Johannes B. Ullrich
SANS Internet Storm Center's Daily Network Security News Podcast
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Network Security News Summary for Friday May 19th, 2023 19.05.2023 6:51
Apple Updates; .zip Survey; Dell/EMC Networker Vuln; Keepass Master PW Exposure Apple Updates Everything https://isc.sans.edu/diary/Apple%20Updates%20Everything/29860 A Quick Survey of .zip Domains https://isc.sans.edu/diary/A%20Quick%20Survey%20of%20.zip%20Domains%3A%20Your%20highest%20risk%20is%20running%20into%20Rick%20Astley./29858 Dell NetWorker Security Update https://www.dell.com/support/kb...
Network Security News Summary for Thursday May 18th, 2023 18.05.2023 5:47
RAR SFX Files; Wemo Vuln; Wago Vuln; Router Vuln to Proxies; TP-Link Malicous Firmware Increase in Malicious RAR SFX Files https://isc.sans.edu/forums/diary/Increase%20in%20Malicious%20RAR%20SFX%20files/29852/ FriendlyName Buffer Overflow in Wemo Smartplug https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/ Wago License Page Exploit https://onekey.com/blog/security-ad...
Network Security News Summary for Wednesday May 17th, 2023 17.05.2023 5:37
Testing Faraday Bags; Sharepoint Scans Encrypted Files; vm2 Escape; geocon for MacOS Signals Defense With Faraday Bags https://isc.sans.edu/forums/diary/Signals%20Defense%20With%20Faraday%20Bags%20%26%20Flipper%20Zero/29840/ Microsoft Sharepoint Scans Password Protected Files https://infosec.exchange/@threatresearch/110373860063222707# Critical Sandbox Escape Vulnerability in VM2 https://github.co...
Network Security News Summary for Tuesday May 16th, 2023 16.05.2023 5:19
Facebook Phish; No Intel Microcode Vuln; Fake Trezor Wallets; TP-Link Exploited Ongoing Facebook Phishing campaign Without a Sender and (almost) without Links https://isc.sans.edu/diary/Ongoing%20Facebook%20phishing%20campaign%20without%20a%20sender%20and%20%28almost%29%20without%20links/29848 Intel Microcode Updates Do Not Patch Vulnerability https://www.theregister.com/2023/05/15/intel_mystery_m...
Network Security News Summary for Monday May 15th, 2023 15.05.2023 7:06
.zip/.mov domains; The .zip gTLD: Risks and Opportunities https://isc.sans.edu/forums/diary/The+zip+gTLD+Risks+and+Opportunities/29838/ Brave Forgetful Browsing https://brave.com/privacy-updates/25-forgetful-browsing/ Intel Mystery Microcode Patch https://www.phoronix.com/news/Intel-12-May-2023-Microcode Netgear Updates https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilitie...
Network Security News Summary for Friday May 12nd, 2023 12.05.2023 6:21
Geolocation Difficulties; Pre-Infected Phones; Dragos Breach; Ruckus Exploited Geolocating IPs is Harder Than You Think https://isc.sans.edu/diary/Geolocating%20IPs%20is%20harder%20than%20you%20think/29834 Pre-Infected Mobile Phones https://www.theregister.com/2023/05/11/bh_asia_mobile_phones/ Dragos Breach https://www.dragos.com/blog/deconstructing-a-cybersecurity-event/ AndoryuBot Targets Ruckus...
Network Security News Summary for Thursday May 11st, 2023 11.05.2023 5:52
CISSM Data Anlysis; Outlook "re-patch"; Snake Malware; Fake System Updates Exploratory Data Analysis with CISSM Cyber Attacks Database Part 2 https://isc.sans.edu/diary/Exploratory%20Data%20Analysis%20with%20CISSM%20Cyber%20Attacks%20Database%20-%20Part%202/29828 Microsoft Patched Outlook (actually Windows) vulnerability again https://www.akamai.com/blog/security-research/important-outlook-vulnera...
