SS-NEWS-085: Deepfake Hysteria, IIS Server Logs as C2!

Episode 85 November 07, 2022 00:29:17
SS-NEWS-085: Deepfake Hysteria, IIS Server Logs as C2!
Security Serengeti
SS-NEWS-085: Deepfake Hysteria, IIS Server Logs as C2!

Nov 07 2022 | 00:29:17

/

Show Notes

Several short stories for your consideration on this fine November day.

First, Sophos thinks we're on the hysteria part of the FUD Curve where Deepfakes are concerned, and we agree (as if our opinion mattered).  Then we discuss Bitcoin Mining Firms possibly going bankrupt.  Not really security related, but hey, it was interesting.  The Samsung is introducing Maintenance Mode for when you have to hand your phone over to be repaired!  Finally, the most interesting, the use of IIS Web Logs for command and control... this is amazing.  Unfortunately, the article didn't have a ton of information, but it's a really cool new method!

Article 1 - Phishing works so well crims won't bother with deepfakes, says Sophos chap

Article 2 - World’s largest Bitcoin mining firm Core Scientific on the verge of insolvency

Article 3 - Maintenance Mode aims to keep phone data private during repairs

Article 4 - Hackers use Microsoft IIS web server logs to control malware
Supporting Article(s):
Cranefly Cyberspy Group Spawns Unique ISS Technique

If you found this interesting or useful, please follow us on Twitter @serengetisec and subscribe and review on your favorite podcast app!

Other Episodes

Episode 117

June 26, 2023 00:25:06
Episode Cover

SS-NEWS-117: Mt Gox Hackers Named and Public Wifi!

This week we discuss the Mt. Gox hack, 9 years on, due to the recent charging, we discuss how sextortion is changing with the...

Listen

Episode 10

May 16, 2021 00:40:16
Episode Cover

SS-RPRT-010: Proofpoint's State of the Phish Report 2021

In this episode, we analyze the 2021 Proofpoint State of the Phish Report, and discuss some of the more interesting findings. Report Download (with...

Listen

Episode 147

July 29, 2024 00:49:14
Episode Cover

SS-NEWS-147 - Does Phishing Education need to mature like Fire Drills did?

This week David and I talk about how current phishing tests closely resemble early attempts at fire drills, through the Google Security Blog, and...

Listen