A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Similar Podcasts
Elixir Outlaws
Elixir Outlaws is an informal discussion about interesting things happening in Elixir. Our goal is to capture the spirit of a conference hallway discussion in a podcast.
The Cynical Developer
A UK based Technology and Software Developer Podcast that helps you to improve your development knowledge and career,
through explaining the latest and greatest in development technology and providing you with what you need to succeed as a developer.
ThunderCast
An inside look at the making of Mozilla Thunderbird, and community-driven conversations with our friends in the open-source software space.
ISC StormCast for Tuesday, October 24th, 2023
Apple TV IPv6 DoS https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336 Squid Patches https://github.com/squid-cache/squid/security/advisories Critical Citrix Update https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/ Cisco Vulnerablity Updates CVE-2023-20198 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
ISC StormCast for Monday, October 23rd, 2023
base64dump.py Handles More Encodings Than Just BASE64 https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332 Stealing OAuth Tokens via Open Redirects https://eval.blog/research/microsoft-account-token-leaks-in-harvest/ VMWare Patches https://www.vmware.com/security/advisories.html Solarwinds Patches https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm
ISC StormCast for Monday, October 23rd, 2023
base64dump.py Handles More Encodings Than Just BASE64 https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332 Stealing OAuth Tokens via Open Redirects https://eval.blog/research/microsoft-account-token-leaks-in-harvest/ VMWare Patches https://www.vmware.com/security/advisories.html Solarwinds Patches https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm
ISC StormCast for Friday, October 20th, 2023
Honeypot Update https://github.com/DShield-ISC/dshield/blob/main/README.md Malicious Keepass Ads https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website Malicious JavaScript in Smart Contracts https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16
ISC StormCast for Friday, October 20th, 2023
Honeypot Update https://github.com/DShield-ISC/dshield/blob/main/README.md Malicious Keepass Ads https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website Malicious JavaScript in Smart Contracts https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16
ISC StormCast for Thursday, October 19th, 2023
Hiding in Hex https://isc.sans.edu/diary/Hiding%20in%20Hex/30322 Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2023.html Citrix Vulnerability Exploited CVE-2023-4966 https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966 Exposed Jupyter Notebooks Exploited https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/
ISC StormCast for Thursday, October 19th, 2023
Hiding in Hex https://isc.sans.edu/diary/Hiding%20in%20Hex/30322 Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2023.html Citrix Vulnerability Exploited CVE-2023-4966 https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966 Exposed Jupyter Notebooks Exploited https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/
ISC StormCast for Wednesday, October 18th, 2023
Changes to SMS Delivery and How it Effects MFA and Phishing https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320 Fake Traffic Tickets with QR Code https://twitter.com/polizeiberlin/status/1713867011837567411 Synology NAS DSM Account Takeover: Not Random Randomnumbers https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure Milesight Routers CVe-2023-43261 https://github.com/win3zz/CVE-2023-43261
ISC StormCast for Wednesday, October 18th, 2023
Changes to SMS Delivery and How it Effects MFA and Phishing https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320 Fake Traffic Tickets with QR Code https://twitter.com/polizeiberlin/status/1713867011837567411 Synology NAS DSM Account Takeover: Not Random Randomnumbers https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure Milesight Routers CVe-2023-43261 https://github.com/win3zz/CVE-2023-43261
ISC StormCast for Tuesday, October 17th, 2023
Are Typos Still relevant As An Indicator of Phishing https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316 Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/ Mail traffic to cancelled domain names https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names SAMBA Update https://www.samba.org/samba/history/security.html
ISC StormCast for Tuesday, October 17th, 2023
Are Typos Still relevant As An Indicator of Phishing https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316 Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/ Mail traffic to cancelled domain names https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names SAMBA Update https://www.samba.org/samba/history/security.html
ISC StormCast for Monday, October 16th, 2023
What's Normal: Odd Mac Addresses https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/ Domain Name Used as Password Captured by DShield Sensor https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/ PoC Exploit for CVE-2023-41993 https://github.com/po6ix/POC-for-CVE-2023-41993 AvosLocker Ransomware Details https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf DarkGate Spreading via Skype and Teams https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html
ISC StormCast for Monday, October 16th, 2023
What's Normal: Odd Mac Addresses https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/ Domain Name Used as Password Captured by DShield Sensor https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/ PoC Exploit for CVE-2023-41993 https://github.com/po6ix/POC-for-CVE-2023-41993 AvosLocker Ransomware Details https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf DarkGate Spreading via Skype and Teams https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html
ISC StormCast for Friday, October 13th, 2023
SeroXen RAT in Typosquatted NuGet Packages https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/ Hexadecimal IP Addresses https://asec.ahnlab.com/en/57635/ Juniper Vulnerabilities https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories] Unpatched Squid Vulnerabilities https://joshua.hu/squid-security-audit-35-0days-45-exploits BSIDES Jacksonville https://bsidesjax.org
ISC StormCast for Friday, October 13th, 2023
SeroXen RAT in Typosquatted NuGet Packages https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/ Hexadecimal IP Addresses https://asec.ahnlab.com/en/57635/ Juniper Vulnerabilities https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories] Unpatched Squid Vulnerabilities https://joshua.hu/squid-security-audit-35-0days-45-exploits BSIDES Jacksonville https://bsidesjax.org