

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Sep 9, 2019 • 5min
ISC StormCast for Monday, September 9th 2019
Unidentified Scanning Activity Likely Associated with Mirai/Successors
https://isc.sans.edu/forums/diary/Unidentified+Scanning+Activity/25304/
Bluekeep Exploit Now in Metasploit
https://blog.rapid7.com/2019/09/06/initial-metasploit-exploit-module-for-bluekeep-cve-2019-0708/
How to Remove GMail Calendar Spam
https://support.google.com/calendar/answer/6084018?co=GENIE.Platform%3DDesktop&hl=en
Exim SNI TLS Vulnerability
https://exim.org/static/doc/security/CVE-2019-15846.txt

Sep 4, 2019 • 6min
ISC StormCast for Wednesday, September 4th 2019
Tricky Link Retrieves Trick Bot
https://isc.sans.edu/forums/diary/Guest+Diary+Tricky+LNK+points+to+TrickBot/25290/
Supermicro Virtual USB Vulnerability
https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/
Facebook Free Basics Key Used to Sign Unrelated Android Apps
https://www.androidpolice.com/2019/08/29/cryptographic-key-used-to-sign-one-of-facebooks-android-apps-compromised/

Sep 3, 2019 • 5min
ISC StormCast for Tuesday, September 3rd 2019
Malware Installs Node.js
https://isc.sans.edu/forums/diary/Malware+Dropping+a+Local+Nodejs+Instance/25284/
Dovecot and PigeonHole Vulnerability
https://www.openwall.com/lists/oss-security/2019/08/28/3
Cloudflare Workers Spreading Malware
https://medium.com/@marcelx/threat-actor-behind-astaroth-is-now-using-cloudflare-workers-to-bypass-your-security-solutions-2c658d08f4c

Sep 2, 2019 • 5min
ISC StormCast for Monday, September 2nd 2019
iOS Exploits in the Wild
https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html
Twitter CEO's Twitter Account Hijacked
https://twitter.com/TwitterComms/status/1167528672523210752

Aug 30, 2019 • 6min
ISC StormCast for Friday, August 30th 2019
Malware Samples Compiling Their Next Stage On PremiseMalware Compiling Itself;
https://isc.sans.edu/forums/diary/Malware+Samples+Compiling+Their+Next+Stage+on+Premise/25278/
CERT-Bund Attempts to Notify Users of Vulnerable Home Automation Systems
https://www.heise.de/security/meldung/CERT-Bund-warnt-vor-offenen-Smarthome-Systemen-4509977.html
French Authorities Shut Down Coinminer Botnet
https://decoded.avast.io/janvojtesek/putting-an-end-to-retadup-a-malicious-worm-that-infected-hundreds-of-thousands/

Aug 29, 2019 • 6min
ISC StormCast for Thursday, August 29th 2019
Open Redirects: A Small But Very Common Vulnerability
https://isc.sans.edu/forums/diary/Guest+Diary+Open+Redirect+A+Small+But+Very+Common+Vulnerability/25276/
CamScanner Malicious Download Component
https://securelist.com/dropper-in-google-play/92496/
Ares ADB Botnet
https://www.wootcloud.com/blogs/ars_botnet.html
Cisco REST API Container for IOS XE Authentication Bypass
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass

Aug 28, 2019 • 7min
ISC StormCast for Wednesday, August 28th 2019
Is it "Safe" To Require TLS 1.2 for Email
https://isc.sans.edu/forums/diary/Is+it+Safe+to+Require+TLS+12+for+EMail/25270/
Android Trojan Infects Tens of Thousands of Devices in 4 Months
https://www.bleepingcomputer.com/news/security/android-trojan-infects-tens-of-thousands-of-devices-in-4-months/
LYCEUM Threat Group Targeting Middle East
https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign

Aug 27, 2019 • 5min
ISC StormCast for Tuesday, August 27th 2019
Apple Patches Jailbreak Vulnerability
https://support.apple.com/en-us/HT210549
Scanning for Pulse Secure VPN Endpoints
https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2019-11510/
Emotet is Back
https://www.bleepingcomputer.com/news/security/emotet-botnet-is-back-servers-active-across-the-world/

Aug 26, 2019 • 5min
ISC StormCast for Monday, August 26th 2019
Simple Mimikatz And RDPWrapper Dropper
https://isc.sans.edu/forums/diary/Simple+Mimikatz+RDPWrapper+Dropper/25262/
Malware Impersonating IRS
https://www.irs.gov/newsroom/security-summit-warns-of-new-irs-impersonation-email-scam-reminds-taxpayers-the-irs-does-not-send-unsolicited-emails
Instagram Phishing with 2FA Codes
https://nakedsecurity.sophos.com/2019/08/23/instagram-phishing-uses-2fa-as-a-lure/
GitHub Adding WebAuthn Support
https://www.theregister.co.uk/2019/08/23/github_upgrades_its_twofactor_authentication_with_webauthn_support/
Lenovo Solution Center Privilege Escalation
https://www.pentestpartners.com/security-blog/privesc-in-lenovo-solution-centre-10-minutes-later/

Aug 23, 2019 • 6min
ISC StormCast for Friday, August 23rd 2019
Steam Zero Days and Bug Bounty Controversy
https://www.theregister.co.uk/2019/08/22/valve_bug_bounty_steam_u_turn/
bb-builder malicious npm Package
https://blog.reversinglabs.com/blog/the-npm-package-that-walked-away-with-all-your-passwords
Phishers Customize Branded Outlook 365 Login Pages
https://www.bleepingcomputer.com/news/security/phishing-attacks-scrape-branded-microsoft-365-login-pages/


