Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

News EN ↓ 2472 episodes

A brief daily summary of what is important in cyber security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually about 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Author

Johannes B. Ullrich

Category

News

Podcast website

isc.sans.edu

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

ISC StormCast for Monday, December 5th 2016 04.12.2016

CSP Bypass with Polyglot Images http://blog.portswigger.net/2016/12/bypassing-csp-using-polyglot-jpegs.html also see this Youtube video on Polyglot Images: https://www.youtube.com/watch?v=Ub5G_t-gUBc Stack Overflow SQL Injection Questions https://laurent22.github.io/so-injections/ Mirai Update: More Outages and Vulnerable Chipset Identified http://www.theregister.co.uk/2016/12/02/broadband_mirai_t...

ISC StormCast for Friday, December 2nd 2016 02.12.2016

Open Source Tool "Beamgun" Fights Rogue USB Devices on Windows https://github.com/JLospinoso/beamgun "Shamoon" Malware is back with a new destructive attack against Saudi Arabia https://www.bloomberg.com/news/articles/2016-12-01/destructive-hacks-strike-saudi-arabia-posing-challenge-to-trump British ISP "KCOM" Suffering Outage After Attack http://www.hulldailymail.co.uk/kcom-blames-cyber-attack-fo...

ISC StormCast for Thursday, December 1st 2016 30.11.2016

Mozilla Patches Firefox 0-Day (Exploit already avaiable!) https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+in+Firefox+used+to+Attack+Tor+Browser/21769/ SQL Slammer "Resurgance" ? https://isc.sans.edu/forums/diary/Take+Back+Wednesday+SQL+Slammer+still+alive+but+barely+kicking/21767/ Goolian Android Malware http://blog.checkpoint.com/2016/11/30/1-million-google-accounts-breached-gooligan/ B...

ISC StormCast for Wednesday, November 30th 2016 29.11.2016

Mirai/TR-069 Update: Deutsche Telekom Routers May have been DDoSed by Traffic Volume, not Exploit https://comsecuris.com/blog/posts/were_900k_deutsche_telekom_routers_compromised_by_mirai/ Bitlocker Encrypted Drives Exposed During System Upgrade http://blog.win-fu.com/2016/11/every-windows-10-in-place-upgrade-is.html Software-Only Defenses Against Rowhammer https://arxiv.org/abs/1611.08396

ISC StormCast for Tuesday, November 29th 2016 29.11.2016

Mirai Variant Scanning Port 5555 and 7547 For TR-069/SOAP Vulnerability https://isc.sans.edu/forums/diary/Port+7547+SOAP+Remote+Code+Execution+Attack+Against+DSL+Modems/21759/ Paypal OAuth Vulnerability http://blog.intothesymmetry.com/2016/11/all-your-paypal-tokens-belong-to-me.html

ISC StormCast for Monday, November 28th 2016 28.11.2016

Extracting Shellcode from Javascript https://isc.sans.edu/forums/diary/Extracting+Shellcode+From+JavaScript/21753/ Using Scapy to Test CozyDuke Snort Signatures https://isc.sans.edu/forums/diary/Scapy+vs+CozyDuke/21755/ Malicious JPEG Spreading via Facebook http://blog.checkpoint.com/2016/11/24/imagegate-check-point-uncovers-new-method-distributing-malware-images/ San Francisco Public Transport ("...

ISC StormCast for Wednesday, November 23rd 2016 23.11.2016

WordPress RCE Via Fake Updates http://www.openwall.com/lists/oss-security/2016/11/21/3 Turning Speakers into Microphones http://cyber.bgu.ac.il/advanced-cyber/system/files/SPEAKEaR.pdf 5 Second Video iOS Crash http://www.cultofmac.com/455215/455215/ "Stubby" Implements Encrypted DNS http://www.theregister.co.uk/2016/11/22/dns_boffins_offer_up_privacy_test/

ISC StormCast for Tuesday, November 22nd 2016 21.11.2016

Encrypted ZIP File With Comments https://isc.sans.edu/forums/diary/ZIP+With+Comment/21737/ Siemens Surveilance Cameras Use Static Default Password https://ics-cert.us-cert.gov/advisories/ICSA-16-322-01 NTP Single Packet DoS Vulnerablity http://dumpco.re/cve-2016-7434/ Windows 10 Does Not Provide the Same Protections as EMET https://insights.sei.cmu.edu/cert/2016/11/windows-10-cannot-protect-insecu...

