SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code

5 snips
Jan 29, 2025
Delve into the world of cybersecurity with discussions on a Python script targeting Exodus wallets, swiftly stealing crypto without saving data. Hear about the exploitation of vulnerabilities in SimpleHelp software, raising alarm for initial network breaches. Explore new side-channel attacks affecting Apple Silicon processors, enabling unauthorized access to sensitive data. The podcast also highlights privilege escalation vulnerabilities in TeamViewer and examines the strange misuse of QR codes in cyber threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Patch SimpleHelp

  • Ensure all SimpleHelp installations are patched to mitigate vulnerabilities.
  • Assume compromise if your SimpleHelp installations aren't patched.
INSIGHT

Apple Silicon Attacks

  • New side-channel attacks, SLAP and FLOP, target Apple Silicon processors.
  • These attacks exploit vulnerabilities in load address and value prediction.
ANECDOTE

Side-Channel Attack Demo

  • One demonstration showed JavaScript reading data from another browser window.
  • This vulnerability allowed malicious JavaScript to read emails from a ProtonMail window.
Get the Snipd Podcast app to discover more snips from this episode
Get the app