

SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch
6 snips Jan 30, 2025
The discussion kicks off with a deep dive into devious Python malware that cleverly mimics PDF documents to steal data. A critical Fortinet vulnerability is making rounds on Russian forums, raising alarms over timely patches. The vulnerabilities in the Voyager PHP framework reveal risks like arbitrary file uploads. Active exploitation of unpatched Zyxel devices highlights the ever-present threat landscape. Finally, a VMware patch tackles a serious SQL injection flaw, underscoring the necessity for quick updates in cybersecurity.
AI Snips
Chapters
Transcript
Episode notes
Python Malware Mimicking PDF with Embedded Environment
- A Python-based information stealer disguises itself as a PDF document.
- It also bundles its own Python environment for Windows, unlike typical Python malware.
Urgent Fortinet Patch Advisory
- Patch Fortinet devices immediately due to an actively exploited vulnerability.
- The exploit bypasses authentication via WebSocket on FortiOS versions 7.0.0 through 7.0.16.
Fortinet's Patch Policy Update
- Update Fortinet devices without a FortiCloud license within seven days of a patch release.
- Failing to do so will block access to the FortiCloud interface via those devices.