A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

In Machines We Trust

In Machines We Trust
A podcast about the automation of everything. Host Jennifer Strong and the team at MIT Technology Review look at what it means to entrust artificial intelligence with our most sensitive decisions.

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

ISC StormCast for Tuesday, April 4th 2017

April 03, 2017 5:34 4.69 MB Downloads: 0

Apple Releases iOS 10.3.1 to Remedy Wifi Remote Code Execution https://support.apple.com/en-us/HT207688 Practical Use of SHA1 Collisions: ISO Images https://isc.sans.edu/forums/diary/A+Practical+Use+for+a+SHA1+Collision/22257/ Microsoft Defender False Positive https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FBluber.A Cracking Weak Session Secrets https://martinfowler.com/articles/session-secret.html Skype Malvertising Advertises Fake Flash Players https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/

ISC StormCast for Monday, April 3rd 2017

April 02, 2017 5:59 5.03 MB Downloads: 0

Google Discovers More LastPass Vulnerabilities; https://bugs.chromium.org/p/project-zero/issues/detail?id=1225&desc=6 Attacking KeePass https://www.slideshare.net/harmj0y/a-case-study-in-attacking-keepass https://github.com/HarmJ0y/KeeThief Bypassing Cylance http://www.blackhillsinfosec.com/?p=5792 Mimi Penguin: Extracting Credentials From Memory on Linux Tools https://github.com/huntergregal/mimipenguin Windows 2003 / IIS 6 Exploit https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html https://github.com/rapid7/metasploit-framework/pull/8162

ISC StormCast for Monday, April 3rd 2017

April 02, 2017 5:59 5.03 MB Downloads: 0

Google Discovers More LastPass Vulnerabilities; https://bugs.chromium.org/p/project-zero/issues/detail?id=1225&desc=6 Attacking KeePass https://www.slideshare.net/harmj0y/a-case-study-in-attacking-keepass https://github.com/HarmJ0y/KeeThief Bypassing Cylance http://www.blackhillsinfosec.com/?p=5792 Mimi Penguin: Extracting Credentials From Memory on Linux Tools https://github.com/huntergregal/mimipenguin Windows 2003 / IIS 6 Exploit https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html https://github.com/rapid7/metasploit-framework/pull/8162

ISC StormCast for Friday, March 31st 2017

March 30, 2017 5:41 4.79 MB Downloads: 0

Diverting built-in features for the bad https://isc.sans.edu/forums/diary/Diverting+builtin+features+for+the+bad/22250/ Fake Job Offers to GitHub Developers Include Malware http://researchcenter.paloaltonetworks.com/2017/03/unit42-dimnie-hiding-plain-sight/ Drones With Lasers! https://arxiv.org/pdf/1703.07751.pdf

ISC StormCast for Friday, March 31st 2017

March 30, 2017 5:41 4.79 MB Downloads: 0

Diverting built-in features for the bad https://isc.sans.edu/forums/diary/Diverting+builtin+features+for+the+bad/22250/ Fake Job Offers to GitHub Developers Include Malware http://researchcenter.paloaltonetworks.com/2017/03/unit42-dimnie-hiding-plain-sight/ Drones With Lasers! https://arxiv.org/pdf/1703.07751.pdf

ISC StormCast for Thursday, March 30th 2017

March 29, 2017 5:08 4.33 MB Downloads: 0

Logical and Physical Security Correlation https://isc.sans.edu/forums/diary/Logical+Physical+Security+Correlation/22243/ Recent Mirai DDoS Attacks https://www.incapsula.com/blog/new-mirai-variant-ddos-us-college.html Crusader Injects Fake Support Phone Numbers into Websites https://www.bleepingcomputer.com/news/security/adware-replaces-phone-numbers-for-security-firms-returned-in-search-results/ VMWare Closes Pwn2Own Guest Escape Vulnerabilities http://www.vmware.com/security/advisories/VMSA-2017-0006.html Apple iCloud for Windows Update https://support.apple.com/de-de/HT207607

ISC StormCast for Thursday, March 30th 2017

March 29, 2017 5:08 4.33 MB Downloads: 0

Logical and Physical Security Correlation https://isc.sans.edu/forums/diary/Logical+Physical+Security+Correlation/22243/ Recent Mirai DDoS Attacks https://www.incapsula.com/blog/new-mirai-variant-ddos-us-college.html Crusader Injects Fake Support Phone Numbers into Websites https://www.bleepingcomputer.com/news/security/adware-replaces-phone-numbers-for-security-firms-returned-in-search-results/ VMWare Closes Pwn2Own Guest Escape Vulnerabilities http://www.vmware.com/security/advisories/VMSA-2017-0006.html Apple iCloud for Windows Update https://support.apple.com/de-de/HT207607

