Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, April 18, 2025

Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Backdoor Analysis; GPT 4.1 Safety Controversy

https://isc.sans.edu/podcastdetail/9414

RedTail: Remnux and Malware Management

A description showing how to set up a malware analysis in the cloud with Remnux and Kasm. RedTail is a sample to illustrate how the environment can be used.

https://isc.sans.edu/diary/RedTail+Remnux+and+Malware+Management+Guest+Diary/31868

Critical Erlang/OTP SSH Vulnerability

Researchers identified a critical vulnerability in the Erlang/OTP SSH library. Due to this vulnerability, SSH servers written in Erlang/OTP allow arbitrary remote code execution without prior authentication

https://www.openwall.com/lists/oss-security/2025/04/16/2

Brickstorm Analysis

An analysis of a recent instance of the Brickstorm backdoor. This backdoor used to be more known for infecting Linux systems, but now it also infects Windows.

https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor

https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf

OpenAI GPT 4.1 Controversy

OpenAI released its latest model, GPT 4.1, without a safety report and guardrails to prevent malware creation.

https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report

SANS Internet Storm Center StormCast Thursday, April 17, 2025

Apple Updates; Oracle Updates; Google Chrome Updates; CVE News

https://isc.sans.edu/podcastdetail/9412

Apple Updates

Apple released updates for iOS, iPadOS, macOS, and VisionOS. The updates fix two vulnerabilities which had already been exploited against iOS.

https://isc.sans.edu/diary/Apple+Patches+Exploited+Vulnerability/31866

Oracle Updates

Oracle released it quarterly critical patch update. The update addresses 378 security vulnerabilities. Many of the critical updates are already known vulnerabilities in open-source software like Apache and Nginx ingress.

https://www.oracle.com/security-alerts/cpuapr2025.html

Oracle Breach Guidance

CISA released guidance for users affected by the recent Oracle cloud breach. The guidance focuses on the likely loss of passwords.

https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise

Google Chrome Update

A Google Chrome update released today fixes two security vulnerabilities. One of the vulnerabilities is rated as critical.

https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html

CVE Updates

CISA extended MITRE's funding to operate the CVE numbering scheme. However, a number of other organizations announced that they may start alternative vulnerability registers.

https://euvd.enisa.europa.eu/

https://gcve.eu/

https://www.thecvefoundation.org/

SANS Internet Storm Center StormCast Wednesday, April 16, 2025

File Upload Service Abuse; OpenSSH 10.0 Released; Apache Roller Vuln; Possible CVE Changes

https://isc.sans.edu/podcastdetail/9410

Online Services Again Abused to Exfiltrate Data

Attackers like to abuse free online services that can be used to exfiltrate data from the ÒoriginalsÓ, like pastebin, to past favorites like anonfiles.com. The latest example is gofile.io. As a defender, it is important to track these services to detect exfiltration early

https://isc.sans.edu/diary/Online+Services+Again+Abused+to+Exfiltrate+Data/31862

OpenSSH 10.0 Released

OpenSSH 10.0 was released. This release adds quantum-safe ciphers and the separation of authentication services into a separate binary to reduce the authentication attack surface.

https://www.openssh.com/releasenotes.html#10.0p1

Apache Roller Vulnerability

Apache Roller addressed a vulnerability. Its CVSS score of 10.0 appears inflated, but it is still a vulnerability you probably want to address.

https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f

CVE Funding Changes

Mitre's government contract to operate the CVE system may run out tomorrow. This could lead to a temporary disruption of services, but the system is backed by a diverse board of directors representing many large companies. It is possible that non-government funding sources may keep the system afloat for now.

https://www.cve.org/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive