

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 16, 2017 • 7min
ISC StormCast for Thursday, March 16th 2017
Twitter App "Twitter Counter" Compromise Leads to Unauthorized Tweets From a Large Number of Accounts
https://twitter.com/thecounter
Telegram and WhatsApp Image Vulnerability
http://blog.checkpoint.com/2017/03/15/check-point-discloses-vulnerability-whatsapp-telegram/
RSA Panel Webcast
https://cc.readytalk.com/registration/#/?meeting=6oowksc223hm&campaign=ijmt1z8qsc1q

Mar 15, 2017 • 6min
ISC StormCast for Wednesday, March 15th 2017
Microsoft's Double Patch Tuesday
https://isc.sans.edu/forums/diary/February+and+March+Microsoft+Patch+Tuesday/22185/

Mar 14, 2017 • 6min
ISC StormCast for Tuesday, March 14th 2017
Creating SHA3 Hashes with sigs.py
https://isc.sans.edu/forums/diary/New+tool+sigspy/22181/
Canada Revenue Agency Website Attacked / Down over Struts2
http://www.cbc.ca/news/politics/cra-internet-vulnerability-government-1.4022591
Webkit Exploit Adobted to Nintendo Switch
https://www.youtube.com/watch?v=xkdPjbaLngE
Analysis of Outdated Javascript Libraries on the Web
http://www.ccs.neu.edu/home/arshad/publications/ndss2017jslibs.pdf
Github Enterprise SAML Authentication Bypass
http://www.economyofmechanism.com/github-saml

Mar 13, 2017 • 7min
ISC StormCast for Monday, March 13th 2017
Issues With Out Of Date Geo Location Databases
https://isc.sans.edu/forums/diary/The+Side+Effect+of+GeoIP+Filters/22173/
Recovering Mobile Device PINs via Thermal Images
http://www.mkhamis.com/data/papers/abdelrahman2017chi.pdf
Unmasking Randomized MAC Addresses
https://arxiv.org/abs/1703.02874v1
Mobile Phone Supply Chain Attacks
http://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/

Mar 10, 2017 • 5min
ISC StormCast for Friday, March 10th 2017
Struts 2 Update
https://isc.sans.edu/forums/diary/Critical+Apache+Struts+2+Vulnerability+Patch+Now/22169/
Exploits Against Haraka Mail Server
https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py
Android Password Stealing Apps
http://www.welivesecurity.com/2017/03/09/new-instagram-credentials-stealers-discovered-google-play/
Drupal Services Module Vulnerability and Exploit
https://www.ambionics.io/blog/drupal-services-module-rce
https://www.drupal.org/node/2858847

Mar 9, 2017 • 6min
ISC StormCast for Thursday, March 9th 2017
Security Researches Target Nintendo Switch
https://twitter.com/qlutoo
https://www.youtube.com/watch?v=CwdDN1kA93Q&feature=youtu.be
Dockerscan
https://github.com/cr0hn/dockerscan
1 in 5 Websites still rely on SHA-1 Based Certificates
http://www.theregister.co.uk/2017/03/08/sha1_certificate_survey/
Not All Malware Samples Are Complex
https://isc.sans.edu/forums/diary/Not+All+Malware+Samples+Are+Complex/22163/
Struts Vulnerability Included in Metasploit
https://github.com/rapid7/metasploit-framework/issues/8064
https://cwiki.apache.org/confluence/display/WW/S2-045?from=groupmessage

Mar 8, 2017 • 7min
ISC StormCast for Wednesday, March 8th 2017
CIA Leak (note that link lead directly to leaked documents)
https://wikileaks.com/ciav7p1/
From Shamoon To Stonedrill: Evolution of Wipers Attacking Saudi Organziations
https://securelist.com/files/2017/03/Report_Shamoon_StoneDrill_final.pdf
WordPress Update
https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/
Reading Secret Keys From SGX Enclaves
https://arxiv.org/abs/1702.08719

Mar 7, 2017 • 6min
ISC StormCast for Tuesday, March 7th 2017
Typosquatting Against Santander Bank in Brazil With Phone Call Follow-up
https://isc.sans.edu/forums/diary/A+very+convincing+Typosquatting+Social+Engineering+campaign+is+targeting+Santander+corporate+customers+in+Brazil/22157/
Post Mortem on 911 DDoS Attack
https://www.wsj.com/articles/how-a-cyberattack-overwhelmed-the-911-system-1488554972
Nextcloud/Owncloud Scanner
https://scan.nextcloud.com
Western Digital MyCloud Vulnerability
https://blog.exploitee.rs/2017/hacking_wd_mycloud/

Mar 6, 2017 • 6min
ISC StormCast for Monday, March 6th 2017
How Your Pictures Affect Your Website Reputation
https://isc.sans.edu/forums/diary/How+your+pictures+may+affect+your+website+reputation/22151/
De-Obuscating Padded Code
https://isc.sans.edu/forums/diary/Another+example+of+maldoc+string+obfuscation+with+extra+bonus+UAC+bypass/22153/
FoxIT PDF Reader Vulnerability
https://www.foxitsoftware.com/support/security-bulletins.php#content-2017
Applying SHA1 Shatter Attack To Bittorent
https://biterrant.io
Gargoyle Memory Scanning Evasion
https://jlospinoso.github.io/security/assembly/c/cpp/developing/software/2017/03/04/gargoyle-memory-analysis-evasion.html
Attacking Synergy Clients
https://www.n00py.io/2017/03/compromising-synergy-clients-with-a-rogue-synergy-server/

Mar 3, 2017 • 5min
ISC StormCast for Friday, March 3rd 2017
Business E-Mail Compromise and Sender Policy Framework Typos (SPF)
https://isc.sans.edu/forums/diary/Phishing+for+Big+Money+Wire+Transfers+is+Still+Alive+and+Well+or+For+Want+of+Good+Punctuation+all+was+Lost/22141/
Android Developers Infected With Malware Publishing Malicious Apps
http://researchcenter.paloaltonetworks.com/2017/03/unit42-google-play-apps-infected-malicious-iframes/
DBLTek GoIP Backdoor
https://www.trustwave.com/Resources/SpiderLabs-Blog/Undocumented-Backdoor-Account-in-DBLTek-GoIP/
Decrypting Findzip/Patcher Ransomware
https://blog.malwarebytes.com/cybercrime/2017/02/decrypting-after-a-findzip-ransomware-infection/


