<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:cc="http://web.resource.org/cc/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:podcast="https://podcastindex.org/namespace/1.0">

<channel>
<atom:link href="https://pcr.apple.com/id304863991"  rel="self" type="application/rss+xml" />
<title>SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)</title>
<link>https://isc.sans.edu/podcast.html#stormcast</link>
<language>en-us</language>
<copyright>(c) SANS Institute 2026 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/</copyright>
  <lastBuildDate>Fri, 17 Apr 2026 02:00:02 GMT</lastBuildDate>
  <pubDate>Fri, 17 Apr 2026 02:00:02 GMT</pubDate>
<image>
<url>https://isc.sans.edu/images/podcast3000.jpg</url>
<title>SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)</title>
<link>https://isc.sans.edu/podcast.html#stormcast</link>
<description>Daily cybersecurity news for practitioners. Vulnerabilities, defenses, threats, network security insight, research and more to make you sound smarter as you get to the office in the morning. New each weekday.</description>
</image>		
<itunes:subtitle>Daily update on current cyber security threats</itunes:subtitle>
<itunes:author>Johannes B. Ullrich</itunes:author>
<itunes:summary>
A brief daily summary of what is important in cyber security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually about 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
</itunes:summary>
<description>
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
</description>
<itunes:owner>
<itunes:name>SANS ISC Handlers</itunes:name>
<itunes:email>handlers@isc.sans.edu</itunes:email>
</itunes:owner>
<itunes:type>episodic</itunes:type>
<itunes:image href="https://isc.sans.edu/images/podcast3000.jpg"/>
<itunes:category text="News">
  <itunes:category text="Tech News" />
</itunes:category>
<itunes:explicit>no</itunes:explicit>

<item>
<title>SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9896</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9896.mp3" length="4985138" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9896.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9896</link>
<pubDate>Fri, 17 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Compromised DVRs and Finding Them in the Wild<br/>
<a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886</a><br/>
Cisco ISE RCE Vulnerability and WebEx Auth Bypass CVE-2026-20184 CVE-2026-20180 CVE-2026-20186<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv</a><br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL</a><br/>
Windows Defender 0-Day (RedSun)<br/>
<a href="https://github.com/Nightmare-Eclipse/RedSun">https://github.com/Nightmare-Eclipse/RedSun</a><br/>
Sonatype Vulnerability CVE-2026-5189<br/>
<a href="https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15">https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9896" type="text/plain" language="en" />
<itunes:keywords>sonatype, windows, defender, hardcoded, password, cisco, DVR, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9894</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9894.mp3" length="5784384" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9894.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9894</link>
<pubDate>Thu, 16 Apr 2026 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Scanning for AI Models<br/>
<a href="https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896">https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896</a><br/>
Microsoft Update Problems<br/>
<a href="https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update">https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update</a><br/>
Microsoft RDP File Warnings<br/>
<a href="https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings">https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings</a><br/>
AI GitHub Action Vulnerabilities<br/>
<a href="https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/">https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/</a><br/>
<a href="https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/">https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/</a><br/>
Wireguard Update<br/>
<a href="https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html">https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9894" type="text/plain" language="en" />
<itunes:keywords>wireguard, microsoft, github, action, rdp, updates, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9892</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9892.mp3" length="7172816" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9892.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9892</link>
<pubDate>Wed, 15 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday April 2026<br/>
<a href="https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/">https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/</a><br/>
Adobe Patches<br/>
<a href="https://helpx.adobe.com/security/Home.html">https://helpx.adobe.com/security/Home.html</a><br/>
Fortinet Patches<br/>
<a href="https://fortiguard.fortinet.com/psirt">https://fortiguard.fortinet.com/psirt</a><br/>
]]></description>
<itunes:duration>8:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9892" type="text/plain" language="en" />
<itunes:keywords>Fortinet, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, April 14th, 2026: EncystPHP Webshell; CPUID Compromise; OpenAI Mac Cert Issue; Axios Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9890</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, April 14th, 2026: EncystPHP Webshell; CPUID Compromise; OpenAI Mac Cert Issue; Axios Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, April 14th, 2026: EncystPHP Webshell; CPUID Compromise; OpenAI Mac Cert Issue; Axios Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9890.mp3" length="5785990" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9890.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9890</link>
<pubDate>Tue, 14 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scans for EncystPHP Webshell<br/>
<a href="https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892">https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892</a><br/>
CPUID Compromise<br/>
<a href="https://securelist.com/tr/cpu-z/119365/">https://securelist.com/tr/cpu-z/119365/</a><br/>
<a href="https://x.com/d0cTB/status/2042520961824559150">https://x.com/d0cTB/status/2042520961824559150</a><br/>
OpenAI Mac Application Update due to Axios Compromise<br/>
<a href="https://openai.com/index/axios-developer-tool-compromise/">https://openai.com/index/axios-developer-tool-compromise/</a><br/>
Axios Vulnerability CVE-2026-40175<br/>
<a href="https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx">https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9890" type="text/plain" language="en" />
<itunes:keywords>axios, openai, mac, cpuid, encystphp, webshell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, April 13th, 2026: Obfuscated JavaScript; Numbers in Passwords; Adobe Patches 0-Day; ClickFix Fix Bypass
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9888</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, April 13th, 2026: Obfuscated JavaScript; Numbers in Passwords; Adobe Patches 0-Day; ClickFix Fix Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, April 13th, 2026: Obfuscated JavaScript; Numbers in Passwords; Adobe Patches 0-Day; ClickFix Fix Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9888.mp3" length="5456324" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9888.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9888</link>
<pubDate>Mon, 13 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Obfuscated JavaScript or Nothing<br/>
<a href="https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884">https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884</a><br/>
Numbers in Passwords<br/>
<a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866</a><br/>
Adobe 0-Day Patch CVE-2026-34621<br/>
<a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a><br/>
ClickFix Bypass via ScriptEditor<br/>
<a href="https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/">https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/</a><br/>
]]></description>
<itunes:duration>6:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9888" type="text/plain" language="en" />
<itunes:keywords>javascript, numbers, obfuscation, passwords, adobe, acrobat, reader, clickfix, macos, scripteditor, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9886</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9886.mp3" length="6447318" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9886.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9886</link>
<pubDate>Thu, 09 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Honeypot Fingerprinting<br/>
<a href="https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878">https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878</a><br/>
Microsoft Locks Accounts for Privacy/Encryption Related Developers<br/>
<a href="https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/">https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/</a> <a href="https://news.ycombinator.com/item?id=47687884">https://news.ycombinator.com/item?id=47687884</a> <a href="https://x.com/windscribecom/status/2041929519628443943">https://x.com/windscribecom/status/2041929519628443943</a><br/>
<a href="https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/">https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/</a><br/>
Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)<br/>
<a href="https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/">https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/</a><br/>
]]></description>
<itunes:duration>7:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9886" type="text/plain" language="en" />
<itunes:keywords>apache, activeMQ, microsoft, developers, veracrypt, wireguard, windscribe, fingerprinting, honeypot, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9884</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9884.mp3" length="5224001" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9884.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9884</link>
<pubDate>Wed, 08 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?<br/>
<a href="https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874">https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874</a><br/>
WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UI<br/>
<a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009</a><br/>
Project Glasswing<br/>
<a href="https://www.anthropic.com/glasswing">https://www.anthropic.com/glasswing</a><br/>
Current Threats Against Kubernetes<br/>
<a href="https://unit42.paloaltonetworks.com/modern-kubernetes-threats/">https://unit42.paloaltonetworks.com/modern-kubernetes-threats/</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9884" type="text/plain" language="en" />
<itunes:keywords>glasswing, anthropic, watchguard, firebox, pivoting, webshell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9882</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9882.mp3" length="5817988" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9882.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9882</link>
<pubDate>Tue, 07 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
How often are redirects used in phishing in 2026?<br/>
<a href="https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870">https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870</a><br/>
Hackerone Suspends Internet Bug Bounty<br/>
<a href="https://hackerone.com/ibb?type=team">https://hackerone.com/ibb?type=team</a><br/>
<a href="https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/">https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/</a><br/>
Bluehammer Windows 0-day Privilege Escalation<br/>
<a href="https://github.com/Nightmare-Eclipse/BlueHammer">https://github.com/Nightmare-Eclipse/BlueHammer</a><br/>
<a href="https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html">https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html</a><br/>
<a href="https://deepwiki.com/Nightmare-Eclipse/BlueHammer">https://deepwiki.com/Nightmare-Eclipse/BlueHammer</a><br/>
Keycloak MFA Bypass CVE-2026-3429<br/>
<a href="https://access.redhat.com/security/cve/cve-2026-3429">https://access.redhat.com/security/cve/cve-2026-3429</a><br/>
]]></description>
<itunes:duration>6:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9882" type="text/plain" language="en" />
<itunes:keywords>keycloak, mfa, bluehammer, windows, 0-day, hackerone, phishing, redirects, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, April 6th, 2026: TeamPCP Update and Axio Post Mortem; Fortinet 0-Day
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9880</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, April 6th, 2026: TeamPCP Update and Axio Post Mortem; Fortinet 0-Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, April 6th, 2026: TeamPCP Update and Axio Post Mortem; Fortinet 0-Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9880.mp3" length="5165062" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9880.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9880</link>
<pubDate>Mon, 06 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Team PCP Update and Axios Post Mortem<br/>
<a href="https://isc.sans.edu/diary/32864">https://isc.sans.edu/diary/32864</a><br/>
<a href="https://github.com/axios/axios/issues/10636">https://github.com/axios/axios/issues/10636</a><br/>
Strapi NPM Packages Compromised<br/>
<a href="https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/">https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/</a><br/>
Fortinet CVE-2026-35616 exctively exploited<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9880" type="text/plain" language="en" />
<itunes:keywords>Fortinet, exploit, 0-day, strapi, npm, teampcp, axios, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, April 3rd, 2026: Vite Exploits; OpenSSH 10.3; Claude Code Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9878</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, April 3rd, 2026: Vite Exploits; OpenSSH 10.3; Claude Code Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, April 3rd, 2026: Vite Exploits; OpenSSH 10.3; Claude Code Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9878.mp3" length="4413460" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9878.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9878</link>
<pubDate>Fri, 03 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)<br/>
<a href="https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860">https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860</a><br/>
OpenSSH 10.3 Release<br/>
<a href="https://seclists.org/oss-sec/2026/q2/7">https://seclists.org/oss-sec/2026/q2/7</a><br/>
Claude Code Vulnerability<br/>
<a href="https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/">https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9878" type="text/plain" language="en" />
<itunes:keywords>Openssh, vite, claude, code, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9876</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9876.mp3" length="3382577" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9876.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9876</link>
<pubDate>Thu, 02 Apr 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Malicious Script That Gets Rid of ADS<br/>
<a href="https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854">https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854</a><br/>
Google Chrome Update fixes 21 Vulnerabilities and 0-Day<br/>
<a href="https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html">https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html</a><br/>
Apple Addresses Darksword Vulnerabilities for older devices<br/>
<a href="https://support.apple.com/en-us/126793">https://support.apple.com/en-us/126793</a><br/>
]]></description>
<itunes:duration>4:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9876" type="text/plain" language="en" />
<itunes:keywords>apple, ios, darksword, google, chrome, ADS, MotW, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, April 1st, 2026:  Application Control Bypass; Axios NPM Module Compromise; TeamPCP vs Cloud
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9874</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, April 1st, 2026:  Application Control Bypass; Axios NPM Module Compromise; TeamPCP vs Cloud
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, April 1st, 2026:  Application Control Bypass; Axios NPM Module Compromise; TeamPCP vs Cloud
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9874.mp3" length="5710101" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9874.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9874</link>
<pubDate>Wed, 01 Apr 2026 02:05:11 GMT</pubDate>
<description><![CDATA[<br/>
Application Control Bypass for Data Exfiltration<br/>
<a href="https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850">https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850</a><br/>
Axios NPM Module Supply Chain Compromise<br/>
<a href="https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan">https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan</a><br/>
<a href="https://www.linkedin.com/events/7444763050819092480/">https://www.linkedin.com/events/7444763050819092480/</a><br/>
TeamPCP vs. Cloud Resources<br/>
<a href="https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild">https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9874" type="text/plain" language="en" />
<itunes:keywords>teampcp, cloud, axios, npm, application conftrol, palo alto, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, March 31st, 2026: Honeypot Session Lifetime; Let’s Encrypt Tests Mass Revocation; F5 RCE Exploited
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9872</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, March 31st, 2026: Honeypot Session Lifetime; Let’s Encrypt Tests Mass Revocation; F5 RCE Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, March 31st, 2026: Honeypot Session Lifetime; Let’s Encrypt Tests Mass Revocation; F5 RCE Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9872.mp3" length="4392299" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9872.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9872</link>
<pubDate>Tue, 31 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Honeypot Session Lifetime<br/>
<a href="https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840">https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840</a><br/>
Let s Encrypt Tests Mass Revocation<br/>
<a href="https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960">https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960</a><br/>
<a href="https://www.certkit.io/blog/ari-solves-mass-certificate-revocation">https://www.certkit.io/blog/ari-solves-mass-certificate-revocation</a><br/>
<a href="https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation">https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation</a><br/>
F5 Vulnerability Re-Classified (and already exploited) as RCE<br/>
<a href="https://my.f5.com/manage/s/article/K000156741">https://my.f5.com/manage/s/article/K000156741</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9872" type="text/plain" language="en" />
<itunes:keywords>F5, Lets’ Encrypt, ARI, revocation, honeypot, session, lifetime, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix Fix; Windows Smart Install
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9870</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix Fix; Windows Smart Install
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix Fix; Windows Smart Install
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9870.mp3" length="7089444" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9870.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9870</link>
<pubDate>Mon, 30 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
TeamPCP Update #2: Telnyx PyPi Compromise<br/>
<a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838</a><br/>
Citrix Netscaler Vulnerability Details<br/>
<a href="https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/">https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/</a><br/>
macOS Clickfix Warning<br/>
<a href="https://x.com/ClassicII_MrMac/status/2036797948911141129">https://x.com/ClassicII_MrMac/status/2036797948911141129</a><br/>
Windows Smart Install<br/>
<a href="https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/">https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/</a><br/>
]]></description>
<itunes:duration>8:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9870" type="text/plain" language="en" />
<itunes:keywords>windows, install, smart, citrix, netscaler, teampcp, telnyx, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, March 27th, 2026: TeamPCP Update; DarkSword vs Patches; LangFlow Exploited
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9868</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, March 27th, 2026: TeamPCP Update; DarkSword vs Patches; LangFlow Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, March 27th, 2026: TeamPCP Update; DarkSword vs Patches; LangFlow Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9868.mp3" length="5222864" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9868.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9868</link>
<pubDate>Fri, 27 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available<br/>
<a href="https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834">https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834</a><br/>
DarkSword and This Weeks iOS Updates<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain">https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain</a><br/>
LangFlow Exploited<br/>
<a href="https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog">https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9868" type="text/plain" language="en" />
<itunes:keywords>langflow, darksword, ios, patches, teampcp, checkmarx, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, March 26th, 2026: Apple Patches; SmatApeSG Update; Trivy/LiteLLM/TeamPCP Update; Google Accelerates Quantum Save Crypto Rollout
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9866</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, March 26th, 2026: Apple Patches; SmatApeSG Update; Trivy/LiteLLM/TeamPCP Update; Google Accelerates Quantum Save Crypto Rollout
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, March 26th, 2026: Apple Patches; SmatApeSG Update; Trivy/LiteLLM/TeamPCP Update; Google Accelerates Quantum Save Crypto Rollout
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9866.mp3" length="5829229" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9866.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9866</link>
<pubDate>Thu, 26 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Patches (almost) everything again. March 2026 edition.<br/>
<a href="https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830">https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830</a><br/>
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)<br/>
<a href="https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20%28ArechClient2%29/32826">https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20%28ArechClient2%29/32826</a><br/>
Trivy/LiteLLM/TeamPCP Updates<br/>
<a href="https://www.sans.org/webcasts/when-security-scanner-became-weapon">https://www.sans.org/webcasts/when-security-scanner-became-weapon</a><br/>
<a href="https://rosesecurity.dev/2026/03/24/sha-pinning-is-not-enough.html">https://rosesecurity.dev/2026/03/24/sha-pinning-is-not-enough.html</a><br/>
Google Moves Up Quantum Crypto Deadline<br/>
<a href="https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/">https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9866" type="text/plain" language="en" />
<itunes:keywords>trivy, litellm, teampcp, apple, smartapesg, google, quantum, crypto, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9864</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, March 25th, 2026: IP KVM Usage; TeampPCP, Trivy, liteLLM and More
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9864.mp3" length="10005625" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9864.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9864</link>
<pubDate>Wed, 25 Mar 2026 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
---<br/>
Special Webcast about Trivy Supply Chain Attacks<br/>
   <a href="https://www.sans.org/webcasts/when-security-scanner-became-weapon">https://www.sans.org/webcasts/when-security-scanner-became-weapon</a><br/>
---<br/>
Detecting IP KVM Usage<br/>
<a href="https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824">https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824</a><br/>
TeamPCP, Trivy, liteLLM, Iran and more<br/>
<a href="https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran">https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran</a><br/>
<a href="https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/">https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/</a><br/>
<a href="https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/">https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/</a><br/>
<a href="https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions">https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions</a><br/>
]]></description>
<itunes:duration>11:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9864" type="text/plain" language="en" />
<itunes:keywords>ipkvm, teampcp, trivy, litellm, checkmarx, supply chain, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, March 24th, 2026: Tax Scam to EDR Kill; Netscaler Patches; gRPC-Go Authz Bypass;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9862</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, March 24th, 2026: Tax Scam to EDR Kill; Netscaler Patches; gRPC-Go Authz Bypass;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, March 24th, 2026: Tax Scam to EDR Kill; Netscaler Patches; gRPC-Go Authz Bypass;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9862.mp3" length="4777832" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9862.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9862</link>
<pubDate>Tue, 24 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill<br/>
<a href="https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill">https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill</a><br/>
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368<br/>
<a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300</a><br/>
gRPC-Go Authorization bypass via missing leading slash in :path CVE-2026-33186<br/>
<a href="https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3">https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9862" type="text/plain" language="en" />
<itunes:keywords>gRPC, Go, authz, netscaler, citrix, w-2, tax, scam, google, seo, BYOVD, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, March 23rd, 2026:  GSocket Backdoor in Bash; Oracle Security Alert; Rockwell Attacks
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9860</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, March 23rd, 2026:  GSocket Backdoor in Bash; Oracle Security Alert; Rockwell Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, March 23rd, 2026:  GSocket Backdoor in Bash; Oracle Security Alert; Rockwell Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9860.mp3" length="4686665" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9860.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9860</link>
<pubDate>Mon, 23 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
GSocket Backdoor Delivered Through Bash Script<br/>
<a href="https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments">https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments</a><br/>
Oracle Security Alert CVE-2026-21992 Released<br/>
<a href="https://blogs.oracle.com/security/alert-cve-2026-21992">https://blogs.oracle.com/security/alert-cve-2026-21992</a><br/>
Rockwell Automation Reiterates Customer Guidance to Disconnect Devices from the Internet and Harden PLCs to Protect from Cyber Threats<br/>
<a href="https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html">https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9860" type="text/plain" language="en" />
<itunes:keywords>rockwell, oracle, gsocket, bash, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9858</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening; Unifi Network Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9858.mp3" length="4828058" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9858.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9858</link>
<pubDate>Fri, 20 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Interesting Cowrie Strings<br/>
<a href="https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810">https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810</a><br/>
Microsoft Intune Hardening Advice<br/>
<a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117">https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117</a><br/>
<a href="https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization">https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization</a><br/>
Unifi Network Update<br/>
<a href="https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b">https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9858" type="text/plain" language="en" />
<itunes:keywords>unifi, ubiquity, microsoft, intune, cowrie, iran, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, March 19th, 2026: Adminer Scans; Apple WebKit Patch; another telnetd vuln; screenconnect vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9856</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, March 19th, 2026: Adminer Scans; Apple WebKit Patch; another telnetd vuln; screenconnect vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, March 19th, 2026: Adminer Scans; Apple WebKit Patch; another telnetd vuln; screenconnect vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9856.mp3" length="4978898" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9856.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9856</link>
<pubDate>Thu, 19 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scans for "adminer"<br/>
<a href="https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808">https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808</a><br/>
Background Security Improvement for WebKit<br/>
<a href="https://support.apple.com/en-us/126604">https://support.apple.com/en-us/126604</a><br/>
Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)<br/>
<a href="https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html">https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html</a><br/>
ScreenConnect  26.1 Security Hardening<br/>
<a href="https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin">https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9856" type="text/plain" language="en" />
<itunes:keywords>screenconnect, connectwise, webkit, adminer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, March 18th, 2026:  IPv4 mapped IPv6; KVM Vulnerabilities; AWS Bedrock DNS Covert Channel
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9854</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, March 18th, 2026:  IPv4 mapped IPv6; KVM Vulnerabilities; AWS Bedrock DNS Covert Channel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, March 18th, 2026:  IPv4 mapped IPv6; KVM Vulnerabilities; AWS Bedrock DNS Covert Channel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9854.mp3" length="5039906" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9854.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9854</link>
<pubDate>Wed, 18 Mar 2026 11:05:02 GMT</pubDate>
<description><![CDATA[<br/>
IPv4 Mapped IPv6 Addresses<br/>
<a href="https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804">https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804</a><br/>
More IP KVM Vulnerabilities<br/>
<a href="https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/">https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/</a><br/>
AWS Bedrock AgentCore Code Interpreter DNS Leak<br/>
<a href="https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter">https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9854" type="text/plain" language="en" />
<itunes:keywords>aws, bedrock, agentcore, kvm, ipv6, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, March 17th, 2026: Proxy URLs; Local Network Address Restrictions; Advanced Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9852</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, March 17th, 2026: Proxy URLs; Local Network Address Restrictions; Advanced Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, March 17th, 2026: Proxy URLs; Local Network Address Restrictions; Advanced Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9852.mp3" length="6590641" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9852.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9852</link>
<pubDate>Tue, 17 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
/proxy/ URL scans with IP addresses<br/>
<a href="https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/">https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/</a><br/>
Local Network Address Restrictions <br/>
<a href="https://learn.microsoft.com/en-us/deployedge/ms-edge-local-network-access#how-to-mitigate-impact-for-cross-origin-iframes">https://learn.microsoft.com/en-us/deployedge/ms-edge-local-network-access#how-to-mitigate-impact-for-cross-origin-iframes</a> <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel</a><br/>
European Security Vendor Targeted by Hackers Fronting as Cisco Domain<br/>
<a href="https://specopssoft.com/blog/phishing-campaign-cisco/">https://specopssoft.com/blog/phishing-campaign-cisco/</a><br/>
]]></description>
<itunes:duration>7:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9852" type="text/plain" language="en" />
<itunes:keywords>phishing, dkim, url, proxy, chrome, edge, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, March 16th, 2026: SmartApeSG and Remcos RAT; React Based Phishing; Google Chrome Patches; AdGaurd Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9850</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, March 16th, 2026: SmartApeSG and Remcos RAT; React Based Phishing; Google Chrome Patches; AdGaurd Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, March 16th, 2026: SmartApeSG and Remcos RAT; React Based Phishing; Google Chrome Patches; AdGaurd Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9850.mp3" length="5220702" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9850.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9850</link>
<pubDate>Mon, 16 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
SmartApeSG campaign uses ClickFix page to push Remcos RAT<br/>
<a href="https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796">https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796</a><br/>
A React-based phishing page with credential exfiltration via EmailJS<br/>
<a href="https://isc.sans.edu/diary/32794">https://isc.sans.edu/diary/32794</a><br/>
Google Chrome announced two zero-day fixes, then removed one.<br/>
<a href="https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html">https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html</a><br/>
AdGuard Vulnerability<br/>
<a href="https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73">https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9850" type="text/plain" language="en" />
<itunes:keywords>adguard, google, chorme, remco, react, rat, emailjs clickfix. smartagesg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, March 13th, 2026: IOT Device Discovery; Apple Patches; Veeam Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9848</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, March 13th, 2026: IOT Device Discovery; Apple Patches; Veeam Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, March 13th, 2026: IOT Device Discovery; Apple Patches; Veeam Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9848.mp3" length="4465267" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9848.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9848</link>
<pubDate>Fri, 13 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
When your IoT Device Logs in as Admin, It s too Late!<br/>
<a href="https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788">https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788</a><br/>
Apple Patches <br/>
 <a href="https://support.apple.com/en-us/100100">https://support.apple.com/en-us/100100</a><br/>
Veeam Patches<br/>
 <a href="https://www.veeam.com/kb4830">https://www.veeam.com/kb4830</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9848" type="text/plain" language="en" />
<itunes:keywords>veeam, apple, patches, iot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, March 12th, 2026: Zombie Zip; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9846</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, March 12th, 2026: Zombie Zip; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, March 12th, 2026: Zombie Zip; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9846.mp3" length="6255548" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9846.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9846</link>
<pubDate>Thu, 12 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Analyzing "Zombie Zip" Files (CVE-2026-0866)<br/>
<a href="https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786">https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786</a><br/>
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit<br/>
<a href="https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass">https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass</a><br/>
]]></description>
<itunes:duration>7:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9846" type="text/plain" language="en" />
<itunes:keywords>zombie, zip, fressrss, bcrypt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, March 11th, 2026: Windows, Fortinet, Adobe, and Zoom Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9844</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, March 11th, 2026: Windows, Fortinet, Adobe, and Zoom Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, March 11th, 2026: Windows, Fortinet, Adobe, and Zoom Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9844.mp3" length="5186436" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9844.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9844</link>
<pubDate>Wed, 11 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday, March 2026<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782</a><br/>
Fortinet Updates<br/>
<a href="https://fortiguard.fortinet.com/psirt">https://fortiguard.fortinet.com/psirt</a><br/>
Adobe Updates<br/>
<a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Zoom Update<br/>
<a href="https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061222">https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0061222</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9844" type="text/plain" language="en" />
<itunes:keywords>zoom, adobe, fortinet, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, March 10th, 2026: Encrypted Client Hello; ExitTool Vulnerability; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9842</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, March 10th, 2026: Encrypted Client Hello; ExitTool Vulnerability; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, March 10th, 2026: Encrypted Client Hello; ExitTool Vulnerability; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9842.mp3" length="6257050" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9842.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9842</link>
<pubDate>Tue, 10 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Encrypted Client Hello: Ready for Prime Time?<br/>
<a href="https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778">https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778</a><br/>
The ExifTool vulnerability: how an image can infect macOS systems<br/>
<a href="https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/">https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/</a><br/>
Remote code execution in Nextcloud Flow via vulnerable Windmill version<br/>
<a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf</a><br/>
]]></description>
<itunes:duration>7:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9842" type="text/plain" language="en" />
<itunes:keywords>Windmill, ExifTool, macOS, ECH, https, tls, client hello, encrypted, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, March 9th, 2026: YARA-X Update; IP Camera Targeting; Node.js Upgrades; nginx UI Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9840</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, March 9th, 2026: YARA-X Update; IP Camera Targeting; Node.js Upgrades; nginx UI Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, March 9th, 2026: YARA-X Update; IP Camera Targeting; Node.js Upgrades; nginx UI Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9840.mp3" length="4313113" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9840.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9840</link>
<pubDate>Mon, 09 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
YARA-X 1.14.0 Release <a href="https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774">https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774</a><br/>
INTERPLAY BETWEEN IRANIAN TARGETING OF IP CAMERAS AND PHYSICAL WARFARE IN THE MIDDLE EAST<br/>
<a href="https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/">https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/</a><br/>
Announcing the Node.js LTS Upgrade and Modernization Program<br/>
<a href="https://openjsf.org/blog/nodejs-lts-upgrade-program">https://openjsf.org/blog/nodejs-lts-upgrade-program</a><br/>
nginx UI Vulnerability<br/>
 <a href="https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762">https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9840" type="text/plain" language="en" />
<itunes:keywords>yara, iran, ip cameras, node.js, nginx, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, March 6th, 2026: Targeted or Not? pac4j-jwt auth bypass; freescout dangerous uploads; MSFT Authenticator vs Graphene OS
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9838</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, March 6th, 2026: Targeted or Not? pac4j-jwt auth bypass; freescout dangerous uploads; MSFT Authenticator vs Graphene OS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, March 6th, 2026: Targeted or Not? pac4j-jwt auth bypass; freescout dangerous uploads; MSFT Authenticator vs Graphene OS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9838.mp3" length="5816703" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9838.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9838</link>
<pubDate>Fri, 06 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary]<br/>
<a href="https://isc.sans.edu/diary/Differentiating%20Between%20a%20Targeted%20Intrusion%20and%20an%20Automated%20Opportunistic%20Scanning%20%5BGuest%20Diary%5D/32768">https://isc.sans.edu/diary/Differentiating%20Between%20a%20Targeted%20Intrusion%20and%20an%20Automated%20Opportunistic%20Scanning%20%5BGuest%20Diary%5D/32768</a><br/>
CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)<br/>
<a href="https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key">https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key</a><br/>
FreeScout Help Desk Vulnerability<br/>
<a href="https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc">https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc</a><br/>
Microsoft Authenticator Not Supported on Graphene OS<br/>
<a href="https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-OS-11200495.html">https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-OS-11200495.html</a><br/>
]]></description>
<itunes:duration>6:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9838" type="text/plain" language="en" />
<itunes:keywords>freesccout, pac4j-jwt, algorithm confusion, targeted, honeypot, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, March 5th, 2026: XWorm Analysis; Cisco “Secure” Firewall Managmeent Center; LastPass Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9836</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, March 5th, 2026: XWorm Analysis; Cisco “Secure” Firewall Managmeent Center; LastPass Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, March 5th, 2026: XWorm Analysis; Cisco “Secure” Firewall Managmeent Center; LastPass Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9836.mp3" length="6420986" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9836.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9836</link>
<pubDate>Thu, 05 Mar 2026 11:50:11 GMT</pubDate>
<description><![CDATA[<br/>
Want More XWorm?<br/>
<a href="https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766">https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766</a><br/>
Cisco  Secure  Firewall Management Center Vulnerabilities<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a><br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2</a><br/>
LastPass Phishing<br/>
<a href="https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/">https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/</a><br/>
]]></description>
<itunes:duration>7:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9836" type="text/plain" language="en" />
<itunes:keywords>LastPass, cisco, firewall management, xworm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, March 4th, 2026: CrushFTP Brute Force; Android Patches 0-Day; 0Auth Phishing Abuse
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9834</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, March 4th, 2026: CrushFTP Brute Force; Android Patches 0-Day; 0Auth Phishing Abuse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, March 4th, 2026: CrushFTP Brute Force; Android Patches 0-Day; 0Auth Phishing Abuse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9834.mp3" length="4249464" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9834.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9834</link>
<pubDate>Wed, 04 Mar 2026 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Bruteforce Scans for CrushFTP<br/>
<a href="https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762">https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762</a><br/>
Android March 2026 Patches, including 0-Day (CVE-2026-21385)<br/>
<a href="https://source.android.com/docs/security/bulletin/2026/2026-03-01">https://source.android.com/docs/security/bulletin/2026/2026-03-01</a><br/>
OAuth redirection abuse enables phishing and malware delivery<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/">https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9834" type="text/plain" language="en" />
<itunes:keywords>crushftp, android, oauth, phishing, brute force, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, March 3rd, 2026: Finding URLs in ZIPs in RTFs; Merkle Tree Certificates; Taming Agentic Browsers
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9832</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, March 3rd, 2026: Finding URLs in ZIPs in RTFs; Merkle Tree Certificates; Taming Agentic Browsers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, March 3rd, 2026: Finding URLs in ZIPs in RTFs; Merkle Tree Certificates; Taming Agentic Browsers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9832.mp3" length="6866258" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9832.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9832</link>
<pubDate>Tue, 03 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Quick Howto: ZIP Files Inside RTF<br/>
<a href="https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments">https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments</a><br/>
Keeping the Internet fast and secure: introducing Merkle Tree Certificates<br/>
<a href="https://blog.cloudflare.com/bootstrap-mtc/">https://blog.cloudflare.com/bootstrap-mtc/</a><br/>
Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel<br/>
<a href="https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/">https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/</a><br/>
]]></description>
<itunes:duration>8:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9832" type="text/plain" language="en" />
<itunes:keywords>agentic, gemini, browsers, chrome, certificate, webpki, zip, rtf, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, March 2nd, 2026: Reversing Fake Fedex; Abusing .ARPA; MSFT Authenticator Update; Apex One Vuln; Special AirSnitch Webcast
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9830</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, March 2nd, 2026: Reversing Fake Fedex; Abusing .ARPA; MSFT Authenticator Update; Apex One Vuln; Special AirSnitch Webcast
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, March 2nd, 2026: Reversing Fake Fedex; Abusing .ARPA; MSFT Authenticator Update; Apex One Vuln; Special AirSnitch Webcast
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9830.mp3" length="6377866" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9830.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9830</link>
<pubDate>Mon, 02 Mar 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Fake Fedex Email Delivers Donuts!<br/>
<a href="https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754">https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754</a><br/>
Abusing .ARPA: The TLD that isn t supposed to host anything<br/>
<a href="https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/">https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/</a><br/>
MC1179154 - Microsoft Authenticator app: Upcoming changes to jailbreak and root detection<br/>
<a href="https://mc.merill.net/message/MC1179154">https://mc.merill.net/message/MC1179154</a><br/>
SECURITY BULLETIN: Apex One and Apex One (Mac) - February 2026<br/>
<a href="https://success.trendmicro.com/en-US/solution/KA-0022458">https://success.trendmicro.com/en-US/solution/KA-0022458</a><br/>
Special Webcast: AirSnitch   How Worried Should You Be?<br/>
<a href="https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be">https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be</a><br/>
]]></description>
<itunes:duration>7:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9830" type="text/plain" language="en" />
<itunes:keywords>fedex, apex, one, airsnitch, webcast, authenticator, microsoft, arpa, tld, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, February 27th, 2026: Finding Singal (@sans_edu intern); Google API Keys and Gemini; AirSnitch Breaking Client Isolation
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9828</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, February 27th, 2026: Finding Singal (@sans_edu intern); Google API Keys and Gemini; AirSnitch Breaking Client Isolation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, February 27th, 2026: Finding Singal (@sans_edu intern); Google API Keys and Gemini; AirSnitch Breaking Client Isolation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9828.mp3" length="7869025" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9828.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9828</link>
<pubDate>Fri, 27 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary]<br/>
<a href="https://isc.sans.edu/diary/Finding%20Signal%20in%20the%20Noise%3A%20Lessons%20Learned%20Running%20a%20Honeypot%20with%20AI%20Assistance%20%5BGuest%20Diary%5D/32744">https://isc.sans.edu/diary/Finding%20Signal%20in%20the%20Noise%3A%20Lessons%20Learned%20Running%20a%20Honeypot%20with%20AI%20Assistance%20%5BGuest%20Diary%5D/32744</a><br/>
Google API Keys Weren't Secrets. But then Gemini Changed the Rules.<br/>
<a href="https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules">https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules</a><br/>
AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks<br/>
<a href="https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/">https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/</a><br/>
]]></description>
<itunes:duration>9:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9828" type="text/plain" language="en" />
<itunes:keywords>airsnitch, wifi, api, google, maps, gemini, noise, honeypot, sans.edu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, February 26th, 2026: CLAIR Model; Cisco SD-WAN 0-Day; Cortex XDR Abuse; OpenSSL Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9826</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, February 26th, 2026: CLAIR Model; Cisco SD-WAN 0-Day; Cortex XDR Abuse; OpenSSL Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, February 26th, 2026: CLAIR Model; Cisco SD-WAN 0-Day; Cortex XDR Abuse; OpenSSL Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9826.mp3" length="5712396" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9826.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9826</link>
<pubDate>Thu, 26 Feb 2026 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary]<br/>
<a href="https://isc.sans.edu/diary/The+CLAIR+Model+A+Synthesized+Conceptual+Framework+for+Mapping+Critical+Infrastructure+Interdependencies+Guest+Diary/32748">https://isc.sans.edu/diary/The+CLAIR+Model+A+Synthesized+Conceptual+Framework+for+Mapping+Critical+Infrastructure+Interdependencies+Guest+Diary/32748</a><br/>
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk</a> <a href="https://blog.talosintelligence.com/uat-8616-sd-wan/">https://blog.talosintelligence.com/uat-8616-sd-wan/</a><br/>
Abusing Cortex XDR Live<br/>
<a href="https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/">https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/</a><br/>
OpenSSL Vulnerability CVE-2025-15467<br/>
<a href="https://seclists.org/oss-sec/2026/q1/220">https://seclists.org/oss-sec/2026/q1/220</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9826" type="text/plain" language="en" />
<itunes:keywords>openssl, cortex, xdr, cisco, catalyst, sd-wan, clair, ics, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, February 25th, 2026: Open Redirects; setHTML in Firefox; telnetd issues
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9824</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, February 25th, 2026: Open Redirects; setHTML in Firefox; telnetd issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, February 25th, 2026: Open Redirects; setHTML in Firefox; telnetd issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9824.mp3" length="6289170" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9824.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9824</link>
<pubDate>Wed, 25 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Open Redirects: A Forgotten Vulnerability?<br/>
<a href="https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742">https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742</a><br/>
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148<br/>
<a href="https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/">https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/</a><br/>
More telnetd issues<br/>
<a href="https://seclists.org/oss-sec/2026/q1/199">https://seclists.org/oss-sec/2026/q1/199</a><br/>
]]></description>
<itunes:duration>7:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9824" type="text/plain" language="en" />
<itunes:keywords>redirects, innerhtml, telnet, sethtml, xss, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, February 24th, 2026: Malicious JPEG Analysis; Calibre Vuln; jsPDF object injection; Roundcube Exploited
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9822</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, February 24th, 2026: Malicious JPEG Analysis; Calibre Vuln; jsPDF object injection; Roundcube Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, February 24th, 2026: Malicious JPEG Analysis; Calibre Vuln; jsPDF object injection; Roundcube Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9822.mp3" length="5945082" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9822.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9822</link>
<pubDate>Tue, 24 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Another day, another malicious JPEG<br/>
<a href="https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738">https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738</a><br/>
Calibre Path Traversal Leading to Arbitrary File Write and Potentially Code Execution CVE-2026-26064 CVE-2026-26065 <br/>
<a href="https://github.com/kovidgoyal/calibre/security/advisories/GHSA-72ch-3hqc-pgmp">https://github.com/kovidgoyal/calibre/security/advisories/GHSA-72ch-3hqc-pgmp</a><br/>
<a href="https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vmfh-7mr7-pp2w">https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vmfh-7mr7-pp2w</a><br/>
CVE-2026-25755: PDF Object Injection in jsPDF (addJS Method)<br/>
<a href="https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md">https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md</a><br/>
Roundcube Webmail Exploited  CVE-2025-49113 <a href="https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10">https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10</a><br/>
<a href="https://www.openwall.com/lists/oss-security/2025/06/02/3">https://www.openwall.com/lists/oss-security/2025/06/02/3</a><br/>
]]></description>
<itunes:duration>7:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9822" type="text/plain" language="en" />
<itunes:keywords>roundcube, webmail, jspdf, calibre, jpeg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, February 23rd, 2026: Japanese Phishing; AI Agents Ignoring Instructions; Starkiller MFA Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9820</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, February 23rd, 2026: Japanese Phishing; AI Agents Ignoring Instructions; Starkiller MFA Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, February 23rd, 2026: Japanese Phishing; AI Agents Ignoring Instructions; Starkiller MFA Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9820.mp3" length="5509740" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9820.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9820</link>
<pubDate>Mon, 23 Feb 2026 02:45:11 GMT</pubDate>
<description><![CDATA[<br/>
Japanese-Language Phishing Emails<br/>
<a href="https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734">https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734</a><br/>
'God-Like' Attack Machines: AI Agents Ignore Security Policies<br/>
<a href="https://www.darkreading.com/application-security/ai-agents-ignore-security-policies">https://www.darkreading.com/application-security/ai-agents-ignore-security-policies</a><br/>
Starkiller: New Phishing Framework Proxies Real Login Pages to Bypass MFA<br/>
<a href="https://abnormal.ai/blog/starkiller-phishing-kit">https://abnormal.ai/blog/starkiller-phishing-kit</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9820" type="text/plain" language="en" />
<itunes:keywords>starkiller, phishing, mfa, mitm, japanese, ai, agents, security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, February 20th, 2026: DynoWiper Analysis; Vibe Passwords; IDE Extension Vulns; Gransstream GXP 1600 Vuln and PoC
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9818</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, February 20th, 2026: DynoWiper Analysis; Vibe Passwords; IDE Extension Vulns; Gransstream GXP 1600 Vuln and PoC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, February 20th, 2026: DynoWiper Analysis; Vibe Passwords; IDE Extension Vulns; Gransstream GXP 1600 Vuln and PoC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9818.mp3" length="5317253" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9818.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9818</link>
<pubDate>Fri, 20 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Under the Hood of DynoWiper<br/>
<a href="https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730">https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730</a><br/>
Vibe Password Generation: Predictable by Design<br/>
<a href="https://www.irregular.com/publications/vibe-password-generation">https://www.irregular.com/publications/vibe-password-generation</a><br/>
Vulnerabilities (CVE-2025-65715, CVE-2025-65716, CVE-2025-65717) in four popular IDE Extensions<br/>
<a href="https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/">https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/</a><br/>
Grandstream GXP1600 VoIP Phones<br/>
<a href="https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/">https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/</a><br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9818" type="text/plain" language="en" />
<itunes:keywords>grandstream, gxp1600, vibe, password, vs code, extensions, dynowiper, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, February 19th, 2026: Malware Image Resuse; Dell RecoveryPoint; Admin Center Vuln; DNS-PERSIST-01
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9816</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, February 19th, 2026: Malware Image Resuse; Dell RecoveryPoint; Admin Center Vuln; DNS-PERSIST-01
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, February 19th, 2026: Malware Image Resuse; Dell RecoveryPoint; Admin Center Vuln; DNS-PERSIST-01
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9816.mp3" length="5944993" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9816.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9816</link>
<pubDate>Thu, 19 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Tracking Malware Campaigns With Reused Material<br/>
<a href="https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726">https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726</a><br/>
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day">https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day</a><br/>
Windows Admin Center Elevation of Privilege Vulnerability CVE-2026-26119<br/>
<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119</a><br/>
 DNS-PERSIST-01: A New Model for DNS-based Challenge Validation<br/>
<a href="https://letsencrypt.org/2026/02/18/dns-persist-01.html">https://letsencrypt.org/2026/02/18/dns-persist-01.html</a><br/>
Defending Web Apps<br/>
<a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices</a><br/>
]]></description>
<itunes:duration>7:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9816" type="text/plain" language="en" />
<itunes:keywords>windows, admin center, dns-persist-01, brickstorm, grimpbolt, dell, recoverypoint, malware, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, February 18th, 2026: IR Phishing; Neenadu Android Backdoor; NiFi Bugs; LLMs Phishing; Encrypted RCS
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9814</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, February 18th, 2026: IR Phishing; Neenadu Android Backdoor; NiFi Bugs; LLMs Phishing; Encrypted RCS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, February 18th, 2026: IR Phishing; Neenadu Android Backdoor; NiFi Bugs; LLMs Phishing; Encrypted RCS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9814.mp3" length="6304792" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9814.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9814</link>
<pubDate>Wed, 18 Feb 2026 02:15:12 GMT</pubDate>
<description><![CDATA[<br/>
Fake Incident Report Used in Phishing Campaign<br/>
<a href="https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722">https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722</a><br/>
Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets <a href="https://securelist.com/keenadu-android-backdoor/118913/">https://securelist.com/keenadu-android-backdoor/118913/</a><br/>
CVE-2026-25903: Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates <a href="https://seclists.org/oss-sec/2026/q1/166">https://seclists.org/oss-sec/2026/q1/166</a><br/>
The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time<br/>
<a href="https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/">https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/</a> <br/>
Encrypted RCS in iOS/iPadOS<br/>
<a href="https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes">https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes</a><br/>
]]></description>
<itunes:duration>7:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9814" type="text/plain" language="en" />
<itunes:keywords>rcs, apple, nifi, android, backdoor, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, February 17th, 2026: 64Bit Malware; Password Manager Weaknesses; OpenClaw Config Theft;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9812</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, February 17th, 2026: 64Bit Malware; Password Manager Weaknesses; OpenClaw Config Theft;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, February 17th, 2026: 64Bit Malware; Password Manager Weaknesses; OpenClaw Config Theft;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9812.mp3" length="4371878" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9812.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9812</link>
<pubDate>Tue, 17 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
2026 64-Bits Malware Trend<br/>
<a href="https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718">https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718</a><br/>
A Comparative Security Analysis of Three Cloud-based Password Managers<br/>
<a href="https://zkae.io">https://zkae.io</a><br/>
Infostealer Infection Targeting OpenClaw Configurations<br/>
<a href="https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/">https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/</a><br/>
]]></description>
<itunes:duration>5:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9812" type="text/plain" language="en" />
<itunes:keywords>openclaw, infostealer, password, managers, malware, 64 bit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, February 16th, 2026: Graph Generator; nslookup and clickfix; Chrome 0-Day; TURN Threats
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9810</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, February 16th, 2026: Graph Generator; nslookup and clickfix; Chrome 0-Day; TURN Threats
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, February 16th, 2026: Graph Generator; nslookup and clickfix; Chrome 0-Day; TURN Threats
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9810.mp3" length="5041625" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9810.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9810</link>
<pubDate>Mon, 16 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
AI-Powered Knowledge Graph Generator & APTs<br/>
<a href="https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712">https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712</a><br/>
nslookup and ClickFix<br/>
<a href="https://x.com/MsftSecIntel/status/2022456612120629742">https://x.com/MsftSecIntel/status/2022456612120629742</a><br/>
Google Chrome 0-Day Patch<br/>
<a href="https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html">https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html</a><br/>
TURN Security Threats<br/>
<a href="https://www.enablesecurity.com/blog/turn-server-security-threats/">https://www.enablesecurity.com/blog/turn-server-security-threats/</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9810" type="text/plain" language="en" />
<itunes:keywords>TURN, Chrome, nslookup, ClickFix, AI, graph, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, February 13th, 2026: SSH Bot; OpenSSH MacOS Change; Abused Employee Monitoring
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9808</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, February 13th, 2026: SSH Bot; OpenSSH MacOS Change; Abused Employee Monitoring
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, February 13th, 2026: SSH Bot; OpenSSH MacOS Change; Abused Employee Monitoring
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9808.mp3" length="4802804" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9808.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9808</link>
<pubDate>Fri, 13 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Four Seconds to Botnet - Analyzing a Self-Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary]<br/>
<a href="https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708">https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708</a><br/>
OpenSSH Update on MacOS<br/>
<a href="https://www.openssh.org/releasenotes.html">https://www.openssh.org/releasenotes.html</a><br/>
Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations<br/>
<a href="https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations">https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9808" type="text/plain" language="en" />
<itunes:keywords>monitoring, openssh, macos, botnet, ssh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, February 12th, 2026: WSL in Malware; Apple and Adobe Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9806</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, February 12th, 2026: WSL in Malware; Apple and Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, February 12th, 2026: WSL in Malware; Apple and Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9806.mp3" length="5162142" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9806.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9806</link>
<pubDate>Thu, 12 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
WSL in the Malware Ecosystem <a href="https://isc.sans.edu/diary/32704">https://isc.sans.edu/diary/32704</a><br/>
Apple Patches Everything: February 2026<br/>
<a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706</a> <br/>
Adobe Updates<br/>
<a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9806" type="text/plain" language="en" />
<itunes:keywords>apple, adobe, wsl, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, February 11th, 2026: Microsoft Patch Tuesday; Secure Boot Updates; Fake 7-Zip; FortiSlob
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9804</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, February 11th, 2026: Microsoft Patch Tuesday; Secure Boot Updates; Fake 7-Zip; FortiSlob
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, February 11th, 2026: Microsoft Patch Tuesday; Secure Boot Updates; Fake 7-Zip; FortiSlob
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9804.mp3" length="6644712" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9804.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9804</link>
<pubDate>Wed, 11 Feb 2026 02:05:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday - February 2026<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700</a><br/>
Refreshing the root of trust<br/>
<a href="https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/">https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/</a><br/>
Fake 7-Zip downloads are turning home PCs into proxy nodes<br/>
<a href="https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes">https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes</a><br/>
FortiNet Vulnerabilities<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-093">https://fortiguard.fortinet.com/psirt/FG-IR-25-093</a> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1052">https://fortiguard.fortinet.com/psirt/FG-IR-25-1052</a><br/>
]]></description>
<itunes:duration>7:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9804" type="text/plain" language="en" />
<itunes:keywords>Fortinet, 7zip, fake, trojan, trust, boot, root, microsoft, patch, tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, February 10th, 2026: Extracting URLs; Singal Phishing; Ivanti PoC; BeyondTrust RCE; Forticlient SQL Inection
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9802</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, February 10th, 2026: Extracting URLs; Singal Phishing; Ivanti PoC; BeyondTrust RCE; Forticlient SQL Inection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, February 10th, 2026: Extracting URLs; Singal Phishing; Ivanti PoC; BeyondTrust RCE; Forticlient SQL Inection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9802.mp3" length="3786928" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9802.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9802</link>
<pubDate>Tue, 10 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Quick Howto: Extract URLs from RTF files<br/>
<a href="https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692">https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692</a><br/>
German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists<br/>
German: <a href="https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html">https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html</a> English: <a href="https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&v=3">https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&v=3</a><br/>
Someone Knows Bash Far Too Well, And We Love It - Pre-Auth RCEs<br/>
<a href="https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/">https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/</a><br/>
Pre-Auth RCE in BeyondTrust Remote Support & PRA CVE-2026-1731<br/>
<a href="https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce">https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce</a><br/>
<a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-02">https://www.beyondtrust.com/trust-center/security-advisories/bt26-02</a><br/>
Fortinet FortiClientEMS SQLi in the administrative interface<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-1142">https://fortiguard.fortinet.com/psirt/FG-IR-25-1142</a><br/>
]]></description>
<itunes:duration>4:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9802" type="text/plain" language="en" />
<itunes:keywords>urls, rtf, signal, phishing, ivanti, beyondtrust, fortinet, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, February 9th, 2026: Azure Vulnerabilties; AI Vulnerability Discovery; GitLab AI Gateway Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9800</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, February 9th, 2026: Azure Vulnerabilties; AI Vulnerability Discovery; GitLab AI Gateway Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, February 9th, 2026: Azure Vulnerabilties; AI Vulnerability Discovery; GitLab AI Gateway Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9800.mp3" length="4527773" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9800.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9800</link>
<pubDate>Mon, 09 Feb 2026 11:47:32 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patches Four Azure Vulnerabilities (three critical)<br/>
<a href="https://msrc.microsoft.com/update-guide/vulnerability">https://msrc.microsoft.com/update-guide/vulnerability</a><br/>
Evaluating and mitigating the growing risk of LLM-discovered 0-days<br/>
<a href="https://red.anthropic.com/2026/zero-days/">https://red.anthropic.com/2026/zero-days/</a><br/>
Gitlab AI Gateway Vulnerability CVE-2026-1868<br/>
<a href="https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/">https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9800" type="text/plain" language="en" />
<itunes:keywords>gitlab, ai gateway, llm, 0-days, anthropic, claude, opus, microsoft, azure, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, February 6th, 2026: Broken Phishing; n8n vulnerability; Android Update; Watchguard Firebox LDAP Injection
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9798</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, February 6th, 2026: Broken Phishing; n8n vulnerability; Android Update; Watchguard Firebox LDAP Injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, February 6th, 2026: Broken Phishing; n8n vulnerability; Android Update; Watchguard Firebox LDAP Injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9798.mp3" length="3955864" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9798.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9798</link>
<pubDate>Fri, 06 Feb 2026 02:05:02 GMT</pubDate>
<description><![CDATA[<br/>
Broken Phishing URLs<br/>
<a href="https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/">https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/</a><br/>
n8n command injection vulnerability<br/>
<a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8">https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8</a><br/>
Android February Update<br/>
<a href="https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01?hl=en">https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01?hl=en</a><br/>
Watchguard Firebox LDAP Injection<br/>
<a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001</a><br/>
]]></description>
<itunes:duration>4:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9798" type="text/plain" language="en" />
