Johannes B. Ullrich

SANS Internet Storm Center's Daily Network Security News Podcast

News EN ↓ 1000 episodes

A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Author

Johannes B. Ullrich

Category

News

Podcast website

isc.sans.edu

Latest episode

Jul 9, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Network Security News Summary for Friday October 7th, 2022 06.10.2022

Infosec Calendar; OnionPoison; MacOS Archives and MOTW Infosec Calendar https://isc.sans.edu/forums/diary/What+is+in+your+Infosec+Calendar/29118 OnionPoison: infected Tor Browser installer distributed through popular YouTube channel https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/ MacOS Architve Utility Vulnerability Details https://www.jamf.com/blog/jamf-threat-la...

Network Security News Summary for Wednesday October 5th, 2022 05.10.2022

Phishing via Telegram; Updated MSFT Exchange fix; PHP Packagist Vuln; Credential Harvesting with Telegram https://isc.sans.edu/forums/diary/Credential%20Harvesting%20with%20Telegram%20API/29112/ Updated Microsoft Exchange Fix https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/ Impacket and Exfiltration Tool Used to Steal...

Network Security News Summary for Tuesday October 4th, 2022 04.10.2022

Exchange Fix Bypass; Schneider UMAS Patch Bypass; Comm100 Compromise Microsoft Exchange Vulnerability Fix Bypassed https://twitter.com/testanull/status/1576774007826718720 Schneider Electric UMAS Patch Bypass https://securelist.com/the-secrets-of-schneider-electrics-umas-protocol/107435/ Supply Chain Attack via Trojanized Comm100 Chat Installer https://www.crowdstrike.com/blog/new-supply-chain-att...

Network Security News Summary for Monday October 3rd, 2022 03.10.2022

Exchange 0-Day Update; Bitbucket Exploited; Apple TCC Bypass Microsoft Exchange 0-Day Update https://isc.sans.edu/forums/diary/Exchange+Server+0Day+Actively+Exploited/29106 https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/ CISA Adds Atlasian Bitbucket Vulnerability to Exploited List https://www.cisa.gov/uscert/ncas/current-activity/2022/09/30/cisa-adds-three-known-exploited-vulnerabilities...

Network Security News Summary for Friday September 30th, 2022 29.09.2022

PNG Analysis; Possible Exchange 0-Day; New VMWAre ESXi Persistence PNG Analysis with pngdump.py https://isc.sans.edu/forums/diary/PNG%20Analysis/29100/ Possible Exchange Server 0-Day Vulnerability https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html https://success.trendmicro.com/dcx/s/solution/000291651?language=en_U...

Network Security News Summary for Thursday September 29th, 2022 29.09.2022

Old Flaw to Access VoIP Creds; IRS SMS Scam; Turnstile vs CAPTCHA; Cisco, Arista, Juniper and Chrome Patches 10 Years Later: Attacker re-discovering old VTiger CRM Vulnerability https://isc.sans.edu/forums/diary/10+Years+Later+Attacker+rediscovering+old+VTiger+CRM+Vulnerability/29098 IRS Reports Significant Increase in Texting Scams https://www.irs.gov/newsroom/irs-reports-significant-increase-in-...

Network Security News Summary for Wednesday September 28th, 2022 28.09.2022

DNS Option 15; YARI for YARA; HTTP Archive Almanac DNS Option 15 and Debugging DNSSEC Errors https://isc.sans.edu/forums/diary/DNS+Option+15+Debugging+DNSSEC+Errors/29094 Yari: A New Era of Yara Debugging https://engineering.avast.io/yari-a-new-era-of-yara-debugging/ HTTP Archive Almanac https://almanac.httparchive.org/en/2022/security keywords: almanac; http archive; https; hsts; dns; option 15;...

Network Security News Summary for Tuesday September 27th, 2022 27.09.2022

Python vs Sandboxes; Mouseover Malware; Redis RCE Flaw; Scoreboard Hacking Easy Python Sandbox Detection https://isc.sans.edu/forums/diary/Easy+Python+Sandbox+Detection/29090 Hackers use PowerPoint Files for "Mouseover" Malware Delivery https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/ Redis 7.0 XAUTOCLAIM Heap Overflow https://github.com/redis/...

