

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Sep 21, 2020 • 6min
ISC StormCast for Monday, September 21st 2020
A Mix of Python and VBA in a Malicious Word Document
https://isc.sans.edu/forums/diary/A+Mix+of+Python+VBA+in+a+Malicious+Word+Document/26578/
Salesforce Phish
https://isc.sans.edu/forums/diary/Analysis+of+a+Salesforce+Phishing+Emails/26582/
Google App Engine Used in Phishing Attacks
https://medium.com/@marcelx/attackers-are-abusing-googles-app-engine-to-circumvent-enterprise-security-solutions-again-eda8345d531d
Sysmon Adds Clipboard Monitoring
https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
Windows Defender No Longer Able to Download Files
https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-windows-defender-ability-after-security-concerns/

Sep 18, 2020 • 6min
ISC StormCast for Friday, September 18th 2020
OSSEC Active Response
https://isc.sans.edu/forums/diary/Suspicious+Endpoint+Containment+with+OSSEC/26576/
Microsoft Patch for Office for Mac
https://docs.microsoft.com/en-us/officeupdates/release-notes-office-for-mac
VMWare Fusion Vulnerablity
https://www.vmware.com/security/advisories/VMSA-2020-0020.html
NSA Secure Boot Configuration Guide
https://media.defense.gov/2020/Sep/15/2002497594/-1/-1/0/CTR-UEFI-SECURE-BOOT-CUSTOMIZATION-20200915.PDF/CTR-UEFI-SECURE-BOOT-CUSTOMIZATION-20200915.PDF
Microsoft Edge Warns Users of Adobe Flash End of Support
https://blogs.windows.com/msedgedev/2020/09/04/update-adobe-flash-end-support/

Sep 17, 2020 • 6min
ISC StormCast for Thursday, September 17th 2020
Most Recent "Mirai" Bot Includes Code to Target Backups
https://isc.sans.edu/forums/diary/Do+Vulnerabilities+Ever+Get+Old+Recent+Mirai+Variant+Scanning+for+20+Year+Old+Amanda+Version/26572/
Apple Security Updates
https://support.apple.com/en-us/HT201222

Sep 16, 2020 • 6min
ISC StormCast for Wednesday, September 16th 2020
Traffic Analysis Quiz: Oh No... Another Infection
https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Oh+No+Another+Infection/26566/
Magento 1 Stores Targeted By Recent Attack
https://sansec.io/research/largest-magento-hack-to-date
Adobe Media Encoder Patch
https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html
Zerologin Reminder
https://www.secura.com/pathtoimg.php?id=2055
Windows "Finger" Utility Abused
http://hyp3rlinx.altervista.org/advisories/Windows_TCPIP_Finger_Command_C2_Channel_and_Bypassing_Security_Software.txt

Sep 15, 2020 • 5min
ISC StormCast for Tuesday, September 15th 2020
Not Everything About ".well-known" is Well Known
https://isc.sans.edu/forums/diary/Not+Everything+About+wellknown+is+Well+Known/26564/
BLE Lock Vulnerable to Replay Attack
https://www.pentestpartners.com/security-blog/360lock-smart-lock-review/
Mobile Iron Exploit Released
https://blog.orange.tw/2020/09/how-i-hacked-facebook-again-mobileiron-mdm-rce.html

Sep 14, 2020 • 6min
ISC StormCast for Monday, September 14th 2020
Pillaging and Protecting the Clipboard
https://isc.sans.edu/forums/diary/Whats+in+Your+Clipboard+Pillaging+and+Protecting+the+Clipboard/26556/
Critical Vulnerability in PANOS
https://security.paloaltonetworks.com/CVE-2020-2040
Linux VoIP Softswitch Malware
https://www.welivesecurity.com/2020/09/10/who-callin-cdrthief-linux-voip-softswitches/
CVE-2020-1472 Zerologon Privilege Escalation Vulnerability
https://www.secura.com/blog/zero-logon

Sep 11, 2020 • 8min
ISC StormCast for Friday, September 11th 2020
Recent Dridex Activity
https://isc.sans.edu/forums/diary/Recent+Dridex+activity/26550/
Zoom Bombings and Zoom 2FA
https://arxiv.org/abs/2009.03822
https://blog.zoom.us/secure-your-zoom-account-with-two-factor-authentication/
AMD Server CPUs May Be Locked to Particular Motherboard
https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-for-enhanced-security-at-a-cost/
BLURtooth Vulnerability
https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/blurtooth/

Sep 10, 2020 • 6min
ISC StormCast for Thursday, September 10th 2020
MacOS 11 Network Traffic
https://isc.sans.edu/forums/diary/A+First+Look+at+macOS+11+Big+Sur+Network+Traffic+New+Now+with+more+GREASE/26548/
Azure Offers Automatic Windows VM Patching
https://azure.microsoft.com/en-us/updates/automatic-vm-guest-patching-now-in-preview/
WeaveScope Used to Attack Docker Infrastructure
https://www.intezer.com/blog/cloud-workload-protection/attackers-abusing-legitimate-cloud-monitoring-tools-to-conduct-cyber-attacks/

Sep 9, 2020 • 7min
ISC StormCast for Wednesday, September 9th 2020
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+September+2020+Patch+Tuesday/26544/
Adobe Security Bulletins
https://helpx.adobe.com/security.html
Intel Patches
https://www.intel.com/content/www/us/en/security-center/default.html

Sep 8, 2020 • 6min
ISC StormCast for Tuesday, September 8th 2020
A Blast From The Past: XXEncoded VB 6.0 Trojan
https://isc.sans.edu/forums/diary/A+blast+from+the+past+XXEncoded+VB60+Trojan/26538/
Office: About OLE and ZIP Files
https://isc.sans.edu/forums/diary/Office+About+OLE+and+ZIP+Files/26540/
Go XSS Vulnerability
https://seclists.org/fulldisclosure/2020/Sep/5
"Baka" JavaScript Skimmer
https://usa.visa.com/content/dam/VCOM/global/support-legal/documents/visa-security-alert-baka-javascript-skimmer.pdf


