A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts
Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.
Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
Linux For Everyone
A show about the thrilling world of desktop Linux, open-source software, and the community creating it. For beginners and veterans alike! Hosted by Jason Evangelho, Jerry Morrison and Schykle.
ISC StormCast for Monday, February 13th 2017
Vulnerabilities in Samsung KNOX https://googleprojectzero.blogspot.de/2017/02/lifting-hyper-visor-bypassing-samsungs.html Auditing MongoDB Configurations https://github.com/stampery/mongoaudit Reversing Javascript https://isc.sans.edu/forums/diary/Analysis+of+a+Suspicious+Piece+of+JavaScript/22056/ Wordpress REST API Flaw Widely Exploited https://www.wordfence.com/blog/2017/02/rapid-growth-in-rest-api-defacements/ Cryptographically Secure PHP Development https://paragonie.com/blog/2017/02/cryptographically-secure-php-development DEV522 Web Application Security Essentials https://www.sans.org/event/sans-2017/course/defending-web-applications-security-essentials
ISC StormCast for Monday, February 13th 2017
Vulnerabilities in Samsung KNOX https://googleprojectzero.blogspot.de/2017/02/lifting-hyper-visor-bypassing-samsungs.html Auditing MongoDB Configurations https://github.com/stampery/mongoaudit Reversing Javascript https://isc.sans.edu/forums/diary/Analysis+of+a+Suspicious+Piece+of+JavaScript/22056/ Wordpress REST API Flaw Widely Exploited https://www.wordfence.com/blog/2017/02/rapid-growth-in-rest-api-defacements/ Cryptographically Secure PHP Development https://paragonie.com/blog/2017/02/cryptographically-secure-php-development DEV522 Web Application Security Essentials https://www.sans.org/event/sans-2017/course/defending-web-applications-security-essentials
ISC StormCast for Friday, February 10th 2017
F5 Big IP Ticketbleed Vulnerability https://filippo.io/Ticketbleed/ CryptoShield Ransomware from Rig EK https://isc.sans.edu/forums/diary/CryptoShield+Ransomware+from+Rig+EK/22047/ Hancitor/Pony Malspam https://isc.sans.edu/forums/diary/HancitorPony+malspam/22053/ Apple Retaining Old Browser History Data https://blog.elcomsoft.com/2017/02/elcomsoft-extracts-deleted-safari-browsing-history-from-icloud/#more-3769 Brute Forcing LUKS Passwords https://0x00sec.org/t/breaking-encryption-hashed-passwords-luks-devices/811
ISC StormCast for Friday, February 10th 2017
F5 Big IP Ticketbleed Vulnerability https://filippo.io/Ticketbleed/ CryptoShield Ransomware from Rig EK https://isc.sans.edu/forums/diary/CryptoShield+Ransomware+from+Rig+EK/22047/ Hancitor/Pony Malspam https://isc.sans.edu/forums/diary/HancitorPony+malspam/22053/ Apple Retaining Old Browser History Data https://blog.elcomsoft.com/2017/02/elcomsoft-extracts-deleted-safari-browsing-history-from-icloud/#more-3769 Brute Forcing LUKS Passwords https://0x00sec.org/t/breaking-encryption-hashed-passwords-luks-devices/811
ISC StormCast for Thursday, February 9th 2017
Cloud Metadata URLs https://isc.sans.edu/forums/diary/Cloud+Metadata+Urls/22046/ Intel Atom C2000 Chip Failures http://www.theregister.co.uk/2017/02/06/cisco_intel_decline_to_link_product_warning_to_faulty_chip/ More W-2 Scams, Now Combined With Wire Transfer Scams https://nakedsecurity.sophos.com/2017/02/08/beware-the-latest-tax-season-spear-phishing-scam/ Macro Malware Coming to MacOS https://objective-see.com/blog/blog_0x17.html
ISC StormCast for Thursday, February 9th 2017
Cloud Metadata URLs https://isc.sans.edu/forums/diary/Cloud+Metadata+Urls/22046/ Intel Atom C2000 Chip Failures http://www.theregister.co.uk/2017/02/06/cisco_intel_decline_to_link_product_warning_to_faulty_chip/ More W-2 Scams, Now Combined With Wire Transfer Scams https://nakedsecurity.sophos.com/2017/02/08/beware-the-latest-tax-season-spear-phishing-scam/ Macro Malware Coming to MacOS https://objective-see.com/blog/blog_0x17.html
ISC StormCast for Wednesday, February 8th 2017
Using Emojis as Passwords https://isc.sans.edu/forums/diary/My+Password+is+taco+Using+Emojis+for+Stronger+Passwords/22042/ Popular iOS Applications Not Using TLS https://medium.com/@chronic_9612/76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-2c9a2409dd1#.nv0mf6w4e Web Bluetooth Security Model https://medium.com/@jyasskin/the-web-bluetooth-security-model-666b4e7eed2#.kqtxdk70h E-Mail Spoofing in GMail https://www.linkedin.com/pulse/aware-sender-spoofing-amongst-gmail-users-renato-marinho
ISC StormCast for Wednesday, February 8th 2017
