

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 7, 2022 • 6min
ISC StormCast for Tuesday, March 8th, 2022
Ukraine Scam Followup
https://isc.sans.edu/forums/diary/No+Bitcoin+No+Problem+Follow+Up+to+Last+Weeks+Donation+Scam/28412/
Dirty Pipe Linux Vulnerability
https://dirtypipe.cm4all.com
Mozilla Firefox and Thunderbird Vulnerability
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/
Azure AutoWarp
https://orca.security/resources/blog/autowarp-microsoft-azure-automation-service-vulnerability/
Terramaster TOS Vulnerability
https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/
https://forum.terra-master.com/en/viewtopic.php?f=28&t=3030

Mar 7, 2022 • 7min
ISC StormCast for Monday, March 7th, 2022
Ukraine Dontation Scam
https://isc.sans.edu/forums/diary/Scam+EMail+Impersonating+Red+Cross/28404/
Cogent Disconnects Russia
https://www.washingtonpost.com/technology/2022/03/04/russia-ukraine-internet-cogent-cutoff/
Russia DDoS Lists
https://safe-surf.ru/upload/ALRT/proxies.txt
https://safe-surf.ru/upload/ALRT/referer_http_header.txt
NVidia Stolen Certificates
https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/
https://twitter.com/cyb3rops/status/1499514240008437762
GitLab Vulnerabilities
https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/#unauthenticated-user-enumeration-on-graphql-api
Cisco Patches
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk

Mar 4, 2022 • 7min
ISC StormCast for Friday, March 4th, 2022
Attackers Search For Exosed "LuCI" Folders
https://isc.sans.edu/diary/28400
Alexa Versus Alexa
https://arxiv.org/abs/2202.08619
Bypassing Google Cloud Armor
https://kloudle.com/blog/piercing-the-cloud-armor-the-8kb-bypass-in-google-cloud-platform-waf
Ukraine Updates
https://www.golem.de/news/ausfall-angriff-auf-ka-sat-satellit-ueber-gatewaystation-in-ukraine-2203-163614.html
https://www.crowdstrike.com/blog/how-to-decrypt-the-partyticket-ransomware-targeting-ukraine/
https://www.bleepingcomputer.com/news/security/ukraine-says-local-govt-sites-hacked-to-push-fake-capitulation-news/

Mar 3, 2022 • 5min
ISC StormCast for Thursday, March 3rd, 2022
The More Often Something is Repeated, the More True it Becomes
https://isc.sans.edu/forums/diary/The+More+Often+Something+is+Repeated+the+More+True+It+Becomes+Dealing+with+Social+Media/28396/
Fortinet Bug
https://www.fortiguard.com/psirt/FG-IR-21-028
IBM Updates
https://www.ibm.com/blogs/psirt/
Google Updates
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html
Conti Ransomware Leak
https://threatpost.com/conti-ransomware-decryptor-trickbot-source-code-leaked/178727/
Middle Box DDoS Attacks
https://www.akamai.com/blog/security/tcp-middlebox-reflection

Mar 2, 2022 • 6min
ISC StormCast for Wednesday, March 2nd, 2022
Geoblocking when you can't Geoblock
https://isc.sans.edu/forums/diary/Geoblocking+when+you+cant+Geoblock/28392/
IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine
https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/
Memory Corruption Vulnerabilities in PJSIP
https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/
Octa Patch for Advanced Server Access Client
https://trust.okta.com/security-advisories/okta-advanced-server-access-client-cve-2022-24295
ViaSat Outage
https://www.reuters.com/business/aerospace-defense/satellite-firm-viasat-probes-suspected-cyberattack-ukraine-elsewhere-2022-02-28/

Mar 1, 2022 • 7min
ISC StormCast for Tuesday, March 1st, 2022
PHP Patches Code Injection Flaw
https://nvd.nist.gov/vuln/detail/CVE-2021-21708
https://bugs.php.net/bug.php?id=81708
Mozilla VPN Local Privilege Escalation
https://www.mozilla.org/en-US/security/advisories/mfsa2022-08/
Google Captcha Breaking
https://east-ee.com/2022/02/28/1367/
Samsung Encryption Vulnerability
https://eprint.iacr.org/2022/208.pdf
tshark Multiple IPs
https://isc.sans.edu/forums/diary/TShark+Multiple+IP+Addresses/28386/

Feb 28, 2022 • 6min
ISC StormCast for Monday, February 28th, 2022
Ukraine Update
https://www.bleepingcomputer.com/news/security/ransomware-gangs-hackers-pick-sides-over-russia-invading-ukraine/
https://ddosecrets.com/wiki/Tetraedr
https://twitter.com/YourAnonOne/status/1496965766435926039
https://www.wired.com/story/ukraine-it-army-russia-war-cyberattacks-ddos/
Odd Windows Behaviour with Fixed Addresses
https://isc.sans.edu/forums/diary/Windows+Fixed+IPv4+Addresses+and+APIPA/28380/
Using Snort IDS Rules in NetWitness Packet Decoder
https://isc.sans.edu/forums/diary/Using+Snort+IDS+Rules+with+NetWitness+PacketDecoder/28382/
NVidia Breach
https://www.bloomberg.com/news/articles/2022-02-25/nvidia-is-investigating-cyber-attack-but-business-uninterrupted
Windows 11 Reset Not Removing All Data
https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#2783msgdesc

Feb 25, 2022 • 7min
ISC StormCast for Friday, February 25th, 2022
Ukraine Update: Webcast
https://www.sans.org/webcasts/russian-cyber-attack-escalation-in-ukraine/
Other Ukraine Related Stories
https://isc.sans.edu/forums/diary/Ukraine+Russia+Situation+From+a+Domain+Names+Perspective/28376/
https://detection.watchguard.com
Zabbix Vulnerablity Exploited
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
https://support.zabbix.com/browse/ZBX-20350
Asustore Victim of Deadbolt Ransomware
https://forum.asustor.com/viewtopic.php?f=45&t=12630
Firepower Rule Update Failure After March 5th 2022
https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html?emailclick=CNSemail
Social Media Takeover Malware Distrubeted Via Microsoft App Store
https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/

Feb 24, 2022 • 7min
ISC StormCast for Thursday, February 24th, 2022
New Sandworm Malware Cyclops Blink Replaces VPNFilter
https://www.ncsc.gov.uk/news/joint-advisory-shows-new-sandworm-malware-cyclops-blink-replaces-vpnfilter
Wiper Malware Seen Deployed Against Targets in the Ukraine
https://twitter.com/juanandres_gs/status/1496581710368358400
https://twitter.com/ESETresearch/status/1496581903205511181
The Rise and Fall of log4shell
https://isc.sans.edu/forums/diary/The+Rise+and+Fall+of+log4shell/28372/
pfsense authenticated RCE
https://www.shielder.it/advisories/pfsense-remote-command-execution/
BVP47 Backdoor
https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf

Feb 23, 2022 • 7min
ISC StormCast for Wednesday, February 23rd, 2022
A Good Old Equation Editor Vulnerablity Deliverying Malware
https://www.welivesecurity.com/2022/02/22/teenage-cybercrime-stop-kids-wrong-path/
Horde Webmail 5.2.22 - Account Takeover via Email
https://blog.sonarsource.com/horde-webmail-account-takeover-via-email
NoVNC Phishing
https://mrd0x.com/bypass-2fa-using-novnc/


