A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts
Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.
The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.
Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
ISC StormCast for Tuesday, October 16th 2018
Proof Of Concept Exploit for Microsoft Edge Vulnerability CVE-2018-8495 https://leucosite.com/Microsoft-Edge-RCE/ Fake Mining Apps https://www.fortinet.com/blog/threat-research/fortinet-discovers-new-android-apps-that-mine-the-unminable.html Fake Google Photo App Turns out to be Ad-Clicker https://www.geeklatest.com/developer-tricks-microsoft-publishes-app-under-google-llc-name-in-windows-store/
ISC StormCast for Monday, October 15th 2018
Many Large Websites Affected by Branch.io XSS Flaw https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/ Medtronics Pacemakers Disable Remote Update https://www.medtronic.com/content/dam/medtronic-com/us-en/corporate/documents/REV-Medtronic-2090-Security-Bulletin_FNL.pdf IBM Updates WebSphere Update https://www-01.ibm.com/support/docview.wss?uid=swg22016254 Incomplete JET Database Patch https://blog.0patch.com/2018/10/patching-re-patching-and-meta-patching.html
ISC StormCast for Monday, October 15th 2018
Many Large Websites Affected by Branch.io XSS Flaw https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/ Medtronics Pacemakers Disable Remote Update https://www.medtronic.com/content/dam/medtronic-com/us-en/corporate/documents/REV-Medtronic-2090-Security-Bulletin_FNL.pdf IBM Updates WebSphere Update https://www-01.ibm.com/support/docview.wss?uid=swg22016254 Incomplete JET Database Patch https://blog.0patch.com/2018/10/patching-re-patching-and-meta-patching.html
ISC StormCast for Friday, October 12th 2018
New Campaign Using Old Equation Editor Vulnerability https://isc.sans.edu/forums/diary/New+Campaign+Using+Old+Equation+Editor+Vulnerability/24196/ Root Access Vulnerability in SONY Smart TVs https://www.fortinet.com/blog/threat-research/sony-smart-tv-exploit-inside-view-hijacking-your-living-room.html MicroTik RouterOS Vulnerablities https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdf Reverse Analysis of WebAssembly https://www.forcepoint.com/blog/security-labs/manual-reverse-engineering-webassembly-static-code-analysis Firefox Delays Symantec Certificate Distrust https://www.theregister.co.uk/2018/10/11/firefox_symantec_certs_delay/
ISC StormCast for Friday, October 12th 2018
New Campaign Using Old Equation Editor Vulnerability https://isc.sans.edu/forums/diary/New+Campaign+Using+Old+Equation+Editor+Vulnerability/24196/ Root Access Vulnerability in SONY Smart TVs https://www.fortinet.com/blog/threat-research/sony-smart-tv-exploit-inside-view-hijacking-your-living-room.html MicroTik RouterOS Vulnerablities https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdf Reverse Analysis of WebAssembly https://www.forcepoint.com/blog/security-labs/manual-reverse-engineering-webassembly-static-code-analysis Firefox Delays Symantec Certificate Distrust https://www.theregister.co.uk/2018/10/11/firefox_symantec_certs_delay/
ISC StormCast for Thursday, October 11th 2018
Remote Code Execution Vulnerability in WhatsApp https://bugs.chromium.org/p/project-zero/issues/detail?id=1654 Salesforce Releases hashh Library https://github.com/salesforce/hassh CVE-2018-8453 Details from Kaspersky https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/ Juniper Patches https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES Experian Vulnerability Could Have Leaked Credit Freeze PINs https://www.nerdwallet.com/blog/finance/security-flaw-at-experian-allows-easy-access-to-pin-to-unlock-credit-freeze/
ISC StormCast for Thursday, October 11th 2018
