

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Oct 5, 2021 • 6min
ISC StormCast for Tuesday, October 5th, 2021
Facebook Outage
https://isc.sans.edu/forums/diary/Facebook+Outage+Yes+its+DNS+sort+of+A+super+quick+analysis+of+what+is+going+on/27900/
Boutique "Dark" Botnet Hunting for Crumbs
https://isc.sans.edu/forums/diary/Boutique+Dark+Botnet+Hunting+for+Crumbs/27898/
Apache Airflow May Leak Credentials
https://www.intezer.com/blog/cloud-security/misconfigured-airflows-leak-credentials/

Oct 4, 2021 • 6min
ISC StormCast for Monday, October 4th, 2021
A New Tool To Add to Your LOLBAS List: cvtres.exe
https://isc.sans.edu/forums/diary/New+Tool+to+Add+to+Your+LOLBAS+List+cvtresexe/27892/
Google Chrome Continuing Updates
https://support.google.com/chrome/answer/95414?hl=en&co=GENIE.Platform%3DDesktop
Cyber Security Awareness Month
https://www.sans.org/security-awareness-training/resources/
https://isc.sans.edu/tag.html?tag=csam
FCC Attempts to Fight SIM Swapping
https://docs.fcc.gov/public/attachments/DOC-376199A1.pdf
MacOS Gatekeeper Bypass
https://labs.f-secure.com/blog/the-discovery-of-cve-2021-1810/

Oct 1, 2021 • 15min
ISC StormCast for Friday, October 1st, 2021
Visa/Apple Express Transit Relay Attack
https://www.bbc.com/news/technology-58719891
FluBot Offering Fake FlutBot Protection
https://twitter.com/CERTNZ/status/1443701853665980440
Undetected Azure Active Directory Brute-Force Attacks
https://www.secureworks.com/research/undetected-azure-active-directory-brute-force-attacks
SANS.edu Student Christopher DeWees: Expired Domain Dumpster Diving https://www.sans.edu/cyber-research/40505/

Sep 30, 2021 • 5min
ISC StormCast for Thursday, September 30th, 2021
Keeping Track of Time: Network Time Protocol and GPSD Bug
https://isc.sans.edu/forums/diary/Keeping+Track+of+Time+Network+Time+Protocol+and+a+GPSD+Bug/27886/
Apple Airtags Stored XSS
https://medium.com/@bobbyrsec/zero-day-hijacking-icloud-credentials-with-apple-airtags-stored-xss-6997da43a216
CISA/NSA Guidance To Configure VPNs
https://media.defense.gov/2021/Sep/28/2002863184/-1/-1/0/CSI_SELECTING-HARDENING-REMOTE-ACCESS-VPNS-20210928.PDF
Facebook Open Sourcing "Mariana Trench" Tool To Analyze Android and Java Apps
https://engineering.fb.com/2021/09/29/security/mariana-trench/

Sep 29, 2021 • 6min
ISC StormCast for Wednesday, September 29th, 2021
TLS 1.3 and SSL: The Current State of Affairs
https://isc.sans.edu/forums/diary/TLS+13+and+SSL+the+current+state+of+affairs/27882/
EFF Discontinues HTTPS Everywhere Plugin
https://www.eff.org/deeplinks/2021/09/https-actually-everywhere
Malicious CryptoCoin Wallet
https://discourse.mozilla.org/t/got-hacked-by-the-add-on-called-safepal-wallet/85797
Microsoft Automates Exchange Mitigations
https://techcommunity.microsoft.com/t5/exchange-team-blog/new-security-feature-in-september-2021-cumulative-update-for/ba-p/2783155

Sep 28, 2021 • 6min
ISC StormCast for Tuesday, September 28th, 2021
Trend Micro ServerProtect Authentication Bypass Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-21-1115/
Let's Encrypt Root CA Expiration
https://community.letsencrypt.org/t/production-chain-changes/150739
ERMAC Android Malware
https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html
QNAP Vulnerabilities
https://www.qnap.com/en/security-advisory/QSA-21-35

Sep 27, 2021 • 6min
ISC StormCast for Monday, September 27th, 2021
Mobile Device Inventory via Active Sync
https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Your+Users+Mobile+Devices+Simple+Inventory/27868/
Autodiscover Attacks
https://autodiscover-vulnerable-tlds.com
https://wiki.mozilla.org/Public_Suffix_List
https://www.guardicore.com/labs/autodiscovering-the-great-leak/
Three More 0-Day Vulnerabilities in iOS
https://habr.com/en/post/579714/
original russian version: https://habr.com/en/post/579716/
Cisco CAPWAP Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-capwap-rce-LYgj8Kf
Sonicwall SMA 100 Series Vulnerablity
https://www.sonicwall.com/support/product-notification/security-notice-critical-arbitrary-file-delete-vulnerability-in-sonicwall-sma-100-series-appliances/210819124854603/

Sep 24, 2021 • 6min
ISC StormCast for Friday, September 24th, 2021
Excel Recipe: Some VBA Code with a Touch of Excel4 Macro
https://isc.sans.edu/forums/diary/Excel+Recipe+Some+VBA+Code+with+a+Touch+of+Excel4+Macro/27864/
Windows Platform Binary Table Weakness
https://eclypsium.com/2021/09/20/everyone-gets-a-rootkit/
Apple Patches Older iOS/MacOS Versions
https://support.apple.com/en-us/HT201222
Broken Digital Signatures Used to Foil Malware Detection
https://blog.google/threat-analysis-group/financially-motivated-actor-breaks-certificate-parsing-avoid-detection/

Sep 23, 2021 • 7min
ISC StormCast for Thursday, September 23rd, 2021
An XML-Obfustcated Office Document (CVE-2021-40444)
https://isc.sans.edu/forums/diary/An+XMLObfuscated+Office+Document+CVE202140444/27860/
Exchange Autodiscovering Leaks Credentials
https://www.guardicore.com/labs/autodiscovering-the-great-leak/
Nagios Vulnerabilities
https://claroty.com/2021/09/21/blog-research-securing-network-management-systems-nagios-xi/
Apple Deprecating TLS 1.0/1.1
https://developer.apple.com/news/?id=bv8ur34d

Sep 22, 2021 • 6min
ISC StormCast for Wednesday, September 22nd, 2021
A First Look at Apple's iOS 15 "Private Relay" feature
https://isc.sans.edu/forums/diary/A+First+Look+at+Apples+iOS+15+Private+Relay+feature/27858/
macOS Finder Security Feature Bypass Leads to Possible RCE
https://ssd-disclosure.com/ssd-advisory-macos-finder-rce/
VMWare vCenter Advisory
https://blogs.vmware.com/vsphere/2021/09/vmsa-2021-0020-what-you-need-to-know.html
NetGear Circle Parental Control Vulnerablity
https://blog.grimm-co.com/2021/09/mama-always-told-me-not-to-trust.html


