Talk With an Expert

Internet Storm Center Tech Corner

SANS ISC Stormcast, Jan 14, 2025

This episode covers brute-force attacks on the password reset functionality of Hikvision devices, a macOS SIP bypass vulnerability, Linux rootkit malware, and a novel ransomware campaign targeting AWS S3 buckets.

https://isc.sans.edu/podcastdetail/9278

Hikvision Password Reset Brute Forcing

Hikvision devices are being targeted using old brute-force attacks exploiting predictable password reset codes.

https://isc.sans.edu/diary/Hikvision+Password+Reset+Brute+Forcing/31586

Analyzing CVE-2024-44243: A macOS System Integrity Protection Bypass

Microsoft details a macOS vulnerability allowing attackers to bypass SIP using kernel extensions.

https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/

Rootkit Malware Controls Linux Systems Remotely

A sophisticated rootkit targeting Linux systems uses zero-day vulnerabilities for remote control.

https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/

Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C

Attackers are using AWS’s SSE-C encryption to lock S3 buckets during ransomware campaigns. We cover how the attack works and how to protect your AWS environment.

https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c

SANS ISC Stormcast, Jan 13, 2025

Defender Updates, Ivanti RCE, Apple USB-C Hack and more

https://isc.sans.edu/podcastdetail/9276

Windows Defender Enhances Chrome Extension Detection

Microsoft's Defender now catalogs Chrome extensions to identify malicious ones. Learn how this improves enterprise security.

https://isc.sans.edu/diary/Windows+Defender+Chrome+Extension+Detection/31574

Multi-OLE Analysis in Malicious Documents

A look at how attackers embed OLE files in Office documents to evade detection and the tools to combat it.

https://isc.sans.edu/diary/Multi-OLE/31580

Ivanti Connect Secure RCE Vulnerability (CVE-2025-0282)

Details of a critical vulnerability affecting Ivanti products and the patching timelines.

https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/

Apple USB-C Controller Compromised

Researchers hacked Apple’s ACE3 USB-C controller, highlighting hardware security challenges.

https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/

IRS Pushes for IP PIN Enrollment

Protect yourself from tax-related identity theft by securing your IP PIN for the 2025 tax season.

https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive