

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Aug 9, 2021 • 5min
ISC StormCast for Monday, August 9th, 2021
Malicious Microsoft Word Remains A Key Infection Vector
https://isc.sans.edu/forums/diary/Malicious+Microsoft+Word+Remains+A+Key+Infection+Vector/27716/
Malware Bazaar Daily Download
https://isc.sans.edu/forums/diary/MALWARE+Bazaar+Download+daily+malware+batches/27728/
Go/Rust IP Address Validation Vulnerability
https://github.com/rust-lang/rust/pull/83652
Facial Recognition "Master Keys"
https://arxiv.org/pdf/2108.01077.pdf
Pulse Secure Patch Bypass
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44858
Hadoop ResourceManager Vulnerability Exploited
https://blog.netlab.360.com/wei-xie-kuai-xun-teamtntxin-huo-dong-tong-guo-gan-ran-wang-ye-wen-jian-ti-gao-chuan-bo-neng-li/

Aug 6, 2021 • 15min
ISC StormCast for Friday, August 6th, 2021
Cisco Patches Unauthencticated RCE in RV340/345 devices
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv340-cmdinj-rcedos-pY8J3qfy
Telegram Flawed Self Destruct in MacOS
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/telegram-self-destruct-not-always/
Significant Vulnerabilities in MacOS Privacy Protections
https://www.darkreading.com/application-security/researchers-find-significant-vulnerabilities-in-mac-os-privacy-protections
Windows Hello Bypass
https://threatpost.com/microsofts-patch-windows-hello-faulty/168392/
STI Student: James Casteel; Content Security Policy Bypass: Exploiting Misconfigurations https://www.sans.org/white-papers/40380

Aug 5, 2021 • 6min
ISC StormCast for Thursday, August 5th, 2021
Pivoting and Hunting for Shenanigans from a Reported Phishing Domain
https://isc.sans.edu/forums/diary/Pivoting+and+Hunting+for+Shenanigans+from+a+Reported+Phishing+Domain/27710/
NichStack TCP/IP Vulnerabilities
https://jfrog.com/blog/infrahalt-14-new-security-vulnerabilities-found-in-nichestack/
Securing the Cloud
https://www.sans.org/newsletters/ouch/securely-using-the-cloud/
Lockbit Recruiting Insiders
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-recruiting-insiders-to-breach-corporate-networks/
Sneaky Phishing Hittin Office 365 Users
https://www.ehackingnews.com/2021/08/microsoft-warns-office-365-users-of.html

Aug 3, 2021 • 5min
ISC StormCast for Wednesday, August 4th, 2021
2FA Issues
https://isc.sans.edu/forums/diary/Three+Problems+with+Two+Factor+Authentication/27704/
Crazy Smishing
https://isc.sans.edu/forums/diary/Is+this+the+Weirdest+Phishing+SMishing+Attempt+Ever/27706/
Google Chrome Update
https://chromereleases.googleblog.com/2021/08/the-stable-channel-has-been-updated-to.html
https://www.bleepingcomputer.com/news/google/google-chrome-to-no-longer-show-secure-website-indicators/
Google Android Update
https://source.android.com/security/bulletin/2021-08-01?hl=en
DoD/NSA Publichses Kubernetes Hardening Guides
https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF

Aug 3, 2021 • 6min
ISC StormCast for Tuesday, August 3rd, 2021
Unsolicited DNS Queries
https://isc.sans.edu/forums/diary/Unsolicited+DNS+Queries/27694/
Changing BAT Files on the Fly
https://isc.sans.edu/forums/diary/Changing+BAT+Files+On+The+Fly/27700/
Empty NPM Package has Over 700,000 Downloads
https://www.bleepingcomputer.com/news/software/empty-npm-package-has-over-700-000-downloads-heres-why/
Blocking PetitPotam with netsh RPC Filters
https://twitter.com/gentilkiwi/status/1421949715986403329
Pneumatic Tube Vulnerabilities
https://www.blackhat.com/us-21/briefings/schedule/index.html#a-hole-in-the-tube-uncovering-vulnerabilities-in-critical-infrastructure-of-healthcare-facilities-23546

Aug 1, 2021 • 5min
ISC StormCast for Sunday, August 1st, 2021
Infected With a .reg File
https://isc.sans.edu/forums/diary/Infected+With+a+reg+File/27692/
Excessive Exchange Permissions (Patched)
https://bugs.chromium.org/p/project-zero/issues/detail?id=2186
Node.JS July 2021 Security Releases
https://nodejs.org/en/blog/vulnerability/july-2021-security-releases-2/
Malicious PyPi Packages
https://jfrog.com/blog/malicious-pypi-packages-stealing-credit-cards-injecting-code/
REvil / Darkside May be Back as Blackmatter
https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/

Jul 30, 2021 • 6min
ISC StormCast for Friday, July 30th, 2021
Malicious Content Delivered Trhough archive.org
https://isc.sans.edu/forums/diary/Malicious+Content+Delivered+Through+archiveorg/27688/
A Large-Scale Security-Oriented Static Analysis of Python Packages in PyPI
https://arxiv.org/abs/2107.12699
Crimea "manifesto" deploys VBA Rat using double attack vectors
https://blog.malwarebytes.com/threat-intelligence/2021/07/crimea-manifesto-deploys-vba-rat-using-double-attack-vectors/

Jul 29, 2021 • 9min
ISC StormCast for Thursday, July 29th, 2021
A Sextortion E-Mail From ... IT Support?!
https://isc.sans.edu/forums/diary/A+sextortion+email+fromIT+support/27682/
AV-Test Compares Android Anti-Virus Software
https://www.av-test.org/en/news/15-security-apps-for-android-in-an-endurance-test/
Oscorp evolves into UBEL: Advanced Android Malware
https://www.cleafy.com/cleafy-labs/ubel-oscorp-evolution
QOMPLX Reboots Punkspider
https://www.globenewswire.com/da/news-release/2021/07/20/2265860/0/en/QOMPLX-Reboots-Punkspider.html
AFRINIC IPv4 Address Heist
https://lists.afrinic.net/pipermail/community-discuss/2021-July/004122.html

Jul 28, 2021 • 7min
ISC StormCast for Wednesday, July 28th, 2021
Details about CVE-2021-30807. (Patch released Monday for MacOS/iOS)
https://saaramar.github.io/IOMobileFrameBuffer_LPE_POC/
Zimbra 8.8.15 XSS and SSRF Vulnerability
https://blog.sonarsource.com/zimbra-webmail-compromise-via-email
LockBit Ransomware Uses Group Policies
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-automates-windows-domain-encryption-via-group-policies/
Microsoft Extending SafeLinks to Teams
https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/microsoft-teams-gets-more-phishing-protection/ba-p/2585559

Jul 27, 2021 • 6min
ISC StormCast for Tuesday, July 27th, 2021
Recovering Malspam Password
https://isc.sans.edu/forums/diary/Failed+Malspam+Recovering+The+Password/27674/
Apple Patches 0-Day
https://support.apple.com/en-us/HT201222
Attackers Adopt Exotic Programming Languages
https://blogs.blackberry.com/en/2021/07/old-dogs-new-tricks-attackers-adopt-exotic-programming-languages
LemonDuck/LemonCat Coinminers Going Multi-OS
https://www.microsoft.com/security/blog/2021/07/22/when-coin-miners-evolve-part-1-exposing-lemonduck-and-lemoncat-modern-mining-malware-infrastructure/
GitHub Expending Supply Chain Security Support to Go
https://github.blog/2021-07-22-github-supply-chain-security-features-go-community/


