

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Feb 10, 2020 • 7min
ISC StormCast for Monday, February 10th 2020
Sandbox Detection Tricks and Nice Obfuscation in a Single VBScript
https://isc.sans.edu/forums/diary/Sandbox+Detection+Tricks+Nice+Obfuscation+in+a+Single+VBScript/25780/
Emotet Spreads via Wifi
https://www.binarydefense.com/emotet-evolves-with-new-wi-fi-spreader/
Exploit Available for sudo pwfeedback bug
https://dylankatz.com/Analysis-of-CVE-2019-18634/
xiongmail/hisilicon Vulnerability
https://censys.io/blog/probing-the-xiongmai-hisilicon-soc-vulnerability

Feb 7, 2020 • 6min
ISC StormCast for Friday, February 7th 2020
Criticial Bluetooth Vulnerability in Android (CVE-2020-0022)
https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022/
Wacom Tablets Reports Application Details to Google
https://robertheaton.com/2020/02/05/wacom-drawing-tablets-track-name-of-every-application-you-open/
Bitbucket Delivers Malware
https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware
Realtek HD Audio Driver Package DLL Preloading
https://safebreach.com/Post/Realtek-HD-Audio-Driver-Package-DLL-Preloading-and-Potential-Abuses-CVE-2019-19705

Feb 6, 2020 • 6min
ISC StormCast for Thursday, February 6th 2020
Fake Browser Updates installing NetSupport RAT
https://isc.sans.edu/forums/diary/Fake+browser+update+pages+are+still+a+thing/25774/
Google Android Update
https://source.android.com/security/bulletin/2020-02-01#Google-Play-system-updates
5 Cisco Vulnerabilities
https://www.armis.com/cdpwn/

Feb 5, 2020 • 6min
ISC StormCast for Wednesday, February 5th 2020
Google Chrome 80 Released
https://www.chromium.org/updates/same-site
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
File Read Vulnerablity in WhatsApp
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html
HiSilicon DVR Backdoor
https://habr.com/en/post/486856/

Feb 4, 2020 • 7min
ISC StormCast for Tuesday, February 4th 2020
Triple Encrypted AZORult Installer
https://isc.sans.edu/forums/diary/Analysis+of+a+tripleencrypted+AZORult+downloader/25768/
New sudo Vulnerability (pwfeedback)
https://www.sudo.ws/alerts/pwfeedback.html
Teamviewer Password Storage
https://whynotsecurity.com/blog/teamviewer/

Feb 3, 2020 • 6min
ISC StormCast for Monday, February 3rd 2020
Stego and Cryptominers (with video)
https://isc.sans.edu/forums/diary/Video+Stego+Cryptominers/25764/
Corona Virus Phishing / Scams
https://blog.knowbe4.com/heads-up-scam-of-the-week-coronavirus-phishing-attacks-in-the-wild?nCOV-2019-bc-index
https://twitter.com/briankrebs/status/1223959185764896768
Google Open Sources Security Token Software
https://security.googleblog.com/2020/01/say-hello-to-opensk-fully-open-source.html

Jan 31, 2020 • 10min
ISC StormCast for Friday, January 31st 2020
Chrome Same-Site Cookie Change
https://www.chromestatus.com/feature/5088147346030592
https://docs.microsoft.com/en-us/office365/troubleshoot/miscellaneous/chrome-behavior-affects-applications
https://caniuse.com/#feat=same-site-cookie-attribute
Avast Apology
https://blog.avast.com/a-message-from-ceo-ondrej-vlcek
Magento Update
https://helpx.adobe.com/security/products/magento/apsb20-02.html

Jan 30, 2020 • 7min
ISC StormCast for Thursday, January 30th 2020
Malware Using Text from Impeachment News Coverage
https://www.bleepingcomputer.com/news/security/malware-tries-to-trump-security-software-with-potus-impeachment/
Coronavirus Themed Malware Targets Japan with Emotet
https://twitter.com/Cryptolaemus1/status/1222388971428294656
https://exchange.xforce.ibmcloud.com/collection/18f373debc38779065a26f1958dc260b
abuse.ch Offers new "I got phished" service
https://igotphished.abuse.ch/
OpenSMTPD RCE Vulnerability
https://www.openwall.com/lists/oss-security/2020/01/28/3

Jan 29, 2020 • 5min
ISC StormCast for Wednesday, January 29th 2020
Recent Emotet Infection installs Trickbot
https://isc.sans.edu/forums/diary/Emotet+epoch+1+infection+with+Trickbot+gtag+mor84/25752/
Apple Updates
https://support.apple.com/en-us/HT201222
Zoom Fixes Video Conferencing Brute Forcing Vulnerability
https://www.theregister.co.uk/2020/01/28/zoom_eavesdrop_hack/
Intel Fixes Yet Another Information Leakage Flaw
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.html
https://cacheoutattack.com/
Avast Anti Virus Selling User's Browsing Data
https://www.vice.com/en_us/article/qjdkq7/avast-antivirus-sells-user-browsing-data-investigation

Jan 28, 2020 • 5min
ISC StormCast for Tuesday, January 28th 2020
Coronavirus Preparedness and Associated Scams
https://isc.sans.edu/forums/diary/Network+Security+Perspective+on+Coronavirus+Preparedness/25750/
RD Gateway RCE Exploit Demoed
https://twitter.com/layle_ctf/status/1221514332049113095?s=12
Mitsubishi Electric Compromised via Trend Micro Vulnerability
http://www.mitsubishielectric.co.jp/news/2020/0120-b.pdf
https://www.zdnet.com/article/trend-micro-antivirus-zero-day-used-in-mitsubishi-electric-hack/


