

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Nov 2, 2020 • 6min
ISC StormCast for Monday, November 2nd 2020
Quick Status of the CAA DNS Record Adoption
https://isc.sans.edu/forums/diary/Quick+Status+of+the+CAA+DNS+Record+Adoption/26738/
Windows Kernel cng.sys pool-based buffer overflow CVE-2020-17087
https://bugs.chromium.org/p/project-zero/issues/detail?id=2104
Operation Earth Kitsune
https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-earth-kitsune-tracking-slub-s-current-operations

Oct 30, 2020 • 15min
ISC StormCast for Friday, October 30th 2020
PATCH NOW: CVE-2020-14882 WebLogic Actively Exploited
https://isc.sans.edu/forums/diary/PATCH+NOW+CVE202014882+Weblogic+Actively+Exploited+Against+Honeypots/26734/
Zonealarm Update
https://www.zonealarm.com/software/extreme-security/release-history
Ransomware Targeting Healthcare
https://us-cert.cisa.gov/ncas/alerts/aa20-302a
OpenEMR Vulnerabilities
https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerability
Mishka McCowan: Mitigating Risk with the CSA 12 Critical Risks for Serverless Applications
https://www.sans.org/reading-room/whitepapers/cloud/mitigating-risk-csa-12-critical-risks-serverless-applications-39845

Oct 29, 2020 • 6min
ISC StormCast for Thursday, October 29th 2020
SMBGhost Remains Unpatched on 8% of Exposed SMB Servers
https://isc.sans.edu/forums/diary/SMBGhost+the+critical+vulnerability+many+seem+to+have+forgotten+to+patch/26732/
Microsoft Defender ATP Cobalt Strike False Positive
https://twitter.com/ffforward/status/1321375690084810753?s=20
QNAP Security Advisory
https://www.qnap.com/en/security-advisory/QSA-20-09
New Linux Trickbot Version Sighted
https://www.netscout.com/blog/asert/dropping-anchor
Abuse.ch Needs Help
https://abuse.ch/blog/moving-forward/

Oct 28, 2020 • 5min
ISC StormCast for Wednesday, October 28th 2020
Vulnerable SonarQube Configurations Used to Steal Code
https://beta.documentcloud.org/documents/20399900-fbi_flash_sonarqube_access_bc
Microsoft Edge Security Updates (Chromium-Based)
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200002
Microsoft Releases Flash Removal Tool
https://support.microsoft.com/en-us/help/4577586/update-for-removal-of-adobe-flash-player
Bypassing MSFT Teams Policies
https://o365blog.com/post/teams-policies/

Oct 27, 2020 • 6min
ISC StormCast for Tuesday, October 27th 2020
Excel 4 Macros: "Abnormal Sheet Visibility"
https://isc.sans.edu/forums/diary/Excel+4+Macros+Abnormal+Sheet+Visibility/26726/
HP Printer Applications Certificate Revoked
https://eclecticlight.co/2020/10/23/why-have-my-hp-printers-stopped-working-how-to-check-their-software-signature/
Link Previews and Privacy
https://www.mysk.blog/2020/10/25/link-previews/

Oct 26, 2020 • 6min
ISC StormCast for Monday, October 26th 2020
An Alternative to Shodan: Censys
https://isc.sans.edu/forums/diary/An+Alternative+to+Shodan+Censys+with+UserAgent+CensysInspect11/26718/
Sooty: SOC Analyst's All-in-One Tool
https://isc.sans.edu/forums/diary/Sooty+SOC+Analysts+AllinOne+Tool/26714/
Adversarial ML Threat Matrix
https://github.com/mitre/advmlthreatmatrix
Samsung S20 RCE
https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/
VMWare Advisory
https://www.vmware.com/security/advisories/VMSA-2020-0023.html

Oct 23, 2020 • 6min
ISC StormCast for Friday, October 23rd 2020
BazarLoader Phishing Lures
https://isc.sans.edu/forums/diary/BazarLoader+phishing+lures+plan+a+Halloween+party+get+a+bonus+and+be+fired+in+the+same+afternoon/26710/
Stalled Reviews for Secure Boot Shim
https://github.com/rhboot/shim-review/issues/120
https://github.com/rhboot/shim-review/issues/102#issuecomment-698963751
Cisco Advisories
https://tools.cisco.com/security/center/publicationListing.x

Oct 22, 2020 • 6min
ISC StormCast for Thursday, October 22nd 2020
Shipping Dangerous Goods
https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/
Chinese State-Sponsored Actors Exploit Same Vulnerablities as Others
https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF
URL Bar Spoofing Vulnerabilities
https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html
Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2020.html

Oct 21, 2020 • 6min
ISC StormCast for Wednesday, October 21st 2020
Mirai-alike Python Scanner
https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/
Google Chrome Update (actively exploited vulnerability fixed)
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
QNAP Fixes ZeroLogon Vulnerability
https://www.qnap.com/en/security-advisory/qsa-20-07
GravityRat Going Multi Platform
https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms
US Census Spoof
https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020

Oct 20, 2020 • 5min
ISC StormCast for Tuesday, October 20th 2020
Out of Band MSFT Patches
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022
https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023
Adobe Magento Patches
https://helpx.adobe.com/security/products/magento/apsb20-59.html
Attacks against SS7
https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991
https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/


