

SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;
Feb 27, 2025
Discover the hidden risks of ephemeral ports as attackers use them to exfiltrate data, prompting the need for vigilant traffic monitoring. A compromised Visual Studio Code theme has alarmingly reached millions, with its exact malicious intent still under wraps. The shocking theft at ByBit reveals how a compromised developer workstation can lead to monumental losses. Additionally, a vulnerability in NAKIVO backup systems sparks concerns as a proof of concept exploit surfaces, catching the cyber world off guard.
AI Snips
Chapters
Transcript
Episode notes
Monitor High Ports
- Monitor network traffic for unusual activity like HTTP/HTTPS on high, non-standard ports.
- Exercise caution, as legitimate services sometimes use high ports, especially in cloud environments.
Malicious VS Code Themes
- Malicious Visual Studio Code themes can execute code, posing a significant security risk.
- Amit Assaraf found a potentially malicious theme downloaded by millions, highlighting the need for caution.
Bybit Breach
- Bybit lost a substantial amount of Ethereum due to a compromised Safe{Wallet} developer workstation.
- The attacker replaced JavaScript code, targeting Bybit's transactions and altering a contract.