Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet StormCast Tuesday, March 11, 2025

Shellcode as UUIDs; Moxa Switch Vuln Updates; Opentext Vuln; Livewire Volt Vuln

https://isc.sans.edu/podcastdetail/9358

Shellcode Encoded in UUIDs

Attackers are using UUIDs to encode Shellcode. The 128 Bit (or 16 Bytes) encoded in each UUID are converted to shell code to implement a cobalt strike beacon

https://isc.sans.edu/diary/Shellcode+Encoded+in+UUIDs/31752

Moxa CVE-2024-12297 Expanded to PT Switches

Moxa in January first released an update to address a fronted authorization logic disclosure vulnerability. It now updated the advisory and included the PT series switches as vulnerable.

https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches

Opentext Insufficiently Protected Credentials

https://portal.microfocus.com/s/article/KM000037455?language=en_US

Livewire Volt API vulnerability

https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv

SANS Internet StormCast Monday, March 10, 2025

Webshells; Undocumented ESP32 Commands; Camera Used For Ransomware Distribution

https://isc.sans.edu/podcastdetail/9356

Commonly Probed Webshell URLs

Many attackers deploy web shells to gain a foothold on vulnerable web servers. These webshells can also be taken over by parasitic exploits.

https://isc.sans.edu/diary/Commonly+Probed+Webshell+URLs/31748

Undocumented ESP32 Commands

A recent conference presentation by Tarlogic revealed several "backdoors" or undocumented features in the commonly used ESP32 Chipsets. Tarlogic also released a toolkit to make it easier to audit chipsets and find these hidden commands.

https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/

https://www.techspot.com/news/107073-researchers-uncover-hidden-backdoor-widely-used-esp32-microchip.html

Camera Off: Akira deploys ransomware via Webcam

The Akira ransomware group was recently observed infecting a network with Ransomware by taking advantage of a webcam.

https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive