

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Nov 8, 2023 • 6min
ISC StormCast for Wednesday, November 8th, 2023
Discover the new world of DNS with designated resolvers and their implications for security and privacy. Learn about BlueNoroff, a malware targeting macOS users in cryptocurrency scams. Dive into Microsoft's advanced Authenticator features designed to enhance security by default. Join the conversation about the evolving landscape of cybersecurity and share your own experiences for a richer community interaction.

Nov 7, 2023 • 6min
ISC StormCast for Tuesday, November 7th, 2023
Explore the latest cyber threats as the hosts dive into the exploitation of Confluence CVE-2023-22518. Discover vulnerabilities in Veeam's monitoring tools and QNAP's network devices, underscoring the critical need for timely system updates. The conversation highlights the significance of proactive cybersecurity measures to minimize risks and protect data from emerging threats.

Nov 6, 2023 • 7min
ISC StormCast for Monday, November 6th, 2023
New Microsoft Exchange Zero Days
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/
StripedFly: Perennially Flying under the Radar
https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/
Send My: Sending Data over Apple's Find My Network
https://github.com/positive-security/send-my

Nov 3, 2023 • 5min
ISC StormCast for Friday, November 3rd, 2023
Quick Tip for Artificially Inflated PE Files
https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370
Apache ActiveMQ Flaw Exploited
https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt
https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/
Critical Firepower Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN
Dozens of npm Packages Caught Attempting to Deploy Reverse Shell
https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/

Nov 2, 2023 • 6min
ISC StormCast for Thursday, November 2nd, 2023
Malware Dropped Through a ZPAQ Archive
https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/
CVSS 4.0 Now Official
https://www.first.org/cvss/v4-0/index.html
MOZI Botnet Killswitch
https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/
URL Shorteners in .us
https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/
Impersonating Slack Users
https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html

Nov 1, 2023 • 4min
ISC StormCast for Wednesday, November 1st, 2023
Multiple Layers of Anti-Sandboxing Techniques
https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362
CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server
https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html
Malvertisement Promotes Malicious PyCharm Version
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza
Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174
https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/

Oct 31, 2023 • 6min
ISC StormCast for Tuesday, October 31st, 2023
Flying under the Radar: The Privacy Impact of Mulicast DNS
https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/
Kubernetes ingress-nginx vulnerability
https://github.com/kubernetes/ingress-nginx/issues/10571
Google Chrome HTTPS Upgrade
https://github.com/dadrian/https-upgrade/blob/main/explainer.md
Wordpad POC CVE-2023-36563
https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/

Oct 30, 2023 • 6min
ISC StormCast for Monday, October 30th, 2023
Size Matters for Many Security Controls
https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352
Spam or Phishing? Looking for Credentials and Passwords
https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354
iOS Leaks MAC Address
https://www.youtube.com/watch?v=T3XABxNogTA
Zero Day Initiative Pwn2Own Summary
https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results
https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results
https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results
Microsoft Octo Tempest Writeup
https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/

Oct 27, 2023 • 6min
ISC StormCast for Friday, October 27th, 2023
Adventures in Validating IPv4 Addresses
https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/
BIG-IP Configuration Utility Unauthenticated Remote Code Execution
https://my.f5.com/manage/s/article/K000137353
https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
iLeakage Vulnerability
https://ileakage.com/

Oct 26, 2023 • 6min
ISC StormCast for Thursday, October 26th, 2023
Apple Updates
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344
Confluence Server Scans CVE-2023-22515
https://isc.sans.edu/diary/30342
Critical VMVware vCenter Patch CVE-2023-34048
https://www.vmware.com/security/advisories/VMSA-2023-0023.html