

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Feb 20, 2020 • 6min
ISC StormCast for Thursday, February 20th 2020
Sonicwall Vulnerabilities
https://psirt.global.sonicwall.com/vuln-list
https://blog.scrt.ch/2020/02/11/sonicwall-sra-and-sma-vulnerabilties/
SQL Server RCE Exploit
https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/
Ransomware in Switzerland
https://www.melani.admin.ch/melani/en/home/dokumentation/newsletter/sicherheitsrisiko-durch-ransomware.html
Peripheral Vulnerabilities in Windows and Linux
https://eclypsium.com/2020/2/18/unsigned-peripheral-firmware/

Feb 19, 2020 • 6min
ISC StormCast for Wednesday, February 19th 2020
Discovering Contents of Folders Without Permission
https://isc.sans.edu/forums/diary/Discovering+contents+of+folders+in+Windows+without+permissions/25816/
Ring Enforces 2FA
https://blog.ring.com/2020/02/18/extra-layers-of-security-and-control/
Iranian's finally discover VPN Vulnerabilities
https://www.clearskysec.com/fox-kitten/
WordPress ThemeGrill Auth Bypass
https://www.webarxsecurity.com/critical-issue-in-themegrill-demo-importer/

Feb 18, 2020 • 6min
ISC StormCast for Tuesday, February 18th 2020
More about Curl on Windows
https://isc.sans.edu/forums/diary/curl+and+SSPI/25812/
WHO Warns of Coronavirus Phishing
https://www.who.int/about/communications/cyber-security
DUO Security / Google Identify Malicous Chrome Extensions
https://duo.com/labs/research/crxcavator-malvertising-2020

Feb 17, 2020 • 5min
ISC StormCast for Monday, February 17th 2020
Keep an Eye on Command-Line Browsers
https://isc.sans.edu/forums/diary/Keep+an+Eye+on+CommandLine+Browsers/25804/
Old Tricks in New Bots: KBOT
https://securelist.com/kbot-sometimes-they-come-back/96157/
OpenSSH Now With Fido/U2F
http://www.openssh.com/txt/release-8.2

Feb 14, 2020 • 7min
ISC StormCast for Friday, February 14th 2020
Changes to Microsoft LDAP/AD And How to Cope with them
https://isc.sans.edu/forums/diary/Authmageddon+deferred+but+not+averted+Microsoft+LDAP+Changes+now+slated+for+Q3Q4+2020/25800/
https://isc.sans.edu/forums/diary/March+Patch+Tuesday+is+Coming+the+LDAP+Changes+will+Change+Your+Life/25796/
SweynTooth BLE Vulnerabilities
https://asset-group.github.io/disclosures/sweyntooth/
Symantec Endpoint Protection Multiple Issues
https://support.symantec.com/us/en/article.SYMSA1505.html
DNSSEC Root Key Signing Ceremony Delayed
https://mm.icann.org/pipermail/root-dnssec-announce/2020/000121.html

Feb 13, 2020 • 6min
ISC StormCast for Thursday, February 13th 2020
Malspam Pushes Ursnif
https://isc.sans.edu/forums/diary/Malpsam+pushes+Ursnif+through+Italian+language+Word+docs/25792/
Safe Documents in Office 365 Advanced Threat Protection
https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/safe-docs
Wordpress GDPR Cookie Consent Plugin Vulnerability
https://blog.nintechnet.com/wordpress-gdpr-cookie-consent-plugin-fixed-vulnerability/
Apple Joins Fido Alliance
https://fidoalliance.org/members/
https://research.kudelskisecurity.com/2020/02/12/fido2-deep-dive-attestations-trust-model-and-security/

Feb 12, 2020 • 22min
ISC StormCast for Wednesday, February 12th 2020
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+for+February+2020/25790/
Adobe Patches
https://helpx.adobe.com/security.html
Ransomware Abuses Out of Date Driver
https://news.sophos.com/en-us/2020/02/06/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software/

Feb 11, 2020 • 6min
ISC StormCast for Tuesday, February 11th 2020
Paypal Phish is Asking for Everything
https://isc.sans.edu/forums/diary/Current+PayPal+phishing+campaign+or+give+me+all+your+personal+information/25786/
Dell SupportAssist Client Uncontrolled Search Patch Vulnerability
https://www.dell.com/support/article/ro/ro/robsdt1/sln320101/dsa-2020-005-dell-supportassist-client-uncontrolled-search-path-vulnerability?lang=en
Lock My PC Used By Support Scammers
https://fspro.net/lock-pc/
https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/
Insecure Docker Registries
https://unit42.paloaltonetworks.com/leaked-docker-code/

Feb 10, 2020 • 7min
ISC StormCast for Monday, February 10th 2020
Sandbox Detection Tricks and Nice Obfuscation in a Single VBScript
https://isc.sans.edu/forums/diary/Sandbox+Detection+Tricks+Nice+Obfuscation+in+a+Single+VBScript/25780/
Emotet Spreads via Wifi
https://www.binarydefense.com/emotet-evolves-with-new-wi-fi-spreader/
Exploit Available for sudo pwfeedback bug
https://dylankatz.com/Analysis-of-CVE-2019-18634/
xiongmail/hisilicon Vulnerability
https://censys.io/blog/probing-the-xiongmai-hisilicon-soc-vulnerability

Feb 7, 2020 • 6min
ISC StormCast for Friday, February 7th 2020
Criticial Bluetooth Vulnerability in Android (CVE-2020-0022)
https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022/
Wacom Tablets Reports Application Details to Google
https://robertheaton.com/2020/02/05/wacom-drawing-tablets-track-name-of-every-application-you-open/
Bitbucket Delivers Malware
https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware
Realtek HD Audio Driver Package DLL Preloading
https://safebreach.com/Post/Realtek-HD-Audio-Driver-Package-DLL-Preloading-and-Potential-Abuses-CVE-2019-19705


