Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: SANS Daily Network Security Podcast (Stormcast) for Friday, July 1st, 2022 - SANS Internet Storm Center SANS Daily Network Security Podcast (Stormcast) for Friday, July 1st, 2022


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Cobalt Strike Domain Suspension; ManageEngine Vuln Details; CWE Top 25 Update

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/8072.mp3

SANS Daily Network Security Podcast (Stormcast) for Friday, July 1st, 2022
00:00
Case Study: Cobalt Strike Server Lives on After its Domain is Suspended
https://isc.sans.edu/forums/diary/Case+Study+Cobalt+Strike+Server+Lives+on+After+Its+Domain+Is+Suspended/28804/

CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
https://www.horizon3.ai/red-team-blog-cve-2022-28219/

CWE Top 25 Update
https://cwe.mitre.org/top25/archive/2022/2022_cwe_top25.html#analysis

Spotify spotify logo

Discussion

Login here to join the discussion.

Application Security: Securing Web Apps, APIs, and MicroservicesWashingtonJul 11th - Jul 16th 2022
Application Security: Securing Web Apps, APIs, and MicroservicesOnlineJul 11th - Jul 16th 2022
Application Security: Securing Web Apps, APIs, and MicroservicesTokyoAug 29th - Sep 3rd 2022
Application Security: Securing Web Apps, APIs, and MicroservicesOnline | Japan Standard TimeAug 29th - Sep 3rd 2022
Intrusion Detection In-DepthRiyadhOct 8th - Oct 13th 2022
Intrusion Detection In-DepthOnline | Arabian Standard TimeOct 8th - Oct 13th 2022
Application Security: Securing Web Apps, APIs, and MicroservicesSan FranciscoDec 5th - Dec 10th 2022
Application Security: Securing Web Apps, APIs, and MicroservicesOnline | US PacificDec 5th - Dec 10th 2022