A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

Thinking Elixir Podcast

Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

ISC StormCast for Friday, March 17th 2017

March 16, 2017 6:04 5.1 MB Downloads: 0

Certain Ubiquity Equipment Vulnerable to CSRF/Code Execution https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170316-0_Ubiquiti_Networks_authenticated_command_injection_v10.txt Proton Mac OS RAT https://www.cybersixgill.com/proton-a-new-mac-os-rat/ Linux Kernel n_hdlc Privilege Escalation http://seclists.org/oss-sec/2017/q1/569 VMWare Copy/Paste Exploit Fixed https://www.vmware.com/security/advisories/VMSA-2017-0005.html

ISC StormCast for Thursday, March 16th 2017

March 15, 2017 6:31 5.49 MB Downloads: 0

Twitter App "Twitter Counter" Compromise Leads to Unauthorized Tweets From a Large Number of Accounts https://twitter.com/thecounter Telegram and WhatsApp Image Vulnerability http://blog.checkpoint.com/2017/03/15/check-point-discloses-vulnerability-whatsapp-telegram/ RSA Panel Webcast https://cc.readytalk.com/registration/#/?meeting=6oowksc223hm&campaign=ijmt1z8qsc1q

ISC StormCast for Thursday, March 16th 2017

March 15, 2017 6:31 5.49 MB Downloads: 0

Twitter App "Twitter Counter" Compromise Leads to Unauthorized Tweets From a Large Number of Accounts https://twitter.com/thecounter Telegram and WhatsApp Image Vulnerability http://blog.checkpoint.com/2017/03/15/check-point-discloses-vulnerability-whatsapp-telegram/ RSA Panel Webcast https://cc.readytalk.com/registration/#/?meeting=6oowksc223hm&campaign=ijmt1z8qsc1q

ISC StormCast for Wednesday, March 15th 2017

March 14, 2017 5:54 4.96 MB Downloads: 0

Microsoft's Double Patch Tuesday https://isc.sans.edu/forums/diary/February+and+March+Microsoft+Patch+Tuesday/22185/

ISC StormCast for Wednesday, March 15th 2017

March 14, 2017 5:54 4.96 MB Downloads: 0

Microsoft's Double Patch Tuesday https://isc.sans.edu/forums/diary/February+and+March+Microsoft+Patch+Tuesday/22185/

ISC StormCast for Tuesday, March 14th 2017

March 13, 2017 5:42 4.8 MB Downloads: 0

Creating SHA3 Hashes with sigs.py https://isc.sans.edu/forums/diary/New+tool+sigspy/22181/ Canada Revenue Agency Website Attacked / Down over Struts2 http://www.cbc.ca/news/politics/cra-internet-vulnerability-government-1.4022591 Webkit Exploit Adobted to Nintendo Switch https://www.youtube.com/watch?v=xkdPjbaLngE Analysis of Outdated Javascript Libraries on the Web http://www.ccs.neu.edu/home/arshad/publications/ndss2017jslibs.pdf Github Enterprise SAML Authentication Bypass http://www.economyofmechanism.com/github-saml

ISC StormCast for Tuesday, March 14th 2017

March 13, 2017 5:42 4.8 MB Downloads: 0

Creating SHA3 Hashes with sigs.py https://isc.sans.edu/forums/diary/New+tool+sigspy/22181/ Canada Revenue Agency Website Attacked / Down over Struts2 http://www.cbc.ca/news/politics/cra-internet-vulnerability-government-1.4022591 Webkit Exploit Adobted to Nintendo Switch https://www.youtube.com/watch?v=xkdPjbaLngE Analysis of Outdated Javascript Libraries on the Web http://www.ccs.neu.edu/home/arshad/publications/ndss2017jslibs.pdf Github Enterprise SAML Authentication Bypass http://www.economyofmechanism.com/github-saml

ISC StormCast for Monday, March 13th 2017

March 12, 2017 6:36 5.56 MB Downloads: 0

Issues With Out Of Date Geo Location Databases https://isc.sans.edu/forums/diary/The+Side+Effect+of+GeoIP+Filters/22173/ Recovering Mobile Device PINs via Thermal Images http://www.mkhamis.com/data/papers/abdelrahman2017chi.pdf Unmasking Randomized MAC Addresses https://arxiv.org/abs/1703.02874v1 Mobile Phone Supply Chain Attacks http://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/