<itunes:keywords>watchguard, firebox, ldap, android, n8n, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, February 5th, 2026: Malicious Scripts; Synectix Vuln; Google Chrome; Google Looker; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9796</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, February 5th, 2026: Malicious Scripts; Synectix Vuln; Google Chrome; Google Looker; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, February 5th, 2026: Malicious Scripts; Synectix Vuln; Google Chrome; Google Looker; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9796.mp3" length="5285449" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9796.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9796</link>
<pubDate>Thu, 05 Feb 2026 02:10:11 GMT</pubDate>
<description><![CDATA[<br/>
Malicious Script Delivering More Maliciousness<br/>
<a href="https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682">https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682</a><br/>
Synectix LAN 232 TRIO Unauthenticated Web Admin CVE-2026-1633<br/>
<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04">https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04</a><br/>
Google Chrome Patches<br/>
<a href="https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html</a><br/>
LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem)<br/>
<a href="https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout">https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9796" type="text/plain" language="en" />
<itunes:keywords>lookup, looker, google, chrome, patches, synectix, malicious script, infostealer, xworm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, February 4th, 2026: Detecting OpenClaw; Synology telnetd Patch; More GlassWorm
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9794</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, February 4th, 2026: Detecting OpenClaw; Synology telnetd Patch; More GlassWorm
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, February 4th, 2026: Detecting OpenClaw; Synology telnetd Patch; More GlassWorm
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9794.mp3" length="4144396" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9794.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9794</link>
<pubDate>Wed, 04 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Detecting and Monitoring OpenClaw (clawdbot, moltbot)<br/>
<a href="https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment">https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment</a><br/>
Synology telnetd Patch<br/>
<a href="https://www.synology.com/en-us/releaseNote/DSM">https://www.synology.com/en-us/releaseNote/DSM</a><br/>
GlassWorm Loader Hits Open VSX via Developer Account Compromise<br/>
<a href="https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise">https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise</a><br/>
]]></description>
<itunes:duration>4:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9794" type="text/plain" language="en" />
<itunes:keywords>vsx, glssworm, synology, telnetd, openclaw, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, February 3rd, 2026: Scanning for AI; Notepad++ Compromise; OpenClaw Vulnerabilities
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9792</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, February 3rd, 2026: Scanning for AI; Notepad++ Compromise; OpenClaw Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, February 3rd, 2026: Scanning for AI; Notepad++ Compromise; OpenClaw Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9792.mp3" length="5392240" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9792.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9792</link>
<pubDate>Tue, 03 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scanning for exposed Anthropic Models <a href="https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674">https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674</a><br/>
Notepad++ Hijacked by State-Sponsored Hackers <a href="https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/">https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/</a><br/>
<a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/">https://notepad-plus-plus.org/news/hijacked-incident-info-update/</a><br/>
Insecure Websockets in OpenClaw<br/>
<a href="https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability">https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability</a><br/>
Malicious OpenClaw Skills<br/>
<a href="https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting">https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting</a><br/>
Exposed OpenClaw Instances<br/>
<a href="https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant">https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9792" type="text/plain" language="en" />
<itunes:keywords>openclaw, websockets, notpad++, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, February 2nd, 2026: Google Presentation Abuse; Ivanti Vuln Exploited; Microsoft NTLM Strategy
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9790</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, February 2nd, 2026: Google Presentation Abuse; Ivanti Vuln Exploited; Microsoft NTLM Strategy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, February 2nd, 2026: Google Presentation Abuse; Ivanti Vuln Exploited; Microsoft NTLM Strategy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9790.mp3" length="6091172" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9790.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9790</link>
<pubDate>Mon, 02 Feb 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Google Presentation Abuse<br/>
<a href="https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/">https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/</a><br/>
Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 & CVE-2026-1340)<br/>
<a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US</a><br/>
Microsoft NTLM Strategy<br/>
<a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526">https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9790" type="text/plain" language="en" />
<itunes:keywords>microsoft, ntlm, ivanti, google, presentation, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, January 30th, 2026: Residential Proxy Networks; Clowdbot/Moltbot Themed Malware; eScan Malicious Updates
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9788</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, January 30th, 2026: Residential Proxy Networks; Clowdbot/Moltbot Themed Malware; eScan Malicious Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, January 30th, 2026: Residential Proxy Networks; Clowdbot/Moltbot Themed Malware; eScan Malicious Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9788.mp3" length="5310678" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9788.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9788</link>
<pubDate>Fri, 30 Jan 2026 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network<br/>
Google dismantled the IPIDEA network that used residential proxies to route malicious traffic.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network">https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network</a><br/>
Fake Clawdbot VS Code Extension Installs ScreenConnect RAT<br/>
The news about Clawdbot (now Moltbot) is used to distribute malware, in particular malicious VS Code extensions.<br/>
<a href="https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware">https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware</a><br/>
Threat Bulletin: Critical eScan Supply Chain Compromise<br/>
Anti-virus vendor eScan was compromised, and its update servers were used to install malware on some customer systems.<br/>
<a href="https://www.morphisec.com/blog/critical-escan-threat-bulletin/">https://www.morphisec.com/blog/critical-escan-threat-bulletin/</a><br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9788" type="text/plain" language="en" />
<itunes:keywords>escan, update, malcious, anti virus, vs code, clawdbot, moltbot, residential, proxy, network, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, January 29th, 2026: WebLogic AI Slop; Fortinet Patches; WebLogic AI Slop; Fortinet Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9786</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, January 29th, 2026: WebLogic AI Slop; Fortinet Patches; WebLogic AI Slop; Fortinet Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, January 29th, 2026: WebLogic AI Slop; Fortinet Patches; WebLogic AI Slop; Fortinet Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9786.mp3" length="5062964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9786.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9786</link>
<pubDate>Thu, 29 Jan 2026 12:40:11 GMT</pubDate>
<description><![CDATA[<br/>
Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?<br/>
We are seeing attempts to attack CVE-2026-21962, a recent weblog vulnerability, using a non-working AI slop exploit<br/>
<a href="https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662">https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662</a><br/>
Fortinet Patches are Rolling Out<br/>
Fortinet is starting to roll out patches for the recent SSO vulnerability<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-060">https://fortiguard.fortinet.com/psirt/FG-IR-26-060</a><br/>
SolarWinds Web Helpdesk Vulnerability<br/>
Another set of vulnerabilities in SolarWinds Web Helpdesk may result in unauthenticated system access<br/>
<a href="https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/">https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9786" type="text/plain" language="en" />
<itunes:keywords>solarwinds, fortinet, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, January 28th, 2026: Romance Scams; DoS Vuln in React Server Components; OpenSSL Patch; Kubernetes Priv Confusion
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9784</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, January 28th, 2026: Romance Scams; DoS Vuln in React Server Components; OpenSSL Patch; Kubernetes Priv Confusion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, January 28th, 2026: Romance Scams; DoS Vuln in React Server Components; OpenSSL Patch; Kubernetes Priv Confusion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9784.mp3" length="6423745" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9784.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9784</link>
<pubDate>Wed, 28 Jan 2026 02:05:03 GMT</pubDate>
<description><![CDATA[<br/>
Initial Stages of Romance Scams [Guest Diary]<br/>
Romance scams often start with random text messages that appear to be  misrouted . This guest diary by Faris Azhari is following some of the initial stages of such a scam.<br/>
<a href="https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650">https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650</a><br/>
Denial of Service Vulnerabilities in React Server Components<br/>
Another folowup fix for the severe React vulnerability from last year, but now only fixing a DoS condition.<br/>
<a href="https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg">https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg</a><br/>
OpenSSL Updates<br/>
OpenSSL released its monthly updates, fixing a potential RCE.<br/>
<a href="https://openssl-library.org/news/vulnerabilities/">https://openssl-library.org/news/vulnerabilities/</a><br/>
Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission<br/>
Many Kubernetes Helm Charts are vulnerable to possible remote code executions due to unclear defined access controls.<br/>
<a href="https://grahamhelton.com/blog/nodes-proxy-rce">https://grahamhelton.com/blog/nodes-proxy-rce</a><br/>
]]></description>
<itunes:duration>7:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9784" type="text/plain" language="en" />
<itunes:keywords>kubernetes, rce, proxy, openssl, dos, react, romance scam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9782</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9782.mp3" length="4900196" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9782.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9782</link>
<pubDate>Tue, 27 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scanning Webserver with  pwd  as a Starting Path<br/>
Attackers are adding the output of the pwd command to their web scans.<br/>
<a href="https://isc.sans.edu/diary/x/32654">https://isc.sans.edu/diary/x/32654</a><br/>
Microsoft Office Security Feature Bypass Vulnerability CVE-2026-21509<br/>
Microsoft released an out-of-band patch for Office fixing a currently exploited vulnerability.<br/>
<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509</a><br/>
Exposed Clawdbot Instances<br/>
Many users of the AI tool clawdbot expose instances without access control.<br/>
<a href="https://x.com/theonejvo/status/2015485025266098536">https://x.com/theonejvo/status/2015485025266098536</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9782" type="text/plain" language="en" />
<itunes:keywords>clwadbot, office, patch, microsoft, webserver, scan, pwd, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, January 26th, 2026: FortiOS SSO Vuln Updates; Outlook OOB Update; VMware vCenter Exploited
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9780</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, January 26th, 2026: FortiOS SSO Vuln Updates; Outlook OOB Update; VMware vCenter Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, January 26th, 2026: FortiOS SSO Vuln Updates; Outlook OOB Update; VMware vCenter Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9780.mp3" length="3659840" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9780.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9780</link>
<pubDate>Mon, 26 Jan 2026 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Analysis of Single Sign-On Abuse on FortiOS<br/>
Fortinet released an advisory. FortiOS devices are vulnerable if configured with any SAML integration, not just FortiCloud<br/>
<a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios">https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios</a><br/>
Outlook OOB Update<br/>
Microsoft released a non-security OOB Update for Outlook, fixing an issue introduced with this months security patches.<br/>
<a href="https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491">https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491</a><br/>
VMware vCenter Server Vulnerabilities Exploited (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081)<br/>
A VMWare vCenter vulnerability patched last June is now actively exploited.<br/>
<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br/>
]]></description>
<itunes:duration>4:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9780" type="text/plain" language="en" />
<itunes:keywords>vmware, vcenter, oob, update, microsoft, outlook, fortios, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, January 23rd, 2026: Scanning AI Code; FortiGate Update; ISC BIND DoS; Trivial SmaterMail Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9778</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, January 23rd, 2026: Scanning AI Code; FortiGate Update; ISC BIND DoS; Trivial SmaterMail Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, January 23rd, 2026: Scanning AI Code; FortiGate Update; ISC BIND DoS; Trivial SmaterMail Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9778.mp3" length="5926241" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9778.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9778</link>
<pubDate>Fri, 23 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Is AI-Generated Code Secure?<br/>
Xavier used the free static code analysis tool Bandit to review code he wrote with heavy AI support.<br/>
<a href="https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648">https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648</a><br/>
Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts<br/>
Arctic Wolf summarized some of the attacks it is seeing against FortiGate devices via the insufficiently patched SSL vulnerability.<br/>
<a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/">https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/</a><br/>
ISC BIND DoS vulnerability in Drone ID Records<br/>
HHIT and BRID records, which are used as part of Drone ID, can be used to crash named if their length is 3 bytes.<br/>
<a href="https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/">https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/</a><br/>
SmarterTools SmarterMail Password Reset Vulnerability<br/>
SmarterTools recently patched a trivial vulnerability in SmarterMail that would allow anybody without authentication to reset administrator passwords.<br/>
<a href="https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/">https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9778" type="text/plain" language="en" />
<itunes:keywords>smartermail, smartertools, isc, bind, dos, drone, drone id, fortinet, fortigate, bandit, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, January 22nd, 2026: Visual Studio Code Scripts; Cisco Unified Comm and Zoom Vuln; Insufficient Fortinet Patch; SANS SOC Survey
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9776</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, January 22nd, 2026: Visual Studio Code Scripts; Cisco Unified Comm and Zoom Vuln; Insufficient Fortinet Patch; SANS SOC Survey
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, January 22nd, 2026: Visual Studio Code Scripts; Cisco Unified Comm and Zoom Vuln; Insufficient Fortinet Patch; SANS SOC Survey
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9776.mp3" length="5510247" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9776.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9776</link>
<pubDate>Thu, 22 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Automatic Script Execution In Visual Studio Code<br/>
Visual Studio Code will read configuration files within the source code that may lead to code execution.<br/>
<a href="https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644">https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644</a><br/>
Cisco Unified Communications Products Remote Code Execution Vulnerability A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b</a><br/>
Zoom Vulnerability<br/>
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to execute remote code on the MMR via network access.<br/>
<a href="https://www.zoom.com/en/trust/security-bulletin/zsb-26001/">https://www.zoom.com/en/trust/security-bulletin/zsb-26001/</a><br/>
Possible new SSO Exploit (CVE-2025-59718) on 7.4.9<br/>
<a href="https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/">https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/</a><br/>
SANS SOC Survey<br/>
The 2026 SOC Survey is open, and we need your input to create a meaningful report. Please share your experience so we can advocate for what actually works in the trenches.<br/>
<a href="https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter">https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9776" type="text/plain" language="en" />
<itunes:keywords>soc, survey, sso, fortinet, zoom, cisco, visual studio, code, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, January 21st, 2026: Punycode Hunting; telnetd vuln; 6 day Certs and IP Certs; Oracle Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9774</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, January 21st, 2026: Punycode Hunting; telnetd vuln; 6 day Certs and IP Certs; Oracle Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, January 21st, 2026: Punycode Hunting; telnetd vuln; 6 day Certs and IP Certs; Oracle Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9774.mp3" length="5661964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9774.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9774</link>
<pubDate>Wed, 21 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Add Punycode to your Threat Hunting Routine<br/>
Punycode patterns in DNS queries make excellent hunting opportunities.<br/>
<a href="https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640">https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640</a><br/>
GNU InetUtils Security Advisory: remote authentication by-pass intelnetd<br/>
telnetd shipping with InetUtils suffers from a critical authentication by-pass vulnerability.<br/>
<a href="https://www.openwall.com/lists/oss-security/2026/01/20/2">https://www.openwall.com/lists/oss-security/2026/01/20/2</a><br/>
6-day and IP Address Certificates are Generally Available<br/>
Let s Encrypt will now offer 6-day certificates as an option. These short-lived certificates can be used for IP addresses.<br/>
<a href="https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability">https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability</a><br/>
Oracle Quarterly Critical Patch Update<br/>
Oracle released its first quarterly patches for 2026, fixing 337 vulnerabilities<br/>
<a href="https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW">https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9774" type="text/plain" language="en" />
<itunes:keywords>oracle, certificates, letsencrypt, inetutils, punycode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, January 20th, 2026: Scans Against LLMs; NTLM Rainbow Table; OOB MSFT Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9772</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, January 20th, 2026: Scans Against LLMs; NTLM Rainbow Table; OOB MSFT Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, January 20th, 2026: Scans Against LLMs; NTLM Rainbow Table; OOB MSFT Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9772.mp3" length="5041285" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9772.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9772</link>
<pubDate>Tue, 20 Jan 2026 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
"How many states are there in the United States?"<br/>
Attackers are actively scanning for LLMs, fingerprinting them using the query  How many states are there in the United States? .<br/>
<a href="https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618">https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618</a><br/>
Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation<br/>
Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables">https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables</a><br/>
Out-of-band update to address issues observed with the January 2026 Windows security update<br/>
Microsoft has identified issues upon installing the January 2026 Windows security update. To address these issues, an out-of-band (OOB) update was released today, January 17, 2026<br/>
<a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9772" type="text/plain" language="en" />
<itunes:keywords>Windows, patch, ntlm, rainbow table, llms, scans, llm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, January 16th, 2026: Cryptojacking Hidden Gifts; Bluetooth Vulnerability; Reprompt in MSFT Copilot
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9770</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, January 16th, 2026: Cryptojacking Hidden Gifts; Bluetooth Vulnerability; Reprompt in MSFT Copilot
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, January 16th, 2026: Cryptojacking Hidden Gifts; Bluetooth Vulnerability; Reprompt in MSFT Copilot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9770.mp3" length="6292882" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9770.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9770</link>
<pubDate>Fri, 16 Jan 2026 03:10:11 GMT</pubDate>
<description><![CDATA[ <br/>
Battling Cryptojacking, Botnets, and IABs<br/>
Cryptojacking often comes with less obvious addons, like SSH backdoors<br/>
<a href="https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632">https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632</a><br/>
Microsoft Copilot Reprompt Attacks<br/>
Adding a query parameter to the URL may prefill a Copilot prompt, altering the meaning of the prompts that follow.<br/>
<a href="https://www.varonis.com/blog/reprompt">https://www.varonis.com/blog/reprompt</a><br/>
Hijacking Bluetooth Accessories Using Google Fast Pair<br/>
Google s fast pair protocol is often not implemented correctly, allowing the Hijacking of Bluetooth accessories<br/>
<a href="https://whisperpair.eu/#about">https://whisperpair.eu/#about</a><br/>
]]></description>
<itunes:duration>7:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9770" type="text/plain" language="en" />
<itunes:keywords>ssh, cryptojacking, copilot, fast pair, bluetooth, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, January 15th, 2026: Luma Streal Repeat Infection; ServiceNow Broken Auth; Starlink/GPS Jamming
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9768</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, January 15th, 2026: Luma Streal Repeat Infection; ServiceNow Broken Auth; Starlink/GPS Jamming
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, January 15th, 2026: Luma Streal Repeat Infection; ServiceNow Broken Auth; Starlink/GPS Jamming
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9768.mp3" length="5188687" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9768.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9768</link>
<pubDate>Thu, 15 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain<br/>
<a href="https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628">https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628</a><br/>
BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow<br/>
<a href="https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/">https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/</a><br/>
Starlink Terminal GPS Spoofing/Jamming Detection in Iran<br/>
<a href="https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md">https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9768" type="text/plain" language="en" />
<itunes:keywords>starlink, gps, bodysnatcher, servicenow, agentic, lumastealer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, January 14th, 2026: Microsoft, Adobe and Fortinet Patches; ConsentFix
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9766</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, January 14th, 2026: Microsoft, Adobe and Fortinet Patches; ConsentFix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, January 14th, 2026: Microsoft, Adobe and Fortinet Patches; ConsentFix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9766.mp3" length="6697289" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9766.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9766</link>
<pubDate>Wed, 14 Jan 2026 02:30:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday January 2026<br/>
Microsoft released patches for 113 vulnerabilities. This includes one already exploited vulnerability, one that was made public before today and eight critical vulnerabilities.<br/>
<a href="https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624">https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624</a><br/>
Adobe Patches<br/>
Adobe released patches for five products. The code execution vulnerabilities in ColdFusion and Acrobat Reader deserve special attention.<br/>
<a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Fortinet Patches<br/>
Fortnet patched two products today, one suffering from an SSRF vulnerability.<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-783">https://fortiguard.fortinet.com/psirt/FG-IR-25-783</a><br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-084">https://fortiguard.fortinet.com/psirt/FG-IR-25-084</a><br/>
ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants<br/>
Attackers are tricking victims to copy/paste OAUTH URLs, including credentials, to a fake CAPTCHA<br/>
<a href="https://pushsecurity.com/blog/consentfix">https://pushsecurity.com/blog/consentfix</a><br/>
]]></description>
<itunes:duration>7:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9766" type="text/plain" language="en" />
<itunes:keywords>ssrf, fortinet, adobe, microsoft, oatuh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, January 13th, 2026: n8n got npm’ed; Gogs exploit; telegram proxy links
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9764</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, January 13th, 2026: n8n got npm’ed; Gogs exploit; telegram proxy links
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, January 13th, 2026: n8n got npm’ed; Gogs exploit; telegram proxy links
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9764.mp3" length="4841104" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9764.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9764</link>
<pubDate>Tue, 13 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
n8n supply chain attack<br/>
Malicious npm pagackages were used to attempt to obtain user OAUTH credentials for NPM.<br/>
<a href="https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem">https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem</a><br/>
Gogs 0-Day Exploited in the Wild<br/>
An at the time unpachted flaw in Gogs was exploited to compromise git repos.<br/>
<a href="https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit">https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit</a><br/>
Telegram Proxy Link Abuse<br/>
Telegram proxy links have been abused to deanonymize users<br/>
<a href="https://x.com/GangExposed_RU/status/2009961417781457129">https://x.com/GangExposed_RU/status/2009961417781457129</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9764" type="text/plain" language="en" />
<itunes:keywords>telegram, gogs, npm, n8n, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, January 12th, 2026: PEB Manipulation; YARA Update; VideoLAND and Apache NimBLE Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9762</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, January 12th, 2026: PEB Manipulation; YARA Update; VideoLAND and Apache NimBLE Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, January 12th, 2026: PEB Manipulation; YARA Update; VideoLAND and Apache NimBLE Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9762.mp3" length="5271443" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9762.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9762</link>
<pubDate>Mon, 12 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Malicious Process Environment Block Manipulation<br/>
The process environment block contains metadata about particular processes, but can be manipulated.<br/>
<a href="https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/">https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/</a><br/>
YARA-X 1.11.0 Release: Hash Function Warnings<br/>
The latest version of YARA will warn users if a hash rule attempts to match an invalid hash.<br/>
<a href="https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616">https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616</a><br/>
VideoLAN Security Bulletin VLC 3.0.22 CVE-2025-51602<br/>
VideoLAN fixed several vulnerabilities in its VLC software.<br/>
<a href="https://www.videolan.org/security/sb-vlc3022.html">https://www.videolan.org/security/sb-vlc3022.html</a><br/>
Apache NimBLE Bluetooth vulnerabilities<br/>
NimBLE is a Bluetooth stack popular in IoT devices. An update fixes some eavesdropping and pairing vulnerabilities.<br/>
<a href="https://mynewt.apache.org/cve/">https://mynewt.apache.org/cve/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9762" type="text/plain" language="en" />
<itunes:keywords>bluetooth, apache, nimble, videolan, yara, vlc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, January 9th, 2026: Gephi Analysis; zlib vuln; GnuPG Vulns; Cisco/Cloudflare DNS Issue
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9760</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, January 9th, 2026: Gephi Analysis; zlib vuln; GnuPG Vulns; Cisco/Cloudflare DNS Issue
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, January 9th, 2026: Gephi Analysis; zlib vuln; GnuPG Vulns; Cisco/Cloudflare DNS Issue
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9760.mp3" length="6053806" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9760.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9760</link>
<pubDate>Fri, 09 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Analysis using Gephi with DShield Sensor Data<br/>
Gephi is a neat tool to create interactive data visualizations. It can be applied to honeypot data to find data clusters.<br/>
<a href="https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608">https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608</a><br/>
zlib v1.3.1.2 Global Buffer Overflow in TGZfname() of zlib untgz Utility<br/>
The untgz utility that is part of zlib suffers from a straightforward buffer overflow in the filename parameter<br/>
<a href="https://seclists.org/fulldisclosure/2026/Jan/3">https://seclists.org/fulldisclosure/2026/Jan/3</a><br/>
GnuPG Vulnerabilities<br/>
Several vulnerabilities in GnuPG were disclosed during a recent talk at the CCC congress.<br/>
<a href="https://gpg.fail">https://gpg.fail</a><br/>
Cisco DNS Bug Reboot<br/>
Last night, several Cisco users reported that their switches rebooted. The issue appears to be related to a change Cloudflare made in the order of CNAME records.  Only users using 1.1.1.1 as a recursive resolver appear to be affected.<br/>
<a href="https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com">https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com</a><br/>
]]></description>
<itunes:duration>7:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9760" type="text/plain" language="en" />
<itunes:keywords>gephi, dshield, honeypot, zlib, untgz, gnupg, ccc, cisco, cloudflare, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, January 8th, 2026: HTML QR Code Phishing; n8n vulnerability; Powerbank Feature Creep
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9758</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, January 8th, 2026: HTML QR Code Phishing; n8n vulnerability; Powerbank Feature Creep
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, January 8th, 2026: HTML QR Code Phishing; n8n vulnerability; Powerbank Feature Creep
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9758.mp3" length="6206838" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9758.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9758</link>
<pubDate>Thu, 08 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
A phishing campaign with QR codes rendered using an HTML table<br/>
Phishing emails are bypassing filters by encoding QR codes as HTML tables.<br/>
<a href="https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606">https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606</a><br/>
n8n vulnerabilities<br/>
In recent days, several new n8n vulnerabilities were disclosed. Ensure that you update any on-premises installations and carefully consider what to use n8n for.<br/>
<a href="https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858">https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858</a><br/>
<a href="https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg">https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg</a><br/>
Power bank feature creep is out of control <br/>
Simple power banks are increasingly equipped with advanced features, including networking, which may expose them to security risks.<br/>
<a href="https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep">https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep</a><br/>
]]></description>
<itunes:duration>7:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9758" type="text/plain" language="en" />
<itunes:keywords>n8n, phishing, html, table, qr code, n8n, power banks, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, January 7th, 2026: Tailsnitch Review; D-Link DSL EoL Vuln; TOTOLINK Unpatched Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9756</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, January 7th, 2026: Tailsnitch Review; D-Link DSL EoL Vuln; TOTOLINK Unpatched Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, January 7th, 2026: Tailsnitch Review; D-Link DSL EoL Vuln; TOTOLINK Unpatched Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9756.mp3" length="4815379" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9756.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9756</link>
<pubDate>Wed, 07 Jan 2026 02:05:02 GMT</pubDate>
<description><![CDATA[<br/>
Tool Review: Tailsnitch<br/>
Tailsnitch is a tool to audit your Tailscale configuration. It does a comprehensive analysis of your configuration and suggests (or even applies) fixes.<br/>
<a href="https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602">https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602</a><br/>
D-Link DSL Command Injection via DNS Configuration Endpoint<br/>
A new vulnerability in very old D-Link DSL modems is currently being exploited.<br/>
<a href="https://www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-endpoint">https://www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-endpoint</a><br/>
TOTOLINK EX200 firmware-upload error handling can activate an unauthenticated root telnet service<br/>
TOTOLINK extenders may start a telnet server and allow unauthenticated access if a firmware update fails.<br/>
<a href="https://kb.cert.org/vuls/id/295169">https://kb.cert.org/vuls/id/295169</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9756" type="text/plain" language="en" />
<itunes:keywords>totolink, ex200, d-link, dsl, tailsnitch, tailscale, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, January 6th, 2026: IPKVM Risks; Tailsnitch; Net-SNMP Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9754</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, January 6th, 2026: IPKVM Risks; Tailsnitch; Net-SNMP Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, January 6th, 2026: IPKVM Risks; Tailsnitch; Net-SNMP Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9754.mp3" length="5156016" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9754.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9754</link>
<pubDate>Tue, 06 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Risks of OOB Access via IP KVM Devices<br/>
Recently, cheap IP KVMs have become popular. But their deployment needs to be secured.<br/>
<a href="https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598">https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598</a><br/>
Tailsnitch<br/>
Tailsnitch is a tool to review your Tailscale configuration for vulnerabilities<br/>
<a href="https://github.com/Adversis/tailsnitch">https://github.com/Adversis/tailsnitch</a><br/>
Net-SNMP snmptrapd vulnerability<br/>
A new vulnerability in snmptrapd may lead to remote code execution<br/>
<a href="https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq">https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9754" type="text/plain" language="en" />
<itunes:keywords>net-snmp, snmp, tailscale, tailsnitch, ipkvm, kvm, nanokvm, pikvm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, January 5th, 2026: MongoBleed/React2Shell Recap; Crypto Scams; DNS Stats; Old Fortinet Vulns
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9752</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, January 5th, 2026: MongoBleed/React2Shell Recap; Crypto Scams; DNS Stats; Old Fortinet Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, January 5th, 2026: MongoBleed/React2Shell Recap; Crypto Scams; DNS Stats; Old Fortinet Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9752.mp3" length="5842462" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9752.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9752</link>
<pubDate>Mon, 05 Jan 2026 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Cryptocurrency Scam Emails and Web Pages As We Enter 2026<br/>
Scam emails are directing victims to confidence scams attempting to steal cryptocurrencies.<br/>
<a href="https://isc.sans.edu/diary/Cryptocurrency%20Scam%20Emails%20and%20Web%20Pages%20As%20We%20Enter%202026/32594">https://isc.sans.edu/diary/Cryptocurrency%20Scam%20Emails%20and%20Web%20Pages%20As%20We%20Enter%202026/32594</a><br/>
Debugging DNS response times with tshark<br/>
tshark is a powerful tool to debug DNS timing issues.<br/>
<a href="https://isc.sans.edu/diary/Debugging+DNS+response+times+with+tshark/32592/">https://isc.sans.edu/diary/Debugging+DNS+response+times+with+tshark/32592/</a><br/>
Old Fortinet Devices Have not been updated<br/>
Over 10,000 Fortinet devices are still vulnerable to a five year old vulnerability<br/>
<a href="https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks/">https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks/</a><br/>
]]></description>
<itunes:duration>6:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9752" type="text/plain" language="en" />
<itunes:keywords>fortinet, dns, tshark, crypto, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Sunday, December 28th, 2025: MongoDB Unauthenticated Memory Leak CVE-2025-14847
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9750</itunes:episode>
<itunes:subtitle>SANS Stormcast Sunday, December 28th, 2025: MongoDB Unauthenticated Memory Leak CVE-2025-14847
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Sunday, December 28th, 2025: MongoDB Unauthenticated Memory Leak CVE-2025-14847
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9750.mp3" length="4905326" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9750.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9750</link>
<pubDate>Sun, 28 Dec 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
MongoDB Unauthenticated Attacker Sensitive Memory Leak CVE-2025-14847<br/>
Over the Christmas holiday, MongoDB patched a sensitive memory leak vulnerability that is now actively being exploited<br/>
<a href="https://www.mongodb.com/community/forums/t/important-mongodb-patch-available/332977">https://www.mongodb.com/community/forums/t/important-mongodb-patch-available/332977</a><br/>
<a href="https://github.com/mongodb/mongo/commit/505b660a14698bd2b5233bd94da3917b585c5728">https://github.com/mongodb/mongo/commit/505b660a14698bd2b5233bd94da3917b585c5728</a><br/>
<a href="https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/">https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/</a><br/>
<a href="https://github.com/joe-desimone/mongobleed/">https://github.com/joe-desimone/mongobleed/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9750" type="text/plain" language="en" />
<itunes:keywords>mongodb, bleed, memory leak, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9748</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, December 22nd, 2025: TLS Callbacks; FreeBSD RCE; NIST Time Server Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9748.mp3" length="5046389" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9748.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9748</link>
<pubDate>Mon, 22 Dec 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
DLLs & TLS Callbacks<br/>
As a follow-up to last week's diary about DLL Entrypoints, Didier is looking at TLS ( Thread Local Storage ) and how it can be abused.<br/>
<a href="https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580">https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580</a><br/>
FreeBSD Remote code execution via ND6 Router Advertisements<br/>
A critical vulnerability in FreeBSD allows for remote code execution. But an attacker must be on the same network.<br/>
<a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc">https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc</a><br/>
NIST Time Server Problems<br/>
The atomic ensemble time scale at the NIST Boulder campus has failed due to a prolonged utility power outage. One impact is that the Boulder Internet Time Services no longer have an accurate time reference. <br/>
<a href="https://tf.nist.gov/tf-cgi/servers.cgi">https://tf.nist.gov/tf-cgi/servers.cgi</a> <a href="https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I">https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9748" type="text/plain" language="en" />
<itunes:keywords>nist, dll, tls, freebsd, IPv6, rtsol, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, December 19th, 2025: Less Vulnerabie Devices; Critical OneView Vulnerablity; Trufflehog finds JWTs
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9746</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, December 19th, 2025: Less Vulnerabie Devices; Critical OneView Vulnerablity; Trufflehog finds JWTs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, December 19th, 2025: Less Vulnerabie Devices; Critical OneView Vulnerablity; Trufflehog finds JWTs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9746.mp3" length="3886052" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9746.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9746</link>
<pubDate>Fri, 19 Dec 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Positive trends related to public IP range from the year 2025<br/>
Fewer ICS systems, as well as fewer systems with outdated SSL versions, are exposed to the internet than before. The trend isn t quite clean for ISC, but SSL2 and SSL3 systems have been cut down by about half.<br/>
<a href="https://isc.sans.edu/diary/Positive%20trends%20related%20to%20public%20IP%20ranges%20from%20the%20year%202025/32584">https://isc.sans.edu/diary/Positive%20trends%20related%20to%20public%20IP%20ranges%20from%20the%20year%202025/32584</a><br/>
Hewlett-Packard Enterprise OneView Software, Remote Code Execution<br/>
HPs OneView Software allows for unauthenticated code execution<br/>
<a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1</a><br/>
Trufflehog Detecting JWTs with Public Keys<br/>
Trufflehog added the ability to detect JWT tokens and validate them using public keys.<br/>
<a href="https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness">https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness</a><br/>
]]></description>
<itunes:duration>4:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9746" type="text/plain" language="en" />
<itunes:keywords>Trufflehog, JWT, ICS, HP, OneView, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9744</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, December 18th, 2025: More React2Shell; Donicwall and Cisco Patch; Updated Chrome Advisory
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9744.mp3" length="5192416" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9744.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9744</link>
<pubDate>Thu, 18 Dec 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Maybe a Little Bit More Interesting React2Shell Exploit<br/>
Attackers are branching out to attack applications that initial exploits may have missed. The latest wave of attacks is going after less common endpoints and attempting to exploit applications that do not have Next.js exposed.<br/>
<a href="https://isc.sans.edu/diary/Maybe%20a%20Little%20Bit%20More%20Interesting%20React2Shell%20Exploit/32578">https://isc.sans.edu/diary/Maybe%20a%20Little%20Bit%20More%20Interesting%20React2Shell%20Exploit/32578</a><br/>
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager<br/>
Cisco s Security Email Gateway and Secure Email and Web Manager patch an already-exploited vulnerability.<br/>
<a href="https://blog.talosintelligence.com/uat-9686/">https://blog.talosintelligence.com/uat-9686/</a><br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4</a><br/>
SONICWALL SMA1000 APPLIANCE LOCAL PRIVILEGE ESCALATION VULNERABILITY<br/>
A local privilege escalation vulnerability, which SonicWall patched today, is already being exploited.<br/>
<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019</a><br/>
Google releases vulnerability details<br/>
Google updated last week s advisory by adding a CVE to the  mystery vulnerability  and adding a statement that it affects WebGPU. No new patch was released.<br/>
<a href="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html">https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9744" type="text/plain" language="en" />
<itunes:keywords>Google, Chrome, WebGPU, sonicwall, cisco, react2shell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, December 17th, 2025: Beyond RC4; Forticloud SSO Vuln Exploited; FortiGate SSO Exploited;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9742</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, December 17th, 2025: Beyond RC4; Forticloud SSO Vuln Exploited; FortiGate SSO Exploited;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, December 17th, 2025: Beyond RC4; Forticloud SSO Vuln Exploited; FortiGate SSO Exploited;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9742.mp3" length="5577348" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9742.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9742</link>
<pubDate>Wed, 17 Dec 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Beyond RC4 for Windows authentication<br/>
Microsoft outlined its transition plan to move away from RC4 for authentication and published guidance and tools to facilitate this change.<br/>
<a href="https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication">https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication</a><br/>
FortiCloud SSO Login Vuln Exploited<br/>
Arctic Wolf observed exploit attempts against vulnerable FortiGate appliances.<br/>
<a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/">https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/</a><br/>
FrePBX Vulnerability<br/>
Horizon3.ai identified three distinct vulnerabilities in FreePBX. In particular, the authentication by-pass issue should be of concern, but default FreePBX installs do not use the vulnerable web authentication feature.<br/>
<a href="https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/">https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/</a><br/>
]]></description>
<itunes:duration>6:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9742" type="text/plain" language="en" />
<itunes:keywords>freepbx, fortinet, saml, rc4, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, December 16th, 2025: Current React2Shell Example; SAML woes; MSMQ issues after patch;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9740</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, December 16th, 2025: Current React2Shell Example; SAML woes; MSMQ issues after patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, December 16th, 2025: Current React2Shell Example; SAML woes; MSMQ issues after patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9740.mp3" length="4836586" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9740.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9740</link>
<pubDate>Tue, 16 Dec 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
More React2Shell Exploits CVE-2025-55182<br/>
Our honeypots continue to detect numerous React2Shell variants. Some using slightly modified exploits<br/>
<a href="https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572">https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572</a><br/>
The Fragile Lock: Novel Bypasses For SAML Authentication<br/>
SAML is a tricky protocol to implement correctly, in particular if different XML parsers are used that may not always agree on how to parse a specific message<br/>
<a href="https://portswigger.net/research/the-fragile-lock">https://portswigger.net/research/the-fragile-lock</a><br/>
December Updates Causes issues with Microsoft Message Queuing<br/>
<a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#message-queuing--msmq--might-fail-with-the-december-2025-windows-security-update">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#message-queuing--msmq--might-fail-with-the-december-2025-windows-security-update</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9740" type="text/plain" language="en" />
<itunes:keywords>MSMQ, message queue, patch, saml, ruby, react2shell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9738</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, December 15th, 2025: DLL Entry Points; ClickFix and Finger; Apple Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9738.mp3" length="5669242" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9738.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9738</link>
<pubDate>Mon, 15 Dec 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Abusing DLLs EntryPoint for the Fun<br/>
DLLs will not just execute code when some of their functions are called, but also as they are loaded.<br/>
<a href="https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562">https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562</a><br/>
Apple Patches Everything: December 2025 Edition<br/>
Apple released patches for all of its operating systems, fixing two already exploited vulnerabilities.<br/>
ClickFix Attacks Still Using the Finger<br/>
ClickFix Attacks Still Using the Finger<br/>
Two examples of ClickFix attacks abusing the finger protocol to load additional malware<br/>
Denial of Service and Source Code Exposure in React Server Components<br/>
Denial of Service and Source Code Exposure in React Server Components<br/>
After last week's critical patch, three more, but less critical, vulnerabilities were identified in React Server Components.<br/>
<a href="https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components">https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9738" type="text/plain" language="en" />
<itunes:keywords>react, clickfix, finger, apple, dll, entrypoint, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, December 12th, 2025: Local AI Models; Mystery Chrome 0-Day; SOAPwn Attack
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9736</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, December 12th, 2025: Local AI Models; Mystery Chrome 0-Day; SOAPwn Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, December 12th, 2025: Local AI Models; Mystery Chrome 0-Day; SOAPwn Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9736.mp3" length="5825280" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9736.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9736</link>
<pubDate>Fri, 12 Dec 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Using AI Gemma 3 Locally with a Single CPU<br/>
Installing AI models on modes hardware is possible and can be useful to experiment with these models on premise<br/>
<a href="https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556">https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556</a><br/>
 Mystery  Google Chrome 0-Day Vulnerability<br/>
Google released an update for Google Chrome fixing a vulnerability that is already being exploited, but has not CVE number assigned to it yet<br/>
<a href="https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html">https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html</a><br/>
SOAPwn: Pwning NET Framework Applications Through HTTP Client Proxies And WSDL<br/>
Watchtwr identified a common vulnerability in SOAP implementations using .Net<br/>
<a href="https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/">https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9736" type="text/plain" language="en" />
<itunes:keywords>SOAP, NET, SOAPwn, Google, Chrome, gemma, ai, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, December 11th, 2025: Possible CVE-2024-9042 variant; react2shell exploits; notepad++ update hijacking; macOS priv escalation
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9734</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, December 11th, 2025: Possible CVE-2024-9042 variant; react2shell exploits; notepad++ update hijacking; macOS priv escalation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, December 11th, 2025: Possible CVE-2024-9042 variant; react2shell exploits; notepad++ update hijacking; macOS priv escalation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9734.mp3" length="5855058" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9734.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9734</link>
<pubDate>Thu, 11 Dec 2025 01:48:20 GMT</pubDate>
<description><![CDATA[<br/>
Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection)<br/>
We observed HTTP requests with our honeypot that may be indicative of a new version of an exploit against an older vulnerability. Help us figure out what is going on.<br/>
<a href="https://isc.sans.edu/diary/Possible%20exploit%20variant%20for%20CVE-2024-9042%20%28Kubernetes%20OS%20Command%20Injection%29/32554">https://isc.sans.edu/diary/Possible%20exploit%20variant%20for%20CVE-2024-9042%20%28Kubernetes%20OS%20Command%20Injection%29/32554</a><br/>
React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182<br/>
Wiz has a writeup with more background on the React2Shell vulnerability and current attacks<br/>
<a href="https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive">https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive</a><br/>
Notepad++ Update Hijacking<br/>
Notepad++ s vulnerable update process was exploited <br/>
<a href="https://notepad-plus-plus.org/news/v889-released/">https://notepad-plus-plus.org/news/v889-released/</a><br/>
New macOS PackageKit Privilege Escalation<br/>
A PoC was released for a new privilege escalation vulnerability in macOS. Currently, there is no patch.<br/>
<a href="https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html">https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html</a><br/>
]]></description>
<itunes:duration>6:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9734" type="text/plain" language="en" />
<itunes:keywords>macos, privilege escalation, zsh, notepad++, evilgrade, react2shell, exploit, kubernetes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, December 10th, 2025: Microsoft, Adobe, Ivanti, Fortinet, and Ruby patches.
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9732</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, December 10th, 2025: Microsoft, Adobe, Ivanti, Fortinet, and Ruby patches.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, December 10th, 2025: Microsoft, Adobe, Ivanti, Fortinet, and Ruby patches.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9732.mp3" length="6775273" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9732.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9732</link>
<pubDate>Wed, 10 Dec 2025 00:35:23 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
Microsoft released its regular monthly patch on Tuesday, addressing 57 flaws.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550</a><br/>
Adobe Patches<br/>
Adobe patched five products. The remote code execution in ColdFusion, as well as the code execution issue in Acrobat, will very likely see exploits soon.<br/>
<a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Ivanti Endpoint Manager Patches<br/>
Ivanti patched four vulnerabilities in End Point Manager.<br/>
<a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US</a><br/>
Fortinet FortiCloud SSO Vulnerability<br/>
Due to a cryptographic vulnerability, Forinet s FortiCloud SSO authentication is bypassable.<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-647">https://fortiguard.fortinet.com/psirt/FG-IR-25-647</a><br/>
ruby-saml vulnerability<br/>
Ruby fixed a vulnerability in ruby-saml. The issue is due to an incomplete patch for another vulnerability a few months ago.<br/>
<a href="https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3">https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3</a><br/>
]]></description>
<itunes:duration>8:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9732" type="text/plain" language="en" />
<itunes:keywords>ruby, saml, fortinet, forticloud, sso, ivanti, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, December 9th, 2025: nanoKVM Vulnerabilities; Ghostframe Phishing; WatchGuard Advisory
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9730</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, December 9th, 2025: nanoKVM Vulnerabilities; Ghostframe Phishing; WatchGuard Advisory
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, December 9th, 2025: nanoKVM Vulnerabilities; Ghostframe Phishing; WatchGuard Advisory
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9730.mp3" length="5407924" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9730.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9730</link>
<pubDate>Tue, 09 Dec 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
nanoKVM Vulnerabilities<br/>
The nanoKVM device updates firmware insecurely; however, the microphone that the authors of the advisory referred to as  undocumented  may actually be documented in the underlying hardware description.<br/>
<a href="https://www.tomshardware.com/tech-industry/cyber-security/researcher-finds-undocumented-microphone-and-major-security-flaws-in-sipeed-nanokvm">https://www.tomshardware.com/tech-industry/cyber-security/researcher-finds-undocumented-microphone-and-major-security-flaws-in-sipeed-nanokvm</a><br/>
Ghostframe Phishing Kit<br/>
The Ghostframe phishing kit uses iFrames and random subdomains to evade detection<br/>
<a href="https://blog.barracuda.com/2025/12/04/threat-spotlight-ghostframe-phishing-kit">https://blog.barracuda.com/2025/12/04/threat-spotlight-ghostframe-phishing-kit</a><br/>
WatchGuard Advisory<br/>
WatchGuard released an update for its Firebox appliance, fixing ten vulnerabilities. Five of these are rated as  High. <br/>
<a href="https://www.watchguard.com/wgrd-psirt/advisories">https://www.watchguard.com/wgrd-psirt/advisories</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9730" type="text/plain" language="en" />
<itunes:keywords>sipeed, nanokvm, kvm, ghostframe, watchguard, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, December 8th, 2025: AutoIT3 FileInstall; React2Shell Update; Tika Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9728</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, December 8th, 2025: AutoIT3 FileInstall; React2Shell Update; Tika Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, December 8th, 2025: AutoIT3 FileInstall; React2Shell Update; Tika Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9728.mp3" length="4682717" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9728.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9728</link>
<pubDate>Mon, 08 Dec 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
AutoIT3 Compiled Scripts Dropping Shellcodes<br/>
Malicious AutoIT3 scripts are usign the  FileInstall  function to include additional scripts at compile time that are dropped as temporary files during execution.<br/>
<a href="https://isc.sans.edu/diary/AutoIT3%20Compiled%20Scripts%20Dropping%20Shellcodes/32542">https://isc.sans.edu/diary/AutoIT3%20Compiled%20Scripts%20Dropping%20Shellcodes/32542</a><br/>
React2Shell Update<br/>
The race is on to patch vulnerable systems. Various groups are aggressively scanning the internet with different exploit variants. Some attempt to bypass WAFs. <br/>
<a href="https://blog.cloudflare.com/5-december-2025-outage/">https://blog.cloudflare.com/5-december-2025-outage/</a><br/>
<a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/">https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/</a><br/>
Apache Tika XXE Flaw<br/>
Apache s Tika library patched a XXE flaw.<br/>
<a href="https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k">https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9728" type="text/plain" language="en" />
<itunes:keywords>apache, tika, react, autoit3, autoit, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, December 5th, 2025: Compromised Govt System; React Vuln Update; Array Networks VPN Attacks
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9726</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, December 5th, 2025: Compromised Govt System; React Vuln Update; Array Networks VPN Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, December 5th, 2025: Compromised Govt System; React Vuln Update; Array Networks VPN Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9726.mp3" length="3849929" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9726.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9726</link>
<pubDate>Fri, 05 Dec 2025 02:05:17 GMT</pubDate>
<description><![CDATA[<br/>
Nation-State Attack or Compromised Government? [Guest Diary]<br/>
An IP address associated with the Indonesian Government attacked one of our interns' honeypots. <br/>
<a href="https://isc.sans.edu/diary/Nation-State%20Attack%20or%20Compromised%20Government%3F%20%5BGuest%20Diary%5D/32536">https://isc.sans.edu/diary/Nation-State%20Attack%20or%20Compromised%20Government%3F%20%5BGuest%20Diary%5D/32536</a><br/>
React Update<br/>
Working exploits for the React vulnerability patched yesterday are not widely available<br/>
Array Networks Array AG Vulnerablity<br/>
A recently patched vulnerability in Array Networks  Array AG VPN gateways is actively exploited.<br/>
<a href="https://www.jpcert.or.jp/at/2025/at250024.html">https://www.jpcert.or.jp/at/2025/at250024.html</a><br/>
]]></description>
<itunes:duration>4:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9726" type="text/plain" language="en" />
<itunes:keywords>react, ssh, array networks, vpn, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, December 4th, 2025: CDN Headers; React Vulnerabiity; PickleScan Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9724</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, December 4th, 2025: CDN Headers; React Vulnerabiity; PickleScan Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, December 4th, 2025: CDN Headers; React Vulnerabiity; PickleScan Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9724.mp3" length="5664008" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9724.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9724</link>
<pubDate>Thu, 04 Dec 2025 03:10:12 GMT</pubDate>
<description><![CDATA[<br/>
Attempts to Bypass CDNs<br/>
Our honeypots recently started receiving scans that included CDN specific headers.<br/>
<a href="https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532">https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532</a><br/>
React Vulnerability CVE-2025-55182<br/>
React patched a critical vulnerability in React server components. Exploitation is likely imminent.<br/>
<a href="https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components">https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components</a><br/>
Unveiling 3 PickleScan Vulnerabilities<br/>
The PyTorch AI model security tool, PickleScan, has patched three critical vulnerabilities.<br/>
<a href="https://jfrog.com/blog/unveiling-3-zero-day-vulnerabilities-in-picklescan/">https://jfrog.com/blog/unveiling-3-zero-day-vulnerabilities-in-picklescan/</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9724" type="text/plain" language="en" />
<itunes:keywords>pytorch, picklescan, react, server components, cdn, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9722</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9722.mp3" length="5125863" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9722.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9722</link>
<pubDate>Wed, 03 Dec 2025 02:45:11 GMT</pubDate>
<description><![CDATA[<br/>
SmartTube Android App Compromise<br/>
The key a developer used to sign the Android YouTube player SmartTube was compromised and used to publish a malicious version.<br/>
<a href="https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826">https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826</a><br/>
<a href="https://github.com/yuliskov/SmartTube/releases/tag/notification">https://github.com/yuliskov/SmartTube/releases/tag/notification</a><br/>
Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners<br/>
Over the course of two years, a malicious NPM package was updated to evade detection and has now been identified, in part, due to its attempt to bypass AI scanners through prompt injection.<br/>
<a href="https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners">https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners</a><br/>
Stored XSS Vulnerability via SVG Animation, SVG URL, and MathML Attributes<br/>
Angular fixed a store XSS vulnerability.<br/>
<a href="https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49">https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9722" type="text/plain" language="en" />
<itunes:keywords>angular, xss, svg, mathml, npm, smarttube, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packdets; Android Update; Long Game Malicious Browser Ext.
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9720</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packdets; Android Update; Long Game Malicious Browser Ext.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packdets; Android Update; Long Game Malicious Browser Ext.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9720.mp3" length="4887859" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9720.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9720</link>
<pubDate>Tue, 02 Dec 2025 02:05:12 GMT</pubDate>
<description><![CDATA[<br/>
Hunting for SharePoint In-Memory ToolShell Payloads<br/>
A walk-through showing how to analyze ToolShell payloads, starting with acquiring packets all the way to decoding embedded PowerShell commands.<br/>
<a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Hunting%20for%20SharePoint%20In-Memory%20ToolShell%20Payloads/32524">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Hunting%20for%20SharePoint%20In-Memory%20ToolShell%20Payloads/32524</a><br/>
Android Security Bulletin December 2025<br/>
Google fixed numerous vulnerabilities with its December Android update. Two of these vulnerabilities are already being exploited.<br/>
<a href="https://source.android.com/docs/security/bulletin/2025-12-01">https://source.android.com/docs/security/bulletin/2025-12-01</a><br/>
4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign<br/>
A group or individual released several browser extensions that worked fine for years until an update injected malicious code into the extension<br/>
<a href="https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign">https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9720" type="text/plain" language="en" />
<itunes:keywords>browser, extension, long game, android, zero-day, sharepoint, toolshell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, December 1st, 2025: More ClickFix; Teams Guest Access; Geoserver XXE Vulnerablity
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9718</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, December 1st, 2025: More ClickFix; Teams Guest Access; Geoserver XXE Vulnerablity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, December 1st, 2025: More ClickFix; Teams Guest Access; Geoserver XXE Vulnerablity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9718.mp3" length="4791696" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9718.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9718</link>
<pubDate>Mon, 01 Dec 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix<br/>
The latest variant of ClickFix tricks users into copy/pasting commands by displaying a fake blue screen of death.<br/>
<a href="https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/">https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/</a><br/>
B2B Guest Access Creates an Unprotected Attack Vector<br/>
Users may be tricked into joining an external Teams workspace as a guest, bypassing protections typically enabled for Teams workspaces.<br/>
<a href="https://www.ontinue.com/resource/blog-microsoft-chat-with-anyone-understanding-phishing-risk/">https://www.ontinue.com/resource/blog-microsoft-chat-with-anyone-understanding-phishing-risk/</a><br/>
Geoserver XXE Vulnerability CVE-2025-58360<br/>
Geoserver patched an external XML entity (XXE) vulnerability.<br/>
<a href="https://helixguard.ai/blog/CVE-2025-58360">https://helixguard.ai/blog/CVE-2025-58360</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9718" type="text/plain" language="en" />
<itunes:keywords>geoserver, teams, clickfix, xxe, xml, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, November 26th, 2025: Attacks Against Messaging; Passwords in Random Websites; Fluentbit Vuln; #thanksgiving
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9716</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, November 26th, 2025: Attacks Against Messaging; Passwords in Random Websites; Fluentbit Vuln; #thanksgiving
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, November 26th, 2025: Attacks Against Messaging; Passwords in Random Websites; Fluentbit Vuln; #thanksgiving
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9716.mp3" length="5141209" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9716.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9716</link>
<pubDate>Wed, 26 Nov 2025 03:10:10 GMT</pubDate>
<description><![CDATA[<br/>
Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications<br/>
Spyware attacks messaging applications in part by triggering vulnerabilities in messaging applications but also by deploying tools like keystroke loggers and screenshot applications.<br/>
<a href="https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications">https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications</a><br/>
Stop Putting Your Passwords Into Random Websites Yes. Just Stop!<br/>
<a href="https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/">https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/</a><br/>
Fluentbit Vulnerability<br/>
<a href="https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover">https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover</a><br/>
Happy Thanksgiving. Next podcast on Monday after Thanksgiving.<br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9716" type="text/plain" language="en" />
<itunes:keywords>fluentbit, passwords, spyware, messaging, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, November 25th, 2025: URL Mapping and Authentication; SHA1-Hulud; Hacklore
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9714</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, November 25th, 2025: URL Mapping and Authentication; SHA1-Hulud; Hacklore
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, November 25th, 2025: URL Mapping and Authentication; SHA1-Hulud; Hacklore
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9714.mp3" length="5197934" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9714.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9714</link>
<pubDate>Tue, 25 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Conflicts between URL mapping and URL based access control.<br/>
Mapping different URLs to the same script, and relying on URL based authentication at the same time, may lead to dangerous authentication and access control gaps.<br/>
<a href="https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518">https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518</a><br/>
Sha1-Hulud, The Second Coming<br/>
A new, destructive variant of the Shai-Hulud worm is currently spreading through NPM/Github repos.<br/>
<a href="https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised">https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised</a><br/>
Hacklore: Cleaning up Outdated Security Advice<br/>
A new website, hacklore.org, has published an open letter from former CISOs and other security leaders aimed at addressing some outdated security advice that is often repeated.<br/>
<a href="https://www.hacklore.org">https://www.hacklore.org</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9714" type="text/plain" language="en" />
<itunes:keywords>hacklore, sha1-hulud, npm, url, mapping, access control, authentication, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, November 24th, 2025: CSS Padding in Phishing; Oracle Identity Manager Scans Update;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9712</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, November 24th, 2025: CSS Padding in Phishing; Oracle Identity Manager Scans Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, November 24th, 2025: CSS Padding in Phishing; Oracle Identity Manager Scans Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9712.mp3" length="4195675" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9712.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9712</link>
<pubDate>Mon, 24 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Use of CSS stuffing as an obfuscation technique?<br/>
Phishing sites stuff their HTML with benign CSS code. This is likely supposed to throw of simple detection engines<br/>
<a href="https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510">https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510</a><br/>
Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day<br/>
Early exploit attempts for the vulnerability were part of Searchlight Cyber s research effort<br/>
<a href="https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/">https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/</a><br/>
ClamAV Cleaning Signature Database<br/>
ClamAV will significantly clean up its signature database<br/>
<a href="https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html">https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html</a><br/>
]]></description>
<itunes:duration>4:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9712" type="text/plain" language="en" />
<itunes:keywords>clamav, oracle, css, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, November 21st, 2025: Oracle Idendity Manager Scans; SonicWall DoS Vuln; Adam Wilson (@sans_edu) reducing prompt injection.
