

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Feb 23, 2023 • 6min
ISC StormCast for Thursday, February 23rd, 2023
Internet Wide Scan Fingerprinting Confluence Servers
https://isc.sans.edu/diary/Internet%20Wide%20Scan%20Fingerprinting%20Confluence%20Servers/29574
Apple Updates Advisories
https://support.apple.com/en-us/HT213606
https://support.apple.com/en-us/HT213605
https://www.trellix.com/en-us/about/newsroom/stories/research/trellix-advanced-research-center-discovers-a-new-privilege-escalation-bug-class-on-macos-and-ios.html
Questionable two-factor Apps
https://twitter.com/mysk_co/status/1627097291063435264
VMWare Carbon Black App Control Vulnerability
https://www.vmware.com/security/advisories/VMSA-2023-0004.html

Feb 22, 2023 • 5min
ISC StormCast for Wednesday, February 22nd, 2023
Phishing Page Branded with Your Corporate Website
https://isc.sans.edu/diary/Phishing%20Page%20Branded%20with%20Your%20Corporate%20Website/29570
Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs
https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/
Apache Commons FileUpload Vulnerability
https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy
VMWare Windows Server 2022 Fix
https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-esxi-70u3k-release-notes.html#resolvedissues

Feb 21, 2023 • 6min
ISC StormCast for Tuesday, February 21st, 2023
OneNote Suricata Rules
https://isc.sans.edu/diary/OneNote%20Suricata%20Rules/29564
New IIS Backdoor
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/frebniis-malware-iis
Outlook Spam
https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/
Godaddy Breach and Website Redirects
https://aboutus.godaddy.net/newsroom/company-news/news-details/2023/Statement-on-recent-website-redirect-issues/default.aspx

Feb 20, 2023 • 6min
ISC StormCast for Monday, February 20th, 2023
Phishing Emails to out Handlers Inbox
https://isc.sans.edu/diary/Spear%20Phishing%20Handlers%20for%20Username%20Password/29560
Twitter Alters 2FA
https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter
Fortinet Updates
https://www.fortiguard.com/psirt-monthly-advisory/february-2023-vulnerability-advisories
https://twitter.com/Horizon3Attack/status/1626692778062237713
Cisco ClamAV Patches
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy

Feb 17, 2023 • 5min
ISC StormCast for Friday, February 17th, 2023
HTML Phishing Attachment with Browser-in-the-Browser Technique
https://isc.sans.edu/diary/HTML%20phishing%20attachment%20with%20browser-in-the-browser%20technique/29556
Windows Server 2022 Might Not Start Up After Updates
https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#windows-server-2022-might-not-start-up
New ESXiArgs Encryption Routing Outmaneuvers Recovery Methods
https://www.malwarebytes.com/blog/news/2023/02/new-esxiargs-encryption-routine-outmaneuvers-recovery-methods
PHP Updates
https://www.php.net
ClamAV Patches
https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html

Feb 16, 2023 • 6min
ISC StormCast for Thursday, February 16th, 2023
DNS Recon Redux
https://isc.sans.edu/diary/DNS%20Recon%20Redux%20-%20Zone%20Transfers%20%28plus%20a%20time%20machine%29%20for%20When%20You%20Can%27t%20do%20a%20Zone%20Transfer/29552
GitHub Copilot Update
https://github.blog/2023-02-14-github-copilot-now-has-a-better-ai-model-and-new-capabilities/
Hyundai Software Update
https://www.hyundaiantitheft.com
Citrix Patches CVE-2023-24486, CVE-2023-24484, CVE-2023-24485, and CVE-2023-24483
https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/citrix-releases-security-updates-workspace-apps-virtual-apps-and
HA Proxy Patch CVE-2023-25725
https://www.mail-archive.com/haproxy@formilux.org/msg43229.html
Firefox Patches
https://www.mozilla.org/en-US/security/advisories/mfsa2023-05/

Feb 15, 2023 • 6min
ISC StormCast for Wednesday, February 15th, 2023
Microsoft February 2023 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20February%202023%20Patch%20Tuesday/29548
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Intel OpenBMC Vulnerabilities
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html

Feb 14, 2023 • 6min
ISC StormCast for Tuesday, February 14th, 2023
Apple Patches Exploited Vulnerablity
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/29544
Venmo Phishing Abusing LinkedIn "slink"
https://isc.sans.edu/diary/Venmo+Phishing+Abusing+LinkedIn+slink/29542/
Malicious PyPi Packages Install Browser Extensions
https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack

Feb 13, 2023 • 5min
ISC StormCast for Monday, February 13th, 2023
Obfuscated Deactivation of Script Block Logging
https://isc.sans.edu/diary/Obfuscated%20Deactivation%20of%20Script%20Block%20Logging/29538
PCAP Data Analysis with Zeek
https://isc.sans.edu/diary/PCAP%20Data%20Analysis%20with%20Zeek/29530
Bing Chat Prompt Injection
https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/
More Malicious Python Packages
https://blog.sonatype.com/malicious-aptx-python-package-drops-meterpreter-shell-deletes-netstat

Feb 10, 2023 • 5min
ISC StormCast for Friday, February 10th, 2023
A Backdoor with Smart Screenshot Capability
https://isc.sans.edu/diary/A%20Backdoor%20with%20Smart%20Screenshot%20Capability/29534
KeePass Patches Issue Allowing Password Export
https://keepass.info/news/n230109_2.53.html
AWS Phishing via Google Ads
https://www.sentinelone.com/blog/cloud-credentials-phishing-malicious-google-ads-target-aws-logins/
Apache Kafka Vulnerability
https://lists.apache.org/thread/vy1c7fqcdqvq5grcqp6q5jyyb302khyz