A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

In Machines We Trust

In Machines We Trust
A podcast about the automation of everything. Host Jennifer Strong and the team at MIT Technology Review look at what it means to entrust artificial intelligence with our most sensitive decisions.

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

ISC StormCast for Thursday, May 4th 2017

May 03, 2017 8:26 7.09 MB Downloads: 0

Google Docs OAUTH Phishing E-Mails https://isc.sans.edu/forums/diary/OAUTH+phishing+against+Google+Docs+beware/22372/ Review Google App Permissions https://myaccount.google.com/u/0/permissions?pli=1 SS7 Exploits Documented in Banking Attacks http://www.sueddeutsche.de/digital/it-sicherheit-schwachstelle-im-mobilfunknetz-kriminelle-hacker-raeumen-konten-leer-1.3486504 http://www.theregister.co.uk/2017/05/03/hackers_fire_up_ss7_flaw/

ISC StormCast for Thursday, May 4th 2017

May 03, 2017 8:26 7.09 MB Downloads: 0

Google Docs OAUTH Phishing E-Mails https://isc.sans.edu/forums/diary/OAUTH+phishing+against+Google+Docs+beware/22372/ Review Google App Permissions https://myaccount.google.com/u/0/permissions?pli=1 SS7 Exploits Documented in Banking Attacks http://www.sueddeutsche.de/digital/it-sicherheit-schwachstelle-im-mobilfunknetz-kriminelle-hacker-raeumen-konten-leer-1.3486504 http://www.theregister.co.uk/2017/05/03/hackers_fire_up_ss7_flaw/

ISC StormCast for Wednesday, May 3rd 2017

May 02, 2017 5:25 4.56 MB Downloads: 0

Scans Sighted for Ports Used by Intel Remote Management Interface https://isc.sans.edu/port.html?port=16992 https://isc.sans.edu/port.html?port=16993 Outlook Forms Can Run Macros https://sensepost.com/blog/2017/outlook-forms-and-shells/ Jenkins Vulnerability https://jenkins.io/security/advisory/2017-04-26/ Google Android May Patchday https://source.android.com/security/bulletin/2017-05-01 IBM Storwize USB Stick Malware http://www-01.ibm.com/support/docview.wss?uid=ssg1S1010146&myns=s028&mynp=OCSTHGUJ&mynp=OCSTLM5A&mynp=OCSTLM6B&mynp=OCHW206&mync=E&cm_sp=s028-_-OCSTHGUJ-OCSTLM5A-OCSTLM6B-OCHW206-_-E

ISC StormCast for Wednesday, May 3rd 2017

May 02, 2017 5:25 4.56 MB Downloads: 0

Scans Sighted for Ports Used by Intel Remote Management Interface https://isc.sans.edu/port.html?port=16992 https://isc.sans.edu/port.html?port=16993 Outlook Forms Can Run Macros https://sensepost.com/blog/2017/outlook-forms-and-shells/ Jenkins Vulnerability https://jenkins.io/security/advisory/2017-04-26/ Google Android May Patchday https://source.android.com/security/bulletin/2017-05-01 IBM Storwize USB Stick Malware http://www-01.ibm.com/support/docview.wss?uid=ssg1S1010146&myns=s028&mynp=OCSTHGUJ&mynp=OCSTLM5A&mynp=OCSTLM6B&mynp=OCHW206&mync=E&cm_sp=s028-_-OCSTHGUJ-OCSTLM5A-OCSTLM6B-OCHW206-_-E

ISC StormCast for Tuesday, May 2nd 2017

May 01, 2017 5:54 4.96 MB Downloads: 0

Intel AMT, SBT and ISM Escalation of Privilege Vulnerability https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/ Local Root Exploit in chkrootkit https://lepetithacker.wordpress.com/2017/04/30/local-root-exploit-in-chkrootkit/ Escape Sequence Exploits in Various Linux Terminals http://www.openwall.com/lists/oss-security/2017/05/01/13

ISC StormCast for Tuesday, May 2nd 2017

May 01, 2017 5:54 4.96 MB Downloads: 0

Intel AMT, SBT and ISM Escalation of Privilege Vulnerability https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/ Local Root Exploit in chkrootkit https://lepetithacker.wordpress.com/2017/04/30/local-root-exploit-in-chkrootkit/ Escape Sequence Exploits in Various Linux Terminals http://www.openwall.com/lists/oss-security/2017/05/01/13

ISC StormCast for Monday, May 1st 2017

April 30, 2017 5:50 4.92 MB Downloads: 0

Simple Javascript Word Macro Not Recognized By Many AV Products https://isc.sans.edu/forums/diary/Another+Day+Another+Obfuscation+Technique/22354/ OS X Malware Adds Proxy To Intercept HTTPS http://blog.checkpoint.com/2017/04/27/osx-malware-catching-wants-read-https-traffic/ OVH Vulnerability Put Servers at Risk https://jrwr.io/doku.php?id=blog:ovh_vrack_security_issue

