

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 22, 2022 • 8min
ISC StormCast for Tuesday, March 22nd, 2022
Maldoc Cleaned by Anti-Virus
https://isc.sans.edu/forums/diary/Maldoc+Cleaned+by+AntiVirus/28460/
Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain
https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain
IBM Spectrum Protect Update
https://www.ibm.com/support/pages/node/6564745
Lapsus$ May have Breached Microsoft
https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/
Statement by President Biden on our Nation's Cybersecurity
https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/statement-by-president-biden-on-our-nations-cybersecurity/

Mar 21, 2022 • 6min
ISC StormCast for Monday, March 21st, 2022
Scans for Movable Type Vulnerability (CVE-2021-20837)
https://isc.sans.edu/forums/diary/Scans+for+Movable+Type+Vulnerability+CVE202120837/28454/
SolarWinds Advisory: Unauahtneticated Access in Web Help Desk (12.7.5)
https://isc.sans.edu/forums/diary/SolarWinds+Advisory+Unauthenticated+Access+in+Web+Help+Desk+1275/28456/
MGLNDD_* Scans
https://isc.sans.edu/forums/diary/MGLNDD+Scans/28458/
CAPTCHA Phishing
https://www.avanan.com/blog/using-captcha-forms-to-bypass-filters
Browser in the Browser Templates
https://mrd0x.com/browser-in-the-browser-phishing-attack/

Mar 18, 2022 • 15min
ISC StormCast for Friday, March 18th, 2022
npm Package Sabotaged for Belarus/Russian Users
https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/
President Zelensky Deepfakes
https://twitter.com/ngleicher/status/1504186935291506693
ATM Rootkit
https://www.mandiant.com/resources/unc2891-overview
Scanner for Backdoored Mikrotik Routers
https://github.com/microsoft/routeros-scanner
SANS.edu Student: Ron Grohman; Network Access Control and ICS: A Practical Guide
https://www.sans.edu/cyber-research/network-access-control-and-ics-a-practical-guide/

Mar 17, 2022 • 6min
ISC StormCast for Thursday, March 17th, 2022
Qakbot Infection With Cobalt Strike and VNC Activity
https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448/
Gh0stCringe RAT Being Distributed to Vulnerable Database Servers
https://asec.ahnlab.com/en/32572/
dompdf 0 day
https://positive.security/blog/dompdf-rce
OpenSSL DoS Vulnerability
https://www.openssl.org/news/secadv/20220315.txt

Mar 16, 2022 • 5min
ISC StormCast for Wednesday, March 16th, 2022
Clean Binaries with Suspicious Behaviour
https://isc.sans.edu/forums/diary/Clean+Binaries+with+Suspicious+Behaviour/28444/
Misconfigured Multi-Factor Authentication Abused
https://www.cisa.gov/uscert/ncas/alerts/aa22-074a
German Office of Information Security Warns Kaspersky Users
https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html
Caddy Wiper Targeting Ukraine
https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/
Fake Antivirus Targeting Ukraine
https://twitter.com/malwrhunterteam/status/1502302718140035080
B1txor20 DNS Tunnel Backdoor
https://blog.netlab.360.com/b1txor20-use-of-dns-tunneling_en/

Mar 15, 2022 • 6min
ISC StormCast for Tuesday, March 15th, 2022
Apple Updates Everything
https://isc.sans.edu/forums/diary/Apple+Updates+Everything+MacOS+123+XCode+133+tvOS+154+watchOS+85+iPadOS+154+and+more/28438/
Look Alike Accounts Used in Ukraine Dontation Scam Impersonating Olena Zelenska
https://isc.sans.edu/forums/diary/Look+Alike+Accounts+Used+in+Ukraine+Donation+Scam+impersonating+Olena+Zelenska/28440/
Curl on Windows
https://isc.sans.edu/forums/diary/Curl+on+Windows/28436/
Veeam Vulnerabilities
https://www.veeam.com/kb4288
Linux Netfilter Privilege Escalation
https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/

Mar 14, 2022 • 5min
ISC StormCast for Monday, March 14th, 2022
Malware Using WebSockets For C&C
https://isc.sans.edu/forums/diary/Keep+an+Eye+on+WebSockets/28430/
Racoon Stealer leverages Telegram
https://decoded.avast.io/vladimirmartyanov/raccoon-stealer-trash-panda-abuses-telegram/
USAHERDS Hack
https://www.wired.com/story/china-apt41-hacking-usaherds-log4j/
YARA 4.2.0 Released
https://isc.sans.edu/forums/diary/YARA+420+Released/28432/

Mar 11, 2022 • 6min
ISC StormCast for Friday, March 11th, 2022
Credential Leaks on Virustotal
https://isc.sans.edu/forums/diary/Credentials+Leaks+on+VirusTotal/28426/
GPS Issues Around Finish Rusian Border
https://www.straitstimes.com/world/europe/finland-detects-gps-disturbance-near-russias-kaliningrad
Russia Considering Internal Certificate Authority
https://www.gosuslugi.ru/tls
https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/
New Spectre Variant
https://www.vusec.net/projects/bhi-spectre-bhb/
Package Manager Vulnerabilities (yarn, pip, composer...)
https://blog.sonarsource.com/securing-developer-tools-package-managers

Mar 10, 2022 • 6min
ISC StormCast for Thursday, March 10th, 2022
Infostealer in a Batch File
https://isc.sans.edu/forums/diary/Infostealer+in+a+Batch+File/28422/
TP240PhoneHome reflection/amplification DDoS Attack Vector
https://blog.cloudflare.com/cve-2022-26143/
Malware Disguises as Pro Ukrainian Cybertools
https://blog.talosintelligence.com/2022/03/threat-advisory-cybercriminals.html#more
Russian Government Sites Hacked in Supply Chain Attack
https://www.bleepingcomputer.com/news/security/russian-government-sites-hacked-in-supply-chain-attack/
Third Party Vulnerabilities in RUGGEDCOM ROS
https://cert-portal.siemens.com/productcert/pdf/ssa-256353.pdf
Adobe Bulletins
https://helpx.adobe.com/security/security-bulletin.html

Mar 9, 2022 • 6min
ISC StormCast for Wednesday, March 9th, 2022
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+March+2022+Patch+Tuesday/28418/
Critical APC UPS Vulnerability
https://www.armis.com/research/tlstorm/
Vulnerabilities in Firmware Affecting HP Devices
https://www.binarly.io/news/BinarlyDiscovers16NewHighImpactVulnerabilitiesinFirmwareAffectingHPEnterpriseDevices/index.html


