Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

News EN ↓ 2472 episodes

A brief daily summary of what is important in cyber security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually about 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Author

Johannes B. Ullrich

Category

News

Podcast website

isc.sans.edu

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

ISC StormCast for Monday, May 2nd 2016 02.05.2016

ATM Jackpotting: Analysis of ATM APIs https://securelist.com/analysis/publications/74533/malware-and-non-malware-ways-for-atm-jackpotting-extended-cut/ Reverse Engineering A ATM Machine Skimmer https://trustfoundry.net/reverse-engineering-a-discovered-atm-skimmer/ Bathroom Scale Vulnerability https://help.fitbit.com/articles/en_US/Help_article/How-do-I-update-my-Aria-scale/ Fake Mobile Payment App...

ISC StormCast for Friday, April 29th 2016 29.04.2016

Powershell and DNS/DHCP https://isc.sans.edu/forums/diary/DNS+and+DHCP+Recon+using+Powershell/20995/ New Version of PCI Standard Released https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2_Summary_of_Changes.pdf OpenSSL Patch Pre-Announced https://mta.openssl.org/pipermail/openssl-announce/2016-April/000069.html NTP Patches http://blog.talosintel.com/2016/04/vulnerability-spotlight-furthe...

ISC StormCast for Thursday, April 28th 2016 28.04.2016

SAML Federated Identity Vulnerability in Office 365 http://www.economyofmechanism.com/office365-authbypass.html .AS Registry Vulnerable to Direct Object Reference https://isecguy.wordpress.com/2016/04/25/flaw-allowed-anyone-to-modify-take-control-over-any-as-domain/ Driveby Exploit Used to Deliver Android Ransomware https://www.bluecoat.com/security-blog/2016-04-25/android-exploit-delivers-dogspec...

ISC StormCast for Wednesday, April 27th 2016 27.04.2016

OS X Memory Forensics https://isc.sans.edu/forums/diary/An+Introduction+to+Mac+memory+forensics/20989/ Facebook App Used to Delivery Facebook Phish http://news.netcraft.com/archives/2016/04/22/hook-like-and-sinker-facebook-serves-up-its-own-phish.html Android. Spy.277.origin Keeps Being Delivered By Google Play Store Apps http://blog.checkpoint.com/2016/04/22/in-the-wild-google-cant-close-the-door...

ISC StormCast for Tuesday, April 26th 2016 26.04.2016

Details From the Breach of the Central Bank of Bangladesh http://baesystemsai.blogspot.de/2016/04/two-bytes-to-951m.html Apple Image IO Denial of Service https://www.landaire.net/blog/apple-imageio-denial-of-service/ Text Messages Used to Phish Apple IDs http://www.independent.co.uk/life-style/gadgets-and-tech/news/apple-id-password-expired-expiry-text-website-scam-phishing-a6991126.html Critical...

ISC StormCast for Monday, April 25th 2016 25.04.2016

Angler EK Used to Spread CryptXXX https://isc.sans.edu/forums/diary/Angler+Exploit+Kit+Bedep+and+CryptXXX/20981/ Honeports Powershell Script https://isc.sans.edu/forums/diary/Honeyports+powershell+script/20979/ Online Credit Card Fraud Soars http://www.pymnts.com/fraud-prevention/2016/online-fraud-attack-rates-soar-since-october/ How to Trick Traffic Sensors https://securelist.com/blog/research/74...

ISC StormCast for Friday, April 22nd 2016 22.04.2016

Accellion Secure File Transfer Vulnerability and Facebook Exploitation http://devco.re/blog/2016/04/21/how-I-hacked-facebook-and-found-someones-backdoor-script-eng-ver/ Application Whitelisting Bypass With regsvr32 http://subt0x10.blogspot.com/2016/04/bypass-application-whitelisting-script.html New NetworkManager Version Released https://cgit.freedesktop.org/NetworkManager/NetworkManager/plain/NEW...

