Talk With an Expert

Internet Storm Center Tech Corner

Internet Storm Center StormCast, Tuesday, January 7, 2025

In this episode, we cover critical vulnerabilities affecting OpenSSH, BeyondTrust, and Nuclei, including the newly discovered "RegreSSHion" flaw and a bypass vulnerability in Nuclei. We also discuss how malware evasion techniques can impact analysis environments and highlight the dangers of fake exploits targeting researchers. Tune in for insights on patching, mitigation strategies, and staying ahead of emerging threats.

https://isc.sans.edu/podcastdetail/9268

Make Malware Happy

A look at how malware adapts and detects analysis environments, and why replicating operational settings is critical during malware analysis.

https://isc.sans.edu/diary/Make+Malware+Happy/31560

Nuclei Signature Verification Bypass (CVE-2024-43405)

A critical vulnerability in Nuclei allows malicious templates to bypass signature verification, risking arbitrary code execution.

https://www.wiz.io/blog/nuclei-signature-verification-bypass

Critical Vulnerability in BeyondTrust (CVE-2024-12356)

A high-risk flaw in BeyondTrust products allows unauthenticated OS command execution, posing a significant threat to privileged access systems.

https://censys.com/cve-2024-12356/

RegreSSHion Code Execution Vulnerability (CVE-2024-6387)

OpenSSH vulnerability "RegreSSHion" enables remote code execution, and fake exploits targeting security researchers are in circulation.

https://cybersecuritynews.com/regresshion-code-execution-vulnerability/

Internet Storm Center StormCast, Monday, January 6, 2025

In this episode, we cover the latest cybersecurity threats and defenses, including Python-delivered malware, goodware hash sets, SSL/TLS protocol updates, and critical vulnerabilities in ASUS routers and Paessler PRTG. Stay informed and secure your systems!

https://isc.sans.edu/podcastdetail/9266

SwaetRAT via Python

https://isc.sans.edu/diary/SwaetRAT+Delivery+Through+Python/31554

Goodware Hash Sets

https://isc.sans.edu/diary/Goodware+Hash+Sets/31556

SSL/TLS Updates

https://isc.sans.edu/diary/Changes+in+SSL+and+TLS+support+in+2024/31550

Cyberhaven Extension Compromise

https://secureannex.com/blog/cyberhaven-extension-compromise/

PRTG Vulnerability

https://www.zerodayinitiative.com/advisories/ZDI-24-1736/

ASUS Router Vulnerabilities

https://cybersecuritynews.com/asus-router-vulnerabilities/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive