SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Jan 30, 2019 • 6min

ISC StormCast for Wednesday, January 30th 2019

Phishing Not Ready for IPv6 https://isc.sans.edu/forums/diary/A+Not+So+Well+Done+Phish+Why+Attackers+need+to+Implement+IPv6+Now/24582/ Apple Disables Facetime Group Messages https://www.apple.com/support/systemstatus/ Outlook 365 Safe Link Errors https://twitter.com/Swiss_Jay/status/1090271197193940992
undefined
Jan 29, 2019 • 5min

ISC StormCast for Tuesday, January 29th 2019

Relaying Exchange's NTLM Autentication to Become Domain Admin https://isc.sans.edu/forums/diary/Relaying+Exchanges+NTLM+authentication+to+domain+admin+and+more/24578/ Facetime Bug Allows Users to Receive Audio before Call is Accepted https://9to5mac.com/2019/01/28/facetime-bug-hear-audio/ AZORult Fake (signed) Google Update https://blog.minerva-labs.com/azorult-now-as-a-signed-google-update
undefined
Jan 28, 2019 • 7min

ISC StormCast for Monday, January 28th 2019

Cisco RV320/325 Router Vulnerability Exploited https://github.com/0x27/CiscoRV320Dump https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info HTTP Signed Exchanges https://wicg.github.io/webpackage/draft-yasskin-http-origin-signed-responses.html BGP Experiments Disrupt Routers https://mailman.nanog.org/pipermail/nanog/2019-January/098761.html Packet Challenge https://johannes.homepc.org/packet9.txt
undefined
Jan 25, 2019 • 6min

ISC StormCast for Friday, January 25th 2019

Ghostscript Remote Code Execution Vulnerability https://www.openwall.com/lists/oss-security/2019/01/23/5 Abusing Exchange to Obtain Domain Admin https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/ IPC Voucher UaF Remote Jailbreak http://blogs.360.cn/post/IPC%20Voucher%20UaF%20Remote%20Jailbreak%20Stage%202%20(EN).html Cisco Security Updates https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-bo
undefined
Jan 24, 2019 • 5min

ISC StormCast for Thursday, January 24th 2019

DHS Emergency Directive Regarding DNS Tampering https://cyber.dhs.gov/ed/19-01/ Abuse of Trusted Microsoft Azure Domains https://github.com/MicrosoftDocs/OfficeDocs-Enterprise/issues/233 Tech Support Scammers Unmasked https://www.fidusinfosec.com/turning-the-tables-on-virgin-media-twitter-scammers/
undefined
Jan 23, 2019 • 7min

ISC StormCast for Wednesday, January 23rd 2019

Turning MISP Data into RPZs https://isc.sans.edu/forums/diary/DNS+Firewalling+with+MISP/24556/ Man in the Middle Vulnerablity in apt https://justi.cz/security/2019/01/22/apt-rce.html PHP PEAR Compromised Package http://pear.php.net Apple Security Updates https://support.apple.com/en-us/HT201222
undefined
Jan 22, 2019 • 6min

ISC StormCast for Tuesday, January 22nd 2019

Suspicious GET Request: Do you know what it is? https://isc.sans.edu/forums/diary/Suspicious+GET+Request+Do+You+Know+What+This+Is/24552/ DNS Flag Day https://dnsflagday.net/
undefined
Jan 21, 2019 • 6min

ISC StormCast for Monday, January 21st 2019

Drupal Patches https://www.drupal.org/sa-core-2019-002 https://www.drupal.org/sa-core-2019-001 WPML User Data Compromised and Used in EMail To Customers https://wpml.org/2019/01/wpml-org-site-back-to-normal-after-an-attack-during-the-weekend/ Targeted Attack Uses Google Drive for Exfiltration https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications/ Packet Challenge Solution https://johannes.homepc.org/packet8.txt
undefined
Jan 18, 2019 • 6min

ISC StormCast for Friday, January 18th 2019

Android Malware Uses Motion Detection to Evade Analysis https://blog.trendmicro.com/trendlabs-security-intelligence/google-play-apps-drop-anubis-banking-malware-use-motion-based-evasion-tactics/ Twitter for Android Bug https://help.twitter.com/en/protected-tweets-android Introduction to WebAuthn/FIDO2 https://medium.com/@herrjemand/introduction-to-webauthn-api-5fd1fb46c285 Ransomware As a Service https://www.bleepingcomputer.com/news/security/blackrouter-ransomware-promoted-as-a-raas-by-iranian-developer/
undefined
Jan 17, 2019 • 6min

ISC StormCast for Thursday, January 17th 2019

Emotet and Other Malspam Campaigns Resume After Holiday Break https://isc.sans.edu/forums/diary/Emotet+infections+and+followup+malware/24532/ Magecart Delivered Via Compromised Advertising Sites https://blog.trendmicro.com/trendlabs-security-intelligence/new-magecart-attack-delivered-through-compromised-advertising-supply-chain/ Premisys Identicard Vulnerabilities https://www.tenable.com/security/research/tra-2019-01 ES File Explorer Open Port Vulnerability https://github.com/fs0c131y/ESFileExplorerOpenPortVuln

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app