SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Nov 13, 2020 • 14min

ISC StormCast for Friday, November 13th 2020

Preventing Exposed Azure Blob Storage https://isc.sans.edu/forums/diary/Preventing+Exposed+Azure+Blob+Storage/26786/ Apple Security Updates https://support.apple.com/en-us/HT201222 DNS Cache Poisoning Attack Reloaded https://dl.acm.org/doi/pdf/10.1145/3372297.3417280 Rebel Powell: Poisoned Postman; Detecting Manipulation of Compliance Features in a Microsoft Exchange Online Environment https://www.sans.org/reading-room/whitepapers/cloud/poisoned-postman-detecting-manipulation-compliance-features-microsoft-exchange-online-environment-39850
undefined
Nov 12, 2020 • 6min

ISC StormCast for Thursday, November 12th 2020

Traffic Analysis Quiz https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+DESKTOPFX23IK5/26780/ Open Source Security Scorecards https://github.com/ossf/scorecard Bitdefender: UPX Unpacking Featuring Ten Memory Corruptions https://landave.io/2020/11/bitdefender-upx-unpacking-featuring-ten-memory-corruptions/ Ubuntu 20.04 Privilege Escalation https://securitylab.github.com/research/Ubuntu-gdm3-accountsservice-LPE
undefined
Nov 11, 2020 • 6min

ISC StormCast for Wednesday, November 11th 2020

Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+November+2020+Patch+Tuesday/26778/ "Platypus" Attack against Intel SGX https://platypusattack.com/ Adobe Updates https://helpx.adobe.com/security.html Firefox Updates https://www.mozilla.org/en-US/security/advisories/mfsa2020-49/#CVE-2020-26950 Fingerprinting ADS-B Signals https://icnp20.cs.ucr.edu/proceedings/aimcom2/Real-World%20ADS-B%20signal%20recognition%20based%20on%20Radio%20Frequency%20Fingerprinting.pdf
undefined
Nov 10, 2020 • 6min

ISC StormCast for Tuesday, November 10th 2020

How Attackers Brush Up Their Malicious Scripts https://isc.sans.edu/forums/diary/How+Attackers+Brush+Up+Their+Malicious+Scripts/26770/ RansomEXX Trojan Attacks Linux Systems https://securelist.com/ransomexx-trojan-attacks-linux-systems/99279/ Fake Microsoft Teams Updates Lead to Cobalt Strike Deployment https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/ More NPM Malare Found https://blog.sonatype.com/discord.dll-successor-to-npm-fallguys- The Internet is Getting Safer: Fall 2020 RPKI Update https://blog.cloudflare.com/rpki-2020-fall-update/
undefined
Nov 9, 2020 • 5min

ISC StormCast for Monday, November 9th 2020

Cryptojacking Targeting WebLogic TCP/7001 Cryptojacking Targeting WebLogic TCP/7001 https://isc.sans.edu/forums/diary/Cryptojacking+Targeting+WebLogic+TCP7001/26768/ Extracting VBA Code From Maldocs https://isc.sans.edu/forums/diary/Quick+Tip+Extracting+all+VBA+Code+from+a+Maldoc/26772/ Let's Encrypt May No Longer Be Recognized by Older Android Versions https://letsencrypt.org/2020/11/06/own-two-feet.html Linux Kernel to Remove set_fs() http://lkml.iu.edu/hypermail/linux/kernel/2010.3/00552.html BigIP Vulnerability https://support.f5.com/csp/article/K43310520
undefined
Nov 6, 2020 • 16min

ISC StormCast for Friday, November 6th 2020

Did You Spot "Invoke-Expression" ? https://isc.sans.edu/forums/diary/Did+You+Spot+InvokeExpression/26762/ Apple Security Updates https://support.apple.com/en-us/HT201222 Corporte VoIP Phone System Attacks https://blog.checkpoint.com/2020/11/05/whos-calling-gaza-and-west-bank-hackers-exploit-and-monetize-corporate-voip-phone-system-vulnerability-internationally/ Mark Lucas: Replacing WINS in an Open Environment with Policy Managed DNS Servers https://www.sans.org/reading-room/whitepapers/dns/replacing-wins-open-environment-policy-managed-dns-servers-39820
undefined
Nov 5, 2020 • 6min

ISC StormCast for Thursday, November 5th 2020

Cisco AnyConnect Security Mobility Client https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-ipc-KfQO9QhK Google Chrome Root CA Policy https://www.chromium.org/Home/chromium-security/root-ca-policy Android November 2020 Security Bulletin https://source.android.com/security/bulletin/2020-11-01
undefined
Nov 4, 2020 • 5min

ISC StormCast for Wednesday, November 4th 2020

Attackers Exploiting WebLogic Servers to Install Cobalt Strike https://isc.sans.edu/forums/diary/Attackers+Exploiting+WebLogic+Servers+via+CVE202014882+to+install+Cobalt+Strike/26752 New SaltStack Vulnerabilities https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/ Adobe Releases Acrobat/Reader Update https://helpx.adobe.com/security/products/acrobat/apsb20-67.html Malicious Twilio NPM Package https://www.npmjs.com/advisories/1574 GitHub Workflow Injection Vulnerabilities https://bugs.chromium.org/p/project-zero/issues/detail?id=2070&can=2&q=&colspec=ID%20Type%20Status%20Priority%20Milestone%20Owner%20Summary&cells=ids
undefined
Nov 3, 2020 • 7min

ISC StormCast for Tuesday, November 3rd 2020

Emotet -> Qakbot -> More Emotet https://isc.sans.edu/forums/diary/Emotet+Qakbot+more+Emotet/26750/ WebLogic Bad News https://www.oracle.com/security-alerts/alert-cve-2020-14750.html https://twitter.com/80vul/status/1322078337137700865 Google Chrome Update https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html NAT Slipstreaming Re-Discovered https://thehackernews.com/2020/11/new-natfirewall-bypass-attack-lets.html
undefined
Nov 2, 2020 • 6min

ISC StormCast for Monday, November 2nd 2020

Quick Status of the CAA DNS Record Adoption https://isc.sans.edu/forums/diary/Quick+Status+of+the+CAA+DNS+Record+Adoption/26738/ Windows Kernel cng.sys pool-based buffer overflow CVE-2020-17087 https://bugs.chromium.org/p/project-zero/issues/detail?id=2104 Operation Earth Kitsune https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-earth-kitsune-tracking-slub-s-current-operations

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app