A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts
Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.
The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.
Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
ISC StormCast for Friday, April 7th 2017
Automatically Inferring Malware Signatures for Anti-Virus Assisted Attacks https://www.sec.cs.tu-bs.de/pubs/2017-asiaccs.pdf Cisco Aironet Default Credentials https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ame Intercepting Two-Factor Authentication https://breakdev.org/evilginx-advanced-phishing-with-two-factor-authentication-bypass/ QNAP NAS Vulnerabilities https://sintonen.fi/advisories/qnap-qts-multiple-rce-vulnerabilities.txt
ISC StormCast for Thursday, April 6th 2017
Whitelists: The Holy Grail of Attackers https://isc.sans.edu/forums/diary/Whitelists+The+Holy+Grail+of+Attackers/22262/ Java Struts2 Vulnerability Used To Install Ransomware https://isc.sans.edu/forums/diary/Java+Struts2+Vulnerability+Used+To+Install+Cerber+Crypto+Ransomware/22264/ Brazilian Bank Looses Control Over Domains https://threatpost.com/lessons-from-top-to-bottom-compromise-of-brazilian-bank/124770/ Google Android April Patch Day https://source.android.com/security/bulletin/2017-04-01#security-vulnerability-summary Radware Observes "BrickerBot" Destroying Devices https://security.radware.com/ddos-threats-attacks/brickerbot-pdos-permanent-denial-of-service/ Struts2 Vulnerability Webcast https://www.sans.org/webcasts/struts-shock-current-attacks-struts2-defend-104787
ISC StormCast for Thursday, April 6th 2017
Whitelists: The Holy Grail of Attackers https://isc.sans.edu/forums/diary/Whitelists+The+Holy+Grail+of+Attackers/22262/ Java Struts2 Vulnerability Used To Install Ransomware https://isc.sans.edu/forums/diary/Java+Struts2+Vulnerability+Used+To+Install+Cerber+Crypto+Ransomware/22264/ Brazilian Bank Looses Control Over Domains https://threatpost.com/lessons-from-top-to-bottom-compromise-of-brazilian-bank/124770/ Google Android April Patch Day https://source.android.com/security/bulletin/2017-04-01#security-vulnerability-summary Radware Observes "BrickerBot" Destroying Devices https://security.radware.com/ddos-threats-attacks/brickerbot-pdos-permanent-denial-of-service/ Struts2 Vulnerability Webcast https://www.sans.org/webcasts/struts-shock-current-attacks-struts2-defend-104787
ISC StormCast for Wednesday, April 5th 2017
Exploiting Broadcom's Wi-Fi Stack https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html Covert Channel Between Virtual Machines Via CPU Cache https://cmaurice.fr/pdf/ndss17_maurice.pdf 40 Vulnerabilities in Samsung Tizen https://motherboard.vice.com/en_us/article/samsung-tizen-operating-system-bugs-vulnerabilities
ISC StormCast for Wednesday, April 5th 2017
Exploiting Broadcom's Wi-Fi Stack https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html Covert Channel Between Virtual Machines Via CPU Cache https://cmaurice.fr/pdf/ndss17_maurice.pdf 40 Vulnerabilities in Samsung Tizen https://motherboard.vice.com/en_us/article/samsung-tizen-operating-system-bugs-vulnerabilities
ISC StormCast for Tuesday, April 4th 2017
Apple Releases iOS 10.3.1 to Remedy Wifi Remote Code Execution https://support.apple.com/en-us/HT207688 Practical Use of SHA1 Collisions: ISO Images https://isc.sans.edu/forums/diary/A+Practical+Use+for+a+SHA1+Collision/22257/ Microsoft Defender False Positive https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FBluber.A Cracking Weak Session Secrets https://martinfowler.com/articles/session-secret.html Skype Malvertising Advertises Fake Flash Players https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/
ISC StormCast for Tuesday, April 4th 2017
Apple Releases iOS 10.3.1 to Remedy Wifi Remote Code Execution https://support.apple.com/en-us/HT207688 Practical Use of SHA1 Collisions: ISO Images https://isc.sans.edu/forums/diary/A+Practical+Use+for+a+SHA1+Collision/22257/ Microsoft Defender False Positive https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FBluber.A Cracking Weak Session Secrets https://martinfowler.com/articles/session-secret.html Skype Malvertising Advertises Fake Flash Players https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/