Network Security News Summary for Wednesday May 10th, 2023 10.05.2023 5:58
Microsoft Patch Tuesday; GitHub Push Protection Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20May%202023%20Patch%20Tuesday/29826 GitHub "Push Protection" now out of Beta https://github.blog/2023-05-09-push-protection-is-generally-available-and-free-for-all-public-repositories/ keywords: microsoft patch tuesday; push protection
Network Security News Summary for Tuesday May 9th, 2023 09.05.2023 6:21
QR Code Threats; Microsoft Edge Update; Fake ChatGPT QR Codes Used in Fake Parking Tickets and Surveys https://www.bleepingcomputer.com/news/security/qr-codes-used-in-fake-parking-tickets-surveys-to-steal-your-money/ Microsoft Edge Update https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel Facebook Sees More Fake ChatGPT https://about.fb.com/news/2023/05/metas-q1-202...
Network Security News Summary for Monday May 8th, 2023 08.05.2023 6:12
Decoding PPAMs; Exploratory Analysis; Colorcpl.exe LOLBIN; Leaked MSI Keys; PHP Packages Compromised; Quickly Finding Encoded Payloads in Office Documents https://isc.sans.edu/forums/diary/Quickly+Finding+Encoded+Payloads+in+Office+Documents/29818/ Exploratory Data Analysis with CISSM Cyber Attacks Database Part 1 https://isc.sans.edu/forums/diary/Exploratory+Data+Analysis+with+CISSM+Cyber+Attacks...
Network Security News Summary for Friday May 5th, 2023 05.05.2023 6:01
Word Infostealer; Cisco SPA-112; Fortinet May Updates; PaperCut New Exploit Infostealer Embedded in a Word Document https://isc.sans.edu/diary/Infostealer%20Embedded%20in%20a%20Word%20Document/29810 Cisco SPA-112 Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-unauth-upgrade-UqhyTWW Fortinet May Updates https://www.fortiguard.com/psirt?date=...
Network Security News Summary for Thursday May 4th, 2023 04.05.2023 7:38
Config File Scans; Google Enables Passkeys; Chrome Dropping TLS Lock; AMD TPM Attacks Increased Number of Configuration File Scans https://isc.sans.edu/diary/Increased%20Number%20of%20Configuration%20File%20Scans/29806 Google Enabling Passkeys https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/ Chrome to Drop Lock Icon from HTTPS https://blog.chromium.org/2023/...
Network Security News Summary for Wednesday May 3rd, 2023 03.05.2023 5:50
VBA Project References; FRRouting Vuln; JWT ECDSA Algo Confusion VBA Project References https://isc.sans.edu/diary/VBA%20Project%20References/29800 BGP Message Parsing Vulnerabilities in FRRouting https://www.forescout.com/blog/three-new-bgp-message-parsing-vulnerabilities-disclosed-in-frrouting-software/ JWT ECDSA Algorithm Confusion https://blog.pentesterlab.com/exploring-algorithm-confusion-att...
Network Security News Summary for Tuesday May 2nd, 2023 02.05.2023 5:40
Passive Phish Analysis; Apple Rapid Security Response; Grafana Vuln; Illumina Vuln; Passive Analysis of a Phishing Attachment https://isc.sans.edu/diary/%22Passive%22%20analysis%20of%20a%20phishing%20attachment/29798 Apple Rapid Security Response https://www.macrumors.com/2023/05/01/rapid-security-response-16-4-1/ Grafana Security Release https://grafana.com/blog/2023/04/26/grafana-security-releas...
Network Security News Summary for Monday May 1st, 2023 30.04.2023 5:27
Loki in Docker; UTF-16 Encoded Malware; AT&T Email Compromise; MacOS Crypto Stealer; Zyxel Vuln Quick IOC Scan With Docker https://isc.sans.edu/diary/Quick%20IOC%20Scan%20With%20Docker/29788 Dobfuscation Scripts When Encodings Help https://isc.sans.edu/diary/Deobfuscating%20Scripts%3A%20When%20Encodings%20Help/29792 Hackers Are Breaking Into AT&T Email Accounts To Steal Cryptocurrency https://tech...
Network Security News Summary for Friday April 28th, 2023 28.04.2023 6:15
Veeam Vuln Ransomware; Google Authenticator Sync; Keycloak Vuln; Ransomware Gang Exploiting Unpatches Veeam Backup Products https://www.computerweekly.com/news/365535586/Ransomware-gang-exploiting-unpatched-Veeam-backup-products Google Authenticator Sync Encryption https://security.googleblog.com/2023/04/google-authenticator-now-supports.html Keycloak Vulnerability https://out.reddit.com/t3_130km0...
