SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch

6 snips
Jan 30, 2025
The discussion kicks off with a deep dive into devious Python malware that cleverly mimics PDF documents to steal data. A critical Fortinet vulnerability is making rounds on Russian forums, raising alarms over timely patches. The vulnerabilities in the Voyager PHP framework reveal risks like arbitrary file uploads. Active exploitation of unpatched Zyxel devices highlights the ever-present threat landscape. Finally, a VMware patch tackles a serious SQL injection flaw, underscoring the necessity for quick updates in cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Python Malware Mimicking PDF with Embedded Environment

  • A Python-based information stealer disguises itself as a PDF document.
  • It also bundles its own Python environment for Windows, unlike typical Python malware.
ADVICE

Urgent Fortinet Patch Advisory

  • Patch Fortinet devices immediately due to an actively exploited vulnerability.
  • The exploit bypasses authentication via WebSocket on FortiOS versions 7.0.0 through 7.0.16.
ADVICE

Fortinet's Patch Policy Update

  • Update Fortinet devices without a FortiCloud license within seven days of a patch release.
  • Failing to do so will block access to the FortiCloud interface via those devices.
Get the Snipd Podcast app to discover more snips from this episode
Get the app