SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Oct 19, 2020 • 7min

ISC StormCast for Monday, October 19th 2020

CVE-2020-5135 SonicWall Buffer Overflow https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/ Spammer Attached Mass Mailer Configuration Instead of Malware https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/ Traffic Analysis Quiz: Ugly-Wolf.net https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/ Qualcomm QCMAP Vulnerabilities https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities Discord Desktop App RCE https://mksben.l0.cm/2020/10/discord-desktop-rce.html
undefined
Oct 16, 2020 • 6min

ISC StormCast for Friday, October 16th 2020

Obfuscated Python RAT https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/ BadNeighbor ICMPv6 Router Advertisement Update https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/ BlueZ Vulnerability https://www.youtube.com/watch?v=qPYrLRausSw https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html https://security.googleblog.com/ (available "soon") Zoom Rolling Out End-to-End Encryption https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/
undefined
Oct 15, 2020 • 6min

ISC StormCast for Thursday, October 15th 2020

TA551/Shathak Word Docs Push IcedID and Bokbot https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/ MSFT Patch Tuesday Followup https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952 Apple T2 Chip Vulnerability Confirmed https://9to5mac.com/2020/10/13/t2-exploit-team/ SAP Updates https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
undefined
Oct 14, 2020 • 7min

ISC StormCast for Wednesday, October 14th 2020

Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/ Adobe Updates https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
undefined
Oct 13, 2020 • 6min

ISC StormCast for Tuesday, October 13th 2020

Nested .MSGs: Turtles All The Way Down https://isc.sans.edu/forums/diary/Nested+MSGs+Turtles+All+The+Way+Down/26668/ Microsoft Attempting To Take Down Trickbot C2 Infrastructure https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/ Google Chrome Cache Partitioning https://developers.google.com/web/updates/2020/10/http-cache-partitioning
undefined
Oct 12, 2020 • 6min

ISC StormCast for Monday, October 12th 2020

Phishing Kits As Far As The Eye Can See https://isc.sans.edu/forums/diary/Phishing+kits+as+far+as+the+eye+can+see/26660/ Open Packaging Conventions https://isc.sans.edu/forums/diary/Open+Packaging+Conventions/26662/ Analyzing MSG Files https://isc.sans.edu/forums/diary/Analyzing+MSG+Files+With+pluginmsgsummary/26664/ Cisco Video Surveillance 8000 Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cdp-rcedos-mAHR8vNx 55 New Apple Flaws https://samcurry.net/hacking-apple/
undefined
Oct 9, 2020 • 20min

ISC StormCast for Friday, October 9th 2020

Hashicorp Vault Vulnerabilities https://googleprojectzero.blogspot.com/2020/10/enter-the-vault-auth-issues-hashicorp-vault.html Ryuk Ransomware Writeup https://thedfirreport.com/2020/10/08/ryuks-return/ Ricky Tan: Zeek Log Reconnaissance with Netowrk Graphs Using Maltego Casefile https://www.sans.org/reading-room/whitepapers/securityanalytics/zeek-log-reconnaissance-network-graphs-maltego-casefile-39815
undefined
Oct 8, 2020 • 7min

ISC StormCast for Thursday, October 8th 2020

Today, Nobody is Going to Attack You https://isc.sans.edu/forums/diary/Today+Nobody+is+Going+to+Attack+You/26654/ Google Chrome Patches https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html Android Security Update https://source.android.com/security/bulletin/2020-10-01 QNAP Patches Helpdesk Application https://www.qnap.com/en/security-advisory/QSA-20-08 Comcast Remote Control Evesdropping https://www.guardicore.com/2020/10/wareztheremote-turning-remotes-into-listening-devices/
undefined
Oct 7, 2020 • 9min

ISC StormCast for Wednesday, October 7th 2020

Apple T2 Chip Vulnerability https://ironpeak.be/blog/crouching-t2-hidden-danger/ NVIDIA Patches https://nvidia.custhelp.com/app/answers/detail/a_id/5075 Cloudflare DDoS Alerts https://blog.cloudflare.com/announcing-ddos-alerts/ Gravatar Privacy Issue https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/
undefined
Oct 6, 2020 • 6min

ISC StormCast for Tuesday, October 6th 2020

Obfuscation and Repetition https://isc.sans.edu/forums/diary/Obfuscation+and+Repetition/26648/ Compromised UEFI Payload Found https://securelist.com/mosaicregressor/98849/ Privilege Escalation Flaw in All AntiVirus Products https://www.cyberark.com/resources/threat-research-blog/anti-virus-vulnerabilities-who-s-guarding-the-watch-tower Rapid7 SMTP "NICER" Report https://blog.rapid7.com/2020/10/02/nicer-protocol-deep-dive-internet-exposure-of-smtp/

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app