
ISC StormCast for Monday, July 17th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
Microsoft Addresses Kernel Mode Driver Signing Issue
Microsoft will accept cross-signed kernel mode drivers as long as the signature timestamp is set to a date before July 29th, 2015. An attacker who somehow has obtained a signing certificate that was valid back in 2015 can now just backdate the signature. Researchers with the technical host, Julian Aachen did analyze over 300 Docker images from Docker Hub and about 8,000 from private repositories. They found it about 8.5% of these images do include secrets.
Play episode from 00:00
Transcript


