

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Nov 28, 2022 • 7min
ISC StormCast for Monday, November 28th, 2022
Log4Shell campaigns are using Nashorn to get reverse shell on victim's machines
https://isc.sans.edu/diary/Log4Shell%20campaigns%20are%20using%20Nashorn%20to%20get%20reverse%20shell%20on%20victim%27s%20machines/29266
Attackers Keep Phishing Victms Under Stress
https://isc.sans.edu/diary/Attackers%20Keep%20Phishing%20Victims%20Under%20Stress/29270
Vulnerable SDK components lead to supply chian risks in IoT and OT environments
https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/
Google Chrome Patches 0-Day
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
Hacking Smartwatches for Spear Phishing
https://cybervelia.com/?p=1380

Nov 18, 2022 • 14min
ISC StormCast for Friday, November 18th, 2022
Lessons Learned from Automatic Failover
https://isc.sans.edu/diary/Lessons%20Learned%20from%20Automatic%20Failover%3A%20When%208.8.8.8%20%22disappears%22.%20IPv6%20to%20the%20Rescue%3F/29260
Bitbucket Server and Data Center Vulnerability
https://jira.atlassian.com/browse/BSERV-13522
Amazon RDS Snapshot Leaks
https://www.mitiga.io/blog/how-mitiga-found-pii-in-exposed-amazon-rds-snapshots
Adobe Commerce merchants to be hit with TrojanOrders this season
https://sansec.io/research/trojanorder-magento
SANS EDU Research: Detecting and Mitigating the GateKeeper User Override on macOS in an Enterprise Environment; Antonio Piazza
https://www.sans.edu/cyber-research/detecting-and-mitigating-the-gatekeeper-user-override-on-macos-in-an-enterprise-environment/

Nov 17, 2022 • 7min
ISC StormCast for Thursday, November 17th, 2022
Evil Maid Attacks - Remediation for the Cheap
https://isc.sans.edu/diary/Evil%20Maid%20Attacks%20-%20Remediation%20for%20the%20Cheap/29256
F5 Big IP CVE-2022-41622 and CVE-2022-41800 Vulnerability Details
https://www.rapid7.com/blog/post/2022/11/16/cve-2022-41622-and-cve-2022-41800-fixed-f5-big-ip-and-icontrol-rest-vulnerabilities-and-exposures/
Details about iPad/iOS Neural Engine Vulnerability CVE-2022-32899
https://github.com/0x36/weightBufs/
Disneyland Malware Team: It's a Puny World After All
https://krebsonsecurity.com/2022/11/disneyland-malware-team-its-a-puny-world-after-all/#more-61870

Nov 16, 2022 • 5min
ISC StormCast for Wednesday, November 16th, 2022
Packet Tuesday
https://packettuesday.com
Stealing Passwords From Infosec Mastodon - Without Bypassing CSP
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
SQLi and Access Flaws in Zendesk
https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws
Electric Vehicle Charging Infrastructure
https://newsreleases.sandia.gov/ev_security/

Nov 15, 2022 • 5min
ISC StormCast for Tuesday, November 15th, 2022
Extracting "HTTP CONNECT" Requests with Python
https://isc.sans.edu/diary/Extracting%20%27HTTP%20CONNECT%27%20Requests%20with%20Python/29246
Windows Kerberos Authentication Breaks After November Updates
https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-after-november-updates/
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22h2#2953msgdesc
Cookies for MFA Bypass Gain Traction Among Cyberattackers
https://www.darkreading.com/threat-intelligence/cookies-mfa-bypass-cyberattackers

Nov 14, 2022 • 6min
ISC StormCast for Monday, November 14th, 2022
Extracting Information From "logfmt" Files with CyberChef
https://isc.sans.edu/diary/Extracting%20Information%20From%20%22logfmt%22%20Files%20With%20CyberChef/29244
Soccer Worldcup Risks
https://www.theregister.com/2022/11/11/world_cup_security/
https://www.welivesecurity.com/2022/11/11/fifa-world-cup-2022-scams-fake-lotteries-ticket-fraud/
Mysterious Company With Government Ties Plays Key Internet Role
https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/
Extortion Scams Hit Website Owners
https://www.bleepingcomputer.com/news/security/new-extortion-scam-threatens-to-damage-sites-reputation-leak-data/

Nov 11, 2022 • 7min
ISC StormCast for Friday, November 11th, 2022
Do you collect "Observables" or "IOCs"
https://isc.sans.edu/diary/Do%20you%20collect%20%22Observables%22%20or%20%22IOCs%22%3F/29238
Android Update fixes Lock Screen Bypass
https://source.android.com/docs/security/bulletin/2022-11-01
https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/
libxml Vulnerability Details
https://gitlab.gnome.org/GNOME/libxml2/-/issues/381
CVE-2022-45063: xterm remote code execution vulnerability
https://www.openwall.com/lists/oss-security/2022/11/10/1

Nov 10, 2022 • 5min
ISC StormCast for Thursday, November 10th, 2022
Another Script-Based Ransomware
https://isc.sans.edu/diary/Another%20Script-Based%20Ransomware/29234
Apple Security Updates
https://support.apple.com/en-us/HT201222
Lenovo UEFI Patch
https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/
FoxIT Update
https://www.foxit.com/support/security-bulletins.html
SAP Update
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10

Nov 9, 2022 • 7min
ISC StormCast for Wednesday, November 9th, 2022
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20November%202022%20Patch%20Tuesday/29230
VMWare Workspace One Updates CVE-2022-31686, CVE-2022-31687, CVE-2022-31688
https://www.vmware.com/security/advisories/VMSA-2022-0028.html
Citrix Gateway / Citrix ADC Vulnerabilities CVE-2022-27510
https://support.citrix.com/article/CTX463706/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516
Microsoft Exchange Updates
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045

Nov 8, 2022 • 6min
ISC StormCast for Tuesday, November 8th, 2022
IPv4 Address Representations
https://isc.sans.edu/diary/IPv4%20Address%20Representations/29224
Azure AD Certificate-based Authentication (CBA) on Mobile
https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/azure-ad-certificate-based-authentication-cba-on-mobile/ba-p/2365672
Twitter Scams
https://nakedsecurity.sophos.com/2022/11/04/twitter-blue-badge-email-scams-dont-fall-for-them/
Facebook Personal Information Removal
https://www.facebook.com/contacts/removal
RSA Conference Finds Unencrypted Confidential Data in WiFi Traffic
https://www.darkreading.com/remote-workforce/unencrypted-traffic-weak-e-mail-passwords-still-undermining-wifi-security


