

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Apr 29, 2022 • 6min
ISC StormCast for Friday, April 29th, 2022
A Day of SMB: What does our SMB/RPC Honeypot see? CVE-2022-26809
https://isc.sans.edu/forums/diary/A+Day+of+SMB+What+does+our+SMBRPC+Honeypot+see+CVE202226809/28594/
Azure PostgreSQL Privilege Escalation
https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/
Security alert: Attack campaign involving stolen OAuth user tokens
https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens
Netatalk Vulnerability Affecting Synology, QNAP, Others?
https://www.synology.com/en-global/security/advisory/Synology_SA_22_06

Apr 28, 2022 • 6min
ISC StormCast for Thursday, April 28th, 2022
MITRE ATT&CK v11
https://isc.sans.edu/forums/diary/MITRE+ATTCK+v11+a+small+update+that+can+help+not+just+with+detection+engineering/28590/
Microsoft Special Report: Ukraine
https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Vwwd
Linux Privilege Escalation Nimbuspwn
https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/
npm Package Planting
https://blog.aquasec.com/npm-package-planting

Apr 27, 2022 • 6min
ISC StormCast for Wednesday, April 27th, 2022
WSO2 Vuln Exploited to Install Crypto Coin Miners
https://isc.sans.edu/forums/diary/WSO2+RCE+exploited+in+the+wild/28586/
Core Impact Backdoor Delivered Via VMware Vulnerablity
https://blog.morphisec.com/vmware-identity-manager-attack-backdoor
VirusTotal Exploit Update
https://twitter.com/bquintero/status/1518738072820670464
Emotet Experimenting With New Delivery Techniques
https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques

Apr 26, 2022 • 6min
ISC StormCast for Tuesday, April 26th, 2022
Simple PDF Linking to Malicious Content
https://isc.sans.edu/forums/diary/Simple+PDF+Linking+to+Malicious+Content/28582/
VirusTotal Remote Code Execution
https://www.cysrc.com/blog/virus-total-blog
Apple's Private Relay can Cause the System to Ignore Firewall Rules
https://mullvad.net/en/blog/2022/4/25/apples-private-relay-can-cause-the-system-to-ignore-firewall-rules/
Emotet Breaks and Later Fixes Installer
https://www.bleepingcomputer.com/news/security/emotet-malware-infects-users-again-after-fixing-broken-installer/

Apr 25, 2022 • 5min
ISC StormCast for Monday, April 25th, 2022
Analyzing Word Phishing Document
https://isc.sans.edu/forums/diary/Analyzing+a+Phishing+Word+Document/28562/
Targeting Roku Streaming Devices
https://isc.sans.edu/forums/diary/Are+Roku+Streaming+Devices+Safe+from+Exploitation/28578/
JWT Null Signature Vulnerability PoC
https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/jwt-null-signature-vulnerable-app
Expat XML Vulnerabilities
https://www.ibm.com/support/pages/node/6573293
Jira Vulnerability
https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html

Apr 22, 2022 • 6min
ISC StormCast for Friday, April 22nd, 2022
Multi Cryptocurrency Clipboard Swapper
https://isc.sans.edu/forums/diary/MultiCryptocurrency+Clipboard+Swapper/28574/
Amazong Fixes AWS log4j Fix
https://aws.amazon.com/security/security-bulletins/AWS-2022-006/
Cisco Fixes
https://tools.cisco.com/security/center/publicationListing.x
Psychic Signature PoC
https://github.com/khalednassar/CVE-2022-21449-TLS-PoC
ALAC Audio Decoder Bug
https://blog.checkpoint.com/2022/04/21/largest-mobile-chipset-manufacturers-used-vulnerable-audio-decoder-2-3-of-android-users-privacy-around-the-world-were-at-risk/

Apr 21, 2022 • 6min
ISC StormCast for Thursday, April 21st, 2022
AA Distribution Quakbot (Qbot) infection siwth DarkVNC
https://isc.sans.edu/forums/diary/aa+distribution+Qakbot+Qbot+infection+with+DarkVNC+traffic/28568/
Java Psychic Signatures
https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/
Snort DoS Vulnerability
https://claroty.com/2022/04/14/blog-research-blinding-snort-breaking-the-modbus-ot-preprocessor/

Apr 20, 2022 • 6min
ISC StormCast for Wednesday, April 20th, 2022
u-boot Password Reset
https://isc.sans.edu/forums/diary/Resetting+Linux+Passwords+with+UBoot+Bootloaders/28564/
Oracle CPU
https://www.oracle.com/security-alerts/cpuapr2022.html
MetaMask iCloud Phishing
https://www.bleepingcomputer.com/news/security/hackers-steal-655k-after-picking-metamask-seed-from-icloud-backup/
SMB1 Gone From Windows 11 Home
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb1-now-disabled-by-default-for-windows-11-home-insiders-builds/ba-p/3289473
Lenovo UEFI/BIOS Vulnerability
https://support.lenovo.com/us/en/product_security/ps500483-lenovo-system-update-privilege-escalation-vulnerability
https://support.lenovo.com/de/de/product_security/LEN-84943

Apr 19, 2022 • 5min
ISC StormCast for Tuesday, April 19th, 2022
Sysmon's ReigstryEvent (Value Set) and Binary Data
https://isc.sans.edu/forums/diary/Sysmons+RegistryEvent+Value+Set/28558/
Ukraine CERT Posts: IcedID and Zimbra Flaw
https://cert.gov.ua/article/39606
https://cert.gov.ua/article/39609
New NSO Pegasus Exploit Spotted in the Wild
https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/
Unofficial Windows 11 Upgrade Delivers Spyware
https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/

Apr 18, 2022 • 6min
ISC StormCast for Monday, April 18th, 2022
Office Now Protects You From Malicious ISO Files
https://isc.sans.edu/forums/diary/Office+Protects+You+From+Malicious+ISO+Files/28554/
Github Stolen OAUTH User Tokens
https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/
Git For Windows Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-24765
Cisco Wireless Controller Bug
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-auth-bypass-JRNhV4fF


