

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Sep 23, 2019 • 5min
ISC StormCast for Monday, September 23rd 2019
Popular Android Selfie Apps Act as Adware
https://www.wandera.com/mobile-security/google-play-adware/
Wireshark Update
https://www.wireshark.org/docs/relnotes/wireshark-3.0.5.html
Harbor Privilege Escalation
https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/

Sep 20, 2019 • 5min
ISC StormCast for Friday, September 20th 2019
Agent Tesla
https://isc.sans.edu/forums/diary/Agent+Tesla+Trojan+Abusing+Corporate+Email+Accounts/25336/
Apple Updates
https://support.apple.com/en-us/HT201222
https://developer.apple.com/documentation/safari_release_notes/safari_13_release_notes
SAMBA 4.11 Released
https://www.samba.org/samba/history/samba-4.11.0.html
GitHub Security Updates
https://github.blog/2019-09-18-securing-software-together/

Sep 19, 2019 • 6min
ISC StormCast for Thursday, September 19th 2019
Analyzing a Current Emotet Sample
https://isc.sans.edu/forums/diary/Emotet+malspam+is+back/25330/
Windows Defender "Scan Now" Failed Bug Fix
https://www.bleepingcomputer.com/news/microsoft/windows-defender-antivirus-scans-broken-after-new-update/
https://borncity.com/win/2019/09/18/defender-antimalware-version-4-18-1908-7-released/
QEMU Vulnerablity
https://www.openwall.com/lists/oss-security/2019/09/17/1
VMWare Vulnerabilty
https://blogs.vmware.com/security/2019/09/amd-display-driver-security-updates-address-cve-2019-5685.html
New CWE Top 25 Released
https://cwe.mitre.org/top25/archive/2019/2019_cwe_top25.html

Sep 18, 2019 • 6min
ISC StormCast for Wednesday, September 18th 2019
Investigating Gaps in Windows Event Logs
https://isc.sans.edu/forums/diary/Investigating+Gaps+in+your+Windows+Event+Logs/25328/
SOHOpelesly Broken 2
https://www.securityevaluators.com/whitepaper/sohopelessly-broken-2/
HP Printer Privacy
https://robertheaton.com/2019/09/15/hp-printers-send-data-on-what-you-print-back-to-hp/

Sep 17, 2019 • 7min
ISC StormCast for Tuesday, September 17th 2019
Encrypted Sextortion
https://isc.sans.edu/forums/diary/Encrypted+Sextortion+PDFs/25324/
SimJacker
https://www.adaptivemobile.com/blog/simjacker-next-generation-spying-over-mobile
LastPass Password Leak
https://bugs.chromium.org/p/project-zero/issues/detail?id=1930
Microsoft Extends EoL For Exchange Server 2010
https://techcommunity.microsoft.com/t5/Exchange-Team-Blog/Microsoft-Extending-End-of-Support-for-Exchange-Server-2010-to/ba-p/753591

Sep 16, 2019 • 6min
ISC StormCast for Monday, September 16th 2019
Rig Exploit Kit Delivering VBScript
https://isc.sans.edu/forums/diary/Rig+Exploit+Kit+Delivering+VBScript/25318/
Pentesters Arrested During Physical Access Pentest
https://arstechnica.com/information-technology/2019/09/check-the-scope-pen-testers-nabbed-jailed-in-iowa-courthouse-break-in-attempt/
iOS Lock Screen Unlock Vulnerability
https://www.theregister.co.uk/2019/09/12/apples_ios_lock_workaround/

Sep 11, 2019 • 5min
ISC StormCast for Wednesday, September 11th 2019
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+September+2019+Patch+Tuesday/25310/
Adobe Patches
https://helpx.adobe.com/security.html
Intel SSH Side Channel Vulnerability
https://www.vusec.net/projects/netcat/
https://www.cs.vu.nl/~herbertb/download/papers/netcat_sp20.pdf

Sep 10, 2019 • 6min
ISC StormCast for Tuesday, September 10th 2019
Firefox to Enable DNS over HTTPs by Default in September
https://blog.mozilla.org/futurereleases/2019/09/06/whats-next-in-making-dns-over-https-the-default/
Telegram Fixes Privacy Bug
https://www.inputzero.io/2019/09/telegram-privacy-fails-again.html
PsiXBot Uses DoH
https://www.proofpoint.com/us/threat-insight/post/psixbot-now-using-google-dns-over-https-and-possible-new-sexploitation-module

Sep 9, 2019 • 5min
ISC StormCast for Monday, September 9th 2019
Unidentified Scanning Activity Likely Associated with Mirai/Successors
https://isc.sans.edu/forums/diary/Unidentified+Scanning+Activity/25304/
Bluekeep Exploit Now in Metasploit
https://blog.rapid7.com/2019/09/06/initial-metasploit-exploit-module-for-bluekeep-cve-2019-0708/
How to Remove GMail Calendar Spam
https://support.google.com/calendar/answer/6084018?co=GENIE.Platform%3DDesktop&hl=en
Exim SNI TLS Vulnerability
https://exim.org/static/doc/security/CVE-2019-15846.txt

Sep 4, 2019 • 6min
ISC StormCast for Wednesday, September 4th 2019
Tricky Link Retrieves Trick Bot
https://isc.sans.edu/forums/diary/Guest+Diary+Tricky+LNK+points+to+TrickBot/25290/
Supermicro Virtual USB Vulnerability
https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/
Facebook Free Basics Key Used to Sign Unrelated Android Apps
https://www.androidpolice.com/2019/08/29/cryptographic-key-used-to-sign-one-of-facebooks-android-apps-compromised/


