
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

In Machines We Trust
A podcast about the automation of everything. Host Jennifer Strong and the team at MIT Technology Review look at what it means to entrust artificial intelligence with our most sensitive decisions.

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
ISC StormCast for Friday, October 16th 2020
Obfuscated Python RAT https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/ BadNeighbor ICMPv6 Router Advertisement Update https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/ BlueZ Vulnerability https://www.youtube.com/watch?v=qPYrLRausSw https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html https://security.googleblog.com/ (available "soon") Zoom Rolling Out End-to-End Encryption https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/
ISC StormCast for Friday, October 16th 2020
Obfuscated Python RAT https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/ BadNeighbor ICMPv6 Router Advertisement Update https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/ BlueZ Vulnerability https://www.youtube.com/watch?v=qPYrLRausSw https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html https://security.googleblog.com/ (available "soon") Zoom Rolling Out End-to-End Encryption https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/
ISC StormCast for Thursday, October 15th 2020
TA551/Shathak Word Docs Push IcedID and Bokbot https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/ MSFT Patch Tuesday Followup https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952 Apple T2 Chip Vulnerability Confirmed https://9to5mac.com/2020/10/13/t2-exploit-team/ SAP Updates https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
ISC StormCast for Thursday, October 15th 2020
TA551/Shathak Word Docs Push IcedID and Bokbot https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/ MSFT Patch Tuesday Followup https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952 Apple T2 Chip Vulnerability Confirmed https://9to5mac.com/2020/10/13/t2-exploit-team/ SAP Updates https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
ISC StormCast for Wednesday, October 14th 2020
Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/ Adobe Updates https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
ISC StormCast for Wednesday, October 14th 2020
Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/ Adobe Updates https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
ISC StormCast for Tuesday, October 13th 2020
Nested .MSGs: Turtles All The Way Down https://isc.sans.edu/forums/diary/Nested+MSGs+Turtles+All+The+Way+Down/26668/ Microsoft Attempting To Take Down Trickbot C2 Infrastructure https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/ Google Chrome Cache Partitioning https://developers.google.com/web/updates/2020/10/http-cache-partitioning
ISC StormCast for Tuesday, October 13th 2020
Nested .MSGs: Turtles All The Way Down https://isc.sans.edu/forums/diary/Nested+MSGs+Turtles+All+The+Way+Down/26668/ Microsoft Attempting To Take Down Trickbot C2 Infrastructure https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/ Google Chrome Cache Partitioning https://developers.google.com/web/updates/2020/10/http-cache-partitioning
ISC StormCast for Monday, October 12th 2020
Phishing Kits As Far As The Eye Can See https://isc.sans.edu/forums/diary/Phishing+kits+as+far+as+the+eye+can+see/26660/ Open Packaging Conventions https://isc.sans.edu/forums/diary/Open+Packaging+Conventions/26662/ Analyzing MSG Files https://isc.sans.edu/forums/diary/Analyzing+MSG+Files+With+pluginmsgsummary/26664/ Cisco Video Surveillance 8000 Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cdp-rcedos-mAHR8vNx 55 New Apple Flaws https://samcurry.net/hacking-apple/
ISC StormCast for Monday, October 12th 2020
Phishing Kits As Far As The Eye Can See https://isc.sans.edu/forums/diary/Phishing+kits+as+far+as+the+eye+can+see/26660/ Open Packaging Conventions https://isc.sans.edu/forums/diary/Open+Packaging+Conventions/26662/ Analyzing MSG Files https://isc.sans.edu/forums/diary/Analyzing+MSG+Files+With+pluginmsgsummary/26664/ Cisco Video Surveillance 8000 Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cdp-rcedos-mAHR8vNx 55 New Apple Flaws https://samcurry.net/hacking-apple/
ISC StormCast for Friday, October 9th 2020
Hashicorp Vault Vulnerabilities https://googleprojectzero.blogspot.com/2020/10/enter-the-vault-auth-issues-hashicorp-vault.html Ryuk Ransomware Writeup https://thedfirreport.com/2020/10/08/ryuks-return/ Ricky Tan: Zeek Log Reconnaissance with Netowrk Graphs Using Maltego Casefile https://www.sans.org/reading-room/whitepapers/securityanalytics/zeek-log-reconnaissance-network-graphs-maltego-casefile-39815
ISC StormCast for Friday, October 9th 2020
Hashicorp Vault Vulnerabilities https://googleprojectzero.blogspot.com/2020/10/enter-the-vault-auth-issues-hashicorp-vault.html Ryuk Ransomware Writeup https://thedfirreport.com/2020/10/08/ryuks-return/ Ricky Tan: Zeek Log Reconnaissance with Netowrk Graphs Using Maltego Casefile https://www.sans.org/reading-room/whitepapers/securityanalytics/zeek-log-reconnaissance-network-graphs-maltego-casefile-39815
ISC StormCast for Thursday, October 8th 2020
Today, Nobody is Going to Attack You https://isc.sans.edu/forums/diary/Today+Nobody+is+Going+to+Attack+You/26654/ Google Chrome Patches https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html Android Security Update https://source.android.com/security/bulletin/2020-10-01 QNAP Patches Helpdesk Application https://www.qnap.com/en/security-advisory/QSA-20-08 Comcast Remote Control Evesdropping https://www.guardicore.com/2020/10/wareztheremote-turning-remotes-into-listening-devices/
ISC StormCast for Thursday, October 8th 2020
Today, Nobody is Going to Attack You https://isc.sans.edu/forums/diary/Today+Nobody+is+Going+to+Attack+You/26654/ Google Chrome Patches https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html Android Security Update https://source.android.com/security/bulletin/2020-10-01 QNAP Patches Helpdesk Application https://www.qnap.com/en/security-advisory/QSA-20-08 Comcast Remote Control Evesdropping https://www.guardicore.com/2020/10/wareztheremote-turning-remotes-into-listening-devices/
ISC StormCast for Wednesday, October 7th 2020
Apple T2 Chip Vulnerability https://ironpeak.be/blog/crouching-t2-hidden-danger/ NVIDIA Patches https://nvidia.custhelp.com/app/answers/detail/a_id/5075 Cloudflare DDoS Alerts https://blog.cloudflare.com/announcing-ddos-alerts/ Gravatar Privacy Issue https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/