

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jan 9, 2020 • 6min
ISC StormCast for Thursday, January 9th 2020
Critical Firefox Update Fixing Exploited Bug
https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/
3 Google Play Store Apps Exploit Android Zero-Day
https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/
Tails 4.2
https://tails.boum.org/news/version_4.2/index.en.html
TikTok Vulnerablities
https://research.checkpoint.com/2020/tik-or-tok-is-tiktok-secure-enough/

Jan 8, 2020 • 5min
ISC StormCast for Wednesday, January 8th 2020
Citrix ADC Update
https://isc.sans.edu/forums/diary/A+Quick+Update+on+Scanning+for+CVE201919781+Citrix+ADC+Gateway+Vulnerability/25686/
Pulse Secure SSLVPN Exploited
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/
https://www.darkreading.com/attacks-breaches/widely-known-flaw-in-pulse-secure-vpn-being-used-in-ransomware-attacks/d/d-id/1336729
Google Project Zero Changing Disclosure Policy
https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html
Google Updates Android
https://source.android.com/security/bulletin/2020-01-01

Jan 7, 2020 • 5min
ISC StormCast for Tuesday, January 7th 2020
Spoofed Scans from 103/8
https://isc.sans.edu/forums/diary/Increase+in+Number+of+Sources+January+3rd+and+4th+spoofed/25678/
Iran Terror Threat
https://www.dhs.gov/sites/default/files/ntas/alerts/20_0104_ntas_bulletin.pdf
BusKill Laptop Kill Cord
https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-man-switch/

Jan 6, 2020 • 5min
ISC StormCast for Monday, January 6th 2020
Quick Summary of the California Conumser Privacy Act
https://isc.sans.edu/forums/diary/CCPA+Quick+Overview/25668/
Cisco Vulnerabilities
https://tools.cisco.com/security/center/publicationListing.x
XiaoMi Camera Cache Bug
https://www.reddit.com/r/googlehome/comments/eine1m/when_i_load_the_xiaomi_camera_in_my_google_home/

Jan 3, 2020 • 8min
ISC StormCast for Friday, January 3rd 2020
Ransomware written in JavaScript using Node.js
https://isc.sans.edu/forums/diary/Ransomware+in+Nodejs/25664/
Landry Restaurant PoS Breach
https://www.landrysinc.com/CreditNotice/CANotice.asp
Holiday Hack Challenge
https://www.holidayhackchallenge.com
Citrix/NetScaler Vulnerability Special Webcast Recording
https://i5c.us/citrix

Dec 31, 2019 • 7min
ISC StormCast for Tuesday, December 31st 2019
ISC API Update
https://isc.sans.edu/api
https://isc.sans.edu/forums/diary/Miscellaneous+Updates+to+our+Threatfeed+API/25654/
CCC Conference
https://fahrplan.events.ccc.de/congress/2019/Fahrplan/
https://events.ccc.de/congress/2019/wiki/index.php/Main_Page

Dec 30, 2019 • 6min
ISC StormCast for Monday, December 30th 2019
Breaking 2FA Soft Tokens
https://resources.fox-it.com/rs/170-CAK-271/images/201912_Report_Operation_Wocao.pdf
PiHole Dashboard
https://isc.sans.edu/forums/diary/ELK+Dashboard+for+Pihole+Logs/25652/
Corrupt Office Documents
https://isc.sans.edu/forums/diary/Corrupt+Office+Documents/25650/
Enumerating Office 365 Users
https://isc.sans.edu/forums/diary/Enumerating+office365+users/25648/

Dec 27, 2019 • 4min
ISC StormCast for Friday, December 27th 2019
Citrix Application Delivery Controller (Netscaler ADC) Critical Vulnerability
https://www.ptsecurity.com/ww-en/about/news/citrix-vulnerability-allows-criminals-to-hack-networks-of-80000-companies/
https://support.citrix.com/article/CTX267027

Dec 23, 2019 • 5min
ISC StormCast for Monday, December 23rd 2019
Extracting VBA Macros From .DWG Files
https://isc.sans.edu/forums/diary/Extracting+VBA+Macros+From+DWG+Files/25634/
Cisco PKI Self-Signed Certificate Expiration
https://www.cisco.com/c/en/us/support/docs/field-notices/704/fn70489.html
AFRINIC IP Address Space Misappropriated By Insider
https://mybroadband.co.za/news/internet/330379-how-internet-resources-worth-r800-million-were-stolen-and-sold-on-the-black-market.html

Dec 20, 2019 • 5min
ISC StormCast for Friday, December 20th 2019
More DNS over HTTPS Details
https://isc.sans.edu/forums/diary/More+DNS+over+HTTPS+Become+One+With+the+Packet+Be+the+Query+See+the+Query/25628/
Ransomware Outing Victims
https://krebsonsecurity.com/2019/12/ransomware-gangs-now-outing-victim-businesses-that-dont-pay-up/
Google Chrome Update
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop_17.html


