
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts

In Machines We Trust
A podcast about the automation of everything. Host Jennifer Strong and the team at MIT Technology Review look at what it means to entrust artificial intelligence with our most sensitive decisions.

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
ISC StormCast for Tuesday, February 21st 2017
Hardening Postfix Against FTP Relay Attacks https://isc.sans.edu/forums/diary/Hardening+Postfix+Against+FTP+Relay+Attacks/22086/ Kaspersky Examins Mobile Car Apps https://securelist.com/analysis/publications/77576/mobile-apps-and-stealing-a-connected-car/ Cars "Remember" Prior Owners http://money.cnn.com/2017/02/17/technology/used-car-hack-safety-location/ Xen Project Reconsidering Vulnerability Disclosure Policy https://blog.xenproject.org/2017/02/14/request-for-comment-scope-of-vulnerabilities-for-which-xsas-are-issued/ Stagefright Vulnerability had minimal affect on Android Security https://www.rsaconference.com/speakers/adrian_ludwig
ISC StormCast for Monday, February 20th 2017
RTRBK: Router, Switch, Firewall Backups in Powershell https://isc.sans.edu/forums/diary/RTRBK+Router+Switch+Firewall+Backups+in+PowerShell+tool+drop/22079/ Windows EMF Imge 0-Day Memory Leak https://bugs.chromium.org/p/project-zero/issues/detail?id=992 Brazillian Traffic Ticket Malspam https://isc.sans.edu/forums/diary/Brazilian+malspam+sends+Autoitbased+malware/22081/ Using XXE To Send E-Mail https://shiftordie.de/blog/2017/02/18/smtp-over-xxe/
ISC StormCast for Monday, February 20th 2017
RTRBK: Router, Switch, Firewall Backups in Powershell https://isc.sans.edu/forums/diary/RTRBK+Router+Switch+Firewall+Backups+in+PowerShell+tool+drop/22079/ Windows EMF Imge 0-Day Memory Leak https://bugs.chromium.org/p/project-zero/issues/detail?id=992 Brazillian Traffic Ticket Malspam https://isc.sans.edu/forums/diary/Brazilian+malspam+sends+Autoitbased+malware/22081/ Using XXE To Send E-Mail https://shiftordie.de/blog/2017/02/18/smtp-over-xxe/
ISC StormCast for Friday, February 17th 2017
AVM Private Key Leak Puts Cable Modems At Risk https://isc.sans.edu/forums/diary/AVM+Private+Key+Leak+Puts+Cable+Modems+Worldwide+At+Risk/22076/ OpenSSL Update https://isc.sans.edu/forums/diary/OpenSSL+110e+Update+No+need+to+panic+openssl/22074/ Microsoft Update Delayed https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/ ANC Attack ASLR Bypass https://www.vusec.net/projects/anc/
ISC StormCast for Friday, February 17th 2017
AVM Private Key Leak Puts Cable Modems At Risk https://isc.sans.edu/forums/diary/AVM+Private+Key+Leak+Puts+Cable+Modems+Worldwide+At+Risk/22076/ OpenSSL Update https://isc.sans.edu/forums/diary/OpenSSL+110e+Update+No+need+to+panic+openssl/22074/ Microsoft Update Delayed https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/ ANC Attack ASLR Bypass https://www.vusec.net/projects/anc/
ISC StormCast for Thursday, February 16th 2017
How Was Your Stay At The Hotel La Playa https://isc.sans.edu/forums/diary/How+was+your+stay+at+the+Hotel+La+Playa/22069 XAgent OS X Malware https://labs.bitdefender.com/2017/02/new-xagent-mac-malware-linked-with-the-apt28/ Conference Phone Compromise https://www.contextis.com//resources/blog/phwning-boardroom-hacking-android-conference-phone/
ISC StormCast for Thursday, February 16th 2017
How Was Your Stay At The Hotel La Playa https://isc.sans.edu/forums/diary/How+was+your+stay+at+the+Hotel+La+Playa/22069 XAgent OS X Malware https://labs.bitdefender.com/2017/02/new-xagent-mac-malware-linked-with-the-apt28/ Conference Phone Compromise https://www.contextis.com//resources/blog/phwning-boardroom-hacking-android-conference-phone/
ISC StormCast for Wednesday, February 15th 2017
Microsoft Cancels Patch Tuesday https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/ Adobe Update For Flash https://helpx.adobe.com/security/products/flash-player/apsb17-04.html WebSephere Update http://www-01.ibm.com/support/docview.wss?uid=swg21997743 Operation Kingphish https://medium.com/amnesty-insights/operation-kingphish-uncovering-a-campaign-of-cyber-attacks-against-civil-society-in-qatar-and-aa40c9e08852#.965et86vk Hacking Node-Serialize http://blog.websecurify.com/2017/02/hacking-node-serialize.html
ISC StormCast for Wednesday, February 15th 2017
