DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches
SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches

SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches

Update: 2025-12-15
Share

Description



Abusing DLLs EntryPoint for the Fun

DLLs will not just execute code when some of their functions are called, but also as they are loaded.

https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562

Apple Patches Everything: December 2025 Edition

Apple released patches for all of its operating systems, fixing two already exploited vulnerabilities.

ClickFix Attacks Still Using the Finger

ClickFix Attacks Still Using the Finger

Two examples of ClickFix attacks abusing the finger protocol to load additional malware

Denial of Service and Source Code Exposure in React Server Components

Denial of Service and Source Code Exposure in React Server Components

After last week's critical patch, three more, but less critical, vulnerabilities were identified in React Server Components.

https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components
Comments 
loading
In Channel
loading
00:00
00:00
1.0x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches

SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches

Dr. Johannes B. Ullrich