
ISC StormCast for Tuesday, August 8th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
CloudFlare Tunneling Attacks
The malicious configuration file reaches out to GitHub downloads a trapper that will then execute various payloads including in the case of cassata here documented a Python remote access tool. Of course anything is possible at this point and I wouldn't be surprised that there's various variations of this attacks out there installing different back doors or rats. Remember ever so often I'm also teaching some classes it's not late yet to register for the next class actually in about two weeks I'll be teaching our defending web allocation theory class online only It will be taught in the Chicago time zone and first week September I'll do the same in London life but it's also available online.
Transcript
Play full episode