

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Oct 19, 2020 • 7min
ISC StormCast for Monday, October 19th 2020
CVE-2020-5135 SonicWall Buffer Overflow
https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/
Spammer Attached Mass Mailer Configuration Instead of Malware
https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/
Traffic Analysis Quiz: Ugly-Wolf.net
https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/
Qualcomm QCMAP Vulnerabilities
https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities
Discord Desktop App RCE
https://mksben.l0.cm/2020/10/discord-desktop-rce.html

Oct 16, 2020 • 6min
ISC StormCast for Friday, October 16th 2020
Obfuscated Python RAT
https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/
BadNeighbor ICMPv6 Router Advertisement Update
https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/
BlueZ Vulnerability
https://www.youtube.com/watch?v=qPYrLRausSw
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html
https://security.googleblog.com/ (available "soon")
Zoom Rolling Out End-to-End Encryption
https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/

Oct 15, 2020 • 6min
ISC StormCast for Thursday, October 15th 2020
TA551/Shathak Word Docs Push IcedID and Bokbot
https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/
MSFT Patch Tuesday Followup
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952
Apple T2 Chip Vulnerability Confirmed
https://9to5mac.com/2020/10/13/t2-exploit-team/
SAP Updates
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196

Oct 14, 2020 • 7min
ISC StormCast for Wednesday, October 14th 2020
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/
Adobe Updates
https://helpx.adobe.com/security/products/flash-player/apsb20-58.html

Oct 13, 2020 • 6min
ISC StormCast for Tuesday, October 13th 2020
Nested .MSGs: Turtles All The Way Down
https://isc.sans.edu/forums/diary/Nested+MSGs+Turtles+All+The+Way+Down/26668/
Microsoft Attempting To Take Down Trickbot C2 Infrastructure
https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/
Google Chrome Cache Partitioning
https://developers.google.com/web/updates/2020/10/http-cache-partitioning

Oct 12, 2020 • 6min
ISC StormCast for Monday, October 12th 2020
Phishing Kits As Far As The Eye Can See
https://isc.sans.edu/forums/diary/Phishing+kits+as+far+as+the+eye+can+see/26660/
Open Packaging Conventions
https://isc.sans.edu/forums/diary/Open+Packaging+Conventions/26662/
Analyzing MSG Files
https://isc.sans.edu/forums/diary/Analyzing+MSG+Files+With+pluginmsgsummary/26664/
Cisco Video Surveillance 8000 Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cdp-rcedos-mAHR8vNx
55 New Apple Flaws
https://samcurry.net/hacking-apple/

Oct 9, 2020 • 20min
ISC StormCast for Friday, October 9th 2020
Hashicorp Vault Vulnerabilities
https://googleprojectzero.blogspot.com/2020/10/enter-the-vault-auth-issues-hashicorp-vault.html
Ryuk Ransomware Writeup
https://thedfirreport.com/2020/10/08/ryuks-return/
Ricky Tan: Zeek Log Reconnaissance with Netowrk Graphs Using Maltego Casefile
https://www.sans.org/reading-room/whitepapers/securityanalytics/zeek-log-reconnaissance-network-graphs-maltego-casefile-39815

Oct 8, 2020 • 7min
ISC StormCast for Thursday, October 8th 2020
Today, Nobody is Going to Attack You
https://isc.sans.edu/forums/diary/Today+Nobody+is+Going+to+Attack+You/26654/
Google Chrome Patches
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Android Security Update
https://source.android.com/security/bulletin/2020-10-01
QNAP Patches Helpdesk Application
https://www.qnap.com/en/security-advisory/QSA-20-08
Comcast Remote Control Evesdropping
https://www.guardicore.com/2020/10/wareztheremote-turning-remotes-into-listening-devices/

Oct 7, 2020 • 9min
ISC StormCast for Wednesday, October 7th 2020
Apple T2 Chip Vulnerability
https://ironpeak.be/blog/crouching-t2-hidden-danger/
NVIDIA Patches
https://nvidia.custhelp.com/app/answers/detail/a_id/5075
Cloudflare DDoS Alerts
https://blog.cloudflare.com/announcing-ddos-alerts/
Gravatar Privacy Issue
https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/

Oct 6, 2020 • 6min
ISC StormCast for Tuesday, October 6th 2020
Obfuscation and Repetition
https://isc.sans.edu/forums/diary/Obfuscation+and+Repetition/26648/
Compromised UEFI Payload Found
https://securelist.com/mosaicregressor/98849/
Privilege Escalation Flaw in All AntiVirus Products
https://www.cyberark.com/resources/threat-research-blog/anti-virus-vulnerabilities-who-s-guarding-the-watch-tower
Rapid7 SMTP "NICER" Report
https://blog.rapid7.com/2020/10/02/nicer-protocol-deep-dive-internet-exposure-of-smtp/


