdf TMobile Data Breach / SIM Swapping https://beta.documentcloud.org/documents/20492859-t-mobile-feb-2021-bc-data-breach
In Episode 218, Ben and Scott talk about opportunities to interact directly with Microsoft Teams engineering, changes to the timeline for the switchover from Stream to OneDrive and SharePoint for recordings in Teams, and the future of MTA certifications. Sponsors Sperry Software – Powerful Outlook Add-ins developed to make your email Read More
Qakbot In a Response to Full Disclosure Post https://isc.sans.edu/forums/diary/Qakbot+in+a+response+to+Full+Disclosure+post/27130/ Firefox Total Cookie Protection https://blog.mozilla.org/security/2021/02/23/total-cookie-protection/ VMWare ESXi / vCenter Server Update https://www.vmware.com/security/advisories/VMSA-2021-0002.html Replacing Content in Signed PDFs https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1B-4_24117_paper.pdf
Unprotecting Malicious Documents For Inspection https://isc.sans.edu/forums/diary/Unprotecting+Malicious+Documents+For+Inspection/27126/ Brave Browser DNS Leak https://www.theregister.com/2021/02/22/in_brief_security/ Telephony DoS https://www.ic3.gov/Media/Y2021/PSA210217
Dynamic Data Exchange (DDE) is Back in the Wild https://isc.sans.edu/forums/diary/Dynamic+Data+Exchange+DDE+is+Back+in+the+Wild/27116/ https://isc.sans.edu/forums/diary/DDE+and+oledump/27122/ macOS Malware "Prototype" https://redcanary.com/blog/clipping-silver-sparrows-wings/ New Phishing Attack Identifed: Malformed URL Prefixes https://www.greathorn.com/blog-new-phishing-attack-identified-malformed-url-prefixes/ Sonicwall SMA 100 Firmware Update https://www.sonicwall.com/support/product-notification/additional-sma-100-series-10-x-and-9-x-firmware-updates-required-updated-feb-19-2-p-m-cst/210122173415410/
In Episode 217, Ben and Scott talk about the new regions coming to Azure in the United States, service availability by region and the availability of Availability Zones in US South Central, and improvements to recovery in Azure Files. Sponsors Sperry Software – Powerful Outlook Add-ins developed to make your email Read More
The new "LinkedInSecureMessage" Phish https://isc.sans.edu/forums/diary/The+new+LinkedInSecureMessage/27110/ Apple M1 Optimized Malware https://objective-see.com/blog/blog_0x62.html QNAP Surveilance Station Vulnerability https://www.qnap.com/en/security-advisory/qsa-21-07 Masslogger Exfiltrates User Credentials https://blog.talosintelligence.com/2021/02/masslogger-cred-exfil.html
More Weirdness on TCP Port 26 https://isc.sans.edu/forums/diary/More+weirdness+on+TCP+port+26/27106/ Microsoft Pulls Servicing Stack Update https://threatpost.com/microsoft-windows-update-patch-tuesday/163981/ Network Monitoring Company Centreon Compromised https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf SHAREit Flaw Could Lead to Remote Code Execution https://www.trendmicro.com/en_us/research/21/b/shareit-flaw-could-lead-to-remote-code-execution.html VSCode NPM Extension RCE https://github.com/jackadamson/CVE-2021-26700
Securing and Optimizing Networks Using pfSense Traffic Shaper to Combat Bufferbloat https://isc.sans.edu/forums/diary/Securing+and+Optimizing+Networks+Using+pfSense+Traffic+Shaper+Limiters+to+Combat+Bufferbloat/27102/ Apple to Proxy Safe Browsing Requests https://twitter.com/othermaciej/status/1359736220809531393 Power Outages and Some Network Outages as a Result https://downdetector.com Phone Scam Success Rates https://www.helpnetsecurity.com/2021/02/15/lost-money-to-phone-scams/ https://nakedsecurity.sophos.com/2021/02/12/sms-tax-scam-unmasked-bogus-but-believable-dont-fall-for-it/