

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 29, 2023 • 5min
ISC StormCast for Wednesday, March 29th, 2023
Network Data Collector Placement Makes a Difference
https://isc.sans.edu/diary/Network%20Data%20Collector%20Placement%20Makes%20a%20Difference/29664
Throttling and Blocking Email from Persistently Vulnerable Exchange Servers to Exchange Online
https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/ba-p/3762078
Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
https://papers.mathyvanhoef.com/usenix2023-wifi.pdf

Mar 28, 2023 • 5min
ISC StormCast for Tuesday, March 28th, 2023
Another Malicious HTA File Analysis Part 1
https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%201/29674
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything%20%28including%20Studio%20Display%29/29682
MacStealer Malware Exfiltrates Mac Secrets
https://www.uptycs.com/blog/macstealer-command-and-control-c2-malware

Mar 27, 2023 • 5min
ISC StormCast for Monday, March 27th, 2023
Update for Windows Snipping Tool
https://isc.sans.edu/diary/Microsoft%20Released%20an%20Update%20for%20Windows%20Snipping%20Tool%20Vulnerability/29670
GitHub Rotates SSH Keys
https://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key/
redis-py vulnerability leads to mixed up sessions, affects ChatGPT
https://openai.com/blog/march-20-chatgpt-outage
Linux Tech Tips YouTube Hack
https://www.theverge.com/2023/3/23/23653115/linus-tech-tips-youtube-hack-crypto-scam
https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434
CyberChef Update
https://github.com/gchq/CyberChef/wiki/Character-encoding,-EOL-separators,-and-editor-features

Mar 24, 2023 • 6min
ISC StormCast for Friday, March 24th, 2023
Cropping and Redacting Images Safely
https://isc.sans.edu/diary/Cropping%20and%20Redacting%20Images%20Safely/29666
Untitled Goose Tool
https://github.com/cisagov/untitledgoosetool
Veeam Vulnerability Details
https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/
Unicode Support in Python used to Evade Detection
https://blog.phylum.io/malicious-actors-use-unicode-support-in-python-to-evade-detection

Mar 23, 2023 • 6min
ISC StormCast for Thursday, March 23rd, 2023
Windows Snipping Tool Privacy Bug: Inspecting PNG Files
https://isc.sans.edu/diary/Windows%2011%20Snipping%20Tool%20Privacy%20Bug%3A%20Inspecting%20PNG%20Files/29660
Acropalypse Detection and Sanitization Tools
https://github.com/infobyte/CVE-2023-21036
WooCommerce Skimmer Reveals Tampered Gateway Plugin
https://blog.sucuri.net/2023/03/woocommerce-skimmer-reveals-tampered-gateway-plugin.html
Netgear Orbi Router Vulnerable
https://blog.talosintelligence.com/vulnerability-spotlight-netgear-orbi-router-vulnerable-to-arbitrary-command-execution/

Mar 22, 2023 • 6min
ISC StormCast for Wednesday, March 22nd, 2023
String Obfuscation: Character Pair Reversal
https://isc.sans.edu/diary/String%20Obfuscation%3A%20Character%20Pair%20Reversal/29654
Windows 11 Snipping Tool Privacy Bug
https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/
Malicious .Net Packages
https://jfrog.com/blog/attackers-are-starting-to-target-net-developers-with-malicious-code-nuget-packages/
Spring Framework Vulnerability
https://spring.io/blog/2023/03/20/spring-framework-6-0-7-and-5-3-26-fix-cve-2023-20860-and-cve-2023-20861
Snappy Vulnerability
https://github.com/KnpLabs/snappy/security/advisories/GHSA-gq6w-q6wh-jggc

Mar 21, 2023 • 5min
ISC StormCast for Tuesday, March 21st, 2023
From Phishing Kit to Telegram ... or Not
https://isc.sans.edu/diary/From%20Phishing%20Kit%20To%20Telegram...%20or%20Not!/29650
Emotet uses OneNote
https://cofense.com/blog/emotet-sending-malicious-emails-after-three-month-hiatus/
WSUS Update
https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/plan/plan-your-wsus-deployment#uup-considerations
DOTRUNPEX .Net Injector
https://research.checkpoint.com/2023/dotrunpex-demystifying-new-virtualized-net-injector-used-in-the-wild/

Mar 20, 2023 • 7min
ISC StormCast for Monday, March 20th, 2023
Old Backdoor, New Obfuscation
https://isc.sans.edu/diary/Old%20Backdoor%2C%20New%20Obfuscation/29646
Samsung Exynos Chip Vulnerability
https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html
Android Image Cropping Problem
https://twitter.com/ItsSimonTime/status/1636857478263750656/photo/1
https://acropalypse.app/
Bitwarden Pins
https://ambiso.github.io/bitwarden-pin/

Mar 17, 2023 • 7min
ISC StormCast for Friday, March 17th, 2023
Simple Shellcode Dissection
https://isc.sans.edu/diary/Simple%20Shellcode%20Dissection/29642
Threat Actors Exploit Progress Telerik Vulnerablity
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-074a
Abusing Adobe Acrobat Sign to Distribute Malware
https://blog.avast.com/adobe-acrobat-sign-malware
Zoom Patches
https://explore.zoom.us/en/trust/security/security-bulletin/
Array Networks Advisory
https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf
Aruba Patches
https://www.arubanetworks.com/support-services/security-bulletins/

Mar 16, 2023 • 7min
ISC StormCast for Thursday, March 16th, 2023
IPFS Phishing and the need for correctly set HTTP security headers
https://isc.sans.edu/diary/IPFS%20phishing%20and%20the%20need%20for%20correctly%20set%20HTTP%20security%20headers/29638
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/
CVE-2023-23415 ICMP RCE
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23415
Chromium Certificate Proposals
https://www.chromium.org/Home/chromium-security/root-ca-policy/moving-forward-together/


