SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) - podcast cover

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrichisc.sans.edu
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Episodes

ISC StormCast for Thursday, October 12th, 2023

CVE-2023-22515 Activately Exploited https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html curl SOCKS5 oversized hostname vulnerability CVe-2023-38545 https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304 Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608 https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-...

Oct 12, 20235 minEp 8698Transcript available on Metacast

ISC StormCast for Wednesday, October 11th, 2023

http2 rapid reset https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/ microsoft patch tuesday https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300

Oct 11, 20238 minEp 8696Transcript available on Metacast

ISC StormCast for Tuesday, October 10th, 2023

ZIP's DOSTIME and DOSDATE Formats https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296 New Magecart Campaign Abusing 404 Pages https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer Sophos Effected by Exim Flaw https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln Turn OFF This WatchGuard Feature: GuardLapse https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/...

Oct 10, 20235 minEp 8694Transcript available on Metacast

ISC StormCast for Monday, October 9th, 2023

Binary IPv6 Address Conversion https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290 Wireshark Updates https://www.wireshark.org/ Improved GitHub Secret Scanning https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/ Prerooted Android Devices https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/ curl update https://github.com/curl/curl/discussions/12026...

Oct 09, 20236 minEp 8692Transcript available on Metacast

ISC StormCast for Friday, October 6th, 2023

New tool: le-hex-to-ip.py https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284 Cisco Emergency Responder Static Credentials Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9 Loony Tunables PoC CVE-2023-4911 https://haxx.in/files/gnu-acme.py Malicious Python Packages https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/ Supermicro BMC Vulnerability https://binarly.io/posts/Binarly_REsear...

Oct 06, 20235 minEp 8690Transcript available on Metacast

ISC StormCast for Thursday, October 5th, 2023

Normal Connections https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/ Apple Patches https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280 Looney Tunables Linux Privilege Escalation https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so Atlasian Confluence Server Vulnerability https://jira.atlassian.com/browse/CONFSERVER-92475...

Oct 05, 20236 minEp 8688Transcript available on Metacast

ISC StormCast for Wednesday, October 4th, 2023

Are Local LLMs Useful in Incident Response? https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274 Pytorch Vulnerability https://github.com/advisories/GHSA-4mqg-h5jf-j9m7 BING Reads Captchas https://twitter.com/literallydenis/status/1708283962399846459 Evilproxy vs. Microsoft 365 https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/...

Oct 04, 20236 minEp 8686Transcript available on Metacast

ISC StormCast for Tuesday, October 3rd, 2023

Friendly Reminder: ZIP Metadata is Not Encrypted https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268 EXIM New Version Released https://www.exim.org/static/doc/security/CVE-2023-zdi.txt Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities Bing AI Serves Malicous Ads https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-i...

Oct 03, 20236 minEp 8684Transcript available on Metacast

ISC StormCast for Monday, October 2nd, 2023

Analyzing MIME Files: a Quick Tip https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266 Infostealers Looking for Password Files https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/ Simple Netcat Backdoor https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/ EXIM Response to the ZDI Release https://exim.org/static/doc/security/CVE-2023-zdi.txt Exploit for WS_FTP Vulnerability https://www.assetnote.io/resources/research/...

Oct 02, 20235 minEp 8682Transcript available on Metacast

ISC StormCast for Friday, September 29th, 2023

IPv4 Addresses in Little Endian Decimal Format https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256 Chrome Update fixes 0-day Vulnerability https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html Unpatched EXIM Vulnerabilities https://www.zerodayinitiative.com/advisories/ZDI-23-1469/ WS_FTP Vulnerabilities https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023...

Sep 29, 20235 minEp 8680Transcript available on Metacast

ISC StormCast for Thursday, September 28th, 2023

GPU Sidechannel Attack https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf Router Firmware Compromised for Persistent Access https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023 https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a More libwebp vulnerability confusion https://www.cve.org/CVERecord?id=CVE-2023-5129 https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp...

Sep 28, 20237 minEp 8678Transcript available on Metacast

ISC StormCast for Wednesday, September 27th, 2023

A new spint on the ZeroFont phishing technique https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248 macOS Sonoma Updates https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252...

Sep 27, 20237 minEp 8676Transcript available on Metacast

ISC StormCast for Tuesday, September 26th, 2023

LuaJIT Malware https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/ NPM systeminformation flaw https://systeminformation.io/security.html Team City Authentication Bypass https://twitter.com/ptswarm/status/1706223917008834748...

Sep 26, 20235 minEp 8674Transcript available on Metacast

ISC StormCast for Monday, September 25th, 2023

Scanning for Laravel - a PHP Framework for Web Artisants https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/ Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/ Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality BSides JAX October 14th ht...

Sep 25, 20237 minEp 8672Transcript available on Metacast

ISC StormCast for Friday, September 22nd, 2023

Apple Patches Three 0-Days https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238 WebP Vulnerability https://blog.isosceles.com/the-webp-0day/ MOVEit Transfer Service Pack https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023 Improved Passkey Support in Windows 11 https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/...

Sep 22, 20236 minEp 8670Transcript available on Metacast

ISC StormCast for Thursday, September 21st, 2023

What's Normal: DNS TTL Values https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/ CISA Highlights Snatch Ransomware https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a npm packages caught exfiltrating Kubernetes config, SSH keys https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys Nagios XI Vulnerabilities https://outpost24.com/blog/nagios-xi-vulnerabilities/...

