A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts
Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.
The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.
Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
ISC StormCast for Friday, March 17th 2017
Certain Ubiquity Equipment Vulnerable to CSRF/Code Execution https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170316-0_Ubiquiti_Networks_authenticated_command_injection_v10.txt Proton Mac OS RAT https://www.cybersixgill.com/proton-a-new-mac-os-rat/ Linux Kernel n_hdlc Privilege Escalation http://seclists.org/oss-sec/2017/q1/569 VMWare Copy/Paste Exploit Fixed https://www.vmware.com/security/advisories/VMSA-2017-0005.html
ISC StormCast for Thursday, March 16th 2017
Twitter App "Twitter Counter" Compromise Leads to Unauthorized Tweets From a Large Number of Accounts https://twitter.com/thecounter Telegram and WhatsApp Image Vulnerability http://blog.checkpoint.com/2017/03/15/check-point-discloses-vulnerability-whatsapp-telegram/ RSA Panel Webcast https://cc.readytalk.com/registration/#/?meeting=6oowksc223hm&campaign=ijmt1z8qsc1q
ISC StormCast for Thursday, March 16th 2017
Twitter App "Twitter Counter" Compromise Leads to Unauthorized Tweets From a Large Number of Accounts https://twitter.com/thecounter Telegram and WhatsApp Image Vulnerability http://blog.checkpoint.com/2017/03/15/check-point-discloses-vulnerability-whatsapp-telegram/ RSA Panel Webcast https://cc.readytalk.com/registration/#/?meeting=6oowksc223hm&campaign=ijmt1z8qsc1q
ISC StormCast for Wednesday, March 15th 2017
Microsoft's Double Patch Tuesday https://isc.sans.edu/forums/diary/February+and+March+Microsoft+Patch+Tuesday/22185/
ISC StormCast for Wednesday, March 15th 2017
Microsoft's Double Patch Tuesday https://isc.sans.edu/forums/diary/February+and+March+Microsoft+Patch+Tuesday/22185/
ISC StormCast for Tuesday, March 14th 2017
Creating SHA3 Hashes with sigs.py https://isc.sans.edu/forums/diary/New+tool+sigspy/22181/ Canada Revenue Agency Website Attacked / Down over Struts2 http://www.cbc.ca/news/politics/cra-internet-vulnerability-government-1.4022591 Webkit Exploit Adobted to Nintendo Switch https://www.youtube.com/watch?v=xkdPjbaLngE Analysis of Outdated Javascript Libraries on the Web http://www.ccs.neu.edu/home/arshad/publications/ndss2017jslibs.pdf Github Enterprise SAML Authentication Bypass http://www.economyofmechanism.com/github-saml
ISC StormCast for Tuesday, March 14th 2017
Creating SHA3 Hashes with sigs.py https://isc.sans.edu/forums/diary/New+tool+sigspy/22181/ Canada Revenue Agency Website Attacked / Down over Struts2 http://www.cbc.ca/news/politics/cra-internet-vulnerability-government-1.4022591 Webkit Exploit Adobted to Nintendo Switch https://www.youtube.com/watch?v=xkdPjbaLngE Analysis of Outdated Javascript Libraries on the Web http://www.ccs.neu.edu/home/arshad/publications/ndss2017jslibs.pdf Github Enterprise SAML Authentication Bypass http://www.economyofmechanism.com/github-saml
ISC StormCast for Monday, March 13th 2017
Issues With Out Of Date Geo Location Databases https://isc.sans.edu/forums/diary/The+Side+Effect+of+GeoIP+Filters/22173/ Recovering Mobile Device PINs via Thermal Images http://www.mkhamis.com/data/papers/abdelrahman2017chi.pdf Unmasking Randomized MAC Addresses https://arxiv.org/abs/1703.02874v1 Mobile Phone Supply Chain Attacks http://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/
ISC StormCast for Monday, March 13th 2017
