Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Tuesday, April 22, 2025

Phishing via Google; ChatGPT Fingerprint; Asus AI Cloud Vuln; PyTorch RCE

https://isc.sans.edu/podcastdetail/9418

It's 2025, so why are malicious advertising URLs still going strong?

Phishing attacks continue to take advantage of GoogleÕs advertising services. Sadly, this is still the case for obviously malicious links, even after various anti-phishing services flag the URL.

https://isc.sans.edu/diary/Its+2025+so+why+are+obviously+malicious+advertising+URLs+still+going+strong/31880

ChatGPT Fingerprinting Documents via Unicode

ChatGPT apparently started leaving fingerprints in texts, which it creates by adding invisible Unicode characters like non-breaking spaces.

https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text

Asus AI Cloud Security Advisory

Asus warns of a remote code execution vulnerability in its routers. The vulnerability is related to the AI Cloud feature. If your router is EoL, disabling the feature will mitigate the vulnerability

https://www.asus.com/content/asus-product-security-advisory/

PyTorch Vulnerability

PyTorch fixed a remote code execution vulnerability exploitable if a malicious model was loaded. This issue was exploitable even with the Òweight_only=True" setting selected

https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6

SANS Internet Storm Center StormCast Monday, April 21, 2025

MSFT Entra Lockouts; Erlang/OTP SSH Exploit; SonicWall Exploit; bubble.io bug

https://isc.sans.edu/podcastdetail/9416

Microsoft Entra User Lockout

Multiple organizations reported widespread alerts and account lockouts this weekend from Microsoft Entra. The issue is caused by a new feature Microsoft enabled. This feature will lock accounts if Microsoft believes that the password for the account was compromised.

https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/

https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability

Erlang/OTP SSH Exploit

An exploit was published for the Erlang/OTP SSH vulnerability. The vulnerability is easy to exploit, and the exploit and a Metasploit module allow for easy remote code execution.

https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb

SonicWall Exploited

An older command injection vulnerability is now exploited on Sonicwall devices after initially gaining access by brute-forcing credentials.

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022

Unpatched Vulnerability in Bubble.io

An unpatched vulnerability in the no-code platform bubble.io can be used to access any project hosted on the site.

https://github.com/demon-i386/pop_n_bubble

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive