

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Oct 8, 2021 • 6min
ISC StormCast for Friday, October 8th, 2021
Who is Hunting For Your IPTV Set-Top Box?
https://isc.sans.edu/forums/diary/Who+Is+Hunting+For+Your+IPTV+SetTop+Box/27912/
Another Update For Apache
https://httpd.apache.org
Font on Lake Rootkit
https://www.welivesecurity.com/2021/10/07/fontonlake-previously-unknown-malware-family-targeting-linux/
osquery 5 with macOS Endpoint Security
https://www.trailofbits.com/post/announcing-osquery-5-now-with-endpointsecurity-on-macos

Oct 7, 2021 • 5min
ISC StormCast for Thursday, October 7th, 2021
Apache 2.4.49 Directory Traversal Vulnerability
https://isc.sans.edu/forums/diary/Apache+2449+Directory+Traversal+Vulnerability+CVE202141773/27908/
Python Ransomware Targeting ESXi Server
https://www.sophos.com/en-us/press-office/press-releases/2021/10/sophos-researchers-uncover-new-python-ransomware-targeting-an-esxi-server-and-virtual-machines.aspx
AT&T SIM Forensics
https://medium.com/telecom-expert/what-is-at-t-doing-at-1111340002-c418876c212c
Google Making Additional 2FA Push
https://blog.google/technology/safety-security/making-sign-safer-and-more-convenient/

Oct 6, 2021 • 6min
ISC StormCast for Wednesday, October 6th, 2021
Looking Glass Sites
https://isc.sans.edu/forums/diary/Looking+Glasses+Debugging+Network+Connectivity+Issues/27904/
Facebook Postmortem
https://engineering.fb.com/2021/10/05/networking-traffic/outage-details/
Apache 2.4.49 Directory Traversal Vulnerability
https://blog.sonatype.com/apache-servers-actively-exploited-in-wild-importance-of-prompt-patching
Windows 11 Released
https://www.microsoft.com/security/blog/2021/10/04/windows-11-offers-chip-to-cloud-protection-to-meet-the-new-security-challenges-of-hybrid-work/
https://www.microsoft.com/en-us/download/details.aspx?id=55319

Oct 5, 2021 • 6min
ISC StormCast for Tuesday, October 5th, 2021
Facebook Outage
https://isc.sans.edu/forums/diary/Facebook+Outage+Yes+its+DNS+sort+of+A+super+quick+analysis+of+what+is+going+on/27900/
Boutique "Dark" Botnet Hunting for Crumbs
https://isc.sans.edu/forums/diary/Boutique+Dark+Botnet+Hunting+for+Crumbs/27898/
Apache Airflow May Leak Credentials
https://www.intezer.com/blog/cloud-security/misconfigured-airflows-leak-credentials/

Oct 4, 2021 • 6min
ISC StormCast for Monday, October 4th, 2021
A New Tool To Add to Your LOLBAS List: cvtres.exe
https://isc.sans.edu/forums/diary/New+Tool+to+Add+to+Your+LOLBAS+List+cvtresexe/27892/
Google Chrome Continuing Updates
https://support.google.com/chrome/answer/95414?hl=en&co=GENIE.Platform%3DDesktop
Cyber Security Awareness Month
https://www.sans.org/security-awareness-training/resources/
https://isc.sans.edu/tag.html?tag=csam
FCC Attempts to Fight SIM Swapping
https://docs.fcc.gov/public/attachments/DOC-376199A1.pdf
MacOS Gatekeeper Bypass
https://labs.f-secure.com/blog/the-discovery-of-cve-2021-1810/

Oct 1, 2021 • 15min
ISC StormCast for Friday, October 1st, 2021
Visa/Apple Express Transit Relay Attack
https://www.bbc.com/news/technology-58719891
FluBot Offering Fake FlutBot Protection
https://twitter.com/CERTNZ/status/1443701853665980440
Undetected Azure Active Directory Brute-Force Attacks
https://www.secureworks.com/research/undetected-azure-active-directory-brute-force-attacks
SANS.edu Student Christopher DeWees: Expired Domain Dumpster Diving https://www.sans.edu/cyber-research/40505/

Sep 30, 2021 • 5min
ISC StormCast for Thursday, September 30th, 2021
Keeping Track of Time: Network Time Protocol and GPSD Bug
https://isc.sans.edu/forums/diary/Keeping+Track+of+Time+Network+Time+Protocol+and+a+GPSD+Bug/27886/
Apple Airtags Stored XSS
https://medium.com/@bobbyrsec/zero-day-hijacking-icloud-credentials-with-apple-airtags-stored-xss-6997da43a216
CISA/NSA Guidance To Configure VPNs
https://media.defense.gov/2021/Sep/28/2002863184/-1/-1/0/CSI_SELECTING-HARDENING-REMOTE-ACCESS-VPNS-20210928.PDF
Facebook Open Sourcing "Mariana Trench" Tool To Analyze Android and Java Apps
https://engineering.fb.com/2021/09/29/security/mariana-trench/

Sep 29, 2021 • 6min
ISC StormCast for Wednesday, September 29th, 2021
TLS 1.3 and SSL: The Current State of Affairs
https://isc.sans.edu/forums/diary/TLS+13+and+SSL+the+current+state+of+affairs/27882/
EFF Discontinues HTTPS Everywhere Plugin
https://www.eff.org/deeplinks/2021/09/https-actually-everywhere
Malicious CryptoCoin Wallet
https://discourse.mozilla.org/t/got-hacked-by-the-add-on-called-safepal-wallet/85797
Microsoft Automates Exchange Mitigations
https://techcommunity.microsoft.com/t5/exchange-team-blog/new-security-feature-in-september-2021-cumulative-update-for/ba-p/2783155

Sep 28, 2021 • 6min
ISC StormCast for Tuesday, September 28th, 2021
Trend Micro ServerProtect Authentication Bypass Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-21-1115/
Let's Encrypt Root CA Expiration
https://community.letsencrypt.org/t/production-chain-changes/150739
ERMAC Android Malware
https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html
QNAP Vulnerabilities
https://www.qnap.com/en/security-advisory/QSA-21-35

Sep 27, 2021 • 6min
ISC StormCast for Monday, September 27th, 2021
Mobile Device Inventory via Active Sync
https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Your+Users+Mobile+Devices+Simple+Inventory/27868/
Autodiscover Attacks
https://autodiscover-vulnerable-tlds.com
https://wiki.mozilla.org/Public_Suffix_List
https://www.guardicore.com/labs/autodiscovering-the-great-leak/
Three More 0-Day Vulnerabilities in iOS
https://habr.com/en/post/579714/
original russian version: https://habr.com/en/post/579716/
Cisco CAPWAP Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-capwap-rce-LYgj8Kf
Sonicwall SMA 100 Series Vulnerablity
https://www.sonicwall.com/support/product-notification/security-notice-critical-arbitrary-file-delete-vulnerability-in-sonicwall-sma-100-series-appliances/210819124854603/


