Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet StormCast Friday, February 14th, 2025

DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhoon vs. Cisco; Crowdstrike Patch

https://isc.sans.edu/podcastdetail/9324

DShield SIEM Docker Updates

Interested in learning more about the attacks hitting your honeypot?

Guy assembled a neat SIEM to create dashboards summarizing the attacks.

https://isc.sans.edu/diary/DShield+SIEM+Docker+Updates/31680

PANOS Path Confusion Auth Bypass

Palo Alto Networks fixed a path confusion vulnerability introduced by the

overly complex middle box chain in PANOS.

https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/

https://www.theregister.com/2025/02/13/palo_alto_firewall/

China's Volt Typhoon Continues to use Cisco Vulns

Recorded Future wrote up some recent attacks of the Red Mike / Volt Typhoon groups going after telecom providers by compromising Cisco systems via an older vulnerability

https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/

Crowdstrike Patches Linux Client

https://www.crowdstrike.com/security-advisories/cve-2025-1146/

SANS Internet StormCast Thursday, February 13th, 2025

Smart City Threats; Advanced Social Engineering Attacks; Wazuh Vulnerability; PAM Vulnerability; Ivanti Patches

https://isc.sans.edu/podcastdetail/9322

An Ontology for Threats: Cybercrime and Digital Forensic Investigation on Smart City Infrastructure

Smart cities is a big topic for many local governments. With building these complex systems, attacks will follow.

https://isc.sans.edu/diary/An+ontology+for+threats+cybercrime+and+digital+forensic+investigation+on+Smart+City+Infrastructure/31676

North Korean state actor tricking admins into executing PowerShell

North Korean state actors are spending quite a bit of effort setting up relationships with South Korean system administrators, culminating in them getting tricked into executing malicious PowerShell scripts.

https://x.com/MsftSecIntel/status/1889407814604296490

Wazuh Vulnerability

A deserialization vulnerability in Wazuh may lead to an unauthenticated remote code execution vulnerability

https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh

PAM PKCS11 Vulnerability

Several vulnerabilities in the Linux PAM module processing smart card authentication can be used to bypass authentication

https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13

Ivanti Patches

Ivanti released its monthly update, fixing a number of critical vulnerabilities in Connect Secure and other products

https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US

SANS Internet StormCast Wednesday, February 12th, 2025

MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS

https://isc.sans.edu/podcastdetail/9320

Microsoft Patch Tuesday

Microsoft released patches for 55 vulnerabilities. Three of them are categorized as critical, two are already exploited and another two have been publicly disclosed. The LDAP server vulnerability could become a huge deal, but it is not clear if an exploit will appear.

https://isc.sans.edu/diary/Microsoft+February+2025+Patch+Tuesday/31674

Adobe Patches

Adobe released patches for seven products. Watch out in particular for the Adobe Commerce issues.

https://helpx.adobe.com/security/security-bulletin.html

Fortinet Acknowledges Exploitation of Vulnerability

https://fortiguard.fortinet.com/psirt/FG-IR-24-535

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive