

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jan 4, 2021 • 4min
ISC StormCast for Monday, January 4th 2021
Traffic Analysis Quiz
https://isc.sans.edu/forums/diary/End+of+Year+Traffic+Analysis+Quiz/26940/
Zyxel Backdoor
https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html
Microsoft Source Code Accessed As a Result of SolarWinds Backdoor
https://msrc-blog.microsoft.com/2020/12/31/microsoft-internal-solorigate-investigation-update/

Dec 30, 2020 • 4min
ISC StormCast for Wednesday, December 30th 2020
Accessing Restricted Directory Listings via Your AV Solution
https://isc.sans.edu/forums/diary/Want+to+know+whats+in+a+folder+you+dont+have+a+permission+to+access+Try+asking+your+AV+solution/26932/
Coin Miner Malware Written in Go
https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/?fbclid=IwAR3eFiHCNoqr5mc2UAOcm8nocjUOjZn0cpcAiSoYmn__JtJfBbjqUUT1OwQ
AutoHotKey Credential Stealer
https://www.trendmicro.com/en_us/research/20/l/stealth-credential-stealer-targets-us-canadian-bank-customers.html

Dec 29, 2020 • 5min
ISC StormCast for Tuesday, December 29th 2020
Extending Android Device Compatibility for Let's Encrypt Certificates
https://letsencrypt.org/2020/12/21/extending-android-compatibility.html
Insufficient Patch for Windows 8.1/10 Print Spooler
https://bugs.chromium.org/p/project-zero/issues/detail?id=2096
Google Docs Vulnerability
https://savebreach.com/stealing-private-documents-through-a-google-docs-bug/
CCC Conferences Virtual
https://streaming.media.ccc.de/rc3

Dec 28, 2020 • 6min
ISC StormCast for Monday, December 28th 2020
base64dump.py Supported Encodings
https://isc.sans.edu/forums/diary/base64dumppy+Supported+Encodings/26924/
String Analysis and Maldocs
https://isc.sans.edu/forums/diary/Quickie+String+Analysis+Maldocs/26922/
Malicious Word Document Delivering an Octopus Backdoor
https://isc.sans.edu/forums/diary/Malicious+Word+Document+Delivering+an+Octopus+Backdoor/26918/
Analysis Dridex Dropper, IoC extraction
https://isc.sans.edu/forums/diary/Analysis+Dridex+Dropper+IoC+extraction+guest+diary/26920/
AT&T Outage due to Nashville Explosion
https://about.att.com/pages/disaster_relief/nashville.html
SolarWinds SUPERNOVA Malware / API Vulnerability
https://www.solarwinds.com/securityadvisory
Citrix ADC DDoS Attack
https://support.citrix.com/article/CTX289674
Crowdstrike Reporting Tool for Azure
https://github.com/CrowdStrike/CRT

Dec 23, 2020 • 4min
ISC StormCast for Wednesday, December 23rd 2020
Malware Victim Selection Through WiFi Identification
https://isc.sans.edu/forums/diary/Malware+Victim+Selection+Through+WiFi+Identification/26910/
New Treck IP Stack Vulnerabilities
https://treck.com/vulnerability-response-information/
Detecting Treck IP Stack
https://github.com/Forescout/project-memoria-detector

Dec 22, 2020 • 6min
ISC StormCast for Tuesday, December 22nd 2020
What's The Deal With Openportstats.com?
https://isc.sans.edu/forums/diary/Whats+the+deal+with+openportstatscom/26912/
Dell Wyse ThinOS 8.6 Security Update
https://www.dell.com/support/kbdoc/en-hr/000180768/dsa-2020-281
SolarWinds 2nd Backdoor
https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/
SolarWinds Domains
https://securelist.com/sunburst-connecting-the-dots-in-the-dns-requests/99862/

Dec 21, 2020 • 6min
ISC StormCast for Monday, December 21st 2020
A slightly optimistic tale of how patching went for CVE-2019-19781
https://isc.sans.edu/forums/diary/A+slightly+optimistic+tale+of+how+patching+went+for+CVE201919781/26900/
Heads-up: VirusTotal Functionality in Sysinternals Tools Not Working
https://isc.sans.edu/forums/diary/Headsup+VirusTotal+Functionality+in+Sysinternals+Tools+Not+Working/26906/
Kasachstan: Browsers Block Government Certificate Authority
https://www.zdnet.com/article/apple-google-microsoft-and-mozilla-ban-kazakhstans-mitm-https-certificate/
5G Vulnerabilities
https://positive-tech.com/about/news/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication/
Bouncy Castle BCrypt Password Verification Error
https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/

Dec 18, 2020 • 6min
ISC StormCast for Friday, December 18th 2020
Token Authentication Requirements for Git Operations
https://github.blog/2020-12-15-token-authentication-requirements-for-git-operations/
Google Attempting to Speed Up OS Update Adoption
https://android-developers.googleblog.com/2020/12/treble-plus-one-equals-four.html
Trend Micro InterScan Web Security Virtual Appliance Vulnerability
https://success.trendmicro.com/solution/000283077
Malicios Browser Extensions
https://blog.avast.com/malicious-browser-extensions-avast

Dec 17, 2020 • 6min
ISC StormCast for Thursday, December 17th 2020
Cloud DNS Logs
https://isc.sans.edu/forums/diary/DNS+Logs+in+Public+Clouds/26892/
Solarwinds Update
https://www.heise.de/news/l-f-SolarWinds-Backdoor-Hersteller-sorgte-fuer-Ausnahmen-von-AV-Ueberwachung-4990910.html
https://krebsonsecurity.com/2020/12/malicious-domain-in-solarwinds-hack-turned-into-killswitch/
Hewlett Packard Enterprise Systems Insight Manager (SIM) Vulnerability
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us
SAP HANA SAML Validation Weakness
https://www.secureauth.com/blog/secureauth-uncovers-saml-validation-weakness-in-sap-hana/

Dec 16, 2020 • 6min
ISC StormCast for Wednesday, December 16th 2020
Analyzing A Fireeye Maldoc
https://isc.sans.edu/forums/diary/Analyzing+FireEye+Maldocs/26882/
Didier Stevens: 2020 Difference Makers
https://www.sans.org/webcasts/2020-difference-makers-awards-ceremony-117154
F5 Big IP Vulnerabilities
https://support.f5.com/csp/article/K20984059
https://support.f5.com/csp/article/K42696541
https://support.f5.com/csp/article/K37960100
Google Outage
https://status.cloud.google.com/incident/zall/20013
GoLang XML Parser Vulnerabilities
https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/


