

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Nov 7, 2022 • 6min
ISC StormCast for Monday, November 7th, 2022
Remcos Downloader With Unicode Obfuscation
https://isc.sans.edu/diary/Remcos%20Downloader%20with%20Unicode%20Obfuscation/29220
Windows Malware With VHD Extension
https://isc.sans.edu/diary/Windows%20Malware%20with%20VHD%20Extension/29222
PyPi Packages Attempting to Deliver w4sp Stealer
https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack

Nov 4, 2022 • 7min
ISC StormCast for Friday, November 4th, 2022
Breakpoints in Burp
https://isc.sans.edu/forums/diary/Breakpoints%20in%20Burp/29214/
TA569 Supply Chain Attack Injects JavaScript
https://twitter.com/threatinsight/status/1587865920130752515
https://www.darkreading.com/application-security/supply-chain-attack-pushes-out-malware-to-more-than-250-media-websites
Link to old story similar to the above JavaScript injection
https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/
Hitachi Infrastructure Analytics Advisor
https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2022-134/index.html
FortiNet Patches
https://fortiguard.fortinet.com/psirt?date=11-2022
Nessus Patches
https://www.tenable.com/security/tns-2022-24

Nov 3, 2022 • 6min
ISC StormCast for Thursday, November 3rd, 2022
Who Put the "Dark" in DarkVNC?
https://isc.sans.edu/forums/diary/Who+put+the+Dark+in+DarkVNC/29210
sigstore General Availability
https://openssf.org/press-release/2022/10/25/sigstore-announces-general-availability-at-sigstorecon/
https://github.blog/2022-10-25-why-were-excited-about-the-sigstore-general-availability/
URLScan.io's SOAR Spot: Chatty Security Tools Leaking Private Data
https://positive.security/blog/urlscan-data-leaks
Checkmk: Remote Code Execution by Chaining Multiple Bugs
https://blog.sonarsource.com/checkmk-rce-chain-1/

Nov 2, 2022 • 8min
ISC StormCast for Wednesday, November 2nd, 2022
OpenSSL 3.0 Punycode Vulnerability Fix
https://isc.sans.edu/forums/diary/Critical+OpenSSL+30+Update+Released+Patches+CVE20223786+CVE20223602/29208
https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/

Nov 1, 2022 • 6min
ISC StormCast for Tuesday, November 1st, 2022
NMAP without NMAP - Port Testing and Scanning with PowerShell
https://isc.sans.edu/diary/NMAP+without+NMAP+Port+Testing+and+Scanning+with+PowerShell/29202
ConnectWise Recover and R1Soft Server Backup Critical Vulnerability
https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin
Google Chrome 0-Day Patch
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html
LODEINFO 2022 Abusing Security Software
https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
Spring Security Vulnerability
https://tanzu.vmware.com/security/cve-2022-31692

Oct 31, 2022 • 6min
ISC StormCast for Monday, October 31st, 2022
Supersizing you DUO and 365 Integration
https://isc.sans.edu/forums/diary/Supersizing%20your%20DUO%20and%20365%20Integration/29194/
TCP/IP Vulnerability CVE-2022 34718 PoC Restoration and Analysis
https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf
Juniper SSLVON / JunOS RCE Vulnerabilities
https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/
Raspberry Robin Update
https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/

Oct 28, 2022 • 6min
ISC StormCast for Friday, October 28th, 2022
Upcoming Critical OpenSSL Vulnerability: What will be Affected?
https://isc.sans.edu/forums/diary/Upcoming+Critical+OpenSSL+Vulnerability+What+will+be+Affected/29192
Apple Updates
https://support.apple.com/en-us/HT201222
Fodcha Botnet Reaches 1Tbps
https://blog.netlab.360.com/ddosmonster_the_return_of__fodcha_cn/
https://www.bleepingcomputer.com/news/security/fodcha-ddos-botnet-reaches-1tbps-in-power-injects-ransoms-in-packets/

Oct 27, 2022 • 6min
ISC StormCast for Thursday, October 27th, 2022
Why is My Cat Using Baidu And Other IoT DNS Oddities
https://isc.sans.edu/forums/diary/Why+is+My+Cat+Using+Baidu+And+Other+IoT+DNS+Oddities/29188
OpenSSL Critical Flaw to Be Patched
https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html
MacOS Ventura Blocks Security Tools
https://www.wired.com/story/apple-macos-ventura-bug-security-tools/
Critical VMWare Security Tools
https://www.vmware.com/security/advisories/VMSA-2022-0027.html

Oct 26, 2022 • 6min
ISC StormCast for Wednesday, October 26th, 2022
Massing Cryptomining Operation via Github Actions
https://sysdig.com/blog/massive-cryptomining-operation-github-actions/
Daixin Team Ransomware Targeting Healthcare Providers
https://www.ic3.gov/Media/News/2022/221021.pdf
Cisco Anyconnect Client Exploited in the Wild
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj
SQLite Vulnerability Details
https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/

Oct 25, 2022 • 6min
ISC StormCast for Tuesday, October 25th, 2022
C2 Communications Through Outlook.com
https://isc.sans.edu/forums/diary/C2+Communications+Through+outlookcom/29180
Apple Patches Everything October 2022 Edition
https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything%3A%20October%202022%20Edition/29182/
Cisco ISE Patch
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM
Dormant Colors Live Campaign With Over 1m Data Stealing Extensions Installed
https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849


