A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

Thinking Elixir Podcast

Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

Linux For Everyone

Linux For Everyone
A show about the thrilling world of desktop Linux, open-source software, and the community creating it. For beginners and veterans alike! Hosted by Jason Evangelho, Jerry Morrison and Schykle.

ISC StormCast for Monday, May 7th 2018

May 06, 2018 5:20 4.49 MB Downloads: 0

Malicious NPM Library Stopped https://blog.npmjs.org/post/173526807575/reported-malicious-module-getcookies Popular GDPR Shield http://gdpr-shield.io (currently down) More Spectre Flaws https://www.heise.de/ct/artikel/Exclusive-Spectre-NG-Multiple-new-Intel-CPU-flaws-revealed-several-serious-4040648.html

ISC StormCast for Friday, May 4th 2018

May 03, 2018 14:48 12.45 MB Downloads: 0

More WebLogic Exploits https://isc.sans.edu/forums/diary/WebLogic+Exploited+in+the+Wild+Again/23617/ Ouch! GDPR Newsletter https://www.sans.org/security-awareness-training/ouch-newsletter GitHub / Twitter Password Storage Issues https://blog.twitter.com/official/en_us/topics/company/2018/keeping-your-account-secure.html https://www.zdnet.com/article/github-says-bug-exposed-account-passwords/ Facebook adds Homegraph Alert to Certificate Transparency log monitoring https://www.facebook.com/notes/protect-the-graph/phishing-domain-detection/2037453483161459/ Disrupting the Empire: Identifying PowerShell Empire Command and Control Activity https://www.sans.org/reading-room/whitepapers/forensics/disrupting-empire-identifying-powershell-empire-command-control-activity-38315

ISC StormCast for Friday, May 4th 2018

May 03, 2018 14:48 12.45 MB Downloads: 0

More WebLogic Exploits https://isc.sans.edu/forums/diary/WebLogic+Exploited+in+the+Wild+Again/23617/ Ouch! GDPR Newsletter https://www.sans.org/security-awareness-training/ouch-newsletter GitHub / Twitter Password Storage Issues https://blog.twitter.com/official/en_us/topics/company/2018/keeping-your-account-secure.html https://www.zdnet.com/article/github-says-bug-exposed-account-passwords/ Facebook adds Homegraph Alert to Certificate Transparency log monitoring https://www.facebook.com/notes/protect-the-graph/phishing-domain-detection/2037453483161459/ Disrupting the Empire: Identifying PowerShell Empire Command and Control Activity https://www.sans.org/reading-room/whitepapers/forensics/disrupting-empire-identifying-powershell-empire-command-control-activity-38315

ISC StormCast for Thursday, May 3rd 2018

May 02, 2018 6:02 5.08 MB Downloads: 0

GPS Jamming Becoming More Common https://www.avweb.com/avwebflash/news/GPS-Jamming-Major-Threat-to-Drone-230749-1.html https://www.heise.de/newsticker/meldung/GPS-unter-Beschuss-Jamming-und-Spoofing-nehmen-zu-4038137.html Windows Command Line References https://isc.sans.edu/forums/diary/Windows+Commands+Reference+An+InfoSec+Must+Have/23613/ LoJack Laptop Anti-Theft Software "Phones Home" to Russia https://asert.arbornetworks.com/lojack-becomes-a-double-agent/ Google Maps Can Be Used as a URL Shortener https://nakedsecurity.sophos.com/2018/05/01/google-maps-open-redirect-flaw-abused-by-spammers/ Retrieving DVR Credentials via "Admin Cookie" https://github.com/ezelf/CVE-2018-9995_dvr_credentials

ISC StormCast for Thursday, May 3rd 2018

May 02, 2018 6:02 5.08 MB Downloads: 0

GPS Jamming Becoming More Common https://www.avweb.com/avwebflash/news/GPS-Jamming-Major-Threat-to-Drone-230749-1.html https://www.heise.de/newsticker/meldung/GPS-unter-Beschuss-Jamming-und-Spoofing-nehmen-zu-4038137.html Windows Command Line References https://isc.sans.edu/forums/diary/Windows+Commands+Reference+An+InfoSec+Must+Have/23613/ LoJack Laptop Anti-Theft Software "Phones Home" to Russia https://asert.arbornetworks.com/lojack-becomes-a-double-agent/ Google Maps Can Be Used as a URL Shortener https://nakedsecurity.sophos.com/2018/05/01/google-maps-open-redirect-flaw-abused-by-spammers/ Retrieving DVR Credentials via "Admin Cookie" https://github.com/ezelf/CVE-2018-9995_dvr_credentials

ISC StormCast for Wednesday, May 2nd 2018

May 01, 2018 5:34 4.69 MB Downloads: 0

Creating Malicious Office Documents https://isc.sans.edu/forums/diary/Diving+into+a+Simple+Maldoc+Generator/23609/ Google (and Amazon) Disable Domain Fronting https://arstechnica.com/information-technology/2018/04/google-disables-domain-fronting-capability-used-to-evade-censors/ Google Chrome To Enforce Certificate Transparency https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/wHILiYf31DE/iMFmpMEkAQAJ

ISC StormCast for Wednesday, May 2nd 2018

May 01, 2018 5:34 4.69 MB Downloads: 0

Creating Malicious Office Documents https://isc.sans.edu/forums/diary/Diving+into+a+Simple+Maldoc+Generator/23609/ Google (and Amazon) Disable Domain Fronting https://arstechnica.com/information-technology/2018/04/google-disables-domain-fronting-capability-used-to-evade-censors/ Google Chrome To Enforce Certificate Transparency https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/wHILiYf31DE/iMFmpMEkAQAJ