Microsoft Cancels Patch Tuesday https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/ Adobe Update For Flash https://helpx.adobe.com/security/products/flash-player/apsb17-04.html WebSephere Update http://www-01.ibm.com/support/docview.wss?uid=swg21997743 Operation Kingphish https://medium.com/amnesty-insights/operation-kingphish-uncovering-a-campaign-of-cyber-attacks-against-civil-society-in-qatar-and-aa40c9e08852#.965et86vk Hacking Node-Serialize http://blog.websecurify.com/2017/02/hacking-node-serialize.html
ISC StormCast for Tuesday, February 14th 2017
New Tool: Packettotal.com http://www.packettotal.com What Not To Decrypt When Intercepting SSL https://isc.sans.edu/forums/diary/Stuff+I+Learned+Decrypting/22059/ webcast: https://www.sans.org/webcasts/8-ways-watch-invisible-analyzing-encrypted-network-traffic-103277 Simple Static Malware Analyzer https://github.com/secrary/SSMA Critical Firefox for Android Vulnerability https://www.mozilla.org/en-US/security/advisories/mfsa2017-04/ Ubuntu ntfs-3g Privilege Escalation https://bugs.chromium.org/p/project-zero/issues/detail?id=1072 Microsoft Patch Tuesday Changes http://www.infoworld.com/article/3139922/microsoft-windows/microsoft-to-revamp-its-documentation-for-security-patches.html
ISC StormCast for Tuesday, February 14th 2017
New Tool: Packettotal.com http://www.packettotal.com What Not To Decrypt When Intercepting SSL https://isc.sans.edu/forums/diary/Stuff+I+Learned+Decrypting/22059/ webcast: https://www.sans.org/webcasts/8-ways-watch-invisible-analyzing-encrypted-network-traffic-103277 Simple Static Malware Analyzer https://github.com/secrary/SSMA Critical Firefox for Android Vulnerability https://www.mozilla.org/en-US/security/advisories/mfsa2017-04/ Ubuntu ntfs-3g Privilege Escalation https://bugs.chromium.org/p/project-zero/issues/detail?id=1072 Microsoft Patch Tuesday Changes http://www.infoworld.com/article/3139922/microsoft-windows/microsoft-to-revamp-its-documentation-for-security-patches.html
ISC StormCast for Monday, February 13th 2017
Vulnerabilities in Samsung KNOX https://googleprojectzero.blogspot.de/2017/02/lifting-hyper-visor-bypassing-samsungs.html Auditing MongoDB Configurations https://github.com/stampery/mongoaudit Reversing Javascript https://isc.sans.edu/forums/diary/Analysis+of+a+Suspicious+Piece+of+JavaScript/22056/ Wordpress REST API Flaw Widely Exploited https://www.wordfence.com/blog/2017/02/rapid-growth-in-rest-api-defacements/ Cryptographically Secure PHP Development https://paragonie.com/blog/2017/02/cryptographically-secure-php-development DEV522 Web Application Security Essentials https://www.sans.org/event/sans-2017/course/defending-web-applications-security-essentials
ISC StormCast for Monday, February 13th 2017
Vulnerabilities in Samsung KNOX https://googleprojectzero.blogspot.de/2017/02/lifting-hyper-visor-bypassing-samsungs.html Auditing MongoDB Configurations https://github.com/stampery/mongoaudit Reversing Javascript https://isc.sans.edu/forums/diary/Analysis+of+a+Suspicious+Piece+of+JavaScript/22056/ Wordpress REST API Flaw Widely Exploited https://www.wordfence.com/blog/2017/02/rapid-growth-in-rest-api-defacements/ Cryptographically Secure PHP Development https://paragonie.com/blog/2017/02/cryptographically-secure-php-development DEV522 Web Application Security Essentials https://www.sans.org/event/sans-2017/course/defending-web-applications-security-essentials
ISC StormCast for Friday, February 10th 2017
F5 Big IP Ticketbleed Vulnerability https://filippo.io/Ticketbleed/ CryptoShield Ransomware from Rig EK https://isc.sans.edu/forums/diary/CryptoShield+Ransomware+from+Rig+EK/22047/ Hancitor/Pony Malspam https://isc.sans.edu/forums/diary/HancitorPony+malspam/22053/ Apple Retaining Old Browser History Data https://blog.elcomsoft.com/2017/02/elcomsoft-extracts-deleted-safari-browsing-history-from-icloud/#more-3769 Brute Forcing LUKS Passwords https://0x00sec.org/t/breaking-encryption-hashed-passwords-luks-devices/811
ISC StormCast for Friday, February 10th 2017
F5 Big IP Ticketbleed Vulnerability https://filippo.io/Ticketbleed/ CryptoShield Ransomware from Rig EK https://isc.sans.edu/forums/diary/CryptoShield+Ransomware+from+Rig+EK/22047/ Hancitor/Pony Malspam https://isc.sans.edu/forums/diary/HancitorPony+malspam/22053/ Apple Retaining Old Browser History Data https://blog.elcomsoft.com/2017/02/elcomsoft-extracts-deleted-safari-browsing-history-from-icloud/#more-3769 Brute Forcing LUKS Passwords https://0x00sec.org/t/breaking-encryption-hashed-passwords-luks-devices/811