Johannes B. Ullrich
SANS Internet Storm Center's Daily Network Security News Podcast
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Network Security News Summary for Wednesday September 13rd, 2023 13.09.2023 5:58
Microsoft Patch Tuesday; OpenSSL 1.1.1 EoL; Adobe Patches Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214 OpenSSL 1.1.1 End of Life https://www.openssl.org/blog/blog/2023/09/11/eol-111/ Adobe Updates https://helpx.adobe.com/security/security-bulletin.html keywords: adobe; openssl; microsoft; patch; tuesday;
Network Security News Summary for Wednesday September 13rd, 2023 12.09.2023 5:53
More Apple Patches; Wiki Eve Attack; Google Looker Studio Phish; HPE One View Vuln; Apple Patches Older Operating Systems https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210 Wi-Fi Enabled Practical Keystroke Eavesdropping https://arxiv.org/pdf/2309.03492.pdf Phishing via Google Looker Studio https://blog.checkpoint.com/security/phishing-via-goo...
Network Security News Summary for Monday September 11st, 2023 11.09.2023 6:50
Honeypot Data and Powershell; Apple 0-Day Details; Cisco 0-Day Exploited; Odd Password Solution Augmenting Honeypot Logs https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204 More details about Apple 0-...
Network Security News Summary for Friday September 8th, 2023 07.09.2023 5:07
Apple Patches 0-Days; iOS Scareware; Aruba and TP Link Patches Apple Patches 0-Days https://isc.sans.edu/diary/30200 https://support.apple.com/en-us/HT201222 iOS Fleezeware/Scareware https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198 Aruba Vulnerabilities https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-01...
Network Security News Summary for Thursday September 7th, 2023 06.09.2023 5:44
DNS Security; MSFT Key Loss Details; Android Updates; Chrome Updates; Atlas VPN Vuln; Security Related DNS Records https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194 Microsoft Reveleas Details about Key Loss https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ September Android Updates https://source.android.com/docs/se...
Network Security News Summary for Wednesday September 6th, 2023 05.09.2023 5:35
Honeypot Usernames; TPM LUKS Bypass; Social Engineering Helpdesks for MFA Bypass Common Usernames Submitted to Honeypots https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188 TPM LUKS Bypass https://pulsesecurity.co.nz/advisories/tpm-luks-bypass Cross Tenant Impersonation Prevention and Detection https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention...
Network Security News Summary for Tuesday September 5th, 2023 04.09.2023 6:17
Password Origins; YARA Rules for Obfuscated Strings; VMware Aria Keys; Windows TLS 1.0/1.1; What is the Origin of Passwords Submitted to Honeypots https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182 Creating a YARA Rule to Detect Obfuscated Strings https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186...
Network Security News Summary for Thursday August 31st, 2023 30.08.2023 5:35
Hurricane Prep; Notepad++ Vulns; 7zip Vuln; BGP Error Handling; Home Office/Small Business Hurricane Prep https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166 Notepad++ Vulnerabilities https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/ 7-Zip Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-23-1164/ BGP Error Handling Issues https:...
Network Security News Summary for Wednesday August 30th, 2023 29.08.2023 6:04
Website Survivaltime; ActiveMime Maldocs; RocketMQ Exploited; ManageEnging Vuln; Survival Time for Web Sites https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170 PDF/ActiveMime Polyglot Maldocs https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/ RocketMQ Vulnerability Exploited https://blogs.ju...
Network Security News Summary for Tuesday August 29th, 2023 29.08.2023 6:32
WINRAR Exploit Analysis; Juniper PoC; Exchange EP Default; Rust Malware Analysis of RAR Exploit Files (CVE-2023-38831) https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164 Juniper Exploit CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847 https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/ Microsoft Will Enabled Extended Protection...
Network Security News Summary for Monday August 28th, 2023 28.08.2023 6:38
Postgresql C2; MacOS Network Connections; Fake/Bad CVEs; Windows Cert Confusion; Bad NPM Package Python Malware Using Postgresql for C2 Communications https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158 macOS: Who is Behind This Network Connection? https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160 CVE-2020-1...
Network Security News Summary for Friday August 25th, 2023 25.08.2023 5:52
Keyboard Walk; Barracuda ESG Warning; Ivanti Sentry Update; Smoke Loader Geolocation How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152 FBI Warns of Persistent Barracuda Backdoors https://www.ic3.gov/Media/News/2023/230823.pdf Ivanti...
Network Security News Summary for Thursday August 24th, 2023 24.08.2023 5:20
XLAM Files; WinRAR 0-Day (new!); Aruba Vulnerablities More Exotic Excel Files Dropping AgentTesla https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150 CVE-2023-38831 WinRAR Vulnerability Exploited https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/ Aruba Vulnerabilities https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt keywords: aruba; wi...