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9710</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, November 21st, 2025: Oracle Idendity Manager Scans; SonicWall DoS Vuln; Adam Wilson (@sans_edu) reducing prompt injection.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, November 21st, 2025: Oracle Idendity Manager Scans; SonicWall DoS Vuln; Adam Wilson (@sans_edu) reducing prompt injection.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9710.mp3" length="11889144" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9710.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9710</link>
<pubDate>Fri, 21 Nov 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Oracle Identity Manager Exploit Observation from September (CVE-2025-61757)<br/>
We observed some exploit attempts in September against an Oracle Identity Manager vulnerability that was patched in October, indicating that exploitation may have occurred prior to the patch being released.<br/>
<a href="https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506">https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506</a><br/>
<a href="https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/">https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/</a><br/>
DigitStealer: a JXA-based infostealer that leaves little footprint<br/>
<a href="https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/">https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/</a><br/>
SonicWall DoS Vulnerability<br/>
Sonicwall patched a DoS vulnerability in SonicOS<br/>
<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016</a><br/>
Adam Wilson: Automating Generative AI Guidelines: Reducing Prompt Injection Risk with 'Shift-Left' MITRE ATLAS Mitigation Testing<br/>
]]></description>
<itunes:duration>14:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9710" type="text/plain" language="en" />
<itunes:keywords>prompt injection, ai, atlas, mitre, sonicwall, sonicos, digitstealer, oracle, identity manager, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, November 20th, 2025: Unicode Issues; FortiWeb More Vulns; DLink DIR-878 Vuln; Operation WrtHug and ASUS Routers
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9708</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, November 20th, 2025: Unicode Issues; FortiWeb More Vulns; DLink DIR-878 Vuln; Operation WrtHug and ASUS Routers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, November 20th, 2025: Unicode Issues; FortiWeb More Vulns; DLink DIR-878 Vuln; Operation WrtHug and ASUS Routers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9708.mp3" length="5524806" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9708.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9708</link>
<pubDate>Thu, 20 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Unicode: It is more than funny domain names.<br/>
Unicode can cause a number of issues due to odd features like variance selectors and text direction issues.<br/>
<a href="https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472">https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472</a><br/>
FortiWeb Multiple OS command injection in API and CLI<br/>
A second silently patched vulnerability in FortiWeb is already being exploited in the wild.<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-513">https://fortiguard.fortinet.com/psirt/FG-IR-25-513</a><br/>
DLink DIR-878 Vulnerability<br/>
DLink disclosed four different vulnerabilities in its popular DIR-878 router. The router is end-of-life and DLink will not release patches<br/>
<a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475</a><br/>
Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router<br/>
A new report,  Operation WrtHug,  has uncovered a massive, coordinated effort that has compromised thousands of ASUS routers worldwide.<br/>
<a href="https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/">https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9708" type="text/plain" language="en" />
<itunes:keywords>unicode, wrthug, asus, dlink, dir-878, fortiweb, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, November 19th, 2025: Kong Tuke; Cloudflare Outage
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9706</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, November 19th, 2025: Kong Tuke; Cloudflare Outage
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, November 19th, 2025: Kong Tuke; Cloudflare Outage
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9706.mp3" length="3897645" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9706.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9706</link>
<pubDate>Wed, 19 Nov 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
KongTuke Activity<br/>
This diary investigates how a recent Kong Tuke infections evolved all the way from starting with a ClickFix attack.<br/>
<a href="https://isc.sans.edu/diary/KongTuke%20activity/32498">https://isc.sans.edu/diary/KongTuke%20activity/32498</a><br/>
Cloudflare Outage<br/>
Cloudflare suffered a large outage today after an oversized configuration file was loaded into its bot protection service<br/>
<a href="https://x.com/dok2001">https://x.com/dok2001</a><br/>
Google Patches Chrome 0-Day<br/>
Google patched two vulnerabilities in Chrome. One of them is already being exploited.<br/>
<a href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html">https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html</a><br/>
]]></description>
<itunes:duration>4:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9706" type="text/plain" language="en" />
<itunes:keywords>google, chrome, v8, cloudflare, outages, kongtuke, clickfix, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, November 18th, 2025: Binary Expression Decoding. Tea NPM Pollution; IBM AIX NIMSH Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9704</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, November 18th, 2025: Binary Expression Decoding. Tea NPM Pollution; IBM AIX NIMSH Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, November 18th, 2025: Binary Expression Decoding. Tea NPM Pollution; IBM AIX NIMSH Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9704.mp3" length="4177859" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9704.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9704</link>
<pubDate>Tue, 18 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Decoding Binary Numeric Expressions<br/>
Didier updated his number to hex script to support simple arithmetic operations in the text.<br/>
<a href="https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490">https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490</a><br/>
Tea Token NPM Pollution<br/>
The NPM repository was hit with around 150,000 submissions that did not contain any useful contributions, but instead attempted to fake contributions to earn a new  tea  coin.<br/>
<a href="https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/">https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/</a><br/>
IBM AIX NIMSH Vulnerabilities<br/>
IBM patched several critical vulnerablities in the NIMSH daemon<br/>
<a href="https://www.ibm.com/support/pages/node/7251173">https://www.ibm.com/support/pages/node/7251173</a><br/>
]]></description>
<itunes:duration>4:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9704" type="text/plain" language="en" />
<itunes:keywords>nimsh, ibm, aix, tea, npm, binary, numeric, decoding, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9702</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9702.mp3" length="6031165" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9702.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9702</link>
<pubDate>Mon, 17 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Fortiweb Vulnerability<br/>
Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly.<br/>
<a href="https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486">https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486</a><br/>
<a href="https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/">https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/</a><br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com">https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com</a><br/>
Flnger.exe and ClickFix<br/>
Attackers started to use the finger.exe binary to retrieve additional payload in ClickFix attacks<br/>
<a href="https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492">https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492</a><br/>
]]></description>
<itunes:duration>7:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9702" type="text/plain" language="en" />
<itunes:keywords>clickfix, finger, fortiweb, finger.exe, fortinet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, November 14th, 2025: SmartApeSG and ClickFix; Formbook Obfuscation Tricks; Sudo-rs Vulnerabilities; SANS Holiday Hack Challenge
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9700</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, November 14th, 2025: SmartApeSG and ClickFix; Formbook Obfuscation Tricks; Sudo-rs Vulnerabilities; SANS Holiday Hack Challenge
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, November 14th, 2025: SmartApeSG and ClickFix; Formbook Obfuscation Tricks; Sudo-rs Vulnerabilities; SANS Holiday Hack Challenge
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9700.mp3" length="8535124" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9700.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9700</link>
<pubDate>Fri, 14 Nov 2025 01:18:18 GMT</pubDate>
<description><![CDATA[<br/>
SmartApeSG campaign uses ClickFix page to push NetSupport RAT<br/>
A detailed analysis of a recent SamtApeSG campaign taking advantage of ClickFix<br/>
<a href="https://isc.sans.edu/diary/32474">https://isc.sans.edu/diary/32474</a><br/>
Formbook Delivered Through Multiple Scripts<br/>
An analysis of a recent version of Formbook showing how it takes advantage of multiple obfuscation tricks<br/>
<a href="https://isc.sans.edu/diary/32480">https://isc.sans.edu/diary/32480</a><br/>
sudo-rs vulnerabilities<br/>
Two vulnerabilities were patched in sudo-rs, the version of sudo written in Rust, showing that while Rust does have an advantage when it comes to memory safety, there are plenty of other vulnerabilities to worry about<br/>
<a href="https://ubuntu.com/security/notices/USN-7867-1">https://ubuntu.com/security/notices/USN-7867-1</a><br/>
<a href="https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com">https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com</a><br/>
SANS Holiday Hack Challenge<br/>
<a href="https://sans.org/HolidayHack">https://sans.org/HolidayHack</a><br/>
]]></description>
<itunes:duration>10:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9700" type="text/plain" language="en" />
<itunes:keywords>holiday, hack, challenge, sudo-rs, formbook, click-fix, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, November 13th, 2025: OWASP Top 10 Update; Cisco/Citrix Exploits; Test post quantum readiness
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9698</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, November 13th, 2025: OWASP Top 10 Update; Cisco/Citrix Exploits; Test post quantum readiness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, November 13th, 2025: OWASP Top 10 Update; Cisco/Citrix Exploits; Test post quantum readiness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9698.mp3" length="5511003" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9698.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9698</link>
<pubDate>Thu, 13 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
OWASP Top 10 2025 Release Candidate<br/>
OWASP published a release candidate for the 2025 version of its Top 10 list<br/>
<a href="https://owasp.org/Top10/2025/0x00_2025-Introduction/">https://owasp.org/Top10/2025/0x00_2025-Introduction/</a><br/>
Citrix/Cisco Exploitation Details<br/>
Amazon detailed how Citrix and Cisco vulnerabilities were used by advanced actors to upload webshells<br/>
<a href="https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/">https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/</a><br/>
Testing Quantum Readyness<br/>
A website tests your services for post-quantum computing-resistant cryptographic algorithms<br/>
<a href="https://qcready.com/">https://qcready.com/</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9698" type="text/plain" language="en" />
<itunes:keywords>quantum, crypto, citrix, cisco, owasp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, November 12th, 2025: Microsoft Patch Tuesday; Gladinet Triofox Vulnerability; SAP Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9696</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, November 12th, 2025: Microsoft Patch Tuesday; Gladinet Triofox Vulnerability; SAP Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, November 12th, 2025: Microsoft Patch Tuesday; Gladinet Triofox Vulnerability; SAP Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9696.mp3" length="5085734" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9696.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9696</link>
<pubDate>Wed, 12 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday for November 2025<br/>
<a href="https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/">https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/</a><br/>
Gladinet Triofox Vulnerability<br/>
Triofox uses the  host  header in lieu of proper access control, allowing an attacker to access the page managing administrators by simply setting the host header to localhost.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480/">https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480/</a><br/>
SAP November 2025 Patch Day<br/>
SAP fixed a critical vulnerability, fixed default credentials in its SQL Anywhere Monitor<br/>
<a href="https://onapsis.com/blog/sap-security-patch-day-november-2025/">https://onapsis.com/blog/sap-security-patch-day-november-2025/</a><br/>
Ivanti Endpoint Manager Updates<br/>
<a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9696" type="text/plain" language="en" />
<itunes:keywords>ivanti, sap, gladinet, triofox, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, November 11th, 2025: 3CX Related Scans; Watchguard Default Password; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9694</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, November 11th, 2025: 3CX Related Scans; Watchguard Default Password; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, November 11th, 2025: 3CX Related Scans; Watchguard Default Password; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9694.mp3" length="6237992" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9694.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9694</link>
<pubDate>Tue, 11 Nov 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
It isn t always defaults: Scans for 3CX Usernames<br/>
Our honeypots detected scans for usernames that may be related to 3CX business phone systems<br/>
<a href="https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464">https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464</a><br/>
Watchguard Default Password Controversy<br/>
A CVE number was assigned to a default password commonly used in Watchguard products. This was a documented username and password that was recently removed in a firmware upgrade.<br/>
<a href="https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt">https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt</a><br/>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59396">https://nvd.nist.gov/vuln/detail/CVE-2025-59396</a><br/>
JavaScript expr-eval Vulnerability<br/>
The JavaScript expr-eval library was vulnerable to a code execution issue.<br/>
<a href="https://www.kb.cert.org/vuls/id/263614">https://www.kb.cert.org/vuls/id/263614</a><br/>
]]></description>
<itunes:duration>7:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9694" type="text/plain" language="en" />
<itunes:keywords>javascript, eval, expt-eval, watchguard, 3cx, usernames, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, November 10th, 2025: Code Repo Requests; Time Delayed ICS Attacks; Encrypted LLM Traffic Sidechannel Attacks
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9692</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, November 10th, 2025: Code Repo Requests; Time Delayed ICS Attacks; Encrypted LLM Traffic Sidechannel Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, November 10th, 2025: Code Repo Requests; Time Delayed ICS Attacks; Encrypted LLM Traffic Sidechannel Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9692.mp3" length="5976309" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9692.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9692</link>
<pubDate>Mon, 10 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Honeypot Requests for Code Repository<br/>
Attackers continue to scan websites for source code repositories. Keep your repositories outside your document root and proactively scan your own sites.<br/>
<a href="https://isc.sans.edu/diary/Honeypot%3A%20Requests%20for%20%28Code%29%20Repositories/32460">https://isc.sans.edu/diary/Honeypot%3A%20Requests%20for%20%28Code%29%20Repositories/32460</a><br/>
Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads<br/>
Newly discovered malicious .NET packages attempt to deliver a time-delayed attack targeting ICS systems.<br/>
<a href="https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads">https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads</a><br/>
Side Channel Leaks in Encrypted Traffic to LLMs<br/>
Traffic to LLMs can be profiled to discover the nature of prompts sent by a user based on the amount and structure of the encrypted data.<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/">https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9692" type="text/plain" language="en" />
<itunes:keywords>llms, ai, nuget, ics, control systems, time, honeypot, source code, repositories, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, November 7th, 2025: PowerShell Log Correlation; RondoBox Disected; Google Chrome and Cisco Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9690</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, November 7th, 2025: PowerShell Log Correlation; RondoBox Disected; Google Chrome and Cisco Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, November 7th, 2025: PowerShell Log Correlation; RondoBox Disected; Google Chrome and Cisco Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9690.mp3" length="4633560" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9690.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9690</link>
<pubDate>Fri, 07 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Binary Breadcrumbs: Correlating Malware Samples with Honeypot Logs Using PowerShell [Guest Diary]<br/>
Windows, with PowerShell, has a great scripting platform to match common Linux/Unix command line utilities. <br/>
<a href="https://isc.sans.edu/diary/Binary%20Breadcrumbs%3A%20Correlating%20Malware%20Samples%20with%20Honeypot%20Logs%20Using%20PowerShell%20%5BGuest%20Diary%5D/32454">https://isc.sans.edu/diary/Binary%20Breadcrumbs%3A%20Correlating%20Malware%20Samples%20with%20Honeypot%20Logs%20Using%20PowerShell%20%5BGuest%20Diary%5D/32454</a><br/>
RondoDox v2 Increases Exploits<br/>
The RondoDox (or RondoWorm) added a substantial amount of new exploits to its repertoire.<br/>
<a href="https://beelzebub.ai/blog/rondo-dox-v2/">https://beelzebub.ai/blog/rondo-dox-v2/</a><br/>
Google Chrome Updates<br/>
Google released an update for Google Chrome addressing five vulnerabilities.<br/>
<a href="https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html</a><br/>
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities<br/>
Cisco patched two critical vulnerabilities in its Contact Center Express software. These vulnerabilities may lead to a full system compromise.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9690" type="text/plain" language="en" />
<itunes:keywords>Cisco, Google, Chrome, RondoDox, Windows, PowerShell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, November 6th, 2025: Domain API Update; Teams Spoofing; VShell Report
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9688</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, November 6th, 2025: Domain API Update; Teams Spoofing; VShell Report
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, November 6th, 2025: Domain API Update; Teams Spoofing; VShell Report
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9688.mp3" length="4804066" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9688.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9688</link>
<pubDate>Thu, 06 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Updates to Domainname API<br/>
Some updates to our domainname API will make it more flexible and make it easier and faster to get the complete dataset.<br/>
<a href="https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452">https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452</a><br/>
Microsoft Teams Impersonation and Spoofing Vulnerabilities<br/>
Checkpoint released details about recently patched spoofing and impersonation vulnerabilities in Microsoft Teams<br/>
<a href="https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/">https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/</a><br/>
NViso Report: VSHELL<br/>
NViso published an amazingly detailed report describing the remote control implant VSHELL. The report includes details about the inner workings of the tool as well as detection ideas.<br/>
<a href="https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool">https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9688" type="text/plain" language="en" />
<itunes:keywords>vshell, teams, microsoft, domains, api, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, November 5th, 2025: Apple Patches; Exploits against Trucking and Logistic; Google Android Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9686</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, November 5th, 2025: Apple Patches; Exploits against Trucking and Logistic; Google Android Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, November 5th, 2025: Apple Patches; Exploits against Trucking and Logistic; Google Android Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9686.mp3" length="5454053" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9686.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9686</link>
<pubDate>Wed, 05 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Patches Everything, Again<br/>
Apple released a minor OS upgrade across its lineup, fixing a number of security vulnerabilities.<br/>
<a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448">https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448</a><br/>
Remote Access Tools Used to Compromise Trucking and Logistics<br/>
Attackers infect trucking and logistics companies with regular remote management tools to inject malware into other companies or learn about high-value loads in order to steal them.<br/>
<a href="https://www.proofpoint.com/us/blog/threat-insight/remote-access-real-cargo-cybercriminals-targeting-trucking-and-logistics">https://www.proofpoint.com/us/blog/threat-insight/remote-access-real-cargo-cybercriminals-targeting-trucking-and-logistics</a><br/>
Google Android Patch Day<br/>
Google released its usual monthly Android updates this week<br/>
<a href="https://source.android.com/docs/security/bulletin/2025-11-01">https://source.android.com/docs/security/bulletin/2025-11-01</a><br/>
]]></description>
<itunes:duration>6:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9686" type="text/plain" language="en" />
<itunes:keywords>apple, patches, trucks, google, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, November 4th, 2025: XWiki SolrSearch Exploits and Rapper Feud; AMD Zen 5 RDSEED Bug; More Malicious Open VSX Extensions
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9684</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, November 4th, 2025: XWiki SolrSearch Exploits and Rapper Feud; AMD Zen 5 RDSEED Bug; More Malicious Open VSX Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, November 4th, 2025: XWiki SolrSearch Exploits and Rapper Feud; AMD Zen 5 RDSEED Bug; More Malicious Open VSX Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9684.mp3" length="5827960" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9684.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9684</link>
<pubDate>Tue, 04 Nov 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
XWiki SolrSearch Exploit Attempts CVE-2025-24893<br/>
We have detected a number of exploit attempts against XWiki taking advantage of a vulnerability that was added to the KEV list on Friday.<br/>
<a href="https://isc.sans.edu/diary/XWiki%20SolrSearch%20Exploit%20Attempts%20%28CVE-2025-24893%29%20with%20link%20to%20Chicago%20Gangs%20Rappers/32444">https://isc.sans.edu/diary/XWiki%20SolrSearch%20Exploit%20Attempts%20%28CVE-2025-24893%29%20with%20link%20to%20Chicago%20Gangs%20Rappers/32444</a><br/>
AMD Zen 5 Random Number Generator Bug<br/>
The RDSEED function for AMD s Zen 5 processors does return 0 more often than it should.<br/>
<a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html</a><br/>
SleepyDuck malware invades Cursor through Open VSX<br/>
Yet another Open VSX extension stealing crypto credentials<br/>
<a href="https://secureannex.com/blog/sleepyduck-malware/">https://secureannex.com/blog/sleepyduck-malware/</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9684" type="text/plain" language="en" />
<itunes:keywords>crypto, open vsx, extensions, amd, zen 5, random, rdseed, xwikit, solrsearch, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, November 3rd, 2025: Port 8530/8531 Scans; BADCANDY Webshells; Open VSX Security Improvements
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9682</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, November 3rd, 2025: Port 8530/8531 Scans; BADCANDY Webshells; Open VSX Security Improvements
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, November 3rd, 2025: Port 8530/8531 Scans; BADCANDY Webshells; Open VSX Security Improvements
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9682.mp3" length="5415125" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9682.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9682</link>
<pubDate>Mon, 03 Nov 2025 02:35:11 GMT</pubDate>
<description><![CDATA[<br/>
Scans for WSUS: Port 8530/8531 TCP, CVE-2025-59287<br/>
We did observe an increase in scans for TCP ports 8530 and 8531. These ports are associated with WSUS and the scans are likely looking for servers vulnerable to CVE-2025-59287<br/>
<a href="https://isc.sans.edu/diary/Scans%20for%20Port%208530%208531%20%28TCP%29.%20Likely%20related%20to%20WSUS%20Vulnerability%20CVE-2025-59287/32440">https://isc.sans.edu/diary/Scans%20for%20Port%208530%208531%20%28TCP%29.%20Likely%20related%20to%20WSUS%20Vulnerability%20CVE-2025-59287/32440</a><br/>
BADCANDY Webshell Implant Deployed via<br/>
The Australian Signals Directorate warns that they still see Cisco IOS XE devices not patches for CVE-2023-20198. A threat actor is now using this vulnerability to deploy the BADCANDY implant for persistent access<br/>
<a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy</a><br/>
Improvements to Open VSX Security<br/>
In reference to the Glassworm incident, OpenVSX published a blog post outlining some of the security improvements they will make to prevent a repeat of this incident.<br/>
<a href="https://blogs.eclipse.org/post/mika">https://blogs.eclipse.org/post/mika</a> l-barbero/open-vsx-security-update-october-2025<br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9682" type="text/plain" language="en" />
<itunes:keywords>wsus, open vsx, badcandy, cisco, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, October 31st, 2025: Bug Bounty Headers; Exchange hardening; MOVEIt vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9680</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, October 31st, 2025: Bug Bounty Headers; Exchange hardening; MOVEIt vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, October 31st, 2025: Bug Bounty Headers; Exchange hardening; MOVEIt vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9680.mp3" length="5315770" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9680.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9680</link>
<pubDate>Fri, 31 Oct 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
X-Request-Purpose: Identifying "research" and bug bounty related scans?<br/>
Our honeypots captured a few requests with bug bounty specific headers. These headers are meant to make it easier to identify requests related to bug bounty, and they are supposed to identify the researcher conducting the scans<br/>
<a href="https://isc.sans.edu/diary/X-Request-Purpose%3A%20Identifying%20%22research%22%20and%20bug%20bounty%20related%20scans%3F/32436">https://isc.sans.edu/diary/X-Request-Purpose%3A%20Identifying%20%22research%22%20and%20bug%20bounty%20related%20scans%3F/32436</a><br/>
Proton Breach Observatory<br/>
Proton opened up its breach observatory. This website will collect information about breaches affecting companies that have not yet made the breach public.<br/>
<a href="https://proton.me/blog/introducing-breach-observatory">https://proton.me/blog/introducing-breach-observatory</a><br/>
Microsoft Exchange Server Security Best Practices<br/>
A new document published by a collaboration of national cyber security agencies summarizes steps that should be taken to harden Exchange Server.<br/>
<a href="https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI_Microsoft_Exchange_Server_Security_Best_Practices.pdf?ver=9mpKKyUrwfpb9b9r4drVMg%3d%3d">https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI_Microsoft_Exchange_Server_Security_Best_Practices.pdf?ver=9mpKKyUrwfpb9b9r4drVMg%3d%3d</a><br/>
MOVEit Vulnerability<br/>
Progress published an advisory for its file transfer program  MOVEIt . This software has had heavily exploited vulnerabilities in the past.<br/>
<a href="https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025">https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025</a><br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9680" type="text/plain" language="en" />
<itunes:keywords>moveit, microsoft, exchange, proton, headers, bug bounty, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, October 30th, 2025: Memory Only Filesystems Forensics; Azure Outage; docker-compose patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9678</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, October 30th, 2025: Memory Only Filesystems Forensics; Azure Outage; docker-compose patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, October 30th, 2025: Memory Only Filesystems Forensics; Azure Outage; docker-compose patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9678.mp3" length="5142376" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9678.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9678</link>
<pubDate>Thu, 30 Oct 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
How to Collect Memory-Only Filesystems on Linux Systems<br/>
Getting forensically sound copies of memory-only file systems on Linux can be tricky, as tools like  dd  do not work.<br/>
<a href="https://isc.sans.edu/diary/How%20to%20collect%20memory-only%20filesystems%20on%20Linux%20systems/32432">https://isc.sans.edu/diary/How%20to%20collect%20memory-only%20filesystems%20on%20Linux%20systems/32432</a><br/>
Microsoft Azure Front Door Outage<br/>
Today, Microsoft s Azure Front Door service failed, leading to users not being able to authenticate to various Azure-related services.<br/>
<a href="https://azure.status.microsoft/en-us/status">https://azure.status.microsoft/en-us/status</a><br/>
Docker-Compose Vulnerability<br/>
A vulnerability in docker-compose may be used to trick users into creating files outside the docker-compose directory<br/>
<a href="https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q">https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9678" type="text/plain" language="en" />
<itunes:keywords>docker, compose, microsoft, azure, ram, temporary, files, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, October 29th, 2025: Invisible Subject Character Phishing; Tomcat PUT Vuln; BIND9 Spoofing Vuln PoC
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9676</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, October 29th, 2025: Invisible Subject Character Phishing; Tomcat PUT Vuln; BIND9 Spoofing Vuln PoC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, October 29th, 2025: Invisible Subject Character Phishing; Tomcat PUT Vuln; BIND9 Spoofing Vuln PoC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9676.mp3" length="6788646" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9676.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9676</link>
<pubDate>Wed, 29 Oct 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Phishing with Invisible Characters in the Subject Line<br/>
Phishing emails use invisible UTF-8 encoded characters to break up keywords used to detect phishing (or spam). This is aided by mail clients not rendering some characters that should be rendered.<br/>
<a href="https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428">https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428</a><br/>
Apache Tomcat PUT Directory Traversal<br/>
Apache released an update to Tomcat fixing a directory traversal vulnerability in how the PUT method is used. Exploits could upload arbitrary files, leading to remote code execution.<br/>
<a href="https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog">https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog</a><br/>
BIND9 DNS Spoofing Vulnerability<br/>
A PoC exploit is now available for the recently patched BIND9 spoofing vulnerability<br/>
<a href="https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918">https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918</a><br/>
]]></description>
<itunes:duration>8:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9676" type="text/plain" language="en" />
<itunes:keywords>bind9, dns, apache, tomcat, put, phishing, subject, unicode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, October 28th, 2025:  Bytes over DNS; Unifi Access Vuln; OpenAI Atlas Prompt Injection
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9674</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, October 28th, 2025:  Bytes over DNS; Unifi Access Vuln; OpenAI Atlas Prompt Injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, October 28th, 2025:  Bytes over DNS; Unifi Access Vuln; OpenAI Atlas Prompt Injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9674.mp3" length="5277452" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9674.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9674</link>
<pubDate>Tue, 28 Oct 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Bytes over DNS<br/>
Didiear investigated which bytes may be transmitted as part of a hostname in DNS packets, depending on the client resolver and recursive resolver constraints<br/>
<a href="https://isc.sans.edu/diary/Bytes%20over%20DNS/32420">https://isc.sans.edu/diary/Bytes%20over%20DNS/32420</a><br/>
Unifi Access Vulnerability<br/>
Unifi fixed a critical vulnerability in it s Access product<br/>
<a href="https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191">https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191</a><br/>
OpenAI Atlas Omnibox Prompt Injection<br/>
OpenAI s latest browser can be jailbroken by inserting prompts in URLs<br/>
<a href="https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection">https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9674" type="text/plain" language="en" />
<itunes:keywords>openai, atlas, unifi, bytes, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, October 27th, 2025: Bilingual Phishing; Kaitai Struct WebIDE
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9672</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, October 27th, 2025: Bilingual Phishing; Kaitai Struct WebIDE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, October 27th, 2025: Bilingual Phishing; Kaitai Struct WebIDE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9672.mp3" length="5327779" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9672.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9672</link>
<pubDate>Mon, 27 Oct 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Bilingual Phishing for Cloud Credentials<br/>
Guy observed identical phishing messages in French and English attempting to phish cloud credentials<br/>
<a href="https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416">https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416</a><br/>
Kaitai Struct WebIDE<br/>
The binary file analysis tool Kaitai Struct is now available in a web only version<br/>
<a href="https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422">https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422</a><br/>
WSUS Emergency Update<br/>
Microsoft released an emergency patch for WSUS to fix a currently exploited critical vulnerability<br/>
<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287</a><br/>
Network Security Devices Endanger Orgs with 90s-era Flaws<br/>
Attackers increasingly use simple-to-exploit network security device vulnerabilities to compromise organizations.<br/>
<a href="https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html">https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9672" type="text/plain" language="en" />
<itunes:keywords>network security, border security, exploits, 0-day, wsus, kaitai, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, October 24th, 2025: Android Infostealer; SessionReaper Exploited; BIND/unbound DNS Spoofing fix; WSUS Exploit
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9670</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, October 24th, 2025: Android Infostealer; SessionReaper Exploited; BIND/unbound DNS Spoofing fix; WSUS Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, October 24th, 2025: Android Infostealer; SessionReaper Exploited; BIND/unbound DNS Spoofing fix; WSUS Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9670.mp3" length="5392144" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9670.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9670</link>
<pubDate>Fri, 24 Oct 2025 02:00:04 GMT</pubDate>
<description><![CDATA[<br/>
Infostealer Targeting Android Devices<br/>
This infostealer, written in Python, specifically targets Android phones. It takes advantage of Termux to gain access to data and exfiltrates it via Telegram.<br/>
<a href="https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414">https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414</a><br/>
Attackers exploit recently patched Adobe Commerce Vulnerability CVE-2025-54236<br/>
Six weeks after Adobe's emergency patch, SessionReaper (CVE-2025-54236) has entered active exploitation. E-Commerce security company SanSec has detected multiple exploit attempts.<br/>
<a href="https://sansec.io/research/sessionreaper-exploitation">https://sansec.io/research/sessionreaper-exploitation</a><br/>
Patch for BIND and unbound nameservers CVE-2025-40780<br/>
The Internet Systems Consortium (ISC.org), as well as the Unbound project, patched a flaw that may allow for DNS spoofing due to a weak random number generator.<br/>
<a href="https://kb.isc.org/docs/cve-2025-40780">https://kb.isc.org/docs/cve-2025-40780</a><br/>
WSUS Exploit Released CVE-2025-59287<br/>
Hawktrace released a walk through showing how to exploit the recently patched WSUS vulnerability<br/>
<a href="https://hawktrace.com/blog/CVE-2025-59287">https://hawktrace.com/blog/CVE-2025-59287</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9670" type="text/plain" language="en" />
<itunes:keywords>wsus, deserialization, bind, adobe, commerce, infostealer, android, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, October 23rd, 2025: Blue Angle Software Exploit; Oracle CPU; Rust tar library vulnerability.
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9668</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, October 23rd, 2025: Blue Angle Software Exploit; Oracle CPU; Rust tar library vulnerability.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, October 23rd, 2025: Blue Angle Software Exploit; Oracle CPU; Rust tar library vulnerability.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9668.mp3" length="6276004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9668.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9668</link>
<pubDate>Thu, 23 Oct 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
webctrl.cgi/Blue Angel Software Suite Exploit Attempts. Maybe CVE-2025-34033 Variant?<br/>
Our honeypots detected attacks that appear to exploit CVE-2025-34033 or a similar vulnerability in the Blue Angle Software Suite.<br/>
<a href="https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410">https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410</a><br/>
Oracle Critical Patch Update<br/>
Oracle released its quarterly critical patch update. The update includes patches for 374 vulnerabilities across all of Oracle s products. There are nine more patches for Oracle s e-Business Suite.<br/>
<a href="https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS">https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS</a><br/>
Rust TAR Library Vulnerability<br/>
A vulnerability in the popular, but no longer maintained, async-tar vulnerability could lead to arbitrary code execution<br/>
<a href="https://edera.dev/stories/tarmageddon">https://edera.dev/stories/tarmageddon</a><br/>
]]></description>
<itunes:duration>7:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9668" type="text/plain" language="en" />
<itunes:keywords>tar, rust, webctrl, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, October 22nd, 2025: NTP Pool; Xubuntu Compromise; Squid Vulnerability; Lanscope Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9666</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, October 22nd, 2025: NTP Pool; Xubuntu Compromise; Squid Vulnerability; Lanscope Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, October 22nd, 2025: NTP Pool; Xubuntu Compromise; Squid Vulnerability; Lanscope Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9666.mp3" length="5558452" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9666.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9666</link>
<pubDate>Wed, 22 Oct 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
What time is it? Accuracy of pool.ntp.org.<br/>
How accurate and reliable is pool.ntp.org? Turns out it is very good!<br/>
<a href="https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390">https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390</a><br/>
Xubuntu Compromise<br/>
The Xubuntu website was compromised last weekend and served malware<br/>
<a href="https://floss.social/@bluesabre/115401767635718361">https://floss.social/@bluesabre/115401767635718361</a><br/>
Squid Proxy Vulnerability<br/>
The Squid team fixed an information disclosure vulnerabilty that may leak authentication credentials.<br/>
<a href="https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr">https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr</a><br/>
Lanscope Endpoint Manager Vulnerablity<br/>
<a href="https://jvn.jp/en/jp/JVN86318557/index.html">https://jvn.jp/en/jp/JVN86318557/index.html</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9666" type="text/plain" language="en" />
<itunes:keywords>squid, xubuntu, time, ntp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, October 21st, 2025: Syscall() Obfuscation; AWS down; Beijing Time Attack
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9664</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, October 21st, 2025: Syscall() Obfuscation; AWS down; Beijing Time Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, October 21st, 2025: Syscall() Obfuscation; AWS down; Beijing Time Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9664.mp3" length="7800716" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9664.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9664</link>
<pubDate>Mon, 20 Oct 2025 22:45:23 GMT</pubDate>
<description><![CDATA[<br/>
Using Syscall() for Obfuscation/Fileless Activity<br/>
Fileless malware written in Python can uses syscall() to create file descriptors in memory, evading signatures.<br/>
<a href="https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384">https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384</a><br/>
AWS Outages<br/>
AWS has had issues most of the day on Monday, affecting numerous services.<br/>
<a href="https://health.aws.amazon.com/health/status">https://health.aws.amazon.com/health/status</a><br/>
Time Server Hack<br/>
China reports a compromise of its time standard servers. <br/>
<a href="https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html">https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html</a><br/>
]]></description>
<itunes:duration>9:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9664" type="text/plain" language="en" />
<itunes:keywords>ntp, time, china, aws, outage, syscall, python, obfuscation, malware, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, October 20th, 2025: Malicious Tiktok; More Google Ad Problems; Satellite Insecurity
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9662</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, October 20th, 2025: Malicious Tiktok; More Google Ad Problems; Satellite Insecurity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, October 20th, 2025: Malicious Tiktok; More Google Ad Problems; Satellite Insecurity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9662.mp3" length="5241626" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9662.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9662</link>
<pubDate>Sun, 19 Oct 2025 19:45:21 GMT</pubDate>
<description><![CDATA[<br/>
TikTok Videos Promoting Malware InstallationTikTok Videos Promoting Malware Installation<br/>
Tiktok videos advertising ways to obtain software like Photoshop for free will instead trick users into downloading <br/>
<a href="https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380">https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380</a><br/>
Google Ads Advertise Malware Targeting MacOS Developers<br/>
Hunt.io discovered Google ads that pretend to advertise tools like Homebrew and password managers to spread malware<br/>
<a href="https://hunt.io/blog/macos-odyssey-amos-malware-campaign">https://hunt.io/blog/macos-odyssey-amos-malware-campaign</a><br/>
Satellite Transmissions are often unencrypted<br/>
A large amount of satellite traffic is unencrypted and easily accessible to eavesdropping<br/>
<a href="https://satcom.sysnet.ucsd.edu">https://satcom.sysnet.ucsd.edu</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9662" type="text/plain" language="en" />
<itunes:keywords>google, ads, malware, tiktop, satellite, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, October 17th, 2025: New Slack Workspace; Cisco SNMP Exploited; BIOS Backdoor; @sans_edu reseach: Active Defense
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9660</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, October 17th, 2025: New Slack Workspace; Cisco SNMP Exploited; BIOS Backdoor; @sans_edu research: Active Defense</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, October 17th, 2025: New Slack Workspace; Cisco SNMP Exploited; BIOS Backdoor; @sans_edu research: Active Defense</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9660.mp3" length="18038572" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9660.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9660</link>
<pubDate>Fri, 17 Oct 2025 01:45:06 GMT</pubDate>
<description><![CDATA[New DShield Support Slack Workspace<br/>
Due to an error on Salesforce s side, we had to create a new Slack Workspace for DShield support.<br/>
<a href="https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376">https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376</a><br/>
Attackers Exploiting Recently Patched Cisco SNMP Flaw (CVE-2025-20352)<br/>
 Trend Micro published details explaining how attackers took advantage of a recently patched Cisco SNMP Vulnerability<br/>
<a href="https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html">https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html</a><br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte</a><br/>
Framework BIOS Backdoor<br/>
The mm command implemented in Framework BIOS shells can be used to compromise a device pre-boot.<br/>
<a href="https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/">https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/</a><br/>
SANS.edu Research:  Mark Stephens, Validating the Effectiveness of MITRE Engage and Active Defense<br/>
<a href="https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/">https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/</a><br/>
]]></description>
<itunes:duration>21:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9660" type="text/plain" language="en" />
<itunes:keywords>@sans_edu, active defenense, mitre, engage, framework, bios, snmp, cisco, slack, salesforce, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, October 16th, 2025: Clipboard Image Stealer; F5 Compromise; Adobe Updates; SAP Patchday
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9658</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, October 16th, 2025: Clipboard Image Stealer; F5 Compromise; Adobe Updates; SAP Patchday
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, October 16th, 2025: Clipboard Image Stealer; F5 Compromise; Adobe Updates; SAP Patchday
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9658.mp3" length="7284558" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9658.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9658</link>
<pubDate>Wed, 15 Oct 2025 20:45:21 GMT</pubDate>
<description><![CDATA[Clipboard Image Stealer<br/>
Xavier presents an infostealer in Python that steals images from the clipboard.<br/>
<a href="https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372">https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372</a><br/>
F5 Compromise<br/>
F5 announced a wide-ranging compromise today. Source code and information about unpatched vulnerabilities were stolen.<br/>
<a href="https://my.f5.com/manage/s/article/K000157005">https://my.f5.com/manage/s/article/K000157005</a> <br/>
<a href="https://my.f5.com/manage/s/article/K000156572">https://my.f5.com/manage/s/article/K000156572</a> <br/>
<a href="https://my.f5.com/manage/s/article/K000154696">https://my.f5.com/manage/s/article/K000154696</a><br/>
Adobe Updates<br/>
Adobe updated 12 different products yesterday. <br/>
<a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
SAP Patchday<br/>
Among the critical vulnerabilities patched in SAP s products are two deserialization vulnerabilities with a CVSS score of 10.0<br/>
<a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html">https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html</a><br/>
<a href="https://onapsis.com/blog/sap-security-patch-day-october-2025/">https://onapsis.com/blog/sap-security-patch-day-october-2025/</a><br/>
]]></description>
<itunes:duration>8:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9658" type="text/plain" language="en" />
<itunes:keywords>adobe, f5, nginx, breach, clipboard, stealer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, October 15th, 2025: Microsoft Patchday; Ivanti Advisory; Fortinet Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9656</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, October 15th, 2025: Microsoft Patchday; Ivanti Advisory; Fortinet Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, October 15th, 2025: Microsoft Patchday; Ivanti Advisory; Fortinet Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9656.mp3" length="5350630" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9656.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9656</link>
<pubDate>Tue, 14 Oct 2025 23:45:28 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
Microsoft not only released new patches, but also the last patches for Windows 10, Office 2016, Office 2019, Exchange 2016 and Exchange 2019.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368</a><br/>
Ivanti Advisory<br/>
Ivanti released an advisory with some mitigation steps users can take until the recently made public vulnerablities are patched.<br/>
<a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US</a><br/>
Fortinet Patches<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-010">https://fortiguard.fortinet.com/psirt/FG-IR-25-010</a><br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-361">https://fortiguard.fortinet.com/psirt/FG-IR-24-361</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9656" type="text/plain" language="en" />
<itunes:keywords>ivanti, microsoft, patches, fortinet, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, October 14th, 2025: ESAFENET Scans; Payroll Priates; MSFT Edge IE Mode
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9654</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, October 14th, 2025: ESAFENET Scans; Payroll Priates; MSFT Edge IE Mode
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, October 14th, 2025: ESAFENET Scans; Payroll Priates; MSFT Edge IE Mode
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9654.mp3" length="5080454" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9654.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9654</link>
<pubDate>Mon, 13 Oct 2025 22:45:46 GMT</pubDate>
<description><![CDATA[<br/>
Scans for ESAFENET CDG V5<br/>
We do see some increase in scans for the Chinese secure document management system, ESAFENET.<br/>
<a href="https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364">https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364</a><br/>
Investigating targeted  payroll pirate  attacks affecting US universities<br/>
Microsoft wrote about how payroll pirates redirect employee paychecks via phishing.<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/">https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/</a><br/>
Attacks against Edge via IE Mode<br/>
Microsoft Edge offers an IE legacy mode to support websites created for Internet Explorer. The old JavaScript engine, which is part of this mode, has been abused in recent attacks, and Microsoft will make it more difficult to enable IE Mode to counter these attacks.<br/>
<a href="https://microsoftedge.github.io/edgevr/posts/Changes-to-Internet-Explorer-Mode-in-Microsoft-Edge/">https://microsoftedge.github.io/edgevr/posts/Changes-to-Internet-Explorer-Mode-in-Microsoft-Edge/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9654" type="text/plain" language="en" />
<itunes:keywords>microsoft, ie, internet explorer, edge, javascript, payroll, pirates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, October 13th, 2025: More Oracle Patches; Sonicwall Compromisses; Unpatched Gladinet; 7-Zip Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9652</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, October 13th, 2025: More Oracle Patches; Sonicwall Compromisses; Unpatched Gladinet; 7-Zip Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, October 13th, 2025: More Oracle Patches; Sonicwall Compromisses; Unpatched Gladinet; 7-Zip Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9652.mp3" length="4986057" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9652.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9652</link>
<pubDate>Sun, 12 Oct 2025 21:45:20 GMT</pubDate>
<description><![CDATA[<br/>
New Oracle E-Business Suite Patches<br/>
Oracle released one more patch for the e-business suite. Oracle does not state if it is already exploited, but the timing of the patch suggests that it should be expedited.<br/>
<a href="https://www.oracle.com/security-alerts/alert-cve-2025-61884.html">https://www.oracle.com/security-alerts/alert-cve-2025-61884.html</a><br/>
Widespread Sonicwall SSLVPN Compromise<br/>
Huntress Labs observed the widespread compromise of the Sonicwall SSLVPN appliance.<br/>
<a href="https://www.huntress.com/blog/sonicwall-sslvpn-compromise">https://www.huntress.com/blog/sonicwall-sslvpn-compromise</a><br/>
Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371)<br/>
An unpatched vulnerability in the  secure  file sharing solutions Gladinet CentreStack and TrioFox is being exploited.<br/>
<a href="https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw">https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw</a><br/>
Two 7-Zip Vulnerabilities CVE-2025-11002, CVE-2025-11001<br/>
7-Zip patched two vulnerabilities that may lead to arbitrary code execution<br/>
<a href="https://www.zerodayinitiative.com/advisories/ZDI-25-949/">https://www.zerodayinitiative.com/advisories/ZDI-25-949/</a><br/>
<a href="https://www.zerodayinitiative.com/advisories/ZDI-25-950/">https://www.zerodayinitiative.com/advisories/ZDI-25-950/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9652" type="text/plain" language="en" />
<itunes:keywords>7zip, gladinet, cntrestack, triofox, sonicwall, oracle, ebusiness, suite, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, October 10th, 2025:  RedTail Defenses; SonicWall Breach; Crowdstrike “Issues”; Ivanti 0-days; Mapping Agentic Attack Surface (@sans_edu paper)</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9650</itunes:episode>
<itunes:subtitle></itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9650.mp3" length="12779396" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9650.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9650</link>
<pubDate>Fri, 10 Oct 2025 00:45:06 GMT</pubDate>
<description><![CDATA[Building Better Defenses: RedTail Observations<br/>
Defending against attacks like RedTail is more then blocking IoCs, but instead one must focus on the techniques and tactics attackers use.<br/>
<a href="https://isc.sans.edu/diary/Guest+Diary+Building+Better+Defenses+RedTail+Observations+from+a+Honeypot/32312">https://isc.sans.edu/diary/Guest+Diary+Building+Better+Defenses+RedTail+Observations+from+a+Honeypot/32312</a><br/>
Sonicwall: It wasn t the user s fault<br/>
Sonicwall admits to a breach resulting in the loss of user configurations stored in its cloud service<br/>
<a href="https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330">https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330</a><br/>
Crowdstrike has Issues<br/>
Crowdstrike fixes two vulnerabilities in the Windows version of its Falcon sensor.<br/>
<a href="https://www.crowdstrike.com/en-us/security-advisories/issues-affecting-crowdstrike-falcon-sensor-for-windows/">https://www.crowdstrike.com/en-us/security-advisories/issues-affecting-crowdstrike-falcon-sensor-for-windows/</a><br/>
Interrogators: Attack Surface Mapping in an Agentic World<br/>
A SANS.edu master s degree student research paper by Michael Samson<br/>
<a href="https://isc.sans.edu/researchpapers/pdfs/michael_samson.pdf">https://isc.sans.edu/researchpapers/pdfs/michael_samson.pdf</a><br/>
keywords: ai; agentic; attack surface; crowdstrike; sonicwall; ivanti; zero day; initiative; redline]]></description>
<itunes:duration>15:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9650" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, October 9th, 2025: Polymorphic Python; ssh ProxyCommand Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9648</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, October 9th, 2025: Polymorphic Python; ssh ProxyCommand Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, October 9th, 2025: Polymorphic Python; ssh ProxyCommand Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9648.mp3" length="5210672" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9648.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9648</link>
<pubDate>Thu, 09 Oct 2025 03:10:14 GMT</pubDate>
<description><![CDATA[<br/>
Polymorphic Python Malware<br/>
Xavier discovered self-modifying Python code on Virustotal. The remote access tool takes advantage of the inspect module to modify code on the fly.<br/>
<a href="https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354">https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354</a><br/>
SSH ProxyCommand Vulnerability<br/>
A user cloning a git repository may be tricked into executing arbitrary code via the SSH proxycommand option.<br/>
<a href="https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984">https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984</a><br/>
Framelink Figma MCP Server CVE-2025-53967<br/>
Framelink Figma s MCP server suffers from a remote code execution vulnerability. <br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9648" type="text/plain" language="en" />
<itunes:keywords>polymorphic, python, git, ssh, proxycommand, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, October 8th, 2025: FreePBX Exploits; Disrupting Teams Threats; Kibana and QT SVG Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9646</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, October 8th, 2025: FreePBX Exploits; Disrupting Teams Threats; Kibana and QT SVG Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, October 8th, 2025: FreePBX Exploits; Disrupting Teams Threats; Kibana and QT SVG Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9646.mp3" length="4997540" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9646.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9646</link>
<pubDate>Wed, 08 Oct 2025 03:25:14 GMT</pubDate>
<description><![CDATA[<br/>
FreePBX Exploit Attempts (CVE-2025-57819)<br/>
A FreePBX SQL injection vulnerability disclosed in August is being used to execute code on affected systems.<br/>
<a href="https://isc.sans.edu/diary/Exploit%20Against%20FreePBX%20%28CVE-2025-57819%29%20with%20code%20execution./32350">https://isc.sans.edu/diary/Exploit%20Against%20FreePBX%20%28CVE-2025-57819%29%20with%20code%20execution./32350</a><br/>
Disrupting Threats Targeting Microsoft Teams<br/>
Microsoft published a blog post outlining how to better secure Teams.<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/">https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/</a><br/>
Kibana XSS Patch CVE-2025-25009<br/>
Elastic patched a stored XSS vulnerability in Kibana<br/>
<a href="https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449">https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449</a><br/>
QT SVG Vulnerabilities CVE-2025-10728, CVE-2025-10729,<br/>
The QT group fixed two vulnerabilities in the QT SVG module. One of the vulnerabilities may be used for code execution<br/>
<a href="https://www.qt.io/blog/security-advisory-uncontrolled-recursion-and-use-after-free-vulnerabilities-in-qt-svg-module-impact-qt">https://www.qt.io/blog/security-advisory-uncontrolled-recursion-and-use-after-free-vulnerabilities-in-qt-svg-module-impact-qt</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9646" type="text/plain" language="en" />
<itunes:keywords>kibana, elastic, xss, microsoft, teams, freepbx, sql injection, svg, qt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, October 7th, 2025: More About Oracle; Redis Vulnerability; GoAnywhere Exploited
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9644</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, October 7th, 2025: More About Oracle; Redis Vulnerability; GoAnywhere Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, October 7th, 2025: More About Oracle; Redis Vulnerability; GoAnywhere Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9644.mp3" length="4674024" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9644.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9644</link>
<pubDate>Tue, 07 Oct 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
More Details About Oracle 0-Day<br/>
The exploit is now widely distributed and has been analyzed to show the nature of the underlying vulnerabilities.<br/>
<a href="https://isc.sans.edu/diary/Quick%20and%20Dirty%20Analysis%20of%20Possible%20Oracle%20E-Business%20Suite%20Exploit%20Script%20%28CVE-2025-61882%29%20%5BUPDATED%5B/32346">https://isc.sans.edu/diary/Quick%20and%20Dirty%20Analysis%20of%20Possible%20Oracle%20E-Business%20Suite%20Exploit%20Script%20%28CVE-2025-61882%29%20%5BUPDATED%5B/32346</a><br/>
<a href="https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/">https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/</a><br/>
 Redis Vulnerability<br/>
Redis patched a ciritcal use after free vulnerability that could lead to arbitrary code execution.<br/>
<a href="https://redis.io/blog/security-advisory-cve-2025-49844/">https://redis.io/blog/security-advisory-cve-2025-49844/</a><br/>
GoAnywhere Bug Exploited<br/>
Microsoft is reporting about the exploitation of the recent GoAnywhere vulnerability<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/">https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9644" type="text/plain" language="en" />
<itunes:keywords>goanywhere, redis, oracle, ebusiness suite, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, October 6th, 2025: Oracle 0-Day
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9642</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, October 6th, 2025: Oracle 0-Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, October 6th, 2025: Oracle 0-Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9642.mp3" length="5440818" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9642.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9642</link>
<pubDate>Mon, 06 Oct 2025 02:45:14 GMT</pubDate>
<description><![CDATA[Oracle E-Business Suite 0-Day CVE-2025-61882<br/>
Last week, the Cl0p ransomware gang sent messages to many businesses stating that an Oracle E-Business Suite vulnerability was used to exfiltrate data. Initially, Oracle believed the root cause to be a vulnerability patched in June, but now Oracle released a patch for a new vulnerability.<br/>
<a href="https://www.oracle.com/security-alerts/alert-cve-2025-61882.html">https://www.oracle.com/security-alerts/alert-cve-2025-61882.html</a><br/>
Zimbra Exploit Analysis<br/>
An exploit against a Zimbra system prior to the patch release is analyzed. These exploits take advantage of .ics files to breach vulnerable systems.<br/>
<a href="https://strikeready.com/blog/0day-ics-attack-in-the-wild/">https://strikeready.com/blog/0day-ics-attack-in-the-wild/</a><br/>
Unity Editor Vulnerability CVE-2025-59489<br/>
The Unity game editor suffered from a code execution vulnerablity that would also expose software developed with vulnerable versions<br/>
<a href="https://unity.com/security/sept-2025-01">https://unity.com/security/sept-2025-01</a>]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9642" type="text/plain" language="en" />
<itunes:keywords>oracle, cl0p, e-business suite, unity, zimbra, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, October 3rd, 2025: More .well-known Scans; RedHat Openshift Patch; TOTOLINK Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9640</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, October 3rd, 2025: More .well-known Scans; RedHat Openshift Patch; TOTOLINK Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, October 3rd, 2025: More .well-known Scans; RedHat Openshift Patch; TOTOLINK Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9640.mp3" length="5530397" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9640.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9640</link>
<pubDate>Fri, 03 Oct 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
More .well-known scans<br/>
Attackers are using API documentation automatically published in the .well-known directory for reconnaissance. <br/>
<a href="https://isc.sans.edu/diary/More%20.well-known%20Scans/32340">https://isc.sans.edu/diary/More%20.well-known%20Scans/32340</a><br/>
RedHat Patches Openshift AI Services<br/>
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example, as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator. <br/>
<a href="https://access.redhat.com/security/cve/cve-2025-10725#cve-affected-packages">https://access.redhat.com/security/cve/cve-2025-10725#cve-affected-packages</a><br/>
TOTOLINK X6000R Vulnerabilities<br/>
Paloalto released details regarding three recently patched vulnerabilities in TotalLink-X6000R routers.<br/>
<a href="https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/">https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/</a><br/>
DrayOS Vulnerability Patched<br/>
Draytek fixed a single memory corruption vulnerability in its Vigor series router. An unauthenticated user may use it to execute arbitrary code.<br/>
<a href="https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities">https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9640" type="text/plain" language="en" />
<itunes:keywords>.well-known, redhat, openshift, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, October 2nd, 2025: Honeypot Passwords; OneLogin Vuln; Breaking Intel SGX; OpenSSL Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9638</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, October 2nd, 2025: Honeypot Passwords; OneLogin Vuln; Breaking Intel SGX; OpenSSL Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, October 2nd, 2025: Honeypot Passwords; OneLogin Vuln; Breaking Intel SGX; OpenSSL Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9638.mp3" length="6884553" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9638.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9638</link>
