

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jun 15, 2021 • 6min
ISC StormCast for Tuesday, June 15th, 2021
Apple iOS 12.5.4 Security Update
https://support.apple.com/en-us/HT212548
NIST.gov DNS Issues
https://puck.nether.net/pipermail/outages/2021-June/013670.html
Akkadian Provisioning Manager Multiple Vulnerabilities
https://www.rapid7.com/blog/post/2021/06/08/akkadian-provisioning-manager-multiple-vulnerabilities-disclosure/
Bypassing MFA in Exchange Online
https://www.microsoft.com/security/blog/2021/06/14/behind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure/

Jun 14, 2021 • 7min
ISC StormCast for Monday, June 14th, 2021
EoL SonicWall SRA 4600 VPN Gateways Exploited in Current Attacks
https://isc.sans.edu/forums/diary/Sonicwall+SRA+4600+Targeted+By+an+Old+Vulnerability/27518/
Older Fortinet Vulnerability Still Exploited
https://isc.sans.edu/forums/diary/Fortinet+Targeted+for+Unpatched+SSL+VPN+Discovery+Activity/27520/
PrivacyMic: Utlizing Inaudible Frequencies for Privacy Preserving Daily Activity Recognition
http://alansonsample.com/publications/docs/2021%20-%20CHI%20-%20PrivacyMic-%20Utilizing%20Inaudible%20Frequencies%20for%20Privacy%20Preserving%20Daily%20Activity%20Recognition.pdf
Linux Vulnerability in polkit
https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/

Jun 11, 2021 • 7min
ISC StormCast for Friday, June 11th, 2021
Are Cookie Banners a Waste of Time or a Complete Waste of Time?
https://isc.sans.edu/forums/diary/Are+Cookie+Banners+a+Waste+of+Time+or+a+Complete+Waste+of+Time/27436/
Citrix Application Delivery Controller Vulnerability
https://support.citrix.com/article/CTX297155
VoIP Monitor GUI XSS
https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/
Denial of Service Vulnerabilitiesin RabbitMQ, EMQ X,and VeneMQ
https://www.synopsys.com/blogs/software-security/cyrc-advisory-rabbitmq-emqx-vernemq/

Jun 10, 2021 • 6min
ISC StormCast for Thursday, June 10th, 2021
Architecture, Compilers and Black Magic
https://isc.sans.edu/forums/diary/Architecture+compilers+and+black+magic+or+what+else+affects+the+ability+of+AVs+to+detect+malicious+files/27510/
ALPACA TLS Attack
https://alpaca-attack.com/ALPACA.pdf
Google Chrome Update
https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html

Jun 9, 2021 • 7min
ISC StormCast for Wednesday, June 9th, 2021
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+June+2021+Patch+Tuesday/27506/
PuzzleMaker Attacks With Chrome Zero-Day Exploit Chain
https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/
Intel Patches
https://www.intel.com/content/www/us/en/security-center/default.html
Adobe Updates
https://helpx.adobe.com/security.html
Let's Encrypt and CentOS 7
https://blog.devgenius.io/lets-encrypt-change-affects-openssl-1-0-x-and-centos-7-49bd66016af3

Jun 8, 2021 • 6min
ISC StormCast for Tuesday, June 8th, 2021
Amazon Sidewalk
https://isc.sans.edu/forums/diary/Amazon+Sidewalk+Cutting+Through+the+Hype/27502/
Windows Container Malware
https://unit42.paloaltonetworks.com/siloscape/
Darkside Ransom Confiscated
https://www.documentcloud.org/documents/20799023-affidavit-1-in-application-by-the-united-states-for-a-seizure-warrant-for-one-account-for-investigation-of-18-usc-ss-981a1a-and-other-offenses-nd-cal-321-mj-70945

Jun 7, 2021 • 5min
ISC StormCast for Monday, June 7th, 2021
Strange Goings on With Port 37
https://isc.sans.edu/forums/diary/Strange+goings+on+with+port+37/27496/
QNAP Video Station RCE Vulnerability
https://www.qnap.com/de-de/security-advisory/qsa-21-21
Updated GitHub Policy
https://github.blog/2021-06-04-updates-to-our-policies-regarding-exploits-malware-and-vulnerability-research/
Cisco WebEx Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-player-kOf8zVT
VMWare vCenter Server Vulnerability Actively Exploited
https://thehackernews.com/2021/06/alert-critical-rce-bug-in-vmware.html

Jun 4, 2021 • 6min
ISC StormCast for Friday, June 4th, 2021
Script to Test CIS Zoom Benchmark
https://github.com/turbot/steampipe-mod-zoom-compliance
F5 BIG-IP Edge Client for Windows Vulnerability
https://support.f5.com/csp/article/K20346072
Fancy Product Designer Wordpress Plugin Vulnerability
https://www.welivesecurity.com/2021/06/03/zero-day-popular-wordpress-plugin-exploited-take-over-websites/
WordPress Pushes Jetpack Plugin Patch
https://www.bleepingcomputer.com/news/security/wordpress-force-installs-jetpack-security-update-on-5-million-sites/
We.Lock Vulnerability
https://github.com/CriticalSecurity/welock

Jun 3, 2021 • 5min
ISC StormCast for Thursday, June 3rd, 2021
Realtek RTL8170C Vulnerabilities
https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day
Huawei LTE USB Stick E3372 Vulnerablity
https://www.theregister.com/2021/06/02/huawei_lte_usb_stick_vulnerability/
NortonLifeLock Crypto
https://investor.nortonlifelock.com/About/Investors/press-releases/press-release-details/2021/NortonLifeLock-Unveils-Norton-Crypto/default.aspx
OpenPGP RNP Patch
https://www.rnpgp.org/advisories/ri-2021-001/

Jun 2, 2021 • 6min
ISC StormCast for Wednesday, June 2nd, 2021
Guildma is now using Finger and Signed Binary Proxy Execution to Evade Defenses
https://isc.sans.edu/forums/diary/Guildma+is+now+using+Finger+and+Signed+Binary+Proxy+Execution+to+evade+defenses/27482/
Bypassing Protected Folders Protections
https://dl.acm.org/doi/10.1145/3431286
Firefox 89 Released
https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/
Microsoft Edge Will make https default
https://blogs.windows.com/msedgedev/2021/06/01/available-for-preview-automatic-https-helps-keep-your-browsing-more-secure/


