

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Aug 11, 2022 • 6min
ISC StormCast for Thursday, August 11th, 2022
And Here They Come Again: DNS Reflection Attacks
https://isc.sans.edu/diary/And+Here+They+Come+Again%3A+DNS+Reflection+Attacks/28928
Rapid 7 Defaultinator
https://defaultinator.com
Zimbra Mass Compromise
https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/
VMWare vRealize Vulnerability
https://www.vmware.com/security/advisories/VMSA-2022-0022.html
Microsoft Vulnerability and IPS/Snort
https://community.meraki.com/t5/Meraki-Service-Notices/Microsoft-vulnerability-and-IPS-SNORT/ba-p/156649

Aug 10, 2022 • 6min
ISC StormCast for Wednesday, August 10th, 2022
Microsoft August 2022 Patch Tuesday
https://isc.sans.edu/diary/Microsoft+August+2022+Patch+Tuesday/28924
AEPIC Leak
https://aepicleak.com
Adobe security bulletins
https://helpx.adobe.com/security/security-bulletin.html

Aug 9, 2022 • 6min
ISC StormCast for Tuesday, August 9th, 2022
JSON All the Logs!
https://isc.sans.edu/diary/JSON+All+the+Logs%21/28920
Microsoft Edge Enhanced Security
https://docs.microsoft.com/en-us/deployedge/microsoft-edge-security-browse-safer
Malicious Python Packages
https://www.darkreading.com/application-security/10-malicious-packages-slither-pypi-registry
New Orchard Botnet
https://blog.netlab.360.com/a-new-botnet-orchard-generates-dga-domains-with-bitcoin-transaction-information/

Aug 8, 2022 • 6min
ISC StormCast for Monday, August 8th, 2022
Exim Vulnerability Silently Patched
https://github.com/ivd38/exim_overflow
DuckDuckGo Stopping Microsoft Tracking Code
https://spreadprivacy.com/more-privacy-and-transparency/
Emergency Broadcast Messaging System Vulnerabilities
https://content.govdelivery.com/accounts/USDHSFEMA/bulletins/3263326
Slack Leaks Hashed Passwords
https://slack.com/intl/en-in/blog/news/notice-about-slack-password-resets
Zimbra Flaw Exploited
https://nvd.nist.gov/vuln/detail/CVE-2022-27924

Aug 5, 2022 • 7min
ISC StormCast for Friday, August 5th, 2022
TLP 2.0 is Here
https://isc.sans.edu/diary/TLP+2.0+is+here/28914
Hijacking email with Cloudflare Email Routing
https://albertpedersen.com/blog/hijacking-email-with-cloudflare-email-routing/
rsync arbitrary file write vulnerablity
https://www.openwall.com/lists/oss-security/2022/08/02/1
Local privilege escalation in Kaspersky VPN
https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/

Aug 4, 2022 • 7min
ISC StormCast for Thursday, August 4th, 2022
l9explore and LeakIX Internet Wide Recon Scans
https://isc.sans.edu/diary/l9explore+and+LeakIX+Internet+wide+recon+scans./28910
Arris / Arris Variant DSL/Fiber Router Critical Vulnerability
http://derekabdine.com/blog/2022-arris-advisory
35,000 Malicious Repo Forks Flood GitHub
https://www.bleepingcomputer.com/news/security/35-000-code-repos-not-hacked-but-clones-flood-github-to-serve-malware/
Palo Alto Master Key
https://twitter.com/rqu50/status/1554566757704089600#m
Laravel Unserialize RCE
https://github.com/beicheng-maker/vulns/issues/1
Unuathenticated Remote Code Execution in DrayTek Vigor Routers
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/rce-in-dratyek-routers.html

Aug 3, 2022 • 6min
ISC StormCast for Wednesday, August 3rd, 2022
Increase in Chinese "Hacktivism" Attacks
https://isc.sans.edu/diary/Increase+in+Chinese+%22Hacktivism%22+Attacks/28906
Zoho Password Manager Exploit
https://xz.aliyun.com/t/11578
VMWare Updates
https://www.vmware.com/security/advisories/VMSA-2022-0021.html
https://twitter.com/VietPetrus
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html

Aug 2, 2022 • 7min
ISC StormCast for Tuesday, August 2nd, 2022
A Little DDoS in the Morning
https://isc.sans.edu/diary/A+Little+DDoS+In+the+Morning/28900
Exposed Twitter API Keys
https://cloudsek.com/whitepapers_reports/how-leaked-twitter-api-keys-can-be-used-to-build-a-bot-army/
TCL LinkHub Serialization Issues
https://blog.talosintelligence.com/2022/08/vulnerability-spotlight-how-misusing.html
Jenkins Plugin Updates
https://www.jenkins.io/security/advisory/2022-07-27/

Aug 1, 2022 • 9min
ISC StormCast for Monday, August 1st, 2022
PDF Analysis Introduction and OpenActions Entries
https://isc.sans.edu/diary/PDF+Analysis+Intro+and+OpenActions+Entries/28894
IPFS The New Hotbed of Phishing
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/ipfs-the-new-hotbed-of-phishing/
Mail Stealing Browser Extension
https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/
Lofylife Malicious NPM Packages
https://securelist.com/lofylife-malicious-npm-packages/107014/
IP Camera Vulnerability
https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/
Nuki Smart Lock Vulnerabilities
https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/
Foxit PDF Reader
https://www.foxit.com/support/security-bulletins.html

Jul 29, 2022 • 7min
ISC StormCast for Friday, July 29th, 2022
Exfiltrating Data with Bookmarks
https://isc.sans.edu/diary/Exfiltrating+Data+With+Bookmarks/28890
Critical Samba Bug Could Let Anyone Become Domain Admin
https://nakedsecurity.sophos.com/2022/07/27/critical-samba-bug-could-let-anyone-become-domain-admin-patch-now/
Apple IP Address Range Hijacked by Rostelecom
https://www.manrs.org/2022/07/for-12-hours-was-part-of-apple-engineerings-network-hijacked-by-russias-rostelecom/
Veritas Patches
https://www.veritas.com/content/support/en_US/security/VTS22-004#c1
IBM Patches
https://www.ibm.com/support/pages/node/6606251
https://www.ibm.com/support/pages/node/6607135


