SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Nov 2, 2020 • 6min

ISC StormCast for Monday, November 2nd 2020

Quick Status of the CAA DNS Record Adoption https://isc.sans.edu/forums/diary/Quick+Status+of+the+CAA+DNS+Record+Adoption/26738/ Windows Kernel cng.sys pool-based buffer overflow CVE-2020-17087 https://bugs.chromium.org/p/project-zero/issues/detail?id=2104 Operation Earth Kitsune https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-earth-kitsune-tracking-slub-s-current-operations
undefined
Oct 30, 2020 • 15min

ISC StormCast for Friday, October 30th 2020

PATCH NOW: CVE-2020-14882 WebLogic Actively Exploited https://isc.sans.edu/forums/diary/PATCH+NOW+CVE202014882+Weblogic+Actively+Exploited+Against+Honeypots/26734/ Zonealarm Update https://www.zonealarm.com/software/extreme-security/release-history Ransomware Targeting Healthcare https://us-cert.cisa.gov/ncas/alerts/aa20-302a OpenEMR Vulnerabilities https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerability Mishka McCowan: Mitigating Risk with the CSA 12 Critical Risks for Serverless Applications https://www.sans.org/reading-room/whitepapers/cloud/mitigating-risk-csa-12-critical-risks-serverless-applications-39845
undefined
Oct 29, 2020 • 6min

ISC StormCast for Thursday, October 29th 2020

SMBGhost Remains Unpatched on 8% of Exposed SMB Servers https://isc.sans.edu/forums/diary/SMBGhost+the+critical+vulnerability+many+seem+to+have+forgotten+to+patch/26732/ Microsoft Defender ATP Cobalt Strike False Positive https://twitter.com/ffforward/status/1321375690084810753?s=20 QNAP Security Advisory https://www.qnap.com/en/security-advisory/QSA-20-09 New Linux Trickbot Version Sighted https://www.netscout.com/blog/asert/dropping-anchor Abuse.ch Needs Help https://abuse.ch/blog/moving-forward/
undefined
Oct 28, 2020 • 5min

ISC StormCast for Wednesday, October 28th 2020

Vulnerable SonarQube Configurations Used to Steal Code https://beta.documentcloud.org/documents/20399900-fbi_flash_sonarqube_access_bc Microsoft Edge Security Updates (Chromium-Based) https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200002 Microsoft Releases Flash Removal Tool https://support.microsoft.com/en-us/help/4577586/update-for-removal-of-adobe-flash-player Bypassing MSFT Teams Policies https://o365blog.com/post/teams-policies/
undefined
Oct 27, 2020 • 6min

ISC StormCast for Tuesday, October 27th 2020

Excel 4 Macros: "Abnormal Sheet Visibility" https://isc.sans.edu/forums/diary/Excel+4+Macros+Abnormal+Sheet+Visibility/26726/ HP Printer Applications Certificate Revoked https://eclecticlight.co/2020/10/23/why-have-my-hp-printers-stopped-working-how-to-check-their-software-signature/ Link Previews and Privacy https://www.mysk.blog/2020/10/25/link-previews/
undefined
Oct 26, 2020 • 6min

ISC StormCast for Monday, October 26th 2020

An Alternative to Shodan: Censys https://isc.sans.edu/forums/diary/An+Alternative+to+Shodan+Censys+with+UserAgent+CensysInspect11/26718/ Sooty: SOC Analyst's All-in-One Tool https://isc.sans.edu/forums/diary/Sooty+SOC+Analysts+AllinOne+Tool/26714/ Adversarial ML Threat Matrix https://github.com/mitre/advmlthreatmatrix Samsung S20 RCE https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/ VMWare Advisory https://www.vmware.com/security/advisories/VMSA-2020-0023.html
undefined
Oct 23, 2020 • 6min

ISC StormCast for Friday, October 23rd 2020

BazarLoader Phishing Lures https://isc.sans.edu/forums/diary/BazarLoader+phishing+lures+plan+a+Halloween+party+get+a+bonus+and+be+fired+in+the+same+afternoon/26710/ Stalled Reviews for Secure Boot Shim https://github.com/rhboot/shim-review/issues/120 https://github.com/rhboot/shim-review/issues/102#issuecomment-698963751 Cisco Advisories https://tools.cisco.com/security/center/publicationListing.x
undefined
Oct 22, 2020 • 6min

ISC StormCast for Thursday, October 22nd 2020

Shipping Dangerous Goods https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/ Chinese State-Sponsored Actors Exploit Same Vulnerablities as Others https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF URL Bar Spoofing Vulnerabilities https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2020.html
undefined
Oct 21, 2020 • 6min

ISC StormCast for Wednesday, October 21st 2020

Mirai-alike Python Scanner https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/ Google Chrome Update (actively exploited vulnerability fixed) https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html QNAP Fixes ZeroLogon Vulnerability https://www.qnap.com/en/security-advisory/qsa-20-07 GravityRat Going Multi Platform https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms US Census Spoof https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020
undefined
Oct 20, 2020 • 5min

ISC StormCast for Tuesday, October 20th 2020

Out of Band MSFT Patches https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022 https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023 Adobe Magento Patches https://helpx.adobe.com/security/products/magento/apsb20-59.html Attacks against SS7 https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991 https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app