ISC StormCast for Thursday, April 21st 2016 21.04.2016

Decoding Pseudo Darkleech https://isc.sans.edu/forums/diary/Decoding+PseudoDarkleech+1/20969/ Tesla Crypt 4.1 https://www.endgame.com/blog/your-package-has-been-successfully-encrypted-teslacrypt-41a-and-malware-attack-chain RansomWhere Protects OS X Users from Ransware https://objective-see.com/products/ransomwhere.html Testing TLS Libraries With TLS Attackers https://github.com/RUB-NDS/TLS-Attack...

ISC StormCast for Wednesday, April 20th 2016 20.04.2016

Oracle Critical Patch Update http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html Flash Provides Top Targeted Vulnerabilties for 2015 https://www.solutionary.com/_assets/pdf/research/2015-gtir.pdf Google Publishes Data About Safe Browsing Effectiveness http://static.googleusercontent.com/media/research.google.com/en//pubs/archive/44924.pdf Detecting curl pipes to bash http...

ISC StormCast for Tuesday, April 19th 2016 19.04.2016

Retefer Banking Malware Appearing Again https://isc.sans.edu/forums/diary/Retefe+is+back+in+town/20957/ Ransomware Switching Focus From Hospitals to Schools http://blog.talosintel.com/2016/04/jboss-backdoor.html git on OS X vulnerable https://rachelbythebay.com/w/2016/04/17/unprotected/

ISC StormCast for Monday, April 18th 2016 18.04.2016

Implementing "bash_history" for cmd.exe https://isc.sans.edu/forums/diary/Windows+Command+Line+Persistence/20949/ Mixed encoding in Malicious Documents https://isc.sans.edu/forums/diary/VBS+VBE/20953/ Swedish Air Traffic Control Outage Result of Solar Flares http://www.lfv.se/en/news/news-2016/full-capacity-after-90-minutes-radar-loss Why you should not require password changes https://www.cesg.go...

ISC StormCast for Friday, April 15th 2016 15.04.2016

Doing HTTP Key Pinning Right https://isc.sans.edu/forums/diary/HTTP+Public+Key+Pinning+How+to+do+it+right/20943/ Apple Ceases Support for Quicktime on Windows https://support.apple.com/HT205771 http://zerodayinitiative.com/advisories/ZDI-16-241/ VMWare Releases Patch for VMWare Client Plugin http://www.vmware.com/security/advisories/VMSA-2016-0004.html Identify Ransomware https://id-ransomware.mal...

ISC StormCast for Thursday, April 14th 2016 - Part 2 14.04.2016

PFSense DShield Client Updated for PFSense Version 2.3 https://isc.sans.edu/forums/diary/Updated+PFSense+Client/20937/ JigSaw Decryption Tool Released http://www.bleepingcomputer.com/news/security/jigsaw-ransomware-decrypted-will-delete-your-files-until-you-pay-the-ransom/ Android Bluetooth Pairing Vulnerability https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-android-bluetooth-pairing-bypas...

ISC StormCast for Thursday, April 14th 2016 14.04.2016

Badlock not as bad https://isc.sans.edu/forums/diary/BadLock+Vulnerability+CVE20162118/20933/ Microsoft Patches https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+Summary+for+April+2016+httpsiscsansedumspatchdayshtmlviewday20160412/20935

ISC StormCast for Tuesday, April 12th 2016 12.04.2016

Petyz Ransomware Decrypted https://isc.sans.edu/forums/diary/Tool+Released+to+Decrypt+Petya+Ransomware+Infected+Disks/20929/ Malware Creator Bribes Anti-Virus Vendors http://blog.checkpoint.com/2016/04/08/qihoo-360-just-the-tip-of-the-whitelisted-malware-iceberg/ User Will Plug in USB Drives They Find In The Parking Lot https://www.elie.net/publication/users-really-do-plug-in-usb-drives-they-find...

