

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Aug 20, 2017 • 5min
ISC StormCast for Monday, August 21st 2017
EngineBox Banking Malware
https://isc.sans.edu/forums/diary/EngineBox+Malware+Supports+10+Brazilian+Banks/22736/
It's Not An Invoice
https://isc.sans.edu/forums/diary/Its+Not+An+Invoice/22738/
iOS Secure Enclave Key Posted
https://www.theiphonewiki.com/wiki/Greensburg_14G60_%28iPhone6,1%29
Vulnerabilities in FoxIT PDF Reader
https://www.thezdi.com/blog/2017/8/17/busting-myths-in-foxit-reader

Aug 18, 2017 • 16min
ISC StormCast for Friday, August 18th 2017
Maldoc with auto-updated link
https://isc.sans.edu/forums/diary/Maldoc+with+autoupdated+link/22730/
Rowhammer is Back: SSD Memory Affected
https://www.usenix.org/system/files/conference/woot17/woot17-paper-kurmus.pdf
Nathaniel Quist: Active Defense in a Labyrinth of Deception
https://www.sans.org/reading-room/whitepapers/ActiveDefense/active-defense-labyrinth-deception-37462

Aug 17, 2017 • 6min
ISC StormCast for Thursday, August 17th 2017
Analysis of a Paypal Phishing Kit
https://isc.sans.edu/forums/diary/Analysis+of+a+Paypal+phishing+kit/22726/
ShadowPad Backdoor in NetSarang Equipment
https://securelist.com/shadowpad-in-corporate-networks/81432/
Solving Captcha Audio Challenges
http://uncaptcha.cs.umd.edu/papers/uncaptcha_woot17.pdf

Aug 16, 2017 • 6min
ISC StormCast for Wednesday, August 16th 2017
Malspam Pushing Trickbot Banking Trojan
https://isc.sans.edu/forums/diary/Malspam+pushing+Trickbot+banking+Trojan/22720/
Banker Google Chrome Extension Targeting Brazil
https://isc.sans.edu/forums/diary/BankerGoogleChromeExtensiontargetingBrazil/22722/
DJI "Go" App May Be Using JSPatch To Modify Applications After Install
https://www.rcgroups.com/forums/showpost.php?p=38096850&postcount=2713
Smartlocks Bricked After Auto-Update
http://www.securitysales.com/news/smart-locks-lobotomized-failed-update/

Aug 15, 2017 • 6min
ISC StormCast for Tuesday, August 15th 2017
When A Malicious Looking E-Mail Turns Out to be "just" spam
https://isc.sans.edu/forums/diary/Sometimes+its+just+SPAM/22716/
Android iOS Intra-Library Collusion
https://arxiv.org/abs/1708.03520
SonicSpy: Android Spyware Apps
https://blog.lookout.com/sonicspy-spyware-threat-technical-research
Checking For Breached Passwords in Active Directory
https://jacksonvd.com/checking-for-breached-passwords-in-active-directory/

Aug 14, 2017 • 6min
ISC StormCast for Monday, August 14th 2017
Outlook Web Access Based Attacks
https://isc.sans.edu/forums/diary/Outlook+Web+Access+based+attacks/22710/
The Good Phishing Email
https://isc.sans.edu/forums/diary/The+Good+Phishing+Email/22712/
Git/CVS/Mercurial and others: ssh vulnerablity
http://blog.recurity-labs.com/2017-08-10/scm-vulns
Postgresql Vulnerablities
https://bugzilla.redhat.com/show_bug.cgi?id=1477185

Aug 11, 2017 • 6min
ISC StormCast for Friday, August 11th 2017
Maldoc Analysis With ViperMonkey
https://isc.sans.edu/forums/diary/Maldoc+Analysis+with+ViperMonkey/22702/
Microsoft Joins Google/Mozilla in Banishing WoSign and StartCom From Trusted CA List
https://blogs.technet.microsoft.com/mmpc/2017/08/08/microsoft-to-remove-wosign-and-startcom-certificates-in-windows-10/
SMS Touch App Leaking Messages
https://www.zscaler.com/blogs/research/mobile-app-wall-shame-sms-touch
Mac Adware Mughthesec
https://objective-see.com/blog/blog_0x20.html

Aug 10, 2017 • 7min
ISC StormCast for Thursday, August 10th 2017
DirectDefense Accuses Carbon Black of Data Leak
https://www.carbonblack.com/2017/08/09/directdefense-incorrectly-asserts-architectural-flaw-in-cb-response/
https://www.directdefense.com/harvesting-cb-response-data-leaks-fun-profit/
Vulnerabilities in Solar Generation
https://horusscenario.com
Hunting Malicious npm Packages
https://duo.com/blog/hunting-malicious-npm-packages

Aug 9, 2017 • 6min
ISC StormCast for Wednesday, August 9th 2017
Microsoft Updates
https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+August+2017/22694/
Adobe Updates
https://helpx.adobe.com/security.html
Android Patches
https://source.android.com/security/bulletin/2017-08-01
How Are People Fooled By This? Email To Sign a Contract Provides Malware
https://isc.sans.edu/forums/diary/How+are+people+fooled+by+this+Email+to+sign+a+contract+provides+malware+instead/22696/

Aug 7, 2017 • 6min
ISC StormCast for Tuesday, August 8th 2017
PHPMyAdmin Scans
https://isc.sans.edu/forums/diary/Increase+of+phpMyAdmin+scans/22688/
Hotspot Shield Leakes Private User Data
https://cdt.org/files/2017/08/FTC-CDT-VPN-complaint-8-7-17.pdf
Debian Turning Off Support for TLS 1.0/1.1
https://lists.debian.org/debian-devel-announce/2017/08/msg00004.html
Ongoing Phishing Attacks Against Google Chrome Plugin Developers
https://www.bleepingcomputer.com/news/security/chrome-extension-developers-under-a-barrage-of-phishing-attacks/