ISC StormCast for Monday, March 13th 2017

March 12, 2017 6:36 5.56 MB Downloads: 0

Issues With Out Of Date Geo Location Databases https://isc.sans.edu/forums/diary/The+Side+Effect+of+GeoIP+Filters/22173/ Recovering Mobile Device PINs via Thermal Images http://www.mkhamis.com/data/papers/abdelrahman2017chi.pdf Unmasking Randomized MAC Addresses https://arxiv.org/abs/1703.02874v1 Mobile Phone Supply Chain Attacks http://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/

ISC StormCast for Friday, March 10th 2017

March 09, 2017 5:18 4.46 MB Downloads: 0

Struts 2 Update https://isc.sans.edu/forums/diary/Critical+Apache+Struts+2+Vulnerability+Patch+Now/22169/ Exploits Against Haraka Mail Server https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py Android Password Stealing Apps http://www.welivesecurity.com/2017/03/09/new-instagram-credentials-stealers-discovered-google-play/ Drupal Services Module Vulnerability and Exploit https://www.ambionics.io/blog/drupal-services-module-rce https://www.drupal.org/node/2858847

ISC StormCast for Friday, March 10th 2017

March 09, 2017 5:18 4.46 MB Downloads: 0

Struts 2 Update https://isc.sans.edu/forums/diary/Critical+Apache+Struts+2+Vulnerability+Patch+Now/22169/ Exploits Against Haraka Mail Server https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py Android Password Stealing Apps http://www.welivesecurity.com/2017/03/09/new-instagram-credentials-stealers-discovered-google-play/ Drupal Services Module Vulnerability and Exploit https://www.ambionics.io/blog/drupal-services-module-rce https://www.drupal.org/node/2858847

ISC StormCast for Thursday, March 9th 2017

March 08, 2017 5:37 4.73 MB Downloads: 0

Security Researches Target Nintendo Switch https://twitter.com/qlutoo https://www.youtube.com/watch?v=CwdDN1kA93Q&feature=youtu.be Dockerscan https://github.com/cr0hn/dockerscan 1 in 5 Websites still rely on SHA-1 Based Certificates http://www.theregister.co.uk/2017/03/08/sha1_certificate_survey/ Not All Malware Samples Are Complex https://isc.sans.edu/forums/diary/Not+All+Malware+Samples+Are+Complex/22163/ Struts Vulnerability Included in Metasploit https://github.com/rapid7/metasploit-framework/issues/8064 https://cwiki.apache.org/confluence/display/WW/S2-045?from=groupmessage

ISC StormCast for Thursday, March 9th 2017

March 08, 2017 5:37 4.73 MB Downloads: 0

Security Researches Target Nintendo Switch https://twitter.com/qlutoo https://www.youtube.com/watch?v=CwdDN1kA93Q&feature=youtu.be Dockerscan https://github.com/cr0hn/dockerscan 1 in 5 Websites still rely on SHA-1 Based Certificates http://www.theregister.co.uk/2017/03/08/sha1_certificate_survey/ Not All Malware Samples Are Complex https://isc.sans.edu/forums/diary/Not+All+Malware+Samples+Are+Complex/22163/ Struts Vulnerability Included in Metasploit https://github.com/rapid7/metasploit-framework/issues/8064 https://cwiki.apache.org/confluence/display/WW/S2-045?from=groupmessage

ISC StormCast for Wednesday, March 8th 2017

March 07, 2017 6:41 5.62 MB Downloads: 0

CIA Leak (note that link lead directly to leaked documents) https://wikileaks.com/ciav7p1/ From Shamoon To Stonedrill: Evolution of Wipers Attacking Saudi Organziations https://securelist.com/files/2017/03/Report_Shamoon_StoneDrill_final.pdf WordPress Update https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/ Reading Secret Keys From SGX Enclaves https://arxiv.org/abs/1702.08719

ISC StormCast for Wednesday, March 8th 2017

March 07, 2017 6:41 5.62 MB Downloads: 0

CIA Leak (note that link lead directly to leaked documents) https://wikileaks.com/ciav7p1/ From Shamoon To Stonedrill: Evolution of Wipers Attacking Saudi Organziations https://securelist.com/files/2017/03/Report_Shamoon_StoneDrill_final.pdf WordPress Update https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/ Reading Secret Keys From SGX Enclaves https://arxiv.org/abs/1702.08719