PodParley PodParley

Storm⚡️Watch - 12/5/23

An episode of the Storm Watch by GreyNoise Intelligence podcast, hosted by GreyNoise Intelligence, titled "Storm⚡️Watch - 12/5/23" was published on December 5, 2023 and runs 66 minutes.

December 5, 2023 ·66m · Storm Watch by GreyNoise Intelligence

0:00 / 0:00

Welcome to the latest episode of Storm⚡️Watch, where we delve into the most recent cybersecurity events and trends.  We are also joined by our friends at Trinity Cyber

In this episode, we're excited to announce the arrival of TAGSMAS! This is a special event where we celebrate the power of tags in cybersecurity and how they can help us better understand and respond to threats.

We start the show with the team over at Trinity Cyber, with an in-depth discussion about what they do and how they and GreyNoise partner to keep organizations (and humans) safe.

The episode continues with a security bulletin from New Relic, who recently identified unauthorized access to their staging environment. This environment provides insights into customer usage and certain logs, but does not store customer telemetry and application data. The unauthorized access was due to stolen credentials and social engineering related to a New Relic employee account. The unauthorized actor used the stolen credentials to view certain customer data within the staging environment. Customers confirmed to be affected by this incident have been notified and given recommended next steps. Importantly, there is no evidence of lateral movement from the staging environment to customer accounts in the separate production environment or to New Relic's production infrastructure.

Next, we discuss a phishing campaign targeting WordPress users. The campaign tricks victims into installing a malicious backdoor plugin on their site. The phishing email claims to be from the WordPress team and warns of a Remote Code Execution vulnerability on the user's site with an identifier of CVE-2023-45124, which is not currently a valid CVE. The email prompts the victim to download a "Patch" plugin and install it. If the victim downloads the plugin and installs it on their WordPress site, the plugin is installed with a slug of wpress-security-wordpress and adds a malicious administrator user with the username wpsecuritypatch. The malicious plugin also includes functionality to ensure that this user remains hidden. 

In our shameless self-promotion segment, we highlight some of our recent work at GreyNoise Labs. We've been busy analyzing and documenting various cybersecurity threats and trends, and we're excited to share our findings with you. Be sure to check out our latest posts on the GreyNoise blog and sign up for our Noiseletter to stay up-to-date with our latest research.

We also discuss some recent vulnerabilities, including a Google Skia Integer Overflow Vulnerability (CVE-2023-6345), an ownCloud graphapi Information Disclosure Vulnerability (CVE-2023-49103), and two Apple Multiple Products WebKit vulnerabilities (CVE-2023-42917 and CVE-2023-42916). These vulnerabilities highlight the ongoing need for robust cybersecurity measures and the importance of staying informed about the latest threats.

Finally, we discuss a recent CISA alert about the Iranian military organization IRGC. IRGC-affiliated cyber actors using the persona "CyberAv3ngers" are actively targeting and compromising Israeli-made Unitronics Vision Series programmable logic controllers (PLCs). These PLCs are commonly used in the Water and Wastewater Systems (WWS) Sector and are additionally used in other industries including, but not limited to, energy, food and beverage manufacturing, and healthcare. The PLCs may be rebranded and appear as different manufacturers and companies. The authoring agencies urge all organizations, especially critical infrastructure organizations, to apply the recommendations listed in the Mitigations section of this advisory to mitigate risk of compromise from these IRGC-affiliated cyber actors.

Thank you for joining us for this episode of Storm⚡️Watch. We look forward to bringing you more insights into the world of cybersecurity in our next episode.

Episode Slides >>

Join our Community Slack >>

Learn more about GreyNoise >>

 

 

Chapter 01

Jan 2, 2026 ·11m

Chapter 02

Jan 1, 2026 ·7m

Chapter 03

Dec 31, 2025 ·14m

Chapter 04, Sec. 01-02

Dec 30, 2025 ·22m

Chapter 04, Sec. 03-04

Dec 29, 2025 ·17m

Chapter 05

Dec 28, 2025 ·16m

ESP - Enchanting Sorcery Productions ESP - Enchanting Sorcery Productions Long-form podcasts & conversations on Tabletop RPGs, Gaming, Anime & Pop Culture!Long-form Tabletop RPG discussion, reviews & deep dives from the lens of Intersectionality, facilitated by a Social Community of Queer Witches & “Dice Dragons.”D&D 5th Edition: Heavensfire (Homebrew), Storm Watch (MCDM: Kingdoms & Warfare), Into the Old Margreve (Kobold Press:Tales of the Old Margreve) and other One-Shots airs live on Twitch at Twitch.tv/EnchantingSorceryFor business or collaborative inquiries, please direct e-mail correspondence to [email protected] Storm Session Podcast Saylor Storm Reality becomes fantasy, or is that imagination turns into real life experience? I am fascinated by how frequently the line between reality and fantasy is crossed in my writing practice. Writing romance novels and podcasting is an astonishing way to play with something from real life and turning into something fun, playful and perhaps a bit twisted. How amusing it is to be able to take an idea and turn it into something real like a living character. My characters all experience real life joy and pain, reinvention, survival and victory. They share the process of evolution and expansion. The places that I write about are all real places where I have lived or visited, from the beaches of Malibu to the islands in Fiji and destinations in between, including the monastery in Dr. Selfish! My many personal interests are reflected in my stories and include fitness, wine, healthy foods (watch for salad cookbook coming soon). I am intrigued by the spiritual world and that of metaphysics. I The Reel Couple Podcast The Reel Couple Do you love a good ghost story? Are you interested by the paranormal or intrigued by stories of cryptoids or UFO's? Do you crave watching horror movies based on real life events? Well, look no more! We delve into mysterious stories of unexplained phenomenon and find THE best movies to watch based on these stories.The Reel Couple found a way to share their knowledge of the film industry AND have a date night by making their own podcast. What better way to get on each others nerves than sitting in front of microphones together for an hour every week!Sarcastic, funny, raw and honest. Support this podcast: https://anchor.fm/the-reel-couple/support Wrist Check Pod Wrist Check Podcast Wrist Check Pod is a weekly podcast connecting the inner circle of the global watch community through compelling stories, expert insights, and engaging discussions. Hosted by Perri and Rashawn, two close friends and watch enthusiasts. The podcast revolves around their appreciation for horology, culture, story, art, and design. It serves as a celebration of all things related to timekeeping, providing listeners with insights into new watch releases, industry updates, and engaging interviews with friends, fellow collectors, celebrities, and notable figures Follow us on Instagram @WristCheckPod
URL copied to clipboard!