SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Sep 3, 2019 • 5min

ISC StormCast for Tuesday, September 3rd 2019

Malware Installs Node.js https://isc.sans.edu/forums/diary/Malware+Dropping+a+Local+Nodejs+Instance/25284/ Dovecot and PigeonHole Vulnerability https://www.openwall.com/lists/oss-security/2019/08/28/3 Cloudflare Workers Spreading Malware https://medium.com/@marcelx/threat-actor-behind-astaroth-is-now-using-cloudflare-workers-to-bypass-your-security-solutions-2c658d08f4c
undefined
Sep 2, 2019 • 5min

ISC StormCast for Monday, September 2nd 2019

iOS Exploits in the Wild https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html Twitter CEO's Twitter Account Hijacked https://twitter.com/TwitterComms/status/1167528672523210752
undefined
Aug 30, 2019 • 6min

ISC StormCast for Friday, August 30th 2019

Malware Samples Compiling Their Next Stage On PremiseMalware Compiling Itself; https://isc.sans.edu/forums/diary/Malware+Samples+Compiling+Their+Next+Stage+on+Premise/25278/ CERT-Bund Attempts to Notify Users of Vulnerable Home Automation Systems https://www.heise.de/security/meldung/CERT-Bund-warnt-vor-offenen-Smarthome-Systemen-4509977.html French Authorities Shut Down Coinminer Botnet https://decoded.avast.io/janvojtesek/putting-an-end-to-retadup-a-malicious-worm-that-infected-hundreds-of-thousands/
undefined
Aug 29, 2019 • 6min

ISC StormCast for Thursday, August 29th 2019

Open Redirects: A Small But Very Common Vulnerability https://isc.sans.edu/forums/diary/Guest+Diary+Open+Redirect+A+Small+But+Very+Common+Vulnerability/25276/ CamScanner Malicious Download Component https://securelist.com/dropper-in-google-play/92496/ Ares ADB Botnet https://www.wootcloud.com/blogs/ars_botnet.html Cisco REST API Container for IOS XE Authentication Bypass https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass
undefined
Aug 28, 2019 • 7min

ISC StormCast for Wednesday, August 28th 2019

Is it "Safe" To Require TLS 1.2 for Email https://isc.sans.edu/forums/diary/Is+it+Safe+to+Require+TLS+12+for+EMail/25270/ Android Trojan Infects Tens of Thousands of Devices in 4 Months https://www.bleepingcomputer.com/news/security/android-trojan-infects-tens-of-thousands-of-devices-in-4-months/ LYCEUM Threat Group Targeting Middle East https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign
undefined
Aug 27, 2019 • 5min

ISC StormCast for Tuesday, August 27th 2019

Apple Patches Jailbreak Vulnerability https://support.apple.com/en-us/HT210549 Scanning for Pulse Secure VPN Endpoints https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2019-11510/ Emotet is Back https://www.bleepingcomputer.com/news/security/emotet-botnet-is-back-servers-active-across-the-world/
undefined
Aug 26, 2019 • 5min

ISC StormCast for Monday, August 26th 2019

Simple Mimikatz And RDPWrapper Dropper https://isc.sans.edu/forums/diary/Simple+Mimikatz+RDPWrapper+Dropper/25262/ Malware Impersonating IRS https://www.irs.gov/newsroom/security-summit-warns-of-new-irs-impersonation-email-scam-reminds-taxpayers-the-irs-does-not-send-unsolicited-emails Instagram Phishing with 2FA Codes https://nakedsecurity.sophos.com/2019/08/23/instagram-phishing-uses-2fa-as-a-lure/ GitHub Adding WebAuthn Support https://www.theregister.co.uk/2019/08/23/github_upgrades_its_twofactor_authentication_with_webauthn_support/ Lenovo Solution Center Privilege Escalation https://www.pentestpartners.com/security-blog/privesc-in-lenovo-solution-centre-10-minutes-later/
undefined
Aug 23, 2019 • 6min

ISC StormCast for Friday, August 23rd 2019

Steam Zero Days and Bug Bounty Controversy https://www.theregister.co.uk/2019/08/22/valve_bug_bounty_steam_u_turn/ bb-builder malicious npm Package https://blog.reversinglabs.com/blog/the-npm-package-that-walked-away-with-all-your-passwords Phishers Customize Branded Outlook 365 Login Pages https://www.bleepingcomputer.com/news/security/phishing-attacks-scrape-branded-microsoft-365-login-pages/
undefined
Aug 22, 2019 • 6min

ISC StormCast for Thursday, August 22nd 2019

KAPE vs. Commando VM: Red vs. Blue https://isc.sans.edu/forums/diary/KAPE+Kroll+Artifact+Parser+and+Extractor/25258/ Attacks against Exposed Sphinx Servers https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/CERT-Bund/CERT-Reports/HOWTOs/Open-Sphinx-Server/open-Sphinx-server_node.html Cisco Patches https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=50#~Vulnerabilities Newly Registered Domains Most Dangerous https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/
undefined
Aug 21, 2019 • 6min

ISC StormCast for Wednesday, August 21st 2019

Guildma Malware is Now Using Facebook and YouTube as Update Channel https://isc.sans.edu/forums/diary/Guildma+malware+is+now+accessing+Facebook+andYouTube+to+keep+uptodate/25222/ Supply Chain Issues: rest-client ruby gem backdoored https://www.theregister.co.uk/2019/08/20/ruby_gem_hacked/

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app