A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

In Machines We Trust

In Machines We Trust
A podcast about the automation of everything. Host Jennifer Strong and the team at MIT Technology Review look at what it means to entrust artificial intelligence with our most sensitive decisions.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

ISC StormCast for Wednesday, October 28th 2020

October 27, 2020 5:19 4.48 MB Downloads: 0

Vulnerable SonarQube Configurations Used to Steal Code https://beta.documentcloud.org/documents/20399900-fbi_flash_sonarqube_access_bc Microsoft Edge Security Updates (Chromium-Based) https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200002 Microsoft Releases Flash Removal Tool https://support.microsoft.com/en-us/help/4577586/update-for-removal-of-adobe-flash-player Bypassing MSFT Teams Policies https://o365blog.com/post/teams-policies/

ISC StormCast for Tuesday, October 27th 2020

October 26, 2020 6:09 5.17 MB Downloads: 0

Excel 4 Macros: "Abnormal Sheet Visibility" https://isc.sans.edu/forums/diary/Excel+4+Macros+Abnormal+Sheet+Visibility/26726/ HP Printer Applications Certificate Revoked https://eclecticlight.co/2020/10/23/why-have-my-hp-printers-stopped-working-how-to-check-their-software-signature/ Link Previews and Privacy https://www.mysk.blog/2020/10/25/link-previews/

ISC StormCast for Tuesday, October 27th 2020

October 26, 2020 6:09 5.17 MB Downloads: 0

Excel 4 Macros: "Abnormal Sheet Visibility" https://isc.sans.edu/forums/diary/Excel+4+Macros+Abnormal+Sheet+Visibility/26726/ HP Printer Applications Certificate Revoked https://eclecticlight.co/2020/10/23/why-have-my-hp-printers-stopped-working-how-to-check-their-software-signature/ Link Previews and Privacy https://www.mysk.blog/2020/10/25/link-previews/

ISC StormCast for Monday, October 26th 2020

October 25, 2020 5:39 4.75 MB Downloads: 0

An Alternative to Shodan: Censys https://isc.sans.edu/forums/diary/An+Alternative+to+Shodan+Censys+with+UserAgent+CensysInspect11/26718/ Sooty: SOC Analyst's All-in-One Tool https://isc.sans.edu/forums/diary/Sooty+SOC+Analysts+AllinOne+Tool/26714/ Adversarial ML Threat Matrix https://github.com/mitre/advmlthreatmatrix Samsung S20 RCE https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/ VMWare Advisory https://www.vmware.com/security/advisories/VMSA-2020-0023.html

ISC StormCast for Monday, October 26th 2020

October 25, 2020 5:39 4.75 MB Downloads: 0

An Alternative to Shodan: Censys https://isc.sans.edu/forums/diary/An+Alternative+to+Shodan+Censys+with+UserAgent+CensysInspect11/26718/ Sooty: SOC Analyst's All-in-One Tool https://isc.sans.edu/forums/diary/Sooty+SOC+Analysts+AllinOne+Tool/26714/ Adversarial ML Threat Matrix https://github.com/mitre/advmlthreatmatrix Samsung S20 RCE https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/ VMWare Advisory https://www.vmware.com/security/advisories/VMSA-2020-0023.html

ISC StormCast for Friday, October 23rd 2020

October 22, 2020 5:42 4.8 MB Downloads: 0

BazarLoader Phishing Lures https://isc.sans.edu/forums/diary/BazarLoader+phishing+lures+plan+a+Halloween+party+get+a+bonus+and+be+fired+in+the+same+afternoon/26710/ Stalled Reviews for Secure Boot Shim https://github.com/rhboot/shim-review/issues/120 https://github.com/rhboot/shim-review/issues/102#issuecomment-698963751 Cisco Advisories https://tools.cisco.com/security/center/publicationListing.x

ISC StormCast for Friday, October 23rd 2020

October 22, 2020 5:42 4.8 MB Downloads: 0

BazarLoader Phishing Lures https://isc.sans.edu/forums/diary/BazarLoader+phishing+lures+plan+a+Halloween+party+get+a+bonus+and+be+fired+in+the+same+afternoon/26710/ Stalled Reviews for Secure Boot Shim https://github.com/rhboot/shim-review/issues/120 https://github.com/rhboot/shim-review/issues/102#issuecomment-698963751 Cisco Advisories https://tools.cisco.com/security/center/publicationListing.x

ISC StormCast for Thursday, October 22nd 2020

October 21, 2020 5:40 4.76 MB Downloads: 0

Shipping Dangerous Goods https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/ Chinese State-Sponsored Actors Exploit Same Vulnerablities as Others https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF URL Bar Spoofing Vulnerabilities https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2020.html

ISC StormCast for Thursday, October 22nd 2020

October 21, 2020 5:40 4.76 MB Downloads: 0

Shipping Dangerous Goods https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/ Chinese State-Sponsored Actors Exploit Same Vulnerablities as Others https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF URL Bar Spoofing Vulnerabilities https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2020.html

ISC StormCast for Wednesday, October 21st 2020

October 20, 2020 5:49 4.89 MB Downloads: 0

Mirai-alike Python Scanner https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/ Google Chrome Update (actively exploited vulnerability fixed) https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html QNAP Fixes ZeroLogon Vulnerability https://www.qnap.com/en/security-advisory/qsa-20-07 GravityRat Going Multi Platform https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms US Census Spoof https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020

ISC StormCast for Wednesday, October 21st 2020

October 20, 2020 5:49 4.89 MB Downloads: 0

Mirai-alike Python Scanner https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/ Google Chrome Update (actively exploited vulnerability fixed) https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html QNAP Fixes ZeroLogon Vulnerability https://www.qnap.com/en/security-advisory/qsa-20-07 GravityRat Going Multi Platform https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms US Census Spoof https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020

ISC StormCast for Tuesday, October 20th 2020

October 19, 2020 5:08 4.31 MB Downloads: 0

Out of Band MSFT Patches https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022 https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023 Adobe Magento Patches https://helpx.adobe.com/security/products/magento/apsb20-59.html Attacks against SS7 https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991 https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/

ISC StormCast for Tuesday, October 20th 2020

October 19, 2020 5:08 4.31 MB Downloads: 0

Out of Band MSFT Patches https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022 https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023 Adobe Magento Patches https://helpx.adobe.com/security/products/magento/apsb20-59.html Attacks against SS7 https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991 https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/

ISC StormCast for Monday, October 19th 2020

October 18, 2020 6:53 5.79 MB Downloads: 0

CVE-2020-5135 SonicWall Buffer Overflow https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/ Spammer Attached Mass Mailer Configuration Instead of Malware https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/ Traffic Analysis Quiz: Ugly-Wolf.net https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/ Qualcomm QCMAP Vulnerabilities https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities Discord Desktop App RCE https://mksben.l0.cm/2020/10/discord-desktop-rce.html

ISC StormCast for Monday, October 19th 2020

October 18, 2020 6:53 5.79 MB Downloads: 0

CVE-2020-5135 SonicWall Buffer Overflow https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/ Spammer Attached Mass Mailer Configuration Instead of Malware https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/ Traffic Analysis Quiz: Ugly-Wolf.net https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/ Qualcomm QCMAP Vulnerabilities https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities Discord Desktop App RCE https://mksben.l0.cm/2020/10/discord-desktop-rce.html