Johannes B. Ullrich
SANS Internet Storm Center's Daily Network Security News Podcast
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Network Security News Summary for Wednesday June 28th, 2023 27.06.2023 5:10
Malware Triage; RowPress Attack; Dell BIOS Update; The Importance of Malware Triage https://isc.sans.edu/diary/The+Importance+of+Malware+Triage/29984/ RowPress: Amplifying Read Disturbance in Modern DRAM Chips https://dl.acm.org/doi/abs/10.1145/3579371.3589063 Dell BIOS Updates https://www.dell.com/support/kbdoc/de-de/000214778/dsa-2023-174-dell-client-bios-security-update-for-an-out-of-bounds-wri...
Network Security News Summary for Tuesday June 27th, 2023 26.06.2023 5:16
BlackLotus Mitigation; Camaro Dragon; Grafana Vuln; BlackLotus Mitigation Guide https://media.defense.gov/2023/Jun/22/2003245723/-1/-1/0/CSI_BlackLotus_Mitigation_Guide. PDF Camaro Dragon Infects USB Drives as well as Network Drives https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/ Grafana Security Release https://grafana.com/blog/2023/...
Network Security News Summary for Monday June 26th, 2023 25.06.2023 6:56
Modiloader Spam; Word Templates; Quakbot Obama271; MSFT Teams Phishing; Free Smart Watches; Email Spam With Modiloader Attached https://isc.sans.edu/diary/Email%20Spam%20with%20Attachment%20Modiloader/29978 Word Document with an Online Attached Template https://isc.sans.edu/diary/Word%20Document%20with%20an%20Online%20Attached%20Template/29976 Quakbot Activity Obama271 Distrubution Tag https://isc...
Network Security News Summary for Friday June 23rd, 2023 22.06.2023 5:27
Apple Updates; VCenter Vuln.; GitHub RepoJacking; Apple Updates Already Exploited Vulnerabilities https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerabilities%20in%20iOS%20iPadOS%2C%20macOS%2C%20watchOS%20and%20Safari/29972 Heap Buffer Overflow in VMWare VCenter https://www.vmware.com/security/advisories/VMSA-2023-0014.html GitHub RepoJacking https://blog.aquasec.com/github-dataset-res...
Network Security News Summary for Thursday June 22nd, 2023 21.06.2023 5:41
YouTube Creator Phishing; Autodesk Maya Malware; Zyxel, Asus and Huawei Vuln; VMware Aria Exploited Analyzing a YouTube Sponsorship Phishing E-Mail https://isc.sans.edu/diary/Analyzing%20a%20YouTube%20Sponsorship%20Phishing%20Mail%20and%20Malware%20Targeting%20Content%20Creators/29966 Malicious Code Can Be Anywhere https://isc.sans.edu/diary/Malicious%20Code%20Can%20Be%20Anywhere/29964 Zyxel Vulne...
Network Security News Summary for Tuesday June 20th, 2023 20.06.2023 5:52
More Formbook; ZIP Bruteforcing; .inf Malware; FortiNAC PoCs; Formbook From Possible ModiLoaeder (DBatLoader) https://isc.sans.edu/diary/Formbook%20from%20Possible%20ModiLoader%20%28DBatLoader%29%20/29958 Brute-Force ZIP Password Cracking with zipdump.py https://isc.sans.edu/diary/Brute-Force%20ZIP%20Password%20Cracking%20with%20zipdump.py/29948 Malware Delivered Through .inf File https://isc.sans...
Network Security News Summary for Friday June 16th, 2023 16.06.2023 5:33
Vulnerability Management; More MOVEit vulns; Critrix Sharefile; Chromeloader News; npm bignum compromise; Supervision and Verfication in Vulnerability Management https://isc.sans.edu/diary/Supervision%20and%20Verification%20in%20Vulnerability%20Management/29952 More MOVEit issues https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023 Critical Citrix Sharefile St...
Network Security News Summary for Thursday June 15th, 2023 15.06.2023 5:56
Deobfuscating VBS; Broken OOXML Sigs; CVE-2023-32019 Patch Not Enabled By Default; Fortigate Updates; Zoom Updates; Fake GitHub Exploits Deobfuscating a VBS Script With Custom Encoding https://isc.sans.edu/diary/Deobfuscating%20a%20VBS%20Script%20With%20Custom%20Encoding/29940 Every Signature is Broken: On the Insecurity of Microsoft Office's OOXML Signatures https://www.usenix.org/conference/usen...
