SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Jun 14, 2016 • 5min

ISC StormCast for Tuesday, June 14th 2016

Flocker Ransomware Locks TVs http://blog.trendmicro.com/trendlabs-security-intelligence/flocker-ransomware-crosses-smart-tv/ Samsung Updates Software Update Software http://seclists.org/fulldisclosure/2016/Jun/21 Lets Encrypt Messes Up Notification E-mail, Leaks Addresses https://community.letsencrypt.org/t/email-address-disclosures-preliminary-report-june-11-2016/16867 ClamAV Fuzzing Finds Bugs in 7z Unpacking Code https://foxglovesecurity.com/2016/06/13/finding-pearls-fuzzing-clamav/
undefined
Jun 13, 2016 • 5min

ISC StormCast for Monday, June 13th 2016

DNS Sinkhole 2.0 Released https://isc.sans.edu/forums/diary/DNS+Sinkhole+ISO+Version+20/21153/ Visual C Telemetry Library https://www.reddit.com/r/cpp/comments/4ibauu/visual_studio_adding_telemetry_function_calls_to/ Crysis Ransomware http://www.eset.com/us/resources/detail/new-ransomware-threat-crysis-lays-claim-to-teslacrypt-s-former-turf/ Intel Releases ROP Attack Protection http://blogs.intel.com/evangelists/2016/06/09/intel-release-new-technology-specifications-protect-rop-attacks/ EMC Fixes Data Domain Session ID Disclosure Vulnerability https://auscert.org.au/render.html?it=35618
undefined
Jun 10, 2016 • 5min

ISC StormCast for Friday, June 10th 2016

Google Chrome PDF Viewer Remote Code Execution Vulnerability Patched http://blog.talosintel.com/2016/06/pdfium.html Google Continues to Remove SSLv3 Support http://googleappsupdates.blogspot.com.au/2016/06/gradually-disabling-support-for-sslv3.html Vibration Sensor Can Be Used As Microphone http://synrg.csl.illinois.edu/vibraphone/paperdocs/VibraPhone_nirupam.pdf Keypass Fixes Vulnerable Update Procedure http://keepass.info/help/kb/sec_issues.html#updsig
undefined
Jun 9, 2016 • 5min

ISC StormCast for Thursday, June 9th 2016

CryptXXX Switches From Angler to Neutrino EK https://isc.sans.edu/forums/diary/Neutrino+EK+and+CryptXXX/21141/ Android Flah Keyboard Uses Excessive Permissions https://regmedia.co.uk/2016/06/07/pentestflashkeybpardpaper.pdf Firefox 47 Released https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/#firefox47 D-Link Camera Vulnerable To Remote Exploit http://blog.senr.io/blog/home-secure-home BITS used to make malware more persistent https://www.secureworks.com/blog/malware-lingers-with-bits
undefined
Jun 7, 2016 • 6min

ISC StormCast for Wednesday, June 8th 2016

Various Internet Sites Flag Password Reuse http://krebsonsecurity.com/2016/06/password-re-user-get-to-get-busy/ Facebook Chat Vulnerability Patched https://www.helpnetsecurity.com/2016/06/07/facebook-vulnerability-chat-messenger/ DNS Cookies: Making DNS More Security https://www.rfc-editor.org/rfc/rfc7873.txt
undefined
Jun 7, 2016 • 5min

ISC StormCast for Tuesday, June 7th 2016

LinkedIn Data Used to Personalize Malicious E-Mail https://twitter.com/certbund/status/739824856011804676?ref_src=twsrc%5Etfw Android Patches https://source.android.com/security/bulletin/2016-06-01.html Mitsubishi Outlander Wifi Hack https://www.pentestpartners.com/blog/hacking-the-mitsubishi-outlander-phev-hybrid-suv/ Using NTP to Calibrate Time Stamps in PCAP https://isc.sans.edu/forums/diary/What+Time+Is+It+Using+NTP+Traffic+to+Calibrate+PCAP+Timestamps/21135/ BING Adds Malware Warning https://blogs.bing.com/webmaster/June-2016/Warning!-Bing-now-offers-enhanced-malware-warnings
undefined
Jun 5, 2016 • 5min

ISC StormCast for Monday, June 6th 2016

A Recent MySQL Honeypot Compromise https://isc.sans.edu/forums/diary/MySQL+is+YourSQL/21117/ Team Viewer Improves Security http://www.teamviewer.com/en/company/press/teamviewer-launches-trusted-devices-and-data-integrity/ Black Shades Ransomware http://www.bleepingcomputer.com/news/security/black-shades-ransomware-encrypts-your-pc-and-taunts-security-researchers/ NTP Update http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities
undefined
Jun 3, 2016 • 5min

ISC StormCast for Friday, June 3rd 2016

Docker Containers Logging https://isc.sans.edu/forums/diary/Docker+Containers+Logging/21121/ Lenovo Suggests Uninstalling Accelerator Application https://support.lenovo.com/us/en/product_security/len_6718 Google Chrome Update http://googlechromereleases.blogspot.com/search/label/Stable%20updates MongoDB Injection http://blog.securelayer7.net/mongodb-security-injection-attacks-with-php/ Ouch! Newsletter https://securingthehuman.sans.org/resources/newsletters/ouch/2016#encryption Detecting DNS Tunneling With Splunk https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022 Android AV Vulnerabilities https://www.sit.fraunhofer.de/fileadmin/dokumente/Presse/teamsik_advisories_AV.pdf?_=1464692835
undefined
Jun 2, 2016 • 5min

ISC StormCast for Thursday, June 2nd 2016

KeePass Insecure Update https://bogner.sh/2016/03/mitm-attack-against-keepass-2s-update-check/ Possible TeamViewer Breach http://www.theregister.co.uk/2016/06/01/teamviewer_mass_breach_report/ Windows 10 Exploit Offered For Sale https://www.trustwave.com/Resources/SpiderLabs-Blog/Zero-Day-Auction-for-the-Masses/?page=1&year=0&month=0 Intrusion Detection in Depth Minneapolis (July 18-23rd) https://www.sans.org/event/minneapolis-2016/course/intrusion-detection-in-depth
undefined
May 31, 2016 • 6min

ISC StormCast for Wednesday, June 1st 2016

Increase in Telnet Scans https://isc.sans.edu/forums/diary/Increase+in+Port+23+telnet+scanning/21115/ Bloatware Introducing Security Flaws in Laptops https://duo.com/blog/out-of-box-exploitation-a-security-analysis-of-oem-updaters Exploit Released for Unpatchable SCADA Controller https://www.exploit-db.com/exploits/37154/ Fail2Ban Adding IPv6 Support https://www.slightfuture.com/security/fail2ban-ipv6 Critical LG Phone Security Flaws http://blog.checkpoint.com/2016/05/29/oems-have-flaws-too-exposing-two-new-lg-vulnerabilities/

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app