

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

May 4, 2020 • 5min
ISC StormCast for Monday, May 4th 2020
ZIP Files and AES
https://isc.sans.edu/forums/diary/ZIP+AES/26080/
Saltstack Vulnerability Exploited in the Wild
https://status.ghost.org/
Mobile Device Manager Compromise
https://research.checkpoint.com/2020/first-seen-in-the-wild-mobile-as-attack-vector-using-mdm/

May 1, 2020 • 7min
ISC StormCast for Friday, May 1st 2020
Collecting IOCs from IMAP Folder
https://isc.sans.edu/forums/diary/Collecting+IOCs+from+IMAP+Folder/26070/
Attack Traffic on TCP Port 9673
https://isc.sans.edu/forums/diary/Attack+traffic+on+TCP+port+9673/26074/
Saltstack Authorization Bypass
https://labs.f-secure.com/advisories/saltstack-authorization-bypass
Mac Sandbox Escape
https://lapcatsoftware.com/articles/sandbox-escape.html

Apr 30, 2020 • 6min
ISC StormCast for Thursday, April 30th 2020
Privacy Preserving Protocols to Trace Covid19 Exposure
https://isc.sans.edu/forums/diary/Privacy+Preserving+Protocols+to+Trace+Covid19+Exposure/26066/
Google Chrome Update
https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_27.html
https://docs.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security
Updated Version of Sysmon
https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon
https://techcommunity.microsoft.com/t5/sysinternals-blog/sysmon-v11-0-livekd-v5-63-process-explorer-v16-32-coreinfo-v3-5/ba-p/1345153
Shade Ransomware Keys Released
https://github.com/shade-team/keys/blob/master/README.md
Exploiting the Exploiters
https://medium.com/@curtbraz/exploiting-the-exploiters-46fd0d620fd8

Apr 29, 2020 • 5min
ISC StormCast for Wednesday, April 29th 2020
Agent Tesla Delivered by the Same Phishing Campagin for Over a Year
https://isc.sans.edu/forums/diary/Agent+Tesla+delivered+by+the+same+phishing+campaign+for+over+a+year/26062/
VMWare ESXi Patch
https://www.vmware.com/security/advisories/VMSA-2020-0008.html
Microsoft Guidance For Ransomware Response
https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/
Adobe Security Patches
https://helpx.adobe.com/security.html

Apr 28, 2020 • 6min
ISC StormCast for Tuesday, April 28th 2020
Powershell Payload Stored in a PSCredential Object
https://isc.sans.edu/forums/diary/Powershell+Payload+Stored+in+a+PSCredential+Object/26058/
Microsoft Teams Account Takeover Bug
https://www.cyberark.com/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams/
USB Drives used to Spread Crypto Coin Mining Botnet
https://www.welivesecurity.com/2020/04/23/eset-discovery-monero-mining-botnet-disrupted/

Apr 27, 2020 • 8min
ISC StormCast for Monday, April 27th 2020
Malware Bazaar
https://isc.sans.edu/forums/diary/MALWARE+Bazaar/26052/
CIRA Luanches Canadian Shield
https://www.cira.ca/newsroom/canadian-shield/cira-launches-canadian-shield-provide-free-privacy-and-security-canadians
Covid19 Tracing Protocols
https://github.com/DP-3T/documents
https://www.pepp-pt.org/content
https://www.apple.com/covid19/contacttracing/
Sophos XG Firewall SQL Injection Vulnerablity Exploited
https://community.sophos.com/kb/en-us/135412

Apr 24, 2020 • 7min
ISC StormCast for Friday, April 24th 2020
GCC's New Security Analyzer Finds Flaw in OpenSSL
https://developers.redhat.com/blog/2020/03/26/static-analysis-in-gcc-10/
IBM Spectrum Protect Server Stack Based Buffer Overflow
https://www.ibm.com/support/pages/node/6195706
Possible Issues With Cummulative Windows Updates
https://www.reddit.com/search/?q=KB4549951
Using a GPU as a Radio
https://duo.com/labs/research/finding-radio-sidechannels
Comparing Red Team Platforms
https://redcanary.com/blog/comparing-red-team-platforms/

Apr 23, 2020 • 6min
ISC StormCast for Thursday, April 23rd 2020
iOS Mail 0Day
https://blog.zecops.com/vulnerabilities/unassisted-ios-attacks-via-mobilemail-maild-in-the-wild/
Zoom 5 To Be Released Shortly Addressing Encryption Issues
https://blog.zoom.us/wordpress/2020/04/22/zoom-hits-milestone-on-90-day-security-plan-releases-zoom-5-0/
OpenSSL Fixes DOS Flaw
https://www.openssl.org/news/secadv/20200421.txt

Apr 22, 2020 • 6min
ISC StormCast for Wednesday, April 22nd 2020
SpectX: Log Parser for DFIR
https://isc.sans.edu/forums/diary/SpectX+Log+Parser+for+DFIR/26040/
Microsoft Patches Autodesk Library in Office
https://www.autodesk.com/trust/security-advisories/adsk-sa-2020-0002
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200004
Stripe Data Collection
https://mtlynch.io/stripe-recording-its-customers/
IBM Data Risk Manager Vulnerabilities
https://github.com/pedrib/PoC/blob/master/advisories/IBM/ibm_drm/ibm_drm_rce.md

Apr 21, 2020 • 6min
ISC StormCast for Tuesday, April 21st 2020
KPOT AutoIt Script: Analysis
https://isc.sans.edu/forums/diary/KPOT+AutoIt+Script+Analysis/26012/
FPGA Vulnerablity
https://www.usenix.org/conference/usenixsecurity20/presentation/ender
Nagios XI Vulnerability
https://exchange.xforce.ibmcloud.com/vulnerabilities/179406