Remote Code Execution Vulnerability in WhatsApp https://bugs.chromium.org/p/project-zero/issues/detail?id=1654 Salesforce Releases hashh Library https://github.com/salesforce/hassh CVE-2018-8453 Details from Kaspersky https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/ Juniper Patches https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES Experian Vulnerability Could Have Leaked Credit Freeze PINs https://www.nerdwallet.com/blog/finance/security-flaw-at-experian-allows-easy-access-to-pin-to-unlock-credit-freeze/
ISC StormCast for Wednesday, October 10th 2018
Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/October+2018+Microsoft+Patch+Tuesday/24186/ Adobe Updates https://helpx.adobe.com/security.html Magecart Infects "Shopper Approved" Plugin https://www.riskiq.com/blog/labs/magecart-shopper-approved/
ISC StormCast for Wednesday, October 10th 2018
Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/October+2018+Microsoft+Patch+Tuesday/24186/ Adobe Updates https://helpx.adobe.com/security.html Magecart Infects "Shopper Approved" Plugin https://www.riskiq.com/blog/labs/magecart-shopper-approved/
ISC StormCast for Tuesday, October 9th 2018
Apple Updates iOS and iCloud for Windows https://support.apple.com/en-ca/HT209162 https://support.apple.com/en-ca/HT209141 Intel Adds Spectre/Meltdown Mitigation to 9th Generation CPUs https://www.bleepingcomputer.com/news/security/spectre-and-meltdown-hardware-protection-added-to-intels-9th-gen-cpus/ Windows October Update File Deleting Issues https://support.microsoft.com/en-us/help/4464619/windows-10-update-history https://blogs.technet.microsoft.com/filecab/2018/08/30/9205/ macOS Code Signing Vulnerabilities https://www.virusbulletin.com/conference/vb2018/abstracts/code-signing-flaw-macos
ISC StormCast for Tuesday, October 9th 2018
Apple Updates iOS and iCloud for Windows https://support.apple.com/en-ca/HT209162 https://support.apple.com/en-ca/HT209141 Intel Adds Spectre/Meltdown Mitigation to 9th Generation CPUs https://www.bleepingcomputer.com/news/security/spectre-and-meltdown-hardware-protection-added-to-intels-9th-gen-cpus/ Windows October Update File Deleting Issues https://support.microsoft.com/en-us/help/4464619/windows-10-update-history https://blogs.technet.microsoft.com/filecab/2018/08/30/9205/ macOS Code Signing Vulnerabilities https://www.virusbulletin.com/conference/vb2018/abstracts/code-signing-flaw-macos
ISC StormCast for Monday, October 8th 2018
WPA2 Karck Attack Update https://www.krackattacks.com/followup.html#overview Cisco Updates https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities Seattle Police Tries to Stop SWATing https://www.seattle.gov/police/need-help/swatting git Vulnerability Fixed https://github.com/timwr/CVE-2017-1000117
ISC StormCast for Monday, October 8th 2018
WPA2 Karck Attack Update https://www.krackattacks.com/followup.html#overview Cisco Updates https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities Seattle Police Tries to Stop SWATing https://www.seattle.gov/police/need-help/swatting git Vulnerability Fixed https://github.com/timwr/CVE-2017-1000117
ISC StormCast for Friday, October 5th 2018
Does the Chinese Military Manipulate Supermicro Motherboards? https://www.bloomberg.com/news/articles/2018-10-04/the-big-hack-amazon-apple-supermicro-and-beijing-respond Cloudflare IPFS Gateway Used For Phishing https://www.bleepingcomputer.com/news/security/phishing-attacks-distributed-through-cloudflares-ipfs-gateway/ DNSSEC Root Key Signing Key Rollover https://www.icann.org/resources/pages/ksk-rollover https://www.icann.org/news/blog/2018-ksk-rollover-operator-preparedness-survey
ISC StormCast for Friday, October 5th 2018
Does the Chinese Military Manipulate Supermicro Motherboards? https://www.bloomberg.com/news/articles/2018-10-04/the-big-hack-amazon-apple-supermicro-and-beijing-respond Cloudflare IPFS Gateway Used For Phishing https://www.bleepingcomputer.com/news/security/phishing-attacks-distributed-through-cloudflares-ipfs-gateway/ DNSSEC Root Key Signing Key Rollover https://www.icann.org/resources/pages/ksk-rollover https://www.icann.org/news/blog/2018-ksk-rollover-operator-preparedness-survey