

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Nov 8, 2021 • 5min
ISC StormCast for Monday, November 8th, 2021
Decyprting Cobalt Strike Traffic With Keys Extracted From Process Memory
https://isc.sans.edu/forums/diary/Decrypting+Cobalt+Strike+Traffic+With+Keys+Extracted+From+Process+Memory/28006/
XMount for Disk Images
https://isc.sans.edu/forums/diary/Xmount+for+Disk+Images/28002/
More Proactive SIMs
https://medium.com/telecom-expert/more-proactive-sims-f8da2ef8b189
Thunderbird Update
https://www.mozilla.org/en-US/security/advisories/mfsa2021-50/

Nov 5, 2021 • 7min
ISC StormCast for Friday, November 5th, 2021
October 2021 Forensic Contest Answers and Analysis
https://isc.sans.edu/forums/diary/October+2021+Forensic+Contest+Answers+and+Analysis/27998/
CVE-2021-43267: Remote Linux Kernel Heap Overflow in TIPC Module
https://www.sentinelone.com/labs/tipc-remote-linux-kernel-heap-overflow-allows-arbitrary-code-execution/
Cisco Patches
https://tools.cisco.com/security/center/publicationListing.x
The Security Risk of Lacking Compiler Protection in WebAssembly
https://arxiv.org/abs/2111.01421

Nov 4, 2021 • 5min
ISC StormCast for Thursday, November 4th, 2021
Gitlab CVE-2021-22205 Exploited (and often not patched)
https://www.rapid7.com/blog/post/2021/11/01/gitlab-unauthenticated-remote-code-execution-cve-2021-22205-exploited-in-the-wild/
New Proxy Shell Exploits Seen Against Exchange
https://blog.talosintelligence.com/2021/11/babuk-exploits-exchange.html
Blackmatter Shutting Down Again
https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-moves-victims-to-lockbit-after-shutdown/
Android 0-Day Patched
https://source.android.com/security/bulletin/2021-11-01

Nov 3, 2021 • 6min
ISC StormCast for Wednesday, November 3rd, 2021
Revisiting BrakTooth: Two Months Later
https://isc.sans.edu/forums/diary/Revisiting+BrakTooth+Two+Months+Later/27992/
Escalating XSS to Sainthood with Nagios
https://blog.grimm-co.com/2021/11/escalating-xss-to-sainthood-with-nagios.html
Pentaho Business Analytics Vulnerablity
https://hawsec.com/publications/pentaho/HVPENT210401-Pentaho-BA-Security-Assessment-Report-v1_1.pdf

Nov 2, 2021 • 7min
ISC StormCast for Tuesday, November 2nd, 2021
Trojan Source: Invisible Vulnerabilities
https://www.trojansource.codes/trojan-source.pdf
Detecting HTTP Header Smuggling Vulnerabilities
https://www.darkreading.com/application-security/free-tool-scans-web-servers-for-vulnerability-to-http-header-smuggling-attacks
Kaspersky Lost Amazon Simple Email Service Token
https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021_phishing

Nov 1, 2021 • 5min
ISC StormCast for Monday, November 1st, 2021
Remote Desktop Protocol RDP Discovery
https://isc.sans.edu/forums/diary/Remote+Desktop+Protocol+RDP+Discovery/27984/
Sysmon Update
https://isc.sans.edu/forums/diary/Sysinternals+Autoruns+and+Sysmon+updates/27986/
Google Chrome Updates
https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html
AbstractEmu Malware Roots Android
https://blog.lookout.com/lookout-discovers-global-rooting-malware-campaign
Microsoft Defender For Endpoint Web Content Filtering
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/web-content-filtering-now-generally-available-on-windows/ba-p/2893357

Oct 29, 2021 • 6min
ISC StormCast for Friday, October 29th, 2021
Critical Hikvision Patch
https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html
https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/
Shrootless Vulnerability in MacOS
https://www.microsoft.com/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/
More Malicious NPM Libraries
https://www.theregister.com/2021/10/27/npm_roblox_ransomware/

Oct 28, 2021 • 5min
ISC StormCast for Thursday, October 28th, 2021
Outlook Web Access Phishing
https://isc.sans.edu/forums/diary/Hunting+for+Phishing+Sites+Masquerading+as+Outlook+Web+Access/27974/
Apple Security Updates Details Available
https://support.apple.com/en-us/HT201222
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
PinkBot Botnet Uses DoH
https://blog.netlab.360.com/pinkbot/
Jira Insight Patch
https://confluence.atlassian.com/adminjiraserver/jira-service-management-security-advisory-2021-10-20-1085186548.html

Oct 27, 2021 • 6min
ISC StormCast for Wednesday, October 27th, 2021
Apple Updates Everything (but no details yet)
https://support.apple.com/en-sa/HT201222
Craigslist E-Mail Hijack
https://www.inky.com/blog/urgency-mail-relay-serve-phishers-well-on-craigslist
UltimaSMS Android Malware
https://blog.avast.com/premium-sms-scam-apps-on-play-store-avast
Firefox Proxy Malware
https://blog.mozilla.org/security/2021/10/25/securing-the-proxy-api-for-firefox-add-ons/

Oct 26, 2021 • 5min
ISC StormCast for Tuesday, October 26th, 2021
Decrypting Cobalt Strike Traffic
https://isc.sans.edu/forums/diary/Decrypting+Cobalt+Strike+Traffic+With+a+Leaked+Private+Key/27968/
Critical Discourse Vulnerability
https://us-cert.cisa.gov/ncas/current-activity/2021/10/24/critical-rce-vulnerability-discourse
Discourse Discussion Platform RCE
https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq
https://0day.click/recipe/discourse-sns-rce/
ua-parser-js malware
https://github.com/advisories/GHSA-pjwm-rvh2-c87w
Vulnerable Billing Software BillQuick Web Used to Deploy Ransomware
https://www.huntress.com/blog/threat-advisory-hackers-are-exploiting-a-vulnerability-in-popular-billing-software-to-deploy-ransomware


