

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jun 28, 2021 • 6min
ISC StormCast for Monday, June 28th, 2021
Increase in UDP Port 389 Scans (LDAP/AD)
https://isc.sans.edu/forums/diary/Is+this+traffic+bAD/27566/
CD/DVD Destruction
https://isc.sans.edu/forums/diary/DIY+CDDVD+Destruction/27572/
Zyxel Exploits
https://twitter.com/JAMESWT_MHT/status/1407987022170578946
https://kb.zyxel.com/KB/searchArticle!viewDetail.action?articleOid=018137&lang=EN
Cisco Vulnerability Exploited
https://threatpost.com/cisco-asa-bug-exploited-poc/167274/
Microsoft Signs Netfilter Rootkit
https://www.gdatasoftware.com/blog/microsoft-signed-a-malicious-netfilter-rootkit

Jun 25, 2021 • 6min
ISC StormCast for Friday, June 25th, 2021
Do You Like Cookies? Some are for sale!
https://isc.sans.edu/forums/diary/Do+you+Like+Cookies+Some+are+for+sale/27558/
A supply-chain breach: Taking over an Atlassian account
https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/23175805/Atlassian-ATO-CPR-blog-FINAL.pdf
Dell Bios Connect Vulnerability
https://eclypsium.com/2021/06/24/biosdisconnect/
ATM Jackpotting via NFC
https://www.wired.com/story/atm-hack-nfc-bugs-point-of-sale/

Jun 24, 2021 • 6min
ISC StormCast for Thursday, June 24th, 2021
DNS Name Server Hijack Attack
https://www.darkreading.com/vulnerabilities---threats/new-dns-name-server-hijack-attack-exposes-businesses-government-agencies/d/d-id/1341377
Paloalto Cortex XSOAR Vulnerablity
https://security.paloaltonetworks.com/CVE-2021-3044
VMWare Carbon Black App Control Authentication Bypass
https://www.vmware.com/security/advisories/VMSA-2021-0012.html?
Standing With Security Researchers Against Misuse of the DMCA
https://www.eff.org/deeplinks/2021/06/dmca-security-researcher-statement

Jun 23, 2021 • 6min
ISC StormCast for Wednesday, June 23rd, 2021
Phishing asking recipients not to report abuse
https://isc.sans.edu/forums/diary/Phishing+asking+recipients+not+to+report+abuse/27556/
PyPi Cryptomining Malware
https://blog.sonatype.com/sonatype-catches-new-pypi-cryptomining-malware-via-automated-detection
Dovecot TLS Implementation Vulnerability
https://hackerone.com/reports/1204962
(see the link to the PDF for more details)
Sonicwall Patch Incomplete
https://www.tripwire.com/state-of-security/featured/analyzing-sonicwalls-unsuccessful-fix-for-cve-2020-5135/

Jun 22, 2021 • 5min
ISC StormCast for Tuesday, June 22nd, 2021
Attack and Defend: Distributed Web Applications (free Webcast)
https://www.sans.org/webcasts/attack-defend-modern-distributed-applications-119610
Darkside Impersonators
https://www.helpnetsecurity.com/2021/06/21/impersonating-darkside/
Tesla RAT COVID-19 Vaccination Phish
https://threatpost.com/agent-tesla-covid-vax-phish/167082/
Tor Browser Update
https://www.bleepingcomputer.com/news/security/tor-browser-fixes-vulnerability-that-tracks-you-using-installed-apps/
Schneider PowerLogic Vulnerabilities
https://www.ehackingnews.com/2021/06/six-major-flaws-identified-in-schneider.html
AutoCAD Update
https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004

Jun 21, 2021 • 6min
ISC StormCast for Monday, June 21st, 2021
Network Forensics on Azure VMs (Part #2)
https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+2/27538/
Google Open Redirect Being Abused
https://isc.sans.edu/forums/diary/Open+redirects+and+why+Phishers+love+them/27542/
Easy Access to the NIST RDS Database
https://isc.sans.edu/forums/diary/Easy+Access+to+the+NIST+RDS+Database/27544/
iOS Wifi Bug
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
NSA VoIP Security Guide
https://media.defense.gov/2021/Jun/17/2002744054/-1/-1/1/CTR_DEPLOYING%20SECURE%20VVOIP%20SYSTEMS.PDF

Jun 18, 2021 • 6min
ISC StormCast for Friday, June 18th, 2021
Network Forensics on Azure VMs
https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+1/27536/
Fake Ledger Hardware Wallets
https://www.ledger.com/phishing-campaigns-status#phishing-campaigns
https://www.reddit.com/r/ledgerwallet/comments/o154gz/package_from_ledger_is_this_legit/
Zoll Defibrilator Dashboard Vulnerability
https://us-cert.cisa.gov/ics/advisories/icsma-21-161-01
Akamai Prolexic Outage
https://threatpost.com/hiccup-akamais-ddos-outages/167004/

Jun 17, 2021 • 5min
ISC StormCast for Thursday, June 17th, 2021
June 2021 Forensic Quiz
https://isc.sans.edu/forums/diary/June+2021+Forensic+Contest/27532/
ThroughTek IP Camera SDK Vulnerability
https://www.nozominetworks.com/blog/new-iot-security-risk-throughtek-p2p-supply-chain-vulnerability/
Peleoton Insecure Boot Vulnerability
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/a-new-program-for-your-peloton-whether-you-like-it-or-not/
Microsoft Defender for Endpoint Detecting Jailbroken Devices
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-new-capabilities-on-android-and-ios/ba-p/2442730

Jun 16, 2021 • 6min
ISC StormCast for Wednesday, June 16th, 2021
Multi Perimeter Device Exploit Mirai Version Hunting For Sonicwall, DLink, Cisco and more
https://isc.sans.edu/forums/diary/Multi+Perimeter+Device+Exploit+Mirai+Version+Hunting+For+Sonicwall+DLink+Cisco+and+more/27528/
Google Open Sourcing Homomorphic Encrypion Libraries
https://developers.googleblog.com/2021/06/our-latest-updates-on-fully-homomorphic-encryption.html
Stealing Tokens, emails, files and more in Microsoft Teams
https://medium.com/tenable-techblog/stealing-tokens-emails-files-and-more-in-microsoft-teams-through-malicious-tabs-a7e5ff07b138

Jun 15, 2021 • 6min
ISC StormCast for Tuesday, June 15th, 2021
Apple iOS 12.5.4 Security Update
https://support.apple.com/en-us/HT212548
NIST.gov DNS Issues
https://puck.nether.net/pipermail/outages/2021-June/013670.html
Akkadian Provisioning Manager Multiple Vulnerabilities
https://www.rapid7.com/blog/post/2021/06/08/akkadian-provisioning-manager-multiple-vulnerabilities-disclosure/
Bypassing MFA in Exchange Online
https://www.microsoft.com/security/blog/2021/06/14/behind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure/


