

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 5, 2018 • 6min
ISC StormCast for Monday, March 5th 2018
Protective Malicious Monero Crypto Coin Miners
https://isc.sans.edu/forums/diary/The+Crypto+Miners+Fight+For+CPU+Cycles/23407/
memcached DDoS Attacks Ask For Ransom
https://blogs.akamai.com/2018/03/memcached-now-with-extortion.html
Cheap Android Trojans Come PreInstalled With Banking Malware
https://news.drweb.com/show/?lng=en&i=11749&c=5
RedDrop Android Malware Installed via 3rd Party App Stores
https://www.wandera.com/blog/reddrop-malware/

Mar 2, 2018 • 8min
ISC StormCast for Friday, March 2nd 2018
Censoring Images At Scale in #WeChat
https://isc.sans.edu/forums/diary/Why+Does+Emperor+Xi+Dislike+Winnie+the+Pooh+and+Scrambled+Eggs/23395/
Trustico Update: Certificate Revocation List Monitor
https://isc.sans.edu/crls.html
Memcached Update: Github Attack
https://githubengineering.com/ddos-incident-report/
http://powerofcommunity.net/poc2017/shengbao.pdf
Microsoft Releases Intel Spectre Microcode Updates
https://support.microsoft.com/en-us/help/4090007/intel-microcode-updates

Mar 1, 2018 • 6min
ISC StormCast for Thursday, March 1st 2018
How Did This Memcache Thing Happen?
https://isc.sans.edu/forums/diary/How+did+this+Memcache+thing+happen/23391/
Trustico TLS Certificate Revocation
https://groups.google.com/forum/#!msg/mozilla.dev.security.policy/wxX4Yv0E3Mk/QZt8UPhKAwAJ
Flash on Its Way Out
https://www.bleepingcomputer.com/news/security/google-chrome-flash-usage-declines-from-80-percent-in-2014-to-under-8-percent-today/
DNSSEC Is Getting Better But Still Struggeling
http://www.theregister.co.uk/2018/02/28/dutch_name_authority_dnssec_validation_errors_can_be_eliminated/
Smart TV Firmware Flaws
https://www.av-comparatives.org/wp-content/uploads/2018/02/avc_sigma_medion_201802.pdf

Feb 28, 2018 • 6min
ISC StormCast for Wednesday, February 28th 2018
Memcached Servers Used in Reflective DDoS Attacks
https://isc.sans.edu/forums/diary/Why+we+Dont+Deserve+the+Internet+Memcached+Reflected+DDoS+Attacks/23389/
Malspam Pushing Formbook Info Stealer
https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/23387/
Various SAML Parsers Affected by Comment Parsing Vulnerability
https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations

Feb 27, 2018 • 5min
ISC StormCast for Tuesday, February 27th 2018
Enumerating S3 Buckets
https://github.com/jordanpotti/AWSBucketDump
Creating AWS Network Diagrams
https://github.com/duo-labs/cloudmapper
Selling Macs and "Find my Mac" Feature
https://medium.com/@mulligan/how-i-sold-an-old-mac-and-unknowingly-tracked-its-location-for-over-3-years-9a35cd3ca4cf
Apple Stopping Support for 1st Gen Apple TV and iTunes on Windows XP / Vista
https://support.apple.com/en-us/HT208104

Feb 26, 2018 • 6min
ISC StormCast for Monday, February 26th 2018
Retrieving Malware Over Tor On Windows (Update)
https://isc.sans.edu/forums/diary/Retrieving+malware+over+Tor+on+Windows/23379/
Blackholing Advertising Sites with Pi-Hole
https://isc.sans.edu/forums/diary/Blackhole+Advertising+Sites+with+Pihole/23377/
Taxslayer Consent Degree with FTC
https://biglawbusiness.com/cybersecurity-enforcers-wake-up-to-unauthorized-computer-access-via-credential-stuffing/
Fortinet (OMG) Mirai
https://www.fortinet.com/blog/threat-research/omg--mirai-based-bot-turns-iot-devices-into-proxy-servers.html

Feb 2, 2018 • 6min
ISC StormCast for Friday, February 2nd 2018
Adobe Flash 0-Day
https://isc.sans.edu/forums/diary/Adobe+Flash+0Day+Used+Against+South+Korean+Targets/23301/
Adaptive Phishing Kit
https://isc.sans.edu/forums/diary/Adaptive+Phishing+Kit/23299/
Crypto Miners "Payload of Choice"
http://blog.talosintelligence.com/2018/01/malicious-xmr-mining.html
Autosploit Links Shodan to Metasploit
https://github.com/NullArray/AutoSploit

Feb 1, 2018 • 7min
ISC StormCast for Thursday, February 1st 2018
Tax Phishing Season Starts
https://isc.sans.edu/forums/diary/Tax+Phishing+Time/23295/
Using FLIR In Incident Response
https://isc.sans.edu/forums/diary/Using+FLIR+in+Incident+Response/23291/
Oracle MICROS POS Vulnerability
https://erpscan.com/press-center/blog/oracle-micros-pos-breached/

Jan 30, 2018 • 7min
ISC StormCast for Wednesday, January 31st 2018
DCShadow Attack
https://www.dropbox.com/s/baypdb6glmvp0j9/Buehat%20IL%20v2.3.pdf
https://blog.alsid.eu/dcshadow-explained-4510f52fc19d
Cisco WebVPN Update
https://isc.sans.edu/forums/diary/Cisco+ASA+WebVPN+Vulnerability/23289/
Reviving DDE Code Execution via OneNote
https://posts.specterops.io/reviving-dde-using-onenote-and-excel-for-code-execution-d7226864caee

Jan 30, 2018 • 6min
ISC StormCast for Tuesday, January 30th 2018
Lenovo Fingerprint Mananger Pro Vulnerability
https://support.lenovo.com/us/en/product_security/len-15999
ClamAV Vulnerablities
http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html
https://blog.malwarebytes.com/malwarebytes-news/2018/01/important-web-blocking-ram-usage/
Malwarebytes Corrupted Update
https://www.malwarebytes.com/pdf/WebProtectionFP.pdf
Cisco Adaptive Security Appliance Remote Code Execution Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1
Web2Top Proxy onion.tor Appears to Steal Ransomware Payments
https://www.proofpoint.com/us/threat-insight/post/double-dipping-diverting-ransomware-bitcoin-payments-onion-domains


