

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Nov 3, 2016 • 6min
ISC StormCast for Thursday, November 3rd 2016
Exchange Web Service Two-Factor Authentication Bypass
http://www.blackhillsinfosec.com/?p=5396
Barracuda DoS Disrupts Mail Delivery
http://status.barracuda.com
Targobank Looses Account Data After Maintenance
http://www.spiegel.de/wirtschaft/service/targobank-kunden-fehlt-geld-auf-dem-konto-it-probleme-a-1119434.html (german only)
Ouch! Security Awareness Newsletter
http://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201611_en.pdf

Nov 2, 2016 • 6min
ISC StormCast for Wednesday, November 2nd 2016
Malvertising On Google AdWords Targeting macOS Users
http://blog.cylance.com/malvertising-on-google-adwords-targeting-macos-users
Microsoft Response to Google Privilege Escalation Disclosure
https://blogs.technet.microsoft.com/mmpc/2016/11/01/our-commitment-to-our-customers-security/
Memcached Remote Code Execution Vulnerabilities
http://blog.talosintel.com/2016/10/memcached-vulnerabilities.html
SAP Vulnerability Details Released
https://erpscan.com/press-center/blog/0-day-sap-vulnerability-published-heres-can/

Nov 1, 2016 • 6min
ISC StormCast for Tuesday, November 1st 2016
snapshot.ps1 DFIR Capture
https://isc.sans.edu/forums/diary/SEC505+DFIR+capture+script+snapshotps1/21659/
Predicting Domain Reputation
http://www.icir.org/vern/papers/predator-ccs16.pdf
Mozilla Removing Battery Status API For Privacy Reasons
https://www.fxsitecompat.com/en-CA/docs/2016/battery-status-api-has-been-removed/
Windows Privilege Escalation 0-day Actively Exploited
https://security.googleblog.com/2016/10/disclosing-vulnerabilities-to-protect.html

Oct 31, 2016 • 7min
ISC StormCast for Monday, October 31st 2016
Volatility Bot: Automated Memory Analysis
https://isc.sans.edu/forums/diary/Volatility+Bot+Automated+Memory+Analysis/21655/
911 System Fragility Exposed in Accidental DoS Attacks
https://staging.mcso.org/Multimedia/PressRelease/911%20Cyber%20Attack.pdf
Vulnerability in Mirai Botnet
https://www.invincealabs.com/blog/2016/10/killing-mirai/
XNU Kernel (iOS/macOS) task_t Privildge Escalation
https://googleprojectzero.blogspot.de/2016/10/taskt-considered-harmful.html

Oct 27, 2016 • 7min
ISC StormCast for Friday, October 28th 2016
Small Changes to Ransomware E-Mails May Fool Some Mail Filters
https://isc.sans.edu/forums/diary/Your+Bill+Is+Not+Overdue+today/21647/
Microsoft / Google Release Browser Updates to Address Flash Vulnerablity
https://technet.microsoft.com/en-us/library/security/ms16-128.aspx
https://googlechromereleases.blogspot.com
Social Media "Support" Phishing
https://www.proofpoint.com/us/corporate-blog/post/cybercriminals-spoof-every-major-bank-masquerade-branded-customer-service-twitter-accounts
Path Traversal Vulnerablity in gnu tar
https://sintonen.fi/advisories/tar-extract-pathname-bypass.proper.txt
Podcast Survey
https://dshield.typeform.com/to/lVgHr5

Oct 26, 2016 • 6min
ISC StormCast for Thursday, October 27th 2016
Adobe Releases Emergency Patch For Flash
https://isc.sans.edu/forums/diary/Critical+Flash+Player+Update+APSB1636/21643/
Mobile Pwn2Own Writeup
http://blog.trendmicro.com/results-mobile-pwn2own-2016/
Mozilla Will Stick With Blacklisting Startcom/WoSign
https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/
Joomla Exploit Released
https://medium.com/@showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.b8gks1jar
Google Spreadsheet Vulnerability
https://www.rodneybeede.com/Google_Spreadsheet_Vuln_-_CSRF_and_JSON_Hijacking_allows_data_theft.html

Oct 26, 2016 • 5min
ISC StormCast for Wednesday, October 26th 2016
Joomla Fixes Two Critical Vulnerablities;
https://www.joomla.org/announcements/release-news/5678-joomla-3-6-4-released.html
Letsencrypt Domain Verification Problem
https://dan.enigmabridge.com/lets-encrypts-vulnerability-as-a-feature-authz-reuse-and-eternal-account-key/
New Locky Variants: Pumpkin Locky
http://blog.talosintel.com/2016/10/pumpkin-locky.html
Pagers still in use for Critical Infrastructure
http://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/industrial-plant-beepers-leaking-secrets

Oct 25, 2016 • 7min
ISC StormCast for Tuesday, October 25th 2016
Updates For iOS, MacOS, Safari
https://support.apple.com/en-us/HT201222
LTE Intercept Vulnerability
http://www.theregister.co.uk/2016/10/23/every_lte_call_text_can_be_intercepted_blacked_out_hacker_finds/
Rowhammer Exploit Demonstrated Against Android
https://www.vusec.net/projects/drammer/

Oct 23, 2016 • 7min
ISC StormCast for Monday, October 24th 2016
ISC Briefing: Large DDoS Attack Against Dyn
https://isc.sans.edu/forums/diary/ISC+Briefing+Large+DDoS+Attack+Against+Dyn/21627/
TCP Port 4786: Cisco Memory Leak Vulnerability
https://isc.sans.edu/forums/diary/Request+for+Packets+TCP+4786+CVE20166385/21625/
Dirty Cow PoC Exploits Available
https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs
To register for today's SANS Technology Institute's Professional Lecture Series, pleaes e-mail info@sans.edu

Oct 20, 2016 • 6min
ISC StormCast for Friday, October 21st 2016
NanoCore RAT Malspam Update
https://isc.sans.edu/forums/diary/Malspam+delivers+NanoCore+RAT/21615/
Dirty Cow Privilege Escalation Flaw
https://bugzilla.redhat.com/show_bug.cgi?id=1384344#c13
Lexmark Markvision Enterprise Application Vulnerability
https://www.digitaldefense.com/blog-zero-day-lexmark-markvision/
WebRTC Security Overview
https://webrtc-security.github.io
UPnP Scanner
https://www.tenable.com/blog/do-you-know-where-your-upnp-is