Network Security News Summary for Wednesday June 14th, 2023 13.06.2023 5:29
Microsoft Patch Tuesday; VMWare 0-Day; SAP Patches Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/June%202023%20Microsoft%20Patch%20Tuesday/29942/ VMWare 0-Day https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass https://www.vmware.com/security/advisories/VMSA-2023-0013.html SAP Patches https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html keywor...
Network Security News Summary for Tuesday June 13rd, 2023 12.06.2023 5:34
Geoserver Cryptominer Attacks; Fortinet Update; Bitwarden Key Leak; Western Digital SMART abuse; Geoserver Attack Details: More Cryptominers Against Unconfigured WebApps https://isc.sans.edu/diary/Geoserver%20Attack%20Details%3A%20More%20Cryptominers%20against%20Unconfigured%20WebApps/29936 Fortinet Update CVE-2023-27997 https://www.fortiguard.com/psirt/FG-IR-23-097 Bitwarden Key Accessible By Low...
Network Security News Summary for Monday June 12nd, 2023 11.06.2023 5:37
Powershell Profiles; Honeypot Activity; More flaws in MOVEit and Fortinet SSLVPN Undetected PowerShell Backdoor Disduigsed as a Profiled File https://isc.sans.edu/diary/Undetected%20PowerShell%20Backdoor%20Disguised%20as%20a%20Profile%20File/29930 DShield Honeypot Activity for May 2023 https://isc.sans.edu/diary/DShield%20Honeypot%20Activity%20for%20May%202023%20/29932 Second MOVEit Vulnerability...
Network Security News Summary for Friday June 9th, 2023 08.06.2023 5:26
Geoserver Scans; Barracuda ESG Replacement; Google Chrome Password Manager; Minecraft Mods; Trend Micro Patch Geoserver Scans https://isc.sans.edu/diary/Ongoing%20scans%20for%20Geoserver/29926 Barracuda Recommends Replacing Compromised Devices https://www.barracuda.com/company/legal/esg-vulnerability Google improves Chrome Password Manager https://www.msn.com/en-us/news/other/chrome-adds-windows-b...
Network Security News Summary for Thursday June 8th, 2023 07.06.2023 5:45
DMARC in .co; VMware Aria Patch; SpinOK Spyware DMARC in .co TLD https://isc.sans.edu/diary/Management%20of%20DMARC%20control%20for%20email%20impersonation%20of%20domains%20in%20the%20.co%20TLD%20-%20part%202/29922 Three Vulnerabilities in VMWare Aria Operations for Networks https://www.vmware.com/security/advisories/VMSA-2023-0012.html SpinOK Spyware SDK found in Android Apps https://vms.drweb.co...
Network Security News Summary for Wednesday June 7th, 2023 07.06.2023 6:04
Copilot vs. Google; Android and Chrome 0-Days; Fake Sextortion; Github Copilot vs Google: Which Code is More Secure https://isc.sans.edu/forums/diary/Github%20Copilot%20vs.%20Google%3A%20Which%20code%20is%20more%20secure/29918/ Android Update https://source.android.com/docs/security/bulletin/2023-06-01 Chrome Updates https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.h...
Network Security News Summary for Tuesday June 6th, 2023 06.06.2023 5:28
Simple Archive Bruteforcer; Keepass Patch; Splunk Advisories; Chrome Extensions; Symantec Updates Brute Forcing Simple Archive Passwords https://isc.sans.edu/diary/Brute%20Forcing%20Simple%20Archive%20Passwords/29914 KeePass 2.54 Released https://keepass.info/news/n230603_2.54.html Splunk Advisories https://advisory.splunk.com/advisories Malicious Google Chrome Extensions https://palant.info/2023/...
Network Security News Summary for Monday June 5th, 2023 05.06.2023 5:57
MoveIT Transfer Exploited; Atomic Wallet Theft; Magecart Update Critical Vulnerability in MoveIT Transfer Actively Exploited https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023 https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/ https://www.mandiant.com/resources/blog/zero-day-moveit-data-theft At...
Network Security News Summary for Friday June 2nd, 2023 01.06.2023 17:09
SSLv2 Remnants; iOS Malware; MOVEit and Reportslab PDF Library Vulnerabilities; Brandon Helms (@sans_edu): CTI For Containers After 28 Years, SSLv2 is Still Not Gone https://isc.sans.edu/forums/diary/After%2028%20years%2C%20SSLv2%20is%20still%20not%20gone%20from%20the%20internet...%20but%20we're%20getting%20there/29908/ Operation Triangulation: iOS Devices Targeted With Previously Unknown Malware...
