

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jan 4, 2023 • 7min
ISC StormCast for Wednesday, January 4th, 2023
NTP Fingerprinting
https://isc.sans.edu/diary/Its%20about%20time%3A%20OS%20Fingerprinting%20using%20NTP/29394
Misc Car Vulnerabilities
https://samcurry.net/web-hackers-vs-the-auto-industry/
Flipper Zero Phishing
https://twitter.com/AlvieriD/status/1609945425871609858
Trend Micro Patch
https://helpcenter.trendmicro.com/en-us/article/TMKA-11252
Packet Tuesday: IP Options
https://www.youtube.com/watch?v=HldNL3SLLwM

Jan 3, 2023 • 6min
ISC StormCast for Tuesday, January 3rd, 2023
Kyverno's container image signature verification bypass
https://www.armosec.io/blog/cve-2022-47633-kyvernos-container-image-signature-verification/
Google Smart Spaeker Vulnerability
https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html
Verizon Decomissions 3G CDMA Network
https://www.fiercewireless.com/wireless/verizon-tells-3g-customers-upgrade-they-lose-service
EarSpy: Spying Caller Speech and Identity Through Speaker Vibrations
https://arxiv.org/pdf/2212.12151.pdf

Jan 2, 2023 • 6min
ISC StormCast for Monday, January 2nd, 2023
SPF and DMARC use on GOV domains in different ccTLDs
https://isc.sans.edu/forums/diary/SPF+and+DMARC+use+on+GOV+domains+in+different+ccTLDs/29384/
CVE-2022-47939 ksmbd Vulnerability
https://ubuntu.com/security/CVE-2022-47939
Netgear Vulnerabilities
https://kb.netgear.com/000065495/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2019-0208
PyTorch Malicious Dependency
https://pytorch.org/blog/compromised-nightly-dependency/

Dec 23, 2022 • 7min
ISC StormCast for Friday, December 23rd, 2022
Exchange OWASSRF Exploited for Remote Code Execution
https://isc.sans.edu/forums/diary/Exchange%20OWASSRF%20Exploited%20for%20Remote%20Code%20Execution/29374/
ksmbd Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-22-1690/
LastPass Incident Update
https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/

Dec 22, 2022 • 6min
ISC StormCast for Thursday, December 22nd, 2022
Quick NTP Measurement
https://isc.sans.edu/diary/Can%20you%20please%20tell%20me%20what%20time%20it%20is%3F%20Adventures%20with%20public%20NTP%20servers./29368
FBI Favors Ad Blockers
https://www.ic3.gov/Media/Y2022/PSA221221
Hidden Costs of Parental Control Apps
https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/
ProxyNotShell Mitigtation Bypass
https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/

Dec 21, 2022 • 7min
ISC StormCast for Wednesday, December 21st, 2022
Linux File System Monitoring and Actions
https://isc.sans.edu/diary/Linux%20File%20System%20Monitoring%20%26%20Actions/29362
Feed of NTP Server IP Addresses
https://isc.sans.edu/api/threatlist/ntpservers?json
Feed of Mastodon Server IP Addresses
https://isc.sans.edu/api/threatlist/mastodon?json
Packet Tuesday TLS Server Hello
https://www.youtube.com/watch?v=2HymU4dxWEQ
Android Preparing Support for Updatable Root Certificates
https://blog.esper.io/android-14-updatable-certificates/
Elastic IP Hijacking
https://www.mitiga.io/blog/elastic-ip-hijacking-a-new-attack-vector-in-aws
Microsoft Fixes HyperV issues With Latest Patch
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#2988

Dec 20, 2022 • 6min
ISC StormCast for Tuesday, December 20th, 2022
Hunting for Mastodon Servers
https://isc.sans.edu/diary/Hunting%20for%20Mastodon%20Servers/29358
KB5021233 Blue Screen
https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22H2#2986msgdesc
Edge Update will disable Internet Explorer in February
https://learn.microsoft.com/en-us/deployedge/edge-learnmore-neededge
Gatekeeper's Achilles heel: Unearthin a macOS vulnerability
https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/
Corsair Bug not causing keystroke logging
https://arstechnica.com/gadgets/2022/12/corsair-says-bug-not-keylogger-behind-some-k100-keyboards-creepy-behavior/
SentinelSneak: Malicious PyPi module poses as security software development kit

Dec 19, 2022 • 6min
ISC StormCast for Monday, December 19th, 2022
Infostealer Malware with Double Extension
https://isc.sans.edu/diary/Infostealer%20Malware%20with%20Double%20Extension/29354
Client Side Encryption For GMail
https://workspaceupdates.googleblog.com/2022/12/client-side-encryption-for-gmail-beta.html
Google Releases OSV Scanner
https://github.com/google/osv-scanner/releases/tag/v1.0.1
Samba Security Patches
https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html
Zyxel Router Buffer Overflow
https://sec-consult.com/blog/detail/enemy-within-unauthenticated-buffer-overflows-zyxel-routers/

Dec 16, 2022 • 6min
ISC StormCast for Friday, December 16th, 2022
Google ads lead to fake software pages pushing IcedID (Bokbot)
https://isc.sans.edu/diary/Google%20ads%20lead%20to%20fake%20software%20pages%20pushing%20IcedID%20%28Bokbot%29/29344
HTML smugglers turn to SVG images
https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/
GitHub Improvements
https://github.blog/2022-12-14-raising-the-bar-for-software-security-next-steps-for-github-com-2fa/
NIST Retires SHA-1
https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm

Dec 15, 2022 • 6min
ISC StormCast for Thursday, December 15th, 2022
Microsoft Patch Issues:
https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45
https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/so-you-say-your-dc-s-memory-is-getting-all-used-up-after/ba-p/3696318
Critical Remote Code Execution Vulneraiblity in SPNEGO Extended Negotiation Security Mechanism
https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/
VMWare EHCI Controller Vulnerability CVE-2022-31705
https://www.vmware.com/security/advisories/VMSA-2022-0033.html
Veem Vulnerability now Exploited
https://www.veeam.com/kb4288
nuget / npm / pypi used to host phishing pages
https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/