ISC StormCast for Monday, May 1st 2017

April 30, 2017 5:50 4.92 MB Downloads: 0

Simple Javascript Word Macro Not Recognized By Many AV Products https://isc.sans.edu/forums/diary/Another+Day+Another+Obfuscation+Technique/22354/ OS X Malware Adds Proxy To Intercept HTTPS http://blog.checkpoint.com/2017/04/27/osx-malware-catching-wants-read-https-traffic/ OVH Vulnerability Put Servers at Risk https://jrwr.io/doku.php?id=blog:ovh_vrack_security_issue

ISC StormCast for Friday, April 28th 2017

April 27, 2017 6:17 5.3 MB Downloads: 0

VISA IP Block Hijacked By Russian ISP https://isc.sans.edu/forums/diary/BGP+Hijacking+The+Internet+is+StillAgain+Broken/22350/ Antminer "Checking" DoS Vulnerability http://www.antbleed.com Symantec Offers Audits To Stave Off Google's CA Blacklisting https://www.symantec.com/connect/blogs/symantec-ca-proposal NoMX Security E-Mail Appliance Pentest https://scotthelme.co.uk/nomx-the-worlds-most-secure-communications-protocol/ vendor response: www.nomx.com SANS Defending Web Applications https://www.sans.org/dev522

ISC StormCast for Friday, April 28th 2017

April 27, 2017 6:17 5.3 MB Downloads: 0

VISA IP Block Hijacked By Russian ISP https://isc.sans.edu/forums/diary/BGP+Hijacking+The+Internet+is+StillAgain+Broken/22350/ Antminer "Checking" DoS Vulnerability http://www.antbleed.com Symantec Offers Audits To Stave Off Google's CA Blacklisting https://www.symantec.com/connect/blogs/symantec-ca-proposal NoMX Security E-Mail Appliance Pentest https://scotthelme.co.uk/nomx-the-worlds-most-secure-communications-protocol/ vendor response: www.nomx.com SANS Defending Web Applications https://www.sans.org/dev522

ISC StormCast for Thursday, April 27th 2017

April 26, 2017 5:35 4.71 MB Downloads: 0

Bots Disrupts US ISP https://www.bleepingcomputer.com/news/security/us-isp-goes-down-as-two-malware-families-go-to-war-over-its-modems/ Samsung Smart TV Wi-Fi Direct Exploit http://seclists.org/fulldisclosure/2017/Apr/101 Adobe Publishes ColdFusion Update https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html SNMP Misconfiguration Eliminates Community String Validation https://stringbleed.github.io/#

ISC StormCast for Thursday, April 27th 2017

April 26, 2017 5:35 4.71 MB Downloads: 0

Bots Disrupts US ISP https://www.bleepingcomputer.com/news/security/us-isp-goes-down-as-two-malware-families-go-to-war-over-its-modems/ Samsung Smart TV Wi-Fi Direct Exploit http://seclists.org/fulldisclosure/2017/Apr/101 Adobe Publishes ColdFusion Update https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html SNMP Misconfiguration Eliminates Community String Validation https://stringbleed.github.io/#

ISC StormCast for Wednesday, April 26th 2017

April 25, 2017 5:53 4.95 MB Downloads: 0

CAA Records and Certificate Issuance https://isc.sans.edu/forums/diary/CAA+Records+and+Certificate+Issuance/22342/ Hyundai Blue Link Infomration Disclosure https://community.rapid7.com/community/infosec/blog/2017/04/25/r7-2017-02-hyundai-blue-link-potential-info-disclosure-fixed HP, Philips, Fujitsu Display Software Privilege Escalation http://blog.sec-consult.com/2017/04/what-unites-hp-philips-and-fujitsu-one.html

ISC StormCast for Wednesday, April 26th 2017

April 25, 2017 5:53 4.95 MB Downloads: 0

CAA Records and Certificate Issuance https://isc.sans.edu/forums/diary/CAA+Records+and+Certificate+Issuance/22342/ Hyundai Blue Link Infomration Disclosure https://community.rapid7.com/community/infosec/blog/2017/04/25/r7-2017-02-hyundai-blue-link-potential-info-disclosure-fixed HP, Philips, Fujitsu Display Software Privilege Escalation http://blog.sec-consult.com/2017/04/what-unites-hp-philips-and-fujitsu-one.html

ISC StormCast for Tuesday, April 25th 2017

April 24, 2017 5:09 4.34 MB Downloads: 0

Android Malware MilyDoor Builds Backdoor Into Networks Via SSH/SOCKS http://blog.trendmicro.com/trendlabs-security-intelligence/dresscode-android-malware-finds-successor-milkydoor/ Remote Code Execution Flaw in Squirrelmail http://seclists.org/fulldisclosure/2017/Apr/81 Atlassian Confluence Update https://confluence.atlassian.com/doc/confluence-security-advisory-2017-04-19-887071137.html TCP Proxy Over Named Pipes / SMB https://github.com/dxflatline/flatpipes