ISC StormCast for Wednesday, March 29th 2017

March 28, 2017 5:29 4.61 MB Downloads: 0

New Exploit Variant for Recent Struts2 Vulnerability https://blog.gdssecurity.com/labs/2017/3/27/an-analysis-of-cve-2017-5638.html PoC Exploit for iBook ePub Javascript Vulnerability https://s1gnalcha0s.github.io/ibooks/epub/2017/03/27/This-book-reads-you-using-JavaScript.html Microsoft Docs.com Leak https://twitter.com/gossithedog/status/845446263244050434 Symantec SSL CA tool https://www.renditioninfosec.com/socapps/sslcheck/index.php

ISC StormCast for Wednesday, March 29th 2017

March 28, 2017 5:29 4.61 MB Downloads: 0

New Exploit Variant for Recent Struts2 Vulnerability https://blog.gdssecurity.com/labs/2017/3/27/an-analysis-of-cve-2017-5638.html PoC Exploit for iBook ePub Javascript Vulnerability https://s1gnalcha0s.github.io/ibooks/epub/2017/03/27/This-book-reads-you-using-JavaScript.html Microsoft Docs.com Leak https://twitter.com/gossithedog/status/845446263244050434 Symantec SSL CA tool https://www.renditioninfosec.com/socapps/sslcheck/index.php

ISC StormCast for Tuesday, March 28th 2017

March 27, 2017 6:46 5.7 MB Downloads: 0

Apple Updates https://support.apple.com/en-us/HT201222 IIS 6 / Windows Server 2003 Exploit https://github.com/edwardz246003/IIS_exploit/blob/master/exploit.py Symantec SSL Update https://www.symantec.com/connect/blogs/message-our-ca-customers

ISC StormCast for Tuesday, March 28th 2017

March 27, 2017 6:46 5.7 MB Downloads: 0

Apple Updates https://support.apple.com/en-us/HT201222 IIS 6 / Windows Server 2003 Exploit https://github.com/edwardz246003/IIS_exploit/blob/master/exploit.py Symantec SSL Update https://www.symantec.com/connect/blogs/message-our-ca-customers

ISC StormCast for Monday, March 27th 2017

March 26, 2017 6:33 5.52 MB Downloads: 0

Google Announces Removal of Symantec CAs for Extended Validation https://www.symantec.com/connect/blogs/symantec-backs-its-ca https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/eUAKwjihhBs https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md Spoofing Referrer in Microsoft Edge https://www.brokenbrowser.com/referer-spoofing-patch-bypass/ Smart TV Compromise Via Broadcast Signals https://www.youtube.com/watch?v=bOJ_8QHX6OA Defending Web Applications Class https://www.sans.org/event/sans-security-west-2017/course/defending-web-applications-security-essentials

ISC StormCast for Monday, March 27th 2017

March 26, 2017 6:33 5.52 MB Downloads: 0

Google Announces Removal of Symantec CAs for Extended Validation https://www.symantec.com/connect/blogs/symantec-backs-its-ca https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/eUAKwjihhBs https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md Spoofing Referrer in Microsoft Edge https://www.brokenbrowser.com/referer-spoofing-patch-bypass/ Smart TV Compromise Via Broadcast Signals https://www.youtube.com/watch?v=bOJ_8QHX6OA Defending Web Applications Class https://www.sans.org/event/sans-security-west-2017/course/defending-web-applications-security-essentials

ISC StormCast for Friday, March 24th 2017

March 23, 2017 6:35 5.55 MB Downloads: 0

"Swearing Trojan" Uses Fake BTSs To Spread Malware http://blog.checkpoint.com/2017/03/21/swearing-trojan-continues-rage-even-authors-arrest/ Lastpass Updates ClickJacking Exploit (Again) https://bugs.chromium.org/p/project-zero/issues/detail?id=1188&desc=2 Application Verifier "Bug" https://github.com/ionescu007/HookingNirvana/blob/master/Esoteric%20Hooks.pdf

ISC StormCast for Friday, March 24th 2017

March 23, 2017 6:35 5.55 MB Downloads: 0

"Swearing Trojan" Uses Fake BTSs To Spread Malware http://blog.checkpoint.com/2017/03/21/swearing-trojan-continues-rage-even-authors-arrest/ Lastpass Updates ClickJacking Exploit (Again) https://bugs.chromium.org/p/project-zero/issues/detail?id=1188&desc=2 Application Verifier "Bug" https://github.com/ionescu007/HookingNirvana/blob/master/Esoteric%20Hooks.pdf