<pubDate>Thu, 02 Oct 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Comparing Honeypot Passwords with HIBP<br/>
Most passwords used against our honeypots are also found in the  Have I been pwn3d  list. However, the few percent that are not found tend to be variations of known passwords, extending them to find likely mutations.<br/>
<a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Comparing%20Honeypot%20Passwords%20with%20HIBP/32310">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Comparing%20Honeypot%20Passwords%20with%20HIBP/32310</a><br/>
Breaking Server SGX via DRAM Inspection<br/>
By observing read and write operations to memory, it is possible to derive keys stored in SGX and break the security of systems relying on SGX.<br/>
<a href="https://wiretap.fail/files/wiretap.pdf">https://wiretap.fail/files/wiretap.pdf</a><br/>
OneLogin OIDC Vulnerability<br/>
A vulnerability in OneLogin can be used to read secret application keys<br/>
<a href="https://www.clutch.security/blog/onelogin-many-secrets-clutch-uncovers-vulnerability-exposing-client-credentials">https://www.clutch.security/blog/onelogin-many-secrets-clutch-uncovers-vulnerability-exposing-client-credentials</a><br/>
OpenSSL Patch<br/>
OpenSSL patched three vulnerabilities. One could lead to remote code execution, but the feature is used infrequently, and the exploit is difficult, according to OpenSSL<br/>
]]></description>
<itunes:duration>8:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9638" type="text/plain" language="en" />
<itunes:keywords>openssl, onelogin, sgx, dram, hibp, passwords, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, October 1st, 2025: Cookie Auth Issues; Western Digtial Command Injection; sudo exploited;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9636</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, October 1st, 2025: Cookie Auth Issues; Western Digtial Command Injection; sudo exploited;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, October 1st, 2025: Cookie Auth Issues; Western Digtial Command Injection; sudo exploited;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9636.mp3" length="4341419" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9636.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9636</link>
<pubDate>Wed, 01 Oct 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Sometimes you don t even need to log in<br/>
Applications using simple, predictable cookies to verify a user s identity are still exploited, and relatively recent vulnerabilities are still due to this very basic mistake.<br/>
<a href="https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334">https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334</a><br/>
Western Digital My Cloud Vulnerability<br/>
Western Digital patched a critical vulnerability in its  MyCloud  device.<br/>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30247">https://nvd.nist.gov/vuln/detail/CVE-2025-30247</a><br/>
sudo vulnerability exploited<br/>
A recently patched vulnerability in sudo is now being exploited.<br/>
<a href="https://www.sudo.ws/security/advisories/">https://www.sudo.ws/security/advisories/</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9636" type="text/plain" language="en" />
<itunes:keywords>mycloud, sudo, western digital, cookies, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, September 30th, 2025: Apple Patch; PAN Global Protect Scans; SSL.com signed malware
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9634</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, September 30th, 2025: Apple Patch; PAN Global Protect Scans; SSL.com signed malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, September 30th, 2025: Apple Patch; PAN Global Protect Scans; SSL.com signed malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9634.mp3" length="4288761" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9634.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9634</link>
<pubDate>Tue, 30 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Patches<br/>
Apple released patches for iOS, macOS, and visionOS, fixing a single font parsing vulnerability<br/>
<a href="https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330">https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330</a><br/>
Increase in Scans for Palo Alto Global Protect Vulnerability (CVE-2024-3400).<br/>
Our honeypots detected an increase in scans for a Palo Alto Global Protect vulnerability.<br/>
<a href="https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328">https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328</a><br/>
Nimbus Manticore / Charming Kitten Malware update<br/>
Checkpoint released a report with details regarding a new Nimbus Manticore exploit kit. The malware in this case uses valid SSL.com-issued certificates.<br/>
<a href="https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/">https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9634" type="text/plain" language="en" />
<itunes:keywords>apple, ios, macos, nimus, manticode, charming kitten, ssl.com, pan, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, September 29th, 2025: Convert Timestamps; Cisco Compromises; GitHub Notification Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9632</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, September 29th, 2025: Convert Timestamps; Cisco Compromises; GitHub Notification Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, September 29th, 2025: Convert Timestamps; Cisco Compromises; GitHub Notification Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9632.mp3" length="7225153" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9632.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9632</link>
<pubDate>Mon, 29 Sep 2025 02:05:18 GMT</pubDate>
<description><![CDATA[<br/>
Converting Timestamps in .bash_history<br/>
Unix shells offer the ability to add timestamps to commands in the .bash_history file. This is often done in the form of Unix timestamps. This new tool converts these timestamps into a more readable format.<br/>
<a href="https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324">https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324</a><br/>
Cisco ASA/FRD Compromises<br/>
Exploitation of the vulnerabilities Cisco patched last week may have bone back about a year. Cisco and CISA have released advisories with help identifying affected devices. <br/>
<a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks">https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks</a><br/>
<a href="https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices">https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices</a><br/>
Github Notification Phishing<br/>
Github notifications are used to impersonate YCombinator and trick victims into installing a crypto drainer.<br/>
<a href="https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/">https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/</a><br/>
]]></description>
<itunes:duration>8:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9632" type="text/plain" language="en" />
<itunes:keywords>cisco, timestamp, bash, history, asa, firepower, ftd, github, phishing, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, September 26th, 2025: Webshells in .well-known; Critical Cisco Vulns Exploited; XCSSET Update; GoAnywhere MFT Exploit Details
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9630</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, September 26th, 2025: Webshells in .well-known; Critical Cisco Vulns Exploited; XCSSET Update; GoAnywhere MFT Exploit Details
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, September 26th, 2025: Webshells in .well-known; Critical Cisco Vulns Exploited; XCSSET Update; GoAnywhere MFT Exploit Details
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9630.mp3" length="5774777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9630.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9630</link>
<pubDate>Fri, 26 Sep 2025 04:05:15 GMT</pubDate>
<description><![CDATA[<br/>
Webshells Hiding in .well-known Places<br/>
Our honeypots registered an increase in scans for URLs in the .well-known directory, which appears to be looking for webshells. <br/>
<a href="https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320">https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320</a><br/>
Cisco Patches Critical Exploited Vulnerabilities<br/>
Cisco released updates addressing already-exploited vulnerabilities in the VPN web server for the ASA and FTD appliances.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks">https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks</a><br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB</a><br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW</a><br/>
XCSSET Evolves Again<br/>
Microsoft detected a new XCSSET variant, an infostealer infecting X-Code projects.<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/">https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/</a><br/>
Exploitation of Fortra GoAnywhere MFT CVE-2025-10035<br/>
watchTowr analyzed the latest GoAnywhere MFT vulnerability and exploits used against it.<br/>
<a href="https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/">https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9630" type="text/plain" language="en" />
<itunes:keywords>goanywhere, mft, xcsset, x-code, cisco, asa, ftd, webhsells, .well-known, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, September 25th, 2025: Hikvision Exploits; Cisco Patches; Sonicawall Anit-Rootkit Patch; Windows 10 Support
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9628</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, September 25th, 2025: Hikvision Exploits; Cisco Patches; Sonicawall Anit-Rootkit Patch; Windows 10 Support
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, September 25th, 2025: Hikvision Exploits; Cisco Patches; Sonicawall Anit-Rootkit Patch; Windows 10 Support
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9628.mp3" length="4662410" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9628.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9628</link>
<pubDate>Thu, 25 Sep 2025 03:40:13 GMT</pubDate>
<description><![CDATA[<br/>
Exploit Attempts Against Older Hikvision Camera Vulnerability<br/>
Out honeypots observed an increase in attacks against some older Hikvision issues. A big part of the problem is weak passwords, and the ability to send credentials as part of the URL.<br/>
<a href="https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316">https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316</a><br/>
Cisco Patches Already Exploited SNMP Vulnerability<br/>
Cisco patched a stack-based buffer overflow in the SNMP subsystem. It is already exploited in the wild, but requires<br/>
admin privileges to achieve code execution.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte</a><br/>
SonicWall Anti-Rootkit Update<br/>
SonicWall released a firmware update for its SMA100 devices specifically designed to eradicate a commonly deployed rootkit.<br/>
<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015</a><br/>
Extended Windows 10 Support<br/>
Microsoft will extend free Windows 10 essential support for US and European customers.<br/>
<a href="https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline">https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9628" type="text/plain" language="en" />
<itunes:keywords>windows, support, hikvision, sonicwall, cisco, snmp, rootkit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, September 24th, 2025: DoS against the Analyst; GitHub Improvements; Solarwinds and Supermicro BMC vulnerabilities
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9626</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, September 24th, 2025: DoS against the Analyst; GitHub Improvements; Solarwinds and Supermicro BMC vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, September 24th, 2025: DoS against the Analyst; GitHub Improvements; Solarwinds and Supermicro BMC vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9626.mp3" length="6196580" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9626.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9626</link>
<pubDate>Wed, 24 Sep 2025 03:15:14 GMT</pubDate>
<description><![CDATA[<br/>
Distracting the Analyst for Fun and Profit<br/>
Our undergraduate intern, Tyler House analyzed what may have been a small DoS attack that was likely more meant to distract than to actually cause a denial of service<br/>
<a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308</a><br/>
GitHub s plan for a more secure npm supply chain<br/>
GitHub outlined its plan to harden the supply chain, in particular in light of the recent attack against npm packages<br/>
<a href="https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/">https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/</a><br/>
SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-26399)<br/>
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.<br/>
<a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399">https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399</a><br/>
Vulnerabilities in Supermicro BMC Firmware CVE-2025-7937 CVE-2025-6198<br/>
Supermicro fixed two vulnerabilities that could allow an attacker to compromise the BMC with rogue firmware.<br/>
<a href="https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025">https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025</a><br/>
]]></description>
<itunes:duration>7:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9626" type="text/plain" language="en" />
<itunes:keywords>BMC, supermicro, solarwinds, github, npm, dos, distraction, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9624</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9624.mp3" length="4053898" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9624.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9624</link>
<pubDate>Tue, 23 Sep 2025 03:50:13 GMT</pubDate>
<description><![CDATA[<br/>
CISA Reports Ivanti EPMM Exploit Sightings<br/>
Two different organizations submitted backdoors to CISA, which are believed to have been installed using Ivanti vulnerabilities patched in May.<br/>
<a href="https://www.cisa.gov/news-events/analysis-reports/ar25-261a">https://www.cisa.gov/news-events/analysis-reports/ar25-261a</a><br/>
Lastpass Observes Impersonation on GitHub<br/>
Lastpass noted a number of companies being impersonated via fake GitHub repositories in order to trick victims to download Mac malware.<br/>
<a href="https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages">https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages</a><br/>
Oracle Scheduler Ransomware<br/>
Ransomware has been discovered that gained access to systems via an exposed Oracle Database Scheduler service.<br/>
<a href="https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/">https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/</a><br/>
]]></description>
<itunes:duration>4:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9624" type="text/plain" language="en" />
<itunes:keywords>oracle, lastpass, github, cisa, epmm, ivanti, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, September 22nd, 2025: Odd HTTP Reuqest; GoAnywhere MFT Bug; EDR Freeze
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9622</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, September 22nd, 2025: Odd HTTP Reuqest; GoAnywhere MFT Bug; EDR Freeze
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, September 22nd, 2025: Odd HTTP Reuqest; GoAnywhere MFT Bug; EDR Freeze
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9622.mp3" length="7598662" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9622.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9622</link>
<pubDate>Mon, 22 Sep 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Help Wanted: What are these odd requests about?<br/>
An odd request is hitting a number of our honeypots with a somewhat unusual HTTP request<br/>
header. Please let me know if you no what the request is about.<br/>
<a href="https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/">https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/</a><br/>
Forta GoAnywhere MFT Vulnerability<br/>
Forta s GoAnywhere MFT product suffers from a critical deserialization vulnerability. Forta released<br/>
an advisory disclosing the vulnerability on Thursday.<br/>
<a href="https://www.fortra.com/security/advisories/product-security/fi-2025-012">https://www.fortra.com/security/advisories/product-security/fi-2025-012</a><br/>
EDR Freeze<br/>
A new tool, EDR Freeze, allows regular users to suspend EDR processes.<br/>
<a href="https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html">https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html</a><br/>
]]></description>
<itunes:duration>9:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9622" type="text/plain" language="en" />
<itunes:keywords>EDR, GoAnywhere MFT, Forta, http, proxy, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, September 19th, 2025: Honeypot File Analysis (@sans_edu); SonicWall Breach; DeepSeek Bias; Chrome 0-day
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9620</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, September 19th, 2025: Honeypot File Analysis (@sans_edu); SonicWall Breach; DeepSeek Bias; Chrome 0-day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, September 19th, 2025: Honeypot File Analysis (@sans_edu); SonicWall Breach; DeepSeek Bias; Chrome 0-day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9620.mp3" length="6087952" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9620.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9620</link>
<pubDate>Fri, 19 Sep 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Exploring Uploads in a Dshield Honeypot Environment<br/>
This guest diary by one of our SANS.edu undergraduate interns shows how to analyze files uploaded to Cowrie<br/>
<a href="https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296">https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296</a><br/>
Sonicwall Breach<br/>
SonicWall  MySonicWall  accounts were breached via credential brute forcing<br/>
<a href="https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330">https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330</a><br/>
DeepSeek Bias<br/>
Cloudflare found significant biases in code created by the Chinese AI engine DeepSeek. Code for organizations not aligned with China s politics contained significantly more bugs<br/>
<a href="https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/">https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/</a><br/>
Google Chrome 0-day<br/>
Google fixed an already-exploited vulnerability in Google Chrome<br/>
<a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html">https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html</a><br/>
]]></description>
<itunes:duration>7:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9620" type="text/plain" language="en" />
<itunes:keywords>bugs, ai, deepseek, bias, sonicwall, google, chrome, cowrie, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9618</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9618.mp3" length="5482834" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9618.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9618</link>
<pubDate>Thu, 18 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
CTRL-Z DLL Hooking<br/>
Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries.<br/>
<a href="https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294">https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294</a><br/>
Global Admin in every Entra ID tenant via Actor tokens<br/>
As part of September s patch Tuesday, Microsoft patched CVE-2025-55241. The discoverer of the vulnerability,<br/>
Dirk-jan Mollema has published a blog post showing how this vulnerability could have been exploited.<br/>
<a href="https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/">https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/</a><br/>
WatchGuard  Firebox iked Out of Bounds Write Vulnerability CVE-2025-9242<br/>
WatchGuard patched an out-of-bounds write vulnerability, which could allow an unauthenticated attacker to compromise the devices.<br/>
<a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015</a><br/>
NVidia Triton Inference Server<br/>
 NVIDIA patched critical vulnerabilities in its Triton Inference Server.<br/>
<a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5691">https://nvidia.custhelp.com/app/answers/detail/a_id/5691</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9618" type="text/plain" language="en" />
<itunes:keywords>nvidia, watchguard, triton, entra, azure, tokens, ctrl-z, dll, hooking, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, September 17th, 2025: Phishing Resistants; More npm Attacks; ChatGPT MCP abuse
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9616</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, September 17th, 2025: Phishing Resistants; More npm Attacks; ChatGPT MCP abuse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, September 17th, 2025: Phishing Resistants; More npm Attacks; ChatGPT MCP abuse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9616.mp3" length="7385162" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9616.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9616</link>
<pubDate>Wed, 17 Sep 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Why You Need Phishing-Resistant Authentication NOW.<br/>
The recent compromise of a number of high-profile npmjs.com accounts has yet again shown how dangerous a  simple  phishing email can be.<br/>
<a href="https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290">https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290</a><br/>
S1ngularity/nx Attackers Strike Again<br/>
A second wave of attacks has hit over a hundred npm-related GitHub repositories. The updated payload implements a worm that propagates itself to other repositories.<br/>
<a href="https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again">https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again</a><br/>
ChatGPT s Calendar Integration Can Be Exploited to Steal Emails<br/>
ChatGPT s new MCP integration can be used, via prompt injection, to affect software connected to ChatGPT via MCP.<br/>
<a href="https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/">https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/</a><br/>
]]></description>
<itunes:duration>8:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9616" type="text/plain" language="en" />
<itunes:keywords>chatgpt, openai, prompt injection, mcp, s1ngularity, nx, npm, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, September 16th, 2025: Apple Updates; Rust Phishing; Samsung 0-day
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9614</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, September 16th, 2025: Apple Updates; Rust Phishing; Samsung 0-day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, September 16th, 2025: Apple Updates; Rust Phishing; Samsung 0-day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9614.mp3" length="5639274" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9614.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9614</link>
<pubDate>Tue, 16 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Updates<br/>
Apple released major updates for all of its operating systems. In addition to new features, these updates patch 33 different vulnerabilities.<br/>
<a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286">https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286</a><br/>
Microsoft End of Life<br/>
October 14th, support for Windows 10, Exchange 2016, and Exchange 2019 will end.<br/>
<a href="https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011.">https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011.</a><br/>
<a href="https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605">https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605</a><br/>
Phishing Targeting Rust Developers<br/>
Rust developers are reporting similar phishing emails as the emails causing the major NPM compromise last week.<br/>
<a href="https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064">https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064</a><br/>
Samsung Patches 0-Day<br/>
Samsung released its monthly updates for its flagship phones fixing, among other vulnerability, an already exploited 0-day.<br/>
<a href="https://security.samsungmobile.com/securityUpdate.smsb">https://security.samsungmobile.com/securityUpdate.smsb</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9614" type="text/plain" language="en" />
<itunes:keywords>Samsung, phishing, rust, microsoft, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, September 15th, 2025: More Archives; Salesforce Attacks; White Cobra; BSides Augusta
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9612</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, September 15th, 2025: More Archives; Salesforce Attacks; White Cobra; BSides Augusta
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, September 15th, 2025: More Archives; Salesforce Attacks; White Cobra; BSides Augusta
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9612.mp3" length="5126278" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9612.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9612</link>
<pubDate>Mon, 15 Sep 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Web Searches For Archives<br/>
Didier observed additional file types being searched for as attackers continue to focus on archive files as they spider web pages<br/>
<a href="https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282">https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282</a><br/>
FBI Flash Alert: Salesforce Attacks<br/>
The FBI is alerting users of Salesforce of two different threat actors targeting Salesforce. There are no new vulnerabilities disclosed, but the initial access usually takes advantage of social engineering or leaked data from the Salesdrift compromise.<br/>
<a href="https://www.ic3.gov/CSA/2025/250912.pdf">https://www.ic3.gov/CSA/2025/250912.pdf</a><br/>
VSCode Cursor Extensions Malware<br/>
Koe Security unmasked details about a recent malicious cursor extension campaign they call White Cobra.<br/>
<a href="https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware">https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware</a><br/>
BSides Augusta<br/>
<a href="https://bsidesaugusta.org/">https://bsidesaugusta.org/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9612" type="text/plain" language="en" />
<itunes:keywords>bsides, vscode, cursor, fbi, salesforce, web, search, archive, zip, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, September 12th, 2025: DShield SIEM Update; Another Sonicwall Warning;  Website Keystroke Logging
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9610</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, September 12th, 2025: DShield SIEM Update; Another Sonicwall Warning;  Website Keystroke Logging
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, September 12th, 2025: DShield SIEM Update; Another Sonicwall Warning;  Website Keystroke Logging
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9610.mp3" length="5580805" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9610.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9610</link>
<pubDate>Fri, 12 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
DShield SIEM Docker Updates<br/>
Guy updated the  DShield SIEM  which graphically summarizes what is happening inside your honeypot.<br/>
<a href="https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276">https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276</a><br/>
Again: Sonicwall SSL VPN Compromises<br/>
The Australian Government s Signals Directorate noted an increase in compromised Sonicwall devices. <br/>
<a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia</a><br/>
Website Keystroke Logging<br/>
Many websites log every keystroke, not just data submitted in forms.<br/>
<a href="https://arxiv.org/pdf/2508.19825">https://arxiv.org/pdf/2508.19825</a><br/>
]]></description>
<itunes:duration>6:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9610" type="text/plain" language="en" />
<itunes:keywords>dshield, siem, sonicwall, website, keystroke, logging, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, September 11th, 2025: BASE64 in DNS; Google Chrome, Ivantii and Sophos Patches; Apple Memory Integrity Feature
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9608</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, September 11th, 2025: BASE64 in DNS; Google Chrome, Ivantii and Sophos Patches; Apple Memory Integrity Feature
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, September 11th, 2025: BASE64 in DNS; Google Chrome, Ivantii and Sophos Patches; Apple Memory Integrity Feature
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9608.mp3" length="6054147" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9608.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9608</link>
<pubDate>Thu, 11 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
BASE64 Over DNS<br/>
The base64 character set exceeds what is allowable in DNS. However, some implementations will work even with these  invalid  characters.<br/>
<a href="https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274">https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274</a><br/>
Google Chrome Update<br/>
Google released an update for Google Chrome, addressing two vulnerabilities. One of the vulnerabilities is rated critical and may allow code execution.<br/>
<a href="https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html">https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html</a><br/>
Ivanti Updates<br/>
Ivanti patched a number of vulnerabilities, several of them critical, across its product portfolio.<br/>
<a href="https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs">https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs</a><br/>
Sophos Patches<br/>
Sophos resolved authentication bypass vulnerability in Sophos AP6 series wireless access point firmware (CVE-2025-10159)<br/>
<a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6">https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6</a><br/>
Apple Introduces Memory Integrity Enforcement<br/>
With the new hardware promoted in yesterday s event, Apple also introduced new memory integrity features based on this new hardware.<br/>
<a href="https://security.apple.com/blog/memory-integrity-enforcement/">https://security.apple.com/blog/memory-integrity-enforcement/</a><br/>
]]></description>
<itunes:duration>7:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9608" type="text/plain" language="en" />
<itunes:keywords>apple, memory safe, memory integrity, sophos, ap6, ivanti, patches, updates, google, base64, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, September 10th, 2025: Microsoft Patch Tuesday;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9606</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, September 10th, 2025: Microsoft Patch Tuesday;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, September 10th, 2025: Microsoft Patch Tuesday;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9606.mp3" length="7079764" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9606.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9606</link>
<pubDate>Wed, 10 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
As part of its September patch Tuesday, Microsoft addressed 177 different vulnerabilities, 86 of which affect Microsoft products. None of the vulnerabilities has been exploited before today. Two of the vulnerabilities were already made public. Microsoft rates 13 of the vulnerabilities are critical.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270</a><br/>
Adobe Patches<br/>
Adobe released patches for nine products, including Adobe Commerce, Coldfusion, and Acrobat.<br/>
<a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
SAP Patches<br/>
SAP patched vulnerabilities across its product portfolio. Particularly interesting are a few critical vulnerabilities in Netweaver, one of which scored a perfect 10.0 CVSS score.<br/>
<a href="https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/">https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/</a><br/>
]]></description>
<itunes:duration>8:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9606" type="text/plain" language="en" />
<itunes:keywords>netweaver, sap, adobe, commerce, acrobat, coldfusion, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9604</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9604.mp3" length="7340400" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9604.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9604</link>
<pubDate>Tue, 09 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Major npm compromise<br/>
A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week.<br/>
<a href="https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y">https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y</a> <a href="https://github.com/orgs/community/discussions/172738">https://github.com/orgs/community/discussions/172738</a> <a href="https://github.com/chalk/chalk/issues/656#issuecomment-3266894253">https://github.com/chalk/chalk/issues/656#issuecomment-3266894253</a><br/>
<a href="https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised">https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised</a><br/>
HTTP Request Signatures<br/>
It looks like some search engines and AI bots are starting to use the HTTP request signature. This should make it easier to identify bot traffic.<br/>
<a href="https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266">https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266</a><br/>
]]></description>
<itunes:duration>8:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9604" type="text/plain" language="en" />
<itunes:keywords>http, request, signature, npm, qix, debug, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, September 8th, 2025: YARA to Debugger Offsets; SVG JavaScript Phishing; FreePBX Patches;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9602</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, September 8th, 2025: YARA to Debugger Offsets; SVG JavaScript Phishing; FreePBX Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, September 8th, 2025: YARA to Debugger Offsets; SVG JavaScript Phishing; FreePBX Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9602.mp3" length="4685748" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9602.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9602</link>
<pubDate>Mon, 08 Sep 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
From YARA Offsets to Virtual Addresses<br/>
Xavier explains how to convert offsets reported by YARA into offsets suitable for the use with debuggers.<br/>
<a href="https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262">https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262</a><br/>
Phishing via JavaScript in SVG Files<br/>
Virustotal uncovered a Colombian phishing campaign that takes advantage of JavaScript in SVG files.<br/>
<a href="https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html">https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html</a><br/>
FreePBX Patches<br/>
FreePBX released details regarding two vulnerabilities patched last week. One of these vulnerabilities was already actively exploited.<br/>
<a href="https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf">https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9602" type="text/plain" language="en" />
<itunes:keywords>FreePBX, javascript, svg, yara, offset, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, September 5th, 2025: Cloudflare Response to 1.1.1.1 Certificate; AI Modem Namespace Reuse; macOS Vulnerability Allowed Keychain Decryption
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9600</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, September 5th, 2025: Cloudflare Response to 1.1.1.1 Certificate; AI Modem Namespace Reuse; macOS Vulnerability Allowed Keychain Decryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, September 5th, 2025: Cloudflare Response to 1.1.1.1 Certificate; AI Modem Namespace Reuse; macOS Vulnerability Allowed Keychain Decryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9600.mp3" length="6983556" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9600.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9600</link>
<pubDate>Fri, 05 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Unauthorized Issuance of Certificate for 1.1.1.1<br/>
Cloudflare published a blog post with more details regarding the bad 1.1.1.1 certificate that was issued by Fina.<br/>
<a href="https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/">https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/</a><br/>
AI Model Namespace Reuse<br/>
Deleted accounts on Huggingface can be taken over by other entities unrelated to the original owner.<br/>
<a href="https://unit42.paloaltonetworks.com/model-namespace-reuse/">https://unit42.paloaltonetworks.com/model-namespace-reuse/</a><br/>
macOS vulnerability allowed Keychain and iOS app decryption without a password<br/>
Excessive entitlements for the gcore binary facilitated access to key material that was sufficient to access secrets stored in Apple s keychain.<br/>
<a href="https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/">https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/</a><br/>
]]></description>
<itunes:duration>8:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9600" type="text/plain" language="en" />
<itunes:keywords>keychain, macos, gcore, ai model, namespace, certificate, ca, cloudflare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, September 4th, 2025: Dassault DELMIA Apriso Exploit Attempts; Android Updates; 1.1.1.1 Certificate Issued
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9598</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, September 4th, 2025: Dassault DELMIA Apriso Exploit Attempts; Android Updates; 1.1.1.1 Certificate Issued
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, September 4th, 2025: Dassault DELMIA Apriso Exploit Attempts; Android Updates; 1.1.1.1 Certificate Issued
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9598.mp3" length="5350384" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9598.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9598</link>
<pubDate>Thu, 04 Sep 2025 13:59:15 GMT</pubDate>
<description><![CDATA[<br/>
Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086<br/>
Our honeypots detected attacks against the manufacturing management system DELMIA Apriso. The deserialization vulnerability was patched in June and is one of a few critical vulnerabilities patched in recent months.<br/>
<a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256</a><br/>
Android Bulletin<br/>
Google released its September update, fixing two already-exploited privilege escalation flaws and some remote code execution issues.<br/>
<a href="https://source.android.com/docs/security/bulletin/2025-09-01">https://source.android.com/docs/security/bulletin/2025-09-01</a><br/>
Mis-issued Certificates for SAN iPAddress:1.1.1.1 by Fina RDC 2020<br/>
Certificate authority Fina RDC issues a certificate for Cloudflare s IP address 1.1.1.1<br/>
<a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc">https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9598" type="text/plain" language="en" />
<itunes:keywords>SAN, Certifiate, Fina RDC, fina, android, honeypot, dassault, demia, apriso, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, September 3rd, 2025: Sextortiion Analysis; Covert Channel DNS/ICMP; Azure AD Secret Theft; Official FreePBX Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9596</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, September 3rd, 2025: Sextortiion Analysis; Covert Channel DNS/ICMP; Azure AD Secret Theft; Official FreePBX Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, September 3rd, 2025: Sextortiion Analysis; Covert Channel DNS/ICMP; Azure AD Secret Theft; Official FreePBX Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9596.mp3" length="4619454" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9596.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9596</link>
<pubDate>Wed, 03 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
A Quick Look at Sextortion at Scale<br/>
Jan analyzed 1900 different sextortion messages using 205 different Bitcoin addresses to look at the success rate, lifetime, and other metrics defining these campaigns.<br/>
<a href="https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252">https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252</a><br/>
Azure AD Client Secret Leak<br/>
Attackers are stealing Azure AD client secrets from websites that are leaving them exposed.<br/>
<a href="https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud">https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud</a><br/>
Covert Channel via ICMP and DNS<br/>
A new bot combines ICMP and DNS in new ways for covert communication. The DNS requests use domains with a fixed prefix followed by a base64 encoded command, and the ICMP echo request packets include commands as a payload.<br/>
<a href="https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/">https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/</a><br/>
Official Release of Critical FreePBX Patch<br/>
Sangoma has announced that the experimental patch released for the exploited FreePBX vulnerability is now considered stable, and users should update to apply it.<br/>
<a href="https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203">https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9596" type="text/plain" language="en" />
<itunes:keywords>freepbx, icmp, dns, azure, secrets, ad, azure ad, sextortion, bitcoin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, September 2nd, 2025: pdf-parser Patch; Salesloft Compromise; Velociraptor Abuse; NeuVector Default Password
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9594</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, September 2nd, 2025: pdf-parser Patch; Salesloft Compromise; Velociraptor Abuse; NeuVector Default Password
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, September 2nd, 2025: pdf-parser Patch; Salesloft Compromise; Velociraptor Abuse; NeuVector Default Password
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9594.mp3" length="4750545" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9594.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9594</link>
<pubDate>Tue, 02 Sep 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
pdf-parser: All Streams<br/>
Didier released a new version of pdf-parser.py. This version fixes a problem with dumping all filtered streams.<br/>
<a href="https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248">https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248</a><br/>
Salesloft Drift Putting OAuth Tokens at Risk<br/>
OAuth tokens used by Salesloft Drift users to provide access to integrations with Salesforce, Google Workspace, and others have been compromised and heavily abused for additional compromise and large-scale data exfiltration from exposed services.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift">https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift</a><br/>
Velociraptor incident response tool abused for remote access<br/>
Attackers are using the open source incident response tool Velociraptor to access remote systems in breached networks. Tools like Velocitraptor are ideal for attackers to perform lateral movement. <br/>
<a href="https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/">https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/</a><br/>
Default Password in NeuVector (Rancher Desktop)<br/>
SuSE fixed a default password vulnerability in NeuVector, a security tool included in Rancher Desktop.<br/>
<a href="https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56">https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9594" type="text/plain" language="en" />
<itunes:keywords>velociraptor, salesloft, pdf, pdf-parser, neuvector, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, August 29th, 2025: Scans for ZIP Files; FreePBX 0-Day; Passwordstate Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9592</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, August 29th, 2025: Scans for ZIP Files; FreePBX 0-Day; Passwordstate Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, August 29th, 2025: Scans for ZIP Files; FreePBX 0-Day; Passwordstate Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9592.mp3" length="4837960" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9592.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9592</link>
<pubDate>Fri, 29 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Increasing Searches for ZIP Files<br/>
Attackers are scanning our honeypots more and more for .zip files. They are looking for backups of credential files and the like left behind by careless administrators and developers.<br/>
<a href="https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242">https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242</a><br/>
FreePBX Vulnerability<br/>
An upatched vulnerability in FreePBX is currently being exploited. FreePBX offers mitigation advice and has also just released a  beta  patch.<br/>
<a href="https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203">https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203</a><br/>
Passwordstate Vulnerability<br/>
Clickstudios patched an authentication bypass vulnerability in its password manager, Passwordstate. The vulnerability can be used to access the emergency password page.<br/>
<a href="https://www.clickstudios.com.au/passwordstate-changelog.aspx">https://www.clickstudios.com.au/passwordstate-changelog.aspx</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9592" type="text/plain" language="en" />
<itunes:keywords>clickstudio, passwordstate, freepbx, zip, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, August 28th, 2025: Launching Shellcode; NX Compromise; Volt Typhoon Report
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9590</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, August 28th, 2025: Launching Shellcode; NX Compromise; Volt Typhoon Report
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, August 28th, 2025: Launching Shellcode; NX Compromise; Volt Typhoon Report
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9590.mp3" length="5589103" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9590.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9590</link>
<pubDate>Thu, 28 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Interesting Technique to Launch a Shellcode<br/>
Xavier came across malware that PowerShell and the CallWindowProcA() API to launch code.<br/>
<a href="https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238">https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238</a><br/>
NX Compromised to Steal Wallets and Credentials<br/>
The popular open source NX build package was compromised. Code was added that uses the help of AI tools like Claude and Gemini to steal credentials from affected systems<br/>
<a href="https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/">https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/</a><br/>
Countering Chinese State-Sponsored Actors  Compromise of Networks Worldwide to Feed the Global Espionage System<br/>
Several law enforcement and cybersecurity agencies worldwide collaborated to release a detailed report on the recent Volt Typhoon incident.<br/>
<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9590" type="text/plain" language="en" />
<itunes:keywords>cisa, volt typhoon, cisco, nx, credentials, supply chain, shellcode, callwindowproca, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, August 27th, 2025: Analyzing IDNs; Netscaler 0-Day Vuln; Git Vuln Exploited; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9588</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, August 27th, 2025: Analyzing IDNs; Netscaler 0-Day Vuln; Git Vuln Exploited; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, August 27th, 2025: Analyzing IDNs; Netscaler 0-Day Vuln; Git Vuln Exploited; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9588.mp3" length="4801552" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9588.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9588</link>
<pubDate>Wed, 27 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Getting a Better Handle on International Domain Names and Punycode<br/>
International Domain names can be used for phishing and other attacks. One way to identify suspect names is to look for mixed script use.<br/>
<a href="https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234">https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234</a><br/>
Citrix Netscaler Vulnerabilities CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424<br/>
Citrix patched three vulnerabilities in Netscaler. One is already being exploited<br/>
<a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424</a><br/>
git vulnerability exploited (CVE-2025-48384)<br/>
A git vulnerability patched in early July is now being exploited<br/>
<a href="https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9">https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9588" type="text/plain" language="en" />
<itunes:keywords>git, citrix, idn, punycode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, August 26th, 2025: Decoding Word Reading Location; Image Downscaling AI Vulnerability; IBM Jazz Team Server Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9586</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, August 26th, 2025: Decoding Word Reading Location; Image Downscaling AI Vulnerability; IBM Jazz Team Server Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, August 26th, 2025: Decoding Word Reading Location; Image Downscaling AI Vulnerability; IBM Jazz Team Server Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9586.mp3" length="4218945" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9586.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9586</link>
<pubDate>Tue, 26 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Reading Location Position Value in Microsoft Word Documents<br/>
Jessy investigated how Word documents store the last visited document location in the registry.<br/>
<a href="https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224">https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224</a><br/>
Weaponizing image scaling against production AI systems<br/>
AI systems often downscale images before processing them. An attacker can create a harmless looking image that would reveal text after downscaling leading to prompt injection<br/>
<a href="https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/">https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/</a><br/>
IBM Jazz Team Server Vulnerability  CVE-2025-36157<br/>
IBM patched a critical vulnerability in its Jazz Team Server<br/>
<a href="https://www.ibm.com/support/pages/node/7242925">https://www.ibm.com/support/pages/node/7242925</a><br/>
]]></description>
<itunes:duration>5:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9586" type="text/plain" language="en" />
<itunes:keywords>IBM, Jazz, Team, downscaling, images, AI, prompt, word, location, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, August 25th, 2025: IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9584</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, August 25th, 2025: IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, August 25th, 2025: IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9584.mp3" length="5098274" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9584.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9584</link>
<pubDate>Mon, 25 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
The end of an era: Properly formatted IP addresses in all of our data.<br/>
When initiall designing DShield, addresses were  zero padded , an unfortunate choice. As of this week, datafeeds should no longer be  zero padded .<br/>
<a href="https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228">https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228</a><br/>
.desktop files used in an attack against Linux Desktops<br/>
Pakistani attackers are using .desktop files to target Indian Linux desktops.<br/>
<a href="https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/">https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/</a><br/>
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram<br/>
A go module advertising its ability to quickly brute force passwords against random IP addresses, has been used to exfiltrate credentials from the person running the module.<br/>
<a href="https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials">https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials</a><br/>
Limiting Onmicrosoft Domain Usage for Sending Emails<br/>
Microsoft is limiting how many emails can be sent by Microsoft 365 users using the  onmicrosoft.com  domain.<br/>
<a href="https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167">https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9584" type="text/plain" language="en" />
<itunes:keywords>onmicrosoft, go, ssh, brute forcer, desktop, BOSS, linux, ip addresses, padding, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, August 22nd, 2025: The -n switch; Commvault Exploit; Docker Desktop Escape Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9582</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, August 22nd, 2025: The -n switch; Commvault Exploit; Docker Desktop Escape Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, August 22nd, 2025: The -n switch; Commvault Exploit; Docker Desktop Escape Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9582.mp3" length="5772657" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9582.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9582</link>
<pubDate>Fri, 22 Aug 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Don't Forget The "-n" Command Line Switch<br/>
Disabling reverse DNS lookups for IP addresses is important not just for performance, but also for opsec. Xavier is explaining some of the risks.<br/>
<a href="https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220">https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220</a><br/>
watchTowr releases details about recent Commvault flaws<br/>
Users of the Commvault enterprise backup solution must patch now after watchTowr released details about recent vulnerabilities<br/>
<a href="https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123">https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123</a><br/>
Docker Desktop Vulnerability CVE-2025-9074 <br/>
A vulnerability in Docker Desktop allows attackers to escape from containers to attack the host.<br/>
<a href="https://docs.docker.com/desktop/release-notes/#4443">https://docs.docker.com/desktop/release-notes/#4443</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9582" type="text/plain" language="en" />
<itunes:keywords>docker, watchTowr, commvault, tcpdump, tshark, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, August 21st, 2025: Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9580</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, August 21st, 2025: Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, August 21st, 2025: Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9580.mp3" length="5773237" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9580.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9580</link>
<pubDate>Thu, 21 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Airtel Router Scans and Mislabeled Usernames<br/>
A quick summary of some odd usernames that show up in our honeypot logs<br/>
<a href="https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216">https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216</a><br/>
Apple Patches 0-Day CVE-2025-43300<br/>
Apple released an update for iOS, iPadOS and MacOS today patching a single, already exploited, vulnerability in ImageIO.<br/>
<a href="https://support.apple.com/en-us/124925">https://support.apple.com/en-us/124925</a><br/>
Microsoft Copilot Audit Logs<br/>
A user retrieving data via copilot obscures the fact that the user may have had access to data in a specific file<br/>
<a href="https://pistachioapp.com/blog/copilot-broke-your-audit-log">https://pistachioapp.com/blog/copilot-broke-your-audit-log</a><br/>
Password Managers Susceptible to Clickjacking<br/>
Many password managers are susceptible to clickjacking, and only few have fixed the problem so far<br/>
<a href="https://marektoth.com/blog/dom-based-extension-clickjacking/">https://marektoth.com/blog/dom-based-extension-clickjacking/</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9580" type="text/plain" language="en" />
<itunes:keywords>password manager, copilot, click jacking, apple, patches, airtel, username, password, ssh, telnet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, August 20th, 2025: Increased Elasticsearch Scans; MSFT Patch Issues
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9578</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, August 20th, 2025: Increased Elasticsearch Scans; MSFT Patch Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, August 20th, 2025: Increased Elasticsearch Scans; MSFT Patch Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9578.mp3" length="5148336" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9578.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9578</link>
<pubDate>Wed, 20 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Increased Elasticsearch Recognizance Scans<br/>
Our honeypots noted an increase in reconnaissance scans for Elasticsearch. In particular, the endpoint /_cluster/settings is hit hard.<br/>
<a href="https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212">https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212</a><br/>
Microsoft Patch Tuesday Issues <br/>
Microsoft noted some issues deploying the most recent patches with WSUS. There are also issues with certain SSDs if larger files are transferred.<br/>
<a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc</a><br/>
<a href="https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot">https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot</a><br/>
SAP Vulnerabilities Exploited CVE-2025-31324, CVE-2025-42999<br/>
Details explaining how to take advantage of two SAP vulnerabilities were made public<br/>
<a href="https://onapsis.com/blog/new-exploit-for-cve-2025-31324/">https://onapsis.com/blog/new-exploit-for-cve-2025-31324/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9578" type="text/plain" language="en" />
<itunes:keywords>SAP, Microsoft, SSD, WSUS, Elasticsearch, scans, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, August 19th, 2025: MFA Bombing; Cisco Firewall Management Vuln; F5 Access for Android Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9576</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, August 19th, 2025: MFA Bombing; Cisco Firewall Management Vuln; F5 Access for Android Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, August 19th, 2025: MFA Bombing; Cisco Firewall Management Vuln; F5 Access for Android Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9576.mp3" length="4350257" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9576.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9576</link>
<pubDate>Tue, 19 Aug 2025 02:15:12 GMT</pubDate>
<description><![CDATA[<br/>
Keeping an Eye on MFA Bombing Attacks<br/>
Attackers will attempt to use authentication fatigue by  bombing  users with MFA authentication requests. Rob is talking in this diary about how to investigate these attacks in a Microsoft ecosystem.<br/>
<a href="https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208">https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208</a><br/>
Critical Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability<br/>
An OS command injection vulnerability may be abused to gain access to the Cisco Secure Firewall Management Center software.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79</a><br/>
F5 Access for Android vulnerability<br/>
An attacker with a network position that allows them to intercept network traffic may be able to read and/or modify data in transit. The attacker would need to intercept vulnerable clients specifically, since other clients would detect the man-in-the-middle (MITM) attack.<br/>
<a href="https://my.f5.com/manage/s/article/K000152049">https://my.f5.com/manage/s/article/K000152049</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9576" type="text/plain" language="en" />
<itunes:keywords>microsoft, mfa, fatique, bombing, F5, Android, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, August 18th, 2025: 5G Attack Framework; Plex Vulnerability; Fortiweb Exploit; Flowise Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9574</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, August 18th, 2025: 5G Attack Framework; Plex Vulnerability; Fortiweb Exploit; Flowise Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, August 18th, 2025: 5G Attack Framework; Plex Vulnerability; Fortiweb Exploit; Flowise Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9574.mp3" length="4805440" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9574.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9574</link>
<pubDate>Mon, 18 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations<br/>
Researchers from the Singapore University of Technology and Design released a new framework, SNI5GECT, to passively sniff and inject traffic into 5G data streams, leading to DoS, downgrade and other attacks.<br/>
<a href="https://isc.sans.edu/diary/SNI5GECT%3A%20Sniffing%20and%20Injecting%205G%20Traffic%20Without%20Rogue%20Base%20Stations/32202">https://isc.sans.edu/diary/SNI5GECT%3A%20Sniffing%20and%20Injecting%205G%20Traffic%20Without%20Rogue%20Base%20Stations/32202</a><br/>
Plex Vulnerability<br/>
Plex patched a vulnerability in the Plex Media Server. Make sure you have updated to at least 1.42.1.<br/>
<a href="https://forums.plex.tv/t/plex-media-server-security-update/928341">https://forums.plex.tv/t/plex-media-server-security-update/928341</a><br/>
FortiWeb Exploit Public<br/>
A security researcher published details about the recent FortiWeb vulnerability, including demonstrating a PoC exploit.<br/>
<a href="https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/">https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/</a><br/>
Flowise OS vulnerability<br/>
<a href="https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/">https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9574" type="text/plain" language="en" />
<itunes:keywords>Flowise, FortiWeb, Plex, SNI5GECT, 5G, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, August 15th, 2025: Analysing Attack with AI; Proxyware via YouTube; Xerox FreeFlow Vuln; Evaluating Zero Trust @SANS_edu
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9572</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, August 15th, 2025: Analysing Attack with AI; Proxyware via YouTube; Xerox FreeFlow Vuln; Evaluating Zero Trust @SANS_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, August 15th, 2025: Analysing Attack with AI; Proxyware via YouTube; Xerox FreeFlow Vuln; Evaluating Zero Trust @SANS_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9572.mp3" length="12771141" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9572.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9572</link>
<pubDate>Fri, 15 Aug 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
AI and Faster Attack Analysis<br/>
A few use cases for LLMs to speed up analysis<br/>
<a href="https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198">https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198</a><br/>
Proxyware Malware Being Distributed on YouTube Video Download Site<br/>
Popular YouTube download sites will attempt to infect users with proxyware.<br/>
<a href="https://asec.ahnlab.com/en/89574/">https://asec.ahnlab.com/en/89574/</a><br/>
Xerox Freeflow Core Vulnerability<br/>
Horizon3.ai discovered XXE Injection (CVE-2025-8355) and Path Traversal (CVE-2025-8356) vulnerabilities in Xerox FreeFlow Core, a print orchestration platform. These vulnerabilities are easily exploitable and enable unauthenticated remote attackers to achieve remote code execution on vulnerable FreeFlow Core instances. <br/>
<a href="https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/">https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/</a><br/>
SANS.edu Research: Darren Carstensen Evaluating Zero Trust Network Access: A Framework for Comparative Security Testing<br/>
Not all Zero Trust Network Access (ZTNA) solutions are created equal, and despite bold marketing claims, many fall short of delivering proper Zero Trust security.<br/>
<a href="https://www.sans.edu/cyber-research/evaluating-zero-trust-network-access-framework-comparative-security-testing/">https://www.sans.edu/cyber-research/evaluating-zero-trust-network-access-framework-comparative-security-testing/</a><br/>
]]></description>
<itunes:duration>15:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9572" type="text/plain" language="en" />
<itunes:keywords>zero trust, xerox, proxyware, youtube, ai, analysis, ztna, sans.edu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, August 14th, 2025: Equation Editor; Kerberos Patch; XZ-Utils Backdoor; ForitSIEM/FortiWeb patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9570</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, August 14th, 2025: Equation Editor; Kerberos Patch; XZ-Utils Backdoor; ForitSIEM/FortiWeb patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, August 14th, 2025: Equation Editor; Kerberos Patch; XZ-Utils Backdoor; ForitSIEM/FortiWeb patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9570.mp3" length="6111186" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9570.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9570</link>
<pubDate>Thu, 14 Aug 2025 02:00:12 GMT</pubDate>
<description><![CDATA[<br/>
CVE-2017-11882 Will Never Die<br/>
The (very) old equation editor vulnerability is still being exploited, as this recent sample analyzed by Xavier shows. The payload of the Excel file attempts to download and execute an infostealer to exfiltrate passwords via email.<br/>
<a href="https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196">https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196</a><br/>
Windows Kerberos Elevation of Privilege Vulnerability<br/>
Yesterday, Microsoft released a patch for a vulnerability that had already been made public. This vulnerability refers to the privilege escalation taking advantage of a path traversal issue in Windows Kerberos affecting Exchange Server in hybrid mode.<br/>
<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779</a><br/>
Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images<br/>
Some old Debian Docker images containing the xz-utils backdoor are still available for download from Docker Hub via the official Debian account.<br/>
<a href="https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images">https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images</a><br/>
FortiSIEM / FortiWeb Vulnerablities<br/>
Fortinet patched already exploited vulnerabilities in FortiWeb and FortiSIEM<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-152">https://fortiguard.fortinet.com/psirt/FG-IR-25-152</a><br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-448">https://fortiguard.fortinet.com/psirt/FG-IR-25-448</a><br/>
]]></description>
<itunes:duration>7:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9570" type="text/plain" language="en" />
<itunes:keywords>fortinet, fortiweb, fortisiem, xz-utils, docker, debian, kerberos, equation editor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, August 13th, 2025: Microsoft Patch Tuesday; libarchive vulnerability upgrade; Adobe Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9568</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, August 13th, 2025: Microsoft Patch Tuesday; libarchive vulnerability upgrade; Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, August 13th, 2025: Microsoft Patch Tuesday; libarchive vulnerability upgrade; Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9568.mp3" length="7493526" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9568.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9568</link>
<pubDate>Wed, 13 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192">https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192</a><br/>
<a href="https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/">https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/</a><br/>
libarchive Vulnerability<br/>
A libarchive vulnerability patched in June was upgraded from a low CVSS score to a critical one. Libarchive is used by compression software across various operating systems, making this a difficult vulnerability to patch<br/>
<a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc">https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc</a><br/>
Adobe Patches<br/>
Adobe released patches for 13 different products. <br/>
<a href="https://helpx.adobe.com/security/Home.html">https://helpx.adobe.com/security/Home.html</a><br/>
]]></description>
