SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Nov 1, 2018 • 5min

ISC StormCast for Thursday, November 1st 2018

Encrypted Word Maldocs https://isc.sans.edu/forums/diary/More+malspam+using+passwordprotected+Word+docs/24262/ iOS / MacOS ICMP Error Remote Code Execution https://lgtm.com/blog/apple_xnu_icmp_error_CVE-2018-4407 iOS Lock Screen Bypass https://www.youtube.com/watch?v=ojigFgwrtKs
undefined
Oct 31, 2018 • 5min

ISC StormCast for Wednesday, October 31st 2018

Change in Strategy for Hancitor Malware https://isc.sans.edu/forums/diary/Campaign+evolution+Hancitor+malspam+starts+pushing+Ursnif+this+week/24256/ Apple Updates https://support.apple.com/en-us/HT201222 Telegram Stores Conversations Locally https://twitter.com/nathanielrsuchy
undefined
Oct 30, 2018 • 6min

ISC StormCast for Tuesday, October 30th 2018

Maldoc Duplicating PowerShell https://isc.sans.edu/forums/diary/Maldoc+Duplicating+PowerShell+Prior+to+Use/24254/ New File Types Emerge in Malware Spam Attachments https://blog.trendmicro.com/trendlabs-security-intelligence/same-old-yet-brand-new-new-file-types-emerge-in-malware-spam-attachments/ Malicious Mac Crypto Currency Tracker Installs Backdoor https://blog.malwarebytes.com/threat-analysis/2018/10/mac-cryptocurrency-ticker-app-installs-backdoors/ Sandbox For Windows Defender https://cloudblogs.microsoft.com/microsoftsecure/2018/10/26/windows-defender-antivirus-can-now-run-in-a-sandbox/
undefined
Oct 29, 2018 • 5min

ISC StormCast for Monday, October 29th 2018

Dissecting Malicious Office Documents in Linux https://isc.sans.edu/forums/diary/Dissecting+Malicious+Office+Documents+with+Linux/24248/ Analyzing Compressed RTF Documents https://isc.sans.edu/forums/diary/Detecting+Compressed+RTF/24250/ SystemD DHCPv6 Remote Code Executing Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-15688 Cryptominers Scan for Docker Engine https://blog.trendmicro.com/trendlabs-security-intelligence/misconfigured-container-abused-to-deliver-cryptocurrency-mining-malware DemonBot Targeting Hadoop https://blog.radware.com/security/2018/10/new-demonbot-discovered/
undefined
Oct 26, 2018 • 5min

ISC StormCast for Friday, October 26th 2018

Scam Calls Targeting Chinese Living in the US https://isc.sans.edu/forums/diary/Fake+BankPost+Office+Phone+Calls+Targeting+Chinese+Immigrants/24244/ X.org Privilege Elevation Flaw https://lists.x.org/archives/xorg-announce/2018-October/002927.html Remote Videos in Office Documents https://blog.cymulate.com/abusing-microsoft-office-online-video Mac Malware Injects Ads https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/
undefined
Oct 25, 2018 • 5min

ISC StormCast for Thursday, October 25th 2018

Reversing AutoIT https://isc.sans.edu/forums/diary/Diving+into+Malicious+AutoIT+Code/24238/ Arcserve Vulnerabilities https://www.digitaldefense.com/blog/zero-day-alerts/arcserve-disclosure/ WebExec Vulnerability https://webexec.org/ More ALPC Flaws from Sandbox Escaper https://twitter.com/SandboxEscaper/status/1054744201244692485 https://twitter.com/mkolsek/status/1054794984908562432
undefined
Oct 24, 2018 • 6min

ISC StormCast for Wednesday, October 24th 2018

Malware Uses Decoy Picture https://isc.sans.edu/forums/diary/Malicious+Powershell+using+a+Decoy+Picture/24234/ DNS over HTTPS Pushback https://twitter.com/paulvixie/status/1053765281917661184 Signal Desktop Leaves Encryption Key Exposed https://twitter.com/nathanielrsuchy Firefox 63 Allows Less Tracking https://blog.mozilla.org/security/2018/10/23/firefox-63-lets-users-block-tracking-cookies/
undefined
Oct 23, 2018 • 5min

ISC StormCast for Tuesday, October 23rd 2018

MSG Files: Compressed RTF https://isc.sans.edu/forums/diary/MSG+Files+Compressed+RTF/24228/ FreeRTOS TCP/IP Stack Vulnerabilities https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/ VLC/Live555 RTSP Server Vulnerability https://www.talosintelligence.com/reports/TALOS-2018-0684 Microsoft Yammer Update https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-8569#ID0EGB
undefined
Oct 22, 2018 • 5min

ISC StormCast for Monday, October 22nd 2018

MacOS LaunchAgent https://isc.sans.edu/forums/diary/Beyond+good+ol+LaunchAgent+part+0/24230/ TLS Session Tracking https://arxiv.org/pdf/1810.07304.pdf jQuery File Upload Plugin https://blogs.akamai.com/sitr/2018/10/having-the-security-rug-pulled-out-from-under-you.html Drupal Update https://www.drupal.org/sa-core-2018-006
undefined
Oct 19, 2018 • 4min

ISC StormCast for Friday, October 19th 2018

Cisco Patches https://tools.cisco.com/security/center/Search.x?publicationTypeIDs=1&firstPublishedStartDate=2018%2F10%2F17&firstPublishedEndDate=2018%2F10%2F17&lastPublishedStartDate=2018%2F10%2F17&lastPublishedEndDate=2018%2F10%2F17 51% Attack Against Crypto Currencies https://old.reddit.com/r/CryptoCurrency/comments/9m1uuj/if_i_livestreamed_the_setup_and_execution_of/ VMWare Patch https://www.vmware.com/au/security/advisories/VMSA-2018-0026.html

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app