Johannes B. Ullrich
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in cyber security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually about 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
ISC StormCast for Monday, May 2nd 2016 02.05.2016 5:44
ATM Jackpotting: Analysis of ATM APIs https://securelist.com/analysis/publications/74533/malware-and-non-malware-ways-for-atm-jackpotting-extended-cut/ Reverse Engineering A ATM Machine Skimmer https://trustfoundry.net/reverse-engineering-a-discovered-atm-skimmer/ Bathroom Scale Vulnerability https://help.fitbit.com/articles/en_US/Help_article/How-do-I-update-my-Aria-scale/ Fake Mobile Payment App...
ISC StormCast for Friday, April 29th 2016 29.04.2016 5:09
Powershell and DNS/DHCP https://isc.sans.edu/forums/diary/DNS+and+DHCP+Recon+using+Powershell/20995/ New Version of PCI Standard Released https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2_Summary_of_Changes.pdf OpenSSL Patch Pre-Announced https://mta.openssl.org/pipermail/openssl-announce/2016-April/000069.html NTP Patches http://blog.talosintel.com/2016/04/vulnerability-spotlight-furthe...
ISC StormCast for Thursday, April 28th 2016 28.04.2016 5:19
SAML Federated Identity Vulnerability in Office 365 http://www.economyofmechanism.com/office365-authbypass.html .AS Registry Vulnerable to Direct Object Reference https://isecguy.wordpress.com/2016/04/25/flaw-allowed-anyone-to-modify-take-control-over-any-as-domain/ Driveby Exploit Used to Deliver Android Ransomware https://www.bluecoat.com/security-blog/2016-04-25/android-exploit-delivers-dogspec...
ISC StormCast for Wednesday, April 27th 2016 27.04.2016 5:02
OS X Memory Forensics https://isc.sans.edu/forums/diary/An+Introduction+to+Mac+memory+forensics/20989/ Facebook App Used to Delivery Facebook Phish http://news.netcraft.com/archives/2016/04/22/hook-like-and-sinker-facebook-serves-up-its-own-phish.html Android. Spy.277.origin Keeps Being Delivered By Google Play Store Apps http://blog.checkpoint.com/2016/04/22/in-the-wild-google-cant-close-the-door...
ISC StormCast for Tuesday, April 26th 2016 26.04.2016 5:23
Details From the Breach of the Central Bank of Bangladesh http://baesystemsai.blogspot.de/2016/04/two-bytes-to-951m.html Apple Image IO Denial of Service https://www.landaire.net/blog/apple-imageio-denial-of-service/ Text Messages Used to Phish Apple IDs http://www.independent.co.uk/life-style/gadgets-and-tech/news/apple-id-password-expired-expiry-text-website-scam-phishing-a6991126.html Critical...
ISC StormCast for Monday, April 25th 2016 25.04.2016 5:10
Angler EK Used to Spread CryptXXX https://isc.sans.edu/forums/diary/Angler+Exploit+Kit+Bedep+and+CryptXXX/20981/ Honeports Powershell Script https://isc.sans.edu/forums/diary/Honeyports+powershell+script/20979/ Online Credit Card Fraud Soars http://www.pymnts.com/fraud-prevention/2016/online-fraud-attack-rates-soar-since-october/ How to Trick Traffic Sensors https://securelist.com/blog/research/74...
ISC StormCast for Friday, April 22nd 2016 22.04.2016 5:18
Accellion Secure File Transfer Vulnerability and Facebook Exploitation http://devco.re/blog/2016/04/21/how-I-hacked-facebook-and-found-someones-backdoor-script-eng-ver/ Application Whitelisting Bypass With regsvr32 http://subt0x10.blogspot.com/2016/04/bypass-application-whitelisting-script.html New NetworkManager Version Released https://cgit.freedesktop.org/NetworkManager/NetworkManager/plain/NEW...