ISC StormCast for Monday, November 21st 2016 21.11.2016

Converting Timestamps with Epocalypse https://isc.sans.edu/forums/diary/How+many+Epoch+times+Epocalypsepy+timestamp+converter/21733/ SIP Disabled on Some Macbook Pros http://www.macrumors.com/2016/11/17/system-integrity-protection-disabled-macbook-pro/ Spoofing Microsoft.com E-Mails with Outlook.com https://www.utkusen.com/blog/sending-valid-phishing-emails-from-microsoftcom.html Various High Prof...

ISC StormCast for Friday, November 18th 2016 18.11.2016

Phishers Protect Phishing Sites from Security Researchers https://isc.sans.edu/forums/diary/Example+of+Getting+Analysts+Researchers+Away/21721/ Fedora / Chrome Automatic Downloads and Code Execution https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html Volutility Version 1.0 Released https://techanarchy.net/2016/11/volutility-version-1-0-release/ iOS Synchronizing...

ISC StormCast for Thursday, November 17th 2016 17.11.2016

Russian Malspam Distributing Troldesh Ransomware https://isc.sans.edu/forums/diary/Malspam+distributing+Troldesh+ransomware/21717/ Poisontap Exploits USB Ethernet Adapters https://samy.pl/poisontap/ Symantec Patches Untrusted DLL Loading Vulnerability https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20161115_00 VMWare Pat...

ISC StormCast for Wednesday, November 16th 2016 16.11.2016

Vulnerability in LUKS Can Be used to Boot Encrypted Linux Systems http://betanews.com/2016/11/15/linux-security-bug-cryptsetup-luks/ Shazam Keeps Microphone Turned on Even While not "Listening" https://objective-see.com/blog/blog_0x13.html nginx Privilege Escalation Vulnerability (Debian Only) http://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html

ISC StormCast for Tuesday, November 15th 2016 15.11.2016

Indictment for the theft of FIFA Game Coins https://regmedia.co.uk/2016/11/14/fifafraudindictment.pdf Crysis Ransomware Master Encryption Key Released http://www.bleepingcomputer.com/news/security/master-decryption-keys-and-decryptor-for-the-crysis-ransomware-released-/ Adult Friend Finder Breached https://www.leakedsource.com/blog/friendfinder Lightbulb Web Application Firewall Auditing Framework...

ISC StormCast for Monday, November 14th 2016 14.11.2016

EMET Will Defeat Shell Code Executing Inside Word https://isc.sans.edu/forums/diary/VBA+Shellcode+and+EMET/21705/ Bitcoin Miners Distributed via FTP Exploits https://isc.sans.edu/forums/diary/Bitcoin+Miner+File+Upload+via+FTP/21707/ 5 Russian Banks Suffer DoS Attack https://www.rt.com/news/366172-russian-banks-ddos-attack/ Wifi May Reveal Mobile Phone Passwords http://dl.acm.org/citation.cfm?id=29...

ISC StormCast for Friday, November 11th 2016 11.11.2016

ICMP Unreachable DoS Attacks https://isc.sans.edu/forums/diary/ICMP+Unreachable+DoS+Attacks+aka+Black+Nurse/21699/ OpenSSL 1.1.0 Patch https://www.openssl.org/news/secadv/20161110.txt OWASP ModSecurity Core Rule Set Version 3.0.0 Release https://lists.owasp.org/pipermail/owasp-modsecurity-core-rule-set/2016-November/002265.html

ISC StormCast for Thursday, November 10th 2016 09.11.2016

DoS Attack Turns off Heat for More then a Week http://www.hs.fi/kotimaa/a1478495966653 (finish only) DLink HNAP Vulnerability https://raw.githubusercontent.com/pedrib/PoC/master/advisories/dlink-hnap-login.txt PoC Exploits Available for Two MSFT Vulnerabilities https://github.com/tinysec/public/tree/master/CVE-2016-7255 https://g-laurent.blogspot.com/2016/11/ms16-137-lsass-remote-memory-corruption...

