

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jun 1, 2021 • 5min
ISC StormCast for Tuesday, June 1st, 2021
Malicious PowerShell Hosted on script.google.com
https://isc.sans.edu/forums/diary/Malicious+PowerShell+Hosted+on+scriptgooglecom/27468/
Sonicwall Advisory
https://www.sonicwall.com/support/product-notification/security-advisory-on-prem-sonicwall-network-security-manager-nsm-command-injection-vulnerability/210525121534120/
Hewlett Packard Enterprise Systems Insight Manger (SIM) Advisory
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us
Memory Protection Bypass in Siemens PLCs
https://claroty.com/2021/05/28/blog-research-race-to-native-code-execution-in-plcs/

May 28, 2021 • 7min
ISC StormCast for Friday, May 28th, 2021
AV evasion with 64-bit Executables
https://isc.sans.edu/forums/diary/All+your+Base+arenearly+equal+when+it+comes+to+AV+evasion+but+64bit+executables+are+not/27466/
Unpatches WebKit Vulnerablity in iOS/macOS
https://blog.theori.io/research/webkit-type-confusion/
VSCode Extension Vulnerabilities
https://snyk.io/blog/visual-studio-code-extension-security-vulnerabilities-deep-dive/
M1RACLES
https://m1racles.com

May 27, 2021 • 6min
ISC StormCast for Thursday, May 27th, 2021
A Survey of Bluetooth Vulnerabilities
https://isc.sans.edu/forums/diary/A+Survey+of+Bluetooth+Vulnerabilities+Trends/27460/
Google Chrome Update
https://chromereleases.googleblog.com/2021/05/stable-channel-update-for-desktop_25.html
Attacks on PDF Certification
https://www.pdf-insecurity.org
nginx vulnerability
https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/

May 26, 2021 • 5min
ISC StormCast for Wednesday, May 26th, 2021
Uncovering Shenenigans in an IP Address Block via Hurricane Electic's BGP Toolkit
https://isc.sans.edu/forums/diary/Uncovering+Shenanigans+in+an+IP+Address+Block+via+Hurricane+Electrics+BGP+Toolkit/27456/
VMware Advisory
https://www.vmware.com/security/advisories/VMSA-2021-0010.html
Trend Micro Bugs
https://blog.talosintelligence.com/2021/05/vuln-spotlight-trend-i.html

May 25, 2021 • 5min
ISC StormCast for Tuesday, May 25th, 2021
Apple Patches 0-Days
https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/
https://support.apple.com/en-us/HT201222
Bluetooth Vulnerabilities
https://kb.cert.org/vuls/id/799380
https://francozappa.github.io/about-bias/publication/antonioli-20-bias/antonioli-20-bias.pdf
NAGIOS Vulnerabilities
https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/

May 24, 2021 • 6min
ISC StormCast for Monday, May 24th, 2021
Serverless Phishing Campaign
https://isc.sans.edu/forums/diary/Serverless+Phishing+Campaign/27446/
Locking Kernel32.dll As Anti-Debugging Technique
https://isc.sans.edu/forums/diary/Locking+Kernel32dll+As+AntiDebugging+Technique/27444/
WinRM Vulnerable to http.sys Vulnerability
https://twitter.com/JimDinMN/status/1395071966487269376
Mozilla Firefox "Content-Type Confusion" Unsafe Code Execution
https://besteffortteam.it/mozilla-firefox-content-type-confusion-unsafe-code-execution/

May 21, 2021 • 20min
ISC StormCast for Friday, May 21st, 2021
New YouTube Video Series: Everything you ever wanted to know about DNS and more
https://isc.sans.edu/forums/diary/New+YouTube+Video+Series+Everything+you+ever+wanted+to+know+about+DNS+and+more/27440/
And Ransomware Just Got a Bit Meaner
https://isc.sans.edu/forums/diary/And+Ransomware+Just+Got+a+Bit+Meaner+yes+it+is+possible/27438/
Attackers Scanned for Exchange Servers Five Minutes after Patch Release
https://www.ehackingnews.com/2021/05/microsoft-exchange-bug-report-allowed.html
GPS For Authentication: Is the Juice Worth the Squeeze @sans_edu
https://www.sans.org/reading-room/whitepapers/authentication/gps-authentication-juice-worth-squeeze-40270

May 20, 2021 • 6min
ISC StormCast for Thursday, May 20th, 2021
May 2021 Forensic Contest: Answers and Analysis
https://isc.sans.edu/forums/diary/May+2021+Forensic+Contest+Answers+and+Analysis/27430/
CIS Controls V8
https://www.cisecurity.org/controls/v8/
Dell iDRAC 9 Security Update
https://www.dell.com/support/kbdoc/en-us/000186420/dsa-2021-082-dell-emc-idrac-9-security-update-for-improper-authentication-vulnerability
QNAP Pre-Auth Remote Code Execution in MuscStation/MalwareRemover
https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/

May 19, 2021 • 5min
ISC StormCast for Wednesday, May 19th, 2021
From RunDLL32 to JavaScript then PowerShell
https://isc.sans.edu/forums/diary/From+RunDLL32+to+JavaScript+then+PowerShell/27428/
New Pulse Secure VPN Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800/
Android Stalkerware Vulnerabilities
https://www.welivesecurity.com/2021/05/17/android-stalkerware-threatens-victims-further-exposes-snoopers-themselves/
Double Encrypting Ransomware
https://www.wired.com/story/ransomware-double-encryption/

May 18, 2021 • 6min
ISC StormCast for Tuesday, May 18th, 2021
Ransomware Defenses
https://isc.sans.edu/forums/diary/Ransomware+Defenses/27420/
AXA Stops Ransomware Payments
https://www.insurancejournal.com/news/international/2021/05/09/613255.htm
http.sys Proof of Concept
https://github.com/0vercl0k/CVE-2021-31166
Google/Mozilla colaborating on HTML Sanitizer API
https://wicg.github.io/sanitizer-api/#sanitizer-api
SANS Technology Institute Research Journal
https://www.sans.edu/cyber-research


