

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Aug 6, 2019 • 6min
ISC StormCast for Tuesday, August 6th 2019
Sexploitation E-Mail: Where did the winnings go
https://isc.sans.edu/forums/diary/Sextortion+Follow+the+Money+The+Final+Chapter/25204/
VMWare Update
https://www.vmware.com/security/advisories/VMSA-2019-0012.html
Android Update Fixes Qualcom Bug
https://source.android.com/security/bulletin/2019-08-01.html
https://blade.tencent.com/en/advisories/qualpwn/

Aug 5, 2019 • 6min
ISC StormCast for Monday, August 5th 2019
Misconfigured JIRA Leaks User Details
https://medium.com/@logicbomb_1/one-misconfig-jira-to-leak-them-all-including-nasa-and-hundreds-of-fortune-500-companies-a70957ef03c7
Google, Amazon, Apple modify policy on listening in on Assistant Recordings
https://datenschutz-hamburg.de/assets/pdf/2019-08-01_press-release-Google_Assistant.pdf
https://www.bloomberg.com/news/articles/2019-08-02/amazon-gives-option-to-disable-human-review-of-alexa-recordings
https://www.theverge.com/2019/8/2/20751270/apple-stops-contractors-siri-voice-recordings-privacy-opt-out
https://www.blog.google/products/assistant/more-information-about-our-processes-safeguard-speech-data/
NVidia Updates
https://nvidia.custhelp.com/app/answers/detail/a_id/4841/kw/Security%20Bulletin
Detecting Incognito Mode in Google Chrome 76
https://blog.jse.li/posts/chrome-76-incognito-filesystem-timing/

Aug 2, 2019 • 6min
ISC StormCast for Friday, August 2nd 2019
What Is Listening On Port 9527/TCP
https://isc.sans.edu/forums/diary/What+is+Listening+On+Port+9527TCP/25194/
PowerShell Empire Abandonded
https://github.com/EmpireProject/Empire
https://twitter.com/xorrior/status/1156626182978383874
Cryptomining via GitHub/PasteBin C&C
https://unit42.paloaltonetworks.com/rockein-the-netflow/

Aug 1, 2019 • 6min
ISC StormCast for Thursday, August 1st 2019
Phishing Attack Targeting Financial Sector
https://isc.sans.edu/forums/diary/Targeted+Phishing+Attacks+in+the+Financial+Industry+Fire3+Phishing+Kit/25188/
Enterprise Software Phoneing Home
https://www.extrahop.com/company/press-releases/2019/extrahop-issues-warning-about-phoning-home/
Google Stripping www and https again
https://bugs.chromium.org/p/chromium/issues/detail?id=883038#c114
Bypassing VISA Contactless Limits
https://www.ptsecurity.com/ww-en/about/news/visa-card-vulnerability-can-bypass-contactless-limits/

Jul 31, 2019 • 6min
ISC StormCast for Wednesday, July 31st 2019
Luno Phishing E-Mail and Badly Implemented 2FA
https://isc.sans.edu/forums/diary/Can+You+Spell+2FA+A+Luno+Phish+Example/25186/
Google Chrome Update
https://w3c.github.io/webappsec-fetch-metadata/
https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html
Apple Re-Releases 2019-004 Security Update for Sierra/High Sierra
https://support.apple.com/en-us/HT210348
Disabling Server Side Recording of Apple Siri Commands
https://github.com/jankais3r/Siri-NoLoggingPLS

Jul 30, 2019 • 7min
ISC StormCast for Tuesday, July 30th 2019
11 Flaws in VxWorks IPNet TCP/IP Stack
https://go.armis.com/urgent11
iOS iMessage File Disclosure Vulnerability
https://bugs.chromium.org/p/project-zero/issues/detail?id=1858

Jul 29, 2019 • 7min
ISC StormCast for Monday, July 29th 2019
DVRIP Port 34567 Uptick
https://isc.sans.edu/forums/diary/DVRIP+Port+34567+Uptick/25174/
LibreOffice LibreLogo Macro Python Code Injection
https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/
Extracting Private Key From Amazon Music Application
https://koen.io/2019/07/26/underscoring-the-private-in-private-key/

Jul 26, 2019 • 6min
ISC StormCast for Friday, July 26th 2019
When Users Attack: Users and Admins Thwarting Security Controls
https://isc.sans.edu/forums/diary/When+Users+Attack+Users+and+Admins+Thwarting+Security+Controls/25170/
Immunity's Canvas Now Includes BlueKeep Exploit
https://twitter.com/Immunityinc/status/1153752470130221057
Johannesburg Power Outages Due To Ransomware
https://twitter.com/CityofJoburgZA
https://www.theregister.co.uk/2019/07/25/johannesburg_ransomware_infection/
Darkmatter Intermediate Certificate Trust Removed From Google Chrome
https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/7-oKhDBLetQ

Jul 25, 2019 • 6min
ISC StormCast for Thursday, July 25th 2019
VLC not Vulnerable to libebml Vulnerablity
https://threader.app/thread/1153963312981389312
Cryptominer With BlueKeep Scanner
https://www.intezer.com/blog-watching-the-watchbog-new-bluekeep-scanner-and-linux-exploits/
Elasticsearch Vulnerabilities used to install DDoS Bot
https://blog.trendmicro.com/trendlabs-security-intelligence/multistage-attack-delivers-billgates-setag-backdoor-can-turn-elasticsearch-databases-into-ddos-botnet-zombies/
May People Be Considered As IOC?
https://isc.sans.edu/forums/diary/May+People+Be+Considered+as+IOC/25166/

Jul 24, 2019 • 6min
ISC StormCast for Wednesday, July 24th 2019
TLS Configuration
https://isc.sans.edu/forums/diary/Verifying+SSLTLS+configuration+part+1/25162/
https://www.sans.org/webcasts/beast-poodle-celebrating-sweet32-111400
Apple Updates Everything
https://support.apple.com/en-us/HT201222
QNAP/Synology Update Security Advise
https://www.qnap.com/en-us/security-advisory/nas-201907-11
https://www.facebook.com/synologydeutschland/photos/a.1594837477441905/2417134061878905/
New Bluekeep Writeup
https://github.com/0xeb-bp/bluekeep


