SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Sep 8, 2016 • 6min

ISC StormCast for Thursday, September 8th 2016

DShield Blocklist Update https://isc.sans.edu/forums/diary/Updated+DShield+Blocklist/21453/ Fortinet FortiWAN Load Balancer Mulitple Unpatched Vulnerabilities http://www.kb.cert.org/vuls/id/724487 Rapid7 Published NSM Vulnerabilities http://www.theregister.co.uk/2016/09/07/natwork_magement_vulns/ OPM Breached by Two Different Attackers https://oversight.house.gov/wp-content/uploads/2016/09/The-OPM-Data-Breach-How-the-Government-Jeopardized-Our-National-Security-for-More-than-a-Generation.pdf
undefined
Sep 6, 2016 • 6min

ISC StormCast for Wednesday, September 7th 2016

Google September Android Security Update https://source.android.com/security/bulletin/2016-09-01.html Hard Coded Password / Key Issue Gets Worse http://blog.sec-consult.com/2016/09/house-of-keys-9-months-later-40-worse.html Snagging Credentials From Locked Machines (Windows and OS X) https://room362.com/post/2016/snagging-creds-from-locked-machines/
undefined
Sep 6, 2016 • 5min

ISC StormCast for Tuesday, September 6th 2016

Apple Patches OS X and Safari for Trident/Pegasus Vulnerabilities https://support.apple.com/en-us/HT201222 Malware Delivered via ".pub" Files https://isc.sans.edu/forums/diary/Malware+Delivered+via+pub+Files/21443/ Sophos Anti Virus False Positive Causes Blue Screen of Death https://community.sophos.com/kb/en-us/125000 Adobe Reviving Flash for Linux https://blogs.adobe.com/flashplayer/2016/08/beta-news-flash-player-npapi-for-linux.html Google Patches Nexuse 5X Vulnerability https://securityintelligence.com/undocumented-patched-vulnerability-in-nexus-5x-allowed-for-memory-dumping-via-usb/
undefined
Sep 1, 2016 • 5min

ISC StormCast for Friday, September 2nd 2016

Malware Using Maxmind For Geolocation https://isc.sans.edu/forums/diary/Maxmindcom+Abused+As+AntiAnalysis+Technique/21435/ Content Security Policy of Limited Use in Real World https://research.google.com/pubs/pub45542.html CryptWare Bitlocker Enhancement Vulnerability https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20160831-0_CryptWare_CryptoPro_Manipulation_of_pre-boot_authentication_v10.txt Google Releases Chrome 53 http://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
undefined
Sep 1, 2016 • 5min

ISC StormCast for Thursday, September 1st 2016

Abobe ColdFusion Update https://helpx.adobe.com/security/products/coldfusion/apsb16-30.html OS X Bittorrent Client Transmission Backdoored http://www.welivesecurity.com/2016/08/30/osxkeydnap-spreads-via-signed-transmission-application/ Arrested Lurk Hacking Group Likely Developed Angler Exploit Kit https://securelist.com/analysis/publications/75944/the-hunt-for-lurk/ Vulnerable REDIS Instances Used by Fake Ransomware https://duo.com/blog/over-18-000-redis-instances-targeted-by-fake-ransomware
undefined
Aug 31, 2016 • 5min

ISC StormCast for Wednesday, August 31st 2016

Today's Locky Variant Arrives as a Windows Script File https://isc.sans.edu/forums/diary/Todays+Locky+Variant+Arrives+as+a+Windows+Script+File/21423/ OneLogin Breached and Secure Notes Lost https://www.onelogin.com/blog/august-2016-incident USB Memory Stick Can Be Used to Exfiltrate Data Wireless http://cyber.bgu.ac.il/t/USBee.pdf Jail Break App in Apple's App Store https://www.reddit.com/r/jailbreak/comments/506eyp/release_ppjailbreak_on_the_appstore/
undefined
Aug 30, 2016 • 6min

ISC StormCast for Tuesday, August 30th 2016

CA WoSign Law Validation Policy https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/k9PBmyLCi8I FBI Warns Of Vulnerabilities in State Election Websites https://www.scribd.com/document/322473050/FBI-Flash-Aug-2016#from_embed Bug in "Keeper" Password Safe Allows Attackers to Steal Passwords https://bugs.chromium.org/p/project-zero/issues/detail?id=917 Bank ATMs Compromised via Malicious EMV Chip https://www.fireeye.com/blog/threat-research/2016/08/ripper_atm_malwarea.html
undefined
Aug 29, 2016 • 6min

ISC StormCast for Monday, August 29th 2016

Spam with Obfuscated Javascript https://isc.sans.edu/forums/diary/Spam+with+Obfuscated+Javascript/21415/ Another Day - Another Ransomware Sample https://isc.sans.edu/forums/diary/Another+Day+Another+Ransomware+Sample/21413/ OpenSSL Update https://www.openssl.org/news/openssl-1.1.0-notes.html Opera Sync Server Breached https://www.opera.com/blogs/security/2016/08/opera-server-breach-incident/ Fake Windows Update Delivers Ransomware http://www.bleepingcomputer.com/news/security/fantom-ransomware-encrypts-your-files-while-pretending-to-be-windows-update/ Dropbox Resets Old Passwords After Data Leak https://www.dropbox.com/help/9257?oref=e
undefined
Aug 25, 2016 • 6min

ISC StormCast for Friday, August 26th 2016

Out-of-Band iOS Patch Fixes 0-Day Vulnerabilities https://isc.sans.edu/forums/diary/OutofBand+iOS+Patch+Fixes+0Day+Vulnerabilities/21409/ Malicious E-Mail Installs Proxy File to Redirect Requests to santander.com.br https://isc.sans.edu/forums/diary/OutofBand+iOS+Patch+Fixes+0Day+Vulnerabilities/21409/ Nginx DNS Resolver Issue (Windows Only) http://blog.zorinaq.com/nginx-resolver-vulns/ Wifi Signals Can Be Used for Keystroke Sniffing https://www.sigmobile.org/mobicom/2015/papers/p90-aliA.pdf
undefined
Aug 24, 2016 • 6min

ISC StormCast for Thursday, August 25th 2016

Juniper/Cisco Updates Regarding #NSA Exploits https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10605&actp=search http://arstechnica.com/security/2016/08/nsa-linked-cisco-exploit-poses-bigger-threat-than-previously-thought/ Wildfire Ransomware Takedown and Key Recovery https://blogs.mcafee.com/mcafee-labs/wildfire-ransomware-extinguished-tool-nomoreransom-unlock-files-free/ "Sandscout" tool to exploit iOS Sandbox Vulnerabilities http://www.maclife.de/news/sandscout-forscher-tu-darmstadt-finden-sicherheitsluecken-ios-sandbox-10081401.html (sorry, only in German) Sweet32 Birthday Attack against 3DES and Blowfish (https/openvpn) http://www.maclife.de/news/sandscout-forscher-tu-darmstadt-finden-sicherheitsluecken-ios-sandbox-10081401.html

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app