Network Security News Summary for Monday September 26th, 2022 26.09.2022

MSFT Teams Token Stealer; Downloading Malware; WhatsApp Patch; Sophos RCE Flaw; CircleCI Phishing Kids Like Cookies and Malware Likes them Too https://isc.sans.edu/forums/diary/Kids+Like+Cookies+Malware+Too/29082 Downloading Files from Removed Domains https://isc.sans.edu/forums/diary/Downloading%20Samples%20From%20Takendown%20Domains/29086/ WhatsApp Security Updates https://www.whatsapp.com/secur...

Network Security News Summary for Friday September 23rd, 2022 23.09.2022

FODHelper Delivers RAT; MSFT Endpoing Conf Manager Updates; Fuzzing Tool; Apple Updates; RAT Delivered Through FODHelper https://isc.sans.edu/forums/diary/RAT+Delivered+Through+FODHelper/29078 Microsoft Endpoint Configuration Manager Spoofing Vulnerability https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37972 New Fuzzing Tool: cifuzz https://github.com/CodeIntelligenceTesting/...

Network Security News Summary for Thursday September 22nd, 2022 22.09.2022

Free Phishing; Insecure tarfile.extract; Twitter Logout Phishing Campaigns Use Free Only Resources https://isc.sans.edu/forums/diary/Phishing%20Campaigns%20Use%20Free%20Online%20Resources/29074/ Insecure use of tarfile.extract in Python https://bugs.python.org/issue1044#msg55464 Twitter Failed to Logout Users After Password Reset https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password...

Network Security News Summary for Wednesday September 21st, 2022 21.09.2022

Chainsaw Hunt; Exploit Cloud PDUs; Default Tamper Protection; Chainsaw: Hunt, search and extract event log records https://isc.sans.edu/diary/Chainsaw%3A+Hunt%2C+search%2C+and+extract+event+log+records/29066 PDU Exploits past NAT https://claroty.com/team82/research/jumping-nat-to-shut-down-electric-devices Tamper Protection will be turned on for all Enterprise Customers https://techcommunity.micro...

Network Security News Summary for Tuesday September 20th, 2022 20.09.2022

Preventing ISO Malware; Emotet Update/History; MSFT Teams Tokens Preventing ISO Malware https://isc.sans.edu/diary/Preventing+ISO+Malware+/29062 State of Emotet https://www.advintel.io/post/advintel-s-state-of-emotet-aka-spmtools-displays-over-million-compromised-machines-through-2022 Undermining Microsoft Teams Security by Mining Tokens https://www.vectra.ai/blogpost/undermining-microsoft-teams-s...

Network Security News Summary for Monday September 19th, 2022 19.09.2022

CustomXML Word Doc; 2FA on Locked Phones; Spellcheck Password Leak; Reflected Content Word Maldoc With CustomXML and Renamed VBAProject.bin https://isc.sans.edu/diary/Word+Maldoc+With+CustomXML+and+Renamed+VBAProject.bin/29056 2FA on Lock Screens https://www.bbc.com/news/uk-england-london-62809151 Chrome and Edge Enhances Spellcheck Features Expose PII, Even Your Password https://www.otto-js.com/n...

Network Security News Summary for Friday September 16th, 2022 16.09.2022

Frameset Word Doc; Windows IKE PoC; Trojaned Putty; EZVIZ Cam Vuln; Lenovo BIOS updates Malicous Word Document With a Frameset https://isc.sans.edu/diary/Malicious+Word+Document+with+a+Frameset/29052 CVE-2022-34721 Exploit https://github.com/78ResearchLab/PoC/tree/main/CVE-2022-34721 Trojaned Putty Used in Attacks https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing Lenovo BIOS Updates h...

Network Security News Summary for Thursday September 15th, 2022 15.09.2022

Python Process Injection; Queen Elizabeth Phishing; Easy Process Injection within Python https://isc.sans.edu/diary/Easy+Process+Injection+within+Python/29048 Queen Elizabeth Related Phishing https://twitter.com/threatinsight/status/1570092339984584705 Microsoft 365 Auto Updates Apps on Locked or Idle Devices https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-under-lock-improved-upda...

