SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln

Feb 25, 2025
Discover the latest Unfurl update that improves URL decoding and timestamp management. Learn how Google is phasing out SMS for GMail, opting for Passkeys instead. Beware of new PayPal phishing tactics that exploit legitimate emails. The podcast also covers vulnerabilities in mail servers, including a serious Exim SQL injection flaw and a newly discovered 0-day in Parallels. Stay informed about evolving cyber threats and enhance your security awareness!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Unfurl Tool

  • Use Unfurl to decode URLs and understand their components.
  • The tool can recognize timestamps and convert them, which is handy for analysis.
ADVICE

Gmail Authentication

  • Google is ditching SMS-based 2FA for Gmail, pushing users towards passkeys or QR code authentication.
  • Consider switching to more secure authentication methods like passkeys.
ADVICE

PayPal Phishing Scam

  • Be wary of PayPal emails about address changes, as attackers might include phishing links in the new address.
  • Verify address changes directly through the PayPal website, not via email links.
Get the Snipd Podcast app to discover more snips from this episode
Get the app