SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Stormcast, Jan 8, 2025: Critical Vulnerabilities in SonicWall, Moxa, and Windows BitLocker – Plus, Malware Targets PHP Servers and the Launch of U.S. Cyber Trust Mark

6 snips
Jan 8, 2025
Discover the alarming exploitation of a zero-day vulnerability in SonicWall SSL-VPN devices. Unearth security flaws in Moxa routers that allow privilege escalation. Learn about the new cryptocurrency mining malware targeting PHP servers. Meanwhile, the White House introduces the U.S. Cyber Trust Mark, aiming to help consumers identify secure connected devices. This insightful discussion emphasizes the importance of patch management and informed decisions in cybersecurity.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Mitigating Cryptocurrency Miners on PHP Servers

  • Patch PHP servers, especially if using PHP CGI installations, to protect against CVE-2024-4577 and similar exploits.
  • Watch for CPU load spikes and investigate further, as crypto miners can indicate broader exploitation.
ADVICE

SonicWall SSL-VPN Zero-Day

  • Patch SonicWall SMA 100 series devices immediately due to actively exploited zero-day vulnerability.
  • Segment your network and limit IP addresses accessing your SSL-VPN gateway.
ADVICE

Moxa Device Vulnerabilities

  • Update firmware on Moxa cellular routers and security appliances to patch critical vulnerabilities.
  • Avoid using default credentials, especially since Moxa devices have hardcoded credentials.
Get the Snipd Podcast app to discover more snips from this episode
Get the app