<itunes:duration>8:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9568" type="text/plain" language="en" />
<itunes:keywords>adobe, libarchive, microsoft, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, August 12th, 2025: Erlang OTP SSH Exploits (Palo Alto Networks); Winrar Exploits; Netscaler Exploits; OpenSSH Pushing PQ Crypto;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9566</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, August 12th, 2025: Erlang OTP SSH Exploits (Palo Alto Networks); Winrar Exploits; Netscaler Exploits; OpenSSH Pushing PQ Crypto;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, August 12th, 2025: Erlang OTP SSH Exploits (Palo Alto Networks); Winrar Exploits; Netscaler Exploits; OpenSSH Pushing PQ Crypto;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9566.mp3" length="5774621" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9566.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9566</link>
<pubDate>Tue, 12 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Erlang OTP SSH Exploits<br/>
A recently patched and easily exploited vulnerability in Erlang/OTP SSH is being exploited. Palo Alto collected some of the details about this exploit activity that they observed.<br/>
<a href="https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/">https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/</a><br/>
WinRAR Exploited<br/>
WinRAR vulnerabilities are actively being exploited by a number of threat actors. The vulnerability allows for the creation of arbitrary files as the archive is extracted.<br/>
<a href="https://thehackernews.com/2025/08/winrar-zero-day-under-active.html">https://thehackernews.com/2025/08/winrar-zero-day-under-active.html</a><br/>
Citrix Netscaler Exploit Updates<br/>
The Dutch Center for Cyber Security is updating its guidance on recent Citrix Netscaler attacks. Note that the attacks started before a patch became available, and attackers are actively hiding their tracks to make it more difficult to detect a compromise.<br/>
<a href="https://www.ncsc.nl/actueel/nieuws/2025/07/22/casus-citrix-kwetsbaarheid">https://www.ncsc.nl/actueel/nieuws/2025/07/22/casus-citrix-kwetsbaarheid</a> <a href="https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/">https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/</a><br/>
OpenSSH Post Quantum Encryption<br/>
Starting in version 10.1, OpenSSH will warn users if they are using quantum-unsafe algorithms<br/>
<a href="https://www.openssh.com/pq.html">https://www.openssh.com/pq.html</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9566" type="text/plain" language="en" />
<itunes:keywords>citirx, netscaler, openssh, ssh, erlang, otp, winrar, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, August 11th, 2025: Fake Tesla Preorders; Bad USB Cameras; Win-DoS Epidemic
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9564</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, August 11th, 2025: Fake Tesla Preorders; Bad USB Cameras; Win-DoS Epidemic
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, August 11th, 2025: Fake Tesla Preorders; Bad USB Cameras; Win-DoS Epidemic
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9564.mp3" length="5976972" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9564.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9564</link>
<pubDate>Mon, 11 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Google Paid Ads for Fake Tesla Websites<br/>
Someone is setting up fake Tesla lookalike websites that attempt to collect credit card data from unsuspecting users trying to preorder Tesla products.<br/>
<a href="https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186">https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186</a><br/>
Compromising USB Devices for Persistent Stealthy Access<br/>
USB devices, like Linux-based web cams, can be compromised to emulate malicious USB devices like keyboards that inject malicious commands.<br/>
<a href="https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/">https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/</a><br/>
Win-DoS Epidemic: A crash course in abusing RPC for Win-DoS & Win-DDoS<br/>
Internet-exposed DCs can be used in very powerful DoS attacks.<br/>
<a href="https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389">https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389</a><br/>
]]></description>
<itunes:duration>7:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9564" type="text/plain" language="en" />
<itunes:keywords>dos, windows, dc, rpc, ldap, usb, linux, badcam, google, tesla, optimus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, August 8th, 2025:: ASN43350 Mass Scans; HTTP1.1 Must Die; Hyprid Exchange Vuln; Sonicwall Update; SANS.edu Research: OSS Security and Shifting Left
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9562</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, August 8th, 2025:: ASN43350 Mass Scans; HTTP1.1 Must Die; Hyprid Exchange Vuln; Sonicwall Update; SANS.edu Research: OSS Security and Shifting Left
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, August 8th, 2025:: ASN43350 Mass Scans; HTTP1.1 Must Die; Hyprid Exchange Vuln; Sonicwall Update; SANS.edu Research: OSS Security and Shifting Left
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9562.mp3" length="20152665" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9562.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9562</link>
<pubDate>Fri, 08 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Mass Internet Scanning from ASN 43350<br/>
Our undergraduate intern Duncan Woosley wrote up aggressive scans from ASN 43350<br/>
<a href="https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments">https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments</a><br/>
HTTP/1.1 Desync Attacks<br/>
Portswigger released details about new types of HTTP/1.1 desync attacks it uncovered. These attacks are particularly critical for organizations using middleboxes to translate from HTTP/2 to HTTP/1.1<br/>
<a href="https://portswigger.net/research/http1-must-die">https://portswigger.net/research/http1-must-die</a><br/>
Microsoft Warns of Exchange Server Vulnerability<br/>
An attacker with admin access to an Exchange Server in a hybrid configuration can use this vulnerability to gain full domain access. The issue is mitigated by an April hotfix, but was not noted in the release of the April Hotfix.<br/>
<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786</a><br/>
Sonicwall Update<br/>
Sonicwall no longer believes that a new vulnerability was used in recent compromises<br/>
<a href="https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430">https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430</a><br/>
SANS.edu Research: Wellington Rampazo, Shift Left the Awareness and Detection of Developers Using Vulnerable Open-Source Software Components<br/>
<a href="https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/">https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/</a><br/>
]]></description>
<itunes:duration>23:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9562" type="text/plain" language="en" />
<itunes:keywords>http/1.1, http request smuggeling, http/2, asn 43350, exchange, sonicwall, SANS.edu, research, shiftin left, wellington, rampazo, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, August 7th, 2025: Sextortion Update; Adobe and Trend Micro release emergency patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9560</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, August 7th, 2025: Sextortion Update; Adobe and Trend Micro release emergency patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, August 7th, 2025: Sextortion Update; Adobe and Trend Micro release emergency patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9560.mp3" length="4294637" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9560.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9560</link>
<pubDate>Thu, 07 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Do Sextortion Scams Still Work in 2025?<br/>
Jan looked at recent sextortion emails to check if any of the crypto addresses in these emails received deposits. Sadly, some did, so these scams still work.<br/>
<a href="https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178">https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178</a><br/>
Akira Ransomware Group s use of Drivers<br/>
Guidepoint Security observed the Akira ransomware group using specific legitimate drivers for privilege escalation<br/>
<a href="https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/">https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/</a><br/>
Adobe Patches Critical Experience Manager Vulnerability<br/>
Adobe released emergency patches for a vulnerability in Adobe Experience Manager after a PoC exploit was made public.<br/>
<a href="https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/">https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/</a><br/>
<a href="https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html">https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html</a><br/>
Trend Micro Apex One Vulnerability<br/>
Trend Micro released an emergency patch for an actively exploited pre-authentication remote code execution vulnerability in the Apex One management console.<br/>
<a href="https://success.trendmicro.com/en-US/solution/KA-0020652">https://success.trendmicro.com/en-US/solution/KA-0020652</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9560" type="text/plain" language="en" />
<itunes:keywords>sextortion, akira, ransomware, driver, adobe, experience manager, trend micro, apex one, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, August 6th, 2025: Machinekeys and VIEWSTATEs; Perplexity Unethical Learning; SonicWall Updates
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9558</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, August 6th, 2025: Machinekeys and VIEWSTATEs; Perplexity Unethical Learning; SonicWall Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, August 6th, 2025: Machinekeys and VIEWSTATEs; Perplexity Unethical Learning; SonicWall Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9558.mp3" length="6461384" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9558.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9558</link>
<pubDate>Wed, 06 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Stealing Machinekeys for fun and profit (or riding the SharePoint wave)<br/>
Bojan explains in detail how .NET uses Machine Keys to protect the VIEWSTATE, and how to abuse the VIEWSTATE for code execution if the Machine Keys are lost.<br/>
<a href="https://isc.sans.edu/diary/Stealing%20Machine%20Keys%20for%20fun%20and%20profit%20%28or%20riding%20the%20SharePoint%20wave%29/32174">https://isc.sans.edu/diary/Stealing%20Machine%20Keys%20for%20fun%20and%20profit%20%28or%20riding%20the%20SharePoint%20wave%29/32174</a><br/>
Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives<br/>
Perplexity will change its User Agent, or use different originating IP addresses, if it detects being blocked from scanning websites<br/>
<a href="https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/">https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/</a><br/>
Gen 7 SonicWall Firewalls   SSLVPN Recent Threat Activity<br/>
Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled. <br/>
<a href="https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430">https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430</a><br/>
]]></description>
<itunes:duration>7:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9558" type="text/plain" language="en" />
<itunes:keywords>sonicall, perplexity, machinekeys, viewstate, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, August 05, 2025: Daily Trends Report; NVidia Triton RCE; Cursor AI Misconfiguration
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9556</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, August 05, 2025: Daily Trends Report; NVidia Triton RCE; Cursor AI Misconfiguration
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, August 05, 2025: Daily Trends Report; NVidia Triton RCE; Cursor AI Misconfiguration
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9556.mp3" length="5713737" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9556.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9556</link>
<pubDate>Tue, 05 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Daily Trends Report<br/>
A new trends report will bring you daily data highlights via e-mail.<br/>
<a href="https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170">https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170</a><br/>
NVidia Triton RCE<br/>
Wiz found an interesting information leakage vulnerability in NVidia s Triton servers that can be leveraged to remote code execution.<br/>
<a href="https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server">https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server</a><br/>
Cursor AI MCP Vulnerability<br/>
An attacker could abuse negligent Cursor MCP configurations to implement backdoors into developer machines.<br/>
<a href="https://www.aim.security/lp/aim-labs-curxecute-blogpost">https://www.aim.security/lp/aim-labs-curxecute-blogpost</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9556" type="text/plain" language="en" />
<itunes:keywords>cursor, mcp, nvidia, triton, rce, trends, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, August 4th, 2025: Legacy Protocols; Sonicwall SSL VPN Possible 0-Day;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9554</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, August 4th, 2025: Legacy Protocols; Sonicwall SSL VPN Possible 0-Day;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, August 4th, 2025: Legacy Protocols; Sonicwall SSL VPN Possible 0-Day;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9554.mp3" length="4445873" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9554.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9554</link>
<pubDate>Mon, 04 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scans for pop3user with guessable password<br/>
A particular IP assigned to a network that calls itself  Unmanaged  has been scanning telnet/ssh for a user called  pop3user  with passwords  pop3user  or  123456 . I assume they are looking for legacy systems that either currently run pop3 or ran pop3 in the past, and left the user enabled.<br/>
<a href="https://isc.sans.edu/diary/Legacy%20May%20Kill/32166">https://isc.sans.edu/diary/Legacy%20May%20Kill/32166</a><br/>
Possible Sonicwall SSL VPN 0-Day<br/>
Arcticwolf observed compromised Sonicwall SSL VPN devices used by the Akira group to install ransomware. These devices were fully patched, and credentials were recently rotated. <br/>
<a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/">https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/</a><br/>
PAM Based Linux Backdoor<br/>
For over a year, attackers have used a PAM-based Linux backdoor that so far has gotten little attention from anti-malware vendors. PAM-based backdoors can be stealthy, and this one in particular includes various anti-forensics tricks.<br/>
<a href="https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/">https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9554" type="text/plain" language="en" />
<itunes:keywords>pam, linux, backdoor, sonicwall, legacy, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, August 1st, 2025: Scattered Spider Domains; Excel Blocking Dangerous Links; CISA Releasing Thorium Platform
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9552</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, August 1st, 2025: Scattered Spider Domains; Excel Blocking Dangerous Links; CISA Releasing Thorium Platform
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, August 1st, 2025: Scattered Spider Domains; Excel Blocking Dangerous Links; CISA Releasing Thorium Platform
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9552.mp3" length="4781953" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9552.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9552</link>
<pubDate>Fri, 01 Aug 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scattered Spider Related Domain Names<br/>
A quick demo of our domain feeds and how they can be used to find Scattered Spider related domains<br/>
<a href="https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162">https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162</a><br/>
Excel External Workbook Links to Blocked File Types Will Be Disabled by Default<br/>
Excel will discontinue allowing links to dangerous file types starting as early as October.<br/>
<a href="https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58">https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58</a><br/>
CISA Releases Thorium<br/>
CISA announced that it released its malware analysis platform, Thorium, as open-source software.<br/>
<a href="https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability">https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9552" type="text/plain" language="en" />
<itunes:keywords>thorium, cisa, scattered spider, excel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday July 31st, 2025: Firebase Security; WebKit Vuln Exploited; Scattered Spider Update
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9550</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday July 31st, 2025: Firebase Security; WebKit Vuln Exploited; Scattered Spider Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday July 31st, 2025: Firebase Security; WebKit Vuln Exploited; Scattered Spider Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9550.mp3" length="5605666" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9550.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9550</link>
<pubDate>Thu, 31 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
 Securing Firebase: Lessons Re-Learned from the Tea Breach<br/>
Inspried by the breach of the Tea app, Brendon Evans recorded a video to inform of Firebase security issues<br/>
<a href="https://isc.sans.edu/diary/Securing%20Firebase%3A%20Lessons%20Re-Learned%20from%20the%20Tea%20Breach/32158">https://isc.sans.edu/diary/Securing%20Firebase%3A%20Lessons%20Re-Learned%20from%20the%20Tea%20Breach/32158</a><br/>
WebKit Vulnerability Exploited before Apple Patch<br/>
A WebKit vulnerablity patched by Apple yesterday has already been exploited in Google Chrome. Google noted the exploit with its patch for the same vulnerability in Chrome.<br/>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6558">https://nvd.nist.gov/vuln/detail/CVE-2025-6558</a><br/>
Scattered Spider Update<br/>
CISA released an update for its report on Scattered Spider, noting that the group also calls helpdesks impersonating users, not just the other way around.<br/>
<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a</a><br/>
]]></description>
<itunes:duration>6:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9550" type="text/plain" language="en" />
<itunes:keywords>scattered spider, webkit, chrome, chromium, exploit, tea, firebase, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday July 30th, 2025: Apple Updates; Python Triage; Papercut Vuln Exploited
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9548</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday July 30th, 2025: Apple Updates; Python Triage; Papercut Vuln Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday July 30th, 2025: Apple Updates; Python Triage; Papercut Vuln Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9548.mp3" length="5661748" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9548.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9548</link>
<pubDate>Wed, 30 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Updates Everything: July 2025 Edition<br/>
Apple released updates for all of its operating systems patching 89 different vulnerabilities. Many vulnerabilities apply to multiple operating systems.<br/>
<a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything%3A%20July%202025/32154">https://isc.sans.edu/diary/Apple%20Updates%20Everything%3A%20July%202025/32154</a><br/>
Python Triage<br/>
A quick python script by Xavier to efficiently search through files, even compressed once, for indicators of compromise.<br/>
<a href="https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/">https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/</a><br/>
PaperCut Attacks<br/>
CISA added a 2024 Papercut vulnerability to the known exploited vulnerability list.<br/>
<a href="https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog">https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9548" type="text/plain" language="en" />
<itunes:keywords>papercut, python, triage, apple, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, July 29th, 2025:Parasitic Exploits; Cisco ISE Exploit; MyASUS Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9546</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, July 29th, 2025:Parasitic Exploits; Cisco ISE Exploit; MyASUS Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, July 29th, 2025:Parasitic Exploits; Cisco ISE Exploit; MyASUS Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9546.mp3" length="4692169" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9546.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9546</link>
<pubDate>Tue, 29 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Parasitic SharePoint Exploits<br/>
We are seeing attacks against SharePoint itself and attempts to exploit backdoors left behind by attackers.<br/>
<a href="https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148">https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148</a><br/>
Cisco ISE Vulnerability Exploited<br/>
A recently patched vulnerability in Cisco ISE is now being exploited. The Zero Day Initiative has released a blog detailing the exploit chain to obtain code execution as an unauthenticated user.<br/>
<a href="https://www.zerodayinitiative.com/blog/2025/7/24/cve-2025-20281-cisco-ise-api-unauthenticated-remote-code-execution-vulnerability">https://www.zerodayinitiative.com/blog/2025/7/24/cve-2025-20281-cisco-ise-api-unauthenticated-remote-code-execution-vulnerability</a><br/>
MyAsus Vulnerablity<br/>
The  MyAsus  tool does not store its access tokens correctly, potentially providing an attacker with access to sensitive functions<br/>
<a href="https://www.asus.com/content/security-advisory/">https://www.asus.com/content/security-advisory/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9546" type="text/plain" language="en" />
<itunes:keywords>SharePoint, Parasitic Attacks, Cisco, ISE, MyASUS, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, July 28th, 2025: Linux Namespaces; UI Automation Abuse; Autoswagger
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9544</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, July 28th, 2025: Linux Namespaces; UI Automation Abuse; Autoswagger
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, July 28th, 2025: Linux Namespaces; UI Automation Abuse; Autoswagger
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9544.mp3" length="4746269" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9544.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9544</link>
<pubDate>Mon, 28 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Linux Namespaces<br/>
Linux namespaces can be used to control networking features on a process-by-process basis. This is useful when trying to present a different network environment to a process being analysed.<br/>
<a href="https://isc.sans.edu/diary/Sinkholing%20Suspicious%20Scripts%20or%20Executables%20on%20Linux/32144">https://isc.sans.edu/diary/Sinkholing%20Suspicious%20Scripts%20or%20Executables%20on%20Linux/32144</a><br/>
Coyote in the Wild: First-Ever Malware That Abuses UI Automation<br/>
Akamai identified malware that takes advantage of Microsoft s UI Automation Framework to programatically interact with the user s system and steal credentials.<br/>
<a href="https://www.akamai.com/blog/security-research/active-exploitation-coyote-malware-first-ui-automation-abuse-in-the-wild">https://www.akamai.com/blog/security-research/active-exploitation-coyote-malware-first-ui-automation-abuse-in-the-wild</a><br/>
Testing REST APIs with Autoswagger<br/>
The tool Autoswagger can be used to automate the testing of REST APIs following the OpenAPI/Swagger standard.<br/>
<a href="https://github.com/intruder-io/autoswagger/">https://github.com/intruder-io/autoswagger/</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9544" type="text/plain" language="en" />
<itunes:keywords>Linux, namespace, coyote, UI Automation, rest, autoswagger, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, July 25th, 2025: ficheck.py; Mital and SonicWall Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9542</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, July 25th, 2025: ficheck.py; Mital and SonicWall Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, July 25th, 2025: ficheck.py; Mital and SonicWall Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9542.mp3" length="4490777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9542.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9542</link>
<pubDate>Fri, 25 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
New File Integrity Tool: ficheck.py<br/>
Jim created a new tool, ficheck.py, that can be used to verify file integrity. It is a drop-in replacement for an older tool, fcheck, which was written in Perl and no longer functions well on modern Linux distributions.<br/>
<a href="https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136">https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136</a> <br/>
Mitel Vulnerability<br/>
Mitel released a patch for a vulnerability in its MX-ONE product. The authentication bypass could provide an attacker with user or even admin privileges.<br/>
<a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009</a><br/>
SonicWall SMA 100 Vulnerability<br/>
SonicWall fixed an arbitrary file upload issue in its SMA 100 series firewalls. But exploitation will require credentials.<br/>
<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9542" type="text/plain" language="en" />
<itunes:keywords>file integrity, ficheck.py, fcheck.pl, mitel, sonicwall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9540</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, July 24th, 2025: Reversing SharePoint Exploit; NPM “is” Compromise; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9540.mp3" length="5786798" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9540.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9540</link>
<pubDate>Thu, 24 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Reversing SharePoint  Toolshell  Exploits CVE-2025-53770 and CVE-2025-53771<br/>
A quick walk-through showing how to decode the payload of recent SharePoint exploits<br/>
<a href="https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138">https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138</a><br/>
Compromised JavaScript NPM  is  Package<br/>
The popular npm package  is  was compromised by malware. Luckily, the malicious code was found quickly, and it was reversed after about five hours.<br/>
<a href="https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack">https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack</a><br/>
Microsoft Quick Machine Recovery<br/>
Microsoft added a new quick machine recovery feature to Windows 11. If the system is stuck in a reboot loop, it will boot to a rescue partition and attempt to find fixes from Microsoft.<br/>
<a href="https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune">https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9540" type="text/plain" language="en" />
<itunes:keywords>sharepoint, reversing, payload, npm, microsoft, windows 11, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, July 23rd, 2025: Sharepoint 2016 Patch; MotW Privacy and WinZip; Interlock Ransomware; Sophos Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9538</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, July 23rd, 2025: Sharepoint 2016 Patch; MotW Privacy and WinZip; Interlock Ransomware; Sophos Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, July 23rd, 2025: Sharepoint 2016 Patch; MotW Privacy and WinZip; Interlock Ransomware; Sophos Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9538.mp3" length="5291173" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9538.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9538</link>
<pubDate>Wed, 23 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Updates SharePoint Vulnerability Guidance CVE-2025-53770 and CVE-2025-53771<br/>
Microsoft released its update for SharePoint 2016, completing the updates across all currently supported versions.<br/>
<a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/</a><br/>
WinZip MotW Privacy<br/>
Starting with version 7.10, WinZip introduced an option to no longer include the download URL in zip files as part of the Mark of the Web (MotW).<br/>
<a href="https://isc.sans.edu/diary/WinRAR%20MoTW%20Propagation%20Privacy/32130">https://isc.sans.edu/diary/WinRAR%20MoTW%20Propagation%20Privacy/32130</a><br/>
Interlock Ransomware<br/>
Several government agencies collaborated to create an informative and comprehensive overview of the Interlock ransomware. Just like prior writeups, this writeup is very informative, including many technical details useful to detect and block this ransomware.<br/>
<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a</a><br/>
Sophos Firewall Updates<br/>
Sophos patched five different vulnerabilities in its firewalls. Two of them are critical, but these only affect a small percentage of users.<br/>
<a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce">https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9538" type="text/plain" language="en" />
<itunes:keywords>sophos, interlock, winzip, motw, microsoft, sharepoint, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, July 22nd, 2025: SharePoint Emergency Patches; How Long Does Patching Take; HPE Wifi Vuln; Zoho WorkDrive Abused
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9536</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, July 22nd, 2025: SharePoint Emergency Patches; How Long Does Patching Take; HPE Wifi Vuln; Zoho WorkDrive Abused
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, July 22nd, 2025: SharePoint Emergency Patches; How Long Does Patching Take; HPE Wifi Vuln; Zoho WorkDrive Abused
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9536.mp3" length="5055716" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9536.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9536</link>
<pubDate>Tue, 22 Jul 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Released Patches for SharePoint Vulnerability CVE-2025-53770 CVE-2025-53771<br/>
Microsoft released a patch for the currently exploited SharePoint vulnerability. It also added a second CVE number identifying the authentication bypass vulnerability.<br/>
<a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/</a><br/>
How Quickly Are Systems Patched?<br/>
Jan took Shodan data to check how quickly recent vulnerabilities were patched. The quick answer: Not fast enough.<br/>
<a href="https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126">https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126</a><br/>
HP Enterprise Instant On Access Points Vulnerability<br/>
HPE patched two vulnerabilities in its Instant On access points (aka Aruba). One allows for authentication bypass, while the second one enables arbitrary code execution as admin.<br/>
<a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us</a><br/>
Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy<br/>
AppLocker sample policies suffer from a simple bug that may enable some rule bypass, but only if signatures are not enforced.<br/>
While reviewing Microsoft s suggested configuration, Varonis Threat Labs noticed a subtle but important issue: the MaximumFileVersion field was set to 65355 instead of the expected 65535. <br/>
<a href="https://www.varonis.com/blog/applocker-bypass-risks">https://www.varonis.com/blog/applocker-bypass-risks</a><br/>
Ghost Crypt Malware Leverages Zoho WorkDrive<br/>
The Ghost malware tricks users into downloading by sending links to Zoho WorkDrive locations.<br/>
<a href="https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis">https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9536" type="text/plain" language="en" />
<itunes:keywords>SharePoint, patches, zoho, workdrive, applocker, hpe, aruba, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday July 21st, 2025: Sharepoint Exploited; Veeam Fake Voicemail Phish; Passkey Phishing Attack
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9534</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday July 21st, 2025: Sharepoint Exploited; Veeam Fake Voicemail Phish; Passkey Phishing Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday July 21st, 2025: Sharepoint Exploited; Veeam Fake Voicemail Phish; Passkey Phishing Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9534.mp3" length="6792021" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9534.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9534</link>
<pubDate>Mon, 21 Jul 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
SharePoint Servers Exploited via 0-day CVE-2025-53770<br/>
Late last week, CodeWhite found a new remote code execution exploit against SharePoint. This vulnerability is now actively exploited.<br/>
<a href="https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/">https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/</a><br/>
Veeam Voicemail Phishing<br/>
Attackers appear to impersonate VEEAM in recent voicemail-themed phishing attempts.<br/>
<a href="https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120">https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120</a><br/>
Passkey Phishing Attack<br/>
A currently active phishing attack takes advantage of the ability to use QR codes to complete the Passkey login procedure<br/>
<a href="https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/">https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/</a><br/>
]]></description>
<itunes:duration>8:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9534" type="text/plain" language="en" />
<itunes:keywords>passkey, sharepoint, veeam, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, July 18th, 2025: Extended File Attributes; Critical Cisco ISE Patch; VMWare Patches; Quarterly Oracle Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9532</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, July 18th, 2025: Extended File Attributes; Critical Cisco ISE Patch; VMWare Patches; Quarterly Oracle Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, July 18th, 2025: Extended File Attributes; Critical Cisco ISE Patch; VMWare Patches; Quarterly Oracle Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9532.mp3" length="4133573" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9532.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9532</link>
<pubDate>Fri, 18 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Hiding Payloads in Linux Extended File Attributes<br/>
Xavier today looked at ways to hide payloads on Linux, similar to how alternate data streams are used on Windows. Turns out that extended file attributes do the trick, and he presents some scripts to either hide data or find hidden data.<br/>
<a href="https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116">https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116</a><br/>
Cisco Patches Critical Identity Services Engine Flaw CVE-2025-20281, CVE-2025-20337, CVE-2025-20282<br/>
An unauthenticated user may execute arbitrary code as root across the network due to improperly validated data in Cisco s Identity Services Engine.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6</a><br/>
Oracle Critical Patch Update<br/>
Oracle patched 309 flaws across 111 products. 9 of these vulnerabilities have a critical CVSS score of 9.0 or higher. <br/>
<a href="https://www.oracle.com/security-alerts/cpujul2025.html">https://www.oracle.com/security-alerts/cpujul2025.html</a><br/>
Broadcom releases VMware Updates<br/>
Broadcom fixed a number of vulnerabilities for ESXi, Workstation, Fusion, and Tools.<br/>
<a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877</a><br/>
]]></description>
<itunes:duration>4:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9532" type="text/plain" language="en" />
<itunes:keywords>broadcom, oracle, cisco, linux, xattr, extended file attributes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, July 17th, 2025: catbox.moe abuse; Sonicwall Attacks; Rendering Issues
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9530</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, July 17th, 2025: catbox.moe abuse; Sonicwall Attacks; Rendering Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, July 17th, 2025: catbox.moe abuse; Sonicwall Attacks; Rendering Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9530.mp3" length="4332584" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9530.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9530</link>
<pubDate>Thu, 17 Jul 2025 02:40:13 GMT</pubDate>
<description><![CDATA[<br/>
More Free File Sharing Services Abuse<br/>
The free file-sharing service catbox.moe is abused by malware. While it officially claims not to allow hosting of executables, it only checks extensions and is easily abused<br/>
<a href="https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112">https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112</a><br/>
Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor<br/>
A group Google identifies as UNC6148 is exploiting the Sonicwall SMA 100 series appliance. The devices are end of life, but even fully patched devices are exploited. Google assumes that these devices are compromised because credentials were leaked during prior attacks. The attacker installs the OVERSTEP backdoor after compromising the device.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor">https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor</a><br/>
Weaponizing Trust in File Rendering Pipelines<br/>
RenderShock is a comprehensive zero-click attack strategy that targets passive file preview, indexing, and automation behaviours in modern operating systems and enterprise environments. It leverages built-in trust mechanisms and background processing in file systems, email clients, antivirus tools, and graphical user interfaces to deliver payloads without requiring any user interaction.<br/>
<a href="https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/">https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9530" type="text/plain" language="en" />
<itunes:keywords>rendershock, unc6148, sonicwall, catbox, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, July 16th, 2025: ADS Keystroke Logger; Fake Homebrew; Broadcom Altiris RCE; Malicious Cursor AI Extensions
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9528</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, July 16th, 2025: ADS Keystroke Logger; Fake Homebrew; Broadcom Altiris RCE; Malicious Cursor AI Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, July 16th, 2025: ADS Keystroke Logger; Fake Homebrew; Broadcom Altiris RCE; Malicious Cursor AI Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9528.mp3" length="4838722" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9528.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9528</link>
<pubDate>Wed, 16 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Keylogger Data Stored in an ADS<br/>
Xavier came across a keystroke logger that stores data in alternate data streams. The data includes keystroke logs as well as clipboard data<br/>
<a href="https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108">https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108</a><br/>
Malvertising Homebrew<br/>
An attacker has been attempting to trick users into installing a malicious version of Homebrew. The fake software is advertised via paid Google ads and directs users to the attacker s GitHub repo.<br/>
<a href="https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc">https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc</a><br/>
CVE-2025-5333: Remote Code Execution in Broadcom Altiris IRM<br/>
LRQA have discovered a critical unauthenticated remote code execution (RCE) vulnerability in the Broadcom Symantec Altiris Inventory Rule Management (IRM) component of Symantec Endpoint Management.<br/>
<a href="https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/">https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/</a><br/>
Code highlighting with Cursor AI for $500,000<br/>
A syntax highlighting extension for Cursor AI was used to compromise a developer s workstation and steal $500,000 in cryptocurrency.<br/>
<a href="https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/">https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9528" type="text/plain" language="en" />
<itunes:keywords>cursor, extensions, broadcom, altiris, malvertising, homebrew, keylogger, ADS, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, July 14th, 2025: Web Honeypot Log Volume; Browser Extension Malware; RDP Forensics
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9526</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, July 14th, 2025: Web Honeypot Log Volume; Browser Extension Malware; RDP Forensics
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, July 14th, 2025: Web Honeypot Log Volume; Browser Extension Malware; RDP Forensics
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9526.mp3" length="5189436" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9526.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9526</link>
<pubDate>Tue, 15 Jul 2025 02:05:16 GMT</pubDate>
<description><![CDATA[<br/>
DShield Honeypot Log Volume Increase<br/>
Within the last few months, there has been a dramatic increase in honeypot log volumes and how often these high volumes are seen. This has not just been from Jesse s residential honeypot, which has historically seen higher log volumes, but from all of the honeypots that Jesse runs. <br/>
<a href="https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100">https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100</a><br/>
Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware.<br/>
Koi Security s investigation of a single  verified  color picker exposed a coordinated campaign of 18 malicious extensions that infected a massive 2.3 million users across Chrome and Edge.<br/>
<a href="https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5">https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5</a><br/>
RDP Forensics<br/>
Comprehensive overview of Windows RDP Forensics<br/>
<a href="https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec">https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9526" type="text/plain" language="en" />
<itunes:keywords>rdp, forensics, malware, browser extension, dshield, honeypot, sonicwall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, July 14th, 2025: Suspect Domain Feed; Wing FTP Exploited; FortiWeb Exploited; NVIDIA GPU Rowhammer
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9524</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, July 14th, 2025: Suspect Domain Feed; Wing FTP Exploited; FortiWeb Exploited; NVIDIA GPU Rowhammer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, July 14th, 2025: Suspect Domain Feed; Wing FTP Exploited; FortiWeb Exploited; NVIDIA GPU Rowhammer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9524.mp3" length="5794584" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9524.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9524</link>
<pubDate>Mon, 14 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Experimental Suspicious Domain Feed<br/>
Our new experimental suspicious domain feed uses various criteria to identify domains that may be used for phishing or other malicious purposes.<br/>
<a href="https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102">https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102</a><br/>
Wing FTP Server RCE Vulnerability Exploited CVE-2025-47812<br/>
 Huntress saw active exploitation of Wing FTP Server remote code execution (CVE-2025-47812) on a customer on July 1, 2025. Organizations running Wing FTP Server should update to the fixed version, version 7.4.4, as soon as possible.<br/>
<a href="https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild">https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild</a><br/>
<a href="https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/">https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/</a><br/>
FortiWeb Pre-Auth RCE (CVE-2025-25257)<br/>
An exploit for the FortiWeb RCE Vulnerability is now available and is being used in the wild.<br/>
<a href="https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce">https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce</a><br/>
NVIDIA Vulnerable to Rowhammer<br/>
NVIDIA has received new research related to the industry-wide DRAM issue known as  Rowhammer . The research demonstrates a potential Rowhammer attack against an NVIDIA A6000 GPU with GDDR6 Memory. The purpose of this notice is to reinforce already known mitigations to Rowhammer attacks.<br/>
<a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025">https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9524" type="text/plain" language="en" />
<itunes:keywords>domain feed, nvidia, rowhammer, fortiweb, sql injection, wing ftp, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, July 11th, 2025: SSH Tunnel; FortiWeb SQL Injection; Ruckus Unpatched Vuln; Missing Motherboard Patches;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9522</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, July 11th, 2025: SSH Tunnel; FortiWeb SQL Injection; Ruckus Unpatched Vuln; Missing Motherboard Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, July 11th, 2025: SSH Tunnel; FortiWeb SQL Injection; Ruckus Unpatched Vuln; Missing Motherboard Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9522.mp3" length="4879794" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9522.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9522</link>
<pubDate>Fri, 11 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
SSH Tunneling in Action: direct-tcp requests<br/>
Attackers are compromising ssh servers to abuse them as relays. The attacker will configure port forwarding direct-tcp connections to forward traffic to a victim. In this particular case, the Yandex mail server was the primary victim of these attacks.<br/>
<a href="https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094">https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094</a><br/>
Fortiguard FortiWeb Unauthenticated SQL injection in GUI (CVE-2025-25257)<br/>
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.<br/>
<a href="https://www.fortiguard.com/psirt/FG-IR-25-151">https://www.fortiguard.com/psirt/FG-IR-25-151</a><br/>
Ruckus Virtual SmartZone (vSZ) and Ruckus Network Director (RND) contain multiple vulnerabilities<br/>
Ruckus products suffer from a number of critical vulnerabilities. There is no patch available, and users are advised to restrict access to the vulnerable admin interface.<br/>
<a href="https://kb.cert.org/vuls/id/613753">https://kb.cert.org/vuls/id/613753</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9522" type="text/plain" language="en" />
<itunes:keywords>ruckus, forgiguard, ssh, tunnel, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, July 10th, 2025: Internal CA with ACME; TapJacking on Android; Adobe Patches;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9520</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, July 10th, 2025: Internal CA with ACME; TapJacking on Android; Adobe Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, July 10th, 2025: Internal CA with ACME; TapJacking on Android; Adobe Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9520.mp3" length="4455568" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9520.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9520</link>
<pubDate>Thu, 10 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Setting up Your Own Certificate Authority for Development: Why and How.<br/>
Some tips on setting up your own internal certificate authority using the smallstep CA.<br/>
<a href="https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092">https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092</a><br/>
Animation-Driven Tapjacking on Android<br/>
Attackers can use a click-jacking like trick to trick victims into clicking on animated transparent dialogs opened from other applications.<br/>
<a href="https://taptrap.click/usenix25_taptrap_paper.pdf">https://taptrap.click/usenix25_taptrap_paper.pdf</a><br/>
Adobe Patches<br/>
Adobe patched 13 different products yesterday. Most concerning are vulnerabilities in Coldfusion that include code execution and arbitrary file disclosure vulnerabilities.<br/>
<a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9520" type="text/plain" language="en" />
<itunes:keywords>ca, smallstap, acme, tapjack, adobe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, July 9th, 2025: Microsoft Patches; Opposum Attack;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9518</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, July 9th, 2025: Microsoft Patches; Opposum Attack;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, July 9th, 2025: Microsoft Patches; Opposum Attack;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9518.mp3" length="6495698" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9518.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9518</link>
<pubDate>Wed, 09 Jul 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday, July 2025<br/>
Today, Microsoft released patches for 130 Microsoft vulnerabilities and 9 additional vulnerabilities not part of Microsoft's portfolio but distributed by Microsoft. 14 of these are rated critical. Only one of the vulnerabilities was disclosed before being patched, and none of the vulnerabilities have so far been exploited.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088</a><br/>
Opposum Attack<br/>
If a TLS server is configured to allow switching from HTTP to HTTPS on a specific port, an attacker may be able to inject a request into the data stream. <br/>
<a href="https://opossum-attack.com/">https://opossum-attack.com/</a><br/>
Ivanti Security Updates<br/>
Ivanty fixed vulnerabilities in Ivanty Connect Secure, EPMM, and EPM. In particular the password decryption vulnerabliity may be interesting.<br/>
<a href="https://www.ivanti.com/blog/july-security-update-2025">https://www.ivanti.com/blog/july-security-update-2025</a><br/>
]]></description>
<itunes:duration>7:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9518" type="text/plain" language="en" />
<itunes:keywords>ivanti, opposum, tls, microsoft, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, July 8th, 2025: Detecting Filename (Windows); Atomic Stealer now with Backdoor; SEO Scams
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9516</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, July 8th, 2025: Detecting Filename (Windows); Atomic Stealer now with Backdoor; SEO Scams
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, July 8th, 2025: Detecting Filename (Windows); Atomic Stealer now with Backdoor; SEO Scams
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9516.mp3" length="4606150" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9516.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9516</link>
<pubDate>Tue, 08 Jul 2025 02:20:02 GMT</pubDate>
<description><![CDATA[<br/>
What s My File Name<br/>
Malware may use the GetModuleFileName API to detect if it was renamed to a name typical for analysis, like sample.exe or malware.exe<br/>
<a href="https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084">https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084</a><br/>
Atomic macOS infostealer adds backdoor for persistent attacks<br/>
Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as 'AMOS') that comes with a backdoor, to attackers persistent access to compromised systems.<br/>
<a href="https://moonlock.com/amos-backdoor-persistent-access">https://moonlock.com/amos-backdoor-persistent-access</a><br/>
HOUKEN SEEKING A PATH BY LIVING ON THE EDGE WITH ZERO-DAYS<br/>
At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024- 8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices.<br/>
<a href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf">https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf</a><br/>
SEO Scams Targeting Putty, WinSCP, and AI Tools<br/>
Paid Google ads are advertising trojaned versions of popuplar tools like ssh and winscp<br/>
<a href="https://arcticwolf.com/resources/blog-uk/malvertising-campaign-delivers-oyster-broomstick-backdoor-via-seo-poisoning-and-trojanized-tools/">https://arcticwolf.com/resources/blog-uk/malvertising-campaign-delivers-oyster-broomstick-backdoor-via-seo-poisoning-and-trojanized-tools/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9516" type="text/plain" language="en" />
<itunes:keywords>malware, getmodulefilename, houken, seo, putty, winscp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9514</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9514.mp3" length="4875043" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9514.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9514</link>
<pubDate>Mon, 07 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Interesting ssh/telnet usernames<br/>
Some interesting usernames observed in our honeypots<br/>
<a href="https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080">https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080</a><br/>
More sudo trouble<br/>
The host option in Sudo can be exploited to execute commands on unauthorized hosts.<br/>
<a href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host">https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host</a><br/>
CitrixBleed2 PoC Posted (CVE-2025-5777)<br/>
WatchTwer published additional details about the recently patched CitrixBleed vulnerability, including a PoC exploit.<br/>
<a href="https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/">https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/</a><br/>
Instagram Using Six Day Certificates<br/>
Instagram changes their TLS certificates daily and they use certificates that are just about to expire in a week.<br/>
<a href="https://hereket.com/posts/instagram-single-day-certificates/">https://hereket.com/posts/instagram-single-day-certificates/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9514" type="text/plain" language="en" />
<itunes:keywords>usernames, scadaadmin, gpu001, gpu002, sudo, citrix, netscaler, citrixbleed, instagram, certificates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday July 3rd, 2025: sudo problems; polymorphic zip files; cisco vulnerablity
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9512</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday July 3rd, 2025: sudo problems; polymorphic zip files; cisco vulnerablity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday July 3rd, 2025: sudo problems; polymorphic zip files; cisco vulnerablity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9512.mp3" length="4489604" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9512.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9512</link>
<pubDate>Thu, 03 Jul 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Sudo chroot Elevation of Privilege<br/>
The sudo chroot option can be leveraged by any local user to elevate privileges to root, even if no sudo rules are defined for that user.<br/>
<a href="https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot">https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot</a><br/>
Polymorphic ZIP Files<br/>
A zip file with a corrupt End of Central Directory Record may extract different data depending on the tool used to extract the files.<br/>
<a href="https://hackarcana.com/article/yet-another-zip-trick">https://hackarcana.com/article/yet-another-zip-trick</a><br/>
Cisco Unified Communications Manager Static SSH Credentials Vulnerability<br/>
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9512" type="text/plain" language="en" />
<itunes:keywords>sudo, cisco, ucm, ssh, zip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday June 30th, 2025: Scattered Spider; AMI BIOS Exploited; Secure Boot Certs Expiring; Microsoft Resliliency Initiative
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9510</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday June 30th, 2025: Scattered Spider; AMI BIOS Exploited; Secure Boot Certs Expiring; Microsoft Resliliency Initiative
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday June 30th, 2025: Scattered Spider; AMI BIOS Exploited; Secure Boot Certs Expiring; Microsoft Resliliency Initiative
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9510.mp3" length="6297096" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9510.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9510</link>
<pubDate>Mon, 30 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scattered Spider Update<br/>
The threat actor known as Scattered Spider is in the news again, this time focusing on airlines. But the techniques used by Scattered Spider, social engineering, are still some of the most dangerous techniques used by various threat actors.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805">https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805</a><br/>
AMI BIOS Vulnerability Exploited CVE-2024-54085<br/>
A vulnerability in the Redfish remote access software, including AMI s BIOS, is now being exploited.<br/>
<a href="https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf">https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf</a><br/>
<a href="https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/">https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/</a><br/>
Act now: Secure Boot certificates expire in June 2026<br/>
The Microsoft certificates used in Secure Boot are the basis of trust for operating system security, and all will be expiring beginning June 2026. <br/>
<a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856">https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856</a><br/>
The Windows Resiliency Initiative: Building resilience for a future-ready enterprise<br/>
Microsoft announced more details about its future security and resilience strategy for Windows. In particular, security tools will no longer have kernel access, which is supposed to prevent a repeat of the Cloudflare issue, but may also restrict security tools  functionality.<br/>
<a href="https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/">https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/</a><br/>
]]></description>
<itunes:duration>7:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9510" type="text/plain" language="en" />
<itunes:keywords>windows, resiliency, cloudflare, secure boot, certificate, ami bios, redfish, scattered spider, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, June 27th, 2025: Open-VSX Flaw; Airoha Bluetooth Vulnerablity; Critical Cisco Identity Service Engine Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9508</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, June 27th, 2025: Open-VSX Flaw; Airoha Bluetooth Vulnerablity; Critical Cisco Identity Service Engine Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, June 27th, 2025: Open-VSX Flaw; Airoha Bluetooth Vulnerablity; Critical Cisco Identity Service Engine Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9508.mp3" length="5710948" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9508.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9508</link>
<pubDate>Fri, 27 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Open-VSX Flaw Puts Developers at Risk<br/>
A flaw in the open-vsx extension marketplace could have let to the compromise of any extension offered by the marketplace.<br/>
<a href="https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44">https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44</a><br/>
Bluetooth Vulnerability Could Allow Eavesdropping<br/>
A vulnerability in the widely used Airoha Bluetooth chipset can be used to compromise devices and use them for eavesdropping.<br/>
<a href="https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/">https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/</a><br/>
Critical Cisco Identity Services Engine Vulnerability<br/>
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6</a><br/>
]]></description>
<itunes:duration>6:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9508" type="text/plain" language="en" />
<itunes:keywords>cisco, ISE, bluetooth, airoha, open-vsx, vs-code, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, June 26th, 2025: Another Netscaler Vuln; CentOS Web Panel Vuln; IP Based Certs
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9506</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, June 26th, 2025: Another Netscaler Vuln; CentOS Web Panel Vuln; IP Based Certs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, June 26th, 2025: Another Netscaler Vuln; CentOS Web Panel Vuln; IP Based Certs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9506.mp3" length="4948133" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9506.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9506</link>
<pubDate>Thu, 26 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543<br/>
Citrix patched a memory overflow vulnerability leading to unintended control flow and denial of service.<br/>
<a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788</a><br/>
Remote code execution in CentOS Web Panel - CVE-2025-48703<br/>
An arbitrary file upload vulnerability in the user (not admin) part of Web Panel can be used to execute arbitrary code<br/>
<a href="https://fenrisk.com/rce-centos-webpanel">https://fenrisk.com/rce-centos-webpanel</a><br/>
Gogs Arbitrary File Deletion Vulnerability<br/>
Due to the insufficient patch for the CVE-2024-39931, it's still possible to delete files under the .git directory and achieve remote command execution.<br/>
<a href="https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7">https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7</a><br/>
Let s Encrypt Will Soon Issue IP Address-Based Certs<br/>
Let s Encrypt is almost ready to issue certificates for IP address SANs from Let's Encrypt's production environment. They'll only be available under the short-lived profile (which has a 6-day validity period), and that profile will remain allowlist-only for a while.<br/>
<a href="https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777">https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9506" type="text/plain" language="en" />
<itunes:keywords>netscaler, adc, citrix, dos, lets encrypt, certificates, gogs, centos, web panel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, June 24th, 2025: Telnet/SSH Scan Evolution; Fake Sonicwall Software; File-Fix vs Click-Fix
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9504</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, June 24th, 2025: Telnet/SSH Scan Evolution; Fake Sonicwall Software; File-Fix vs Click-Fix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, June 24th, 2025: Telnet/SSH Scan Evolution; Fake Sonicwall Software; File-Fix vs Click-Fix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9504.mp3" length="3404306" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9504.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9504</link>
<pubDate>Wed, 25 Jun 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Quick Password Brute Forcing Evolution Statistics<br/>
After collecting usernames and passwords from our ssh and telnet honeypots for about a decade, I took a look back at how scans changed. Attackers are attempting more passwords in each scans than they used to, but the average length of passwords did not change.<br/>
<a href="https://isc.sans.edu/diary/Quick%20Password%20Brute%20Forcing%20Evolution%20Statistics/32068">https://isc.sans.edu/diary/Quick%20Password%20Brute%20Forcing%20Evolution%20Statistics/32068</a><br/>
Introducing FileFix   A New Alternative to ClickFix Attacks<br/>
Attackers may trick the user into copy/pasting strings into file explorer, which will execute commands similar to the ClickFix attack that tricks users into copy pasting the command into the start menu s cmd feature.<br/>
<a href="https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/">https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/</a><br/>
Threat Actors Modify and Re-Create Commercial Software to Steal User s Information<br/>
A fake Sonicwall Netextender clone will steal user s credentials<br/>
<a href="https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information">https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information</a><br/>
]]></description>
<itunes:duration>4:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9504" type="text/plain" language="en" />
<itunes:keywords>clickfix, filefix, password, brute forcing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, June 24th, 2025: Ichano ATHome IP Camera Scans; Netscaler Vulnerability; WinRar Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9502</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, June 24th, 2025: Ichano ATHome IP Camera Scans; Netscaler Vulnerability; WinRar Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, June 24th, 2025: Ichano ATHome IP Camera Scans; Netscaler Vulnerability; WinRar Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9502.mp3" length="4259964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9502.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9502</link>
<pubDate>Tue, 24 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Scans for Ichano AtHome IP Cameras<br/>
A couple days ago, a few sources started scanning for the username super_yg and the password 123. This is associated with Ichano IP Camera software.<br/>
<a href="https://isc.sans.edu/diary/Scans%20for%20Ichano%20AtHome%20IP%20Cameras/32062">https://isc.sans.edu/diary/Scans%20for%20Ichano%20AtHome%20IP%20Cameras/32062</a><br/>
Critical Netscaler Security Update CVE-2025-5777<br/>
CVE 2025-5777 is a critical severity vulnerability impacting NetScaler Gateway, i.e. if NetScaler has been configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.<br/>
<a href="https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/">https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/</a><br/>
WinRar Vulnerability CVE-2025-6218<br/>
WinRar may be tricked into extracting files into attacker-determined locations, possibly leading to remote code execution<br/>
<a href="https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=276&cHash=b5165454d983fc9717bc8748901a64f9">https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=276&cHash=b5165454d983fc9717bc8748901a64f9</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9502" type="text/plain" language="en" />
<itunes:keywords>ip cameras, winrar, netscaler, ichano, athome, ip camera, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, June 23rd, 2025: ADS and Python; More Secure Cloud PCs; Zend.to Path Traversal; Parser Differentials
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9500</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, June 23rd, 2025: ADS and Python; More Secure Cloud PCs; Zend.to Path Traversal; Parser Differentials
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, June 23rd, 2025: ADS and Python; More Secure Cloud PCs; Zend.to Path Traversal; Parser Differentials
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9500.mp3" length="4715210" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9500.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9500</link>
<pubDate>Mon, 23 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
ADS & Python Tools<br/>
Didier explains how to use his tools cut-bytes.py and filescanner to extract information from alternate data streams.<br/>
<a href="https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058">https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058</a><br/>
Enhanced security defaults for Windows 365 Cloud PCs<br/>
Microsoft announced more secure default configurations for its Windows 365 Cloud PC offerings.<br/>
<a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914">https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914</a><br/>
CVE-2025-34508: Another File Sharing Application, Another Path Traversal<br/>
Horizon3 reveals details of a recently patched directory traversal vulnerability in zend.to.<br/>
<a href="https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/">https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/</a><br/>
Unexpected security footguns in Go's parsers<br/>
Go parsers for JSON and XML are not always compatible and can parse data in unexpected ways. This blog by Trails of Bits goes over the various security implications of this behaviour.<br/>
<a href="https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/">https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9500" type="text/plain" language="en" />
<itunes:keywords>parsers, go, xml, json, zend.to, ads, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, June 20th, 2025: New Employee Phishing; Malicious Tech Support Links; Social Engineering App Sepecific Passwords