Network Security News Summary for Wednesday September 14th, 2022 14.09.2022

Microsoft Patch Tuesday; Adobe Patches; Magento Extension Hack; Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+September+2022+Patch+Tuesday/29044/ Adobe Patches https://helpx.adobe.com/security/security-bulletin.html Magento Vendor Fishpig Hacked, Backdoors Added https://sansec.io/research/rekoobe-fishpig-magento keywords: microsoft; patch tuesday; patches; ipv6; ipsec; ike; a...

Network Security News Summary for Tuesday September 13rd, 2022 12.09.2022

Honeypot vs VirusTotal; Apple Patches; Ransomware Enters via MiVoice Voip Device VirusTotal Result Comparisons for Honeypot Malware https://isc.sans.edu/diary/VirusTotal+Result+Comparisons+for+Honeypot+Malware/29040 Apple Patches https://support.apple.com/en-us/HT201222 Lorenz Ransomware Group Cracks MiVoice and Calls Back For Free https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-...

Network Security News Summary for Monday September 12nd, 2022 11.09.2022

File Exchange Malware; Bypassing Github Code Review; Intermittent Encryption; CRLs are Back; Malware Abusing File Exchange Site https://isc.sans.edu/diary/Phishing+Word+Documents+with+Suspicious+URL/29034 Bypassing GitHub Required Reviewers to Submit Malicious Code https://www.legitsecurity.com/blog/bypassing-github-required-reviewers-to-submit-malicious-code Crimeware Trends: Ransomware Developer...

Network Security News Summary for Friday September 9th, 2022 09.09.2022

VBS vs CyberChef; pfBlockerNG RCE; MSFT Teams Data Exfil; Analyzing Obfuscated VBS with CyberChef https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/29028 pfBlockerNG Unauthenticated RCE https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/29028 GifShell attack creates reverse shell using microsoft teams gifs https://www.bleepingcomputer.com/news/security/gifshell-att...

Network Security News Summary for Thursday September 8th, 2022 08.09.2022

PHP Deserialization; TeslaGun; Cisco RV Router Vulns; Shikitega Malware; PHP Deserialization Exploit Attempt https://isc.sans.edu/diary/PHP+Deserialization+Exploit+attempt/29024 TA505 Group's TeslaGun In-Depth Analysis https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis Cisco publishes unpatched Small Business Router Vulnerability https://tools.cisco.com/security/ce...

Network Security News Summary for Wednesday September 7th, 2022 07.09.2022

Encoded Cobalt Strike; EvilProxy PaaS; Zyxel NAS RCE; Moobot vs D-Link Analysis of an Encoded Cobalt Strike Beacon https://isc.sans.edu/diary/Analysis+of+an+Encoded+Cobalt+Strike+Beacon/29014 EvilProxy Phishing-As-A-Service with MFA Bypass https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web Zyxel Patches RCE Vulnerability https://www.zyxel.com/su...

Network Security News Summary for Tuesday September 6th, 2022 06.09.2022

Webb Malware; Defender False Postives; Chrome 0-Day; Sharkbot; James Webb JPEG With Malware https://isc.sans.edu/diary/James+Webb+JPEG+With+Malware/29010 Windows Defender False Positive https://www.theregister.com/2022/09/05/windows_defender_chrome_false_positive/ Google Chrome 0-Day https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html Sharkbot Android Infostealer i...

Network Security News Summary for Friday September 2nd, 2022 02.09.2022

Jolokia Scans (maybe Geode?); Exchange Basic Auth; AWS Access Keys; Gitlab; Jolokie Scans: Possible Hunt for Vulnerable Apache Geode Servers https://isc.sans.edu/diary/Jolokia+Scans%3A+Possible+Hunt+for+Vulnerable+Apache+Geode+Servers+%28CVE-2022-37021%29/29006 Microsoft Basic Authentication Deprecation in Exchange Online https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authenticati...

Network Security News Summary for Thursday September 1st, 2022 01.09.2022

QNAME Minimization; iOS 12 Update; Translate Miner; Geode and Foxit PDF Reader Updates Underscores and DNS: The Privacy Story https://isc.sans.edu/diary/Underscores+and+DNS%3A+The+Privacy+Story/29002 iOS 12.5.6 Update https://support.apple.com/en-us/HT201222 Malware Disguised as Google Translate Desktop App https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disg...

Listen to the SANS Internet Storm Center's Daily Network Security News Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.