

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jun 28, 2016 • 6min
ISC StormCast for Tuesday, June 28th 2016
Recent Fake DDOS Threats by "Armada Collective"
https://blog.cloudflare.com/empty-ddos-threats-meet-the-armada-collective/
IRS Discontinues e-Filing Pins
https://www.irs.gov/uac/irs-statement-on-the-electronic-filing-pin
CCTV Cameras Still A Major Threat
https://blog.sucuri.net/2016/06/large-cctv-botnet-leveraged-ddos-attacks.html

Jun 27, 2016 • 6min
ISC StormCast for Monday, June 27th 2016
"Bart" Ransomware
https://isc.sans.edu/forums/diary/Bart+a+new+Ransomware/21195/
Swagger Vulnerablity
https://community.rapid7.com/community/infosec/blog/2016/06/23/r7-2016-06-remote-code-execution-via-swagger-parameter-injection-cve-2016-5641
"Enriched" Voter Database Leak
https://mackeeper.com/blog/post/239-another-us-voter-database-leak

Jun 24, 2016 • 5min
ISC StormCast for Friday, June 24th 2016
Uber Vulnerabliity Summary
https://labs.integrity.pt/articles/uber-hacking-how-we-found-out-who-you-are-where-you-are-and-where-you-went/
Apple Intentially Left Kernel Decrypted
https://techcrunch.com/2016/06/22/apple-unencrypted-kernel/
Wordpress Fixes Various Critical Vulnerabilities
https://codex.wordpress.org/Version_4.5.3
Let's Encrypt Reaching 5 Million Issued Certificates
https://letsencrypt.org/2016/06/22/https-progress-june-2016.html
Necurs Botnet is Back
https://www.proofpoint.com/us/threat-insight/post/necurs-botnet-returns-with-updated-locky-ransomware-in-tow

Jun 23, 2016 • 5min
ISC StormCast for Thursday, June 23rd 2016
Deobfuscating Java Code
https://isc.sans.edu/forums/diary/Security+through+obscurity+never+works/21187/
iOS 10 Beta Not Encrypted To Aid Bug Hunters
https://www.technologyreview.com/s/601748/apple-opens-up-iphone-code-in-what-could-be-savvy-strategy-or-security-screwup/
Microsoft Updates SEAL
http://research.microsoft.com/en-us/people/kilai/v2.0-beta.pdf
Cisco Releases Pidgin Vulnerabilities
http://blog.talosintel.com/2016/06/vulnerability-spotlight-pidgin.html
Libarchive vulnerabilities
http://blog.talosintel.com/2016/06/the-poisoned-archives.html

Jun 22, 2016 • 5min
ISC StormCast for Wednesday, June 22nd 2016
Apple Airport (and Time Capsule) Update
https://support.apple.com/en-us/HT201222
StartCom Adding API For Free SSL Certificates
https://support.apple.com/en-us/HT201222
BitCoin Phishing With Typo Squatting Domains
http://blog.cyren.com/articles/2016-Q2_bitcoin-phishing-via-google-adwords.html
Google Attempting to Simplify 2 Factor Authentication
http://googleappsupdates.blogspot.co.uk/2016/06/new-settings-for-2-step-verification.html

Jun 21, 2016 • 5min
ISC StormCast for Tuesday, June 21st 2016
Fake SWIFT Payment Notices Used in Malicious E-Mail Campaign
https://isc.sans.edu/forums/diary/Ongoing+Spam+Campaign+Related+to+Swift/21177/
RedHat Fixes Various OpenSSL Integer Overflows
https://github.com/openssl/openssl/commit/a004e72b95835136d3f1ea90517f706c24c03da7
JavaScript Ransom Ware
http://www.bleepingcomputer.com/news/security/the-new-raa-ransomware-is-created-entirely-using-javascript/
Triada/Horde Mobile Malware Updates
http://blog.checkpoint.com/2016/06/17/in-the-wild-mobile-malware-implements-new-features/

Jun 19, 2016 • 5min
ISC StormCast for Monday, June 20th 2016
Avoiding Javascript Malware
https://isc.sans.edu/forums/diary/Controlling+JavaScript+Malware+Before+it+Runs/21171/
LogMeIn Joining Other Sites in Proactively Resetting Passwords
https://blog.logmeininc.com/password-reuse-issue-affecting-logmein-users/
Kaspersky Publishes Details Around Recent Flash Vulnerability
https://securelist.com/blog/research/75100/operation-daybreak/
CSRF Vulnerability in Democratic Party Donation Platform
http://rajk.me/actblue/#intro

Jun 17, 2016 • 5min
ISC StormCast for Friday, June 17th 2016
Adobe Patches Critiical Flash Vulnerability
https://helpx.adobe.com/security/products/flash-player/apsb16-18.html
Teamviewer Users May be Compromised by Trojaned Client
http://blog.trendmicro.com/trendlabs-security-intelligence/unsupported-teamviewer-versions-exploited-backdoors-keylogging/
Siemens ICS Equipment Transmits Credentials Over the Network
https://ics-cert.us-cert.gov/advisories/ICSA-16-161-02
GitHub Resets User Accounts Compromissed In 3rd Party Incident
https://github.com/blog/2190-github-security-update-reused-password-attack
HTTP Header Injection in Python urllib
http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html

Jun 16, 2016 • 5min
ISC StormCast for Thursday, June 16th 2016
Group Policy Issues After Applying MS16-072 (KB3159398)
https://social.technet.microsoft.com/Forums/en-US/e2ebead9-b30d-4789-a151-5c7783dbbe34/patch-tuesday-kb3159398?forum=winserverGP
Apple Will Reject Apps Using HTTP
https://developer.apple.com/videos/play/wwdc2016/706/
Rising AntiVirus Includes Malware (article only in german)
http://www.heise.de/security/meldung/Virenscanner-infiziert-Systeme-mit-Sality-Virus-3237654.html
SAP Patch
https://erpscan.com/press-center/blog/sap-security-notes-june-2016/
Breached RDP Servers For Rent
https://www.wired.com/2016/06/xdedic-server-trading-forum-kaspersky/

Jun 15, 2016 • 8min
ISC StormCast for Wednesday, June 15th 2016
Microsoft Updates
https://isc.sans.edu/mspatchdays.html?viewday=2016-06-14
Adobe Updates (Incl. active exploitation of Flash Vuln.)
https://helpx.adobe.com/security.html


