SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal Scams; VMWare Escape Fix

Mar 5, 2025
A Romanian attacker expands their scanning tactics to hunt for SMTP credentials, complicating cybersecurity efforts. An update to mac-robber.py resolves symlink issues, enhancing security tool functionality. A serious vulnerability in ADSelfService Plus could allow unauthorized access without MFA. Google's March Android update tackles critical vulnerabilities, while PayPal's no-code-checkout feature faces exploitation by scammers. Broadcom addresses three VMware vulnerabilities to prevent potential virtual machine breaches.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Secure SMTP Credentials

  • Secure your SMTP credentials, as attackers now target files like "smtp-token" and "smtp-keys".
  • These files likely belong to applications like the Jansen project, an identity management tool.
ADVICE

Update MacRobber.py

  • Update your MacRobber.py tool to the latest version.
  • This update fixes issues with symlinks, improving its functionality.
ADVICE

Patch ADSelfService Plus

  • Patch Ad Self-Service Plus to fix a session handling vulnerability.
  • Implement two-factor authentication to mitigate unauthorized access to user enrollment data.
Get the Snipd Podcast app to discover more snips from this episode
Get the app