SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;

Feb 27, 2025
Discover the hidden risks of ephemeral ports as attackers use them to exfiltrate data, prompting the need for vigilant traffic monitoring. A compromised Visual Studio Code theme has alarmingly reached millions, with its exact malicious intent still under wraps. The shocking theft at ByBit reveals how a compromised developer workstation can lead to monumental losses. Additionally, a vulnerability in NAKIVO backup systems sparks concerns as a proof of concept exploit surfaces, catching the cyber world off guard.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Monitor High Ports

  • Monitor network traffic for unusual activity like HTTP/HTTPS on high, non-standard ports.
  • Exercise caution, as legitimate services sometimes use high ports, especially in cloud environments.
INSIGHT

Malicious VS Code Themes

  • Malicious Visual Studio Code themes can execute code, posing a significant security risk.
  • Amit Assaraf found a potentially malicious theme downloaded by millions, highlighting the need for caution.
ANECDOTE

Bybit Breach

  • Bybit lost a substantial amount of Ethereum due to a compromised Safe{Wallet} developer workstation.
  • The attacker replaced JavaScript code, targeting Bybit's transactions and altering a contract.
Get the Snipd Podcast app to discover more snips from this episode
Get the app