

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Sep 18, 2023 • 6min
ISC StormCast for Monday, September 18th, 2023
The podcast discusses the risks of using Google Authenticator, suggesting stronger options like pass keys or FIDO 2. It also highlights vulnerabilities in QNAP operating systems and explores phishing-resistant authentication methods and cross-site scripting vulnerabilities in various platforms.

Sep 15, 2023 • 6min
ISC StormCast for Friday, September 15th, 2023
DShield and eqmu, logging experts, discuss Raspberry Pi debugging on Windows, vulnerabilities in the NCURSIS library, exploiting Windows Themes, and the deployment of the three AM ransomware as a backup plan.

Sep 14, 2023 • 6min
ISC StormCast for Thursday, September 14th, 2023
Backdoored Free DownloadManager
https://securelist.com/backdoored-free-download-manager-linux-malware/110465/
Foxit PDF Reader Updates
https://www.foxit.com/support/security-bulletins.html
macOS MetaStealer: New Family of Obfuscated Go Infostealers
https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/
Windows 11 to Support Blocking SMB NTLM Hashes
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206

Sep 13, 2023 • 6min
ISC StormCast for Wednesday, September 13th, 2023
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214
OpenSSL 1.1.1 End of Life
https://www.openssl.org/blog/blog/2023/09/11/eol-111/
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html

Sep 12, 2023 • 6min
ISC StormCast for Tuesday, September 12th, 2023
Apple Patches Older Operating Systems
https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210
Wi-Fi Enabled Practical Keystroke Eavesdropping
https://arxiv.org/pdf/2309.03492.pdf
Phishing via Google Looker Studio
https://blog.checkpoint.com/security/phishing-via-google-looker-studio
HPE One View Authentication Bypass
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us

Sep 11, 2023 • 7min
ISC StormCast for Monday, September 11th, 2023
Augmenting Honeypot Logs
https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204
More details about Apple 0-day
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs
Odd Password Solution
https://notpickard.com/@rdp/111009868239846779

Sep 8, 2023 • 5min
ISC StormCast for Friday, September 8th, 2023
Apple Patches 0-Days
https://isc.sans.edu/diary/30200
https://support.apple.com/en-us/HT201222
iOS Fleezeware/Scareware
https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198
Aruba Vulnerabilities
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt
TP Link Vulnerabilities
https://jvn.jp/en/vu/JVNVU99392903/

Sep 7, 2023 • 6min
ISC StormCast for Thursday, September 7th, 2023
Security Related DNS Records
https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194
Microsoft Reveleas Details about Key Loss
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
September Android Updates
https://source.android.com/docs/security/bulletin/2023-09-01
Google Chrome Update
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html
Atlas VPN Tunnel Termination Vulnerability
https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/

Sep 6, 2023 • 6min
ISC StormCast for Wednesday, September 6th, 2023
Common Usernames Submitted to Honeypots
https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188
TPM LUKS Bypass
https://pulsesecurity.co.nz/advisories/tpm-luks-bypass
Cross Tenant Impersonation Prevention and Detection
https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection

Sep 5, 2023 • 6min
ISC StormCast for Tuesday, September 5th, 2023
What is the Origin of Passwords Submitted to Honeypots
https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182
Creating a YARA Rule to Detect Obfuscated Strings
https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186
VMware Aria Operations for Networks Hardcoded Keys 2023-34039
https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/
https://github.com/sinsinology/CVE-2023-34039/
Windows will Disable TLS 1.0/1.1
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center