Talk With an Expert

Internet Storm Center Tech Corner

SANS ISC StormCast Tuesday, February 4, 2025

Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service

https://isc.sans.edu/podcastdetail/9308

Crypto Wallet Scam

YouTube spam messages leak private keys to crypto wallets. However, these keys can not be used to withdraw funds. Victims are scammed into depositing "gas fees" which are then collected by the scammer.

https://isc.sans.edu/diary/Crypto+Wallet+Scam/31646

Mediatek Patches

Mediatek patched numerous vulnerabilities in its WLAN products. Some allow for unauthenticated arbitrary code execution

https://corp.mediatek.com/product-security-bulletin/February-2025

D-Link Vulnerability

D-Link disclosed a vulnerability in older routers that as of May no longer receive any updates. Your only option is to upgrade hardare.

https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415

Microsoft Discontinues VPN Service

Microsoft is shutting down the VPN service that was included as part of Microsoft Defender

https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a

SANS ISC StormCast Monday, February 3, 2025

Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors

https://isc.sans.edu/podcastdetail/9306

To Simulate or Replicate: Crafting Cyber Ranges

Automating the creation of cyber ranges. This will be a multi part series and this part covers creating the DNS configuration in Windows

https://isc.sans.edu/diary/To+Simulate+or+Replicate+Crafting+Cyber+Ranges/31642

Scammers Exploiting DeepSeek Hype

Scammers are using the hype around DeepSeek, and some of the confusion caused by its site not being reachable, to scam users into installing malware. I am also including a link to a "jailbreak" of DeepSeek (this part was not covered in the podcast).

https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/

https://lab.wallarm.com/jailbreaking-generative-ai/

PyPi Archived Status

PyPi introduced a new feature to mark repositories as archived. This implies that the author is no longer maintaining the particular package

https://blog.pypi.org/posts/2025-01-30-archival/

ICS Medical Advisory: Comtec Patient Monitor Backdoor

An interested backdoor was found in a Comtech Patient Monitor.

https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive