

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Oct 25, 2021 • 6min
ISC StormCast for Monday, October 25th, 2021
Malware Quiz
https://isc.sans.edu/forums/diary/October+2021+Contest+Forensic+Challenge/27960/ Odd Zip Files https://isc.sans.edu/forums/diary/Phishing+ZIP+With+Malformed+Filename/27966/ Decrypting Cobalt Strike Configurations Using Known Secret Keys https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/ Tracking BLE Fingerprints https://cseweb.ucsd.edu/~nibhaska/papers/sp22_paper.pdf GPS Software Bug https://us-cert.cisa.gov/ncas/current-activity/2021/10/21/gps-daemon-gpsd-rollover-bug https://isc.sans.edu/forums/diary/Keeping+Track+of+Time+Network+Time+Protocol+and+a+GPSD+Bug/27886/

Oct 22, 2021 • 6min
ISC StormCast for Friday, October 22nd, 2021
Stolen Images Evidence Campaign Pushes Sliver Based Malware
https://isc.sans.edu/forums/diary/Stolen+Images+Evidence+campaign+pushes+Sliverbased+malware/27954/
FiveSys Rootkit Signed By Microsoft
https://www.bitdefender.com/files/News/CaseStudies/study/405/Bitdefender-DT-Whitepaper-Fivesys-creat5699-en-EN.pdf
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2021.html
WinRAR Vulnerability
https://swarm.ptsecurity.com/winrars-vulnerable-trialware-when-free-software-isnt-free/
Crypto Mining npm Libraries
https://blog.sonatype.com/newly-found-npm-malware-mines-cryptocurrency-on-windows-linux-macos-devices

Oct 21, 2021 • 6min
ISC StormCast for Thursday, October 21st, 2021
Thanks to Covid 19: New Types of Documents are Lost in the Wild
https://isc.sans.edu/forums/diary/Thanks+to+COVID19+New+Types+of+Documents+are+Lost+in+The+Wild/27952/
Google Chrome 95 Released
https://chromestatus.com/roadmap
Squirrel VM Bug
https://thehackernews.com/2021/10/squirrel-engine-bug-could-let-attackers.html
BlackByte Decryptor Released
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/blackbyte-ransomware-pt-1-in-depth-analysis/
https://github.com/SpiderLabs/BlackByteDecryptor

Oct 20, 2021 • 5min
ISC StormCast for Wednesday, October 20th, 2021
Can You Make the Great Chinese Firewall Work For You
https://isc.sans.edu/forums/diary/Can+you+make+the+Great+Chinese+Firewall+work+for+you/27948/
Fake Government Assistance Websites
https://www.ic3.gov/Media/Y2021/PSA211015
TA505 Coming Back
https://www.proofpoint.com/us/blog/threat-insight/whatta-ta-ta505-ramps-activity-delivers-new-flawedgrace-variant
BlackMatter Ransomware
https://us-cert.cisa.gov/ncas/alerts/aa21-291a

Oct 19, 2021 • 5min
ISC StormCast for Tuesday, October 19th, 2021
Malcious PowerShell Script Using Client Certificate Authentication
https://isc.sans.edu/forums/diary/Malicious+PowerShell+Using+Client+Certificate+Authentication/27944/
PowerShell Updates
https://github.com/PowerShell/Announcements/issues/27
Juniper JunOS Patches
https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES
TianFu Cup
https://tianfucup.com/en/#canjia

Oct 18, 2021 • 6min
ISC StormCast for Monday, October 18th, 2021
Active Scanning for Apache Vulnerabilities CVE-2021-41773 and 42013
https://isc.sans.edu/forums/diary/Apache+is+Actively+Scan+for+CVE202141773+CVE202142013/27940/
Warranty Repairs and Non Removable Storage Risks
https://isc.sans.edu/forums/diary/Warranty+Repairs+and+NonRemovable+Storage+Risks/27938/
Crypto Wallet Compromised on OpenSea NFT Marketplace
https://blog.checkpoint.com/2021/10/13/check-point-software-prevents-theft-of-crypto-wallets-on-opensea-the-worlds-largest-nft-marketplace/
$5.2 Billion worth of Bitcoin Transactions Linked to Ransomware
https://www.fincen.gov/sites/default/files/shared/Financial%20Trend%20Analysis_Ransomeware%20508%20FINAL.pdf

Oct 15, 2021 • 7min
ISC StormCast for Friday, October 15th, 2021
Port Forwarding with Windows for the Win
https://isc.sans.edu/forums/diary/PortForwarding+with+Windows+for+the+Win/27934/
Please Fix Your E-Mail Brute Forcing Tool
https://isc.sans.edu/forums/diary/Please+fix+your+EMail+Brute+forcing+tool/27930/
Ad Blocker Injects Ads
https://www.imperva.com/blog/the-ad-blocker-that-injects-ads/
Romance Scams Go After Crypto Currency
https://nakedsecurity.sophos.com/2021/10/13/romance-scams-with-a-cryptocurrency-twist-new-research-from-sophoslabs/
Sysmon For Linux
https://github.com/Sysinternals/SysmonForLinux
Foxit Updates
https://www.foxit.com/support/security-bulletins.html
VMWare Updates
https://www.vmware.com/security/advisories/VMSA-2021-0023.html

Oct 13, 2021 • 6min
ISC StormCast for Wednesday, October 13th, 2021
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+October+2021+Patch+Tuesday/27928/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
PyPi Remove mitmproxy2 Module
https://twitter.com/maximilianhils/status/1447525552370458625
https://web.archive.org/web/20211012105244/https://gist.github.com/mhils/7ff29d50b25a1c99e06834cf95684333

Oct 12, 2021 • 5min
ISC StormCast for Tuesday, October 12th, 2021
Non HTTP Requests Hitting Web Server
https://isc.sans.edu/forums/diary/Things+that+go+Bump+in+the+Night+Non+HTTP+Requests+Hitting+Web+Servers/27924/
Apple Updates iOS/iPadOS to 15.0.2
https://saaramar.github.io/IOMFB_integer_overflow_poc/
https://support.apple.com/en-us/HT212846
Weak SSH Keys Used with GitKraken
https://github.blog/2021-10-11-github-security-update-revoking-weakly-generated-ssh-keys/
Let's Encrypt Outage
https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/6164b5af714e1f053880ba0c

Oct 11, 2021 • 5min
ISC StormCast for Monday, October 11th, 2021
Scanning for Previous Oracle WebLogic Vulnerabilities
https://isc.sans.edu/forums/diary/Scanning+for+Previous+Oracle+WebLogic+Vulnerabilities/27918/
Sorting Things Out - Sorting Data by IP Address
https://isc.sans.edu/forums/diary/Sorting+Things+Out+Sorting+Data+by+IP+Address/27916/
https://gitlab.com/slackermedia/bashcrawl
Telegram Does Not Remove Auto-Deleted Messages from Cache
https://habr.com/en/post/580582/
Microsoft To Disable Excel 4.0 Macros By Default
https://twitter.com/GelosSnake/status/1446192775087722497
https://m365admin.handsontek.net/macro-settings-update-to-disable-excel-4-0-macros-by-default/


