

SANS ISC Stormcast, Jan 8, 2025: Critical Vulnerabilities in SonicWall, Moxa, and Windows BitLocker – Plus, Malware Targets PHP Servers and the Launch of U.S. Cyber Trust Mark
6 snips Jan 8, 2025
Discover the alarming exploitation of a zero-day vulnerability in SonicWall SSL-VPN devices. Unearth security flaws in Moxa routers that allow privilege escalation. Learn about the new cryptocurrency mining malware targeting PHP servers. Meanwhile, the White House introduces the U.S. Cyber Trust Mark, aiming to help consumers identify secure connected devices. This insightful discussion emphasizes the importance of patch management and informed decisions in cybersecurity.
AI Snips
Chapters
Transcript
Episode notes
Mitigating Cryptocurrency Miners on PHP Servers
- Patch PHP servers, especially if using PHP CGI installations, to protect against CVE-2024-4577 and similar exploits.
- Watch for CPU load spikes and investigate further, as crypto miners can indicate broader exploitation.
SonicWall SSL-VPN Zero-Day
- Patch SonicWall SMA 100 series devices immediately due to actively exploited zero-day vulnerability.
- Segment your network and limit IP addresses accessing your SSL-VPN gateway.
Moxa Device Vulnerabilities
- Update firmware on Moxa cellular routers and security appliances to patch critical vulnerabilities.
- Avoid using default credentials, especially since Moxa devices have hardcoded credentials.