Network Security News Summary for Thursday June 1st, 2023 31.05.2023 6:52
Apache NiFi Attacks; Gigabyte Backdoor; SalesForce Ghost Sites; ImageMagick Shell Command Injection Apache NiFi Attacks https://isc.sans.edu/diary/Your%20Business%20Data%20and%20Machine%20Learning%20at%20Risk%3A%20Attacks%20Against%20Apache%20NiFi/29900 Gigabyte App Center Backdoor; https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/ Salesforce Ghost Sites https://www.v...
Network Security News Summary for Wednesday May 31st, 2023 31.05.2023 5:54
ModiLoader Sample; MacOS SIP Bypass; OpenSSL Update; Barracuda Vuln Details; Nextcloud, Zyxel Vuln; Malspam Pushes ModiLoader Infection for Remocs Rat https://isc.sans.edu/diary/Malspam%20pushes%20ModiLoader%20%28DBatLoader%29%20infection%20for%20Remcos%20RAT/29896 MacOS SIP Bypass https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integri...
Network Security News Summary for Tuesday May 30th, 2023 29.05.2023 5:50
Word in PPT; DocuSign Malspam; Archiver in Browser; Casandra and MXsecurity Vulnerabilities Analyzing Office Documents Embedded Inside PowerPoint Files https://isc.sans.edu/diary/Analyzing%20Office%20Documents%20Embedded%20Inside%20PPT%20%28PowerPoint%29%20Files/29894 DocuSign Themed Email Leads to Script-Based Infection https://isc.sans.edu/diary/DocuSign-themed%20email%20leads%20to%20script-base...
Network Security News Summary for Friday May 26th, 2023 26.05.2023 5:22
IR Case/Alert Mgnmt; GitLab Exploit; Expo OAUTH Vuln Details; Mitel MiVoice and DLink Vulnerabilities; IR Case/Alert Management https://isc.sans.edu/diary/IR%20Case%20Alert%20Management/29880 Exploit for CVE-2023-2825 GitLab Vulnerability https://github.com/Occamsec/CVE-2023-2825 Expo Framework OAUTH Vulnerability CVE-2023-28131 https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-...
Network Security News Summary for Thursday May 25th, 2023 25.05.2023 5:32
Enriching Cowrie; Volt Typhoon; Android Spy App; Zyxel, Baracuda and GitLab Patches; More Data Enrichment for Cowrie Logs https://isc.sans.edu/diary/More%20Data%20Enrichment%20for%20Cowrie%20Logs/29878 Volt Typhoon: Living of the Land https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land. PDF Android App Breaking Bad https://www.welivesecurity.com/2023/05/23/android-app-...
Network Security News Summary for Wednesday May 24th, 2023 24.05.2023 6:19
Apache NiFi Scans; Samsung 0-Day Fix; Lenovo Bricked; Dell VX Rail; BrutePrint Apache Nifi Scans https://isc.sans.edu/diary/Help+us+figure+this+out+Scans+for+Apache+Nifi/29874/ Samsung Updates fix 0-Day https://security.samsungmobile.com/securityUpdate.smsb Lenovo All-In One Bricked by Windows Update https://www.reddit.com/r/Lenovo/comments/136tatm/lenovo_firmware_10055_bricking_thinkcentre_v53024...
Network Security News Summary for Tuesday May 23rd, 2023 23.05.2023 5:14
ABUS Camera Vuln; .ZIP vs Virustotal; Nissan Car Key Replay; Synology DSM 6.2; Jenkins Plugins; PyPi Suspension Lifted; Probes for recent ABUS Security Camera Vulnerability https://isc.sans.edu/diary/Probes%20for%20recent%20ABUS%20Security%20Camera%20Vulnerability%3A%20Attackers%20keep%20an%20eye%20on%20everything./29870 .ZIP Domains Confuse Virustotal https://twitter.com/imohanasundaram/status/16...
Network Security News Summary for Monday May 22nd, 2023 22.05.2023 5:30
HTA Analysis; Encoding Mistakes; PyPi Attack; PyPi PGP Signatures; npm RATs Another Malicious HTA File Analysis - Part 3 https://isc.sans.edu/forums/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%203/29678/ When the Phisher Messes Up With Encoding https://isc.sans.edu/diary/When%20the%20Phisher%20Messes%20Up%20With%20Encoding/29864 PyPi Suspends New Users and Projects https://status....
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.