Using Emojis as Passwords https://isc.sans.edu/forums/diary/My+Password+is+taco+Using+Emojis+for+Stronger+Passwords/22042/ Popular iOS Applications Not Using TLS https://medium.com/@chronic_9612/76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-2c9a2409dd1#.nv0mf6w4e Web Bluetooth Security Model https://medium.com/@jyasskin/the-web-bluetooth-security-model-666b4e7eed2#.kqtxdk70h E-Mail Spoofing in GMail https://www.linkedin.com/pulse/aware-sender-spoofing-amongst-gmail-users-renato-marinho
ISC StormCast for Tuesday, February 7th 2017
Malicous or Not? Help Me Decide https://isc.sans.edu/forums/diary/Malicious+Or+Not+You+decide/22040/ OpenBSD Http Server DoS Vulnerability https://pierrekim.github.io/blog/2017-02-07-openbsd-httpd-CVE-2017-5850.html Bypassing Tor Browser Via Windows DRM https://www.myhackerhouse.com/windows_drm_vs_torbrowser/ Freedom Hosting II Compromise https://www.scmagazineuk.com/major-dark-web-host-hacked-381000-sets-of-user-details-leaked-online/article/636259/
ISC StormCast for Tuesday, February 7th 2017
Malicous or Not? Help Me Decide https://isc.sans.edu/forums/diary/Malicious+Or+Not+You+decide/22040/ OpenBSD Http Server DoS Vulnerability https://pierrekim.github.io/blog/2017-02-07-openbsd-httpd-CVE-2017-5850.html Bypassing Tor Browser Via Windows DRM https://www.myhackerhouse.com/windows_drm_vs_torbrowser/ Freedom Hosting II Compromise https://www.scmagazineuk.com/major-dark-web-host-hacked-381000-sets-of-user-details-leaked-online/article/636259/
ISC StormCast for Monday, February 6th 2017
Base64 Encoded Malware Samples on Pastebin https://isc.sans.edu/forums/diary/Many+Malware+Samples+Found+on+Pastebin/22036/ Cisco Recaling Meraki Access Points over Fatal Hardware Flaw http://www.cisco.com/c/en/us/support/web/clock-signal.html SQL Injection Vulnerability in McAfee e Policy Orchastrator https://kc.mcafee.com/corporate/index?page=content&id=SB10187 Update from Microsoft on SMB 3 Vulnerability https://threatpost.com/microsoft-waits-for-patch-tuesday-to-fix-smb-zero-day/123541/ Malicious Files Sent via Whatsapp to Target Indian Military http://economictimes.indiatimes.com/news/defence/defence-security-forces-alerted-against-whatsapp-virus/articleshow/56258702.cms
ISC StormCast for Monday, February 6th 2017
Base64 Encoded Malware Samples on Pastebin https://isc.sans.edu/forums/diary/Many+Malware+Samples+Found+on+Pastebin/22036/ Cisco Recaling Meraki Access Points over Fatal Hardware Flaw http://www.cisco.com/c/en/us/support/web/clock-signal.html SQL Injection Vulnerability in McAfee e Policy Orchastrator https://kc.mcafee.com/corporate/index?page=content&id=SB10187 Update from Microsoft on SMB 3 Vulnerability https://threatpost.com/microsoft-waits-for-patch-tuesday-to-fix-smb-zero-day/123541/ Malicious Files Sent via Whatsapp to Target Indian Military http://economictimes.indiatimes.com/news/defence/defence-security-forces-alerted-against-whatsapp-virus/articleshow/56258702.cms
ISC StormCast for Friday, February 3rd 2017
SMB 3 0-Day DoS Exploit https://isc.sans.edu/forums/diary/Windows+SMBv3+Denial+of+Service+Proof+of+Concept+0+Day+Exploit/22029/ WordPress Update Silently Fixes Security Flaw https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/ Webroot Update Patches BSOD Flaw https://community.webroot.com/t5/Product-Questions/BSOD-0x50-PAGE-FAULT-IN-NONPAGED-AREA/td-p/284302?sf54120672=1&sf54123115=1 Google Adds Support for Mandatory Two-Factor Authentication to G-Suite https://security.googleblog.com/2017/02/better-and-more-usable-protection-from.html Cisco Prime Home Vulnerablity https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-prime-home
ISC StormCast for Friday, February 3rd 2017
SMB 3 0-Day DoS Exploit https://isc.sans.edu/forums/diary/Windows+SMBv3+Denial+of+Service+Proof+of+Concept+0+Day+Exploit/22029/ WordPress Update Silently Fixes Security Flaw https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/ Webroot Update Patches BSOD Flaw https://community.webroot.com/t5/Product-Questions/BSOD-0x50-PAGE-FAULT-IN-NONPAGED-AREA/td-p/284302?sf54120672=1&sf54123115=1 Google Adds Support for Mandatory Two-Factor Authentication to G-Suite https://security.googleblog.com/2017/02/better-and-more-usable-protection-from.html Cisco Prime Home Vulnerablity https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-prime-home
ISC StormCast for Thursday, February 2nd 2017
Multiple Vulnerabilites in tcpdump https://isc.sans.edu/forums/diary/Multiple+Vulnerabilities+in+tcpdump/22017/ Quick Analysis of Data Left Available by Attackers https://isc.sans.edu/forums/diary/Quick+Analysis+of+Data+Left+Available+by+Attackers/22015/ Securing The Human Ouch! Newsletter https://securingthehuman.sans.org/ouch/ Redis CSRF Vulnerability Exploit https://github.com/dxa4481/whatsinmyredis