A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts
Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.
The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.
Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
ISC StormCast for Friday, October 23rd 2020
BazarLoader Phishing Lures https://isc.sans.edu/forums/diary/BazarLoader+phishing+lures+plan+a+Halloween+party+get+a+bonus+and+be+fired+in+the+same+afternoon/26710/ Stalled Reviews for Secure Boot Shim https://github.com/rhboot/shim-review/issues/120 https://github.com/rhboot/shim-review/issues/102#issuecomment-698963751 Cisco Advisories https://tools.cisco.com/security/center/publicationListing.x
ISC StormCast for Thursday, October 22nd 2020
Shipping Dangerous Goods https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/ Chinese State-Sponsored Actors Exploit Same Vulnerablities as Others https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF URL Bar Spoofing Vulnerabilities https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2020.html
ISC StormCast for Thursday, October 22nd 2020
Shipping Dangerous Goods https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/ Chinese State-Sponsored Actors Exploit Same Vulnerablities as Others https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF URL Bar Spoofing Vulnerabilities https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2020.html
ISC StormCast for Wednesday, October 21st 2020
Mirai-alike Python Scanner https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/ Google Chrome Update (actively exploited vulnerability fixed) https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html QNAP Fixes ZeroLogon Vulnerability https://www.qnap.com/en/security-advisory/qsa-20-07 GravityRat Going Multi Platform https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms US Census Spoof https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020
ISC StormCast for Wednesday, October 21st 2020
Mirai-alike Python Scanner https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/ Google Chrome Update (actively exploited vulnerability fixed) https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html QNAP Fixes ZeroLogon Vulnerability https://www.qnap.com/en/security-advisory/qsa-20-07 GravityRat Going Multi Platform https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms US Census Spoof https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020
ISC StormCast for Tuesday, October 20th 2020
Out of Band MSFT Patches https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022 https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023 Adobe Magento Patches https://helpx.adobe.com/security/products/magento/apsb20-59.html Attacks against SS7 https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991 https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/
ISC StormCast for Tuesday, October 20th 2020
Out of Band MSFT Patches https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022 https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023 Adobe Magento Patches https://helpx.adobe.com/security/products/magento/apsb20-59.html Attacks against SS7 https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991 https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/
ISC StormCast for Monday, October 19th 2020
CVE-2020-5135 SonicWall Buffer Overflow https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/ Spammer Attached Mass Mailer Configuration Instead of Malware https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/ Traffic Analysis Quiz: Ugly-Wolf.net https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/ Qualcomm QCMAP Vulnerabilities https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities Discord Desktop App RCE https://mksben.l0.cm/2020/10/discord-desktop-rce.html
ISC StormCast for Monday, October 19th 2020
CVE-2020-5135 SonicWall Buffer Overflow https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/ Spammer Attached Mass Mailer Configuration Instead of Malware https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/ Traffic Analysis Quiz: Ugly-Wolf.net https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/ Qualcomm QCMAP Vulnerabilities https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities Discord Desktop App RCE https://mksben.l0.cm/2020/10/discord-desktop-rce.html
ISC StormCast for Friday, October 16th 2020
Obfuscated Python RAT https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/ BadNeighbor ICMPv6 Router Advertisement Update https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/ BlueZ Vulnerability https://www.youtube.com/watch?v=qPYrLRausSw https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html https://security.googleblog.com/ (available "soon") Zoom Rolling Out End-to-End Encryption https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/
ISC StormCast for Friday, October 16th 2020
Obfuscated Python RAT https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/ BadNeighbor ICMPv6 Router Advertisement Update https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/ BlueZ Vulnerability https://www.youtube.com/watch?v=qPYrLRausSw https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html https://security.googleblog.com/ (available "soon") Zoom Rolling Out End-to-End Encryption https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/
ISC StormCast for Thursday, October 15th 2020
TA551/Shathak Word Docs Push IcedID and Bokbot https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/ MSFT Patch Tuesday Followup https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952 Apple T2 Chip Vulnerability Confirmed https://9to5mac.com/2020/10/13/t2-exploit-team/ SAP Updates https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
ISC StormCast for Thursday, October 15th 2020
TA551/Shathak Word Docs Push IcedID and Bokbot https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/ MSFT Patch Tuesday Followup https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952 Apple T2 Chip Vulnerability Confirmed https://9to5mac.com/2020/10/13/t2-exploit-team/ SAP Updates https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196
ISC StormCast for Wednesday, October 14th 2020
Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/ Adobe Updates https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
ISC StormCast for Wednesday, October 14th 2020
Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/ Adobe Updates https://helpx.adobe.com/security/products/flash-player/apsb20-58.html