Network Security News Summary for Wednesday August 23rd, 2023 23.08.2023 6:02
Fernet Encryption; inotify triage; Coldfusion Exploit; Openfire Exploit; New XLoader; Fernet Encryption in Malware https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/ Malware Triage With Inotify Tools https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/ Adobe Coldfusion Exploited https://www.cisa.gov/known-exploite...
Network Security News Summary for Tuesday August 22nd, 2023 22.08.2023 6:07
SystemBC Scans; Exchange SU Rerelease; Ivanti Exploit; DUO Outages; mTLS vulnerabilities SystemBC Scans and ProxyNation https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138 https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware Exchange Server Security Update Re-Release https://techcommunity.microsoft.com/t5/exchange-team-blog/re-re...
Network Security News Summary for Monday August 21st, 2023 20.08.2023 5:36
Zalando Phish/RAT; WinRAR Code Exec; Hotmail SPF Fail; Ivacy VPN Cert Abused; Chrome Extension Warning; From a Zalando Phish to a RAT https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136 RARLAB WinRAR Recovery Volume Vulnerability https://www.zerodayinitiative.com/advisories/ZDI-23-1152/ Hotmail SPF Record Error Leads to spam false positives https://www.bleepingcomputer.co...
Network Security News Summary for Friday August 18th, 2023 17.08.2023 5:44
Whitespaces; Fake Airplane Mode; LinkedIn Attacks; Robot Vacuum Privacy Command Line Parsing - Are These Really Unique Strings? https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126 iOS 16 Fake Airplane Mode https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/ LinkedIn Attacks https://cyberint.com/b...
Network Security News Summary for Thursday August 17th, 2023 17.08.2023 6:41
PowerShell Gallery Malware; Windows Time Issues; Malicious QR Codes; Citrix Scanner PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks Windows Random Time Issues https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-dat...
Network Security News Summary for Wednesday August 16th, 2023 16.08.2023 5:54
macOS Background Task Manager; Ivanti Avalanche Vuln; Synology Cloud Access Vuln; Fake Beta Crypto Apps macOS Background Task Manager Bypass https://www.wired.com/story/apple-mac-background-task-management-flaw/ Ivanti Avalanche Vulnerability https://www.tenable.com/security/research/tra-2023-27 Exploiting Synology NAS Cloud Connectivity https://claroty.com/team82/research/a-pain-in-the-nas-exploi...
Network Security News Summary for Tuesday August 15th, 2023 15.08.2023 5:51
PDFiD False Pos; CVE-2023-32019 Fix Update; CyberPower/Dataprobe Vulns; Ford Vuln; PDFiD False Positives Revisited https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122 CVE-2023-32019 Fix Enabled by Default; https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080 CyberPower and Datap...
Network Security News Summary for Monday August 14th, 2023 14.08.2023 5:31
Python Anti-Debugging; Zoom Zero Touch Vuln; DNS Spoofing Show Me All Your Windows https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116 Zero Touch Pwn https://blog.syss.com/posts/zero-touch-pwn/ Maginot DNS Spoofing Attack https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang keywords: windows; python; anti-debugging; zero touch; zoom; dns; spoofing
Network Security News Summary for Friday August 11st, 2023 10.08.2023 6:01
SQL Auth Weakness; Windows Defender Pretender; Dell Compellent Static Key; Sogou Keyboard Vuln; Some things never change, such as SQL Authentication "Encryption" https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112 Defender Pretender: When Windows Defender Updates Become a Security Risk https://www.blackhat.com/us-23/briefings/...
Network Security News Summary for Thursday August 10th, 2023 09.08.2023 6:15
Tunnelcrack VPN vuln; Mozilla VPN Issue; Exchange Patch Trouble; VSCode Secrets Tunnelcrack VPN Vulnerability https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf Mozilla VPN Vulnerablity https://www.openwall.com/lists/oss-security/2023/08/03/1 Non English Exchange Server Patch Issues https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-upda...
Network Security News Summary for Wednesday August 9th, 2023 08.08.2023 6:02
Microsoft Patch Tuesday; Adobe Updates Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106 Adobe Updates https://helpx.adobe.com/security/security-bulletin.html keywords: adobe; adobe commerce; reader; acrobat; microsoft; patch tuesday
Network Security News Summary for Tuesday August 8th, 2023 08.08.2023 6:27
Research Scan IPs; OpenBullet Malware; Cloudflare Tunnel Abuse; Update: Researchers Scanning the Internet https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102 Malicious OpenBullet Configuration Files https://www.kasada.io/threat-intel-openbullet-malware/ Abusing Cloudflare Tunnels https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.