SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Nov 8, 2023 • 6min

ISC StormCast for Wednesday, November 8th, 2023

Discover the new world of DNS with designated resolvers and their implications for security and privacy. Learn about BlueNoroff, a malware targeting macOS users in cryptocurrency scams. Dive into Microsoft's advanced Authenticator features designed to enhance security by default. Join the conversation about the evolving landscape of cybersecurity and share your own experiences for a richer community interaction.
undefined
Nov 7, 2023 • 6min

ISC StormCast for Tuesday, November 7th, 2023

Explore the latest cyber threats as the hosts dive into the exploitation of Confluence CVE-2023-22518. Discover vulnerabilities in Veeam's monitoring tools and QNAP's network devices, underscoring the critical need for timely system updates. The conversation highlights the significance of proactive cybersecurity measures to minimize risks and protect data from emerging threats.
undefined
Nov 6, 2023 • 7min

ISC StormCast for Monday, November 6th, 2023

New Microsoft Exchange Zero Days https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/ StripedFly: Perennially Flying under the Radar https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/ Send My: Sending Data over Apple's Find My Network https://github.com/positive-security/send-my
undefined
Nov 3, 2023 • 5min

ISC StormCast for Friday, November 3rd, 2023

Quick Tip for Artificially Inflated PE Files https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370 Apache ActiveMQ Flaw Exploited https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/ Critical Firepower Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN Dozens of npm Packages Caught Attempting to Deploy Reverse Shell https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/
undefined
Nov 2, 2023 • 6min

ISC StormCast for Thursday, November 2nd, 2023

Malware Dropped Through a ZPAQ Archive https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/ CVSS 4.0 Now Official https://www.first.org/cvss/v4-0/index.html MOZI Botnet Killswitch https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/ URL Shorteners in .us https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/ Impersonating Slack Users https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html
undefined
Nov 1, 2023 • 4min

ISC StormCast for Wednesday, November 1st, 2023

Multiple Layers of Anti-Sandboxing Techniques https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362 CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html Malvertisement Promotes Malicious PyCharm Version https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174 https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/
undefined
Oct 31, 2023 • 6min

ISC StormCast for Tuesday, October 31st, 2023

Flying under the Radar: The Privacy Impact of Mulicast DNS https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/ Kubernetes ingress-nginx vulnerability https://github.com/kubernetes/ingress-nginx/issues/10571 Google Chrome HTTPS Upgrade https://github.com/dadrian/https-upgrade/blob/main/explainer.md Wordpad POC CVE-2023-36563 https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/
undefined
Oct 30, 2023 • 6min

ISC StormCast for Monday, October 30th, 2023

Size Matters for Many Security Controls https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352 Spam or Phishing? Looking for Credentials and Passwords https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354 iOS Leaks MAC Address https://www.youtube.com/watch?v=T3XABxNogTA Zero Day Initiative Pwn2Own Summary https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results Microsoft Octo Tempest Writeup https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/
undefined
Oct 27, 2023 • 6min

ISC StormCast for Friday, October 27th, 2023

Adventures in Validating IPv4 Addresses https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/ BIG-IP Configuration Utility Unauthenticated Remote Code Execution https://my.f5.com/manage/s/article/K000137353 https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/ iLeakage Vulnerability https://ileakage.com/
undefined
Oct 26, 2023 • 6min

ISC StormCast for Thursday, October 26th, 2023

Apple Updates https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344 Confluence Server Scans CVE-2023-22515 https://isc.sans.edu/diary/30342 Critical VMVware vCenter Patch CVE-2023-34048 https://www.vmware.com/security/advisories/VMSA-2023-0023.html

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app