Sep 21, 20236 minEp 8668Transcript available on Metacast

ISC StormCast for Wednesday, September 20th, 2023

Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230 Trend Micro Apex One 0-day https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US SprySOCKS Backdoor https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html GitLab Patches https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/...

Sep 20, 20235 minEp 8666Transcript available on Metacast

ISC StormCast for Tuesday, September 19th, 2023

Internet Wide Multi VPN Search from Single /24 Network https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226 iOS/iPadOS/tvOS/WatchOS Updates https://support.apple.com/en-us/HT201222 Juniper Vuln Details/Exploit CVE-2023-36845 https://vulncheck.com/blog/juniper-cve-2023-36845...

Sep 19, 20235 minEp 8664Transcript available on Metacast

ISC StormCast for Monday, September 18th, 2023

When MFA isn't actually MFA https://retool.com/blog/mfa-isnt-mfa/ QNAP Patches https://www.qnap.com/en/security-advisories?ref=security_advisory_details Chrome able to use Apple Keychain Passkeys https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/ Fortinet XSS https://fortiguard.fortinet.com/psirt/FG-IR-23-106 vBulletin XSS https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c...

Sep 18, 20236 minEp 8662Transcript available on Metacast

ISC StormCast for Friday, September 15th, 2023

DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216 Uncursing the ncurses memory corruption vulnerabilities https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/ Arbitrary code execution via Windows Themes (CVE-2023-38146) https://exploits.forsale/themebleed/ 3AM Ransomware used if LockBit Fails https://symantec-enterprise-b...

Sep 15, 20236 minEp 8660Transcript available on Metacast

ISC StormCast for Thursday, September 14th, 2023

Backdoored Free DownloadManager https://securelist.com/backdoored-free-download-manager-linux-malware/110465/ Foxit PDF Reader Updates https://www.foxit.com/support/security-bulletins.html macOS MetaStealer: New Family of Obfuscated Go Infostealers https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/ Windows 11 to Support Blocking SMB NTLM Hashes https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-su...

Sep 14, 20236 minEp 8658Transcript available on Metacast

ISC StormCast for Wednesday, September 13th, 2023

Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214 OpenSSL 1.1.1 End of Life https://www.openssl.org/blog/blog/2023/09/11/eol-111/ Adobe Updates https://helpx.adobe.com/security/security-bulletin.html...

Sep 13, 20236 minEp 8656Transcript available on Metacast

ISC StormCast for Tuesday, September 12th, 2023

Apple Patches Older Operating Systems https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210 Wi-Fi Enabled Practical Keystroke Eavesdropping https://arxiv.org/pdf/2309.03492.pdf Phishing via Google Looker Studio https://blog.checkpoint.com/security/phishing-via-google-looker-studio HPE One View Authentication Bypass https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us...

Sep 12, 20236 minEp 8654Transcript available on Metacast

ISC StormCast for Monday, September 11th, 2023

Augmenting Honeypot Logs https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204 More details about Apple 0-day https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/ Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remo...

Sep 11, 20237 minEp 8652Transcript available on Metacast

ISC StormCast for Friday, September 8th, 2023

Apple Patches 0-Days https://isc.sans.edu/diary/30200 https://support.apple.com/en-us/HT201222 iOS Fleezeware/Scareware https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198 Aruba Vulnerabilities https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt TP Link Vulnerabilities https://jvn.jp/en/vu/JVNVU99392903/...

Sep 08, 20235 minEp 8650Transcript available on Metacast

ISC StormCast for Thursday, September 7th, 2023

Security Related DNS Records https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194 Microsoft Reveleas Details about Key Loss https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ September Android Updates https://source.android.com/docs/security/bulletin/2023-09-01 Google Chrome Update https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html Atlas VPN Tunnel Termination Vulnerability https://ww...

Sep 07, 20236 minEp 8648Transcript available on Metacast

ISC StormCast for Wednesday, September 6th, 2023

Common Usernames Submitted to Honeypots https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188 TPM LUKS Bypass https://pulsesecurity.co.nz/advisories/tpm-luks-bypass Cross Tenant Impersonation Prevention and Detection https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection...

Sep 06, 20236 minEp 8646Transcript available on Metacast

ISC StormCast for Tuesday, September 5th, 2023

What is the Origin of Passwords Submitted to Honeypots https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182 Creating a YARA Rule to Detect Obfuscated Strings https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186 VMware Aria Operations for Networks Hardcoded Keys 2023-34039 https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/ https://github.com/sinsinology/CVE-2023-34039/ Wi...

Sep 05, 20236 minEp 8644Transcript available on Metacast

ISC StormCast for Friday, September 1st, 2023

The low, low cost of (committing) cybercrime https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/ Unpinnable Github Actions https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/ Exploitation of Cisco ASA SSL VPNs https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/ Splunk Vulnerabilities https://advisory.splunk.com/advisories Top Level Domain Issues https://b...

Sep 01, 20236 minEp 8642Transcript available on Metacast

ISC StormCast for Thursday, August 31st, 2023

Home Office/Small Business Hurricane Prep https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166 Notepad++ Vulnerabilities https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/ 7-Zip Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-23-1164/ BGP Error Handling Issues https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling...

Aug 31, 20236 minEp 8640Transcript available on Metacast
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) - Listen or read transcript on Metacast