SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Aug 7, 2020 • 6min

ISC StormCast for Friday, August 7th 2020

FTCode Ransomware Resurfaces https://isc.sans.edu/forums/diary/A+Fork+of+the+FTCode+Powershell+Ransomware/26434/ Microsoft Anti-Malware Flaging Host File Manipulation https://www.bleepingcomputer.com/news/microsoft/windows-10-hosts-file-blocking-telemetry-is-now-flagged-as-a-risk/ Reviving older printer vulnerablity https://www.blackhat.com/us-20/briefings/schedule/#a-decade-after-stuxnets-printer-vulnerability-printing-is-still-the-stairway-to-heaven-19685
undefined
Aug 6, 2020 • 6min

ISC StormCast for Thursday, August 6th 2020

Malware Analysis Quiz https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Whats+the+Malware+From+This+Infection/26430/ Exploiting CVE-2020-9854 on MacOS https://objective-see.com/blog/blog_0x4D.html iOS OAuth2 Vulnerablity https://www.computest.nl/en/knowledge-platform/blog/vulnerability-new-touchid-feature-iCloud-accounts-at-risk-breached/ Limiting Location Data Exposure https://media.defense.gov/2020/Aug/04/2002469874/-1/-1/0/CSI_LIMITING_LOCATION_DATA_EXPOSURE_FINAL.PDF
undefined
Aug 5, 2020 • 6min

ISC StormCast for Wednesday, August 5th 2020

A Reminder to Patch CVE-2020-3452. Active Exploitation Seen https://isc.sans.edu/forums/diary/Reminder+Patch+Cisco+ASA+FTD+Devices+CVE20203452+Exploitation+Continues/26426/ Internet Choke Points: Concentration of Authoritative Name Servers https://isc.sans.edu/forums/diary/Internet+Choke+Points+Concentration+of+Authoritative+Name+Servers/26428/ August Android Patches Released https://source.android.com/security/bulletin/2020-08-01 Possible New iOS Jailbreak Affecting Secure Enclave https://twitter.com/SparkZheng/status/1286599007834271744
undefined
Aug 4, 2020 • 6min

ISC StormCast for Tuesday, August 4th 2020

VBA Macro With Multiple Command and Control Channels https://isc.sans.edu/forums/diary/Powershell+Bot+with+Multiple+C2+Protocols/26420/ Boothole Patch Causes Unbootable Systems https://access.redhat.com/solutions/5272311 https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass#Recovery Disabling MacOS TCC https://objective-see.com/blog/blog_0x4C.html CISA Publishes Details about Chinese Malware https://us-cert.cisa.gov/ncas/current-activity/2020/08/03/chinese-malicious-cyber-activity
undefined
Aug 3, 2020 • 5min

ISC StormCast for Monday, August 3rd 2020

Pages Hit By Bad Bots https://isc.sans.edu/forums/diary/What+pages+do+bad+bots+look+for/26414/ KeePassRPC Vulnerablity https://forum.kee.pm/t/a-critical-security-update-for-keepassrpc-is-available/3040 QNAP Updates Malware Remover https://www.bleepingcomputer.com/news/security/qnap-urges-users-to-update-malware-remover-after-qsnatch-alert/ Android Phone Updates https://www.theregister.com/2020/07/31/nearly_a_third_of_secondhand/
undefined
Jul 31, 2020 • 6min

ISC StormCast for Friday, July 31st 2020

Python Developers: Prepare! https://isc.sans.edu/forums/diary/Python+Developers+Prepare/26408/ Office 365 Phishing Hiding in Google Ads https://cofense.com/threat-actors-bypass-gateways-google-ad-redirects/ Zoom Brute Forcing Vulnerability https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/ Netgear Vulnerabilities https://www.kb.cert.org/vuls/id/576779 https://kb.netgear.com/000061982/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Routers-Mobile-Routers-Modems-Gateways-and-Extenders OPNSense Update https://opnsense.org/opnsense-20-7/ Microsoft Retiring SHA1 https://techcommunity.microsoft.com/t5/windows-it-pro-blog/sha-1-windows-content-to-be-retired-august-3-2020/ba-p/1544373
undefined
Jul 30, 2020 • 6min

ISC StormCast for Thursday, July 30th 2020

Consumer VPNs: You May Be Fine Without It https://isc.sans.edu/forums/diary/Consumer+VPNs+You+May+Be+Fine+Without/26404/ Tails Update https://tails.boum.org/news/version_4.9/index.en.html Firefox Update https://www.mozilla.org/en-US/security/advisories/mfsa2020-30/ Chrome Update https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html GRUB2 Vulnerability https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/ Facial Recognition With Masks https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8311.pdf
undefined
Jul 29, 2020 • 6min

ISC StormCast for Wednesday, July 29th 2020

New Datafeeds https://isc.sans.edu/forums/diary/All+I+want+this+Tuesday+More+Data/26400/ Emotet Stealing Email Attachments https://twitter.com/CofenseLabs/status/1288167724594671618 Magento Update https://helpx.adobe.com/security/products/magento/apsb20-47.html Explosed Docker Servers Infected with More Malware https://www.intezer.com/container-security/watch-your-containers-doki-infecting-docker-servers-in-the-cloud/
undefined
Jul 28, 2020 • 5min

ISC StormCast for Tuesday, July 28th 2020

In Memory of Donald Smith https://isc.sans.edu/forums/diary/In+Memory+of+Donald+Smith/26396/ Analyzing Metasploit ASP .Net Payloads https://isc.sans.edu/forums/diary/Analyzing+Metasploit+ASP+NET+Payloads/26392/ Emotet Payloads Replaces with GIFs https://twitter.com/GossiTheDog/status/1286271503005290497 QNAP Devices Attacked https://us-cert.cisa.gov/ncas/alerts/aa20-209a
undefined
Jul 27, 2020 • 6min

ISC StormCast for Monday, July 27th 2020

Compromized Desktop Applications By Web Technologies https://isc.sans.edu/forums/diary/Compromized+Desktop+Applications+by+Web+Technologies/26384/ Cracking Maldoc VBA Project Passwords https://isc.sans.edu/forums/diary/Cracking+Maldoc+VBA+Project+Passwords/26390/ Cisco Patching Treck IP Stack Vulnerabilities https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC Ubiquity Devices Breack Due to Malformed Feed https://community.ui.com/questions/Threat-Management-rules-silently-disabled-for-users-as-of-July-17-2020/35221bd2-843d-41a3-a957-33f57d9a8468

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app