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9498</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, June 20th, 2025: New Employee Phishing; Malicious Tech Support Links; Social Engineering App Sepecific Passwords
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, June 20th, 2025: New Employee Phishing; Malicious Tech Support Links; Social Engineering App Sepecific Passwords
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9498.mp3" length="4852953" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9498.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9498</link>
<pubDate>Fri, 20 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
How Long Until the Phishing Starts? About Two Weeks<br/>
After setting up a Google Workspace and adding a new user, it took only two weeks for the new employee to receive somewhat targeted phishing emails.<br/>
<a href="https://isc.sans.edu/diary/How%20Long%20Until%20the%20Phishing%20Starts%3F%20About%20Two%20Weeks/32052">https://isc.sans.edu/diary/How%20Long%20Until%20the%20Phishing%20Starts%3F%20About%20Two%20Weeks/32052</a><br/>
Scammers hijack websites of Bank of America, Netflix, Microsoft, and more to insert fake phone numbers<br/>
Scammers are placing Google ads that point to legitimate companies  sites, but are injecting malicious text into the page advertising fake tech support numbers<br/>
<a href="https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number">https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number</a><br/>
What s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia<br/>
Targeted attacks are tricking victims into creating app-specific passwords to Google resources.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia">https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9498" type="text/plain" language="en" />
<itunes:keywords>asp, app specific, google, scammer, workspace, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, June 16th, 2025: Extracting Data from JPEG; Windows Recall Export; Anubis Wiper; Mitel Vuln and PoC
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9496</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, June 16th, 2025: Extracting Data from JPEG; Windows Recall Export; Anubis Wiper; Mitel Vuln and PoC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, June 16th, 2025: Extracting Data from JPEG; Windows Recall Export; Anubis Wiper; Mitel Vuln and PoC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9496.mp3" length="4857064" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9496.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9496</link>
<pubDate>Tue, 17 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Extracting Data From JPEGs<br/>
Didier shows how to efficiently extract data from JPEGs using his tool jpegdump.py<br/>
<a href="https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048">https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048</a><br/>
Windows Recall Export in Europe<br/>
In its latest insider build for Windows 11, Microsoft is testing an export feature for data stored by Recall. The feature is limited to European users and requires that you note an encryption key that will be displayed only once as Recall is enabled.<br/>
<a href="https://blogs.windows.com/windows-insider/2025/06/13/announcing-windows-11-insider-preview-build-26120-4441-beta-channel/">https://blogs.windows.com/windows-insider/2025/06/13/announcing-windows-11-insider-preview-build-26120-4441-beta-channel/</a><br/>
Anubis Ransomware Now Wipes Data<br/>
The Anubis ransomware, usually known for standard double extortion, is now also wiping data preventing any recovery even if you pay the ransom.<br/>
<a href="https://www.trendmicro.com/en_us/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html">https://www.trendmicro.com/en_us/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html</a><br/>
Mitel Vulnerabilities CVE-2025-47188<br/>
Mitel this week patched a critical path traversal vulnerability (sadly, no CVE), and Infoguard Labs published a PoC exploit for an older file upload vulnerability.<br/>
<a href="https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/">https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/</a> <a href="https://www.mitel.com/support/mitel-product-security-advisory-misa-2025-0007">https://www.mitel.com/support/mitel-product-security-advisory-misa-2025-0007</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9496" type="text/plain" language="en" />
<itunes:keywords>mitel, anubis, ringtone, wiper, ransomware, windows, recall, jpegdump, jpeg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, June 16th, 2025: Katz Stealer in JPG; JavaScript Attacks; Reviving expired Discord Invites for Evil
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9494</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, June 16th, 2025: Katz Stealer in JPG; JavaScript Attacks; Reviving expired Discord Invites for Evil
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, June 16th, 2025: Katz Stealer in JPG; JavaScript Attacks; Reviving expired Discord Invites for Evil
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9494.mp3" length="5665299" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9494.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9494</link>
<pubDate>Mon, 16 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Katz Stealer in JPG<br/>
Xavier found some multistage malware that uses an Excel Spreadsheet and an HTA file to load an image that includes embeded a copy of Katz stealer.<br/>
<a href="https://isc.sans.edu/diary/More+Steganography/32044">https://isc.sans.edu/diary/More+Steganography/32044</a><br/>
<a href="https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/">https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/</a><br/>
JavaScript obfuscated with JSF*CK is being used on over 200,000 websites to direct victims to malware<br/>
Expired Discord Invite Links Used for Malware Distribution<br/>
Expired discord invite links are revived as vanity links to direct victims to malware sites<br/>
<a href="https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/">https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9494" type="text/plain" language="en" />
<itunes:keywords>discord, invite, malware, katz, jpg, jpeg, javascript, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, June 13th, 2025: Honeypot Scripts; EchoLeak MSFT Copilot Vuln; Thunderbolt mailbox URL Vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9492</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, June 13th, 2025: Honeypot Scripts; EchoLeak MSFT Copilot Vuln; Thunderbolt mailbox URL Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, June 13th, 2025: Honeypot Scripts; EchoLeak MSFT Copilot Vuln; Thunderbolt mailbox URL Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9492.mp3" length="4801156" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9492.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9492</link>
<pubDate>Fri, 13 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Automated Tools to Assist with DShield Honeypot Investigations<br/>
<a href="https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038">https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038</a><br/>
EchoLeak: Zero-Click Microsoft 365 Copilot Data Leak<br/>
Microsoft fixed a vulnerability in Copilot that could have been abused to exfiltrate data from Copilot users. Copilot mishandled instructions an attacker included in documents inspected by Copilot and executed them.<br/>
<a href="https://www.aim.security/lp/aim-labs-echoleak-blogpost">https://www.aim.security/lp/aim-labs-echoleak-blogpost</a><br/>
Thunderbolt Vulnerability<br/>
Thunderbolt users may be tricked into downloading arbitrary files if an email includes a mailbox:/// URL.<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/">https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9492" type="text/plain" language="en" />
<itunes:keywords>honeypot tools, echoleak, copilot, thunderbolt, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, June 12th, 2025: Quasar RAT; Windows 11 24H2 Delay; SMB Client Vuln PoC; Connectwise Signing Keys; KDE Telnet code exec
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9490</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, June 12th, 2025: Quasar RAT; Windows 11 24H2 Delay; SMB Client Vuln PoC; Connectwise Signing Keys; KDE Telnet code exec
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, June 12th, 2025: Quasar RAT; Windows 11 24H2 Delay; SMB Client Vuln PoC; Connectwise Signing Keys; KDE Telnet code exec
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9490.mp3" length="5431869" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9490.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9490</link>
<pubDate>Thu, 12 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Quasar RAT Delivered Through Bat Files<br/>
Xavier is walking you through a quick reverse analysis of a script that will injection code extracted from a PNG image to implement a Quasar RAT.<br/>
<a href="https://isc.sans.edu/diary/Quasar%20RAT%20Delivered%20Through%20Bat%20Files/32036">https://isc.sans.edu/diary/Quasar%20RAT%20Delivered%20Through%20Bat%20Files/32036</a><br/>
Delayed Windows 11 24H2 Rollout<br/>
Microsoft slightly throttled the rollout of windows 11 24H2 due to issues stemming from the patch Tuesday fixes.<br/>
<a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3570">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3570</a><br/>
An In-Depth Analysis of CVE-2025-33073<br/>
Patch Tuesday fixed an already exploited SMB client vulnerability. A blog by Synacktiv explains the nature of the issue and how to exploit it.<br/>
<a href="https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025">https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025</a><br/>
Connectwise Rotating Signing Certificates<br/>
Connectwise is rotating signing certificates after a recent compromise, and will release a new version of its Screen share software soon to harden its configuration.<br/>
<a href="https://www.connectwise.com/company/trust/advisories">https://www.connectwise.com/company/trust/advisories</a><br/>
KDE Telnet URL Vulnerablity<br/>
The Konsole delivered as part of KDE may be abused to execute arbitrary code via  telnet  URLs.<br/>
<a href="https://kde.org/info/security/advisory-20250609-1.txt">https://kde.org/info/security/advisory-20250609-1.txt</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9490" type="text/plain" language="en" />
<itunes:keywords>kde, telnet, konsole, conectwise, SMB, windows, RAT, BAT, Quasar, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, June 11th, 2025: Microsoft Patch Tuesday; Acrobat Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9488</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, June 11th, 2025: Microsoft Patch Tuesday; Acrobat Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, June 11th, 2025: Microsoft Patch Tuesday; Acrobat Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9488.mp3" length="5861925" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9488.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9488</link>
<pubDate>Wed, 11 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
Microsoft today released patches for 67 vulnerabilities. 10 of these vulnerabilities are rated critical. One vulnerability has already been exploited and another vulnerability has been publicly disclosed before today.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202025/32032">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202025/32032</a><br/>
Adobe Vulnerabilities<br/>
Adobe released patches for 7 different applications. Two significant ones are Adobe Commerce and Adobe Acrobat Reader. All vulnerabilities patched for Adobe Commerce can only be exploited by an authenticated user. The Adobe Acrobat Reader vulnerabilities are exploited by a user opening a crafted PDF, and the exploit may execute arbitrary code.<br/>
<a href="https://helpx.adobe.com/security/Home.html">https://helpx.adobe.com/security/Home.html</a><br/>
]]></description>
<itunes:duration>6:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9488" type="text/plain" language="en" />
<itunes:keywords>microsoft, patches, tuesday, adobe, commerce, pdf, acrobat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast June, Tuesday, June 10th, 2025: Octosql; Mirai vs. Wazuh DNS4EU; Wordpress Fair Package Manager
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9486</itunes:episode>
<itunes:subtitle>SANS Stormcast June, Tuesday, June 10th, 2025: Octosql; Mirai vs. Wazuh DNS4EU; Wordpress Fair Package Manager
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast June, Tuesday, June 10th, 2025: Octosql; Mirai vs. Wazuh DNS4EU; Wordpress Fair Package Manager
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9486.mp3" length="5176261" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9486.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9486</link>
<pubDate>Tue, 10 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
OctoSQL & Vulnerability Data<br/>
OctoSQL is a neat tool to query files in different formats using SQL. This can, for example, be used to query the JSON vulnerability files from CISA or NVD and create interesting joins between different files.<br/>
<a href="https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026">https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026</a><br/>
Mirai vs. Wazuh<br/>
The Mirai botnet has now been observed exploiting a vulnerability in the open-source EDR tool Wazuh.<br/>
<a href="https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability">https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability</a><br/>
DNS4EU<br/>
The European Union created its own public recursive resolver to offer a public resolver compliant with European privacy laws. This resolver is currently operated by ENISA, but the intent is to have a commercial entity operate and support it by a commercial entity.<br/>
<a href="https://www.joindns4.eu/">https://www.joindns4.eu/</a><br/>
WordPress FAIR Package Manager<br/>
Recent legal issues around different WordPress-related entities have made it more difficult to maintain diverse sources of WordPress plugins. With WordPress plugins usually being responsible for many of the security issues, the Linux Foundation has come forward to support the  FAIR Package Manager,  a tool intended to simplify the management of WordPress packages.<br/>
<a href="https://github.com/fairpm">https://github.com/fairpm</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9486" type="text/plain" language="en" />
<itunes:keywords>Octosql, wazuh, mirai, dns4eu, dns, wordpress, fair, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast June, June 9th, 2025: Extracting PNG Data; GlueStack Packages Backdoor; MacOS targeted by Clickfix; INETPUB restore script
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9484</itunes:episode>
<itunes:subtitle>SANS Stormcast June, June 9th, 2025: Extracting PNG Data; GlueStack Packages Backdoor; MacOS targeted by Clickfix; INETPUB restore script
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast June, June 9th, 2025: Extracting PNG Data; GlueStack Packages Backdoor; MacOS targeted by Clickfix; INETPUB restore script
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9484.mp3" length="4805586" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9484.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9484</link>
<pubDate>Mon, 09 Jun 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Extracting With pngdump.py<br/>
Didier extended his pngdump.py script to make it easier to extract additional data appended to the end of the image file.<br/>
<a href="https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022">https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022</a><br/>
16 React Native Packages for GlueStack Backdoored Overnight<br/>
16 npm packages with over a million weekly downloads between them were compromised. The compromised packages include a remote admin tool that was seen before in similar attacks.<br/>
<a href="https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem">https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem</a><br/>
Atomic MacOS Stealer Exploits Clickfix<br/>
MacOS users are now also targeted by fake captchas, tricking users into running exploit code.<br/>
<a href="https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers">https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers</a><br/>
Microsoft INETPUB Script<br/>
Microsoft published a simple PowerShell script to restore the inetpub folder in case you removed it by mistake.<br/>
<a href="https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0">https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9484" type="text/plain" language="en" />
<itunes:keywords>microsoft, inetpub, atomix, amos, stealer, clickfix, gluestack, backdoor, pngdump.py, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, June 6th, 2025: Fake Zoom Clients; Python tarfile vulnerability; HPE Insight Remote Support Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9482</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, June 6th, 2025: Fake Zoom Clients; Python tarfile vulnerability; HPE Insight Remote Support Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, June 6th, 2025: Fake Zoom Clients; Python tarfile vulnerability; HPE Insight Remote Support Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9482.mp3" length="4214817" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9482.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9482</link>
<pubDate>Fri, 06 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Be Careful With Fake Zoom Client Downloads<br/>
Miscreants are tricking victims into downloading fake Zoom clients (and likely other meeting software) by first sending them fake meeting invites that direct victims to a page that offers malware for download as an  update  to the Zoom client.<br/>
<a href="https://isc.sans.edu/diary/Be%20Careful%20With%20Fake%20Zoom%20Client%20Downloads/32014">https://isc.sans.edu/diary/Be%20Careful%20With%20Fake%20Zoom%20Client%20Downloads/32014</a><br/>
Python tarfile Vulnerability<br/>
Recently, the Python tarfile module introduced a  filter  option to help mitigate some of the insecure behavior common to software unpacking archives. This filter is, however, not working quite as well as it should.<br/>
<a href="https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/">https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/</a><br/>
Hewlett Packard Enterprise Insight Remote Support processAttachmentDataStream Directory Traversal Remote Code Execution Vulnerability<br/>
HP fixed, among other vulnerabilities, a critical remote code execution vulnerability in Insight Remote Support (IRS)<br/>
<a href="https://www.zerodayinitiative.com/advisories/ZDI-25-325/">https://www.zerodayinitiative.com/advisories/ZDI-25-325/</a><br/>
]]></description>
<itunes:duration>5:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9482" type="text/plain" language="en" />
<itunes:keywords>hp, insight, remote, support, irs, python, tarfile, zoom, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, June 5th, 2025: Phishing Comment Trick; AWS default logging mode change; Cisco Backdoor Fixed; Infoblox Vulnerability Details Released
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9480</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, June 5th, 2025: Phishing Comment Trick; AWS default logging mode change; Cisco Backdoor Fixed; Infoblox Vulnerability Details Released
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, June 5th, 2025: Phishing Comment Trick; AWS default logging mode change; Cisco Backdoor Fixed; Infoblox Vulnerability Details Released
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9480.mp3" length="4567881" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9480.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9480</link>
<pubDate>Thu, 05 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Phishing e-mail that hides malicious links from Outlook users<br/>
Jan found a phishing email that hides the malicious link from Outlook users. The email uses specific HTML comment clauses Outlook interprets to render or not render specific parts of the email s HTML code. Jan suggests that the phishing email is intented to not expose users of <br/>
 <a href="https://isc.sans.edu/diary/Phishing%20e-mail%20that%20hides%20malicious%20link%20from%20Outlook%20users/32010">https://isc.sans.edu/diary/Phishing%20e-mail%20that%20hides%20malicious%20link%20from%20Outlook%20users/32010</a><br/>
Amazon changing default logging from blocking to non-blocking<br/>
Amazon will change the default logging mode from blocking to non-blocking. Non-blocking logging will not stop the application if logging fails, but may result in a loss of logs.<br/>
<a href="https://aws.amazon.com/blogs/containers/preventing-log-loss-with-non-blocking-mode-in-the-awslogs-container-log-driver/">https://aws.amazon.com/blogs/containers/preventing-log-loss-with-non-blocking-mode-in-the-awslogs-container-log-driver/</a><br/>
Cisco Removes Backdoor<br/>
Cisco fixed a Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability. <br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7</a><br/>
Infoblox Vulnerability Details disclosed<br/>
Details regarding several vulnerabilities recently patched in Infoblox s NetMRI have been made public. In particular an unauthenticated remote code execution issue should be considered critical. <br/>
<a href="https://rhinosecuritylabs.com/research/infoblox-multiple-cves/">https://rhinosecuritylabs.com/research/infoblox-multiple-cves/</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9480" type="text/plain" language="en" />
<itunes:keywords>infoblox, netmri, Cisco, backdoor, amazon, logging, outlook, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, June 4th, 2025: vBulletin Exploited; Chrome 0-Day Patch; Roundcube RCE Patch; Multiple HP StoreOnce Vulns Patched
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9478</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, June 4th, 2025: vBulletin Exploited; Chrome 0-Day Patch; Roundcube RCE Patch; Multiple HP StoreOnce Vulns Patched
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, June 4th, 2025: vBulletin Exploited; Chrome 0-Day Patch; Roundcube RCE Patch; Multiple HP StoreOnce Vulns Patched
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9478.mp3" length="6229847" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9478.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9478</link>
<pubDate>Wed, 04 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
vBulletin Exploits CVE-2025-48827, CVE-2025-48828<br/>
We do see exploit attempts for the vBulletin flaw disclosed about a week ago. The flaw is only exploitable if vBulltin is run on PHP 8.1, and was patched over a year ago. However, vBulltin never disclosed the type of vulnerability that was patched.<br/>
<a href="https://isc.sans.edu/diary/vBulletin%20Exploits%20%28CVE-2025-48827%2C%20CVE-2025-48828%29/32006">https://isc.sans.edu/diary/vBulletin%20Exploits%20%28CVE-2025-48827%2C%20CVE-2025-48828%29/32006</a><br/>
Google Chrome 0-Day Patched<br/>
Google released a security update for Google Chrome patching three flaws. One of these is already being exploited.<br/>
<a href="https://chromereleases.googleblog.com/">https://chromereleases.googleblog.com/</a><br/>
Roundcube Update<br/>
Roundcube patched a vulnerability that allows any authenticated user to execute arbitrary code.<br/>
<a href="https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10">https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10</a><br/>
HP Vulnerabilities in StoreOnce<br/>
HP patched multiple vulnerabilities in StoreOnce. These issues could lead to remote code execution<br/>
<a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&docLocale=en_US">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&docLocale=en_US</a><br/>
]]></description>
<itunes:duration>7:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9478" type="text/plain" language="en" />
<itunes:keywords>HP, roundcube, storeonce, google, chrome, 0-day, vBulletin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, June 3rd, 2025: Windows SSH C2; Google Removes CAs from trusted list; MSFT issues Emergency Patch to fix Crash issue; Qualcom Adreno GPU 0-day
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9476</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, June 3rd, 2025: Windows SSH C2; Google Removes CAs from trusted list; MSFT issues Emergency Patch to fix Crash issue; Qualcom Adreno GPU 0-day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, June 3rd, 2025: Windows SSH C2; Google Removes CAs from trusted list; MSFT issues Emergency Patch to fix Crash issue; Qualcom Adreno GPU 0-day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9476.mp3" length="5137952" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9476.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9476</link>
<pubDate>Tue, 03 Jun 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Simple SSH Backdoor<br/>
Xavier came across a simple SSH backdoor taking advantage of the ssh client preinstalled on recent Windows systems. The backdoor is implemented via an SSH configuration file that instructs the SSH client to connect to a remote system and forward a shell on a random port. This will make the shell accessible to anybody able to connect to the C2 host. <br/>
<a href="https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000">https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000</a><br/>
Google Chrome to Distrust CAs<br/>
Google Chrome will remove the Chunghwa Telecom and Netlock certificate authorities from its list of trusted CAs. Any certificates issued after July 31st will not be trusted. Certificates issued before the deadline will be trusted until they expire.<br/>
<a href="https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html">https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html</a><br/>
Microsoft Emergency Update to Fix Crashes Caused by May Patch<br/>
Microsoft released an emergency update for a bug caused by one of the patches released in May. Due to the bug, systems may not restart after the patch is applied. This affects, first of all, virtual systems running in Azure and HyperV but apparently has also affected some physical systems.<br/>
<a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys</a><br/>
Qualcomm Adreno Graphics Processing Unit Patch (Exploited!) <br/>
Qualcomm released an update for the driver for its Adreno GPU. The patched vulnerability is already being exploited against Android devices.<br/>
<a href="https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html">https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9476" type="text/plain" language="en" />
<itunes:keywords>qualcom, adreno, netlock, chungwa, ssh, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, June 2nd, 2025: PNG with RAT; Cisco IOS XE WLC Exploit; vBulletin Exploit
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9474</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, June 2nd, 2025: PNG with RAT; Cisco IOS XE WLC Exploit; vBulletin Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, June 2nd, 2025: PNG with RAT; Cisco IOS XE WLC Exploit; vBulletin Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9474.mp3" length="4788965" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9474.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9474</link>
<pubDate>Mon, 02 Jun 2025 09:53:08 GMT</pubDate>
<description><![CDATA[<br/>
A PNG Image With an Embedded Gift<br/>
Xavier shows how Python code attached to a PNG image can be used to implement a command and control channel or a complete remote admin kit.<br/>
<a href="https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998">https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998</a><br/>
Cisco IOS XE WLC Arbitrary File Upload Vulnerability (CVE-2025-20188) Analysis<br/>
Horizon3 analyzed a recently patched flaw in Cisco Wireless Controllers. This arbitrary file upload flaw can easily be used to execute arbitrary code.<br/>
<a href="https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/">https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/</a><br/>
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE<br/>
A change in PHP 8.1 can expose methods previously expected to be  safe . vBulletin fixed a related flaw about a year ago without explicitly highlighting the security impact of the fix. A blog post now exposed the flaw and provided exploit examples. We have seen exploit attempts against honeypots starting May 25th, two days after the blog was published.<br/>
<a href="https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce">https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9474" type="text/plain" language="en" />
<itunes:keywords>vbulletin, php, exploit, cisco, wlc, png, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, May 30th 2025: Alternate Data Streams; Connectwise Breach; Google Calendar C2; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9472</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, May 30th 2025: Alternate Data Streams; Connectwise Breach; Google Calendar C2; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, May 30th 2025: Alternate Data Streams; Connectwise Breach; Google Calendar C2; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9472.mp3" length="11580837" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9472.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9472</link>
<pubDate>Fri, 30 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Alternate Data Streams: Adversary Defense Evasion and Detection<br/>
Good Primer of alternate data streams and how they are abused, as well as how to detect and defend against ADS abuse.<br/>
<a href="https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990">https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990</a><br/>
Connectwise Breach Affects ScreenConnect Customers<br/>
Connectwise s ScreenConnect solution was compromised, leading to attacks against a small number of customers. This is yet another example of how attackers are taking advantage of remote access solutions.<br/>
<a href="https://www.connectwise.com/company/trust/advisories">https://www.connectwise.com/company/trust/advisories</a><br/>
Mark Your Calendar: APT41 Innovative Tactics<br/>
Google detected attacks leveraging Google s calendar solution as a command and control channel.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics">https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics</a><br/>
Webs of Deception: Using the SANS ICS Kill Chain to Flip the Advantage to the Defender<br/>
Defending a small Industrial Control System (ICS) against sophisticated threats can seem futile. The resource disparity between small ICS defenders and sophisticated attackers poses a significant security challenge.<br/>
<a href="https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/">https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/</a><br/>
]]></description>
<itunes:duration>13:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9472" type="text/plain" language="en" />
<itunes:keywords>deceptoin, ics, apt41, google, calendar, connectwise, screenconnect, ads, alternate data streams, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday May 29th 2025: LLM Assisted Analysis; MSP Ransomware; Everetz Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9470</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday May 29th 2025: LLM Assisted Analysis; MSP Ransomware; Everetz Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday May 29th 2025: LLM Assisted Analysis; MSP Ransomware; Everetz Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9470.mp3" length="5188381" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9470.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9470</link>
<pubDate>Thu, 29 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Exploring a Use Case of Artificial Intelligence Assistance with Understanding an Attack<br/>
Jennifer Wilson took a  weird string  found in a recent honeypot sample and worked with ChatGPT to figure out what it is all about.<br/>
<a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980</a><br/>
Ransomware Deployed via SimpleHelp Vulnerabilities<br/>
Ransomware actors are using vulnerabilities in SimpleHelp to gain access to victim s networks via MSPs. The exploited vulnerabilities were patched in January.<br/>
<a href="https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/">https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/</a><br/>
OS Command Injection in Everetz Equipment<br/>
Broadcast equipment manufactured by Everetz is susceptible to an OS command injection vulnerability. Everetz has not responded to researchers reporting the vulnerability so far and there is no patch available.<br/>
<a href="https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009">https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9470" type="text/plain" language="en" />
<itunes:keywords>llm, chatgpt, telegram, simplehelp, ransomware, everetz, os command injection, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday May 28th 2025: Securing authorized_keys; ADAuditPlus SQL Injection; Dero Miner vs Docker API
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9468</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday May 28th 2025: Securing authorized_keys; ADAuditPlus SQL Injection; Dero Miner vs Docker API
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday May 28th 2025: Securing authorized_keys; ADAuditPlus SQL Injection; Dero Miner vs Docker API
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9468.mp3" length="5570809" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9468.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9468</link>
<pubDate>Wed, 28 May 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
SSH authorized_keys File<br/>
One of the most common techniques used by many bots is to add rogue keys to the authorized_keys file, implementing an SSH backdoor. Managing these files and detecting unauthorized changes is not hard and should be done if you operate Unix systems.<br/>
<a href="https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986">https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986</a><br/>
REMOTE COMMAND EXECUTION ON SMARTBEDDED METEOBRIDGE (CVE-2025-4008)<br/>
Weatherstation software Meteobridge suffers from an easily exploitable unauthenticated remote code execution vulnerability<br/>
<a href="https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008">https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008</a><br/>
<a href="https://forum.meteohub.de/viewtopic.php?t=18687">https://forum.meteohub.de/viewtopic.php?t=18687</a><br/>
Manageengine ADAuditPlus SQL Injection<br/>
Zoho patched two SQL Injection vulnerabilities in its ManageEngine ADAuditPlus product<br/>
<a href="https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html">https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html</a><br/>
<a href="https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html">https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html</a><br/>
Dero Miner Infects Containers through Docker API<br/>
Kaspersky found yet another botnet infecting docker containers to spread crypto coin miners. The initial access happens via exposed docker APIs.<br/>
<a href="https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/">https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9468" type="text/plain" language="en" />
<itunes:keywords>dero, miner, docker, manageengine, adauditplus, sql injection, ssh, authorized_keys, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, May 27th 2025: SVG Steganography; Fortinet PoC; GitLab Duo Prompt Injection
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9466</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, May 27th 2025: SVG Steganography; Fortinet PoC; GitLab Duo Prompt Injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, May 27th 2025: SVG Steganography; Fortinet PoC; GitLab Duo Prompt Injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9466.mp3" length="6065717" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9466.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9466</link>
<pubDate>Tue, 27 May 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
SVG Steganography<br/>
Steganography is not only limited to pixel-based images but can be used to embed messages into vector-based formats like SVG.<br/>
<a href="https://isc.sans.edu/diary/SVG%20Steganography/31978">https://isc.sans.edu/diary/SVG%20Steganography/31978</a><br/>
Fortinet Vulnerability Details CVE-2025-32756<br/>
Horizon3.ai shows how it was able to find the vulnerability in Fortinet s products, and how to possibly exploit this issue. The vulnerability is already being exploited in the wild and was patched May 13th<br/>
<a href="https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/">https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/</a><br/>
Remote Prompt Injection in GitLab Duo Leads to Source Code Theft<br/>
An attacker may leave instructions (prompts) for GitLab Duo embedded in the source code. This could be used to exfiltrate source code and secrets or to inject malicious code into an application.<br/>
<a href="https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo">https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo</a><br/>
]]></description>
<itunes:duration>7:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9466" type="text/plain" language="en" />
<itunes:keywords>steganography, svg, fortinet, gitlab, duo, prompt injection, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, May 23rd 2025: Backup Connectivity; Windows 2025 dMSA Abuse; Samlify Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9464</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, May 23rd 2025: Backup Connectivity; Windows 2025 dMSA Abuse; Samlify Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, May 23rd 2025: Backup Connectivity; Windows 2025 dMSA Abuse; Samlify Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9464.mp3" length="6640141" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9464.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9464</link>
<pubDate>Fri, 23 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Resilient Secure Backup Connectivity for SMB/Home Users<br/>
 Establishing resilient access to a home network via a second ISP may lead to unintended backdoors. Secure the access and make sure you have the visibility needed to detect abuse.<br/>
<a href="https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972">https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972</a><br/>
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory<br/>
An attacker with the ability to create service accounts may be able to manipulate these accounts to mark them as migrated accounts, inheriting all privileges the original account had access to.<br/>
<a href="https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory">https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory</a><br/>
Flaw in samlify That Opens Door to SAML Single Sign-On Bypass CVE-2025-47949<br/>
The samlify Node.js library does not verify SAML assertions correctly. It will consider the entire assertion valid, not just the original one. An attacker may use this to obtain additional privileges or authenticate as a different user<br/>
<a href="https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass">https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass</a><br/>
]]></description>
<itunes:duration>7:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9464" type="text/plain" language="en" />
<itunes:keywords>pgp, openpgp, npm, javascript, dns, cname, researchers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, May 22nd 2025: Crypto Confidence Scams; Extension Mayhem for VS Code and Chrome
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9462</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, May 22nd 2025: Crypto Confidence Scams; Extension Mayhem for VS Code and Chrome
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, May 22nd 2025: Crypto Confidence Scams; Extension Mayhem for VS Code and Chrome
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9462.mp3" length="5341081" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9462.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9462</link>
<pubDate>Thu, 22 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
New Variant of Crypto Confidence Scam<br/>
Scammers are offering login credentials for what appears to be high value crypto coin accounts. However, the goal is to trick users into paying for expensive  VIP  memberships to withdraw the money.<br/>
<a href="https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968">https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968</a><br/>
Malicious Chrome Extensions<br/>
Malicious Chrome extensions mimick popular services like VPNs to trick users into installing them. Once installed, the extensions will exfiltrate browser secrets<br/>
<a href="https://dti.domaintools.com/dual-function-malware-chrome-extensions/">https://dti.domaintools.com/dual-function-malware-chrome-extensions/</a><br/>
Malicious VS Code Extensions<br/>
Malicious Visual Studio Code extensions target crypto developers to trick them into installing them to exfiltrate developer secrets.<br/>
<a href="https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise">https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9462" type="text/plain" language="en" />
<itunes:keywords>vs code, chrome, extensions, crypto, confidence scams, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, May 21st 2025: Researchers Scanning the Internet; Forgotten DNS Records; openpgp.js Vulneraiblity
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9460</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, May 21st 2025: Researchers Scanning the Internet; Forgotten DNS Records; openpgp.js Vulneraiblity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, May 21st 2025: Researchers Scanning the Internet; Forgotten DNS Records; openpgp.js Vulneraiblity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9460.mp3" length="6596782" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9460.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9460</link>
<pubDate>Wed, 21 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Researchers Scanning the Internet<br/>
 A  newish  RFC, RFC 9511, suggests researchers identify themselves by adding strings to the traffic they send, or by operating web servers on machines from which the scan originates. We do offer lists of researchers and just added three new groups today<br/>
<a href="https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964">https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964</a><br/>
Cloudy with a change of Hijacking: Forgotten DNS Records<br/>
Organizations do not always remove unused CNAME records. An attacker may take advantage of this if an attacker is able to take possession of the now unused public cloud resource the name pointed to.<br/>
<a href="https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/">https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/</a><br/>
Message signature verification can be spoofed CVE-2025-47934<br/>
A vulnerability in openpgp.js may be used to spoof message signatures. openpgp.js is a popular library in systems implementing end-to-end encrypted browser applications.<br/>
<a href="https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8">https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8</a><br/>
]]></description>
<itunes:duration>7:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9460" type="text/plain" language="en" />
<itunes:keywords>pgp, openpgp, npm, javascript, dns, cname, researchers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, May 20th 2025: AutoIT Code RAT; Fake Keepass Download; Procolored Printer Software Compromise
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9458</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, May 20th 2025: AutoIT Code RAT; Fake Keepass Download; Procolored Printer Software Compromise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, May 20th 2025: AutoIT Code RAT; Fake Keepass Download; Procolored Printer Software Compromise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9458.mp3" length="5616581" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9458.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9458</link>
<pubDate>Tue, 20 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
RAT Dropped By Two Layers of AutoIT Code<br/>
 Xavier explains how AutoIT was used to install a remote admin tool (RAT) and how to analyse such a tool<br/>
<a href="https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960">https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960</a><br/>
RVTools compromise confirmed<br/>
Robware.net, the site behind the popular tool RVTools now confirmed that it was compromised. The site is currently offline.<br/>
<a href="https://www.robware.net/readMore">https://www.robware.net/readMore</a><br/>
Trojaned Version of Keepass used to install info stealer and Cobalt Strike beacon<br/>
 A backdoored version of KeePass was used to trick victims into installing Cobalt Strike and other malware. In this case, Keepass itself was not compromised and the malicious version was advertised via search engine optimization tricks<br/>
<a href="https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign">https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign</a><br/>
Procolored UV Printer Software Compromised<br/>
 The official software offered by the makers of the Procolored UV printer has been compromised, and versions with malware were distributed for about half a year.<br/>
<a href="https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3">https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3</a><br/>
<a href="https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads">https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9458" type="text/plain" language="en" />
<itunes:keywords>dynamic autoit, rvtools, keeppass, uv printer, procolored, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, May 18th 2025: xorsearch python functions; pwn2own Berlin; senior govt official impersonation; dynamic domain risk
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9456</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, May 18th 2025: xorsearch python functions; pwn2own Berlin; senior govt official impersonation; dynamic domain risk
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, May 18th 2025: xorsearch python functions; pwn2own Berlin; senior govt official impersonation; dynamic domain risk
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9456.mp3" length="5466240" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9456.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9456</link>
<pubDate>Mon, 19 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
xorsearch.py: Python Functions<br/>
Didier s xorsearch tool now supports python functions to filter output<br/>
<a href="https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858">https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858</a><br/>
Pwn2Own Berlin 2025<br/>
 Last weeks Pwn2Own contest in Berlin allowed researchers to demonstrate a number of new exploits with a large focus on privilege escalation and virtual machine escape.<br/>
<a href="https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results">https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results</a><br/>
Senior US Officials Impersonated in Malicious Messaging Campaign<br/>
The FBI warns of senior US officials being impersonated in text and voice messages.<br/>
<a href="https://www.ic3.gov/PSA/2025/PSA250515">https://www.ic3.gov/PSA/2025/PSA250515</a><br/>
Scattered Spider: TTP Evolution in 2025<br/>
Pushscurity provided an update on how Scattered Spider evolved. One thing they noted was that Scattered Spider takes advantage of legit dynamic domain name systems to make detection more difficult<br/>
<a href="https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/">https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9456" type="text/plain" language="en" />
<itunes:keywords>dynamic domains, it.com, vipshing, smishing, phishing, vmware, priviledge escalation, xorsearch, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, May 16th: Increase in Sonicwall Scans; RVTools Compromised?; RountPress
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9454</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, May 16th: Increase in Sonicwall Scans; RVTools Compromised?; RountPress
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, May 16th: Increase in Sonicwall Scans; RVTools Compromised?; RountPress
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9454.mp3" length="5413771" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9454.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9454</link>
<pubDate>Fri, 16 May 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Web Scanning SonicWall for CVE-2021-20016 - Update<br/>
 Scans for SonicWall increased by an order of magnitude over the last couple of weeks. Many of the attacks appear to originate from  Global Host , a low-cost virtual hosting provider.<br/>
<a href="https://isc.sans.edu/diary/Web%20Scanning%20SonicWall%20for%20CVE-2021-20016%20-%20Update/31952">https://isc.sans.edu/diary/Web%20Scanning%20SonicWall%20for%20CVE-2021-20016%20-%20Update/31952</a><br/>
Google Update Patches Exploited Chrome Flaw<br/>
 Google released an update for Chrome. The update fixes two specific flaws reported by external researchers, CVE-2025-4664 and CVE-2025-4609. The first flaw is already being exploited in the wild.<br/>
<a href="https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html">https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html</a><br/>
<a href="https://x.com/slonser_/status/1919439373986107814">https://x.com/slonser_/status/1919439373986107814</a><br/>
RVTools Bumblebee Malware Attack<br/>
Zerodaylabs published its analysis of the RV-Tools Backdoor attack. It suggests that this may not be solely a search engine optimization campaign directing victims to the malicious installer, but that the RVTools distribution site was compromised.<br/>
<a href="https://zerodaylabs.net/rvtools-bumblebee-malware/">https://zerodaylabs.net/rvtools-bumblebee-malware/</a><br/>
Operation RoundPress<br/>
ESET Security wrote up a report summarizing recent XSS attacks against open-source webmail systems<br/>
<a href="https://www.welivesecurity.com/en/eset-research/operation-roundpress/">https://www.welivesecurity.com/en/eset-research/operation-roundpress/</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9454" type="text/plain" language="en" />
<itunes:keywords>Roundpress, xss, rvtools, google, chrome, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, May 15th: Google Open Redirects; Adobe, Ivanti, and Samsung patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9452</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, May 15th: Google Open Redirects; Adobe, Ivanti, and Samsung patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, May 15th: Google Open Redirects; Adobe, Ivanti, and Samsung patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9452.mp3" length="5265782" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9452.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9452</link>
<pubDate>Thu, 15 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Another day, another phishing campaign abusing google.com open redirects<br/>
 Google s links from it s maps page to hotel listings do suffer from an open redirect vulnerability that is actively exploited to direct users to phishing pages.<br/>
<a href="https://isc.sans.edu/diary/Another%20day%2C%20another%20phishing%20campaign%20abusing%20google.com%20open%20redirects/31950">https://isc.sans.edu/diary/Another%20day%2C%20another%20phishing%20campaign%20abusing%20google.com%20open%20redirects/31950</a><br/>
Adobe Patches<br/>
Adobe patched 12 different applications. Of particular interest is the update to ColdFusion, which fixes several arbitrary code execution and arbitrary file read problems.<br/>
<a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Samsung Patches magicInfo 9 Again<br/>
Samsung released a new patch for the already exploited magicInfo 9 CMS vulnerability. While the description is identical to the patch released last August, a new CVE number is used.<br/>
<a href="https://security.samsungtv.com/securityUpdates#SVP-MAY-2025">https://security.samsungtv.com/securityUpdates#SVP-MAY-2025</a><br/>
Ivanti Patches Critical Ivanti Neurons Flaw<br/>
Ivanti released a patch for Ivanti Neurons for ITSM (on-prem only) fixing a critical authentication bypass vulnerability. Ivanti also points to its guidance to secure the underlying IIS server to make exploitation of flaws like this more difficult<br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9452" type="text/plain" language="en" />
<itunes:keywords>adobe, ivanti, samsung, google, open redirect, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, May 14th: Microsoft Patch Tuesday; 0-Days patched for Ivanti Endpoint Manager and Fortinet Products
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9450</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, May 14th: Microsoft Patch Tuesday; 0-Days patched for Ivanti Endpoint Manager and Fortinet Products
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, May 14th: Microsoft Patch Tuesday; 0-Days patched for Ivanti Endpoint Manager and Fortinet Products
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9450.mp3" length="5582137" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9450.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9450</link>
<pubDate>Wed, 14 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
Microsoft patched 70-78 vulnerabilities (depending on how you count them). Five of these vulnerabilities are already being exploited. In particular, a remote code execution vulnerability in the scripting engine should be taken seriously. It requires the Microsoft Edge browser to run in Internet Explorer mode.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20May%202025/31946">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20May%202025/31946</a><br/>
Security Advisory Ivanti Endpoint Manager Mobile (EPMM) May 2025 (CVE-2025-4427 and CVE-2025-4428)<br/>
Ivanti patched an authentication bypass vulnerability and a remote code execution vulnerability. The authentication bypass can exploit the remote code execution vulnerability without authenticating first.<br/>
<a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US</a><br/>
Fortinet Patches Exploited Vulnerability in API (CVE-2025-32756)<br/>
 Fortinet patched an already exploited stack-based buffer overflow vulnerability in the API of multiple Fortinet products. The vulnerability is exploited via crafted HTTP requests.<br/>
<a href="https://fortiguard.fortinet.com/psirt/FG-IR-25-254">https://fortiguard.fortinet.com/psirt/FG-IR-25-254</a><br/>
]]></description>
<itunes:duration>6:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9450" type="text/plain" language="en" />
<itunes:keywords>fortinet, ivanti, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, May 12th: Apple Patches; Unipi Technologies Scans; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9448</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, May 12th: Apple Patches; Unipi Technologies Scans; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, May 12th: Apple Patches; Unipi Technologies Scans; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9448.mp3" length="5458660" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9448.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9448</link>
<pubDate>Tue, 13 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Updates Everything<br/>
 Apple patched all of its operating systems. This update ports a patch for a recently exploited vulnerability to older versions of iOS and macOS.<br/>
<a href="https://isc.sans.edu/diary/31942">https://isc.sans.edu/diary/31942</a><br/>
It Is 2025, And We Are Still Dealing With Default IoT Passwords And Stupid 2013 Router Vulnerabilities<br/>
  Versions of the Mirai botnet are attacking devices made by Unipi Technology. These devices are using a specific username and password combination. In addition, this version of the Mirai botnet will also attempt exploits against an old Netgear vulnerability.<br/>
<a href="https://isc.sans.edu/diary/It%20Is%202025%2C%20And%20We%20Are%20Still%20Dealing%20With%20Default%20IoT%20Passwords%20And%20Stupid%202013%20Router%20Vulnerabilities/31940">https://isc.sans.edu/diary/It%20Is%202025%2C%20And%20We%20Are%20Still%20Dealing%20With%20Default%20IoT%20Passwords%20And%20Stupid%202013%20Router%20Vulnerabilities/31940</a><br/>
Output Messenger Vulnerability<br/>
 The internal messenger application  Output Messenger  is currently used in sophisticated attacks. Attackers are exploiting a path traversal vulnerability that has not been fixed.<br/>
<a href="https://www.outputmessenger.com/cve-2025-27920/">https://www.outputmessenger.com/cve-2025-27920/</a><br/>
Commvault Correction<br/>
 Commvault s patch indeed fixes the recent vulnerability. The  Pioneer Release  Will Dormann used to experiment will only offer patches after it has been registered, which leads to an error when assessing the patch s efficacy. <br/>
<a href="https://www.darkreading.com/application-security/commvault-patch-works-as-intended">https://www.darkreading.com/application-security/commvault-patch-works-as-intended</a><br/>
]]></description>
<itunes:duration>6:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9448" type="text/plain" language="en" />
<itunes:keywords>commvault, output messenger, mirai, unipi, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, May 11th: Steganography Challenge; End-of-Life Routers; ASUS Driverhub; RV-Tools SEO Poisoning
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9446</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, May 11th: Steganography Challenge; End-of-Life Routers; ASUS Driverhub; RV-Tools SEO Poisoning
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, May 11th: Steganography Challenge; End-of-Life Routers; ASUS Driverhub; RV-Tools SEO Poisoning
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9446.mp3" length="5591950" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9446.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9446</link>
<pubDate>Mon, 12 May 2025 01:42:54 GMT</pubDate>
<description><![CDATA[<br/>
Steganography Challenge<br/>
 Didier revealed the solution to last weekend s cryptography challenge. The image used the same encoding scheme as Didier described before, but the columns and rows were transposed.<br/>
 <a href="https://isc.sans.edu/forums/diary/Steganography%20Challenge%3A%20My%20Solution/31912/">https://isc.sans.edu/forums/diary/Steganography%20Challenge%3A%20My%20Solution/31912/</a><br/>
FBI Warns of End-of-life routers<br/>
 The FBI is tracking larger botnets taking advantage of unpatched routers. Many of these routers are end-of-life, and no patches are available for the exploited vulnerabilities. The attackers are turning the devices into proxies, which are resold for various criminal activities.<br/>
 <a href="https://www.ic3.gov/PSA/2025/PSA250507">https://www.ic3.gov/PSA/2025/PSA250507</a><br/>
ASUS Driverhub Vulnerability<br/>
 ASUS Driverhub software does not properly check the origin of HTTP requests, allowing a CSRF attack from any website leading to arbitrary code execution.<br/>
 <a href="https://mrbruh.com/asusdriverhub/">https://mrbruh.com/asusdriverhub/</a><br/>
RV-Tools SEO Poisoning <br/>
 Varonis Threat Labs observed SEO poisoning being used to trick system administrators into installing a malicious version of RV Tools. The malicious version includes a remote access tool leading to the theft of credentials<br/>
<a href="https://www.varonis.com/blog/seo-poisoning#initial-access-and-persistence">https://www.varonis.com/blog/seo-poisoning#initial-access-and-persistence</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9446" type="text/plain" language="en" />
<itunes:keywords>steganography, fbi, router, seq, rv-tools, asus, driverhub, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, May 9th: SSH Exfil Tricks; magicINFO still vulnerable; SentinelOne Vulnerability; Commvault insufficient patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9444</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, May 9th: SSH Exfil Tricks; magicINFO still vulnerable; SentinelOne Vulnerability; Commvault insufficient patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, May 9th: SSH Exfil Tricks; magicINFO still vulnerable; SentinelOne Vulnerability; Commvault insufficient patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9444.mp3" length="4158604" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9444.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9444</link>
<pubDate>Fri, 09 May 2025 03:35:13 GMT</pubDate>
<description><![CDATA[<br/>
No Internet Access: SSH to the Rescue<br/>
 If faced with restrictive outbound network access policies, a single inbound SSH connection can quickly be turned into a tunnel or a full-blown VPN<br/>
<a href="https://isc.sans.edu/diary/No%20Internet%20Access%3F%20SSH%20to%20the%20Rescue!/31932">https://isc.sans.edu/diary/No%20Internet%20Access%3F%20SSH%20to%20the%20Rescue!/31932</a><br/>
SAMSUNG magicINFO 9 Server Flaw Still exploitable<br/>
 The SAMSUNG magicINFO 9 Server Vulnerability we found being exploited last week is apparently still not completely patched, and current versions are vulnerable to the exploit observed in the wild.<br/>
<a href="https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw">https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw</a><br/>
Bring Your Own Installer: Bypassing SentinelOne Through Agent Version Change Interruption<br/>
SentinelOne s installer is vulnerable to an exploit allowing attackers to shut down the end point protection software<br/>
<a href="https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone">https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone</a><br/>
Commvault Still Exploitable<br/>
 A recent patch for Commvault is apparently ineffective and the PoC exploit published by watchTowr is still working against up to date patched systems<br/>
 <a href="https://infosec.exchange/@wdormann/114458913006792356">https://infosec.exchange/@wdormann/114458913006792356</a><br/>
]]></description>
<itunes:duration>4:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9444" type="text/plain" language="en" />
<itunes:keywords>commvault, patches, sentinelone, samung, magicinfo, ssh, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, May 8th: Modular Malware; Sysaid Vuln; Cisco Wireless Controller Patch; Unifi Protect Camera Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9442</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, May 8th: Modular Malware; Sysaid Vuln; Cisco Wireless Controller Patch; Unifi Protect Camera Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, May 8th: Modular Malware; Sysaid Vuln; Cisco Wireless Controller Patch; Unifi Protect Camera Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9442.mp3" length="4786152" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9442.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9442</link>
<pubDate>Thu, 08 May 2025 03:25:14 GMT</pubDate>
<description><![CDATA[<br/>
Example of Modular Malware<br/>
 Xavier analyzes modular malware that downloads DLLs from GitHub if specific features are required. In particular, the webcam module is inspected in detail. <br/>
<a href="https://isc.sans.edu/diary/Example%20of%20%22Modular%22%20Malware/31928">https://isc.sans.edu/diary/Example%20of%20%22Modular%22%20Malware/31928</a><br/>
Sysaid XXE Vulnerabilities<br/>
 IT Service Management Software Sysaid patched a number of XXE vulnerabilities. Without authentication, an attacker is able to obtain confidential data and completely compromise the system. watchTowr published a detailed analysis of the flaws including exploit code. <br/>
 <a href="https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/">https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/</a><br/>
Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability<br/>
 Cisco Patched a vulnerability in its wireless controller software that may be used to not only upload files but also execute code as root without authentication.<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC</a><br/>
Unifi Protect Camera Vulnerability<br/>
 Ubiquity patched a vulnerability in its Protect camera firmware fixing a buffer overflow flaw.<br/>
<a href="https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc">https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9442" type="text/plain" language="en" />
<itunes:keywords>unifi, protect, camera, ubiquity, cisco, wireless, sysaid, xxe, modular, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, May 7th: Infostealer with Webserver; Android Update; CISA Warning
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9440</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, May 7th: Infostealer with Webserver; Android Update; CISA Warning
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, May 7th: Infostealer with Webserver; Android Update; CISA Warning
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9440.mp3" length="5665840" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9440.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9440</link>
<pubDate>Wed, 07 May 2025 03:35:15 GMT</pubDate>
<description><![CDATA[<br/>
Python InfoStealer with Embedded Phishing Webserver<br/>
 Didier found an interesting infostealer that, in addition to implementing typical infostealer functionality, includes a web server suitable to create local phishing sites.<br/>
<a href="https://isc.sans.edu/diary/Python%20InfoStealer%20with%20Embedded%20Phishing%20Webserver/31924">https://isc.sans.edu/diary/Python%20InfoStealer%20with%20Embedded%20Phishing%20Webserver/31924</a><br/>
Android Update Fixes Freetype 0-Day<br/>
 Google released its monthly Android update. As part of the update, it patched a vulnerability in Freetype that is already being exploited. Android is not alone in using Freetype. Freetype is a very commonly used library to parse fonts like Truetype fonts.<br/>
<a href="https://source.android.com/docs/security/bulletin/2025-05-01">https://source.android.com/docs/security/bulletin/2025-05-01</a><br/>
CISA Warns of Unsophistacted Cyber Actors<br/>
 CISA released an interesting title report warning operators of operational technology networks of ubiquitous attacks by unsophisticated actors. It emphasizes how important it is to not forget basic security measures to defend against these attacks.<br/>
<a href="https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology">https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9440" type="text/plain" language="en" />
<itunes:keywords>python, infostealer, phishing, webserver, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, May 6th: Mirai Exploiting Samsung magicInfo 9; Kali Signing Key Lost;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9438</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, May 6th: Mirai Exploiting Samsung magicInfo 9; Kali Signing Key Lost;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, May 6th: Mirai Exploiting Samsung magicInfo 9; Kali Signing Key Lost;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9438.mp3" length="5842935" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9438.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9438</link>
<pubDate>Tue, 06 May 2025 03:20:14 GMT</pubDate>
<description><![CDATA[<br/>
Mirai Now Exploits Samsung MagicINFO CMS CVE-2024-7399<br/>
 The Mirai botnet added a new vulnerability to its arsenal. This vulnerability, a file upload and remote code execution vulnerability in Samsung s MagicInfo 9 CMS, was patched last August but attracted new attention last week after being mostly ignored so far.<br/>
<a href="https://isc.sans.edu/diary/Mirai+Now+Exploits+Samsung+MagicINFO+CMS+CVE20247399/31920">https://isc.sans.edu/diary/Mirai+Now+Exploits+Samsung+MagicINFO+CMS+CVE20247399/31920</a><br/>
New Kali Linux Signing Key<br/>
 The Kali Linux maintainers lost access to the secret key used to sign packages. Users must install a new key that will be used going forward.<br/>
<a href="https://www.kali.org/blog/new-kali-archive-signing-key/">https://www.kali.org/blog/new-kali-archive-signing-key/</a><br/>
The Risk of Default Configuration: How Out-of-the-Box Helm Charts Can Breach Your Cluster<br/>
 Many out-of-the-box Helm charts for Kubernetes applications deploy vulnerable configurations with exposed ports and no authentication<br/>
<a href="https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-risk-of-default-configuration-how-out-of-the-box-helm-charts-can-breach-your/4409560">https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-risk-of-default-configuration-how-out-of-the-box-helm-charts-can-breach-your/4409560</a><br/>
]]></description>
<itunes:duration>6:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9438" type="text/plain" language="en" />
<itunes:keywords>kali, linux, mirai, helm, kubernetes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, May 5th: Steganography Challenge; Microsoft Makes Passkeys Default and Moves Away from Authenticator as Password Manager; Magento Components Backdoored.
