

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Dec 8, 2022 • 5min
ISC StormCast for Thursday, December 8th, 2022
ZeroBot / WSZero IoT Botnet
https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities
https://blog.netlab.360.com/new-ddos-botnet-wszeor/
Cacti Vulnerability CVE-2022-46169
https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf
Wireshark Updates
https://www.wireshark.org/docs/relnotes/wireshark-4.0.2.html
Apple iCloud Security Improvements
https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/

Dec 7, 2022 • 6min
ISC StormCast for Wednesday, December 7th, 2022
Mirai Botnet and Gafgyt DDoS Team Up
https://isc.sans.edu/forums/diary/Mirai%20Botnet%20and%20Gafgyt%20DDoS%20Team%20Up%20Against%20SOHO%20Routers./29304/Gafgyt/Mirai Sample; Packet Tuesday;
Packet Tuesday Episode 4: TLS Client Hello
https://www.youtube.com/playlist?list=PLs4eo9Tja8biVteSW4a3GHY8qi0t1lFLL
Defcon Skimming: A new batch of Web Skimming attacks
https://blog.jscrambler.com/defcon-skimming-a-new-batch-of-web-skimming-attacks
Fake D-Link Vulnerability used by Moobot
https://vulncheck.com/blog/moobot-uses-fake-vulnerability
Android Patches CVE-2022-20411
https://source.android.com/docs/security/bulletin/2022-12-01?hl=en

Dec 6, 2022 • 6min
ISC StormCast for Tuesday, December 6th, 2022
VLCs Check For Updates No Updates
https://isc.sans.edu/diary/VLCs+Check+For+Updates+No+Updates/29300
AMI MegaRAC Baseboard Managment Controller Vulnerabilities
https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/
Netgear IPv6 Firewall Misconfiguration
https://medium.com/tenable-techblog/netgear-router-network-misconfiguration-70ac695c81a6
Veritas NetBackup Patch
https://www.veritas.com/content/support/en_US/security/VTS22-019

Dec 5, 2022 • 9min
ISC StormCast for Monday, December 5th, 2022
QBot Update
https://isc.sans.edu/forums/diary/obama224%20distribution%20Qakbot%20tries%20.vhd%20%28virtual%20hard%20disk%29%20images/29294/
Living of the Land: Unix tools in Windows
https://isc.sans.edu/diary/Linux%20LOLBins%20Applications%20Available%20in%20Windows/29296
https://isc.sans.edu/forums/diary/Fingerexe+LOLBin/29298/
CVE-2022-44721 Crowdstrike Falcon Uninstaller
https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller
Android Platform Key Leak
https://twitter.com/MishaalRahman/status/1598426974594433025
GitHub Pipeline Vulnerability
https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust

Dec 2, 2022 • 6min
ISC StormCast for Friday, December 2nd, 2022
Quarkus Java Framework Vulnerability CVE-2022-4116
https://www.contrastsecurity.com/security-influencers/localhost-attack-against-quarkus-developers-contrast-security
https://access.redhat.com/security/cve/CVE-2022-4116
FreeBSD Ping RCE CVE-2022-23093
https://www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc
NVidia GPU Display Driver Vulnerablities CVE-2022-34669
https://nvidia.custhelp.com/app/answers/detail/a_id/5415
TrustCor CA Revoked
https://www.washingtonpost.com/technology/2022/11/30/trustcor-internet-authority-mozilla/
Android Platform Certificates Used to Sign Malware
https://bugs.chromium.org/p/apvi/issues/detail?id=100

Dec 1, 2022 • 6min
ISC StormCast for Thursday, December 1st, 2022
What is the deal wtih these router vulnerabilities
https://isc.sans.edu/diary/Whats+the+deal+with+these+router+vulnerabilities/29288/
Apple Updates
https://support.apple.com/en-us/HT201222
VLC Media Player Updates CVE-2022-41325
https://www.videolan.org/security/sb-vlc3018.html
VIN used to authenticate to Sirius XM Connected Vehicle Services
https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/

Nov 30, 2022 • 7min
ISC StormCast for Wednesday, November 30th, 2022
LinkedIn Bots
https://isc.sans.edu/diary/Identifying%20Groups%20of%20%22Bot%22%20Accounts%20on%20LinkedIn/29282
Oracle Fusion Middle Ware Exploited CVE-2021-35587
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Windows IKE Flaw Exploited CVE-2022-34721
https://www.cyfirma.com/outofband/windows-internet-key-exchange-ike-remote-code-execution-vulnerability-analysis/
Anker Eufy Cameras Sending Images to Cloud even if asked not to
https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/
Packet Tuesday
https://packettuesday.com
SANS Holiday Hack Challenge Sign Up
https://www.sans.org/mlp/holiday-hack-challenge/

Nov 29, 2022 • 7min
ISC StormCast for Tuesday, November 29th, 2022
Ukraine Themed Twitter Spam Pushing iOS Scareware
https://isc.sans.edu/diary/Ukraine%20Themed%20Twitter%20Spam%20Pushing%20iOS%20Scareware/29276
Google Maps Privacy Issues
https://garrit.xyz/posts/2022-11-24-smart-move-google
ACER UEFI BIOS Vulnerabilities
https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings
OpenSSL Usage in UEFI Firmware Exposes Weakness in SBOMs
https://www.binarly.io/posts/OpenSSL_Usage_in_UEFI_Firmware_Exposes_Weakness_in_SBOMs/index.html

Nov 28, 2022 • 7min
ISC StormCast for Monday, November 28th, 2022
Log4Shell campaigns are using Nashorn to get reverse shell on victim's machines
https://isc.sans.edu/diary/Log4Shell%20campaigns%20are%20using%20Nashorn%20to%20get%20reverse%20shell%20on%20victim%27s%20machines/29266
Attackers Keep Phishing Victms Under Stress
https://isc.sans.edu/diary/Attackers%20Keep%20Phishing%20Victims%20Under%20Stress/29270
Vulnerable SDK components lead to supply chian risks in IoT and OT environments
https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/
Google Chrome Patches 0-Day
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
Hacking Smartwatches for Spear Phishing
https://cybervelia.com/?p=1380

Nov 18, 2022 • 14min
ISC StormCast for Friday, November 18th, 2022
Lessons Learned from Automatic Failover
https://isc.sans.edu/diary/Lessons%20Learned%20from%20Automatic%20Failover%3A%20When%208.8.8.8%20%22disappears%22.%20IPv6%20to%20the%20Rescue%3F/29260
Bitbucket Server and Data Center Vulnerability
https://jira.atlassian.com/browse/BSERV-13522
Amazon RDS Snapshot Leaks
https://www.mitiga.io/blog/how-mitiga-found-pii-in-exposed-amazon-rds-snapshots
Adobe Commerce merchants to be hit with TrojanOrders this season
https://sansec.io/research/trojanorder-magento
SANS EDU Research: Detecting and Mitigating the GateKeeper User Override on macOS in an Enterprise Environment; Antonio Piazza
https://www.sans.edu/cyber-research/detecting-and-mitigating-the-gatekeeper-user-override-on-macos-in-an-enterprise-environment/