ISC StormCast for Thursday, April 21st 2016 21.04.2016 5:13
Decoding Pseudo Darkleech https://isc.sans.edu/forums/diary/Decoding+PseudoDarkleech+1/20969/ Tesla Crypt 4.1 https://www.endgame.com/blog/your-package-has-been-successfully-encrypted-teslacrypt-41a-and-malware-attack-chain RansomWhere Protects OS X Users from Ransware https://objective-see.com/products/ransomwhere.html Testing TLS Libraries With TLS Attackers https://github.com/RUB-NDS/TLS-Attack...
ISC StormCast for Wednesday, April 20th 2016 20.04.2016 6:36
Oracle Critical Patch Update http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html Flash Provides Top Targeted Vulnerabilties for 2015 https://www.solutionary.com/_assets/pdf/research/2015-gtir.pdf Google Publishes Data About Safe Browsing Effectiveness http://static.googleusercontent.com/media/research.google.com/en//pubs/archive/44924.pdf Detecting curl pipes to bash http...
ISC StormCast for Tuesday, April 19th 2016 19.04.2016 5:26
Retefer Banking Malware Appearing Again https://isc.sans.edu/forums/diary/Retefe+is+back+in+town/20957/ Ransomware Switching Focus From Hospitals to Schools http://blog.talosintel.com/2016/04/jboss-backdoor.html git on OS X vulnerable https://rachelbythebay.com/w/2016/04/17/unprotected/
ISC StormCast for Monday, April 18th 2016 18.04.2016 5:54
Implementing "bash_history" for cmd.exe https://isc.sans.edu/forums/diary/Windows+Command+Line+Persistence/20949/ Mixed encoding in Malicious Documents https://isc.sans.edu/forums/diary/VBS+VBE/20953/ Swedish Air Traffic Control Outage Result of Solar Flares http://www.lfv.se/en/news/news-2016/full-capacity-after-90-minutes-radar-loss Why you should not require password changes https://www.cesg.go...
ISC StormCast for Friday, April 15th 2016 15.04.2016 5:50
Doing HTTP Key Pinning Right https://isc.sans.edu/forums/diary/HTTP+Public+Key+Pinning+How+to+do+it+right/20943/ Apple Ceases Support for Quicktime on Windows https://support.apple.com/HT205771 http://zerodayinitiative.com/advisories/ZDI-16-241/ VMWare Releases Patch for VMWare Client Plugin http://www.vmware.com/security/advisories/VMSA-2016-0004.html Identify Ransomware https://id-ransomware.mal...
ISC StormCast for Thursday, April 14th 2016 - Part 2 14.04.2016 5:21
PFSense DShield Client Updated for PFSense Version 2.3 https://isc.sans.edu/forums/diary/Updated+PFSense+Client/20937/ JigSaw Decryption Tool Released http://www.bleepingcomputer.com/news/security/jigsaw-ransomware-decrypted-will-delete-your-files-until-you-pay-the-ransom/ Android Bluetooth Pairing Vulnerability https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-android-bluetooth-pairing-bypas...
ISC StormCast for Thursday, April 14th 2016 14.04.2016 7:28
Badlock not as bad https://isc.sans.edu/forums/diary/BadLock+Vulnerability+CVE20162118/20933/ Microsoft Patches https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+Summary+for+April+2016+httpsiscsansedumspatchdayshtmlviewday20160412/20935
ISC StormCast for Tuesday, April 12th 2016 12.04.2016 5:39
Petyz Ransomware Decrypted https://isc.sans.edu/forums/diary/Tool+Released+to+Decrypt+Petya+Ransomware+Infected+Disks/20929/ Malware Creator Bribes Anti-Virus Vendors http://blog.checkpoint.com/2016/04/08/qihoo-360-just-the-tip-of-the-whitelisted-malware-iceberg/ User Will Plug in USB Drives They Find In The Parking Lot https://www.elie.net/publication/users-really-do-plug-in-usb-drives-they-find...
