Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, May 9, 2025

SSH Exfil Tricks; magicINFO still vulnerable; SentinelOne Vulnerability; Commvault insufficient patch

https://isc.sans.edu/podcastdetail/9444

No Internet Access? SSH to the Rescue

If faced with restrictive outbound network access policies, a single inbound SSH connection can quickly be turned into a tunnel or a full-blown VPN

https://isc.sans.edu/diary/No+Internet+Access+SSH+to+the+Rescue/31932

SAMSUNG magicINFO 9 Server Flaw Still exploitable

The SAMSUNG magicINFO 9 Server Vulnerability we found being exploited last week is apparently still not completely patched, and current versions are vulnerable to the exploit observed in the wild.

https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw

Bring Your Own Installer: Bypassing SentinelOne Through Agent Version Change Interruption

SentinelOne’s installer is vulnerable to an exploit allowing attackers to shut down the end point protection software

https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone

Commvault Still Exploitable

A recent patch for Commvault is apparently ineffective and the PoC exploit published by watchTowr is still working against up to date patched systems

https://infosec.exchange/@wdormann/114458913006792356

SANS Internet Storm Center StormCast Thursday, May 8, 2025

Modular Malware; SysAid Vuln; Cisco Wireless Controller Patch; UniFi Protect Camera Patch

https://isc.sans.edu/podcastdetail/9442

Example of Modular Malware

Xavier analyzes modular malware that downloads DLLs from GitHub if specific features are required. In particular, the webcam module is inspected in detail.

https://isc.sans.edu/diary/Example+of+Modular+Malware/31928

SysAid XXE Vulnerabilities

IT Service Management Software SysAid patched a number of XXE vulnerabilities. Without authentication, an attacker is able to obtain confidential data and completely compromise the system. watchTowr published a detailed analysis of the flaws including exploit code.

https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/

Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability

Cisco Patched a vulnerability in its wireless controller software that may be used to not only upload files but also execute code as root without authentication.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC

UniFi Protect Camera Vulnerability

Ubiquity patched a vulnerability in its Protect camera firmware fixing a buffer overflow flaw.

https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc

SANS Internet Storm Center StormCast Wednesday, May 7, 2025

Infostealer with Webserver; Android Update; CISA Warning

https://isc.sans.edu/podcastdetail/9440

Python InfoStealer with Embedded Phishing Webserver

Didier found an interesting infostealer that, in addition to implementing typical infostealer functionality, includes a web server suitable to create local phishing sites.

https://isc.sans.edu/diary/Python+InfoStealer+with+Embedded+Phishing+Webserver/31924

Android Update Fixes Freetype 0-Day

Google released its monthly Android update. As part of the update, it patched a vulnerability in Freetype that is already being exploited. Android is not alone in using Freetype. Freetype is a very commonly used library to parse fonts like Truetype fonts.

https://source.android.com/docs/security/bulletin/2025-05-01

CISA Warns of Unsophisticated Cyber Actors

CISA released an interesting title report warning operators of operational technology networks of ubiquitous attacks by unsophisticated actors. It emphasizes how important it is to not forget basic security measures to defend against these attacks.

https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive