A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

Thinking Elixir Podcast

Thinking Elixir Podcast
The Thinking Elixir podcast is a weekly show where we talk about the Elixir programming language and the community around it. We cover news and interview guests to learn more about projects and developments in the community.

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

ISC StormCast for Thursday, May 5th 2016

May 04, 2016 1:03 0.8 MB Downloads: 0

Malicious Ads Seens On CBS TV Stations https://blog.malwarebytes.org/threat-analysis/2016/05/cbs-affiliated-television-stations-expose-visitors-to-angler-exploit-kit/ ImageMagick Vulnerability https://isc.sans.edu/forums/diary/ImageTragick+Another+Vulnerability+Another+Nickname/21023/ Fake DDoS Threats Continue http://www.actionfraud.police.uk/news/online-extortion-demands-affecting-businesses-apr16/ Cisco Patches Tele Presence Equipment https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml Cracking PeopleSoft PS_TOKEN with oclHashcat http://blog.gosecure.ca/2016/05/04/oracle-peoplesoft-still-a-threat-for-enterprises/

ISC StormCast for Thursday, May 5th 2016

May 04, 2016 1:03 0.8 MB Downloads: 0

Malicious Ads Seens On CBS TV Stations https://blog.malwarebytes.org/threat-analysis/2016/05/cbs-affiliated-television-stations-expose-visitors-to-angler-exploit-kit/ ImageMagick Vulnerability https://isc.sans.edu/forums/diary/ImageTragick+Another+Vulnerability+Another+Nickname/21023/ Fake DDoS Threats Continue http://www.actionfraud.police.uk/news/online-extortion-demands-affecting-businesses-apr16/ Cisco Patches Tele Presence Equipment https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml Cracking PeopleSoft PS_TOKEN with oclHashcat http://blog.gosecure.ca/2016/05/04/oracle-peoplesoft-still-a-threat-for-enterprises/

ISC StormCast for Wednesday, May 4th 2016

May 04, 2016 1:39 1.42 MB Downloads: 0

OpenSSL Update Released https://isc.sans.edu/forums/diary/OpenSSL+Updates/21015/ Gerber Exploit Kit Installed By Neutrino EK https://isc.sans.edu/forums/diary/Neutrino+exploit+kit+sends+Cerber+ransomware/21017/ Image Magick Vulnerablity https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 http://www.openwall.com/lists/oss-security/2016/05/03/18 Microsoft Will No Longer Consider SHA-1 Certificates As Secure https://blogs.windows.com/msedgedev/2016/04/29/sha1-deprecation-roadmap/

ISC StormCast for Wednesday, May 4th 2016

May 04, 2016 1:39 1.42 MB Downloads: 0

OpenSSL Update Released https://isc.sans.edu/forums/diary/OpenSSL+Updates/21015/ Gerber Exploit Kit Installed By Neutrino EK https://isc.sans.edu/forums/diary/Neutrino+exploit+kit+sends+Cerber+ransomware/21017/ Image Magick Vulnerablity https://www.imagemagick.org/discourse-server/viewtopic.php?f=4&t=29588 http://www.openwall.com/lists/oss-security/2016/05/03/18 Microsoft Will No Longer Consider SHA-1 Certificates As Secure https://blogs.windows.com/msedgedev/2016/04/29/sha1-deprecation-roadmap/

ISC StormCast for Tuesday, May 3rd 2016

May 02, 2016 5:29 4.67 MB Downloads: 0

Fake Google Chrome Update Installs Malware on Android https://www.zscaler.com/blogs/research/android-infostealer-posing-fake-google-chrome-update Android May Security Bulletin https://source.android.com/security/bulletin/2016-05-01.html Google Chrome Update https://source.android.com/security/bulletin/2016-05-01.html Pwned List Got Pwned http://krebsonsecurity.com/2016/05/how-the-pwnedlist-got-pwned/

ISC StormCast for Tuesday, May 3rd 2016

May 02, 2016 5:29 4.67 MB Downloads: 0

Fake Google Chrome Update Installs Malware on Android https://www.zscaler.com/blogs/research/android-infostealer-posing-fake-google-chrome-update Android May Security Bulletin https://source.android.com/security/bulletin/2016-05-01.html Google Chrome Update https://source.android.com/security/bulletin/2016-05-01.html Pwned List Got Pwned http://krebsonsecurity.com/2016/05/how-the-pwnedlist-got-pwned/

ISC StormCast for Monday, May 2nd 2016

May 01, 2016 5:44 4.86 MB Downloads: 0

ATM Jackpotting: Analysis of ATM APIs https://securelist.com/analysis/publications/74533/malware-and-non-malware-ways-for-atm-jackpotting-extended-cut/ Reverse Engineering A ATM Machine Skimmer https://trustfoundry.net/reverse-engineering-a-discovered-atm-skimmer/ Bathroom Scale Vulnerability https://help.fitbit.com/articles/en_US/Help_article/How-do-I-update-my-Aria-scale/ Fake Mobile Payment Apps in Google Play Store https://info.phishlabs.com/blog/fraudster-phishing-users-with-malicious-mobile-apps

ISC StormCast for Monday, May 2nd 2016

May 01, 2016 5:44 4.86 MB Downloads: 0

ATM Jackpotting: Analysis of ATM APIs https://securelist.com/analysis/publications/74533/malware-and-non-malware-ways-for-atm-jackpotting-extended-cut/ Reverse Engineering A ATM Machine Skimmer https://trustfoundry.net/reverse-engineering-a-discovered-atm-skimmer/ Bathroom Scale Vulnerability https://help.fitbit.com/articles/en_US/Help_article/How-do-I-update-my-Aria-scale/ Fake Mobile Payment Apps in Google Play Store https://info.phishlabs.com/blog/fraudster-phishing-users-with-malicious-mobile-apps

ISC StormCast for Friday, April 29th 2016

April 28, 2016 5:09 4.24 MB Downloads: 0

Powershell and DNS/DHCP https://isc.sans.edu/forums/diary/DNS+and+DHCP+Recon+using+Powershell/20995/ New Version of PCI Standard Released https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2_Summary_of_Changes.pdf OpenSSL Patch Pre-Announced https://mta.openssl.org/pipermail/openssl-announce/2016-April/000069.html NTP Patches http://blog.talosintel.com/2016/04/vulnerability-spotlight-further-ntpd_27.html#more

ISC StormCast for Friday, April 29th 2016

April 28, 2016 5:09 4.24 MB Downloads: 0

Powershell and DNS/DHCP https://isc.sans.edu/forums/diary/DNS+and+DHCP+Recon+using+Powershell/20995/ New Version of PCI Standard Released https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2_Summary_of_Changes.pdf OpenSSL Patch Pre-Announced https://mta.openssl.org/pipermail/openssl-announce/2016-April/000069.html NTP Patches http://blog.talosintel.com/2016/04/vulnerability-spotlight-further-ntpd_27.html#more

ISC StormCast for Thursday, April 28th 2016

April 27, 2016 5:19 4.38 MB Downloads: 0

SAML Federated Identity Vulnerability in Office 365 http://www.economyofmechanism.com/office365-authbypass.html .AS Registry Vulnerable to Direct Object Reference https://isecguy.wordpress.com/2016/04/25/flaw-allowed-anyone-to-modify-take-control-over-any-as-domain/ Driveby Exploit Used to Deliver Android Ransomware https://www.bluecoat.com/security-blog/2016-04-25/android-exploit-delivers-dogspectus-ransomware CryptXXX Decrypt Tool https://support.kaspersky.com/viruses/disinfection/8547?_ga=1.128163404.1397432418.1454514283#block3

ISC StormCast for Thursday, April 28th 2016

April 27, 2016 5:19 4.38 MB Downloads: 0

SAML Federated Identity Vulnerability in Office 365 http://www.economyofmechanism.com/office365-authbypass.html .AS Registry Vulnerable to Direct Object Reference https://isecguy.wordpress.com/2016/04/25/flaw-allowed-anyone-to-modify-take-control-over-any-as-domain/ Driveby Exploit Used to Deliver Android Ransomware https://www.bluecoat.com/security-blog/2016-04-25/android-exploit-delivers-dogspectus-ransomware CryptXXX Decrypt Tool https://support.kaspersky.com/viruses/disinfection/8547?_ga=1.128163404.1397432418.1454514283#block3

ISC StormCast for Wednesday, April 27th 2016

April 26, 2016 5:02 4.02 MB Downloads: 0

OS X Memory Forensics https://isc.sans.edu/forums/diary/An+Introduction+to+Mac+memory+forensics/20989/ Facebook App Used to Delivery Facebook Phish http://news.netcraft.com/archives/2016/04/22/hook-like-and-sinker-facebook-serves-up-its-own-phish.html Android.Spy.277.origin Keeps Being Delivered By Google Play Store Apps http://blog.checkpoint.com/2016/04/22/in-the-wild-google-cant-close-the-door-on-android-malware/ Tool To Replay RDP Sessions From pcaps http://www.contextis.com/resources/blog/rdp-replay-code-release/ Juniper Update http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727&cat=SIRT_1&actp=LIST RouterSploit Router Exploit Framework https://github.com/reverse-shell/routersploit

ISC StormCast for Wednesday, April 27th 2016

April 26, 2016 5:02 4.02 MB Downloads: 0

OS X Memory Forensics https://isc.sans.edu/forums/diary/An+Introduction+to+Mac+memory+forensics/20989/ Facebook App Used to Delivery Facebook Phish http://news.netcraft.com/archives/2016/04/22/hook-like-and-sinker-facebook-serves-up-its-own-phish.html Android.Spy.277.origin Keeps Being Delivered By Google Play Store Apps http://blog.checkpoint.com/2016/04/22/in-the-wild-google-cant-close-the-door-on-android-malware/ Tool To Replay RDP Sessions From pcaps http://www.contextis.com/resources/blog/rdp-replay-code-release/ Juniper Update http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10727&cat=SIRT_1&actp=LIST RouterSploit Router Exploit Framework https://github.com/reverse-shell/routersploit

ISC StormCast for Tuesday, April 26th 2016

April 25, 2016 5:23 4.26 MB Downloads: 0

Details From the Breach of the Central Bank of Bangladesh http://baesystemsai.blogspot.de/2016/04/two-bytes-to-951m.html Apple Image IO Denial of Service https://www.landaire.net/blog/apple-imageio-denial-of-service/ Text Messages Used to Phish Apple IDs http://www.independent.co.uk/life-style/gadgets-and-tech/news/apple-id-password-expired-expiry-text-website-scam-phishing-a6991126.html Critical HP Data Protector Patch https://h20564.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05085988 Armada Collection (or imposter) Making Fake DDoS Threats https://blog.cloudflare.com/empty-ddos-threats-meet-the-armada-collective/