
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts

In Machines We Trust
A podcast about the automation of everything. Host Jennifer Strong and the team at MIT Technology Review look at what it means to entrust artificial intelligence with our most sensitive decisions.

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
ISC StormCast for Tuesday, May 7th 2019
Decoding UTF-16 in UDF Files https://isc.sans.edu/forums/diary/Text+and+TNULeNULxNULtNUL/24912/ VMWare Fusion 11 Guest VM RCE https://theevilbit.github.io/posts/vmware_fusion_11_guest_vm_rce_cve-2019-5514/ Hackers Are Using Bad Passwords Too https://www.ankitanubhav.info/post/c2bruting Amazon S3 Discontinues Path Style Access https://www.bleepingcomputer.com/news/security/amazon-to-disable-s3-path-style-access-used-to-bypass-censorship/
ISC StormCast for Monday, May 6th 2019
Git Ransomware https://www.theregister.co.uk/2019/05/03/git_ransomware_bitcoin/ DLink Ransomware Patch https://eu.dlink.com/de/de/support/support-news/2019/february/28/dns320_trojan_cr1pttor Jenkins Plugin Vulnerabilities https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2019/may/story-of-a-hundred-vulnerable-jenkins-plugins/ Malicious WPAD Domains https://blog.redteam.pl/2019/05/badwpad-and-wpad-pl-wpadblocking-com.html
ISC StormCast for Monday, May 6th 2019
Git Ransomware https://www.theregister.co.uk/2019/05/03/git_ransomware_bitcoin/ DLink Ransomware Patch https://eu.dlink.com/de/de/support/support-news/2019/february/28/dns320_trojan_cr1pttor Jenkins Plugin Vulnerabilities https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2019/may/story-of-a-hundred-vulnerable-jenkins-plugins/ Malicious WPAD Domains https://blog.redteam.pl/2019/05/badwpad-and-wpad-pl-wpadblocking-com.html
ISC StormCast for Friday, May 3rd 2019
New SAP Exploits Used to Target Exposed https://www.onapsis.com/10kblaze Cisco Patches SSH Default Credential Vulnerability in Nexus 9000 Switches https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey Current State of JavaScript Crypto Jacking https://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/ D-Link Camera Vulnerabilities https://www.welivesecurity.com/2019/05/02/d-link-camera-vulnerability-video-stream/ Securepairs Promotes "Right to Repair" https://securepairs.org/
ISC StormCast for Friday, May 3rd 2019
New SAP Exploits Used to Target Exposed https://www.onapsis.com/10kblaze Cisco Patches SSH Default Credential Vulnerability in Nexus 9000 Switches https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey Current State of JavaScript Crypto Jacking https://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/ D-Link Camera Vulnerabilities https://www.welivesecurity.com/2019/05/02/d-link-camera-vulnerability-video-stream/ Securepairs Promotes "Right to Repair" https://securepairs.org/
ISC StormCast for Thursday, May 2nd 2019
RCE Vulnerability in Dell Support Assist https://d4stiny.github.io/Remote-Code-Execution-on-most-Dell-computers/ Creston Multiple Vulnerabilities https://www.crestron.com/en-US/Security/Security_Advisories Polymorphic Skimmer Targeting 57 different Payment Gateways https://labs.sansec.io/2019/04/29/polymorphic-skimmer-57-payment-gateways/ More Attacks Against S/Mime and PGP Signed Email https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf
ISC StormCast for Thursday, May 2nd 2019
RCE Vulnerability in Dell Support Assist https://d4stiny.github.io/Remote-Code-Execution-on-most-Dell-computers/ Creston Multiple Vulnerabilities https://www.crestron.com/en-US/Security/Security_Advisories Polymorphic Skimmer Targeting 57 different Payment Gateways https://labs.sansec.io/2019/04/29/polymorphic-skimmer-57-payment-gateways/ More Attacks Against S/Mime and PGP Signed Email https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf
ISC StormCast for Wednesday, May 1st 2019
Sodinokibi Ransomware Exploits WebLogic Server Vulnerability https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html Facebook Leaking Sellers Exact Locations https://www.7elements.co.uk/resources/blog/facebooks-burglary-shopping-list/ Revive Adserver Deserialization Vulnerability https://www.revive-adserver.com/security/revive-sa-2019-001/ AutoMacTC: Automating Mac Forensics Triage https://www.crowdstrike.com/blog/automating-mac-forensic-triage/ Kroll Artifact Parser And Extractor (KAPE) https://learn.duffandphelps.com/kape
ISC StormCast for Wednesday, May 1st 2019
Sodinokibi Ransomware Exploits WebLogic Server Vulnerability https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html Facebook Leaking Sellers Exact Locations https://www.7elements.co.uk/resources/blog/facebooks-burglary-shopping-list/ Revive Adserver Deserialization Vulnerability https://www.revive-adserver.com/security/revive-sa-2019-001/ AutoMacTC: Automating Mac Forensics Triage https://www.crowdstrike.com/blog/automating-mac-forensic-triage/ Kroll Artifact Parser And Extractor (KAPE) https://learn.duffandphelps.com/kape
ISC StormCast for Tuesday, April 30th 2019
iLnkP2P Allows Access To Millions of Security Cameras https://hacked.camera Windows 10 Users Not Applying October Update https://reports.adduplex.com/#/r/2019-04 iFrame "Ransom Support" Attacks https://blog.trendmicro.com/trendlabs-security-intelligence/tech-support-scam-employs-new-trick-by-using-iframe-to-freeze-browsers/
ISC StormCast for Tuesday, April 30th 2019
iLnkP2P Allows Access To Millions of Security Cameras https://hacked.camera Windows 10 Users Not Applying October Update https://reports.adduplex.com/#/r/2019-04 iFrame "Ransom Support" Attacks https://blog.trendmicro.com/trendlabs-security-intelligence/tech-support-scam-employs-new-trick-by-using-iframe-to-freeze-browsers/
ISC StormCast for Monday, April 29th 2019
WebLogic Update https://isc.sans.edu/diary.html?storyid=24890 Docker Hub Breach https://success.docker.com/article/docker-hub-user-notification
ISC StormCast for Monday, April 29th 2019
WebLogic Update https://isc.sans.edu/diary.html?storyid=24890 Docker Hub Breach https://success.docker.com/article/docker-hub-user-notification
ISC StormCast for Friday, April 26th 2019
Unpatched Vulnerablity in WebLogic Exploited https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+Alert+WebLogic+Zero+Day/24880/ Collecting Windows Service Accounts https://isc.sans.edu/forums/diary/Service+Accounts+Redux+Collecting+Service+Accounts+with+PowerShell/24882/ Confluence Vulnerablity Exploited by GandGrab https://blog.alertlogic.com/active-exploitation-of-confluence-vulnerability-cve-2019-3396-dropping-gandcrab-ransomware/ New Micrsoft Security Baseline for Windows 10 / Windows Server https://blogs.technet.microsoft.com/secguide/2019/04/24/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903/
ISC StormCast for Friday, April 26th 2019
Unpatched Vulnerablity in WebLogic Exploited https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+Alert+WebLogic+Zero+Day/24880/ Collecting Windows Service Accounts https://isc.sans.edu/forums/diary/Service+Accounts+Redux+Collecting+Service+Accounts+with+PowerShell/24882/ Confluence Vulnerablity Exploited by GandGrab https://blog.alertlogic.com/active-exploitation-of-confluence-vulnerability-cve-2019-3396-dropping-gandcrab-ransomware/ New Micrsoft Security Baseline for Windows 10 / Windows Server https://blogs.technet.microsoft.com/secguide/2019/04/24/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903/