ISC StormCast for Sunday, April 10th 2016 10.04.2016 6:33
Flash Releases Pre-Announced Emergency Patch https://helpx.adobe.com/security/products/flash-player/apsb16-10.html http://blog.trendmicro.com/trendlabs-security-intelligence/look-adobe-flash-player-cve-2016-1019-zero-day-vulnerability/ Wordpress Will Start Using SSL https://en.blog.wordpress.com/2016/04/08/https-everywhere-encryption-for-all-wordpress-com-sites/ iMessage Vulnerablitiy Allows Acces...
ISC StormCast for Friday, April 8th 2016 08.04.2016 5:37
Google/Facebook CAPTCHA Broken Again https://www.blackhat.com/docs/asia-16/materials/asia-16-Sivakorn-Im-Not-a-Human-Breaking-the-Google-reCAPTCHA-wp.pdf Updated FBI Damage Numbers For Business E-Mail Compromise https://www.fbi.gov/phoenix/press-releases/2016/fbi-warns-of-dramatic-increase-in-business-e-mail-scams PowerWare / PoshCoder Ransomware Decryption https://www.alienvault.com/open-threat-e...
ISC StormCast for Thursday, April 7th 2016 07.04.2016 4:50
Cisco Security Advisory https://tools.cisco.com/security/center/publicationListing.x#~CiscoSecurityAdvisory OSVDB Closes Down https://blog.osvdb.org/2016/04/05/osvdb-fin/ Apple iOS Passcode Bypass Vulnerability http://seclists.org/fulldisclosure/2016/Apr/19 Securing the Human: Ouch Newsletter https://securingthehuman.sans.org/resources/newsletters/ouch/2016
ISC StormCast for Wednesday, April 6th 2016 06.04.2016 6:14
New Microsoft Patches API https://isc.sans.edu/forums/diary/New+Features+for+Microsoft+Patch+Data/20911/ BadLock Webcast https://www.sans.org/webcasts/badlock-102107 Microsoft Single Signon Vulnerable to Token Hijacking https://whitton.xyz/articles/obtaining-tokens-outlook-office-azure-account/ Domino's Pizza Mobile App Payment Bypass http://www.ifc0nfig.com/dominos-pizza-and-payments/
ISC StormCast for Tuesday, April 5th 2016 05.04.2016 4:54
Android Patch Monday https://source.android.com/security/bulletin/2016-04-02.html Jenkins Continous Integration Tool Leaks Anonymous Usage Data https://jenkins.io/blog/2016/03/30/usage-statistics-privacy-advisory/ BREACH Attack Revived/Improved audio: https://regmedia.co.uk/2016/04/04/podcast_beast_2_bhasia.mp3 slides: https://www.blackhat.com/docs/asia-16/materials/asia-16-Karakostas-Practical-Ne...
ISC StormCast for Monday, April 4th 2016 04.04.2016 5:33
Tips for Stopping Ransomware https://isc.sans.edu/forums/diary/Tips+for+Stopping+Ransomware/20903/ Vulnerability in Lhasa decompression library http://blog.talosintel.com/2016/03/vulnerability-lhasa.html How to Decrypt Kimcilware Encrypted Files http://blog.fortinet.com/post/kimcilware-ransomware-how-to-decrypt-encrypted-files-and-who-is-behind-it Fileless Malware http://blog.airbuscybersecurity.c...
ISC StormCast for Friday, April 1st 2016 01.04.2016 5:30
Trend Micro Leaves Remote Debugger in Password Manager https://bugs.chromium.org/p/project-zero/issues/detail?id=773&can=1&q=trend Several Palo Alto Vulnerabilities https://www.troopers.de/media/filer_public/a5/4d/a54da07e-3780-4f83-b4ac-8c620666a60a/paloalto_troopers.pdf Bypassing The iOS Gatekeeper https://www.checkpoint.com/resources/sidestepper-ios-vulnerability/iOS_Vulnerability_Report_160330...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.