SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Friday, Apr 4th: URL Frequency Analysis; Ivanti Flaw Exploited; WinRAR MotW Vuln; Tax filing scams; Oracle Breach Update

5 snips
Apr 4, 2025
Discover how frequency analysis can predict malicious URLs and enhance cybersecurity. Learn about a recently exploited Ivanti vulnerability that was initially thought unexploitable. Dive into the WinRAR flaw that mismanages symlinks, potentially endangering users. Stay alert about Microsoft’s warning on rising tax-related scams as filing deadlines approach. Lastly, catch up on an Oracle breach impacting customer information, emphasizing the importance of secure online practices.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

URL Frequency Analysis

  • Analyze web server logs for malicious activity by using frequency analysis.
  • Train a model with honeypot data and legitimate website logs for better triage.
ANECDOTE

Ivanti Vulnerability Exploited

  • A critical Ivanti Connect Secure vulnerability (CVE-2025-22457), deemed unexploitable, was exploited.
  • Attackers likely reversed the patch to develop an exploit, highlighting their creativity.
ADVICE

WinRAR Vulnerability

  • Update WinRAR to address a Mark of the Web vulnerability (CVE-2025-31334).
  • The vulnerability doesn't correctly apply the mark of the web when simlinks are involved.
Get the Snipd Podcast app to discover more snips from this episode
Get the app