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9436</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, May 5th: Steganography Challenge; Microsoft Makes Passkeys Default and Moves Away from Authenticator as Password Manager; Magento Components Backdoored.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, May 5th: Steganography Challenge; Microsoft Makes Passkeys Default and Moves Away from Authenticator as Password Manager; Magento Components Backdoored.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9436.mp3" length="5006050" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9436.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9436</link>
<pubDate>Mon, 05 May 2025 03:50:16 GMT</pubDate>
<description><![CDATA[<br/>
Steganography Challenge<br/>
 Didier published a fun steganography challenge. A solution will be offered on Saturday.<br/>
<a href="https://isc.sans.edu/diary/Steganography+Challenge/31910">https://isc.sans.edu/diary/Steganography+Challenge/31910</a><br/>
Microsoft Makes Passkeys Default Authentication Method<br/>
 Microsoft is now encouraging new users to use Passkeys as the  default  and only login method, further moving away from passwords<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/">https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/</a><br/>
Microsoft Authenticator Autofill Changes<br/>
 Microsoft will no longer support the use of Microsoft authenticator as a password safe. Instead, it will move users to the password prefill feature built into Microsoft Edge. This change will start in June and should be completed in August at which point you must have moved your credentials out of Microsoft Authenticator <br/>
<a href="https://support.microsoft.com/en-gb/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6">https://support.microsoft.com/en-gb/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6</a><br/>
Backdoor found in popular e-commerce components<br/>
 SANSEC identified several backdoored Magento e-commerce components. These backdoors were installed as far back as 2019 but only recently activated, at which point they became known. Affected vendors dispute any compromise at this point.<br/>
<a href="https://sansec.io/research/license-backdoor">https://sansec.io/research/license-backdoor</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9436" type="text/plain" language="en" />
<itunes:keywords>backdoor, magento, msft, authenticator, passkeys, stegaonography, challenge, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, May 2nd: More Steganography; Malicious Python Packages GMail C2; BEC to Steal Rent Payments
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9434</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, May 2nd: More Steganography; Malicious Python Packages GMail C2; BEC to Steal Rent Payments
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, May 2nd: More Steganography; Malicious Python Packages GMail C2; BEC to Steal Rent Payments
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9434.mp3" length="6104701" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9434.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9434</link>
<pubDate>Fri, 02 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Steganography Analysis With pngdump.py: Bitstreams<br/>
 More details from Didiear as to how to extract binary content hidden inside images<br/>
<a href="https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904">https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904</a><br/>
Using Trusted Protocols Against You: Gmail as a C2 Mechanism<br/>
 Attackers are using typosquatting to trick developers into installing malicious python packages. These python packages will use GMail as a command and control channel by sending email to hard coded GMail accounts<br/>
<a href="https://socket.dev/blog/using-trusted-protocols-against-you-gmail-as-a-c2-mechanism">https://socket.dev/blog/using-trusted-protocols-against-you-gmail-as-a-c2-mechanism</a><br/>
Security Brief: French BEC Threat Actor Targets Property Payments<br/>
A French business email compromise threat actor is targeting property management firms to send emails to tenents tricking them into sending rent payments to fake bank accounts<br/>
<a href="https://www.proofpoint.com/us/blog/threat-insight/security-brief-french-bec-threat-actor-targets-property-payments">https://www.proofpoint.com/us/blog/threat-insight/security-brief-french-bec-threat-actor-targets-property-payments</a><br/>
SANS.edu Research Journal<br/>
 <a href="https://isc.sans.edu/j/research">https://isc.sans.edu/j/research</a><br/>
]]></description>
<itunes:duration>7:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9434" type="text/plain" language="en" />
<itunes:keywords>Steganograpy, Research Journal, bec, tenants, rent, gmail, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, May 1st: Sonicwall Attacks; Cached Windows RDP Credentials
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9432</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, May 1st: Sonicwall Attacks; Cached Windows RDP Credentials
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, May 1st: Sonicwall Attacks; Cached Windows RDP Credentials
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9432.mp3" length="5442102" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9432.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9432</link>
<pubDate>Thu, 01 May 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Web Scanning for Sonicwall Vulnerabilities CVE-2021-20016<br/>
 For the last week, scans for Sonicwall API  login  and  domain  endpoints have skyrocketed. These attacks may be exploiting an older vulnerability or just attempting to brute force credentials.<br/>
<a href="https://isc.sans.edu/diary/Web%20Scanning%20Sonicwall%20for%20CVE-2021-20016/31906">https://isc.sans.edu/diary/Web%20Scanning%20Sonicwall%20for%20CVE-2021-20016/31906</a><br/>
The Wizards APT Group SLAAC Spoofing Adversary in the Middle Attacks<br/>
 ESET published an article with details regarding an IPv6-linked attack they have observed. Attackers use router advertisements to inject fake recursive DNS servers that are used to inject IP addresses for hostnames used to update software. This leads to the victim downloading malware instead of legitimate updates.<br/>
<a href="https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/">https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/</a><br/>
Windows RDP Access is Possible with Old Credentials<br/>
 Credential caching may lead to Windows allowing RDP logins with old credentials.<br/>
<a href="https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/?comments-page=1#comments">https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/?comments-page=1#comments</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9432" type="text/plain" language="en" />
<itunes:keywords>Sonicwall, Windows, RDP, SLAAC, IPv6, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, April 30th: SMS Attacks; Apple Airplay Vulnerabilities
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9430</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, April 30th: SMS Attacks; Apple Airplay Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, April 30th: SMS Attacks; Apple Airplay Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9430.mp3" length="7440736" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9430.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9430</link>
<pubDate>Wed, 30 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
More Scans for SMS Gateways and APIs<br/>
 Attackers are not just looking for SMS Gateways like the scans we reported on last week, but they are also actively scanning for other ways to use APIs and add on tools to send messages using other people s credentials.<br/>
<a href="https://isc.sans.edu/diary/More%20Scans%20for%20SMS%20Gateways%20and%20APIs/31902">https://isc.sans.edu/diary/More%20Scans%20for%20SMS%20Gateways%20and%20APIs/31902</a><br/>
AirBorne: AirPlay Vulnerabilities<br/>
 Researchers at Oligo revealed over 20 weaknesses they found in Apple s implementation of the AirPlay protocol. These vulnerabilities can be abused to execute code or launch denial-of-service attacks against affected devices. Apple patched the vulnerabilities in recent updates.<br/>
<a href="https://www.oligo.security/blog/airborne">https://www.oligo.security/blog/airborne</a><br/>
]]></description>
<itunes:duration>8:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9430" type="text/plain" language="en" />
<itunes:keywords>SMS, Airplay, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, April 29th: SRUM-DUMP 3; Policy Puppetry; Choice Jacking; @sansinstitute at #RSAC
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9428</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, April 29th: SRUM-DUMP 3; Policy Puppetry; Choice Jacking; @sansinstitute at #RSAC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, April 29th: SRUM-DUMP 3; Policy Puppetry; Choice Jacking; @sansinstitute at #RSAC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9428.mp3" length="6405917" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9428.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9428</link>
<pubDate>Tue, 29 Apr 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
SRUM-DUMP Version 3: Uncovering Malware Activity in Forensics<br/>
  Mark Baggett released SRUM-DUMP Version 3. The tool simplifies data extraction from Widnows  System Resource Usage Monitor (SRUM). This database logs how much resources software used for 30 days, and is invaluable to find out what software was executed when and if it sent or received network data.<br/>
<a href="https://isc.sans.edu/diary/SRUM-DUMP%20Version%203%3A%20Uncovering%20Malware%20Activity%20in%20Forensics/31896">https://isc.sans.edu/diary/SRUM-DUMP%20Version%203%3A%20Uncovering%20Malware%20Activity%20in%20Forensics/31896</a><br/>
Novel Universal Bypass For All Major LLMS<br/>
  Hidden Layer discovered a new prompt injection technique that bypasses security constraints in large language models.<br/>
The technique uses an XML formatted prequel for a prompt, which appears to the LLM as a policy file. This  Policy Puppetry  can be used to rewrite some of the security policies configured for LLMs. Unlike other techniques, this technique works across multiple LLMs without changing the policy.<br/>
<a href="https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/">https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/</a><br/>
CHOICEJACKING: Compromising Mobile Devices through Malicious Chargers like a Decade ago<br/>
 The old  Juice Jacking  is back, at least if you do not run the latest version of Android or iOS. This issue may allow a malicious USB device, particularly a USB charger, to take control of a device connected to it.<br/>
<a href="https://pure.tugraz.at/ws/portalfiles/portal/89650227/Final_Paper_Usenix.pdf">https://pure.tugraz.at/ws/portalfiles/portal/89650227/Final_Paper_Usenix.pdf</a><br/>
SANS @RSA: <a href="https://www.sans.org/mlp/rsac/">https://www.sans.org/mlp/rsac/</a><br/>
]]></description>
<itunes:duration>7:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9428" type="text/plain" language="en" />
<itunes:keywords>SRUM, windows, forensics, llms, policy, puppetry, choice jacking, usb, chargers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, April 28th: Image Steganography; SAP Netweaver Exploited
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9426</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, April 28th: Image Steganography; SAP Netweaver Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, April 28th: Image Steganography; SAP Netweaver Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9426.mp3" length="6658743" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9426.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9426</link>
<pubDate>Mon, 28 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Example of a Payload Delivered Through Steganography<br/>
 Xavier and Didier published two diaries this weekend, building on each other. First, Xavier showed an example of an image being used to smuggle an executable past network defenses, and second, Didier showed how to use his tools to extract the binary.<br/>
<a href="https://isc.sans.edu/diary/Example%20of%20a%20Payload%20Delivered%20Through%20Steganography/31892">https://isc.sans.edu/diary/Example%20of%20a%20Payload%20Delivered%20Through%20Steganography/31892</a><br/>
SAP Netweaver Exploited CVE-2025-31324 <br/>
  An arbitrary file upload vulnerability in SAP s Netweaver product is actively exploited to upload webshells. Reliaquest discovered the issue. Reliaquest reports that they saw it being abused to upload the Brute Ratel C2 framework. Users of Netweaver must turn off the developmentserver alias and disable visual composer, and the application was deprecated for about 10 years. SAP has released an emergency update for the issue.<br/>
<a href="https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/">https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/</a><br/>
<a href="https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/">https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/</a><br/>
Any.Run Reports False Positive Uploads<br/>
 Due to false positives caused by MS Defender XDR flagging Adobe Acrobat Cloud links as malicious, many users of Any.Run s free tier uploaded confidential documents to Any.Run. Anyrun blocked these uploads for now but reminded users to be cautious about what documents are being uploaded.<br/>
<a href="https://x.com/anyrun_app/status/1915429758516560190">https://x.com/anyrun_app/status/1915429758516560190</a><br/>
]]></description>
<itunes:duration>7:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9426" type="text/plain" language="en" />
<itunes:keywords>any.run, adobe, xdr, microsoft, sap, netweaver, steganography, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, April 25th: SMS Gateway Scans; Comvault Exploit; Patch Window Shrinkage; More inetpub issues;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9424</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, April 25th: SMS Gateway Scans; Comvault Exploit; Patch Window Shrinkage; More inetpub issues;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, April 25th: SMS Gateway Scans; Comvault Exploit; Patch Window Shrinkage; More inetpub issues;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9424.mp3" length="5579068" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9424.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9424</link>
<pubDate>Fri, 25 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Attacks against Teltonika Networks SMS Gateways<br/>
  Attackers are actively scanning for SMS Gateways. These attacks take advantage of default passwords and other commonly used passwords. <br/>
 <a href="https://isc.sans.edu/diary/Attacks%20against%20Teltonika%20Networks%20SMS%20Gateways/31888">https://isc.sans.edu/diary/Attacks%20against%20Teltonika%20Networks%20SMS%20Gateways/31888</a><br/>
Commvault Vulnerability CVE-2205-34028<br/>
 Commvault, about a week ago, published an advisory and a fix for a vulnerability in its backup software. watchTowr now released a detailed writeup and exploit for the vulnerability<br/>
<a href="https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/">https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/</a><br/>
Exploitation Trends Q1 2025<br/>
 Vulncheck published a summary of exploitation trends, pointing out that about a quarter of vulnerabilities are exploited a day after a patch is made available.<br/>
<a href="https://vulncheck.com/blog/exploitation-trends-q1-2025">https://vulncheck.com/blog/exploitation-trends-q1-2025</a><br/>
inetpub directory issues<br/>
 The inetpub directory introduced by Microsoft in its April patch may lead to a denial of service against applying patches on Windows if an attacker can create a junction for that location pointing to an existing system binary like Notepad.<br/>
<a href="https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741">https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741</a><br/>
]]></description>
<itunes:duration>6:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9424" type="text/plain" language="en" />
<itunes:keywords>inetpub, vulncheck, patches, watchTowr, teltonika, sms, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday, April 24th: Honeypot iptables Maintenance; XRPL.js Compromise; Erlang/OTP SSH Vuln affecting Cisco
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9422</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday, April 24th: Honeypot iptables Maintenance; XRPL.js Compromise; Erlang/OTP SSH Vuln affecting Cisco
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday, April 24th: Honeypot iptables Maintenance; XRPL.js Compromise; Erlang/OTP SSH Vuln affecting Cisco
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9422.mp3" length="4823630" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9422.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9422</link>
<pubDate>Thu, 24 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Honeypot Iptables Maintenance and DShield-SIEM Logging<br/>
 In this diary, Jesse is talking about some of the tasks to maintain a honeypot, like keeping filebeats up to date and adjusting configurations in case your dynamic IP address changes<br/>
<a href="https://isc.sans.edu/diary/Honeypot%20Iptables%20Maintenance%20and%20DShield-SIEM%20Logging/31876">https://isc.sans.edu/diary/Honeypot%20Iptables%20Maintenance%20and%20DShield-SIEM%20Logging/31876</a><br/>
XRPL.js Compromised<br/>
 An unknown actor was able to push malicious updates of the XRPL.js library to NPM. The library is officially recommended for writing Riple (RPL) cryptocurrency code. The malicious library exfiltrated secret keys to the attacker<br/>
<a href="https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor">https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor</a><br/>
<a href="https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx">https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx</a><br/>
Cisco Equipment Affected by Erlang/OTP SSH Vulnerability<br/>
 Cisco published an advisory explaining which of its products are affected by the critical Erlang/OTP SSH library vulnerability<br/>
<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9422" type="text/plain" language="en" />
<itunes:keywords>SIEM, filebeats, iptables, honeypot, ripl, xrp, supply chain, npm, erlang/otp, erlang, ssh, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, April 23rd: More xorsearch Updates; DKIM Replay Attack; SSL.com Vulnerability Fixed
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9420</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, April 23rd: More xorsearch Updates; DKIM Replay Attack; SSL.com Vulnerability Fixed
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, April 23rd: More xorsearch Updates; DKIM Replay Attack; SSL.com Vulnerability Fixed
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9420.mp3" length="5291512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9420.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9420</link>
<pubDate>Wed, 23 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
xorsearch.py: Ad Hoc YARA Rules<br/>
  Adhoc YARA rules allow for easy searches using command line arguments without having to write complete YARA rules for simple use cases like string and regex searches<br/>
<a href="https://isc.sans.edu/diary/xorsearch.py%3A%20%22Ad%20Hoc%20YARA%20Rules%22/31856">https://isc.sans.edu/diary/xorsearch.py%3A%20%22Ad%20Hoc%20YARA%20Rules%22/31856</a><br/>
Google Spoofed via DKIM Replay Attack<br/>
 DKIM replay attacks are a known issue where the attacker re-uses a prior DKIM signature. This will work as long as the headers signed by the signature are unchanged. Recently, this attack has been successful against Google.<br/>
<a href="https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/">https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/</a><br/>
SSL.com E-Mail Validation Bug<br/>
 SSL.com did not properly verify which domain a particular email address is authorized to receive certificates for. This could have been exploited against webmail providers.<br/>
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1961406">https://bugzilla.mozilla.org/show_bug.cgi?id=1961406</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9420" type="text/plain" language="en" />
<itunes:keywords>dmarc, dkim, google, replay, ad-hoc, yara, xorsearch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, April 22nd: Phishing via Google; ChatGPT Fingerprint; Asus AI Cloud Vuln; PyTorch RCE
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9418</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, April 22nd: Phishing via Google; ChatGPT Fingerprint; Asus AI Cloud Vuln; PyTorch RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, April 22nd: Phishing via Google; ChatGPT Fingerprint; Asus AI Cloud Vuln; PyTorch RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9418.mp3" length="4695314" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9418.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9418</link>
<pubDate>Tue, 22 Apr 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
It's 2025, so why are malicious advertising URLs still going strong?<br/>
  Phishing attacks continue to take advantage of Google s advertising services. Sadly, this is still the case for obviously malicious links, even after various anti-phishing services flag the URL.<br/>
<a href="https://isc.sans.edu/diary/It%27s%202025...%20so%20why%20are%20obviously%20malicious%20advertising%20URLs%20still%20going%20strong%3F/31880">https://isc.sans.edu/diary/It%27s%202025...%20so%20why%20are%20obviously%20malicious%20advertising%20URLs%20still%20going%20strong%3F/31880</a><br/>
ChatGPT Fingerprinting Documents via Unicode<br/>
 ChatGPT apparently started leaving fingerprints in texts, which it creates by adding invisible Unicode characters like non-breaking spaces.<br/>
<a href="https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text">https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text</a><br/>
Asus AI Cloud Security Advisory<br/>
 Asus warns of a remote code execution vulnerability in its routers. The vulnerability is related to the AI Cloud feature. If your router is EoL, disabling the feature will mitigate the vulnerability<br/>
<a href="https://www.asus.com/content/asus-product-security-advisory/">https://www.asus.com/content/asus-product-security-advisory/</a><br/>
PyTorch Vulnerability<br/>
 PyTorch fixed a remote code execution vulnerability exploitable if a malicious model was loaded. This issue was exploitable even with the  weight_only=True" setting selected<br/>
<a href="https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6">https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9418" type="text/plain" language="en" />
<itunes:keywords>pytorch, ai cloud, asus, phishing, google, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, April 21st: MSFT Entra Lockouts; Erlang/OTP SSH Exploit; Sonicwall Exploit; bubble.io bug
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9416</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, April 21st: MSFT Entra Lockouts; Erlang/OTP SSH Exploit; Sonicwall Exploit; bubble.io bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, April 21st: MSFT Entra Lockouts; Erlang/OTP SSH Exploit; Sonicwall Exploit; bubble.io bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9416.mp3" length="6319436" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9416.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9416</link>
<pubDate>Mon, 21 Apr 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Entra User Lockout<br/>
 Multiple organizations reported widespread alerts and account lockouts this weekend from Microsoft Entra. The issue is caused by a new feature Microsoft enabled. This feature will lock accounts if Microsoft believes that the password for the account was compromised.<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/">https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/</a><br/>
<a href="https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability">https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability</a><br/>
Erlang/OTP SSH Exploit<br/>
 An exploit was published for the Erlang/OTP SSH vulnerability. The vulnerability is easy to exploit, and the exploit and a Metasploit module allow for easy remote code execution.<br/>
<a href="https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb">https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb</a><br/>
Sonicwall Exploited<br/>
 An older command injection vulnerability is now exploited on Sonicwall devices after initially gaining access by brute-forcing credentials.<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022</a><br/>
Unpatched Vulnerability in Bubble.io<br/>
 An unpatched vulnerability in the no-code platform bubble.io can be used to access any project hosted on the site.<br/>
<a href="https://github.com/demon-i386/pop_n_bubble">https://github.com/demon-i386/pop_n_bubble</a><br/>
]]></description>
<itunes:duration>7:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9416" type="text/plain" language="en" />
<itunes:keywords>bubble, no-code, bubble.io, sonicwall, ssh, erlang, microsoft, entra, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Backdoor Analysis; GPT 4.1 Safety Controversy
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9414</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Backdoor Analysis; GPT 4.1 Safety Controversy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Backdoor Analysis; GPT 4.1 Safety Controversy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9414.mp3" length="5302894" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9414.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9414</link>
<pubDate>Fri, 18 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
RedTail: Remnux and Malware Management<br/>
 A description showing how to set up a malware analysis in the cloud with Remnux and Kasm. RedTail is a sample to illustrate how the environment can be used.<br/>
<a href="https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868">https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868</a><br/>
Critical Erlang/OTP SSH Vulnerability<br/>
 Researchers identified a critical vulnerability in the Erlang/OTP SSH library. Due to this vulnerability, SSH servers written in Erlang/OTP allow arbitrary remote code execution without prior authentication<br/>
<a href="https://www.openwall.com/lists/oss-security/2025/04/16/2">https://www.openwall.com/lists/oss-security/2025/04/16/2</a><br/>
Brickstorm Analysis<br/>
 An analysis of a recent instance of the Brickstorm backdoor. This backdoor used to be more known for infecting Linux systems, but now it also infects Windows.<br/>
<a href="https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor">https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor</a><br/>
<a href="https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf">https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf</a><br/>
OpenAI GPT 4.1 Controversy<br/>
 OpenAI released its latest model, GPT 4.1, without a safety report and guardrails to prevent malware creation.<br/>
<a href="https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report">https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9414" type="text/plain" language="en" />
<itunes:keywords>openai, safety, malware, brickstorm, erlang, ssh, redtail, kasm, docker, container, aws, remnux, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday April 17th: Apple Updates; Oracle Updates; Google Chrome Updates; CVE News;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9412</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday April 17th: Apple Updates; Oracle Updates; Google Chrome Updates; CVE News;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday April 17th: Apple Updates; Oracle Updates; Google Chrome Updates; CVE News;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9412.mp3" length="5105560" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9412.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9412</link>
<pubDate>Thu, 17 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Updates<br/>
 Apple released updates for iOS, iPadOS, macOS, and VisionOS. The updates fix two vulnerabilities which had already been exploited against iOS.<br/>
<a href="https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866">https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866</a><br/>
Oracle Updates<br/>
 Oracle released it quarterly critical patch update. The update addresses 378 security vulnerabilities. Many of the critical updates are already known vulnerabilities in open-source software like Apache and Nginx ingress.<br/>
<a href="https://www.oracle.com/security-alerts/cpuapr2025.html">https://www.oracle.com/security-alerts/cpuapr2025.html</a><br/>
Oracle Breach Guidance<br/>
 CISA released guidance for users affected by the recent Oracle cloud breach. The guidance focuses on the likely loss of passwords.<br/>
<a href="https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise">https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise</a><br/>
Google Chrome Update<br/>
 A Google Chrome update released today fixes two security vulnerabilities. One of the vulnerabilities is rated as critical.<br/>
<a href="https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html">https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html</a><br/>
CVE Updates<br/>
 CISA extended MITRE s funding to operate the CVE numbering scheme. However, a number of other organizations announced that they may start alternative vulnerability registers.<br/>
<a href="https://euvd.enisa.europa.eu/">https://euvd.enisa.europa.eu/</a><br/>
<a href="https://gcve.eu/">https://gcve.eu/</a><br/>
<a href="https://www.thecvefoundation.org/">https://www.thecvefoundation.org/</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9412" type="text/plain" language="en" />
<itunes:keywords>cve, cisa, mitre, chrome, google, oracle, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Apr 16th: File Upload Service Abuse; OpenSSH 10.0 Released; Apache Roller Vuln; Possible CVE Changes
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9410</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Apr 16th: File Upload Service Abuse; OpenSSH 10.0 Released; Apache Roller Vuln; Possible CVE Changes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Apr 16th: File Upload Service Abuse; OpenSSH 10.0 Released; Apache Roller Vuln; Possible CVE Changes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9410.mp3" length="4963285" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9410.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9410</link>
<pubDate>Wed, 16 Apr 2025 00:48:11 GMT</pubDate>
<description><![CDATA[<br/>
Online Services Again Abused to Exfiltrate Data<br/>
 Attackers like to abuse free online services that can be used to exfiltrate data. From the  originals , like pastebin,<br/>
to past favorites like anonfiles.com. The latest example is gofile.io. As a defender, it is important to track these services to detect exfiltration early<br/>
<a href="https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862">https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862</a><br/>
OpenSSH 10.0 Released<br/>
 OpenSSH 10.0 was released. This release adds quantum-safe ciphers and the separation of authentication services into a separate binary to reduce the authentication attack surface.<br/>
<a href="https://www.openssh.com/releasenotes.html#10.0p1">https://www.openssh.com/releasenotes.html#10.0p1</a><br/>
Apache Roller Vulnerability<br/>
 Apache Roller addressed a vulnerability. Its CVSS score of 10.0 appears inflated, but it is still a vulnerability you probably want to address.<br/>
<a href="https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f">https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f</a><br/>
CVE Funding Changes<br/>
 Mitre s government contract to operate the CVE system may run out tomorrow. This could lead to a temporary disruption of services, but the system is backed by a diverse board of directors representing many large companies. It is possible that non-government funding sources may keep the system afloat for now.<br/>
<a href="https://www.cve.org/">https://www.cve.org/</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9410" type="text/plain" language="en" />
<itunes:keywords>cve, mitre, apache, roller, openssh, gofile, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday April 15th: xorsearch Update; Short Lived Certificates; New USB Malware
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9408</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday April 15th: xorsearch Update; Short Lived Certificates; New USB Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday April 15th: xorsearch Update; Short Lived Certificates; New USB Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9408.mp3" length="4695226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9408.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9408</link>
<pubDate>Tue, 15 Apr 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
xorsearch Update<br/>
 Diedier updated his "xorsearch" tool. It is now a python script, not a compiled binary, and supports Yara signatures. With Yara support also comes support for regular expressions.<br/>
<a href="https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854">https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854</a><br/>
Shorter Lived Certificates<br/>
 The CA/Brower Forum passed an update to reduce the maximum livetime of<br/>
certificates. The reduction will be implemented over the next four years. EFF also released an update to certbot introducing  profiles that can be used to request shorter lived certificates.<br/>
<a href="https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs">https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs</a><br/>
<a href="https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI">https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI</a><br/>
New Malware Harvesting Data from USB drives and infecting them.<br/>
 Kaspersky is reporting that they identified new malware that not only harvests data from USB drives, but also spread via USB drives by replacing existing documents with malicious files.<br/>
 <a href="https://securelist.com/goffee-apt-new-attacks/116139/">https://securelist.com/goffee-apt-new-attacks/116139/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9408" type="text/plain" language="en" />
<itunes:keywords>goffee, usb, malware, russia, kaspersky, certificates, certbot, eff, xorsearch, yara, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday April 14th: Langlow AI Attacks; Fortinet Attack Cleanup; MSFT Inetpub; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9406</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday April 14th: Langlow AI Attacks; Fortinet Attack Cleanup; MSFT Inetpub; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday April 14th: Langlow AI Attacks; Fortinet Attack Cleanup; MSFT Inetpub; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9406.mp3" length="5985428" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9406.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9406</link>
<pubDate>Mon, 14 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248)<br/>
 After spotting individaul attempts to exploit the recent Langflow vulnerability late last weeks, we now see more systematic internet wide scans attempting to verify the vulnerability.<br/>
<a href="https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/">https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/</a><br/>
Fortinet Analysis of Threat Actor Activity<br/>
 Fortinet oberved recent vulnerablities in its devices being used to add a symlink to ease future compromise. The symlink is not removed by prior patches, and Fortinet released additional updates to detect and remove this attack artifact.<br/>
<a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity">https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity</a><br/>
MSFT Inetpub<br/>
 Microsoft clarrified that its April patches created the inetpub directory on purpose. Users should not remove it.<br/>
<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability</a><br/>
SANSFIRE<br/>
 <a href="https://isc.sans.edu/j/sansfire">https://isc.sans.edu/j/sansfire</a><br/>
]]></description>
<itunes:duration>7:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9406" type="text/plain" language="en" />
<itunes:keywords>sansfire, inetpub, fortinet, langflow, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday April 11th: Network Infraxploit; Windows Hello Broken; Dell Update; Langflow Exploit
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9404</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday April 11th: Network Infraxploit; Windows Hello Broken; Dell Update; Langflow Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday April 11th: Network Infraxploit; Windows Hello Broken; Dell Update; Langflow Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9404.mp3" length="4688121" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9404.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9404</link>
<pubDate>Fri, 11 Apr 2025 09:48:22 GMT</pubDate>
<description><![CDATA[<br/>
Network Infraxploit<br/>
 Our undergraduate intern, Matthew Gorman, wrote up a walk through of<br/>
 CVE-2018-0171, an older Cisco vulnerability, that is still actively being<br/>
 exploited. For example, VOLT TYPHOON recently exploited this problem.<br/>
 <a href="https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844">https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844</a><br/>
Windows Update Issues / Windows 10 Update<br/>
 Microsoft updated its "Release Health" notes with details regarding issues<br/>
 users experiences with Windows Hello, Citrix, and Roblox. Microsoft also released an emergency update for Office 2016 which has stability problems after applying the most recent update.<br/>
<a href="https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb">https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb</a><br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521</a><br/>
 <a href="https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5">https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5</a><br/>
Dell Updates<br/>
 Dell releases critical updates for it's Powerscale One FS product. In particular, it fixes a default password problem.<br/>
 <a href="https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities">https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities</a><br/>
Langflow Vulnerablity (possible exploit scans sighted) CVE-2025-3248<br/>
 Langflow addressed a critical vulnerability end of March. This writeup by Horizon3 demonstrates how the issue is possibly exploited. We have so far seen one "hit" in our honeypot logs for the vulnerable API endpoint URL.<br/>
 <a href="https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/">https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9404" type="text/plain" language="en" />
<itunes:keywords>langfow, dell, windows, updates, infraxploit, cisco, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast ThursdayApril 10th: Getting Past PyArmor; CenterStack RCE; Android 0-Day Patch; VMware Tanzu Patches; Odd Win11 Directory; WhatsApp File Confusion; SANS AI Guide;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9402</itunes:episode>
<itunes:subtitle>SANS Stormcast ThursdayApril 10th: Getting Past PyArmor; CenterStack RCE; Android 0-Day Patch; VMware Tanzu Patches; Odd Win11 Directory; WhatsApp File Confusion; SANS AI Guide;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast ThursdayApril 10th: Getting Past PyArmor; CenterStack RCE; Android 0-Day Patch; VMware Tanzu Patches; Odd Win11 Directory; WhatsApp File Confusion; SANS AI Guide;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9402.mp3" length="5542925" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9402.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9402</link>
<pubDate>Thu, 10 Apr 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Getting Past PyArmor<br/>
  PyArmor is a python obfuscation tool used for malicious and non-malicious software. Xavier is taking a look at a sample to show what can be learned from these obfuscated samples with not too much work. <br/>
<a href="https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840">https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840</a><br/>
CenterStack RCE CVE-2025-30406<br/>
 Gladinet s CenterStack secure file-sharing software suffers from an inadequately protected machine key vulnerability that can be used to modify ViewState data. This vulnerability may lead to remote code execution, which is already exploited.<br/>
<a href="https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf">https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf</a><br/>
Google Patches two zero-day vulnerabilities CVE-2024-53150 CVE-2024-53197<br/>
 Google released its monthly patches for Android. Two of the patched vulnerabilities are already exploited. One of them was used by Serbian law enforcement.<br/>
 <a href="https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android">https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android</a><br/>
Broadcom VMWare Tenzu Updates<br/>
 Broadcom released updates for VMWare Tenzu. Many vulnerabilities affect the backup component and allow for arbitrary command execution.<br/>
  <a href="https://support.broadcom.com/web/ecx/security-advisory?">https://support.broadcom.com/web/ecx/security-advisory?</a><br/>
Windows 11 April Update ads inetpub directory<br/>
 The April Windows 11 update appears to create a new /inetpub directory. It is unclear why, and removing it appears to have no bad effects.<br/>
<a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/">https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/</a><br/>
WhatsApp File Type Confusion/Spoofing<br/>
 WhatsApp patched a file type confusion vulnerability. A victim may be tricked into downloading n<br/>
<a href="https://www.whatsapp.com/security/advisories/2025/">https://www.whatsapp.com/security/advisories/2025/</a><br/>
SANS Critical AI Security Guidelines<br/>
<a href="https://www.sans.org/mlp/critical-ai-security-guidelines">https://www.sans.org/mlp/critical-ai-security-guidelines</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9402" type="text/plain" language="en" />
<itunes:keywords>sans, ai, guidelines, whatsapp, inetpub, vmware, tenzu, google, android, 0-day, centerstrack, pyarmor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday, April 10th: Microsoft Patch Tuesday; Adobe Patches; OpenSSL 3.5 with PQC; Fortinet</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9400</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday, April 10th: Microsoft Patch Tuesday; Adobe Patches; OpenSSL 3.5 with PQC; Fortinet</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday, April 10th: Microsoft Patch Tuesday; Adobe Patches; OpenSSL 3.5 with PQC; Fortinet</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9400.mp3" length="6149448" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9400.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9400</link>
<pubDate>Wed, 09 Apr 2025 10:11:11 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
  Microsoft patched over 120 vulnerabilities this month.  11 of these were rated critical, and one vulnerability is already being exploited.<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838">https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838</a><br/>
Adobe Updates<br/>
 Adobe released patches for 12 different products. In particular important are patches for Coldfusion addressing several remote code execution vulnerabilities. Adobe Commercse got patches as well, but none of the vulnerabilities are rated critical.<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
OpenSSL 3.5 Released<br/>
  OpenSSL 3.5 was released with support to post quantum ciphers. This is a long term support release.<br/>
  <a href="https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA">https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA</a><br/>
Fortiswitch Update<br/>
 Fortinet released an update for Fortiswitch addressing a vulnerability that may be used to reset a password without verification.<br/>
  <a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-435">https://fortiguard.fortinet.com/psirt/FG-IR-24-435</a><br/>
]]></description>
<itunes:duration>7:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9400" type="text/plain" language="en" />
<itunes:keywords>fortinet, fortiswitch, adobe, commerce, coldfusion, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday, April 8th:
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9398</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday, April 8th:
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday, April 8th:
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9398.mp3" length="5300445" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9398.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9398</link>
<pubDate>Tue, 08 Apr 2025 02:40:16 GMT</pubDate>
<description><![CDATA[<br/>
XORsearch: Searching With Regexes<br/>
 Didier explains a workaround to use his tool XORsearch to search for regular expressions instead of simple strings.<br/>
<a href="https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834">https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834</a><br/>
MCP Security Notification: Tool Poisoning Attacks<br/>
Invariant labs summarized a critical weakness in the Model Context Protocol (MCP) that allows for "Tool Poisoning Attacks." Many major providers such as Anthropic and OpenAI, workflow automation systems like Zapier, and MCP clients like Cursor are susceptible to this attack<br/>
<a href="https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks">https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks</a><br/>
Making :visited more private<br/>
 Google Chrome changed how links are marked as  visited . This new  partitioning  scheme was introduced to improve privacy. Instead of marking a link as  visited  on any page where it is displayed, it is only marked as visited if the user clicks on the link while visiting the particular site where the link is displayed.<br/>
<a href="https://developer.chrome.com/blog/visited-links">https://developer.chrome.com/blog/visited-links</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9398" type="text/plain" language="en" />
<itunes:keywords>xorsearch, regular expression, regex, mcp, agentic, model context protocol, vistied, chrome, privacy, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday April 7th 2025: New Username Report; Quickshell Vulnerability; Apache Traffic Director Request Smuggeling
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9396</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday April 7th 2025: New Username Report; Quickshell Vulnerability; Apache Traffic Director Request Smuggeling
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday April 7th 2025: New Username Report; Quickshell Vulnerability; Apache Traffic Director Request Smuggeling
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9396.mp3" length="5242218" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9396.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9396</link>
<pubDate>Mon, 07 Apr 2025 01:20:47 GMT</pubDate>
<description><![CDATA[<br/>
New SSH Username Report<br/>
  A new ssh/telnet username reports makes it easier to identify new usernames attackers are using against our telnet and ssh honeypots<br/>
<a href="https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830">https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830</a><br/>
Quickshell Sharing is Caring: About an RCE Attack Chain on Quick Share<br/>
 The Google Quick Share protocol is susceptible to several vulnerabilities that have not yet been fully patched, allowing for some file overwrite issues that could lead to the accidental execution of malicious code.<br/>
 <a href="https://www.blackhat.com/asia-25/briefings/schedule/index.html#quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share-43874">https://www.blackhat.com/asia-25/briefings/schedule/index.html#quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share-43874</a><br/>
Apache Traffic Director Request Smuggling Vulnerability<br/>
   <a href="https://www.openwall.com/lists/oss-security/2025/04/02/4">https://www.openwall.com/lists/oss-security/2025/04/02/4</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9396" type="text/plain" language="en" />
<itunes:keywords>apache, request smuggling, quickshell, quick share, ssh, usernames, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, Apr 4th: URL Frequency Analysis; Ivanti Flaw Exploited; WinRAR MotW Vuln; Tax filing scams; Oracle Breach Update
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9394</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, Apr 4th: URL Frequency Analysis; Ivanti Flaw Exploited; WinRAR MotW Vuln; Tax filing scams; Oracle Breach Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, Apr 4th: URL Frequency Analysis; Ivanti Flaw Exploited; WinRAR MotW Vuln; Tax filing scams; Oracle Breach Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9394.mp3" length="5278250" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9394.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9394</link>
<pubDate>Fri, 04 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Exploring Statistical Measures to Predict URLs as Legitimate or Intrusive<br/>
  Using frequency analysis, and training the model with honeypot data as well as log data from legitimate websites allows for a fairly simple and reliable triage of web server logs to identify possible malicious activity.<br/>
  <a href="https://isc.sans.edu/diary/Exploring%20Statistical%20Measures%20to%20Predict%20URLs%20as%20Legitimate%20or%20Intrusive%20%5BGuest%20Diary%5D/31822">https://isc.sans.edu/diary/Exploring%20Statistical%20Measures%20to%20Predict%20URLs%20as%20Legitimate%20or%20Intrusive%20%5BGuest%20Diary%5D/31822</a><br/>
Critical Unexploitable Ivanti Vulnerability Exploited CVE-2025-22457<br/>
 In February, Ivanti patched  CVE-2025-22457. At the time, the vulnerability was not considered to be exploitable. Mandiant now published a blog disclosing that the vulnerability was exploited as soon as mid-march<br/>
 <a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability/">https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability/</a><br/>
WinRAR MotW Vulnerability CVE-2025-31334<br/>
 WinRAR patched a vulnerability that would not apply the  Mark of the Web  correctly if a compressed file included symlinks. This may make it easier to trick a victim into executing code downloaded from a website.<br/>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31334">https://nvd.nist.gov/vuln/detail/CVE-2025-31334</a><br/>
Microsoft Warns of Tax-Related Scam<br/>
 With the US personal income tax filing deadline only about a week out, Microsoft warns of commonly deployed scams that they are observing related to income tax filings<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/">https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/</a><br/>
Oracle Breach Update<br/>
 <a href="https://www.bloomberg.com/news/articles/2025-04-02/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen">https://www.bloomberg.com/news/articles/2025-04-02/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9394" type="text/plain" language="en" />
<itunes:keywords>oracle, microsoft, tax, irs, winrar, motw, ivanti, frequency analysis, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday Apr 3rd: Juniper Password Scans; Hacking Call Records; End to End Encrypted GMail
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9392</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday Apr 3rd: Juniper Password Scans; Hacking Call Records; End to End Encrypted GMail
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday Apr 3rd: Juniper Password Scans; Hacking Call Records; End to End Encrypted GMail
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9392.mp3" length="7884345" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9392.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9392</link>
<pubDate>Thu, 03 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Surge in Scans for Juniper  t128  Default User<br/>
 Lasst week, we dedtect a significant surge in ssh scans for the username  t128 . This user is used by Juniper s Session Smart Routing, a product they acquired from  128 Technologies  which is the reason for the somewhat unusual username. <br/>
 <a href="https://isc.sans.edu/diary/Surge%20in%20Scans%20for%20Juniper%20%22t128%22%20Default%20User/31824">https://isc.sans.edu/diary/Surge%20in%20Scans%20for%20Juniper%20%22t128%22%20Default%20User/31824</a><br/>
Vulnerable Verizon API Allowed for Access to Call Logs<br/>
 An API Verizon offered to users of its call filtering application suffered from an authentication bypass vulnerability allowing users to access any Verizon user s call history. While using a JWT to authenticate the user, the phone number used to retrieve the call history logs was passed in a not-authenticated header.<br/>
<a href="https://evanconnelly.github.io/post/hacking-call-records/">https://evanconnelly.github.io/post/hacking-call-records/</a><br/>
Google Offering End-to-End Encryption to G-Mail Business Users<br/>
  Google will add an end-to-end encryption feature to commercial GMail users. However, for non GMail users to read the emails they first must click on a link and log in to Google.<br/>
<a href="https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses">https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses</a><br/>
]]></description>
<itunes:duration>9:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9392" type="text/plain" language="en" />
<itunes:keywords>gmail, google, verizon, t128, juniper, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Apr 2nd: Apple Updates Everything; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9390</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Apr 2nd: Apple Updates Everything; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Apr 2nd: Apple Updates Everything; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9390.mp3" length="6112689" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9390.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9390</link>
<pubDate>Wed, 02 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apple Patches Everything<br/>
 Apple released updates for all of its operating systems. Most were released on Monday with WatchOS patches released today on Tuesday. Two already exploited vulnerabilities, which were already patched in the latest iOS and macOS versions, are now patched for older operating systems as well. A total of 145 vulnerabilities were patched.<br/>
<a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20March%2031st%202025%20Edition/31816">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20March%2031st%202025%20Edition/31816</a><br/>
VMWare Workstation and Fusion update check broken<br/>
 VMWare s automatic update check in its Workstation and Fusion products is currently broken due to a redirect added as part of the Broadcom transition<br/>
<a href="https://community.broadcom.com/vmware-cloud-foundation/question/certificate-error-is-occured-during-connecting-update-server">https://community.broadcom.com/vmware-cloud-foundation/question/certificate-error-is-occured-during-connecting-update-server</a><br/>
NIM Postgres Vulnerability<br/>
 NIM Developers using prepared statements to send SQL queries to Postgres may expose themselves to a SQL injection vulnerability. NIM s Postgres library does not appear to use actual prepared statements; instead, it assembles the code and the user data as a string and passes them on to the database. This may lead to a SQL injection vulnerability<br/>
<a href="https://blog.nns.ee/2025/03/28/nim-postgres-vulnerability/">https://blog.nns.ee/2025/03/28/nim-postgres-vulnerability/</a><br/>
]]></description>
<itunes:duration>7:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9390" type="text/plain" language="en" />
<itunes:keywords>apple, ios, macos, vmware, nim, postres, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday Apr 1st: Apache Camel Exploits; New Cert Authorities Requirements; Possible Oracle Breach
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9388</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday Apr 1st: Apache Camel Exploits; New Cert Authorities Requirements; Possible Oracle Breach
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday Apr 1st: Apache Camel Exploits; New Cert Authorities Requirements; Possible Oracle Breach
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9388.mp3" length="6662912" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9388.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9388</link>
<pubDate>Tue, 01 Apr 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Apache Camel Exploit Attempt by Vulnerability Scans<br/>
 A recently patched vulnerability in Apache Camel has been integrated into some vulnerability scanners, like for example OpenVAS. We do see some exploit attempts in our honeypots, but they appear to be part of internal vulnerablity scans<br/>
 <a href="https://isc.sans.edu/diary/Apache%20Camel%20Exploit%20Attempt%20by%20Vulnerability%20Scan%20%28CVE-2025-27636%2C%20CVE-2025-29891%29/31814">https://isc.sans.edu/diary/Apache%20Camel%20Exploit%20Attempt%20by%20Vulnerability%20Scan%20%28CVE-2025-27636%2C%20CVE-2025-29891%29/31814</a><br/>
New Security Requirements for Certificate Authorities<br/>
 Starting in July, certificate authorities need to verify domain ownership data from multiple viewpoints around the internet. They will also have to use linters to verify certificate requests.<br/>
 <a href="https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html">https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html</a><br/>
Possible Oracle Breach<br/>
 Oracle still denies being the victim of a data berach as leaked data may show different.<br/>
<a href="https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a">https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a</a><br/>
<a href="https://www.theregister.com/2025/03/30/infosec_news_in_brief/">https://www.theregister.com/2025/03/30/infosec_news_in_brief/</a><br/>
<a href="https://www.darkreading.com/cyberattacks-data-breaches/oracle-still-denies-breach-researchers-persist">https://www.darkreading.com/cyberattacks-data-breaches/oracle-still-denies-breach-researchers-persist</a><br/>
]]></description>
<itunes:duration>7:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9388" type="text/plain" language="en" />
<itunes:keywords>oracle, breach, tls, certificates, camel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday, March 31st: Comparing Phishing Sites; DOH and MX Abuse Phishing; opkssh
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9386</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday, March 31st: Comparing Phishing Sites; DOH and MX Abuse Phishing; opkssh
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday, March 31st: Comparing Phishing Sites; DOH and MX Abuse Phishing; opkssh
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9386.mp3" length="6365443" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9386.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9386</link>
<pubDate>Mon, 31 Mar 2025 01:18:33 GMT</pubDate>
<description><![CDATA[<br/>
A Tale of Two Phishing Sties<br/>
 Two phishing sites may use very different backends, even if the site itself appears to be visually very similar. Phishing kits are often copied and modified, leading to sites using similar visual tricks on the user facing site, but very different backends to host the sites and reporting data to the miscreant.<br/>
 <a href="https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810">https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810</a><br/>
A Phihsing Tale of DOH and DNS MX Abuse<br/>
 Infoblox discovered a new variant of the Meerkat phishing kit that uses DoH in Javascript to discover MX records, and generate better customized phishing pages.<br/>
 <a href="https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/">https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/</a><br/>
Using OpenID Connect for SSH<br/>
 Cloudflare opensourced it's OPKSSH too. It integrates SSO systems supporting OpenID connect with SSH.<br/>
<a href="https://github.com/openpubkey/opkssh/">https://github.com/openpubkey/opkssh/</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9386" type="text/plain" language="en" />
<itunes:keywords>openid, ssh, cloudflare, phishing, dns, doh, phishing kits, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday, March 28th: Sitecore Exploited; Blasting Past Webp; Splunk and Firefox Vulnerabilities</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9384</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday, March 27th: Sitecore Exploited; Blasting Past Webp; Splunk and Firefox Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday, March 27th: Sitecore Exploited; Blasting Past Webp; Splunk and Firefox Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9384.mp3" length="5521880" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9384.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9384</link>
<pubDate>Fri, 28 Mar 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Sitecore "thumbnailsaccesstoken" Deserialization Scans (and some new reports) CVE-2025-27218<br/>
 Our honeypots detected a deserialization attack against the CMS Sitecore using a  thumnailaccesstoken  header. The underlying vulnerability was patched in January, and security firm Searchlight Cyber revealed details about this vulnerability a couple of weeks ago. <br/>
 <a href="https://isc.sans.edu/diary/Sitecore%20%22thumbnailsaccesstoken%22%20Deserialization%20Scans%20%28and%20some%20new%20reports%29%20CVE-2025-27218/31806">https://isc.sans.edu/diary/Sitecore%20%22thumbnailsaccesstoken%22%20Deserialization%20Scans%20%28and%20some%20new%20reports%29%20CVE-2025-27218/31806</a><br/>
Blasting Past Webp<br/>
 Google s Project Zero revealed details how the NSO BLASTPASS exploit took advantage of a Webp image parsing vulnerability in iOS. This zero-click attack was employed in targeted attack back in 2023 and Apple patched the underlying vulnerability in September 2023. But this is the first  byte by byte  description showing how the attack worked.<br/>
 <a href="https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html">https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html</a><br/>
Splunk Vulnerabilities<br/>
 Splunk patched about a dozen of vulnerabilities. None of them are rated critical, but a vulnerability rated  High  allows authenticated users to execute arbitrary code.<br/>
 <a href="https://advisory.splunk.com/">https://advisory.splunk.com/</a><br/>
Firefox 0-day Patched<br/>
 Mozilla patched a sandbox escape vulnerability that is already being exploited.<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/">https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9384" type="text/plain" language="en" />
<itunes:keywords>firefox, mozilla, splunk, webp, sitecore, deserialization, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday Mar 27th: Classifying Malware with ML; Malicious NPM Packages; Google Chrome 0-day
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9382</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday Mar 27th: Classifying Malware with ML; Malicious NPM Packages; Google Chrome 0-day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday Mar 27th: Classifying Malware with ML; Malicious NPM Packages; Google Chrome 0-day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9382.mp3" length="4648061" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9382.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9382</link>
<pubDate>Thu, 27 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest<br/>
    This diary explores a novel methodology for classifying malware by integrating entropy-driven feature selection with a specialized Convolutional Neural Network (CNN). Motivated by the increasing obfuscation tactics used by modern malware authors, we will focus on capturing high-entropy segments within files, regions most likely to harbor malicious functionality, and feeding these distinct byte patterns into our model.<br/>
  <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Leveraging%20CNNs%20and%20Entropy-Based%20Feature%20Selection%20to%20Identify%20Potential%20Malware%20Artifacts%20of%20Interest/31790">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Leveraging%20CNNs%20and%20Entropy-Based%20Feature%20Selection%20to%20Identify%20Potential%20Malware%20Artifacts%20of%20Interest/31790</a><br/>
    <br/>
Malware found on npm infecting local package with reverse shell<br/>
 Researchers at Reversinglabs found two malicious NPM packages, ethers-provider2, and ethers-providerz that patch the well known (and not malicious) ethers package to add a reverse shell and downloader.<br/>
 <a href="https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell">https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell</a><br/>
Google Patched Google Chrome 0-day<br/>
  Google patched a vulnerability in Chrome that was already exploited in attacks against media and educational organizations in Russia<br/>
 <a href="https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html">https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html</a><br/>
]]></description>
<itunes:duration>4:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9382" type="text/plain" language="en" />
<itunes:keywords>google, chrome, npm, ethers, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Mar 26th: XWiki Exploit; File Converter Correction; VMWare Vulnerability; Draytek Router Reboots; MMC Exploit Details;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9380</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Mar 26th: XWiki Exploit; File Converter Correction; VMWare Vulnerability; Draytek Router Reboots; MMC Exploit Details;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Mar 26th: XWiki Exploit; File Converter Correction; VMWare Vulnerability; Draytek Router Reboots; MMC Exploit Details;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9380.mp3" length="5515404" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9380.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9380</link>
<pubDate>Wed, 26 Mar 2025 02:05:03 GMT</pubDate>
<description><![CDATA[<br/>
XWiki Search Vulnerablity Exploit Attempts (CVE-2024-3721)<br/>
 Our honeypot detected an increase in exploit attempts for an XWiki command injection vulnerablity. The vulnerability was patched last April, but appears to be exploited more these last couple days. The vulnerability affects the search feature and allows the attacker to inject Groovy code templates.<br/>
 <a href="https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800">https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800</a> <br/>
Correction: FBI Image Converter Warning<br/>
 The FBI's Denver office warned of online file converters, not downloadable conversion tools<br/>
 <a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam">https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam</a><br/>
VMWare Vulnerability<br/>
 Broadcom released a fix for a VMWare Tools vulnerability. The vulnerability allows users of a Windows virtual machine to escalate privileges within the machine.<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518</a><br/>
Draytek Reboots<br/>
 Over the weekend, users started reporting Draytek routers rebooting and getting stuck in a reboot loop. Draytek now published advise as to how to fix the problem.<br/>
 <a href="https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/">https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/</a><br/>
Microsoft Managemnt Console Exploit CVE-2025-26633<br/>
 TrendMicro released details showing how the MMC vulnerability Microsoft patched as part of its patch tuesday this month was exploited.<br/>
 <a href="https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html">https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9380" type="text/plain" language="en" />
<itunes:keywords>microsoft, draytek, trendmicro, mmc, vmware, fbi, image conversion, denver, xwiki, groovy, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday Mar 25th: Privacy Awware Bots; Ingress Nightmare; Malicious File Converters; VSCode Extension Leads to Ransomware
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9378</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday Mar 25th: Privacy Awware Bots; Ingress Nightmare; Malicious File Converters; VSCode Extension Leads to Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday Mar 25th: Privacy Awware Bots; Ingress Nightmare; Malicious File Converters; VSCode Extension Leads to Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9378.mp3" length="5238921" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9378.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9378</link>
<pubDate>Tue, 25 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Privacy Aware Bots<br/>
 A botnet is using privacy as well as CSRF prevention headers to better blend in with normal browsers. However, in the process they may make it actually easier to spot them.<br/>
 <a href="https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796">https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796</a><br/>
Critical Ingress Nightmare Vulnerability<br/>
 ingress-nginx fixed four new vulnerabilities, one of which may lead to a Kubernetes cluster compromise. Note that at the time I am making this live, not all of the URLs below are available yet, but I hope they will be available shortly after publishing this podcast<br/>
 <a href="https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments">https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments</a><br/>
 <a href="https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities">https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities</a><br/>
 <a href="https://kubernetes.io/blog/">https://kubernetes.io/blog/</a><br/>
FBI Warns of File Converter Scams<br/>
 File converters may include malicious ad ons. Be careful where you get your software from.<br/>
<a href="https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam">https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam</a><br/>
VSCode Extension Includes Ransomware<br/>
 <a href="https://x.com/ReversingLabs/status/1902355043065500145">https://x.com/ReversingLabs/status/1902355043065500145</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9378" type="text/plain" language="en" />
<itunes:keywords>vscode, ransomware, fbi, file converter, scam, malware, ingress, nightmare, kubernetes, bots, privacy, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday Mar 24th: Critical Next.js Vulnerability; Microsoft Trust Signing Platform Abuse
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9376</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday Mar 24th: Critical Next.js Vulnerability; Microsoft Trust Signing Platform Abuse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday Mar 24th: Critical Next.js Vulnerability; Microsoft Trust Signing Platform Abuse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9376.mp3" length="6292846" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9376.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9376</link>
<pubDate>Mon, 24 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Critical Next.js Vulnerability CVE-2025-29927<br/>
 A critical vulnerability in how the x-middleware-subrequest header is verified may lead to bypassing authorization in Next.js applications.<br/>
<a href="https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware">https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware</a><br/>
<a href="https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw">https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw</a><br/>
<a href="https://www.runzero.com/blog/next-js/">https://www.runzero.com/blog/next-js/</a><br/>
Microsoft Trust Signing Service Abused<br/>
 Attackers abut the Microsoft Trust Signing Service, a service meant to help developers create signed software, to obtain short lived signatures for malware.<br/>
 <a href="https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/">https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/</a><br/>
]]></description>
<itunes:duration>7:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9376" type="text/plain" language="en" />
<itunes:keywords>microsoft, trust, signing, digital signature, next.js, authorization, middleware, proxies, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday Mar 21st: New Data Feeds; SEO Spam; Veeam Deserialization; IBM AIX RCE; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9374</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday Mar 21st: New Data Feeds; SEO Spam; Veeam Deserialization; IBM AIX RCE; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday Mar 21st: New Data Feeds; SEO Spam; Veeam Deserialization; IBM AIX RCE; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9374.mp3" length="7336373" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9374.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9374</link>
<pubDate>Fri, 21 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Some New Data Feeds and Little Incident<br/>
 We started offering additional data feeds, and an SEO spamer attempted to make us change a link from an old podcast episode.<br/>
 <a href="https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786">https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786</a><br/>
Veeam Deserialization Vulnerability<br/>
 Veeam released details regarding the latest vulnerablity in Veeam, pointing out the insufficient patch applied to a prior deserialization vulnerability.<br/>
 <a href="https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/">https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/</a><br/>
IBM AIX Vulnerablity<br/>
 The AIX NIM service is vulnerable to an unauthenticated remote code execution vulnerability<br/>
 <a href="https://www.ibm.com/support/pages/node/7186621">https://www.ibm.com/support/pages/node/7186621</a><br/>
thanks Chris Mosby for Spotify comment<br/>
]]></description>
<itunes:duration>8:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9374" type="text/plain" language="en" />
<itunes:keywords>ibm, aix, veeam, data feeds, seo spam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday Mar 20th: Cisco Smart Licensing Attacks; Vulnerable Drivers again; Synology Advisories Updated
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9372</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday Mar 20th: Cisco Smart Licensing Attacks; Vulnerable Drivers again; Synology Advisories Updated
