A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

In Machines We Trust

In Machines We Trust
A podcast about the automation of everything. Host Jennifer Strong and the team at MIT Technology Review look at what it means to entrust artificial intelligence with our most sensitive decisions.

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

ISC StormCast for Wednesday, May 2nd 2018

May 01, 2018 5:34 4.69 MB Downloads: 0

Creating Malicious Office Documents https://isc.sans.edu/forums/diary/Diving+into+a+Simple+Maldoc+Generator/23609/ Google (and Amazon) Disable Domain Fronting https://arstechnica.com/information-technology/2018/04/google-disables-domain-fronting-capability-used-to-evade-censors/ Google Chrome To Enforce Certificate Transparency https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/wHILiYf31DE/iMFmpMEkAQAJ

ISC StormCast for Wednesday, May 2nd 2018

May 01, 2018 5:34 4.69 MB Downloads: 0

Creating Malicious Office Documents https://isc.sans.edu/forums/diary/Diving+into+a+Simple+Maldoc+Generator/23609/ Google (and Amazon) Disable Domain Fronting https://arstechnica.com/information-technology/2018/04/google-disables-domain-fronting-capability-used-to-evade-censors/ Google Chrome To Enforce Certificate Transparency https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/wHILiYf31DE/iMFmpMEkAQAJ

ISC StormCast for Tuesday, May 1st 2018

April 30, 2018 5:40 4.77 MB Downloads: 0

April WebLogic Patch Incomplete and Intense Scanning for WebLogic Under Way https://www.bleepingcomputer.com/news/security/hackers-scan-the-web-for-vulnerable-weblogic-servers-after-oracle-botches-patch/ Facex Worm Spreads Malicious Chrome Extensions via Facebook https://blog.trendmicro.com/trendlabs-security-intelligence/facexworm-targets-cryptocurrency-trading-platforms-abuses-facebook-messenger-for-propagation/ $15 DTV Transmitter as a SDR https://hackernoon.com/osmo-fl2k-a-15-dtv-transmitter-fm-radio-hijack-and-gps-spoofing-device-68ac08ba7d76

ISC StormCast for Tuesday, May 1st 2018

April 30, 2018 5:40 4.77 MB Downloads: 0

April WebLogic Patch Incomplete and Intense Scanning for WebLogic Under Way https://www.bleepingcomputer.com/news/security/hackers-scan-the-web-for-vulnerable-weblogic-servers-after-oracle-botches-patch/ Facex Worm Spreads Malicious Chrome Extensions via Facebook https://blog.trendmicro.com/trendlabs-security-intelligence/facexworm-targets-cryptocurrency-trading-platforms-abuses-facebook-messenger-for-propagation/ $15 DTV Transmitter as a SDR https://hackernoon.com/osmo-fl2k-a-15-dtv-transmitter-fm-radio-hijack-and-gps-spoofing-device-68ac08ba7d76

ISC StormCast for Monday, April 30th 2018

April 29, 2018 6:33 5.51 MB Downloads: 0

A Few Sample #Drupal Exploits including CVE-2018-7602 https://isc.sans.edu/forums/diary/More+Threat+Hunting+with+User+Agent+and+Drupal+Exploits/23597/ Triggering SMB Connections to Steal NTLM Credentials via PDFs https://research.checkpoint.com/ntlm-credentials-theft-via-pdf-files/ NTFS Crash DoS Exploit Published for Windwos 10 and 7 https://github.com/mtivadar/windows10_ntfs_crash_dos Apple HomeKit / Secure Element Problems https://www.youtube.com/watch?v=1CNAMgctAp0 Azucar Assessing Azure Security https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/introducing-azucar/

ISC StormCast for Monday, April 30th 2018

April 29, 2018 6:33 5.51 MB Downloads: 0

A Few Sample #Drupal Exploits including CVE-2018-7602 https://isc.sans.edu/forums/diary/More+Threat+Hunting+with+User+Agent+and+Drupal+Exploits/23597/ Triggering SMB Connections to Steal NTLM Credentials via PDFs https://research.checkpoint.com/ntlm-credentials-theft-via-pdf-files/ NTFS Crash DoS Exploit Published for Windwos 10 and 7 https://github.com/mtivadar/windows10_ntfs_crash_dos Apple HomeKit / Secure Element Problems https://www.youtube.com/watch?v=1CNAMgctAp0 Azucar Assessing Azure Security https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/introducing-azucar/

ISC StormCast for Friday, April 27th 2018

April 26, 2018 7:12 6.06 MB Downloads: 0

HP iLO Ransomware https://www.bleepingcomputer.com/news/security/ransomware-hits-hpe-ilo-remote-management-interfaces/ Total Meltdown Exploit Available https://blog.xpnsec.com/total-meltdown-cve-2018-1038/ WD My Cloud EX2 Access Control Bypass https://www.trustwave.com/Resources/SpiderLabs-Blog/WD-My-Cloud-EX2-Serves-Your-Files-to-Anyone/ Hyperoptic ZTE Home Router Hardcoded Account https://www.contextis.com/resources/advisories/hyperoptic-zte-home-routers

ISC StormCast for Friday, April 27th 2018

April 26, 2018 7:12 6.06 MB Downloads: 0

HP iLO Ransomware https://www.bleepingcomputer.com/news/security/ransomware-hits-hpe-ilo-remote-management-interfaces/ Total Meltdown Exploit Available https://blog.xpnsec.com/total-meltdown-cve-2018-1038/ WD My Cloud EX2 Access Control Bypass https://www.trustwave.com/Resources/SpiderLabs-Blog/WD-My-Cloud-EX2-Serves-Your-Files-to-Anyone/ Hyperoptic ZTE Home Router Hardcoded Account https://www.contextis.com/resources/advisories/hyperoptic-zte-home-routers