Issues With Out Of Date Geo Location Databases https://isc.sans.edu/forums/diary/The+Side+Effect+of+GeoIP+Filters/22173/ Recovering Mobile Device PINs via Thermal Images http://www.mkhamis.com/data/papers/abdelrahman2017chi.pdf Unmasking Randomized MAC Addresses https://arxiv.org/abs/1703.02874v1 Mobile Phone Supply Chain Attacks http://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/
ISC StormCast for Friday, March 10th 2017
Struts 2 Update https://isc.sans.edu/forums/diary/Critical+Apache+Struts+2+Vulnerability+Patch+Now/22169/ Exploits Against Haraka Mail Server https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py Android Password Stealing Apps http://www.welivesecurity.com/2017/03/09/new-instagram-credentials-stealers-discovered-google-play/ Drupal Services Module Vulnerability and Exploit https://www.ambionics.io/blog/drupal-services-module-rce https://www.drupal.org/node/2858847
ISC StormCast for Friday, March 10th 2017
Struts 2 Update https://isc.sans.edu/forums/diary/Critical+Apache+Struts+2+Vulnerability+Patch+Now/22169/ Exploits Against Haraka Mail Server https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py Android Password Stealing Apps http://www.welivesecurity.com/2017/03/09/new-instagram-credentials-stealers-discovered-google-play/ Drupal Services Module Vulnerability and Exploit https://www.ambionics.io/blog/drupal-services-module-rce https://www.drupal.org/node/2858847
ISC StormCast for Thursday, March 9th 2017
Security Researches Target Nintendo Switch https://twitter.com/qlutoo https://www.youtube.com/watch?v=CwdDN1kA93Q&feature=youtu.be Dockerscan https://github.com/cr0hn/dockerscan 1 in 5 Websites still rely on SHA-1 Based Certificates http://www.theregister.co.uk/2017/03/08/sha1_certificate_survey/ Not All Malware Samples Are Complex https://isc.sans.edu/forums/diary/Not+All+Malware+Samples+Are+Complex/22163/ Struts Vulnerability Included in Metasploit https://github.com/rapid7/metasploit-framework/issues/8064 https://cwiki.apache.org/confluence/display/WW/S2-045?from=groupmessage
ISC StormCast for Thursday, March 9th 2017
Security Researches Target Nintendo Switch https://twitter.com/qlutoo https://www.youtube.com/watch?v=CwdDN1kA93Q&feature=youtu.be Dockerscan https://github.com/cr0hn/dockerscan 1 in 5 Websites still rely on SHA-1 Based Certificates http://www.theregister.co.uk/2017/03/08/sha1_certificate_survey/ Not All Malware Samples Are Complex https://isc.sans.edu/forums/diary/Not+All+Malware+Samples+Are+Complex/22163/ Struts Vulnerability Included in Metasploit https://github.com/rapid7/metasploit-framework/issues/8064 https://cwiki.apache.org/confluence/display/WW/S2-045?from=groupmessage
ISC StormCast for Wednesday, March 8th 2017
CIA Leak (note that link lead directly to leaked documents) https://wikileaks.com/ciav7p1/ From Shamoon To Stonedrill: Evolution of Wipers Attacking Saudi Organziations https://securelist.com/files/2017/03/Report_Shamoon_StoneDrill_final.pdf WordPress Update https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/ Reading Secret Keys From SGX Enclaves https://arxiv.org/abs/1702.08719
ISC StormCast for Wednesday, March 8th 2017
CIA Leak (note that link lead directly to leaked documents) https://wikileaks.com/ciav7p1/ From Shamoon To Stonedrill: Evolution of Wipers Attacking Saudi Organziations https://securelist.com/files/2017/03/Report_Shamoon_StoneDrill_final.pdf WordPress Update https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/ Reading Secret Keys From SGX Enclaves https://arxiv.org/abs/1702.08719