A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Similar Podcasts

Elixir Outlaws

Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.

The Cynical Developer

The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career, through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.

ThunderCast

ThunderCast
An inside look at the making of Mozilla Thunderbird, and community-driven conversations with our friends in the open-source software space.

ISC StormCast for Tuesday, November 14th, 2023

November 13, 2023 5:04 4.57 MB Downloads: 0

Noticing command control channels by reviewing DNS protocols https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396 Passive SSH Key Compromise via Lattices https://eprint.iacr.org/2023/1711.pdf Juniper Vulnerabilities Exploited https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US

ISC StormCast for Monday, November 13th, 2023

November 12, 2023 5:46 5.15 MB Downloads: 0

Routers Targeted for Gafgyt Botnet https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/ ScreenConnect used to Attack Healthcare https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack Fake Skills Assessment Portals Associated with Sapphire Sleet https://twitter.com/MsftSecIntel/status/1722316019920728437 OpenVPN Access Server Vulnerabilities https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/

ISC StormCast for Monday, November 13th, 2023

November 12, 2023 5:46 5.15 MB Downloads: 0

Routers Targeted for Gafgyt Botnet https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/ ScreenConnect used to Attack Healthcare https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack Fake Skills Assessment Portals Associated with Sapphire Sleet https://twitter.com/MsftSecIntel/status/1722316019920728437 OpenVPN Access Server Vulnerabilities https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/

ISC StormCast for Friday, November 10th, 2023

November 09, 2023 5:25 4.86 MB Downloads: 0

Visual Examples of Code Injection https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388 SysAid Exploited by Cl0p Ransomware (CVE-2023-47246) https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification WS_FTP Server Update CVE-2023-42659 https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023 Malvertiser copies PC news site to delivery infostealer https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer pyArrow/Apache Arrow Vulnerability https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n

ISC StormCast for Friday, November 10th, 2023

November 09, 2023 5:25 4.86 MB Downloads: 0

Visual Examples of Code Injection https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388 SysAid Exploited by Cl0p Ransomware (CVE-2023-47246) https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification WS_FTP Server Update CVE-2023-42659 https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023 Malvertiser copies PC news site to delivery infostealer https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer pyArrow/Apache Arrow Vulnerability https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n

ISC StormCast for Thursday, November 9th, 2023

November 08, 2023 5:21 4.8 MB Downloads: 0

Example of a Phishing Campaing Project File https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384 Cryptomining with Microsoft Azure Automation Services https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure Windows 11 Insider Changing Firewall Behaviour https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/ CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog

ISC StormCast for Thursday, November 9th, 2023

November 08, 2023 5:21 4.8 MB Downloads: 0

Example of a Phishing Campaing Project File https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384 Cryptomining with Microsoft Azure Automation Services https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure Windows 11 Insider Changing Firewall Behaviour https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/ CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog

ISC StormCast for Wednesday, November 8th, 2023

November 07, 2023 6:22 5.65 MB Downloads: 0

What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR) https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380 BlueNoroff macOS Malware https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/ Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130

ISC StormCast for Wednesday, November 8th, 2023

November 07, 2023 6:22 5.65 MB Downloads: 0

What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR) https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380 BlueNoroff macOS Malware https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/ Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130

ISC StormCast for Tuesday, November 7th, 2023

November 06, 2023 6:11 5.5 MB Downloads: 0

Confluence CVe-2023-22518 Exploited https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376 Google Threat Horizons Report https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/ Veeam Update https://www.veeam.com/kb4508 QNAP Update https://www.qnap.com/de-de/security-advisory/qsa-23-35

ISC StormCast for Tuesday, November 7th, 2023

November 06, 2023 6:11 5.5 MB Downloads: 0

Confluence CVe-2023-22518 Exploited https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376 Google Threat Horizons Report https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/ Veeam Update https://www.veeam.com/kb4508 QNAP Update https://www.qnap.com/de-de/security-advisory/qsa-23-35

ISC StormCast for Monday, November 6th, 2023

November 05, 2023 7:07 6.28 MB Downloads: 0

New Microsoft Exchange Zero Days https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/ StripedFly: Perennially Flying under the Radar https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/ Send My: Sending Data over Apple's Find My Network https://github.com/positive-security/send-my

ISC StormCast for Monday, November 6th, 2023

November 05, 2023 7:07 6.28 MB Downloads: 0

New Microsoft Exchange Zero Days https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/ StripedFly: Perennially Flying under the Radar https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/ Send My: Sending Data over Apple's Find My Network https://github.com/positive-security/send-my

ISC StormCast for Friday, November 3rd, 2023

November 02, 2023 5:22 4.82 MB Downloads: 0

Quick Tip for Artificially Inflated PE Files https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370 Apache ActiveMQ Flaw Exploited https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/ Critical Firepower Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN Dozens of npm Packages Caught Attempting to Deploy Reverse Shell https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/

ISC StormCast for Friday, November 3rd, 2023

November 02, 2023 5:22 4.82 MB Downloads: 0

Quick Tip for Artificially Inflated PE Files https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370 Apache ActiveMQ Flaw Exploited https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/ Critical Firepower Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN Dozens of npm Packages Caught Attempting to Deploy Reverse Shell https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/