Podcast Detail

SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/9298.mp3

Podcast Logo
SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches

Interested in Internet Storm Center stickers? Check here if there are still some available for today.

This episode shows how attackers are bypassing phishing filter by abusing the "shy" softhyphen HTML entitiy. We got an update from Apple fixing a 0-day vulnerability in addition to a number of other issues. watchTowr show how to exploit an interesting FortiOS vulnerability and we have patches for Github Desktop and Apache Solr

An unusal shy z-wasp phish
How the soft hyphen "shy" HTML entity can be abused to bypass e-mail filters

Apple Patches
Apple released patches for all of its operating systems, fixing a 0-day vulnerability among many others issues

Get Fortirekt I am the Super_admin now
Details about a recent FortiOS Vulnerability

GitHub Desktop Vulnerability

Apache Solr Vulnerability