

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jan 25, 2022 • 6min
ISC StormCast for Tuesday, January 25th, 2022
Moonbound UEFI Malware
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
Exploit of Sonicwall CVE-2021-20038
https://twitter.com/buffaloverflow/status/1485671824725786633
Dell EMC AppSync Vulnerability
https://www.dell.com/support/kbdoc/de-de/000195377/dsa-2022-003-dell-emc-appsync-security-update-for-multiple-vulnerabilities
Twitter API Keys Leaked in GitHub
https://incognitatech.medium.com/using-twitter-to-notify-careless-developers-the-unorthodox-way-d71478ad367a

Jan 24, 2022 • 6min
ISC StormCast for Monday, January 24th, 2022
Obscure Wininet.dll Feature
https://isc.sans.edu/forums/diary/Obscure+Wininetdll+Feature/28262/
Mixed VBA and Excel 4 Macro in Targeted Excel Sheet
https://isc.sans.edu/forums/diary/Mixed+VBA+Excel4+Macro+In+a+Targeted+Excel+Sheet/28264/
https://techcommunity.microsoft.com/t5/excel-blog/excel-4-0-xlm-macros-now-restricted-by-default-for-customer/ba-p/3057905
F5 January 2022 Patches
https://support.f5.com/csp/article/K40084114
McAfee Privilege Escalation
https://kc.mcafee.com/corporate/index?page=content&id=SB10378

Jan 21, 2022 • 6min
ISC StormCast for Friday, January 21st, 2022
RedLine Stealer Delivered Through FTP
https://isc.sans.edu/forums/diary/RedLine+Stealer+Delivered+Through+FTP/28258/
Google Camera Alters QR Codes
https://www.heise.de/hintergrund/Googles-Kamera-verfaelscht-Links-in-QR-Codes-6332669.html
https://www.androidpolice.com/google-camera-randomly-changes-some-qr-code-urls-on-android-12/
Linux Kernel Privilege Escalation / Container Escape
https://seclists.org/oss-sec/2022/q1/54
https://access.redhat.com/security/cve/cve-2022-0185
Crypto.com 2FA Bypass
https://threatpost.com/2fa-bypassed-crypto-com-heist/177846/
Windows Policies to Avoid
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/why-you-shouldn-t-set-these-25-windows-policies/ba-p/3066178

Jan 20, 2022 • 6min
ISC StormCast for Thursday, January 20th, 2022
0.0.0.0 in Emotet Spambot Traffic
https://isc.sans.edu/forums/diary/0000+in+Emotet+Spambot+Traffic/28254/
Linux Patch to Make 0.0.0.0/8 Routable
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=96125bf9985a
WebKit Patch for Cross Origin Database Name Leak
https://trac.webkit.org/changeset/288078/webkit
ACER Care Center Privilege Escalation
https://aptw.tf/2022/01/20/acer-care-center-privesc.html
Imporper Input Validation Vulnerability in Serv-U
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247

Jan 19, 2022 • 6min
ISC StormCast for Wednesday, January 19th, 2022
Phishing E-Mail With an Advertisement
https://isc.sans.edu/forums/diary/Phishing+email+withan+advertisement/28250/
Virustotal Credential
https://www.safebreach.com/blog/2022/the-perfect-cyber-crime/
Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpujan2022.html
Box MFA Bypass
https://www.varonis.com/blog/box-mfa-bypass-sms

Jan 18, 2022 • 5min
ISC StormCast for Tuesday, January 18th, 2022
Log4Shell Attacks Getting Smarter
https://isc.sans.edu/forums/diary/Log4Shell+Attacks+Getting+Smarter/28246/
Microsoft Releases Special Update to Deal with January Update Fail
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-oob-updates-for-january-windows-update-issues/
Cisco Unified Contact Center Management Portal and Unifed Contact Center Domain Manager Privilege Escalation Vulnerablity
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ccmp-priv-esc-JzhTFLm4
Zoho Critical Security Patch Released in Desktop Central and Desktop Central MSP
https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022
Google Chrome Restricting Private Network Access
https://developer.chrome.com/blog/private-network-access-preflight/

Jan 17, 2022 • 5min
ISC StormCast for Monday, January 17th, 2022
Use of Alternate Data Streams in Research Scans
https://isc.sans.edu/forums/diary/Use+of+Alternate+Data+Streams+in+Research+Scans+for+indexjsp/28240/
Microsoft Resumes Windows Server 2019 Cumulative Updates
https://www.bleepingcomputer.com/news/microsoft/microsoft-resumes-rollout-of-january-windows-server-updates/
Safari Index DB Leak
https://fingerprintjs.com/blog/indexeddb-api-browser-vulnerability-safari-15/

Jan 14, 2022 • 6min
ISC StormCast for Friday, January 14th, 2022
MSFT Patch Issues
https://borncity.com/win/2022/01/12/patchday-windows-8-1-server-2012-r2-updates-11-januar-2022-mgliche-boot-probleme/
https://support.microsoft.com/en-us/topic/january-11-2022-kb5009624-monthly-rollup-23f4910b-6bdd-475c-bb4d-c0e961aff0bc
https://support.microsoft.com/en-us/topic/january-11-2022-kb5009595-security-only-update-060870c2-ad08-40e5-b000-a9f6d40c0831
Jenkins Security Advisory 2022-01-1
https://www.jenkins.io/security/advisory/2022-01-12/
Qakbot Configuration Decryptor
https://github.com/drole/qakbot-registry-decrypt
Android allows Disabling 2G
https://www.bleepingcomputer.com/news/security/android-users-can-now-disable-2g-to-block-stingray-attacks/
Weakness in Microsoft Defender
https://twitter.com/splinter_code/status/1481073265380581381

Jan 13, 2022 • 6min
ISC StormCast for Thursday, January 13th, 2022
A Quick CVE-2022-21907 FAQ
https://isc.sans.edu/forums/diary/A+Quick+CVE202221907+FAQ+work+in+progress/28234/
Details Released Regarding Patched Sonicwall Vulnerabilities
https://www.rapid7.com/blog/post/2022/01/11/cve-2021-20038-42-sonicwall-sma-100-multiple-vulnerabilities-fixed-2/
iOS/iPad OS Fixing HomeKit Vulnerability / Private Relay issues
https://support.apple.com/en-us/HT201222
https://www.macrumors.com/2022/01/12/apple-icloud-private-relay-ios-15-2/
Atticking RDP From Inside
https://www.cyberark.com/resources/threat-research-blog/attacking-rdp-from-inside
Nanocore, Netwire and AsyncRAT Spreading Campaign Uses Public Cloud Infrastructre
https://blog.talosintelligence.com/2022/01/nanocore-netwire-and-asyncrat-spreading.html

Jan 12, 2022 • 7min
ISC StormCast for Wednesday, January 12th, 2022
Microsoft Patch Tuesday - January 2022
https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+January+2022/28230/
Adobe Updates
https://helpx.adobe.com/security.html


