

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Sep 7, 2021 • 5min
ISC StormCast for Tuesday, September 7th, 2021
Confluence Update
https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
https://www.jenkins.io/blog/2021/09/04/wiki-attacked/
ProxyShell Update
https://news.sophos.com/en-us/2021/09/03/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks/
RCE-0-Day for GhostScript 9.50
https://github.com/duc-nt/RCE-0-day-for-GhostScript-9.50
Netgear Switch Auth Bypass
https://kb.netgear.com/000063978/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Smart-Switches-PSV-2021-0140-PSV-2021-0144-PSV-2021-0145

Sep 3, 2021 • 14min
ISC StormCast for Friday, September 3rd, 2021
Attackers Will Always Abuse Major Events in our Lifes
https://isc.sans.edu/forums/diary/Attackers+Will+Always+Abuse+Major+Events+in+our+Lifes/27808/
Active Exploitation of Confluence Server CVE-2021-26084
https://www.rapid7.com/blog/post/2021/09/02/active-exploitation-of-confluence-server-cve-2021-26084/
GitHub Removing old Ciphers / Keys
https://github.blog/2021-09-01-improving-git-protocol-security-github/
Cisco Enterprise NFV Infrastructure Software Authentication Bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh
Hackers are Selling Tool to Hide Malware in GPUs
https://www.ehackingnews.com/2021/09/hackers-are-selling-tool-to-hide.html
Michael Beck: Cloud Forensics Triage Framework (CFTF)
https://www.sans.org/white-papers/40415/

Sep 2, 2021 • 6min
ISC StormCast for Thursday, September 2nd, 2021
STRRAT: A Java Based RAT That Doesn't Care if You Have Java
https://isc.sans.edu/forums/diary/STRRAT+a+Javabased+RAT+that+doesnt+care+if+you+have+Java/27798/
IPC360 Baby Monitor Vulnerability
https://www.bitdefender.com/files/News/CaseStudies/study/402/Bitdefender-PR-Whitepaper-VictureIPC-creat5590-en-EN.pdf
Annke Network Video Recorder Vulnerability
https://us-cert.cisa.gov/ics/advisories/icsa-21-238-02
ProxyWare Abuse
https://blog.talosintelligence.com/2021/08/proxyware-abuse.html

Sep 1, 2021 • 5min
ISC StormCast for Wednesday, September 1st, 2021
BrakTooth: Impacts, Implications and Next Steps
https://isc.sans.edu/forums/diary/BrakTooth+Impacts+Implications+and+Next+Steps/27802/
Fortress Home Security System Weakness
https://threatpost.com/fortress-home-security-remote-disarmament/169069/
PostgreSQL set_user Module Vulnerability
https://www.postgresql.org/about/news/set_user-201-released-2279/

Aug 31, 2021 • 6min
ISC StormCast for Tuesday, August 31st, 2021
Cryptocurrency Clipboard Swapper Delivered With Love
https://isc.sans.edu/forums/diary/Cryptocurrency+Clipboard+Swapper+Delivered+With+Love/27794/
ProxyToken Vulnerability in Exchange
https://www.zerodayinitiative.com/blog/2021/8/30/proxytoken-an-authentication-bypass-in-microsoft-exchange-server
LockFile Ransomware Evasion Tricks
https://thehackernews.com/2021/08/lockfile-ransomware-bypasses-protection.html

Aug 30, 2021 • 5min
ISC StormCast for Monday, August 30th, 2021
ChaosDB: Azure Cosmos Database Vulnerability
https://chaosdb.wiz.io
Phishing via Open Redirects
https://www.microsoft.com/security/blog/2021/08/26/widespread-credential-phishing-campaign-abuses-open-redirector-links/
Parallels Vulnerability
https://exchange.xforce.ibmcloud.com/vulnerabilities/208188
https://www.zerodayinitiative.com/advisories/ZDI-21-1000/

Aug 27, 2021 • 6min
ISC StormCast for Friday, August 27th, 2021
Cisco Advisories
https://tools.cisco.com/security/center/publicationListing.x
GETH DoS Vulnerability
https://github.com/ethereum/go-ethereum/releases/tag/v1.10.8
Confluence Security Advisory
https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
VMWare Updates
https://www.vmware.com/security/advisories.html

Aug 26, 2021 • 6min
ISC StormCast for Thursday, August 26th, 2021
There May Be Many More SPF Records Than We Might Expect
https://isc.sans.edu/forums/diary/There+may+be+many+more+SPF+records+than+we+might+expect/27786/
OpenSSL Update
https://www.openssl.org/news/vulnerabilities.html
F5 Update
https://support.f5.com/csp/article/K50974556
https://support.f5.com/csp/article/K41351250
SideWalk Backdoor
https://www.welivesecurity.com/2021/08/24/sidewalk-may-be-as-dangerous-as-crosswalk/

Aug 25, 2021 • 5min
ISC StormCast for Wednesday, August 25th, 2021
Attackers Hunting for Twilio Credentials
https://isc.sans.edu/forums/diary/Attackers+Hunting+For+Twilio+Credentials/27782/
Modified WhatsApp Spreading Malware
https://securelist.com/triada-trojan-in-whatsapp-mod/103679/
Privilege Escalation without Pluggin in Device
http://0xsp.com/security%20research%20&%20development%20(SRD)/local-administrator-is-not-just-with-razer-it-is-possible-for-all

Aug 24, 2021 • 6min
ISC StormCast for Tuesday, August 24th, 2021
Out of Band Phishing Using SMS Messages to Evade Network Detection
https://isc.sans.edu/forums/diary/Out+of+Band+Phishing+Using+SMS+messages+to+Evade+Network+Detection/27768/
Elevate Priviledges with Razer Mouse
https://twitter.com/j0nh4t/status/1429049506021138437
Realtek Vulnerabilites Exploited
https://securingsam.com/realtek-vulnerabilities-weaponized/
Exposed Microsoft Power Apps
https://www.upguard.com/breaches/power-apps