ISC StormCast for Thursday, April 26th 2018

April 25, 2018 5:21 4.51 MB Downloads: 0

New Drupal Remote Code Execution Vulnerability https://www.drupal.org/sa-core-2018-004 Malicious Network Traffic From /bin/bash https://isc.sans.edu/forums/diary/Malicious+Network+Traffic+From+binbash/23591/ Insecure Hotel Locks https://safeandsavvy.f-secure.com/2018/04/25/researchers-find-way-to-generate-master-keys-to-hotels/ Amazon Echo As Evesdropping Device (signin required) https://info.checkmarx.com/wp-alexa

ISC StormCast for Thursday, April 26th 2018

April 25, 2018 5:21 4.51 MB Downloads: 0

New Drupal Remote Code Execution Vulnerability https://www.drupal.org/sa-core-2018-004 Malicious Network Traffic From /bin/bash https://isc.sans.edu/forums/diary/Malicious+Network+Traffic+From+binbash/23591/ Insecure Hotel Locks https://safeandsavvy.f-secure.com/2018/04/25/researchers-find-way-to-generate-master-keys-to-hotels/ Amazon Echo As Evesdropping Device (signin required) https://info.checkmarx.com/wp-alexa

ISC StormCast for Monday, March 12th 2018

March 11, 2018 7:34 6.36 MB Downloads: 0

Paying For Ransomware Often Fails to Recover Files https://cyber-edge.com/cdr/#about-this-report Microtik Router Malware Infects Sysadmin PCs https://s3-eu-west-1.amazonaws.com/khub-media/wp-content/uploads/sites/43/2018/03/09133534/The-Slingshot-APT_report_ENG_final.pdf CNNVD Held Back Vulnerabilities https://www.recordedfuture.com/chinese-mss-vulnerability-influence/ Keeper Exposes S3 Bucket http://www.zdnet.com/article/password-manager-maker-keeper-hit-by-another-security-snafu/ https://keepersecurity.com/blog/2018/03/10/keepers-response-zdnets-article-regarding-s3-bucket-configuration-issue/ Chip and Pin Clones https://www.kaspersky.com/blog/chip-n-pin-cloning/21502/

ISC StormCast for Monday, March 12th 2018

March 11, 2018 7:34 6.36 MB Downloads: 0

Paying For Ransomware Often Fails to Recover Files https://cyber-edge.com/cdr/#about-this-report Microtik Router Malware Infects Sysadmin PCs https://s3-eu-west-1.amazonaws.com/khub-media/wp-content/uploads/sites/43/2018/03/09133534/The-Slingshot-APT_report_ENG_final.pdf CNNVD Held Back Vulnerabilities https://www.recordedfuture.com/chinese-mss-vulnerability-influence/ Keeper Exposes S3 Bucket http://www.zdnet.com/article/password-manager-maker-keeper-hit-by-another-security-snafu/ https://keepersecurity.com/blog/2018/03/10/keepers-response-zdnets-article-regarding-s3-bucket-configuration-issue/ Chip and Pin Clones https://www.kaspersky.com/blog/chip-n-pin-cloning/21502/

ISC StormCast for Friday, March 9th 2018

March 08, 2018 6:05 5.13 MB Downloads: 0

Apache Solr Vulnerability used to Install Cryptocoin Miner https://isc.sans.edu/forums/diary/Apache+SOLR+the+new+target+for+cryptominers/23425/ CRIMEB4NK IRC Bot https://isc.sans.edu/forums/diary/CRIMEB4NK+IRC+Bot/23423/ Cisco Patches https://tools.cisco.com/security/center/publicationListing.x Any.Run Malware Analysis Tool https://any.run

ISC StormCast for Friday, March 9th 2018

March 08, 2018 6:05 5.13 MB Downloads: 0

Apache Solr Vulnerability used to Install Cryptocoin Miner https://isc.sans.edu/forums/diary/Apache+SOLR+the+new+target+for+cryptominers/23425/ CRIMEB4NK IRC Bot https://isc.sans.edu/forums/diary/CRIMEB4NK+IRC+Bot/23423/ Cisco Patches https://tools.cisco.com/security/center/publicationListing.x Any.Run Malware Analysis Tool https://any.run

ISC StormCast for Thursday, March 8th 2018

March 07, 2018 5:49 4.89 MB Downloads: 0

Ransomware News: GlobeImposter Gets A Facelift, GandCrab is Still Out there https://isc.sans.edu/forums/diary/Ransomware+news+GlobeImposter+gets+a+facelift+GandCrab+is+still+out+there/23417/ How to Break Encryption https://blog.malwarebytes.com/threat-analysis/2018/03/encryption-101-how-to-break-encryption/ Bypassing Adobe Flash Security Protections https://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-protection-mechanism/ Hundreds of Bitcoin Mining Servers Stolen in Iceland https://www.theguardian.com/world/2018/mar/07/hundreds-of-bitcoin-mining-servers-stolen-in-iceland Several Android Mail Apps Send Password To Developer (article in German) https://www.kuketz-blog.de/mail-apps-zahlreiche-android-apps-uebermitteln-login-passwort/