

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Sep 10, 2021 • 7min
ISC StormCast for Friday, September 10th, 2021
ISC/DShield API Updates
https://isc.sans.edu/forums/diary/Updates+to+Our+DatafeedsAPI/27824/
Update on Windows MSHTML Vulnerability
https://www.bleepingcomputer.com/news/microsoft/windows-mshtml-zero-day-defenses-bypassed-as-new-info-emerges/
GitHub Actions check-spelling community workflow GITHUB_TOKEN leakage
https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md

Sep 9, 2021 • 6min
ISC StormCast for Thursday, September 9th, 2021
Protonmail Correction
https://protonmail.com/blog/climate-activist-arrest/
https://protonmail.com/privacy-policy
"Stolen Images Evidence" Campaign Continues Pushing BazarLoader Malware
https://isc.sans.edu/forums/diary/Stolen+Images+Evidence+Campaign+Continues+Pushing+BazarLoader+Malware/27816/
Thyotic Secret Server Critical Update
https://docs.thycotic.com/ss/11.0.0/release-notes/ss-rn-11-0-000007.md
Zoho Vulnerablity Exploited
https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html

Sep 8, 2021 • 6min
ISC StormCast for Wednesday, September 8th, 2021
Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444
ProntonMail/VPN Releasing User's IP Address
https://protonmail.com/blog/climate-activist-arrest/
What's App End To End Encryption Questioned (but upheld)
https://twitter.com/evacide/status/1435288900587589632?s=20
PRIVATELOG and STASHLOG Malware Store Payload in Common Log File System (CLFS)
https://www.fireeye.com/blog/threat-research/2021/09/unknown-actor-using-clfs-log-files-for-stealth.html

Sep 7, 2021 • 5min
ISC StormCast for Tuesday, September 7th, 2021
Confluence Update
https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
https://www.jenkins.io/blog/2021/09/04/wiki-attacked/
ProxyShell Update
https://news.sophos.com/en-us/2021/09/03/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks/
RCE-0-Day for GhostScript 9.50
https://github.com/duc-nt/RCE-0-day-for-GhostScript-9.50
Netgear Switch Auth Bypass
https://kb.netgear.com/000063978/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Smart-Switches-PSV-2021-0140-PSV-2021-0144-PSV-2021-0145

Sep 3, 2021 • 14min
ISC StormCast for Friday, September 3rd, 2021
Attackers Will Always Abuse Major Events in our Lifes
https://isc.sans.edu/forums/diary/Attackers+Will+Always+Abuse+Major+Events+in+our+Lifes/27808/
Active Exploitation of Confluence Server CVE-2021-26084
https://www.rapid7.com/blog/post/2021/09/02/active-exploitation-of-confluence-server-cve-2021-26084/
GitHub Removing old Ciphers / Keys
https://github.blog/2021-09-01-improving-git-protocol-security-github/
Cisco Enterprise NFV Infrastructure Software Authentication Bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh
Hackers are Selling Tool to Hide Malware in GPUs
https://www.ehackingnews.com/2021/09/hackers-are-selling-tool-to-hide.html
Michael Beck: Cloud Forensics Triage Framework (CFTF)
https://www.sans.org/white-papers/40415/

Sep 2, 2021 • 6min
ISC StormCast for Thursday, September 2nd, 2021
STRRAT: A Java Based RAT That Doesn't Care if You Have Java
https://isc.sans.edu/forums/diary/STRRAT+a+Javabased+RAT+that+doesnt+care+if+you+have+Java/27798/
IPC360 Baby Monitor Vulnerability
https://www.bitdefender.com/files/News/CaseStudies/study/402/Bitdefender-PR-Whitepaper-VictureIPC-creat5590-en-EN.pdf
Annke Network Video Recorder Vulnerability
https://us-cert.cisa.gov/ics/advisories/icsa-21-238-02
ProxyWare Abuse
https://blog.talosintelligence.com/2021/08/proxyware-abuse.html

Sep 1, 2021 • 5min
ISC StormCast for Wednesday, September 1st, 2021
BrakTooth: Impacts, Implications and Next Steps
https://isc.sans.edu/forums/diary/BrakTooth+Impacts+Implications+and+Next+Steps/27802/
Fortress Home Security System Weakness
https://threatpost.com/fortress-home-security-remote-disarmament/169069/
PostgreSQL set_user Module Vulnerability
https://www.postgresql.org/about/news/set_user-201-released-2279/

Aug 31, 2021 • 6min
ISC StormCast for Tuesday, August 31st, 2021
Cryptocurrency Clipboard Swapper Delivered With Love
https://isc.sans.edu/forums/diary/Cryptocurrency+Clipboard+Swapper+Delivered+With+Love/27794/
ProxyToken Vulnerability in Exchange
https://www.zerodayinitiative.com/blog/2021/8/30/proxytoken-an-authentication-bypass-in-microsoft-exchange-server
LockFile Ransomware Evasion Tricks
https://thehackernews.com/2021/08/lockfile-ransomware-bypasses-protection.html

Aug 30, 2021 • 5min
ISC StormCast for Monday, August 30th, 2021
ChaosDB: Azure Cosmos Database Vulnerability
https://chaosdb.wiz.io
Phishing via Open Redirects
https://www.microsoft.com/security/blog/2021/08/26/widespread-credential-phishing-campaign-abuses-open-redirector-links/
Parallels Vulnerability
https://exchange.xforce.ibmcloud.com/vulnerabilities/208188
https://www.zerodayinitiative.com/advisories/ZDI-21-1000/

Aug 27, 2021 • 6min
ISC StormCast for Friday, August 27th, 2021
Cisco Advisories
https://tools.cisco.com/security/center/publicationListing.x
GETH DoS Vulnerability
https://github.com/ethereum/go-ethereum/releases/tag/v1.10.8
Confluence Security Advisory
https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
VMWare Updates
https://www.vmware.com/security/advisories.html


