

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jul 11, 2018 • 6min
ISC StormCast for Wednesday, July 11th 2018
MSFT Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+July+2018+now+with+Dashboard/23858/
https://patchtuesdaydashboard.com/
SettingContent-ms Files Blacklisted
https://support.office.com/en-us/article/packager-activation-in-office-365-desktop-applications-52808039-4a7c-4550-be3a-869dd338d834?ui=en-US&rs=en-US&ad=US
Adobe Patches
https://helpx.adobe.com/security.html
Stolen DLINK Certificate
https://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/

Jul 10, 2018 • 6min
ISC StormCast for Tuesday, July 10th 2018
Reverse Shell via Weblogic Flaw
https://isc.sans.edu/forums/diary/Criminals+Dont+Read+Instructions+or+Use+Strong+Passwords/23850/
Apple Patches Everything Again
https://isc.sans.edu/forums/diary/Apple+Patches+Everything+Again/23852/
Microsoft Offers Better Azure AD Password Protection
http://www.longevitytech.us/2018/07/09/azure-ad-password-protection-the-cloud-security-service-your-active-directory-needs-now/

Jul 9, 2018 • 4min
ISC StormCast for Monday, July 9th 2018
Trivial Exploit For HP iLO 4 (patched last August)
https://airbus-seclab.github.io/ilo/SSTIC2018-Article-subverting_your_server_through_its_bmc_the_hpe_ilo4_case-gazet_perigaud_czarny.pdf
Flexible Miner/Ransomware
https://securelist.com/to-crypt-or-to-mine-that-is-the-question/86307/
Hacker Steals Gas From Gas Station
https://gizmodo.com/hackers-reportedly-stole-600-gallons-of-gas-from-detroi-1827433411

Jul 6, 2018 • 5min
ISC StormCast for Friday, July 6th 2018
Gentoo GitHub Breach Post Morten
https://wiki.gentoo.org/wiki/Github/2018-06-28
Hamas Sets World Cup Trap for Israeli Soldiers
https://www.reuters.com/article/us-israel-palestinians-cyber/israel-says-hamas-tried-to-snare-soldiers-in-world-cup-cyber-trap-idUSKBN1JT1ZX

Jul 5, 2018 • 3min
ISC StormCast for Thursday, July 5th 2018
Progress Indication For Scripts in Windows
https://isc.sans.edu/forums/diary/Progress+indication+for+scripts+on+Windows/23830/
Stylish Extension Steals History
https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/
Data Leaks From Android Apps
https://recon.meddle.mobi/panoptispy/

Jul 2, 2018 • 5min
ISC StormCast for Tuesday, July 3rd 2018
Odd PHP Exploit Attempt
https://isc.sans.edu/forums/diary/Hello+Peppa+PHP+Scans/23826/
Diameter Security Report
https://www.ptsecurity.com/ww-en/premium/diameter-2018/
Attack Against Trezor via DNS or BGP
https://blog.trezor.io/psa-phishing-alert-fake-trezor-wallet-website-3bcfdfc3eced
Symantec Offers VPNFilter Check
http://www.symantec.com/filtercheck/

Jul 2, 2018 • 6min
ISC StormCast for Monday, July 2nd 2018
MacOS Malware Targeting Slack/Dicord Crypto Comunities
https://isc.sans.edu/forums/diary/Crypto+community+target+of+MacOS+malware/23816/
New LTE Attacks Made Public
https://alter-attack.net
Rowhammer Attacks Against Android
https://rampageattack.com

Jun 29, 2018 • 6min
ISC StormCast for Friday, June 29th 2018
Less Greedy Cryptominers
https://isc.sans.edu/forums/diary/New+and+Improved+Cryptominers+Now+with+50+less+Greed/23812/
Disassemling Webassembly
https://www.forcepoint.com/blog/security-labs/analyzing-webassembly-binaries
Spectre Browser Mitigation Bypass
https://alephsecurity.com/2018/06/26/spectre-browser-query-cache/
Gentoo Github Repository Compromise
https://archives.gentoo.org/gentoo-announce/message/dc23d48d2258e1ed91599a8091167002

Jun 27, 2018 • 7min
ISC StormCast for Thursday, June 28th 2018
Secret Office 365 Activity Log API Unveiled (plus tool to extract logs)
http://lmgsecurity.com/exposing-the-secret-office-365-forensics-tool/
Anonymizing Printers
https://tu-dresden.de/ing/informatik/sya/ps/die-professur/news/geheime-daten-auf-dem-druckpapier-diplominformatiker-der-tu-dresden-entwickeln-verfahren-gegen-druckerueberwachung
Silently Profiling Unknown Malware Samples
https://isc.sans.edu/forums/diary/Silently+Profiling+Unknown+Malware+Samples/23808/
Cisco CVE-2018-0296 Exploited
https://www.bleepingcomputer.com/news/security/cisco-asa-flaw-exploited-in-the-wild-after-publication-of-two-pocs/

Jun 27, 2018 • 7min
ISC StormCast for Wednesday, June 27th 2018
Analyzing XPS Files
https://isc.sans.edu/forums/diary/Analyzing+XPS+files/23804/
WPA3 Standard Finalized
https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-wi-fi-certified-wpa3-security
Executing Code with SettingContent-ms Files
https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39
EFF Analysis of STARTTLS
https://www.eff.org/deeplinks/2018/06/technical-deep-dive-starttls-everywhere