Network Security News Summary for Thursday April 27th, 2023 27.04.2023 5:46
Hunting Phishing Sites; RSA Top Attack Panel; @sans_edu research journal Strolling Through Cyberspace and Hunting for Phishing Sites https://isc.sans.edu/diary/Strolling%20through%20Cyberspace%20and%20Hunting%20for%20Phishing%20Sites/29780 RSA Panel: Five most dangerous new attack techniques https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques...
Network Security News Summary for Wednesday April 26th, 2023 26.04.2023 6:22
ChatGPT CVSS Scores; SLP Amplification; Apache Superset RCE; Sophos Web Appliance PoC Calculating CVSS Scores with ChatGPT https://isc.sans.edu/diary/Calculating%20CVSS%20Scores%20with%20ChatGPT/29774 Amplifying SLP Traffic https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp Insecure Default Configuration in Apache Superset https://...
Network Security News Summary for Tuesday April 25th, 2023 25.04.2023 6:05
Aukill BYOVD Ransomware; Papercut Exploit; Solarwinds Patch; APC UPS Software Patch; Virustotal Code Insight Aukill EDR Killer Malware Abuses Process Explorer Driver https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/ Papercut Vulnerability Deep Dive https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise Solarwinds Patc...
Network Security News Summary for Monday April 24th, 2023 24.04.2023 5:46
DMARC in .co; X_Trader Fallout; Car Hacking; DNS Decoy Dog Management of DMARC control for email impersonation fo domains in the .co TLD https://isc.sans.edu/forums/diary/Management+of+DMARC+control+for+email+impersonation+of+domains+in+the+co+TLD+part+1/29768/ X_Trader Supply Chain Attack Fallout https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain Car...
Network Security News Summary for Friday April 21st, 2023 21.04.2023 6:35
Password Expiry; 3CX Update; Google Ghosttokens; PyPi Trusted Publishers Taking a Bite Out of Password Expiry Helpdesk Calls https://isc.sans.edu/diary/Taking%20a%20Bite%20Out%20of%20Password%20Expiry%20Helpdesk%20Calls/29758 3CX Software Supply Chain Compromise https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise Google Ghost Tokens https://astrix.security/ghosttoken-explo...
Network Security News Summary for Thursday April 20th, 2023 20.04.2023 4:49
Chrome 0-Day; Oracle CPU; Github npm Prvenance; MSFT Threat Actor Naming; Yet Another Google Chrome 0-Day https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html Oracle Critical Patch Update April 2023 https://www.oracle.com/security-alerts/cpuapr2023.html Github Provenance Action for npm Packages https://www.theregister.com/2023/04/19/github_actions_npm_origins/ Mi...
Network Security News Summary for Wednesday April 19th, 2023 18.04.2023 5:23
UDDIExplorer; SNMP Against Routers; Data from Discarded Routers UDDIs Are Back: Attackers Rediscovering Old Exploits. https://isc.sans.edu/diary/UDDIs%20are%20back%3F%20Attackers%20rediscovering%20old%20exploits./29754UDDIExplorer; UDDIExplorer; Russian Attacks against Routers https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108 Information Leakage on Discarded Routers https://www.we...
Network Security News Summary for Tuesday April 18th, 2023 18.04.2023 5:23
Increase in Honeypots in China; Mac Ransomware; GC2 in Malware The strange case of the Great Honeypot of China https://isc.sans.edu/diary/The%20strange%20case%20of%20Great%20honeypot%20of%20China/29750 The LockBit ransomware (kinda) comes for macOS https://objective-see.org/blog/blog_0x75.html Google Cloud Used as C&C https://thehackernews.com/2023/04/google-uncovers-apt41s-use-of-open.html keywor...
Network Security News Summary for Monday April 17th, 2023 17.04.2023 5:25
Fake Chrome Errors; Chromium 0-Day; LAPS Compatibility Issues; Manage Engine Attack Campaing Tht Uses Fake Google Chrome Errors https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com Chromium Publishes Emergency Update https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html LAPS Update Errors...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.