

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Oct 8, 2020 • 7min
ISC StormCast for Thursday, October 8th 2020
Today, Nobody is Going to Attack You
https://isc.sans.edu/forums/diary/Today+Nobody+is+Going+to+Attack+You/26654/
Google Chrome Patches
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html
Android Security Update
https://source.android.com/security/bulletin/2020-10-01
QNAP Patches Helpdesk Application
https://www.qnap.com/en/security-advisory/QSA-20-08
Comcast Remote Control Evesdropping
https://www.guardicore.com/2020/10/wareztheremote-turning-remotes-into-listening-devices/

Oct 7, 2020 • 9min
ISC StormCast for Wednesday, October 7th 2020
Apple T2 Chip Vulnerability
https://ironpeak.be/blog/crouching-t2-hidden-danger/
NVIDIA Patches
https://nvidia.custhelp.com/app/answers/detail/a_id/5075
Cloudflare DDoS Alerts
https://blog.cloudflare.com/announcing-ddos-alerts/
Gravatar Privacy Issue
https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/

Oct 6, 2020 • 6min
ISC StormCast for Tuesday, October 6th 2020
Obfuscation and Repetition
https://isc.sans.edu/forums/diary/Obfuscation+and+Repetition/26648/
Compromised UEFI Payload Found
https://securelist.com/mosaicregressor/98849/
Privilege Escalation Flaw in All AntiVirus Products
https://www.cyberark.com/resources/threat-research-blog/anti-virus-vulnerabilities-who-s-guarding-the-watch-tower
Rapid7 SMTP "NICER" Report
https://blog.rapid7.com/2020/10/02/nicer-protocol-deep-dive-internet-exposure-of-smtp/

Oct 5, 2020 • 6min
ISC StormCast for Monday, October 5th 2020
Analysis of a Phishing Kit
https://isc.sans.edu/forums/diary/Analysis+of+a+Phishing+Kit/26634/
Hoaxcalls Botnet Scanning for Huawei Home Gateway
https://isc.sans.edu/forums/diary/Scanning+for+SOHO+Routers/26638/
SQL Server Cumulative Update 8
https://support.microsoft.com/en-us/help/4577194/cumulative-update-8-for-sql-server-2019
Telstra Accidentially Reroutes Proton Mail Traffic
https://protonmail.com/blog/bgp-hijacking-september-2020/
"Raccine" Ransomware Vaccine
https://github.com/Neo23x0/Raccine

Oct 2, 2020 • 5min
ISC StormCast for Friday, October 2nd 2020
Making Sensor of Azure AD Activity Logs
https://isc.sans.edu/forums/diary/Making+sense+of+Azure+AD+AAD+activity+logs/26626/
IOCs Turning into IOOIs
https://isc.sans.edu/forums/diary/IOCs+turning+into+IOOIs/26624/
Apple Security Patch Pulled
https://mrmacintosh.com/mojave-2020-005-security-update-causing-major-problems-updated
Have I Been EMOTET Service
https://www.haveibeenemotet.com/

Oct 1, 2020 • 6min
ISC StormCast for Thursday, October 1st 2020
Scans for FPURL.xml: Reconnaissance or Not?
https://isc.sans.edu/forums/diary/Scans+for+FPURLxml+Reconnaissance+or+Not/26622/
HP Device Manager Backdoor
https://support.hp.com/us-en/document/c06921908
https://www.theregister.com/2020/09/30/hp_device_manager_backdoor_database_account/
KensingtonWorks RCE
https://robertheaton.com/another-rce-in-kensingtonworks/

Sep 30, 2020 • 5min
ISC StormCast for Wednesday, September 30th 2020
Managing Remote Access for Contractors and Partners
https://isc.sans.edu/forums/diary/Managing+Remote+Access+for+Partners+Contractors/26614/#comments
Updated Windows ZeroLogon Advisory
https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc
Cisco Patching Exploited DoS Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz
FoxIT PDF Reader Update
https://www.foxitsoftware.com/support/security-bulletins.html

Sep 29, 2020 • 6min
ISC StormCast for Tuesday, September 29th 2020
Some Tyler Technologies Customers Targeted after Breach
https://isc.sans.edu/forums/diary/Some+Tyler+Technologies+Customers+Targeted+with+The+Installation+of+a+Bomgar+Client/26610/
Obfuscated PowerShell Backdoor
https://isc.sans.edu/forums/diary/PowerShell+Backdoor+Launched+from+a+ShellCode/26602/
QNAP Fixes AgeLocker Vulnerability in Photo Station
https://www.qnap.com/de-de/security-advisory/qsa-20-06
TrendMicro Apex One Vulnerablity
https://success.trendmicro.com/product-support/apex-one

Sep 28, 2020 • 6min
ISC StormCast for Monday, September 28th 2020
Securing Exchange Online
https://isc.sans.edu/forums/diary/Securing+Exchange+Online+Guest+Diary/26600/
Decoding Corrupt BASE64
https://isc.sans.edu/forums/diary/Decoding+Corrupt+BASE64+Strings/26606/
Fortinet VPN Default Setting Problem
https://securingsam.com/breaching-the-fort/
Single Use Credit Cards Numbers
https://www.helpnetsecurity.com/2020/09/25/privacy-cards/

Sep 25, 2020 • 6min
ISC StormCast for Friday, September 25th 2020
Party in Ibiza with PowerShell
https://isc.sans.edu/forums/diary/Party+in+Ibiza+with+PowerShell/26594/
Microsoft Tracking Zerologon Exploits
https://twitter.com/MsftSecIntel/status/1308941504707063808
Apple Patches
https://support.apple.com/en-us/HT201222
Instagram for Android Vulnerability
https://blog.checkpoint.com/2020/09/24/instahack-how-researchers-were-able-to-take-over-the-instagram-app-using-a-malicious-image/


