

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jul 1, 2021 • 7min
ISC StormCast for Thursday, July 1st, 2021
CVE-2021-1675 Incomplete Patch - Printnightmware
https://isc.sans.edu/forums/diary/CVE20211675+Incomplete+Patch+and+Leaked+RCE+Exploit/27588/
Internet Explorer PDF Update
https://support.microsoft.com/en-us/topic/june-29-2021-kb5004760-os-builds-19041-1082-19042-1082-and-19043-1082-out-of-band-9508f7a2-0713-432f-b06c-1ae6d802a2f7
NETGEAR Router Vulnerabilities (DGN-2200v1)
https://www.microsoft.com/security/blog/2021/06/30/microsoft-finds-new-netgear-firmware-vulnerabilities-that-could-lead-to-identity-theft-and-full-system-compromise/

Jun 30, 2021 • 6min
ISC StormCast for Wednesday, June 30th, 2021
Google "Sweepstake" Phish Withouth Link
https://isc.sans.edu/forums/diary/Diving+into+a+Google+Sweepstakes+Phishing+Email/27578/
Forensics Contest Solution / Winner
https://isc.sans.edu/forums/diary/June+2021+Forensic+Contest+Answers+and+Analysis/27582/
WD MyBook Details
https://arstechnica.com/gadgets/2021/06/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices/
Adobe Experience Manager PoC
https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/

Jun 28, 2021 • 6min
ISC StormCast for Monday, June 28th, 2021
Increase in UDP Port 389 Scans (LDAP/AD)
https://isc.sans.edu/forums/diary/Is+this+traffic+bAD/27566/
CD/DVD Destruction
https://isc.sans.edu/forums/diary/DIY+CDDVD+Destruction/27572/
Zyxel Exploits
https://twitter.com/JAMESWT_MHT/status/1407987022170578946
https://kb.zyxel.com/KB/searchArticle!viewDetail.action?articleOid=018137&lang=EN
Cisco Vulnerability Exploited
https://threatpost.com/cisco-asa-bug-exploited-poc/167274/
Microsoft Signs Netfilter Rootkit
https://www.gdatasoftware.com/blog/microsoft-signed-a-malicious-netfilter-rootkit

Jun 25, 2021 • 6min
ISC StormCast for Friday, June 25th, 2021
Do You Like Cookies? Some are for sale!
https://isc.sans.edu/forums/diary/Do+you+Like+Cookies+Some+are+for+sale/27558/
A supply-chain breach: Taking over an Atlassian account
https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/23175805/Atlassian-ATO-CPR-blog-FINAL.pdf
Dell Bios Connect Vulnerability
https://eclypsium.com/2021/06/24/biosdisconnect/
ATM Jackpotting via NFC
https://www.wired.com/story/atm-hack-nfc-bugs-point-of-sale/

Jun 24, 2021 • 6min
ISC StormCast for Thursday, June 24th, 2021
DNS Name Server Hijack Attack
https://www.darkreading.com/vulnerabilities---threats/new-dns-name-server-hijack-attack-exposes-businesses-government-agencies/d/d-id/1341377
Paloalto Cortex XSOAR Vulnerablity
https://security.paloaltonetworks.com/CVE-2021-3044
VMWare Carbon Black App Control Authentication Bypass
https://www.vmware.com/security/advisories/VMSA-2021-0012.html?
Standing With Security Researchers Against Misuse of the DMCA
https://www.eff.org/deeplinks/2021/06/dmca-security-researcher-statement

Jun 23, 2021 • 6min
ISC StormCast for Wednesday, June 23rd, 2021
Phishing asking recipients not to report abuse
https://isc.sans.edu/forums/diary/Phishing+asking+recipients+not+to+report+abuse/27556/
PyPi Cryptomining Malware
https://blog.sonatype.com/sonatype-catches-new-pypi-cryptomining-malware-via-automated-detection
Dovecot TLS Implementation Vulnerability
https://hackerone.com/reports/1204962
(see the link to the PDF for more details)
Sonicwall Patch Incomplete
https://www.tripwire.com/state-of-security/featured/analyzing-sonicwalls-unsuccessful-fix-for-cve-2020-5135/

Jun 22, 2021 • 5min
ISC StormCast for Tuesday, June 22nd, 2021
Attack and Defend: Distributed Web Applications (free Webcast)
https://www.sans.org/webcasts/attack-defend-modern-distributed-applications-119610
Darkside Impersonators
https://www.helpnetsecurity.com/2021/06/21/impersonating-darkside/
Tesla RAT COVID-19 Vaccination Phish
https://threatpost.com/agent-tesla-covid-vax-phish/167082/
Tor Browser Update
https://www.bleepingcomputer.com/news/security/tor-browser-fixes-vulnerability-that-tracks-you-using-installed-apps/
Schneider PowerLogic Vulnerabilities
https://www.ehackingnews.com/2021/06/six-major-flaws-identified-in-schneider.html
AutoCAD Update
https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004

Jun 21, 2021 • 6min
ISC StormCast for Monday, June 21st, 2021
Network Forensics on Azure VMs (Part #2)
https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+2/27538/
Google Open Redirect Being Abused
https://isc.sans.edu/forums/diary/Open+redirects+and+why+Phishers+love+them/27542/
Easy Access to the NIST RDS Database
https://isc.sans.edu/forums/diary/Easy+Access+to+the+NIST+RDS+Database/27544/
iOS Wifi Bug
https://blog.chichou.me/2021/06/20/quick-analysis-wifid/
NSA VoIP Security Guide
https://media.defense.gov/2021/Jun/17/2002744054/-1/-1/1/CTR_DEPLOYING%20SECURE%20VVOIP%20SYSTEMS.PDF

Jun 18, 2021 • 6min
ISC StormCast for Friday, June 18th, 2021
Network Forensics on Azure VMs
https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+1/27536/
Fake Ledger Hardware Wallets
https://www.ledger.com/phishing-campaigns-status#phishing-campaigns
https://www.reddit.com/r/ledgerwallet/comments/o154gz/package_from_ledger_is_this_legit/
Zoll Defibrilator Dashboard Vulnerability
https://us-cert.cisa.gov/ics/advisories/icsma-21-161-01
Akamai Prolexic Outage
https://threatpost.com/hiccup-akamais-ddos-outages/167004/

Jun 17, 2021 • 5min
ISC StormCast for Thursday, June 17th, 2021
June 2021 Forensic Quiz
https://isc.sans.edu/forums/diary/June+2021+Forensic+Contest/27532/
ThroughTek IP Camera SDK Vulnerability
https://www.nozominetworks.com/blog/new-iot-security-risk-throughtek-p2p-supply-chain-vulnerability/
Peleoton Insecure Boot Vulnerability
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/a-new-program-for-your-peloton-whether-you-like-it-or-not/
Microsoft Defender for Endpoint Detecting Jailbroken Devices
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-new-capabilities-on-android-and-ios/ba-p/2442730