ISC StormCast for Tuesday, May 1st 2018

April 30, 2018 5:40 4.77 MB Downloads: 0

April WebLogic Patch Incomplete and Intense Scanning for WebLogic Under Way https://www.bleepingcomputer.com/news/security/hackers-scan-the-web-for-vulnerable-weblogic-servers-after-oracle-botches-patch/ Facex Worm Spreads Malicious Chrome Extensions via Facebook https://blog.trendmicro.com/trendlabs-security-intelligence/facexworm-targets-cryptocurrency-trading-platforms-abuses-facebook-messenger-for-propagation/ $15 DTV Transmitter as a SDR https://hackernoon.com/osmo-fl2k-a-15-dtv-transmitter-fm-radio-hijack-and-gps-spoofing-device-68ac08ba7d76

ISC StormCast for Tuesday, May 1st 2018

April 30, 2018 5:40 4.77 MB Downloads: 0

April WebLogic Patch Incomplete and Intense Scanning for WebLogic Under Way https://www.bleepingcomputer.com/news/security/hackers-scan-the-web-for-vulnerable-weblogic-servers-after-oracle-botches-patch/ Facex Worm Spreads Malicious Chrome Extensions via Facebook https://blog.trendmicro.com/trendlabs-security-intelligence/facexworm-targets-cryptocurrency-trading-platforms-abuses-facebook-messenger-for-propagation/ $15 DTV Transmitter as a SDR https://hackernoon.com/osmo-fl2k-a-15-dtv-transmitter-fm-radio-hijack-and-gps-spoofing-device-68ac08ba7d76

ISC StormCast for Monday, April 30th 2018

April 29, 2018 6:33 5.51 MB Downloads: 0

A Few Sample #Drupal Exploits including CVE-2018-7602 https://isc.sans.edu/forums/diary/More+Threat+Hunting+with+User+Agent+and+Drupal+Exploits/23597/ Triggering SMB Connections to Steal NTLM Credentials via PDFs https://research.checkpoint.com/ntlm-credentials-theft-via-pdf-files/ NTFS Crash DoS Exploit Published for Windwos 10 and 7 https://github.com/mtivadar/windows10_ntfs_crash_dos Apple HomeKit / Secure Element Problems https://www.youtube.com/watch?v=1CNAMgctAp0 Azucar Assessing Azure Security https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/introducing-azucar/

ISC StormCast for Monday, April 30th 2018

April 29, 2018 6:33 5.51 MB Downloads: 0

A Few Sample #Drupal Exploits including CVE-2018-7602 https://isc.sans.edu/forums/diary/More+Threat+Hunting+with+User+Agent+and+Drupal+Exploits/23597/ Triggering SMB Connections to Steal NTLM Credentials via PDFs https://research.checkpoint.com/ntlm-credentials-theft-via-pdf-files/ NTFS Crash DoS Exploit Published for Windwos 10 and 7 https://github.com/mtivadar/windows10_ntfs_crash_dos Apple HomeKit / Secure Element Problems https://www.youtube.com/watch?v=1CNAMgctAp0 Azucar Assessing Azure Security https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/introducing-azucar/

ISC StormCast for Friday, April 27th 2018

April 26, 2018 7:12 6.06 MB Downloads: 0

HP iLO Ransomware https://www.bleepingcomputer.com/news/security/ransomware-hits-hpe-ilo-remote-management-interfaces/ Total Meltdown Exploit Available https://blog.xpnsec.com/total-meltdown-cve-2018-1038/ WD My Cloud EX2 Access Control Bypass https://www.trustwave.com/Resources/SpiderLabs-Blog/WD-My-Cloud-EX2-Serves-Your-Files-to-Anyone/ Hyperoptic ZTE Home Router Hardcoded Account https://www.contextis.com/resources/advisories/hyperoptic-zte-home-routers

ISC StormCast for Friday, April 27th 2018

April 26, 2018 7:12 6.06 MB Downloads: 0

HP iLO Ransomware https://www.bleepingcomputer.com/news/security/ransomware-hits-hpe-ilo-remote-management-interfaces/ Total Meltdown Exploit Available https://blog.xpnsec.com/total-meltdown-cve-2018-1038/ WD My Cloud EX2 Access Control Bypass https://www.trustwave.com/Resources/SpiderLabs-Blog/WD-My-Cloud-EX2-Serves-Your-Files-to-Anyone/ Hyperoptic ZTE Home Router Hardcoded Account https://www.contextis.com/resources/advisories/hyperoptic-zte-home-routers

ISC StormCast for Thursday, April 26th 2018

April 25, 2018 5:21 4.51 MB Downloads: 0

New Drupal Remote Code Execution Vulnerability https://www.drupal.org/sa-core-2018-004 Malicious Network Traffic From /bin/bash https://isc.sans.edu/forums/diary/Malicious+Network+Traffic+From+binbash/23591/ Insecure Hotel Locks https://safeandsavvy.f-secure.com/2018/04/25/researchers-find-way-to-generate-master-keys-to-hotels/ Amazon Echo As Evesdropping Device (signin required) https://info.checkmarx.com/wp-alexa

ISC StormCast for Thursday, April 26th 2018

April 25, 2018 5:21 4.51 MB Downloads: 0

New Drupal Remote Code Execution Vulnerability https://www.drupal.org/sa-core-2018-004 Malicious Network Traffic From /bin/bash https://isc.sans.edu/forums/diary/Malicious+Network+Traffic+From+binbash/23591/ Insecure Hotel Locks https://safeandsavvy.f-secure.com/2018/04/25/researchers-find-way-to-generate-master-keys-to-hotels/ Amazon Echo As Evesdropping Device (signin required) https://info.checkmarx.com/wp-alexa