Johannes B. Ullrich
SANS Internet Storm Center's Daily Network Security News Podcast
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Network Security News Summary for Wednesday November 29th, 2023 29.11.2023 5:37
Sharepoint Attack; MSFT removes Defender App Guard for Office; Synology , Tomcat and Chrome Vuln; Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357 https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436 Microsoft Deprecates Microsoft Defender Application Guard for Office https://learn.microsof...
Network Security News Summary for Tuesday November 28th, 2023 28.11.2023 6:37
OwnCloud Exploited; Fingerprint Reader Weakness Scans for ownCloud Vulnerability (CVE-2023-49103) https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432 Windows Hello Fingerprint Reader Weakness https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/ keywords: windows; hello; fingerprint; owncloud
Network Security News Summary for Monday November 27th, 2023 26.11.2023 6:01
DShield Birthday; Mirai Exploits; OVA Files; OpenCart Vuln; Holiday Hack Challenge DShield Birthday https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420 Mirai uses CVE-2023-1389 https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418 More Mirai Vulnerabilities https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days Analyzi...
Network Security News Summary for Friday November 17th, 2023 17.11.2023 15:25
Faster tcpdump; Zimbra Exploit Details; FortiSIEM Vuln; AI-Exploits; CrushFTP and FortiSIEM Patches; @sans_edu Research: Scott Poley; Storing Less Beyond -n: Optimizign tcpdump performance https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/ Zimbra 0-day used to target international government organizations https://blog.google/threat-analysis-group/zimbra-0-...
Network Security News Summary for Thursday November 16th, 2023 15.11.2023 5:57
MSIX to Redline; ChatGPT Code Interpreter vuln; Aruba and Netty Vulns; HARArmor @FronteggForSaaS Redline Dropped Through MSIX Package https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404 ChatGPT Code Interpreter Security Hole https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole Directory Traversal in Reactor Netty CVE-2023-34062 https://spring.io/securi...
Network Security News Summary for Wednesday November 15th, 2023 15.11.2023 7:11
Microsoft Patches; Adobe Patches; Intel CPU Glitch State Patch Microsoft Patches https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400 Adobe Updates https://helpx.adobe.com/security/security-bulletin.html Intel CPU Glitch State Patch https://lock.cmpxchg8b.com/reptar.html https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html keywords: intel;...
Network Security News Summary for Tuesday November 14th, 2023 14.11.2023 5:05
Discovering DNS C&C; Passive SSH Key Compromise; Juniper Vuln Exploited Noticing command control channels by reviewing DNS protocols https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396 Passive SSH Key Compromise via Lattices https://eprint.iacr.org/2023/1711.pdf Juniper Vulnerabilities Exploited https://supportportal.juniper.net/s/artic...
Network Security News Summary for Monday November 13th, 2023 12.11.2023 5:47
Gafgyt Update; ScreenConnect Healthcare Breach; Fake Assessment Websites Routers Targeted for Gafgyt Botnet https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/ ScreenConnect used to Attack Healthcare https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack Fake Skills Assessment Portals As...
Network Security News Summary for Friday November 10th, 2023 10.11.2023 5:26
Visualizing Code Injection; SysAid Exploit; WS_FTP Update; CPU-Z Impersonation; pyArrow Vulnerability Visual Examples of Code Injection https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388 SysAid Exploited by Cl0p Ransomware (CVE-2023-47246) https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification WS_FTP Server Update CVE-2023-42659 htt...
Network Security News Summary for Thursday November 09th, 2023 09.11.2023 5:21
Project Phishing; Azure Automation Mining; Windows Firewall Changes; SLP DoS Vuln added to KEV; Example of a Phishing Campaing Project File https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384 Cryptomining with Microsoft Azure Automation Services https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure Windows 11 Insider Changing Firewall Behaviour https...
Network Security News Summary for Wednesday November 08th, 2023 07.11.2023 6:23
Discovery of Deisgnated Resolvers; BlueNoroff macOS Malware; MSFT hardens MFA; What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR) https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380 BlueNoroff macOS Malware https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/ Emphasizing Se...
Network Security News Summary for Tuesday November 07th, 2023 07.11.2023 6:12
Confluence CVE-2023-22518 Exploited; Calender Data Exfil; Veeam and QNAP Patches Confluence CVe-2023-22518 Exploited https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376 Google Threat Horizons Report https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf https://www.sans.edu/cyber-research/boo...