ISC StormCast for Sunday, April 10th 2016 10.04.2016

Flash Releases Pre-Announced Emergency Patch https://helpx.adobe.com/security/products/flash-player/apsb16-10.html http://blog.trendmicro.com/trendlabs-security-intelligence/look-adobe-flash-player-cve-2016-1019-zero-day-vulnerability/ Wordpress Will Start Using SSL https://en.blog.wordpress.com/2016/04/08/https-everywhere-encryption-for-all-wordpress-com-sites/ iMessage Vulnerablitiy Allows Acces...

ISC StormCast for Friday, April 8th 2016 08.04.2016

Google/Facebook CAPTCHA Broken Again https://www.blackhat.com/docs/asia-16/materials/asia-16-Sivakorn-Im-Not-a-Human-Breaking-the-Google-reCAPTCHA-wp.pdf Updated FBI Damage Numbers For Business E-Mail Compromise https://www.fbi.gov/phoenix/press-releases/2016/fbi-warns-of-dramatic-increase-in-business-e-mail-scams PowerWare / PoshCoder Ransomware Decryption https://www.alienvault.com/open-threat-e...

ISC StormCast for Thursday, April 7th 2016 07.04.2016

Cisco Security Advisory https://tools.cisco.com/security/center/publicationListing.x#~CiscoSecurityAdvisory OSVDB Closes Down https://blog.osvdb.org/2016/04/05/osvdb-fin/ Apple iOS Passcode Bypass Vulnerability http://seclists.org/fulldisclosure/2016/Apr/19 Securing the Human: Ouch Newsletter https://securingthehuman.sans.org/resources/newsletters/ouch/2016

ISC StormCast for Wednesday, April 6th 2016 06.04.2016

New Microsoft Patches API https://isc.sans.edu/forums/diary/New+Features+for+Microsoft+Patch+Data/20911/ BadLock Webcast https://www.sans.org/webcasts/badlock-102107 Microsoft Single Signon Vulnerable to Token Hijacking https://whitton.xyz/articles/obtaining-tokens-outlook-office-azure-account/ Domino's Pizza Mobile App Payment Bypass http://www.ifc0nfig.com/dominos-pizza-and-payments/

ISC StormCast for Tuesday, April 5th 2016 05.04.2016

Android Patch Monday https://source.android.com/security/bulletin/2016-04-02.html Jenkins Continous Integration Tool Leaks Anonymous Usage Data https://jenkins.io/blog/2016/03/30/usage-statistics-privacy-advisory/ BREACH Attack Revived/Improved audio: https://regmedia.co.uk/2016/04/04/podcast_beast_2_bhasia.mp3 slides: https://www.blackhat.com/docs/asia-16/materials/asia-16-Karakostas-Practical-Ne...

ISC StormCast for Monday, April 4th 2016 04.04.2016

Tips for Stopping Ransomware https://isc.sans.edu/forums/diary/Tips+for+Stopping+Ransomware/20903/ Vulnerability in Lhasa decompression library http://blog.talosintel.com/2016/03/vulnerability-lhasa.html How to Decrypt Kimcilware Encrypted Files http://blog.fortinet.com/post/kimcilware-ransomware-how-to-decrypt-encrypted-files-and-who-is-behind-it Fileless Malware http://blog.airbuscybersecurity.c...

ISC StormCast for Friday, April 1st 2016 01.04.2016

Trend Micro Leaves Remote Debugger in Password Manager https://bugs.chromium.org/p/project-zero/issues/detail?id=773&can=1&q=trend Several Palo Alto Vulnerabilities https://www.troopers.de/media/filer_public/a5/4d/a54da07e-3780-4f83-b4ac-8c620666a60a/paloalto_troopers.pdf Bypassing The iOS Gatekeeper https://www.checkpoint.com/resources/sidestepper-ios-vulnerability/iOS_Vulnerability_Report_160330...

Listen to the SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.