

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Dec 15, 2020 • 7min
ISC StormCast for Tuesday, December 15th 2020
SolarWinds Followup
https://isc.sans.edu/forums/diary/SolarWinds+Breach+Used+to+Infiltrate+Customer+Networks+Solarigate/26884/
https://sansurl.com/solarwinds
Apple Updates Everything
https://support.apple.com/en-us/HT201222
Sophos and Reversing Labs Release 20 Million Malware Samples
https://github.com/sophos-ai/SOREL-20M

Dec 14, 2020 • 6min
ISC StormCast for Monday, December 14th 2020
SolarWinds Compromise
https://isc.sans.edu/forums/diary/SolarWinds+Breach+Used+to+Infiltrate+Customer+Networks+Solarigate/26884/
Writing Yara Rules for Fun and Profit: Notes form the FireEye Breach Countermeasures
https://isc.sans.edu/forums/diary/Writing+Yara+Rules+for+Fun+and+Profit+Notes+from+the+FireEye+Breach+Countermeasures/26870/
Flash Player EoL
https://helpx.adobe.com/flash-player/release-note/fp_32_air_32_release_notes.html
Subway Marketing System Hacked to Send TrickBot Malware Emails
https://www.bleepingcomputer.com/news/security/subway-marketing-system-hacked-to-send-trickbot-malware-emails/

Dec 11, 2020 • 13min
ISC StormCast for Friday, December 11th 2020
Python Backdoor Talking to a C2 Through Ngrok
https://isc.sans.edu/forums/diary/Python+Backdoor+Talking+to+a+C2+Through+Ngrok/26866/
Cisco Releases Improved Patch for Jabber Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-ZktzjpgO
https://watchcom.no/nyheter/nyhetsarkiv/uncovers-cisco-jabber-vulnerabilities/
SANS Holiday Hack Challenge
https://holidayhackchallenge.com/2020/
Karim Lalji: Fear of the Unkown: A Metanalysis of Insecure Object Deserialization Vulnerabilities
https://www.sans.org/reading-room/whitepapers/testing/fear-unknown-metanalysis-insecure-object-deserialization-vulnerabilities-39920

Dec 10, 2020 • 6min
ISC StormCast for Thursday, December 10th 2020
Oblivious DoH
https://blog.cloudflare.com/oblivious-dns/
HTTP Archive Almanach
https://almanac.httparchive.org/en/2020/security
Open Source IoT TCP/IP Stack Vulnerabilities
https://www.forescout.com/company/resources/amnesia33-how-tcp-ip-stacks-breed-critical-vulnerabilities-in-iot-ot-and-it-devices/
Fireeye Red Team Tool Signatures
https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html

Dec 9, 2020 • 6min
ISC StormCast for Wednesday, December 9th 2020
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/December+2020+Microsoft+Patch+Tuesday+Exchange+Sharepoint+Dynamics+and+DNS+Spoofing/26860/
Adobe Patch Tuesday
https://helpx.adobe.com/security.html
OpenSSL Patch (Tuesday)
https://www.openssl.org/news/secadv/20201208.txt

Dec 8, 2020 • 6min
ISC StormCast for Tuesday, December 8th 2020
Corrupt BASE64 Strings: Detection and Decoding
https://isc.sans.edu/forums/diary/Corrupt+BASE64+Strings+Detection+and+Decoding/26616/
Microsoft Teams Remote Code Execution Vulnerability (Patched)
https://github.com/oskarsve/ms-teams-rce
PlayStation Now RCE
https://hackerone.com/reports/873614
Cisco Security Manager Java Deserialization Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-java-rce-mWJEedcD

Dec 7, 2020 • 6min
ISC StormCast for Monday, December 7th 2020
Proxy Scanner Attempting to Connect to Specific Hostname
https://isc.sans.edu/forums/diary/Is+IP+91199118137+testing+Access+to+aahwwx52hostxyz/26852/
Recovering Passwords From Pixelized Screenshots
https://www.linkedin.com/pulse/recovering-passwords-from-pixelized-screenshots-sipke-mellema/
Tomcat Information Leak
http://mail-archives.us.apache.org/mod_mbox/www-announce/202012.mbox/%3C52858194-2efd-6f17-1821-9036c8494df0%40apache.org%3E
Google Updates
https://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.html

Dec 4, 2020 • 17min
ISC StormCast for Friday, December 4th 2020
Traffic Analysis Quiz: Mr. Natural
https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Mr+Natural/26844/
An iOS Zero-Click Radio Proximity Exploit Odyssey
https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html
Github "State of the Octoverse" Report
https://octoverse.github.com/static/2020-security-report.pdf
Christopher Hurless: Open-Source Endpoint Detection and Response with CIS Benchmarks, OSQuery, Elastic Stack and The Hive
https://www.sans.org/reading-room/whitepapers/incident/open-source-endpoint-detection-response-cis-benchmarks-osquery-elastic-stack-thehive-39900

Dec 3, 2020 • 7min
ISC StormCast for Thursday, December 3rd 2020
Prevelance of DNS Spoofing
https://arxiv.org/abs/2011.12978
New npm Malware Includes Bladabindi Trojan
https://blog.sonatype.com/bladabindi-njrat-rat-in-jdb.js-npm-malware
DarkIRC Bot Exploits Recent Oracle WebLogic Vulnerablity
https://blogs.juniper.net/en-us/threat-research/darkirc-bot-exploits-oracle-weblogic-vulnerability

Dec 2, 2020 • 9min
ISC StormCast for Wednesday, December 2nd 2020
Xanthe Docker Aware Miner
https://blog.talosintelligence.com/2020/12/xanthe-docker-aware-miner.html#more
Ocean Lotus Mac Backdoor
https://www.trendmicro.com/en_us/research/20/k/new-macos-backdoor-connected-to-oceanlotus-surfaces.html
OpenClinic vs OpenClinic GA
https://labs.bishopfox.com/advisories/openclinic-version-0.8.2
https://us-cert.cisa.gov/ics/advisories/icsma-20-184-01
https://sourceforge.net/p/open-clinic/discussion/1231980/thread/a2e8909fc5/
Register For Cyberstart
https://www.cyberstartamerica.org


