

SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal Scams; VMWare Escape Fix
Mar 5, 2025
A Romanian attacker expands their scanning tactics to hunt for SMTP credentials, complicating cybersecurity efforts. An update to mac-robber.py resolves symlink issues, enhancing security tool functionality. A serious vulnerability in ADSelfService Plus could allow unauthorized access without MFA. Google's March Android update tackles critical vulnerabilities, while PayPal's no-code-checkout feature faces exploitation by scammers. Broadcom addresses three VMware vulnerabilities to prevent potential virtual machine breaches.
AI Snips
Chapters
Transcript
Episode notes
Secure SMTP Credentials
- Secure your SMTP credentials, as attackers now target files like "smtp-token" and "smtp-keys".
- These files likely belong to applications like the Jansen project, an identity management tool.
Update MacRobber.py
- Update your MacRobber.py tool to the latest version.
- This update fixes issues with symlinks, improving its functionality.
Patch ADSelfService Plus
- Patch Ad Self-Service Plus to fix a session handling vulnerability.
- Implement two-factor authentication to mitigate unauthorized access to user enrollment data.