CyberWire Daily

Weathering the internet storm. [Research Saturday]

02.03.2024 - By N2K NetworksPlay

Download our free app to listen on your phone

Download on the App StoreGet it on Google Play

Johannes Ullrich from SANS talking about the Internet Storm Center and how they do research. Internet Storm Center was created as a mix of manual reports submitted by security analysts during Y2K and automated firewall collection started by DShield.

The research shares how SANS used their "agile honeypots" to "zoom in" on events to more effectively collect data targeting specific vulnerabilities. Internet Storm Center has been noted on three separate attacks that were observed.

The research can be found here:

Jenkins Brute Force Scans

Scans for Ivanti Connect "Secure" VPN Vulnerability (CVE-2023-46805, CVE-2024-21887)

Scans/Exploit Attempts for Atlassian Confluence RCE Vulnerability CVE-2023-22527

More episodes from CyberWire Daily