Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet StormCast Tuesday, February 11th, 2025

7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update

https://isc.sans.edu/podcastdetail/9318

Reminder: 7-Zip MoW

The MoW must be added to any files extracted from ZIP or other compound file formats. 7-Zip does not do so by default unless you alter the default configuration.

https://isc.sans.edu/diary/Reminder+7Zip+MoW/31668

Apple Fixes 0-Day

Apple released updates to iOS and iPadOS fixing a bypass for USB Restricted Mode. The vulnerability is already being exploited.

https://support.apple.com/en-us/122174

AMD ZEN CPU Microcode Update

An attacker is able to replace microcode on some AMD CPUs. This may alter how the CPUs function and Google released a PoC showing how it can be used to manipulate the random number generator.

https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w

Trimble Cityworks Exploited

CISA added a recent Trimble Cityworks vulnerability to its list of exploited vulnerabilities.

https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?

Google Tag Manager Skimmer Steals Credit Card Info

Sucuri released a blog post with updates to the mage cart campaign. The latest version is injecting malicious code as part of the google tag manager / analytics code.

https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html

SANS Internet StormCast Monday, February 10th, 2025

Podcast Anniversary; SSL 2.0; Exposed DeepSeek Installs; Crypto Scam costs

https://isc.sans.edu/podcastdetail/9316

SSL 2.0 Turns 30 This Sunday

SSL was created in February 1995. However, back in 2005, only a year later, SSL 3.0 was released, and as of 2011, SSL 2.0 was deprecated, and support was removed from many crypto libraries. However, over 400k hosts are still exposed via SSL 2.0.

https://isc.sans.edu/diary/SSL+20+turns+30+this+Sunday+Perhaps+the+time+has+come+to+let+it+die/31664

DeepSeek News

Many articles cover various security shortcomings in the Chinese DeepSeek AI model. Remember that some of these issues are not unique to DeepSeek.

https://www.upguard.com/blog/deepseek-adoption

https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face

https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak

https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/

Crypto Wallet Scam Not For Free

Didier looked closer at the recent dual signature crypto scams. These wallets are not free; attackers must spend money to set them up.

https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive