

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jun 26, 2018 • 7min
ISC StormCast for Tuesday, June 26th 2018
Guilty By Association
https://isc.sans.edu/forums/diary/Guilty+by+association/23800/
Filezila and Adware
https://forum.filezilla-project.org/viewtopic.php?t=48441
iOS Pin Brute Forcing Confusion
https://twitter.com/hackerfantastic/status/1010631766087032832
https://twitter.com/hackerfantastic/status/1010240042990596096
Azure Baseline Security Policy
https://cloudblogs.microsoft.com/enterprisemobility/2018/06/22/baseline-security-policy-for-azure-ad-admin-accounts-in-public-preview/
Phone Battery Usage as Keystroke Logger
https://sites.google.com/site/silbersteinmark/Home/popets18power.pdf?attredirects=1

Jun 25, 2018 • 6min
ISC StormCast for Monday, June 25th 2018
XPS Documents Used for Spam
https://isc.sans.edu/forums/diary/XPS+Attachment+Used+for+Phishing/23794/
New Exploit Kit Trends
https://researchcenter.paloaltonetworks.com/2018/06/unit42-the-old-and-new-current-trends-in-web-based-threats/
https://blog.malwarebytes.com/cybercrime/2018/06/exploit-kits-spring-2018-review/
Deprecating TLSv1.0 and TLSv1.1
https://datatracker.ietf.org/doc/draft-moriarty-tls-oldversions-diediedie/
Leaky Firebase Installs
http://info.appthority.com/-q2-2018-mtr-download-Firebase-vulnerability

Jun 22, 2018 • 6min
ISC StormCast for Friday, June 22nd 2018
Fake Fortnite
https://blog.malwarebytes.com/cybercrime/2018/06/fake-fortnite-android-links-found-youtube/
Fake Wannacry E-Mails
https://twitter.com/actionfrauduk/status/1009803967705092096
Ransomware Installs In Internet Cafes
http://hznews.hangzhou.com.cn/shehui/content/2018-06/16/content_7020998.htm
OpenVPN Malicious Configuration Files
https://medium.com/tenable-techblog/reverse-shell-from-an-openvpn-configuration-file-73fd8b1d38da
Cisco Advisories
https://tools.cisco.com/security/center/publicationListing.x

Jun 21, 2018 • 7min
ISC StormCast for Thursday, June 21st 2018
Netflix Phishing Sites Using TLS
https://isc.sans.edu/forums/diary/Secure+Phishing+Netflix+Phishing+Goes+TLS/23786/
OpenBSD Disables Hyperthreading By Default
https://www.mail-archive.com/source-changes@openbsd.org/msg99141.html
Bithumb Cyrpto Currency Exchnage Breached Again
https://www.bleepingcomputer.com/news/security/bithumb-hacked-second-time-in-a-year-hackers-steal-31-million/
Microsoft Edge CORS Bypass via Audio Files
https://jakearchibald.com/2018/i-discovered-a-browser-bug/
Microsoft Releases a Special Patch for Oracle Outside-In Libraries
https://support.microsoft.com/en-us/help/4092041/description-of-the-security-update-for-microsoft-exchange-server-2013

Jun 19, 2018 • 6min
ISC StormCast for Wednesday, June 20th 2018
PowerShell ScriptBlock Loggin Bypass in the Wild
https://isc.sans.edu/forums/diary/PowerShell+ScriptBlock+Logging+Or+Not/23782/
Virustotal "False Positive" Alert
http://blog.virustotal.com/2018/06/vtmonitor-to-mitigate-false-positives.html
Cloud Environments Explosed to the Internet
https://info.lacework.com/hubfs/Containers%20At-Risk_%20A%20Review%20of%2021,000%20Cloud%20Environments.pdf
Google Home DNS Rebinding Attack Reveals Geolocation
https://www.tripwire.com/state-of-security/vert/googles-newest-feature-find-my-home

Jun 19, 2018 • 6min
ISC StormCast for Tuesday, June 19th 2018
Obfuscated JavaScript Targeting Mobile Devices
https://isc.sans.edu/forums/diary/Malicious+JavaScript+Targeting+Mobile+Browsers/23778/
Axis Camera Vulnerabilities
https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/
Apple Caches Confidential Data on Unencrypted Drives
https://wojciechregula.blog/your-encrypted-photos-in-macos-cache/
Andy Emulator Infected With CryptoMiner
https://www.reddit.com/r/emulators/comments/8rj8g5/warning_andy_android_emulator_andyos_andyroid/

Jun 18, 2018 • 7min
ISC StormCast for Monday, June 18th 2018
SMTP Strangeness - Possible C2
https://isc.sans.edu/forums/diary/SMTP+Strangeness+Possible+C2/23770/
Encrypted Office Documents
https://isc.sans.edu/forums/diary/Encrypted+Office+Documents/23774/
Recent Port 8000 Scans
https://www.bleepingcomputer.com/news/security/all-that-port-8000-traffic-this-week-yeah-thats-satori-looking-for-new-bots/
New Clipboard Cryptocoin Stealing Bot
https://blog.360totalsecurity.com/en/new-cryptominer-hijacks-your-bitcoin-transaction-over-300000-computers-have-been-attacked/
WebUSB Weakness
https://pwnaccelerator.github.io/2018/webusb-yubico-disclosure.html

Jun 15, 2018 • 12min
ISC StormCast for Friday, June 15th 2018
Analyzing a Compromised Wordpress Site
https://isc.sans.edu/forums/diary/A+Bunch+of+Compromized+Wordpress+Sites/23764/
Breacking Bluetooth Low Energy Smart Padlock
https://www.pentestpartners.com/security-blog/totally-pwning-the-tapplock-smart-lock/
WIM Disk Image Vulnerability
https://blog.talosintelligence.com/2018/06/vulnerability-spotlight-talos-2018-0545.html
Extracting Timely Sign-In Data from Office 365 Logs
https://www.sans.org/reading-room/whitepapers/logging/extracting-timely-sign-in-data-office-365-logs-38435

Jun 14, 2018 • 6min
ISC StormCast for Thursday, June 14th 2018
From MicroTik With Love: Yet Another Router Botnet?
https://isc.sans.edu/forums/diary/From+Microtik+with+Love/23762/
Using Cortana To Compromise Windows 10
https://securingtomorrow.mcafee.com/mcafee-labs/want-to-break-into-a-locked-windows-10-device-ask-cortana-cve-2018-8140/
Compromised Docker Images
https://kromtech.com/blog/security-center/cryptojacking-invades-cloud-how-modern-containerization-trend-is-exploited-by-attackers
Lazy FPU Save/Restore Allows Malware Access to FPU
https://access.redhat.com/solutions/3485131

Jun 13, 2018 • 6min
ISC StormCast for Wednesday, June 13th 2018
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+June+2018+Patch+Tuesday/23758/
Apple Code Signing Verification Vulnerability
https://www.okta.com/security-blog/2018/06/issues-around-third-party-apple-code-signing-checks/
Google Chrome Restricting Inline Extension Install
https://blog.chromium.org/2018/06/improving-extension-transparency-for.html