Network Security News Summary for Monday November 06th, 2023 05.11.2023 7:08
Possible Exchange Flaws; Sriped Fly Botnet; Send My New Microsoft Exchange Zero Days https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/ StripedFly: Perennially Flying under the Radar https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/ Send My: Sending Data over Apple's Find My Network https://github.com/positive-s...
Network Security News Summary for Friday November 03th, 2023 03.11.2023 5:23
Inflated PE Files; ActiveMQ Exploit; Firepower Vuln; Malicious NPM; Quick Tip for Artificially Inflated PE Files https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370 Apache ActiveMQ Flaw Exploited https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-...
Network Security News Summary for Thursday November 02th, 2023 01.11.2023 5:43
ZPAQ Archives; CVSS 4.0; Slack Impersonation; MOZI Demise; URL Shorteners Malware Dropped Through a ZPAQ Archive https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/ CVSS 4.0 Now Official https://www.first.org/cvss/v4-0/index.html MOZI Botnet Killswitch https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-...
Network Security News Summary for Wednesday November 01th, 2023 01.11.2023 4:12
Anti-Sandboxing; Confluence Vuln; PyCharm Malvertisement; Thorn SFTP Vuln; Multiple Layers of Anti-Sandboxing Techniques https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362 CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-conflu...
Network Security News Summary for Tuesday October 31th, 2023 30.10.2023 6:14
Multicast DNS; Kubernetes ingress-nginx; HTTPS Upgrade; Wordpad PoC Flying under the Radar: The Privacy Impact of Mulicast DNS https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/ Kubernetes ingress-nginx vulnerability https://github.com/kubernetes/ingress-nginx/issues/10571 Google Chrome HTTPS Upgrade https://github.com/dadrian/h...
Network Security News Summary for Monday October 30th, 2023 30.10.2023 6:07
Size Matters; Spam or Phishing; iOS MAC Leaks; ZDI Summary; Octo Tempest Size Matters for Many Security Controls https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352 Spam or Phishing? Looking for Credentials and Passwords https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354 iOS Leaks MAC Address https://www.youtube.c...
Network Security News Summary for Friday October 27th, 2023 27.10.2023 6:03
IPv4 Addresses; F5 BigIP Vuln; Apple iLeakage; Adventures in Validating IPv4 Addresses https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/ BIG-IP Configuration Utility Unauthenticated Remote Code Execution https://my.f5.com/manage/s/article/K000137353 https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/ iLeakage...
Network Security News Summary for Thursday October 26th, 2023 26.10.2023 6:07
Apple Updates; Confluence Server Scans; Critical VMWare Patch Apple Updates https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344 Confluence Server Scans CVE-2023-22515 https://isc.sans.edu/diary/30342 Critical VMVware vCenter Patch CVE-2023-34048 https://www.vmware.com/...
Network Security News Summary for Wednesday October 25th, 2023 24.10.2023 5:39
Google Samsung False Positive; OAuth Hijacking Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/ OAuth Hijacking https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts Microsoft Exchange Server CVe-2023-36745 PoC https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-...
Network Security News Summary for Tuesday October 24th, 2023 23.10.2023 6:25
Apple TV IPv6 DoS; Squid Patches; Critical Citrix Patch; Cisco Vuln Updates; Apple TV IPv6 DoS https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336 Squid Patches https://github.com/squid-cache/squid/security/advisories Critical Citrix Update https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc...
Network Security News Summary for Monday October 23th, 2023 22.10.2023 6:40
Base64Dump; OAUTH Redirect; Okta Breach; VMWare and Solarwinds Patches base64dump.py Handles More Encodings Than Just BASE64 https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332 Stealing OAuth Tokens via Open Redirects https://eval.blog/research/microsoft-account-token-leaks-in-harvest/ VMWare Patches https://www.vmware.com/security/advisories.html Sol...
Network Security News Summary for Friday October 20th, 2023 19.10.2023 6:37
honeypot update; Malicious Keepass Ad; JavaScript in Blockchain; Honeypot Update https://github.com/DShield-ISC/dshield/blob/main/README.md Malicious Keepass Ads https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website Malicious JavaScript in Smart Contracts https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in...
Network Security News Summary for Thursday October 19th, 2023 19.10.2023 5:41
Hex Decode; Oracle CPU; Citrix Vuln Exploited; Exposed Jupyter Notebooks Hiding in Hex https://isc.sans.edu/diary/Hiding%20in%20Hex/30322 Oracle Quarterly Critical Patch Update https://www.oracle.com/security-alerts/cpuoct2023.html Citrix Vulnerability Exploited CVE-2023-4966 https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966 Exposed Jupyter Notebooks Exploited...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.