SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Oct 2, 2018 • 6min

ISC StormCast for Tuesday, October 2nd 2018

Update About Facebook Breach https://newsroom.fb.com/news/2018/09/security-update/ Adobe Acrobat/Reader Update https://helpx.adobe.com/security/products/acrobat/apsb18-30.html SMTP MTA Strict Transport Security (MTA-STS) https://www.rfc-editor.org/rfc/rfc8461.txt
undefined
Oct 1, 2018 • 6min

ISC StormCast for Monday, October 1st 2018

Facebook Leaks more than 50 Million Accounts https://newsroom.fb.com/news/2018/09/security-update/ Telegram Leaks Local IP Address By Default https://www.inputzero.io/2018/09/bug-bounty-telegram-cve-2018-17780.html Site Tricks Users Into Subscribing to Browser Notifications https://www.bleepingcomputer.com/news/security/sites-trick-users-into-subscribing-to-browser-notification-spam/ DDE Code Injection https://isc.sans.edu/forums/diary/More+Excel+DDE+Code+Injection/24150/
undefined
Sep 28, 2018 • 6min

ISC StormCast for Friday, September 28th 2018

Enriching Radare2 and x64dbg malware analysis with statically decoded strings https://isc.sans.edu/forums/diary/Enriching+Radare2+and+x64dbg+malware+analysis+with+statically+decoded+strings/24146/ Weaknesses in Apple's Mobile Device Management https://duo.com/labs/research/mdm-me-maybe LoJax UEFI Rootkit https://www.welivesecurity.com/2018/09/27/lojax-first-uefi-rootkit-found-wild-courtesy-sednit-group/
undefined
Sep 27, 2018 • 5min

ISC StormCast for Thursday, September 27th 2018

Emotet Malware Delivery Service Update https://isc.sans.edu/forums/diary/One+Emotet+infection+leads+to+three+followup+malware+infections/24140/ Fedora Crypto Policy Update Causes SSH Issues https://bugzilla.redhat.com/show_bug.cgi?id=1631970 Android Banking Trojan Impersonates QRecorder https://lukasstefanko.com/2018/09/banking-trojan-found-on-google-play-stole-10000-euros-from-victims.html Google Reverts Changes to Chrome https://www.blog.google/products/chrome/product-updates-based-your-feedback/amp/
undefined
Sep 26, 2018 • 5min

ISC StormCast for Wednesday, September 26th 2018

Firefox Haveibeenpwned Monitor https://blog.mozilla.org/blog/2018/09/25/introducing-firefox-monitor-helping-people-take-control-after-a-data-breach/ Chrome 69 Privacy Issues https://www.bleepingcomputer.com/news/google/chrome-69-keeps-googles-cookies-after-you-clear-browser-data/ Cisco FragmentSmack Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-ip-fragment Micorsoft Bitlocker Turns itself Off During Updates https://social.technet.microsoft.com/Forums/en-US/0e48536f-40ff-4046-bd08-ed4a39b4840f/bitlocker-automatically-suspending-during-updates?forum=win10itprosecurity
undefined
Sep 25, 2018 • 6min

ISC StormCast for Tuesday, September 25th 2018

More Sextortion Emails https://isc.sans.edu/forums/diary/Sextortion+Spam+and+the+Infinite+Monkey+Theorem/24136/ MacOS 10.14 (Mojahve) Security Fixes https://support.apple.com/en-us/HT209139 Mojave Privacy Protection Bypass https://vimeo.com/291491984 Cloudflare Supporting Encrypted SNI https://blog.cloudflare.com/esni/
undefined
Sep 24, 2018 • 5min

ISC StormCast for Monday, September 24th 2018

Odd DNS Requests from Firewalls https://isc.sans.edu/forums/diary/Suspicious+DNS+Requests+Issued+by+a+Firewall/24128/ Securing API Connections https://isc.sans.edu/forums/diary/The+danger+of+sending+information+for+API+consumption+without+adequate+security+measures/24130/ Microsoft JET Database 0day https://www.zerodayinitiative.com/advisories/ZDI-18-1075/ Western Digital Releases Patch for MyCloud Drives https://support.wdc.com/knowledgebase/answer.aspx?ID=25952&s Job Offers With Malware Attachment https://www.bleepingcomputer.com/news/security/malware-disguised-as-job-offers-distributed-on-freelance-sites/
undefined
Sep 21, 2018 • 13min

ISC StormCast for Friday, September 21st 2018

Hunting for Suspicious Processes with OSSEC https://isc.sans.edu/forums/diary/Hunting+for+Suspicious+Processes+with+OSSEC/24122/ NSSLabs Sues Crowdstrike, Symantec, ESET https://www.nsslabs.com/blog/company/advancing-transparency-and-accountability-in-the-cybersecurity-industry/ Bitcoin Core Vulnerability https://motherboard.vice.com/amp/en_us/article/qvakp3/a-major-bug-in-bitcoin-software-could-have-crashed-the-currency?__twitter_impression=true WebAuthn Standard https://paragonie.com/blog/2018/08/security-concerns-surrounding-webauthn-don-t-implement-ecdaa-yet https://fidoalliance.org/
undefined
Sep 20, 2018 • 5min

ISC StormCast for Thursday, September 20th 2018

Adobe Releases Special Patch for Acrobat and Reader https://helpx.adobe.com/security/products/acrobat/apsb18-34.html Akamai State of the Internet Report https://www.akamai.com/us/en/about/our-thinking/state-of-the-internet-report/global-state-of-the-internet-security-ddos-attack-reports.jsp Peekabo DVR Vulnerability https://www.tenable.com/blog/tenable-research-advisory-peekaboo-critical-vulnerability-in-nuuo-network-video-recorder
undefined
Sep 19, 2018 • 5min

ISC StormCast for Wednesday, September 19th 2018

Certificate Transparency Tools https://isc.sans.edu/forums/diary/Using+Certificate+Transparency+as+an+Attack+Defense+Tool/24114/ Kodi Malicious Add-Ons https://www.welivesecurity.com/2018/09/13/kodi-add-ons-launch-cryptomining-campaign/ Cloudflare Making DNSSEC Adoption Easier https://blog.cloudflare.com/automatically-provision-and-maintain-dnssec/ Western Digital MyCloud Unauthenticated Admin Access https://www.securify.nl/advisory/SFY20180102/authentication-bypass-vulnerability-in-western-digital-my-cloud-allows-escalation-to-admin-privileges.html

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app