

SANS Stormcast Monday, June 16th, 2025: Extracting Data from JPEG; Windows Recall Export; Anubis Wiper; Mitel Vuln and PoC
8 snips Jun 17, 2025
Discover how to expertly extract data from JPEG files with a nifty tool, jpegdump.py. Microsoft's new Windows 11 feature allows European users to export data while managing encryption keys. Meanwhile, the Anubis ransomware takes a dark turn by wiping data even after ransom payments. Plus, critical vulnerabilities in Mitel software are discussed, highlighting the urgency for immediate security measures. Stay informed about these emerging threats and cutting-edge tech developments!
AI Snips
Chapters
Transcript
Episode notes
Extract Data From JPEGs Easily
- Use Didier's jpegdump.py to extract hidden data from JPEG files efficiently.
- It supports pushing data blocks to other tools for detailed malware analysis.
Windows Recall Data Export in Europe
- Microsoft stores Windows Recall screenshots encrypted locally, limiting user visibility.
- European users can now export this data using a one-time encryption key shown at feature enablement.
Anubis Ransomware Now Deletes Data
- Anubis ransomware evolved to a wiper mode that deletes data, preventing recovery after ransom payment.
- Paying ransom likely won't restore data; victims should demand proof of file integrity before paying.