

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 5, 2020 • 7min
ISC StormCast for Thursday, March 5th 2020
MSFT Subdomain Takeover
https://vullnerability.com/blog/microsoft-subdomain-account-takeover
Homoglyph Attacks in the News Again
https://www.soluble.ai/blog/public-disclosure-emoji-to-zero-day
Coronavirus Phish
https://twitter.com/JCyberSec_/status/1234806881195044865

Mar 4, 2020 • 6min
ISC StormCast for Wednesday, March 4th 2020
Introduction to EvtxEcmd (Evtx Explorer)
https://isc.sans.edu/forums/diary/Introduction+to+EvtxEcmd+Evtx+Explorer/25858/
Let's Encrypt Revoking Certificates
https://community.letsencrypt.org/t/revoking-certain-certificates-on-march-4/114864
Using Smart Devices in the Home Securely (NCSC Version)
https://www.ncsc.gov.uk/guidance/smart-devices-in-the-home
Ransomware and Cloud Backups
https://www.bleepingcomputer.com/news/security/ransomware-attackers-use-your-cloud-backups-against-you/
SANS Coronavirus Training Guarantee
https://www.sans.org/training-guarantee

Mar 3, 2020 • 6min
ISC StormCast for Tuesday, March 3rd 2020
SSL Distribution by Country
https://isc.sans.edu/forums/diary/Secure+vs+cleartext+protocols+couple+of+interesting+stats/25854/
Checkpoint Evasion Encyclopedia
https://research.checkpoint.com/2020/cpr-evasion-encyclopedia-the-check-point-evasion-repository/
OWASP Threat Dragon
https://github.com/mike-goodwin/owasp-threat-dragon-desktop
SANS Free Things
https://sans.org/free

Mar 2, 2020 • 5min
ISC StormCast for Monday, March 2nd 2020
Show me Your Clipboard Data!
https://isc.sans.edu/forums/diary/Show+me+Your+Clipboard+Data/25846/
Hazelcast IMDB Discover Scan
https://isc.sans.edu/forums/diary/Hazelcast+IMDG+Discover+Scan/25850/
Microsoft Exchange Server Vulnerabilty Scans
https://twitter.com/GossiTheDog/status/1232369036438233088
Tomcat Ghostcat Vulnerability
https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E

Feb 28, 2020 • 6min
ISC StormCast for Friday, February 28th 2020
Ultrasonic Triggers for Cellphone Assistants.
https://source.wustl.edu/2020/02/surfing-attack-hacks-siri-google-with-ultrasonic-waves/
Comparing Information Leakage from Different Browsers
https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf
Cloud Snooper Attack
https://news.sophos.com/en-us/2020/02/25/cloud-snooper-attack-bypasses-firewall-security-measures/

Feb 27, 2020 • 7min
ISC StormCast for Thursday, February 27th 2020
Kr00k WiFi Attack
https://www.eset.com/int/kr00k/
Impersonating LTE Users
https://imp4gt-attacks.net/
Zyxel RCE Vulnerablity
https://www.kb.cert.org/vuls/id/498544/

Feb 26, 2020 • 6min
ISC StormCast for Wednesday, February 26th 2020
Fraudulant Paypal Charges (links in German)
https://twitter.com/iblueconnection/status/1232259071602044928
https://www.heise.de/security/meldung/Google-Pay-Luecke-in-virtuellen-Kreditkarten-erlaubt-unberechtigte-Abbuchungen-4667527.html
https://stadt-bremerhaven.de/google-pay-virtuelle-paypal-kreditkarten-weisen-sicherheitsluecken-auf/
Chrome Update
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
Microsoft Public Preview For Azure AD Hybrid Environments
https://techcommunity.microsoft.com/t5/azure-active-directory-identity/public-preview-of-azure-ad-support-for-fido2-security-keys-in/ba-p/1187929

Feb 25, 2020 • 7min
ISC StormCast for Tuesday, February 25th 2020
ScrollToTextFragment Privacy Concerns in Google Chrome 80
https://github.com/WICG/ScrollToTextFragment/issues/76#issue-538137989
https://docs.google.com/document/d/1YHcl1-vE_ZnZ0kL2almeikAj2gkwCq8_5xwIae7PVik/edit#heading=h.uoiwg23pt0tx
Another OpenSMTPD Vulnerability
https://github.com/OpenSMTPD/OpenSMTPD/releases
WhatsApp Group Invite Links in Search Engines
https://twitter.com/JordanWildon/status/1230829082662842369

Feb 24, 2020 • 7min
ISC StormCast for Monday, February 24th 2020
Old Style Excel Macro Malware
https://isc.sans.edu/forums/diary/Maldoc+Excel+4+Macros+in+OOXML+Format/25830/
Simple But Efficient VBScript Obfuscation
https://isc.sans.edu/forums/diary/Simple+but+Efficient+VBScript+Obfuscation/25828/
Let's Encrypt Beefs Up Validation
https://letsencrypt.org/2020/02/19/multi-perspective-validation.html
Google Play Store Joker / Clicken Malware
https://research.checkpoint.com/2020/android-app-fraud-haken-clicker-and-joker-premium-dialer/
Google Warns of Microsoft Edge
https://www.heise.de/security/meldung/l-f-Google-findet-den-neuen-Edge-Browser-doof-und-unsicher-4665634.html

Feb 21, 2020 • 7min
ISC StormCast for Friday, February 21st 2020
Enumerating Who "Owns" a Workstation for IR
https://isc.sans.edu/forums/diary/Whodat+Enumerating+Who+owns+a+Workstation+for+IR/25822/
Special Update for Adobe After Effects and Media Encoder
https://helpx.adobe.com/security/products/after_effects/apsb20-09.html
https://helpx.adobe.com/security/products/media-encoder/apsb20-10.html
Cisco Updates
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-on-prem-static-cred-sL8rDs8
Apple To No Longer Accept Certifcates as Valid that Exceed a Lifetime of 13 months
https://www.theregister.co.uk/2020/02/20/apple_shorter_cert_lifetime/
Python ReDoS Bugs
https://blog.r2c.dev/posts/finding-python-redos-bugs-at-scale-using-dlint-and-r2c/