ISC StormCast for Monday, April 3rd 2017
Google Discovers More LastPass Vulnerabilities; https://bugs.chromium.org/p/project-zero/issues/detail?id=1225&desc=6 Attacking KeePass https://www.slideshare.net/harmj0y/a-case-study-in-attacking-keepass https://github.com/HarmJ0y/KeeThief Bypassing Cylance http://www.blackhillsinfosec.com/?p=5792 Mimi Penguin: Extracting Credentials From Memory on Linux Tools https://github.com/huntergregal/mimipenguin Windows 2003 / IIS 6 Exploit https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html https://github.com/rapid7/metasploit-framework/pull/8162
ISC StormCast for Monday, April 3rd 2017
Google Discovers More LastPass Vulnerabilities; https://bugs.chromium.org/p/project-zero/issues/detail?id=1225&desc=6 Attacking KeePass https://www.slideshare.net/harmj0y/a-case-study-in-attacking-keepass https://github.com/HarmJ0y/KeeThief Bypassing Cylance http://www.blackhillsinfosec.com/?p=5792 Mimi Penguin: Extracting Credentials From Memory on Linux Tools https://github.com/huntergregal/mimipenguin Windows 2003 / IIS 6 Exploit https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html https://github.com/rapid7/metasploit-framework/pull/8162
ISC StormCast for Friday, March 31st 2017
Diverting built-in features for the bad https://isc.sans.edu/forums/diary/Diverting+builtin+features+for+the+bad/22250/ Fake Job Offers to GitHub Developers Include Malware http://researchcenter.paloaltonetworks.com/2017/03/unit42-dimnie-hiding-plain-sight/ Drones With Lasers! https://arxiv.org/pdf/1703.07751.pdf
ISC StormCast for Friday, March 31st 2017
Diverting built-in features for the bad https://isc.sans.edu/forums/diary/Diverting+builtin+features+for+the+bad/22250/ Fake Job Offers to GitHub Developers Include Malware http://researchcenter.paloaltonetworks.com/2017/03/unit42-dimnie-hiding-plain-sight/ Drones With Lasers! https://arxiv.org/pdf/1703.07751.pdf
ISC StormCast for Thursday, March 30th 2017
Logical and Physical Security Correlation https://isc.sans.edu/forums/diary/Logical+Physical+Security+Correlation/22243/ Recent Mirai DDoS Attacks https://www.incapsula.com/blog/new-mirai-variant-ddos-us-college.html Crusader Injects Fake Support Phone Numbers into Websites https://www.bleepingcomputer.com/news/security/adware-replaces-phone-numbers-for-security-firms-returned-in-search-results/ VMWare Closes Pwn2Own Guest Escape Vulnerabilities http://www.vmware.com/security/advisories/VMSA-2017-0006.html Apple iCloud for Windows Update https://support.apple.com/de-de/HT207607
ISC StormCast for Thursday, March 30th 2017
Logical and Physical Security Correlation https://isc.sans.edu/forums/diary/Logical+Physical+Security+Correlation/22243/ Recent Mirai DDoS Attacks https://www.incapsula.com/blog/new-mirai-variant-ddos-us-college.html Crusader Injects Fake Support Phone Numbers into Websites https://www.bleepingcomputer.com/news/security/adware-replaces-phone-numbers-for-security-firms-returned-in-search-results/ VMWare Closes Pwn2Own Guest Escape Vulnerabilities http://www.vmware.com/security/advisories/VMSA-2017-0006.html Apple iCloud for Windows Update https://support.apple.com/de-de/HT207607
ISC StormCast for Wednesday, March 29th 2017
New Exploit Variant for Recent Struts2 Vulnerability https://blog.gdssecurity.com/labs/2017/3/27/an-analysis-of-cve-2017-5638.html PoC Exploit for iBook ePub Javascript Vulnerability https://s1gnalcha0s.github.io/ibooks/epub/2017/03/27/This-book-reads-you-using-JavaScript.html Microsoft Docs.com Leak https://twitter.com/gossithedog/status/845446263244050434 Symantec SSL CA tool https://www.renditioninfosec.com/socapps/sslcheck/index.php
ISC StormCast for Wednesday, March 29th 2017
New Exploit Variant for Recent Struts2 Vulnerability https://blog.gdssecurity.com/labs/2017/3/27/an-analysis-of-cve-2017-5638.html PoC Exploit for iBook ePub Javascript Vulnerability https://s1gnalcha0s.github.io/ibooks/epub/2017/03/27/This-book-reads-you-using-JavaScript.html Microsoft Docs.com Leak https://twitter.com/gossithedog/status/845446263244050434 Symantec SSL CA tool https://www.renditioninfosec.com/socapps/sslcheck/index.php