

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 9, 2020 • 6min
ISC StormCast for Monday, March 9th 2020
Excel Maldocs: Hidden Sheets
https://isc.sans.edu/forums/diary/Excel+Maldocs+Hidden+Sheets/25876/
Wireshark 3.2.2. Released
https://www.wireshark.org/docs/relnotes/wireshark-3.2.2.html
Linux PPP Vulnerability
https://www.kb.cert.org/vuls/id/782301/
NordVPN Vulnerablity
https://www.theregister.co.uk/2020/03/06/nordvpn_no_auth_needed_view_user_payments/
Unpatched Android Devices
https://www.which.co.uk/news/2020/03/more-than-one-billion-android-devices-at-risk-of-malware-threats/

Mar 6, 2020 • 6min
ISC StormCast for Friday, March 6th 2020
Survey Phish
https://isc.sans.edu/forums/diary/Will+You+Put+Your+Password+in+a+Survey/25866/
Healthcare.gov Sending E-Mail Looking Like Phishing
https://twitter.com/johullrich/status/1235740586717720577
Intel x86 Root of Trust: Loss of Trust
https://blog.ptsecurity.com/2020/03/intelx86-root-of-trust-loss-of-trust.html
Let's Encrypt Revises Revokation Plan
https://community.letsencrypt.org/t/2020-02-29-caa-rechecking-bug/114591/2
Trust Me, I'm Certified Podcast
https://www.giac.org/podcasts

Mar 5, 2020 • 7min
ISC StormCast for Thursday, March 5th 2020
MSFT Subdomain Takeover
https://vullnerability.com/blog/microsoft-subdomain-account-takeover
Homoglyph Attacks in the News Again
https://www.soluble.ai/blog/public-disclosure-emoji-to-zero-day
Coronavirus Phish
https://twitter.com/JCyberSec_/status/1234806881195044865

Mar 4, 2020 • 6min
ISC StormCast for Wednesday, March 4th 2020
Introduction to EvtxEcmd (Evtx Explorer)
https://isc.sans.edu/forums/diary/Introduction+to+EvtxEcmd+Evtx+Explorer/25858/
Let's Encrypt Revoking Certificates
https://community.letsencrypt.org/t/revoking-certain-certificates-on-march-4/114864
Using Smart Devices in the Home Securely (NCSC Version)
https://www.ncsc.gov.uk/guidance/smart-devices-in-the-home
Ransomware and Cloud Backups
https://www.bleepingcomputer.com/news/security/ransomware-attackers-use-your-cloud-backups-against-you/
SANS Coronavirus Training Guarantee
https://www.sans.org/training-guarantee

Mar 3, 2020 • 6min
ISC StormCast for Tuesday, March 3rd 2020
SSL Distribution by Country
https://isc.sans.edu/forums/diary/Secure+vs+cleartext+protocols+couple+of+interesting+stats/25854/
Checkpoint Evasion Encyclopedia
https://research.checkpoint.com/2020/cpr-evasion-encyclopedia-the-check-point-evasion-repository/
OWASP Threat Dragon
https://github.com/mike-goodwin/owasp-threat-dragon-desktop
SANS Free Things
https://sans.org/free

Mar 2, 2020 • 5min
ISC StormCast for Monday, March 2nd 2020
Show me Your Clipboard Data!
https://isc.sans.edu/forums/diary/Show+me+Your+Clipboard+Data/25846/
Hazelcast IMDB Discover Scan
https://isc.sans.edu/forums/diary/Hazelcast+IMDG+Discover+Scan/25850/
Microsoft Exchange Server Vulnerabilty Scans
https://twitter.com/GossiTheDog/status/1232369036438233088
Tomcat Ghostcat Vulnerability
https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E

Feb 28, 2020 • 6min
ISC StormCast for Friday, February 28th 2020
Ultrasonic Triggers for Cellphone Assistants.
https://source.wustl.edu/2020/02/surfing-attack-hacks-siri-google-with-ultrasonic-waves/
Comparing Information Leakage from Different Browsers
https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf
Cloud Snooper Attack
https://news.sophos.com/en-us/2020/02/25/cloud-snooper-attack-bypasses-firewall-security-measures/

Feb 27, 2020 • 7min
ISC StormCast for Thursday, February 27th 2020
Kr00k WiFi Attack
https://www.eset.com/int/kr00k/
Impersonating LTE Users
https://imp4gt-attacks.net/
Zyxel RCE Vulnerablity
https://www.kb.cert.org/vuls/id/498544/

Feb 26, 2020 • 6min
ISC StormCast for Wednesday, February 26th 2020
Fraudulant Paypal Charges (links in German)
https://twitter.com/iblueconnection/status/1232259071602044928
https://www.heise.de/security/meldung/Google-Pay-Luecke-in-virtuellen-Kreditkarten-erlaubt-unberechtigte-Abbuchungen-4667527.html
https://stadt-bremerhaven.de/google-pay-virtuelle-paypal-kreditkarten-weisen-sicherheitsluecken-auf/
Chrome Update
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
Microsoft Public Preview For Azure AD Hybrid Environments
https://techcommunity.microsoft.com/t5/azure-active-directory-identity/public-preview-of-azure-ad-support-for-fido2-security-keys-in/ba-p/1187929

Feb 25, 2020 • 7min
ISC StormCast for Tuesday, February 25th 2020
ScrollToTextFragment Privacy Concerns in Google Chrome 80
https://github.com/WICG/ScrollToTextFragment/issues/76#issue-538137989
https://docs.google.com/document/d/1YHcl1-vE_ZnZ0kL2almeikAj2gkwCq8_5xwIae7PVik/edit#heading=h.uoiwg23pt0tx
Another OpenSMTPD Vulnerability
https://github.com/OpenSMTPD/OpenSMTPD/releases
WhatsApp Group Invite Links in Search Engines
https://twitter.com/JordanWildon/status/1230829082662842369


