

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Apr 29, 2019 • 5min
ISC StormCast for Monday, April 29th 2019
WebLogic Update
https://isc.sans.edu/diary.html?storyid=24890
Docker Hub Breach
https://success.docker.com/article/docker-hub-user-notification

Apr 26, 2019 • 5min
ISC StormCast for Friday, April 26th 2019
Unpatched Vulnerablity in WebLogic Exploited
https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+Alert+WebLogic+Zero+Day/24880/
Collecting Windows Service Accounts
https://isc.sans.edu/forums/diary/Service+Accounts+Redux+Collecting+Service+Accounts+with+PowerShell/24882/
Confluence Vulnerablity Exploited by GandGrab
https://blog.alertlogic.com/active-exploitation-of-confluence-vulnerability-cve-2019-3396-dropping-gandcrab-ransomware/
New Micrsoft Security Baseline for Windows 10 / Windows Server
https://blogs.technet.microsoft.com/secguide/2019/04/24/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903/

Apr 25, 2019 • 7min
ISC StormCast for Thursday, April 25th 2019
Rooting Out Unwanted Domain Admins With Powershell
https://isc.sans.edu/forums/diary/Where+have+all+the+Domain+Admins+gone+Rooting+out+Unwanted+Domain+Administrators/24874/
Mac OS X-Protect Now Covering Windows Malware
https://twitter.com/patrickwardle/status/1120771284286103552
Wifi Finder Leaks Hotspot Passwords
https://techcrunch.com/2019/04/22/hotspot-password-leak/
Github Hosting Phishing Pages
https://www.proofpoint.com/us/threat-insight/post/threat-actors-abuse-github-service-host-variety-phishing-kits
RSA Webinar: The Five Most Dangerous New Attack Techniques and How to Counter Them
https://www.rsaconference.com/videos/rsac-2019-the-five-most-dangerous-new-attack-techniques-and-how-to-counter-them-continued

Apr 24, 2019 • 6min
ISC StormCast for Wednesday, April 24th 2019
Decoding Malicious VBA Office Document Without Source Code
https://isc.sans.edu/forums/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870/
More Updates on "ShadowHammer" Supply Chain Attack
https://securelist.com/operation-shadowhammer-a-high-profile-supply-chain-attack/90380/
A Malicious Sight in Google Sites
https://www.netskope.com/blog/malicious-google-sites

Apr 22, 2019 • 6min
ISC StormCast for Tuesday, April 23rd 2019
.rar Files Exploiting ACE Vulneraiblity CVE-2018-20250
https://isc.sans.edu/forums/diary/rar+Files+and+ACE+Exploit+CVE201820250/24864/
Malware Senders Become Younger and Less Sophisticated (in German)
https://www.heise.de/security/meldung/Malware-Verteiler-werden-immer-juenger-infizieren-sich-oft-selbst-4403823.html
McAfee Antivirus Affected by April Windows Update Crashes
http://kc.mcafee.com/corporate/index?page=content&id=KB91465
Rules to Protect Against Azure Blog Phishing in Outlook 365
https://malware-research.org/simple-rule-to-protect-against-spoofed-windows-net-phishing-attacks/
Windows 7 End of Support Messages
https://www.windowslatest.com/2019/04/20/windows-7-users-are-now-receiving-the-end-of-support-notifications/

Apr 22, 2019 • 7min
ISC StormCast for Monday, April 22nd 2019
Analyzing UDF Files Using Python
https://isc.sans.edu/forums/diary/Analyzing+UDF+Files+with+Python/24860/
HTML Ping To Be Adopted By All Major Browsers
https://webkit.org/blog/8821/link-click-analytics-and-privacy/
Microsoft to Modify Edge User Agent for Some Sites
https://www.onmsft.com/news/new-edge-insider-browser-can-change-user-agent-strings-based-on-what-website-youre-visiting
French Government Chat System Used Weak User Management
https://m.heise.de/security/meldung/Tchap-Frankreichs-nicht-so-exklusiver-Regierungschat-4403961.html

Apr 19, 2019 • 7min
ISC StormCast for Friday, April 19th 2019
Malware Delivered As a UDF .img file
https://isc.sans.edu/forums/diary/Malware+Sample+Delivered+Through+UDF+Image/24854/
Facebook Stored Passwords in Plain Text
https://newsroom.fb.com/news/2019/03/keeping-passwords-secure/
Iranian Statesponsored Malware and Data Leaked
https://misterch0c.blogspot.com/2019/04/apt34-oilrig-leak.html
Windows 8 Live Tiles Domain Takeover
https://www.golem.de/news/subdomain-takeover-microsoft-verliert-kontrolle-ueber-windows-kacheln-1904-140709.html

Apr 18, 2019 • 5min
ISC StormCast for Thursday, April 18th 2019
DNS Hijacking by Sea Turtle
https://blog.talosintelligence.com/2019/04/seaturtle.html
Broadcom Wifi Driver Vulnerabilities
https://www.kb.cert.org/vuls/id/166939/
NamPoHyu Virus Infects Samba Servers
https://www.bleepingcomputer.com/news/security/nampohyu-virus-ransomware-targets-remote-samba-servers/
Increased Attacks on Confluence
https://twitter.com/DFNCERT/status/1118468599230943233

Apr 17, 2019 • 6min
ISC StormCast for Wednesday, April 17th 2019
PoC Exploit for Windows 10 DHCP Client Vulnerability CVE-2019-0726 (russian)
https://habr.com/ru/company/pt/blog/448378/
Oracle April 2019 Critical Patch Update
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
WiPro Breached Via Phishing Attacks
https://krebsonsecurity.com/2019/04/experts-breach-at-it-outsourcing-giant-wipro/
IDA and GHydra Part 2 (Strings And Parameters)
https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+2+strings+and+parameters/24848/

Apr 16, 2019 • 7min
ISC StormCast for Tuesday, April 16th 2019
Common "False Positives" in DNS Query Logs
https://isc.sans.edu/forums/diary/Odd+DNS+Requests+that+are+Normal/24844/
Adblock Plus Allows Filter List Providers to Inject Code in Pages
https://armin.dev/blog/2019/04/adblock-plus-code-injection/
Executables in Polyglot DICOM Images
https://github.com/d00rt/pedicom/blob/master/doc/Attacking_Digital_Imaging_and_Communication_in_Medicine_(DICOM)_file_format_standard_-_Markel_Picado_Ortiz_(d00rt).pdf
Malicious/Misleading VPN Ads
https://www.bleepingcomputer.com/news/security/mobile-vpns-promoted-by-you-are-infected-or-hacked-ads/


