Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet StormCast Tuesday, April 15, 2025

xorsearch Update; Short Lived Certificates; New USB Malware

https://isc.sans.edu/podcastdetail/9408

xorsearch Update

Didier updated his "xorsearch" tool. It is now a python script, not a compiled binary, and supports Yara signatures. With Yara support also comes support for regular expressions.

https://isc.sans.edu/diary/xorsearchpy+Searching+With+Regexes/31854

Shorter-Lived Certificates

The CA/Browser Forum passed an update to reduce the maximum lifetime of certificates. The reduction will be implemented over the next four years. EFF also released an update to certbot introducing profiles that can be used to request shorter-lived certificates.

https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs

https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI

New Malware Harvesting Data from USB drives and infecting them.

Kaspersky is reporting that they identified new malware that not only harvests data from USB drives, but also spread via USB drives by replacing existing documents with malicious files.

https://therecord.media/goffee-espionage-campaign-russia-flash-drives

SANS Internet StormCast Monday, April 14, 2025

Langflow AI Attacks; Fortinet Attack Cleanup; MSFT Inetpub; SANSFIRE

https://isc.sans.edu/podcastdetail/9406

Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248)

After spotting individual attempts to exploit the recent Langflow vulnerability late last weeks, we now see more systematic internet wide scans attempting to verify the vulnerability.

https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/

Fortinet Analysis of Threat Actor Activity

Fortinet observed recent vulnerabilities in its devices being used to add a symlink to ease future compromise. The symlink is not removed by prior patches, and Fortinet released additional updates to detect and remove this attack artifact.

https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity

MSFT Inetpub

Microsoft clarified that its April patches created the inetpub directory on purpose. Users should not remove it.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability

SANSFIRE

https://isc.sans.edu/j/sansfire

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive