SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Nov 14, 2017 • 8min

ISC StormCast for Tuesday, November 14th 2017

FaceID Beaten By Mask http://www.bkav.com/d/top-news/-/view_content/content/103968/face-id-beaten-by-mask-not-an-effective-security-measure Various URL Validation and HTTP Request Libraries Allow SSRF https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf Using Heart Rythm As Biometric ID http://www.buffalo.edu/news/releases/2017/09/034.html
undefined
Nov 13, 2017 • 7min

ISC StormCast for Monday, November 13th 2017

Auditing TLS Root Certificates on Windows https://isc.sans.edu/forums/diary/Keep+An+Eye+on+your+Root+Certificates/23030/ How Google Accounts Are Hijacked https://security.googleblog.com/2017/11/new-research-understanding-root-cause.html Battling E-Mail Phishing https://isc.sans.edu/forums/diary/Battling+email+phishing/23028/ Hacking Airplanes http://www.aviationtoday.com/2017/11/08/boeing-757-testing-shows-airplanes-vulnerable-hacking-dhs-says/
undefined
Nov 10, 2017 • 7min

ISC StormCast for Friday, November 10th 2017

Twilio Credentials Found in Mobile Apps (requires registration) http://info.appthority.com/-q4-2017-mtr-download-eavesdropper Drive By Cryto Currency Mining Keeps Increasing https://go.malwarebytes.com/rs/805-USG-300/images/Drive-by_Mining_FINAL.pdf Intel's Management Engine Firmware Decoded https://twitter.com/h0t_max https://www.theregister.co.uk/2017/11/09/chipzilla_come_closer_closer_listen_dump_ime/
undefined
Nov 9, 2017 • 6min

ISC StormCast for Thursday, November 9th 2017

Mantistek Gaming Keyboard Cloud Driver Exfiltrates Keystroke Data https://thehackernews.com/2017/11/mantistek-keyboard-keylogger.html Logitech Will Discontinue Harmony Link Device and Brick it via Firmware Update in March 2018 https://www.theverge.com/circuitbreaker/2017/11/8/16623076/logitech-harmony-link-discontinued-bricked Amazon Is Introducing Additional Security Features for S3 https://aws.amazon.com/blogs/aws/new-amazon-s3-encryption-security-features/
undefined
Nov 8, 2017 • 7min

ISC StormCast for Wednesday, November 8th 2017

Interesting RTF Maldoc VBA Dropper https://isc.sans.edu/forums/diary/Interesting+VBA+Dropper/23016/ Multiple Linux USB Flaws Made Public http://www.openwall.com/lists/oss-security/2017/11/06/8 Google Android November Patches https://source.android.com/security/bulletin/2017-11-01#media-framework Ethereum Multi Signature Wallet Bug Cause Loss of $280 Million https://paritytech.io/blog/security-alert.html https://github.com/paritytech/parity/issues/6995
undefined
Nov 7, 2017 • 6min

ISC StormCast for Tuesday, November 7th 2017

Fake WhatsApp App in Google Play Store https://www.reddit.com/r/Android/comments/7ahujw/psa_two_different_developers_under_the_same_name/ Crunchyroll.com Redirect Leads to Malware https://blog.ellation.com/crunchyroll-com-update-a2a593cf9155 https://bartblaze.blogspot.com.au/2017/11/crunchyroll-hack-delivers-malware.html Recovering Previously Encrypted iOS Backups https://www.gillware.com/forensics/blog/digital-forensics-case-study/new-solution-encrypted-backups/
undefined
Nov 6, 2017 • 5min

ISC StormCast for Monday, November 6th 2017

PDF Parser for URLs and Text Content of PDFs https://isc.sans.edu/forums/diary/Extracting+the+text+from+PDF+documents/23008/ https://isc.sans.edu/forums/diary/PDF+documents+URLs/23006/ Mobile Pwn2Own Contest 2017 https://www.zerodayinitiative.com/blog OpenSSL Patch https://www.openssl.org/news/secadv/20171102.txt IEEE P1735 Standard Leads to Weak Crypto https://eprint.iacr.org/2017/828.pdf
undefined
Nov 2, 2017 • 7min

ISC StormCast for Friday, November 3rd 2017

Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKI http://www.umiacs.umd.edu/~tdumitra/papers/CCS-2017.pdf Half of Most Popular Free iOS Apps do not use TLS correctly http://www.zeit.de/digital/datenschutz/2017-10/iphone-ios-apps-hacker-verschluesselung/komplettansicht#comments Image Downloader Chrome Extension Includes Adware https://www.bleepingcomputer.com/news/security/psa-beware-the-image-downloader-chrome-adware-extension/ Employees Pay Up Ransomware https://www.bleepingcomputer.com/news/security/59-percent-of-employees-hit-by-ransomware-at-work-paid-ransom-out-of-their-own-pockets/
undefined
Nov 1, 2017 • 6min

ISC StormCast for Thursday, November 2nd 2017

Configuring SSH Properly on Cisco IOS https://isc.sans.edu/forums/diary/Securing+SSH+Services+Go+Blue+Team/22992/ Ethereum Miners Hijacked via Default SSH Credentials https://labs.bitdefender.com/2017/11/ethereum-os-miners-targeted-by-ssh-based-hijacker/ Crypto Shuffler Steals Bitcoin From Clipboard https://www.kaspersky.com/blog/cryptoshuffler-bitcoin-stealer/19976/ Google Calender Event Injection Added To Mail Snipper https://www.blackhillsinfosec.com/google-calendar-event-injection-mailsniper/ November Ouch! Newsletter released: Shopping Security Online https://securingthehuman.sans.org/resources/newsletters/ouch/2017?utm_medium=Social&utm_source=Twitter&utm_content=OUCH+Nov+2017+all+languages+&utm_campaign=STH+Ouch+#november2017
undefined
Oct 31, 2017 • 5min

ISC StormCast for Wednesday, November 1st 2017

Malicious Powershell Code https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/ Apple Updates Everything https://support.apple.com/en-gb/HT201222 Internet Draft To Update IoT Devices https://tools.ietf.org/html/draft-moran-suit-architecture-00

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app