
SANS ISC Stormcast: macOS Network Traffic Analysis, Cisco Email Gateway SQL Injection, and Active Directory Security Guidance
Johannes Ullrich from the SANS Internet Storm Center recorded this September 16, 2020 episode covering three main cybersecurity topics. He analyzed network traffic from a fresh macOS boot, noting minimal changes from previous versions including IPv6 duplicate address discovery with nonce options, DNS over HTTPS discovery attempts, and connections to albert.apple.com for device activation which uses TLS certificate pinning. Cisco disclosed a SQL injection vulnerability in their Secure Email Gateway that is already being exploited in the wild, allowing attackers to gain arbitrary code execution as root by simply sending an email containing SQL code. CISA and partner agencies released a 70-page document on detecting and mitigating Active Directory compromises, covering misconfigurations, prevention methods, and log analysis for detecting compromises. NIST published new inter-agency guidance on protecting tokens and assertions from forgery, theft, and misuse, particularly focused on non-human identities and API access management.