SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Apr 15, 2019 • 6min

ISC StormCast for Monday, April 15th 2019

Configuring MTA-STS https://isc.sans.edu/forums/diary/Configuring+MTASTS+and+TLS+Reporting+For+Your+Domain/24840/ How to Find Hidden Cameras in Your AirBNB https://isc.sans.edu/forums/diary/How+to+Find+Hidden+Cameras+in+your+AirBNB/24834/ Insecure Storage of VPN Credentials https://www.kb.cert.org/vuls/id/192371/ Microsoft Patch Problems https://support.microsoft.com/en-us/help/4493472/windows-7-update-kb4493472 https://support.microsoft.com/en-us/help/4493446/windows-8-1-update-kb4493446 Internet Explorer XML External Entity Vulnerability http://hyp3rlinx.altervista.org/advisories/MICROSOFT-INTERNET-EXPLORER-v11-XML-EXTERNAL-ENTITY-INJECTION-0DAY.txt
undefined
Apr 12, 2019 • 6min

ISC StormCast for Friday, April 12th 2019

GMail Will Be Supporting MTA-STS and SMTP TLS Reporting https://tools.ietf.org/html/rfc8461 https://tools.ietf.org/html/rfc8460 https://www.zdnet.com/article/gmail-becomes-first-major-email-provider-to-support-mta-sts-and-tls-reporting/ Juniper Patch Fixes Static Password in Junos OS https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10923&actp=METADATA Uniden Commercial IP Camera Site Hosting Malware https://twitter.com/JayTHL/status/1116200014630596609
undefined
Apr 11, 2019 • 8min

ISC StormCast for Thursday, April 11th 2019

WPA3 Dragonblood Vulnerability http://papers.mathyvanhoef.com/dragonblood.pdf North Korean Trojan: HOPLIGHT https://www.us-cert.gov/ncas/analysis-reports/AR19-100A Gaza Cybergang Group1 "SneakyPastes" https://securelist.com/gaza-cybergang-group1-operation-sneakypastes/90068/
undefined
Apr 9, 2019 • 7min

ISC StormCast for Wednesday, April 10th 2019

Microsoft and Adobe Patches https://isc.sans.edu/forums/diary/Microsoft+April+2019+Patch+Tuesday/24826/ https://helpx.adobe.com/security.html Fake "Food Poisoning" emails in Germany (in german) https://www.polizei-praevention.de/aktuelles/erneut-mails-mit-schadsoftware-gegen-gewerbetreibende-im-umlauf.html Vulnerability in Apache Axis https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/ Golang DLL Injection Vulnerability https://www.openwall.com/lists/oss-security/2019/04/09/1
undefined
Apr 9, 2019 • 6min

ISC StormCast for Tuesday, April 9th 2019

GHidra vs. IDA https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+1+the+decompilerunreachable+code/24822/ TrendMicro Patch https://success.trendmicro.com/solution/1122250 Dovecot Patch https://dovecot.org/list/dovecot-news/2019-March/000403.html Apache CVE-2019-0211 Exploit https://github.com/cfreal/exploits/tree/master/CVE-2019-0211-apache Using JavaScript in Exploits https://www.youtube.com/watch?v=HfpnloZM61I
undefined
Apr 7, 2019 • 7min

ISC StormCast for Monday, April 8th 2019

Fake Office 365 Invoices Spread Ransomware https://isc.sans.edu/forums/diary/Fake+Office+365+Payment+Information+Update/24818/ Malware Hiding in .well-known directory https://www.zscaler.com/blogs/research/abuse-hidden-well-known-directory-https-sites Altering CT Images to Manipulate Diagnosis https://arxiv.org/pdf/1901.03597.pdf QT Framework RCE Vulnerability https://www.zerodayinitiative.com/blog/2019/4/3/loading-up-a-pair-of-qt-bugs-detailing-cve-2019-1636-and-cve-2019-6739
undefined
Apr 4, 2019 • 6min

ISC StormCast for Friday, April 5th 2019

New Waves of Scans Detected By An Old Rule https://isc.sans.edu/forums/diary/New+Waves+of+Scans+Detected+by+an+Old+Rule/24812/ Xiaomi GuardApp Vulnerable to Man in the Middle https://blog.checkpoint.com/2019/04/04/xiaomi-vulnerability-when-security-is-not-what-it-seems/ Xwo Web Scanner Hunting for MongoDB https://www.alienvault.com/blogs/labs-research/xwo-a-python-based-bot-scanner Vulnerable SmartWatches "Defaced" https://api.heise.de/svc/embetty/tweet/1112326532939374593-images-0 https://www.heise.de/newsticker/meldung/Vidimensio-Smartwatches-Der-Sicherheits-Alptraum-geht-weiter-4359967.html
undefined
Apr 4, 2019 • 6min

ISC StormCast for Thursday, April 4th 2019

Ghidra tips for IDA users: Automatic Comments for API Call Parameters https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+0+automatic+comments+for+API+call+parameters/24806/ Security Awareness Newsletter: Making Passwords Simple https://www.sans.org/security-awareness-training/resources/making-passwords-simple IRS Themed Phishing Emails https://www.proofpoint.com/us/threat-insight/post/tax-themed-email-campaigns-target-2019-filers Large Leak of Facebook User Data via 3rd Party App https://www.upguard.com/breaches/facebook-user-data-leak Arbitrary Command Execution in PostgreSQL https://medium.com/greenwolf-security/authenticated-arbitrary-command-execution-on-postgresql-9-3-latest-cd18945914d5
undefined
Apr 3, 2019 • 5min

ISC StormCast for Wednesday, April 3rd 2019

Compromised LaCie Drive Spread Fake AntiVirus https://isc.sans.edu/forums/diary/Fake+AV+is+Back+LaCie+Network+Drives+Used+to+Spread+Malware/24802/ Unpatched SOP Vulnerability in Internet Explorer/Edge https://thehackernews.com/2019/03/microsoft-edge-ie-zero-days.html Apache Fixes Privilege Escalation Flaw https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2019-0211 Verizon Users Phished for Credentials https://blog.lookout.com/mobile-phishing-verizon
undefined
Apr 2, 2019 • 5min

ISC StormCast for Tuesday, April 2nd 2019

Common "OpenAction" False Positive in PDFs Created by OpenOffice https://isc.sans.edu/forums/diary/Analysis+of+PDFs+Created+with+OpenOfficeLibreOffice/24798/ Android Monthly Update https://source.android.com/security/bulletin/2019-04-01#2019-04-01-details Malicious Android App Forwards Banking Calls to Attacker https://www.blackhat.com/asia-19/briefings/schedule/index.html#when-voice-phishing-met-malicious-android-app-13419 Google Allowing WebAuthn Login from Firefox/Edge https://twitter.com/christiaanbrand/status/1111430192596025347 All Your Data Are Belong to Us: Defending Against Credential Stuffing Attacks https://www.sans.org/webcasts/data-belong-us-defend-credential-stuffing-110340

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app