Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet StormCast Tuesday, February 25, 2025

Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim; libXML; Parallels Vuln

https://isc.sans.edu/podcastdetail/9338

Unfurl Update Released

Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs.

https://isc.sans.edu/diary/Unfurl+v202502+released/31716

Google Confirms GMail To Ditch SMS Code Authentication

Google no longer considers SMS authentication save enough for GMail. Instead, it pushes users to use Passkeys, or QR code based app authentication

https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/

Beware of Paypal New Address Feature Abuse

Attackers are using "address change" e-mails to send links to phishing sites or trick users into calling fake tech support phone numbers. Attackers are just adding the malicious content as part of the address. The e-mail themselves are legitimate PayPal emails and will pass various spam and phishing filters.

https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/

Exim SQL Injection Vulnerability

Exim, with sqlite support and ETRN enabled, is vulnerable to a simple SQL injection exploit. A PoC has been released

https://www.exim.org/static/doc/security/CVE-2025-26794.txt

https://github.com/OscarBataille/CVE-2025-26794?

XMLlib patches

https://gitlab.gnome.org/GNOME/libxml2/-/issues/847

https://gitlab.gnome.org/GNOME/libxml2/-/issues/828

0-Day in Parallels

https://jhftss.github.io/Parallels-0-day/

SANS Internet StormCast Monday, February 24, 2025

sigs.py update; Google Introducing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns

https://isc.sans.edu/podcastdetail/9336

Tool Update: Sigs.py

Jim updates sigs.py. The tool verifies hashes for files and automatically recognizes what hash is used.

https://isc.sans.edu/diary/Tool+update+sigspy+added+check+mode/31706

Google Announcing Quantum Safe Digital Signatures in Cloud KMS

Google announced the option to use quantum safe digital signatures for its cloud key management system.

https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms

Windows 11 Patch issues

The February Patch Tuesday appears to have caused issues with a number of Windows 11 systems. In particular the usability of the file manager appears to be affected.

https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/

LTE/5G Vulnerabilities

Researchers at the university of Florida have identified a large number of vulnerabilities in 5G and LTE networks.

https://nathanielbennett.com/publications/ransacked.pdf

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive