

SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code
5 snips Jan 29, 2025
Delve into the world of cybersecurity with discussions on a Python script targeting Exodus wallets, swiftly stealing crypto without saving data. Hear about the exploitation of vulnerabilities in SimpleHelp software, raising alarm for initial network breaches. Explore new side-channel attacks affecting Apple Silicon processors, enabling unauthorized access to sensitive data. The podcast also highlights privilege escalation vulnerabilities in TeamViewer and examines the strange misuse of QR codes in cyber threats.
AI Snips
Chapters
Transcript
Episode notes
Patch SimpleHelp
- Ensure all SimpleHelp installations are patched to mitigate vulnerabilities.
- Assume compromise if your SimpleHelp installations aren't patched.
Apple Silicon Attacks
- New side-channel attacks, SLAP and FLOP, target Apple Silicon processors.
- These attacks exploit vulnerabilities in load address and value prediction.
Side-Channel Attack Demo
- One demonstration showed JavaScript reading data from another browser window.
- This vulnerability allowed malicious JavaScript to read emails from a ProtonMail window.