SANS Internet Storm Center's Daily Network Security News Podcast

Network Security News Summary for Friday December 16th, 2022


Listen Later

MSFT Patch Issues; SPNEGO Vuln now Critical; VMWare Escape; Veem Exploited; Repository Phishing Microsoft Patch Issues: https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45 https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/so-you-say-your-dc-s-memory-is-getting-all-used-up-after/ba-p/3696318 Critical Remote Code Execution Vulneraiblity in SPNEGO Extended Negotiation Security Mechanism https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/ VMWare EHCI Controller Vulnerability CVE-2022-31705 https://www.vmware.com/security/advisories/VMSA-2022-0033.html Veem Vulnerability now Exploited https://www.veeam.com/kb4288 nuget / npm / pypi used to host phishing pages https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/ keywords: npm, npm, pypi, phishing, veem, backup, vmware, spnego, windows
...more
View all episodesView all episodes
Download on the App Store

SANS Internet Storm Center's Daily Network Security News PodcastBy Johannes B. Ullrich