ISC StormCast for Wednesday, November 9th 2016 08.11.2016

Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/November+2016+Microsoft+Patch+Day/21689/ Adobe Updates https://helpx.adobe.com/security/products/connect/apsb16-35.html https://helpx.adobe.com/security/products/flash-player/apsb16-37.html

ISC StormCast for Tuesday, November 8th 2016 08.11.2016

Tesco Bank Limits Online Banking After Online Criminal Activity https://yourcommunity.tescobank.com/t5/News/Message-for-Current-Account-customers/td-p/6599 Belkin WeMo Devices Used To Attack Mobile Devices https://www.blackhat.com/eu-16/briefings/schedule/index.html#breaking-bhad-abusing-belkin-home-automation-devices-4640 Fake Retail Apps Flooding Apple App Store http://www.nytimes.com/2016/11/07...

ISC StormCast for Monday, November 7th 2016 07.11.2016

Hancitor Maldoc Bypasses Application Whitelisting https://isc.sans.edu/forums/diary/Hancitor+Maldoc+Bypasses+Application+Whitelisting/21683/ Microsoft Extends EMET Support Deadline https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/ Wifi Based IMSI Catcher https://www.blackhat.com/docs/eu-16/materials/eu-16-OHanlon-WiFi-IMSI-Catcher.pdf

ISC StormCast for Friday, November 4th 2016 03.11.2016

Reconstruct Binaries Sent via Telnet https://isc.sans.edu/forums/diary/Extracting+Malware+Transmitted+Via+Telnet/21673/ Wix.com DOM Based XSS https://www.contrastsecurity.com/security-influencers/dom-xss-in-wix.com DNS Based Mail Security https://nccoe.nist.gov/projects/building_blocks/secured_email Web of Trust Plugin Released Anonymized User Data https://www.mywot.com/en/forum/70396--virus-spywa...

ISC StormCast for Thursday, November 3rd 2016 03.11.2016

Exchange Web Service Two-Factor Authentication Bypass http://www.blackhillsinfosec.com/?p=5396 Barracuda DoS Disrupts Mail Delivery http://status.barracuda.com Targobank Looses Account Data After Maintenance http://www.spiegel.de/wirtschaft/service/targobank-kunden-fehlt-geld-auf-dem-konto-it-probleme-a-1119434.html (german only) Ouch! Security Awareness Newsletter http://securingthehuman.sans.org...

ISC StormCast for Wednesday, November 2nd 2016 02.11.2016

Malvertising On Google AdWords Targeting macOS Users http://blog.cylance.com/malvertising-on-google-adwords-targeting-macos-users Microsoft Response to Google Privilege Escalation Disclosure https://blogs.technet.microsoft.com/mmpc/2016/11/01/our-commitment-to-our-customers-security/ Memcached Remote Code Execution Vulnerabilities http://blog.talosintel.com/2016/10/memcached-vulnerabilities.html S...

ISC StormCast for Tuesday, November 1st 2016 01.11.2016

snapshot.ps1 DFIR Capture https://isc.sans.edu/forums/diary/SEC505+DFIR+capture+script+snapshotps1/21659/ Predicting Domain Reputation http://www.icir.org/vern/papers/predator-ccs16.pdf Mozilla Removing Battery Status API For Privacy Reasons https://www.fxsitecompat.com/en-CA/docs/2016/battery-status-api-has-been-removed/ Windows Privilege Escalation 0-day Actively Exploited https://security.googl...

ISC StormCast for Monday, October 31st 2016 31.10.2016

Volatility Bot: Automated Memory Analysis https://isc.sans.edu/forums/diary/Volatility+Bot+Automated+Memory+Analysis/21655/ 911 System Fragility Exposed in Accidental DoS Attacks https://staging.mcso.org/Multimedia/PressRelease/911%20Cyber%20Attack.pdf Vulnerability in Mirai Botnet https://www.invincealabs.com/blog/2016/10/killing-mirai/ XNU Kernel (iOS/macOS) task_t Privildge Escalation https://g...

ISC StormCast for Friday, October 28th 2016 27.10.2016

Small Changes to Ransomware E-Mails May Fool Some Mail Filters https://isc.sans.edu/forums/diary/Your+Bill+Is+Not+Overdue+today/21647/ Microsoft / Google Release Browser Updates to Address Flash Vulnerablity https://technet.microsoft.com/en-us/library/security/ms16-128.aspx https://googlechromereleases.blogspot.com Social Media "Support" Phishing https://www.proofpoint.com/us/corporate-blog/post/c...

Listen to the SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.