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday Mar 20th: Cisco Smart Licensing Attacks; Vulnerable Drivers again; Synology Advisories Updated
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9372.mp3" length="6278305" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9372.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9372</link>
<pubDate>Thu, 20 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Exploit Attempts for Cisco Smart Licensing Utility CVE-2024-20439 CVE-2024-20440<br/>
 Attackers added last September's Cisco Smart Licensing Utility vulnerability to their toolset. These attacks orginate most likely from botnets and the same attackers are scanning for a wide range of additional vulnerabilities. The vulnerability is a static credential issue and trivial to exploit after the credentials were published last fall.<br/>
 <a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782</a><br/>
Legacy Driver Exploitation Through Bypassing Certificate Verification<br/>
 Ahnlab documented a new type of "bring your own vulnerable driver" vulnerability. In this case, an old driver used by an anit-malware and anti-rootkit system can be used to shut down arbitrary processeses, including security related processeses.<br/>
 <a href="https://asec.ahnlab.com/en/86881/">https://asec.ahnlab.com/en/86881/</a><br/>
Synology Vulnerability Updates<br/>
 Synology updates some security advisories it release last year adding addition details and vulnerable systems.<br/>
 <a href="https://www.synology.com/en-global/security/advisory/Synology_SA_24_20">https://www.synology.com/en-global/security/advisory/Synology_SA_24_20</a><br/>
 <a href="https://www.synology.com/en-global/security/advisory/Synology_SA_24_24">https://www.synology.com/en-global/security/advisory/Synology_SA_24_24</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9372" type="text/plain" language="en" />
<itunes:keywords>synology, driver, cisco, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Mar 19th 2025: Python DLL Side Loading; Tomcast RCE Correction; SAML Roulette; Windows Shortcut 0-Day
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9370</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Mar 19th 2025: Python DLL Side Loading; Tomcast RCE Correction; SAML Roulette; Windows Shortcut 0-Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Mar 19th 2025: Python DLL Side Loading; Tomcast RCE Correction; SAML Roulette; Windows Shortcut 0-Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9370.mp3" length="6412030" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9370.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9370</link>
<pubDate>Wed, 19 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Python Bot Delivered Through DLL Side-Loading<br/>
 A "normal", but vulnerable to DLL side-loading PDF reader may be used to launch additional exploit code<br/>
 <a href="https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778">https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778</a><br/>
Tomcat RCE Correction<br/>
 To exploit the Tomcat RCE I mentioned yesterday, two non-default configuration options must be selected by the victim.<br/>
 <a href="https://x.com/dkx02668274/status/1901893656316969308">https://x.com/dkx02668274/status/1901893656316969308</a><br/>
SAML Roulette: The Hacker Always Wins<br/>
 This Portswigger blog explains in detail how to exploit the ruby-saml vulnerablity against GitLab.<br/>
 <a href="https://portswigger.net/research/saml-roulette-the-hacker-always-wins">https://portswigger.net/research/saml-roulette-the-hacker-always-wins</a><br/>
Windows Shortcut Zero Day Exploit<br/>
 Attackers are currently taking advantage of an unpatched vulnerability in how Windows displays Shortcut (.lnk file) details. Trendmicro explains how the attack works and provides PoC code. Microsoft is not planning to fix this issue<br/>
 <a href="https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html">https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html</a><br/>
]]></description>
<itunes:duration>7:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9370" type="text/plain" language="en" />
<itunes:keywords>windows, shortcut, link, lnk, saml, ruby, xml, tomcat, rce, python, dll, sideloading, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday Mar 18th 2025: Analyzing GUID Encoded Shellcode; Node.js SAML Vuln; Tomcat RCE in the Wild; CSS e-mail obfuscation</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9368</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday Mar 17th 2025: Analyzing GUID Encoded Shellcode; Node.js SAML Vuln; Tomcat RCE in the Wild; CSS e-mail obfuscation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday Mar 17th 2025: Analyzing GUID Encoded Shellcode; Node.js SAML Vuln; Tomcat RCE in the Wild; CSS e-mail obfuscation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9368.mp3" length="6193071" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9368.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9368</link>
<pubDate>Tue, 18 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Static Analysis of GUID Encoded Shellcode<br/>
 Didier explains how to decode shell code embeded as GUIDs in malware, and how to feed the result to his tool 1768.py which will extract Cobal Strike configuration information from the code.<br/>
 <a href="https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774">https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774</a><br/>
SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries<br/>
 xml-crypto, a library use in Node.js applications to decode XML and support SAML, has found to parse comments incorrectly leading to several SAML vulnerabilities.<br/>
 <a href="https://workos.com/blog/samlstorm">https://workos.com/blog/samlstorm</a><br/>
One PUT Request to Own Tomcat: CVE-2025-24813 RCE is in the Wild<br/>
 A just made public deserialization vulnerablity in Tomcat is already being exploited. Contributing to the rapid exploit release is the similarity of this vulnerability to other Java deserializtion vulnerabilities. <br/>
<a href="https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/">https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/</a>  CVE-2025-24813<br/>
CSS Abuse for Evasion and Tracking<br/>
 Attackers are using cascading stylesheets to evade detection and enable more stealthy tracking of users<br/>
 <a href="https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/">https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9368" type="text/plain" language="en" />
<itunes:keywords>css, tracking, abuse, put, tomcat, saml, node.js, xml-crypto, guid, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday March 17th: Mirai Makes Mistakes; Compromised Github Action; ruby-saml vulnerability; Fake GitHub Security Alert Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9366</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday March 17th: Mirai Makes Mistakes; Compromised Github Action; ruby-saml vulnerability; Fake GitHub Security Alert Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday March 17th: Mirai Makes Mistakes; Compromised Github Action; ruby-saml vulnerability; Fake GitHub Security Alert Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9366.mp3" length="5850177" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9366.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9366</link>
<pubDate>Mon, 17 Mar 2025 01:35:10 GMT</pubDate>
<description><![CDATA[<br/>
Mirai Bot Now Incorporating Malformed DrayTek Vigor Router Exploits<br/>
 One of the many versions of the Mirai botnet added some new exploit strings attempting to take advantage of an old DrayTek Vigor Router vulnerability, but they got the URL wrong.<br/>
<a href="https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770">https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770</a><br/>
Compromised GitHub Action<br/>
 The popular GitHub action tj-actions/changed-files was compromised and leaks credentials via the action logs<br/>
 <a href="https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised">https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised</a><br/>
ruby-saml authentication bypass<br/>
 A confusion in how to parse SAML messages between two XML parsers used by Ruby leads to an authentication bypass in saml-ruby.<br/>
 <a href="https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/">https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/</a><br/>
GitHub Fake Security Alerts<br/>
 Fake GitHub security alerts are used to trick package maintainers into adding OAUTH privileges to malicious apps.<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/">https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/</a><br/>
]]></description>
<itunes:duration>6:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9366" type="text/plain" language="en" />
<itunes:keywords>github, oauth, saml, ruby, phishing, actions, mirai, draytek, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast: File Hashes in MSFT BI; Apache Camel Vuln; Juniper Fixes Exploited Vuln; AMI Patches 10.0 Redfish BMC Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9364</itunes:episode>
<itunes:subtitle>SANS Stormcast: File Hashes in MSFT BI; Apache Camel Vuln; Juniper Fixes Exploited Vuln; AMI Patches 10.0 Redfish BMC Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast: File Hashes in MSFT BI; Apache Camel Vuln; Juniper Fixes Exploited Vuln; AMI Patches 10.0 Redfish BMC Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9364.mp3" length="5417198" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9364.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9364</link>
<pubDate>Fri, 14 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
File Hashes Analysis with Power BI<br/>
 Guy explains in this diary how to analyze Cowrie honeypot file hashes using Microsoft's BI tool and what you may be able to discover using this tool.<br/>
 <a href="https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764">https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764</a><br/>
Apache Camel Vulnerability<br/>
 Apache released two patches for Camel in close succession. Initially, the vulnerability was only addressed for headers, but as Akamai discovered, it can also be exploited via query parameters. This vulnerability is trivial to exploit and leads to arbitrary code execution.<br/>
 <a href="https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations">https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations</a><br/>
Juniper Patches Junos Vulnerability<br/>
 Juniper patches an already exploited vulnerability in JunOS. However, to exploit the vulnerability, and attacker already needs privileged access. By exploiting the vulnerability, an attacker may completely compromised the device.<br/>
 <a href="https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US">https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US</a><br/>
AMI Security Advisory<br/>
 AMI patched three vulnerabilities. One of the, an authentication bypass in Redfish, allows for a complete system compromise without authentication and is rated with a CVSS score of 10.0.<br/>
 <a href="https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf">https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9364" type="text/plain" language="en" />
<itunes:keywords>AMI, BIOS, Redfish, Juniper, JunOS, apache, camel, power bi, cowrie, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday Mar 13th: Exploiting Login Pages with Log4j; Patch Tuesday Fallout; Adobe Patches; Medusa Ransomware; Zoom and Font Library Updates;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9362</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday Mar 13th: Exploiting Login Pages with Log4j; Patch Tuesday Fallout; Adobe Patches; Medusa Ransomware; Zoom and Font Library Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday Mar 13th: Exploiting Login Pages with Log4j; Patch Tuesday Fallout; Adobe Patches; Medusa Ransomware; Zoom and Font Library Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9362.mp3" length="5266271" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9362.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9362</link>
<pubDate>Thu, 13 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Log4J Scans for VMWare Hyhbrid Cloud Extensions<br/>
 An attacker is scanning various login pages, including the authentication feature in the VMWare HCX REST API for Log4j vulnerabilities. The attack submits the exploit string as username, hoping to trigger the vulnerability as Log4j logs the username<br/>
 <a href="https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762">https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762</a><br/>
Patch Tuesday Fallout<br/>
 Yesterday's Apple patch may re-activate Apple Intelligence for users who earlier disabled it. Microsoft is offering support for users whos USB printers started printing giberish after a January patch was applies.<br/>
 <a href="https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/">https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/</a><br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update</a><br/>
Adobe Updates<br/>
 Adobe updated seven different products, including Adobe Acrobat. The Acrobat vulnerability may lead to remote code execution and Adobe considers the vulnerablities critical.<br/>
<a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Medusa Ransomware<br/>
 CISA and partner agencies released details about the Medusa Ransomware. The document includes many details useful to defenders.<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a</a><br/>
Zoom Update<br/>
 Zoom released a critical update fixing a number of remote code execution vulnerabilities.<br/>
 <a href="https://www.zoom.com/en/trust/security-bulletin/">https://www.zoom.com/en/trust/security-bulletin/</a><br/>
FreeType Library Vulnerability<br/>
 <a href="https://www.facebook.com/security/advisories/cve-2025-27363">https://www.facebook.com/security/advisories/cve-2025-27363</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9362" type="text/plain" language="en" />
<itunes:keywords>freetype, zoom, medusa, ransomware, adobe, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Mar 12th: Microsoft Patch Tuesday; Apple Patch; Espressif ESP32 Statement
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9360</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Mar 12th: Microsoft Patch Tuesday; Apple Patch; Espressif ESP32 Statement
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Mar 12th: Microsoft Patch Tuesday; Apple Patch; Espressif ESP32 Statement
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9360.mp3" length="6911147" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9360.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9360</link>
<pubDate>Wed, 12 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
 Microsoft Patched six already exploited vulnerabilities today. In addition, the patches included a critical patch for Microsoft's DNS server and about 50 additional patches.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756</a><br/>
Apple Updates iOS/macOS<br/>
 Apple released an update to address a single, already exploited, vulnerability in WebKit. This vulnerability affects iOS, macOS and VisionOS.<br/>
 <a href="https://support.apple.com/en-us/100100">https://support.apple.com/en-us/100100</a><br/>
Expressif Response to ESP32 Debug Commands<br/>
 Expressif released a statement commenting on the recent release of a paper alledging "Backdoors" in ESP32 chipsets. According to Expressif, these commands are debug commands and not reachable directly via Bluetooth.<br/>
 <a href="https://www.espressif.com/en/news/Response_ESP32_Bluetooth">https://www.espressif.com/en/news/Response_ESP32_Bluetooth</a><br/>
]]></description>
<itunes:duration>7:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9360" type="text/plain" language="en" />
<itunes:keywords>apple, expressif, esp32, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday Mar 11th: Shellcode as UUIDs; Moxe Switch Vuln Updates; Opentext Vuln; Livewire Volt Vuln; 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9358</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday Mar 11th: Shellcode as UUIDs; Moxe Switch Vuln Updates; Opentext Vuln; Livewire Volt Vuln; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday Mar 11th: Shellcode as UUIDs; Moxe Switch Vuln Updates; Opentext Vuln; Livewire Volt Vuln; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9358.mp3" length="4460276" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9358.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9358</link>
<pubDate>Tue, 11 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Shellcode Encoded in UUIDs<br/>
 Attackers are using UUIDs to encode Shellcode. The 128 Bit (or 16 Bytes) encoded in each UUID are converted to shell code to implement a cobalt strike beacon<br/>
 <a href="https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752">https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752</a><br/>
Moxa CVE-2024-12297 Expanded to PT Switches<br/>
 Moxa in January first releast an update to address a fronted authorizaation logic disclosure vulnerability. It now updated the advisory and included the PT series switches as vulenrable.<br/>
 <a href="https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches">https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches</a><br/>
Opentext Insufficently Protected Credentials<br/>
 <a href="https://portal.microfocus.com/s/article/KM000037455?language=en_US">https://portal.microfocus.com/s/article/KM000037455?language=en_US</a><br/>
Livewire Volt API vulnerability<br/>
 <a href="https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv">https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv</a><br/>
]]></description>
<itunes:duration>4:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9358" type="text/plain" language="en" />
<itunes:keywords>livewire, volt, api, opentest, moxa, switches, pt, shellcode uuid, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast: Webshells; Undocumented ESP32 Commands; Camera Used For Ransomware Distribution
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9356</itunes:episode>
<itunes:subtitle>SANS Stormcast: Webshells; Undocumented ESP32 Commands; Camera Used For Ransomware Distribution
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast: Webshells; Undocumented ESP32 Commands; Camera Used For Ransomware Distribution
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9356.mp3" length="5940271" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9356.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9356</link>
<pubDate>Mon, 10 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Commonly Probed Webshell URLs<br/>
 Many attackers deploy web shells to gain a foothold on vulnerable web servers. These webshells can also be taken over by parasitic exploits.<br/>
<a href="https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748">https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748</a><br/>
Undocumented ESP32 Commands<br/>
 A recent conference presentation by Tarlogic revealed several "backdoors" or undocumented features in the commonly used ESP32 Chipsets. Tarlogic also released a toolkit to make it easier to audit chipsets and find these hiddent commands.<br/>
 <a href="https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/">https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/</a><br/>
Camera Off: Akira deploys ransomware via Webcam<br/>
 The Akira ransomware group was recently observed infecting a network with Ransomware by taking advantage of a webcam.<br/>
 <a href="https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam">https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9356" type="text/plain" language="en" />
<itunes:keywords>webcam, akira, esp32, expressif, webshell, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday Mar 7th: Chrome vs Extensions; Kibana Update; PrePw0n3d Android TV Sticks; Identifying APTs (@sans_edu, Eric LeBlanc)
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9354</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday Mar 7th: Chrome vs Extensions; Kibana Update; PrePw0n3d Android TV Sticks; Identifying APTs (@sans_edu, Eric LeBlanc)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday Mar 7th: Chrome vs Extensions; Kibana Update; PrePw0n3d Android TV Sticks; Identifying APTs (@sans_edu, Eric LeBlanc)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9354.mp3" length="11936179" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9354.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9354</link>
<pubDate>Fri, 07 Mar 2025 02:45:24 GMT</pubDate>
<description><![CDATA[<br/>
Latest Google Chrome Update Encourages UBlock Origin Removal<br/>
 The latest update to Google Chrome not only disabled the UBlock Origin ad blocker, but also guides users to uninstall the extension instead of re-enabling it.<br/>
<a href="https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html</a><br/>
<a href="https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/">https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/</a><br/>
Critical Kibana Update<br/>
 Elastic published a critical Kibana update patching a prototype polution vulnerability that would allow arbitrary code execution for users with the "Viewer" role.<br/>
<a href="https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441">https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441</a><br/>
Certified PrePw0n3d Android TV Sticks<br/>
 Wired is reporting of over a million Android TV sticks that were found to be pre-infected with adware<br/>
<a href="https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/">https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/</a><br/>
SANS.edu Research Paper<br/>
 Advanced Persistent Threats (APTs) are among the most challenging to detect in enterprise environments, often mimicking authorized privileged access prior to their actions on objectives.<br/>
 <a href="https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/">https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/</a><br/>
]]></description>
<itunes:duration>13:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9354" type="text/plain" language="en" />
<itunes:keywords>sans.edu, research, apt, android, kibana, elastic, ublock, origin, chrome, extensions, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday Mar 6th: DShield ELK Analysis; Jailbreaking AMD CPUs; VIM Vulnerability; Snail Mail Ransomware
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9352</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday Mar 6th: DShield ELK Analysis; Jailbreaking AMD CPUs; VIM Vulnerability; Snail Mail Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday Mar 6th: DShield ELK Analysis; Jailbreaking AMD CPUs; VIM Vulnerability; Snail Mail Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9352.mp3" length="5939797" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9352.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9352</link>
<pubDate>Thu, 06 Mar 2025 02:45:34 GMT</pubDate>
<description><![CDATA[<br/>
DShield Traffic Analysis using ELK<br/>
 The "DShield SIEM" includes an ELK dashboard as part of the Honeypot. Learn how to find traffic of interest with this tool.<br/>
 <a href="https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742">https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742</a><br/>
Zen and the Art of Microcode Hacking<br/>
 Google released details, including a proof of concept exploit, showing how to take advantage of the recently patched AMD microcode vulnerability<br/>
<a href="https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking">https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking</a> CVE-2024-56161<br/>
VIM Vulnerability<br/>
 An attacker may execute arbitrary code by tricking a user to open a crafted tar file in VIM<br/>
 <a href="https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3">https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3</a><br/>
Snil Mail Fake Ransom Note<br/>
 A copy cat group is impersonating ransomware actors. The group sends snail mail to company executives claiming to have stolen company data and threatening to leak it unless a payment is made.<br/>
 <a href="https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/">https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9352" type="text/plain" language="en" />
<itunes:keywords>snail mail, ransomware, vim, zen, microcode, elk, dshield, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal Scams; VMWare Escape Fix
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9350</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal Scams; VMWare Escape Fix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal Scams; VMWare Escape Fix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9350.mp3" length="5473415" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9350.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9350</link>
<pubDate>Wed, 05 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Romanian Distillery Scanning for SMTP Credentials<br/>
 A particular attacker expanded the scope of their leaked credential file scans. In addition to the usual ".env" style files, it is not looking for specific SMTP related credential files.<br/>
 <a href="https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736">https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736</a><br/>
Tool Updates: mac-robber.py<br/>
 This update of mac-robber.py fixes issues with symlinks.<br/>
 <a href="https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738">https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738</a><br/>
CVE-2025-1723   Account takeover vulnerability in ADSelfService Plus<br/>
 CVE-2025-1723 describes a vulnerability caused by session mishandling in ADSelfService Plus that could allow unauthorized access to user enrollment data when MFA was not enabled for ADSelfService Plus login.<br/>
 <a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html">https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html</a><br/>
Android March Update<br/>
 Google released an update for Android addressing two already exploited vulnerabilities and several critical issues.<br/>
 <a href="https://source.android.com/docs/security/bulletin/2025-03-01">https://source.android.com/docs/security/bulletin/2025-03-01</a><br/>
PayPal's no-code-checkout Abuse<br/>
 Attackers are using PayPal's no-code-checkout feature is being abused by scammers to host PayPal tech support scam pages right within the PayPal.com domain.<br/>
 <a href="https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers">https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers</a><br/>
Broadcom Fixes three VMWare VCenter Vulnerabilities<br/>
 <a href="https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004">https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9350" type="text/plain" language="en" />
<itunes:keywords>vmware, broadcom, paypal, android, adselfservice, zoho, mac-robber, smtp, credentials, json, jennsen, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9348</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9348.mp3" length="5548019" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9348.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9348</link>
<pubDate>Tue, 04 Mar 2025 02:03:34 GMT</pubDate>
<description><![CDATA[<br/>
Mark of the Web: Some Technical Details<br/>
 Windows implements the "Mark of the Web" (MotW) as an alternate data stream that contains not just the "zoneid" of where the file came from, but may include other data like the exact URL and referrer. <br/>
 <a href="https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732">https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732</a><br/>
Havoc Sharepoint with Microsoft Graph API<br/>
 A recent phishing attack observed by Fortinet uses a simple HTML email to trick a user into copy pasting powershell into their system to execute additional code. Most of the malware interaction uses a Sharepoint site via Microsoft's Graph API futher hiding the malicious traffic<br/>
<a href="https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2">https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2</a><br/>
Paragon Partition Manager Exploit<br/>
 A vulnerable Paragon Partition Manager has been user recently to escalate privileges for ransomware deployment. Even if you to not have PAragon installed: An attacker may just "bring the vulnerable driver" to your system.<br/>
 <a href="https://kb.cert.org/vuls/id/726882">https://kb.cert.org/vuls/id/726882</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9348" type="text/plain" language="en" />
<itunes:keywords>paragon, partition, manager, sharepoint, clickfix, click-fix, phishing, motw, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday Mar 3rd: AI Training Data Leaks; MITRE Caldera Vuln; modsecurity bypass
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9346</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday Mar 3rd: AI Training Data Leaks; MITRE Caldera Vuln; modsecurity bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday Mar 3rd: AI Training Data Leaks; MITRE Caldera Vuln; modsecurity bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9346.mp3" length="6274486" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9346.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9346</link>
<pubDate>Mon, 03 Mar 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Common Crawl includes Common Leaks<br/>
 The "Common Crawl" dataset, a large dataset created by spidering website, contains as expected many API keys and other secrets. This data is often used to train large language models<br/>
 <a href="https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data">https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data</a><br/>
Github Repositories Exposed by Copilot<br/>
 As it is well known, Github's Copilot is using data from public GitHub repositories to train it's model. However, it appears that repositories who were briefly left open and later made private have been included as well, allowing Copilot users to retrieve files from these repositories.<br/>
 <a href="https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot">https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot</a><br/>
MITRE Caldera Framework Allows Unauthenticated Code Execution<br/>
 The MITRE Caldera adversary emulation framework allows for unauthenticted code execution by allowing attackers to specify compiler options<br/>
 <a href="https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e">https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e</a><br/>
modsecurity Rule Bypass<br/>
 Attackers may bypass the modsecurity web application firewall by prepending encoded characters with 0.<br/>
 <a href="https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j">https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j</a><br/>
]]></description>
<itunes:duration>7:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9346" type="text/plain" language="en" />
<itunes:keywords>ai, copilot, api keys, mitre, caldera, common crawl, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9344</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9344.mp3" length="12414325" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9344.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9344</link>
<pubDate>Fri, 28 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Njrat Compaign Using Microsoft dev Tunnels:<br/>
 A recent version of the Njrat remote admin tool is taking advantage of Microsoft's developer tunnels (devtunnels.ms) as a command and control channel.<br/>
 <a href="https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724">https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724</a><br/>
NrootTag Apple FindMy Abuse<br/>
 Malware could use a weakness in the keys used for Apple FindMy to abuse it to track victims. Updates were released with iOS 18.2, but to solve the issue the vast majority of Apple users must update.<br/>
<a href="https://nroottag.github.io/">https://nroottag.github.io/</a><br/>
360XSS: Mass Website Exploitation via Virtual Tour Framework<br/>
 The Krpano VR library which is often used to implement 3D virtual tours on real estate websites, is currently being abused to inject spam messages. The XSS vulnerabilty could allow attackers to inject even more malicious JavaScript.<br/>
 <a href="https://olegzay.com/360xss/">https://olegzay.com/360xss/</a><br/>
SANS.edu Research: Proof is in the Pudding: EDR Configuration Versus Ransomware. Benjamin Powell<br/>
<a href="https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/">https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/</a><br/>
]]></description>
<itunes:duration>14:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9344" type="text/plain" language="en" />
<itunes:keywords>sans.edu, ben power, krpano, vr, 360, xss, findmy, ios, njrat, microsoft, devtunnels, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9342</itunes:episode>
<itunes:subtitle>SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9342.mp3" length="5950045" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9342.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9342</link>
<pubDate>Thu, 27 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Attacker of of Ephemeral Ports<br/>
 Attackers often use ephermeral ports to reach out to download additional resources or exfiltrate data. This can be used, with care, to detect possible compromises.<br/>
<a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710</a><br/>
Compromised Visal Studio Code Extension downloaded by Millions<br/>
 Amit Assaraf identified a likely compromised Visual Studio Code theme that was installed by millions of potential victims. Amit did not disclose the exact malicious behaviour, but is asking for victims to contact them for details.<br/>
 <a href="https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26">https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26</a> <br/>
ByBit Theft Due to Compromised Developer Workstation<br/>
 ByBit and Safe{Wallet} disclosed that the record breaking ethereum theft was due to a compromised Safe{Wallet} developer workstation. A replaced JavaScript file targeted ByBit and altered a transaction signed by ByBit.<br/>
 <a href="https://x.com/benbybit/status/1894768736084885929">https://x.com/benbybit/status/1894768736084885929</a><br/>
 <a href="https://x.com/safe/status/1894768522720350673">https://x.com/safe/status/1894768522720350673</a><br/>
PoC for NAKIVO Backup Replication Vulnerability<br/>
 This vulnerability allows the compromise of NAKIVO backup systems. The vulnerability was patched silently in November, and never disclosed by NAKIVO. Instead, WatchTowr now disloses details including a proof of concept exploit.<br/>
 <a href="https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/">https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/</a><br/>
OpenH264 Vulnerability<br/>
 <a href="https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x">https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x</a><br/>
rsync vulnerability exploited<br/>
 <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9342" type="text/plain" language="en" />
<itunes:keywords>rsync, openh254, nakivo, bybit, safewallet, visual studio code, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9340</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9340.mp3" length="5298015" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9340.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9340</link>
<pubDate>Wed, 26 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Massive Botnet Targets M365 with Password Spraying<br/>
 A large botnet is targeting service accounts in M365 with credentials stolen by infostealer malware.<br/>
 <a href="https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf">https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf</a><br/>
Mixing up Public and Private Keys in OpenID<br/>
 The complex OpenID specificiation and the flexibility it supports enables careless administrators to publich private keys instead or in addition to public keys<br/>
<a href="https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html">https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html</a><br/>
Healthcare Malware Hunt Part 1:<br/>
 Medial images are often encoded in the DICOM format, an image format unique to medical imaging. Patients looking for viewers for DICOM images are tricked into downloading malware.<br/>
 <a href="https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/">https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9340" type="text/plain" language="en" />
<itunes:keywords>dicom, medical, malware, openid, m365, infostealer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9338</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9338.mp3" length="5456793" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9338.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9338</link>
<pubDate>Tue, 25 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Unfurl Update Released<br/>
 Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs.<br/>
 <a href="https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716">https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716</a><br/>
Google Confirms GMail To Ditch SMS Code Authentication<br/>
 Google no longer considers SMS authentication save enough for GMail. Instead, it pushes users to use Passkeys, or QR code based app authentication<br/>
 <a href="https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/">https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/</a><br/>
Beware of Paypal New Address Feature Abuse<br/>
 Attackers are using "address change" e-mails to send links to phishing sites or trick users into calling fake tech support phone numbers. Attackers are just adding the malicious content as part of the address. The e-mail themselves are legitimate PayPal emails and will pass various spam and phishing filters.<br/>
 <a href="https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/">https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/</a><br/>
Exim SQL Injection Vulnerability<br/>
 Exim, with sqlite support and ETRN enabled, is vulnerable to a simple SQL injection exploit. A PoC has been released<br/>
<a href="https://www.exim.org/static/doc/security/CVE-2025-26794.txt">https://www.exim.org/static/doc/security/CVE-2025-26794.txt</a><br/>
<a href="https://github.com/OscarBataille/CVE-2025-26794?">https://github.com/OscarBataille/CVE-2025-26794?</a><br/>
XMLlib patches<br/>
 <a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/847">https://gitlab.gnome.org/GNOME/libxml2/-/issues/847</a><br/>
 <a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/828">https://gitlab.gnome.org/GNOME/libxml2/-/issues/828</a><br/>
0-Day in Parallels<br/>
 <a href="https://jhftss.github.io/Parallels-0-day/">https://jhftss.github.io/Parallels-0-day/</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9338" type="text/plain" language="en" />
<itunes:keywords>0-day, parallels, exim, sql, injection, paypal, phishing, sms, google, qmail, unfurl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9336</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9336.mp3" length="4756867" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9336.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9336</link>
<pubDate>Mon, 24 Feb 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
Tool Update: Sigs.py<br/>
 Jim updates sigs.py. The tool verifies hashes for files and automatically recognizes what hash is used.<br/>
<a href="https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706">https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706</a><br/>
Google Announcing Quantum Safe Digital Signatures in Cloud KMS<br/>
 Google announced the option to use quantum safe digital signatures for its<br/>
 cloud key management system.<br/>
<a href="https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms">https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms</a><br/>
Windows 11 Patch issues<br/>
 The February Patch Tuesday appears to have caused issues with a number of Windows 11 systems. In particular the usability of the file manager appears to be affected.<br/>
 <a href="https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/">https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/</a><br/>
LTE/5G Vulnerabilities<br/>
 Researchers at the university of Florida have identified a large number of vulnerabilities in 5G and LTE networks.<br/>
 <a href="https://nathanielbennett.com/publications/ransacked.pdf">https://nathanielbennett.com/publications/ransacked.pdf</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9336" type="text/plain" language="en" />
<itunes:keywords>ransacked, lte, 5g, windows 11, microsoft, patches, quantum, google, kms, signatures, hashes, sigs.py, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Friday Feb 21st: Kibana Queries; Mongoose Injection; U-Boot Flaws; Unifi Protect Camera Vulnerabilities; Protecting Network Devices as Endpoint (Austin Clark @sans_edu)
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9334</itunes:episode>
<itunes:subtitle>SANS Stormcast Friday Feb 21st: Kibana Queries; Mongoose Injection; U-Boot Flaws; Unifi Protect Camera Vulnerabilities; Protecting Network Devices as Endpoint (Austin Clark @sans_edu)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Friday Feb 21st: Kibana Queries; Mongoose Injection; U-Boot Flaws; Unifi Protect Camera Vulnerabilities; Protecting Network Devices as Endpoint (Austin Clark @sans_edu)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9334.mp3" length="10767483" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9334.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9334</link>
<pubDate>Fri, 21 Feb 2025 00:50:46 GMT</pubDate>
<description><![CDATA[<br/>
Using ES|QL In Kibana to Query DShield Honeypot Logs<br/>
 Using the "Elastic Search Piped Query Language" to query DShield honeypot logs<br/>
<a href="https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704">https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704</a><br/>
Mongoose Flaws Put MongoDB at risk<br/>
 The Object Direct Mapping library Mongoose suffers from an injection vulnerability leading to the potenitial of remote code exeuction in MongoDB<br/>
<a href="https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/">https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/</a><br/>
U-Boot Vulnerabilities<br/>
 The open source boot loader U-Boot does suffer from a number of issues allowing the bypass of its integrity checks. This may lead to the execution of malicious code on boot.<br/>
 <a href="https://www.openwall.com/lists/oss-security/2025/02/17/2">https://www.openwall.com/lists/oss-security/2025/02/17/2</a><br/>
Unifi Protect Camera Update<br/>
 <a href="https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f">https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f</a><br/>
]]></description>
<itunes:duration>12:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9334" type="text/plain" language="en" />
<itunes:keywords>unifi, protect, u-boot, honeypot, kibana, logs, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Wednesday Feb 20th: XWorm Cocktail; Quantum Computing Breakthrough; Signal Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9332</itunes:episode>
<itunes:subtitle>SANS Stormcast Wednesday Feb 20th: XWorm Cocktail; Quantum Computing Breakthrough; Signal Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Wednesday Feb 20th: XWorm Cocktail; Quantum Computing Breakthrough; Signal Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9332.mp3" length="6175716" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9332.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9332</link>
<pubDate>Thu, 20 Feb 2025 01:38:40 GMT</pubDate>
<description><![CDATA[<br/>
XWorm Cocktail: A Mix of PE data with PowerShell Code<br/>
 Quick analysis of an interesting XWrom sample with powershell code embedded inside an executable<br/>
<a href="https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700">https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700</a><br/>
Microsoft's Majorana 1 Chip Carves New Path for Quantum Computing<br/>
 Microsoft announced a breack through in Quantum computing. Its new prototype Majorana 1 chip takes advantage of exotic majorana particles to implement a scalable low error rate solution to building quantum computers<br/>
 <a href="https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/">https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/</a><br/>
Russia Targeting Signal Messenger<br/>
 Signal is well regarded as a secure end to end encrypted messaging platform. However, a user may be tricked into providing access to their account by scanning a QR code masquerading as a group channel invitation.<br/>
<a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/">https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/</a><br/>
]]></description>
<itunes:duration>7:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9332" type="text/plain" language="en" />
<itunes:keywords>russia, signal, ukraine, quantum, majorana, xworm, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9330</itunes:episode>
<itunes:subtitle>SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9330.mp3" length="6081218" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9330.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9330</link>
<pubDate>Wed, 19 Feb 2025 00:31:58 GMT</pubDate>
<description><![CDATA[<br/>
ModelScan: Protection Against Model Serialization Attacks<br/>
 ModelScan is a tool to inspect AI models for deserialization attacks. The tool will detect suspect commands and warn the user.<br/>
 <a href="https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692">https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692</a><br/>
OpenSSH MitM and DoS Vulnerabilities<br/>
 OpenSSH Patched two vulnerabilities discovered by Qualys. One may be used for MitM attack in specfic configurations of OpenSSH.<br/>
 <a href="https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt">https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt</a><br/>
Juniper Authentication Bypass<br/>
 Juniper fixed an authentication bypass vulnerability that affects several prodcuts. The patch was released outside the normal patch schedule.<br/>
 <a href="https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US">https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US</a><br/>
DELL BIOS Patches<br/>
 DELL released BIOS updates fixing a privilege escalation issue. The update affects a large part of Dell's portfolio<br/>
 <a href="https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021">https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021</a><br/>
]]></description>
<itunes:duration>6:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9330" type="text/plain" language="en" />
<itunes:keywords>dell, bios, juniper, openssh, modelscan, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9328</itunes:episode>
<itunes:subtitle>SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9328.mp3" length="4178747" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9328.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9328</link>
<pubDate>Tue, 18 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
My Very Personal Guidance and Strategies to Protect Network Edge Devices<br/>
 A quick summary to help you secure edge devices. This may be a bit opinionated, but these are the strategies that I find work and are actionable.<br/>
<a href="https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660">https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660</a><br/>
PostgreSQL SQL Injection<br/>
 A followup to yesterday's segment about the PostgreSQL vulnerability. Rapid7 released a Metasploit module to exploit the vulnerability.<br/>
<a href="https://github.com/rapid7/metasploit-framework/pull/19877">https://github.com/rapid7/metasploit-framework/pull/19877</a><br/>
Ivanti Connect Secure Exploited<br/>
 The Japanese CERT observed exploitation of January's Connect Secure vulnerability<br/>
<a href="https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html">https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html</a><br/>
WinZip Vulnerability<br/>
 WinZip patched a buffer overflow vulenrability that may be triggered by malicious 7Z files<br/>
<a href="https://www.zerodayinitiative.com/advisories/ZDI-25-047/">https://www.zerodayinitiative.com/advisories/ZDI-25-047/</a><br/>
Xerox Printer Patch<br/>
 Xerox patched two vulnerabililites in its enterprise multifunction printers that may be exploited for lateral movement.<br/>
 <a href="https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf">https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf</a><br/>
]]></description>
<itunes:duration>4:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9328" type="text/plain" language="en" />
<itunes:keywords>xerox, winzip, ivanti, connect secure, postgresql, sql, edge, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Monday Feb 17th: Fake BSOD; Volatile IPs; Postgresql libpq SQL Injection; OAUTH Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9326</itunes:episode>
<itunes:subtitle>SANS Stormcast Monday Feb 17th: Fake BSOD; Volatile IPs; Postgresql libpq SQL Injection; OAUTH Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Monday Feb 17th: Fake BSOD; Volatile IPs; Postgresql libpq SQL Injection; OAUTH Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9326.mp3" length="7450021" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9326.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9326</link>
<pubDate>Mon, 17 Feb 2025 01:22:04 GMT</pubDate>
<description><![CDATA[<br/>
Fake BSOD Delivered by Malicious Python Script<br/>
 Xavier found an odd malicious Python script that displays a blue screen of<br/>
death to users. The purpose isn't quite clear. It could be a teach support scam<br/>
tricking users into calling the 800 number displayed, or a simple<br/>
anti-reversing trick<br/>
 <a href="https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686">https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686</a><br/>
The Danger of IP Volatility<br/>
 Accounting for IP addresses is important, and if not done properly, may<br/>
 lead to resources being exposed after IP addresses are released.<br/>
 <a href="https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688">https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688</a><br/>
PostgreSQL SQL Injection<br/>
 Functions in PostgreSQL's libpq do not properly escape parameters which may<br/>
lead to SQL injection issues if the functions are used to create input for pqsql.<br/>
 <a href="https://www.postgresql.org/support/security/CVE-2025-1094/">https://www.postgresql.org/support/security/CVE-2025-1094/</a><br/>
Multiple Russian Threat Actors Targeting Microsoft Device Code Auth<br/>
 The OAUTH device code flow is used to attach devices with limited input capability to a user's account. However, this can be abused via phishing attacks.<br/>
<a href="https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/">https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/</a><br/>
]]></description>
<itunes:duration>8:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9326" type="text/plain" language="en" />
<itunes:keywords>oauth, postgresql, ip, volatility, bsod, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Feb 14th 2025: DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhone vs. Cisco; Crowdstrike Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9324</itunes:episode>
<itunes:subtitle>SANS Stormcast Feb 14th 2025: DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhone vs. Cisco; Crowdstrike Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Feb 14th 2025: DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhone vs. Cisco; Crowdstrike Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9324.mp3" length="5343574" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9324.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9324</link>
<pubDate>Fri, 14 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
DShield SIEM Docker Updates<br/>
 Interested in learning more about the attacks hitting your honeypot?<br/>
 Guy assembled a neat SIEM to create dashboards summarizing the attacks.<br/>
<a href="https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680">https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680</a><br/>
PANOS Path Confusion Auth Bypass<br/>
 Palo Alto Networks fixed a path confusion vulnerability introduced by the<br/>
 overly complex midle box chain in PANOS.<br/>
 <a href="https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/">https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/</a><br/>
 <a href="https://www.theregister.com/2025/02/13/palo_alto_firewall/">https://www.theregister.com/2025/02/13/palo_alto_firewall/</a><br/>
China's Volt Typhoon Continues to use Cisco Vulns<br/>
 Recorded Future wrote up some recent attacks of the Red Mike / Volt Typhoon groups going after telecom providers by compromissing Cisco systems via an older vulnerabilty<br/>
 <a href="https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/">https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/</a><br/>
Crowdstrike Patches Linux Client<br/>
 <a href="https://www.crowdstrike.com/security-advisories/cve-2025-1146/">https://www.crowdstrike.com/security-advisories/cve-2025-1146/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9324" type="text/plain" language="en" />
<itunes:keywords>crowdstrike, falcon, china, volt typhoon, redmike, cisco, panos, nginx, apache, php, dshield, siem, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Feb 13th 2025: Smart City Threats; Advanced Social Engineering Attacks; Wazuh Vulnerability; PAM Vulnerability; Ivanti Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9322</itunes:episode>
<itunes:subtitle>SANS Stormcast Feb 13th 2025: Smart City Threats; Advanced Social Engineering Attacks; Wazuh Vulnerability; PAM Vulnerability; Ivanti Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Feb 13th 2025: Smart City Threats; Advanced Social Engineering Attacks; Wazuh Vulnerability; PAM Vulnerability; Ivanti Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9322.mp3" length="5289644" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9322.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9322</link>
<pubDate>Thu, 13 Feb 2025 01:26:50 GMT</pubDate>
<description><![CDATA[<br/>
An Ontology for Threats: Cybercrime and Digital Forensic Investigation on Smart City Infrastructure<br/>
 Smart cities is a big topic for many local governments. With building these complex systems, attacks will follow. <br/>
 <a href="https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676">https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676</a><br/>
North Korean state actor tricking admins into executing PowerShell<br/>
 North Korean state actors are spending quite a bit of effort setting up relationships with South Korean system administrators, culminating in them getting tricked into executing malicious PowerShell scripts.<br/>
 <a href="https://x.com/MsftSecIntel/status/1889407814604296490">https://x.com/MsftSecIntel/status/1889407814604296490</a><br/>
Wazuh Vulnerability<br/>
 A deserialization vulnerability in Wazuh may lead to an unauthenticated remote code execution vulnerability<br/>
 <a href="https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh">https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh</a><br/>
PAM PKCS11 Vulnerablity<br/>
 Several vulnerabilities in the Linux PAM module processing smart card authentication can be used to bypass authentication<br/>
<a href="https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13">https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13</a><br/>
Ivanti Patches<br/>
 Ivanti released its monhtly update, fixing a number of critical vulnerabilities in Connect Secure and other prodcuts<br/>
<a href="https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US">https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9322" type="text/plain" language="en" />
<itunes:keywords>ivanti, pam, pkcs11, linux, wazuh, korea, powershell, ontology, smart city, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Feb 12th 2025: MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9320</itunes:episode>
<itunes:subtitle>SANS Stormcast Feb 12th 2025: MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Feb 12th 2025: MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9320.mp3" length="5217647" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9320.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9320</link>
<pubDate>Wed, 12 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
 Microsoft released patches for 55 vulnerabilities. Three of them are actagorized as critical, two are already exploited and another two have been publicly disclosed. The LDAP server vulnerability could become a huge deal, but it is not clear if an exploit will appear.<br/>
<a href="https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674">https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674</a><br/>
Adobe Patches<br/>
 Adobe released patches for seven products. Watch out in particular for the Adobe Commerce issues<br/>
<a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Fortinet Acknowledges Exploitation of Vulnerability<br/>
 <a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535">https://fortiguard.fortinet.com/psirt/FG-IR-24-535</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9320" type="text/plain" language="en" />
<itunes:keywords>fortinet, adobe, microsoft, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Stormcast Feb 11th 2025: 7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9318</itunes:episode>
<itunes:subtitle>SANS Stormcast Feb 11th 2025: 7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Stormcast Feb 11th 2025: 7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9318.mp3" length="6371398" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9318.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9318</link>
<pubDate>Tue, 11 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Reminder: 7-Zip MoW<br/>
 The MoW must be added to any files extracted from ZIP or other compound file formats. 7-Zip does not do so by default unless you alter the default configuration.<br/>
 <a href="https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668">https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668</a><br/>
Apple Fixes 0-Day<br/>
 Apple released updates to iOS and iPadOS fixing a bypass for USB Restricted Mode. The vulnerability is already being exploited.<br/>
 <a href="https://support.apple.com/en-us/122174">https://support.apple.com/en-us/122174</a><br/>
AMD ZEN CPU Microcode Update<br/>
 An attacker is able to replace microcode on some AMD CPUs. This may alter how the CPUs function and Google released a PoC showing how it can be used to manipulate the random number generator.<br/>
 <a href="https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w">https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w</a><br/>
Trimble Cityworks Exploited<br/>
 CISA added a recent Trimble Cityworks vulnerabliity to its list of exploited vulnerabilities. <br/>
 <a href="https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?">https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?</a><br/>
Google Tag Manager Skimmer Steals Credit Card Info<br/>
 Sucuri released a blog post with updates to the mage cart campaign. The latest version is injecting malicious code as part of the google tag manager / analytics code.<br/>
 <a href="https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html">https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9318" type="text/plain" language="en" />
<itunes:keywords>google, sucuri, amd, trimble, cityworks, tag manager, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Internet Stormcast Feb 10th 2025: Podcast Anniversary; SSL 2.0; Exposed Deepseek Installs; Crypto Scam costs
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9316</itunes:episode>
<itunes:subtitle>SANS Internet Stormcast Feb 10th 2025: Podcast Anniversary; SSL 2.0; Exposed Deepseek Installs; Crypto Scam costs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Internet Stormcast Feb 10th 2025: Podcast Anniversary; SSL 2.0; Exposed Deepseek Installs; Crypto Scam costs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9316.mp3" length="6038550" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9316.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9316</link>
<pubDate>Mon, 10 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
SSL 2.0 Turns 30 This Sunday<br/>
  SSL was created in February 1995. However, back in 2005, only a year later, SSL 3.0 was released, and as of 2011, SSL 2.0 was deprecated, and support was removed from many crypto libraries. However, over 400k hosts are still exposed via SSL 2.0.<br/>
  <a href="https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664">https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664</a><br/>
Deepseek News<br/>
 Many articles cover various security shortcomings in the Chinese Deepseek AI model. Remember that some of these issues are not unique to Deepseek.<br/>
<a href="https://www.upguard.com/blog/deepseek-adoption">https://www.upguard.com/blog/deepseek-adoption</a><br/>
<a href="https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face">https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face</a><br/>
<a href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak">https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</a><br/>
<a href="https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/">https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/</a><br/>
Crypto Wallet Scam Not For Free<br/>
  Didier looked closer at the recent dual signature crypto scams. These wallets are not free; attackers must spend money to set them up.<br/>
<a href="https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666">https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9316" type="text/plain" language="en" />
<itunes:keywords>crypto, deepseek, ssl, anniversary, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Internet Stormcast Feb 7th 2025: Unbreakable Anti-Debugging;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9314</itunes:episode>
<itunes:subtitle>SANS Internet Stormcast Feb 7th 2025: Unbreakable Anti-Debugging;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Internet Stormcast Feb 7th 2025: Unbreakable Anti-Debugging;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9314.mp3" length="5630055" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9314.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9314</link>
<pubDate>Fri, 07 Feb 2025 01:28:34 GMT</pubDate>
<description><![CDATA[<br/>
The Unbreakable Multi-Layer Anti-Debugging System<br/>
 Xavier found a nice Python script that included what it calls the "Unbreakable Multi-Layer Anti-Debugging System". Leave it up to Xavier to tear it appart for you.<br/>
 <a href="https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658">https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658</a><br/>
Take my money: OCR crypto stealers in Google Play and App Store<br/>
 Malware using OCR on screen shots was available not just via Google Play, but also the Apple App Store.<br/>
 <a href="https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/">https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/</a><br/>
Threat Actors Still Leveraging Legit RMM Tool ScreenConnect<br/>
 Unsurprisingly, threat actors still like to use legit remote admin tools, like ScreenConnect, as a command and control channel. Silent Push outlines the latest trends and IoCs they found<br/>
 <a href="https://www.silentpush.com/blog/screenconnect/">https://www.silentpush.com/blog/screenconnect/</a><br/>
Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities<br/>
 Java deserializing strikes again to allow arbitrary code execution. Cisco fixed this vulnerability and a authorization bypass issue in its Identity Services Engine<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF</a><br/>
F5 Update<br/>
 F5 fixes an interesting authentication bypass problem affecting TLS client certificates<br/>
 <a href="https://my.f5.com/manage/s/article/K000149173">https://my.f5.com/manage/s/article/K000149173</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9314" type="text/plain" language="en" />
<itunes:keywords>f5, java, cisco, ise, ios, android, screenshots, screenconnect, python, anti-debugging, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firefox CT Policy; Veeam and Netgear patches</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9312</itunes:episode>
<itunes:subtitle>SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firewall CT Policy; Veeam and Netgear patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firewall CT Policy; Veeam and Netgear patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9312.mp3" length="6197561" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9312.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9312</link>
<pubDate>Thu, 06 Feb 2025 01:30:25 GMT</pubDate>
<description><![CDATA[<br/>
Phishing via com- prefix domains<br/>
 Every day, attackers are registering a few hunder domain names starting with com-. These are used in phishing e-mails, like for example "toll fee scams", to create more convincing phishing links.<br/>
 <a href="https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654">https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654</a><br/>
Microsoft Windows 10 Extended Security Updates<br/>
 Microsoft released pricing and additional details for the Windows 10 extended security updates. For the first year after official free updates stopped, security updates will be available for $61 for the first year.<br/>
 <a href="https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates">https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates</a><br/>
Mozilla Enforcing Certificate Transparency<br/>
 Mozilla is following the lead from other browsers, and will require certificates to include a certificate signature timestamp as proof of compliance with certificate transparency requirements.<br/>
 <a href="https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ">https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ</a><br/>
 <a href="https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies">https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies</a><br/>
Veeam Update<br/>
 Veeam's internal backup process may be used to execute arbitrary code by an attacker with a machine in the middle position.<br/>
 <a href="https://www.veeam.com/kb4712">https://www.veeam.com/kb4712</a><br/>
Netgear Unauthenticated RCE<br/>
 <a href="https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039">https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9312" type="text/plain" language="en" />
<itunes:keywords>netgear, veeam, firefox, certificate transparency, ct, microsoft, windows 10, ESU, updates, phishing, sunpass, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS Internet Stormcast Feb 5th 2025: Feed Updates and Rosti; Resurrecting Dead S3 Buckets; Let's Encrypt Changes; Edge Device Security</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9310</itunes:episode>
<itunes:subtitle>SANS Internet Stormcast Feb 5th 2025: Feed Updates and Rosti; Resurrecting Dead S3 Buckets; Let's Encrypt Changes; Edge Device Security</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Internet Stormcast Feb 5th 2025: Feed Updates and Rosti; Resurrecting Dead S3 Buckets; Let's Encrypt Changes; Edge Device Security</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9310.mp3" length="6455924" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9310.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9310</link>
<pubDate>Wed, 05 Feb 2025 01:53:31 GMT</pubDate>
<description><![CDATA[<br/>
Some Updates to Our Data Feeds<br/>
 We made some updates to the documentation for our data feeds, and added the neat Rosti Feed to our list as well as to our ipinfo page.<br/>
 <a href="https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650">https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650</a><br/>
8 Million Request Later We Meade the Solarwindws Supply Chain Attack Look Amateur<br/>
 While the title is a bit of watchTowr hyperbole, the problem of resurrecting dead S3 buckets back to live is real and needs to be addressed. Boring solutions will help not becoming an exciting headline.<br/>
<a href="https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/">https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/</a><br/>
Let's Encrypt Ending Expiration Emails<br/>
 Let's Encrypt will no longer send emails for expiring certificates. They suggest other free services to send these emails for you<br/>
<a href="https://letsencrypt.org/2025/01/22/ending-expiration-emails/">https://letsencrypt.org/2025/01/22/ending-expiration-emails/</a><br/>
Guidance and Strategies Protect Network Edge Edvices<br/>
 CISA and other agencies created a guidance document outlining how to protect edge devices like firewalls, vpn concentrators and other similar devices.<br/>
 <a href="https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices">https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices</a><br/>
]]></description>
<itunes:duration>7:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9310" type="text/plain" language="en" />
<itunes:keywords>cisa, edge, devices, guidance, letsencrypt, email, s3, bucket, feeds, documentation, data, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast Feb 4th 2025: Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9308</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast Feb 4th 2025: Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast Feb 4th 2025: Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9308.mp3" length="5493011" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9308.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9308</link>
<pubDate>Tue, 04 Feb 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Crypto Wallet Scam<br/>
 YouTube spam messages leak private keys to crypto wallets. However, these keys can not be used to withdraw funds. Victims are scammed into depositing "gas fees" which are then collected by the scammer.<br/>
 <a href="https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646">https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646</a><br/>
Mediatek Patches<br/>
 Mediatek patched numerous vulnerabilities in its WLAN products. Some allow for unauthenticated arbitrary code execution<br/>
<a href="https://corp.mediatek.com/product-security-bulletin/February-2025">https://corp.mediatek.com/product-security-bulletin/February-2025</a><br/>
D-Link Vulnerability<br/>
 D-Link disclosed a vulnerability in older routers that as of May no longer receive any updates. Your only option is to upgrade hardare.<br/>
<a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415</a><br/>
Microsoft Discontinues VPN Service<br/>
 Microsoft is shutting down the VPN service that was included as part of Microsoft Defender<br/>
 <a href="https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a">https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9308" type="text/plain" language="en" />
<itunes:keywords>microsoft, dlink, mediatek, okx, crypto, scam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast Feb 3rd 2025: Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9306</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast Feb 3rd 2025: Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast Feb 3rd 2025: Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9306.mp3" length="5638390" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9306.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9306</link>
<pubDate>Mon, 03 Feb 2025 02:00:03 GMT</pubDate>
<description><![CDATA[<br/>
To Simulate or Replicate: Crafting Cyber Ranges<br/>
 Automating the creation of cyber ranges. This will be a multi part series and this part covers creating the DNS configuration in Windows<br/>
<a href="https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642">https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642</a><br/>
Scammers Exploiting Deepseek Hype<br/>
 Scammers are using the hype around Deepseek, and some of the confusion caused by it's site not being reachable, to scam users into installing malware. I am also including a link to a "jailbreak" of Deepseek (this part was not covered in the podcast).<br/>
 <a href="https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/">https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/</a><br/>
 <a href="https://lab.wallarm.com/jailbreaking-generative-ai/">https://lab.wallarm.com/jailbreaking-generative-ai/</a><br/>
PyPi Archived Status<br/>
 PyPi introduced a new feature to mark repositories as archived. This implies that the author is no longer maintaining the particular package<br/>
<a href="https://blog.pypi.org/posts/2025-01-30-archival/">https://blog.pypi.org/posts/2025-01-30-archival/</a><br/>
ICS Mecial Advisory: Comtec Patient Monitor Backdoor<br/>
 And interested backdoor was found in a Comtech Patient Monitor.<br/>
 <a href="https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01">https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9306" type="text/plain" language="en" />
<itunes:keywords>comtech, medical, backdoor, pypi, deepseek, dns, cyber range, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast Jan 31st 2025: Old Netgear Vuln in Depth; Lightning AI RCE; Canon Printer RCE; Deepseek Leak;
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9304</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast Jan 31st 2025: Old Netgear Vuln in Depth; Lightning AI RCE; Canon Printer RCE; Deepseek Leak;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast Jan 31st 2025: Old Netgear Vuln in Depth; Lightning AI RCE; Canon Printer RCE; Deepseek Leak;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9304.mp3" length="5031335" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9304.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9304</link>
<pubDate>Fri, 31 Jan 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
PCAPs or It Didn't Happen: Exposing an Old Netgear Vulnerability Still Active in 2025 [Guest Diary]<br/>
<a href="https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638">https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638</a><br/>
RCE Vulnerablity in AI Development Platform Lightning AI<br/>
 Noma Security discovered a neat remote code execution vulnerability in Lightning AI. This vulnerability is exploitable by tricking a logged in user into clicking a simple link.<br/>
 <a href="https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/">https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/</a><br/>
Canon Laser Printers and Small Office Multifunctional Printer Vulnerabilities<br/>
 Canon fixed three different vulnerablities affecting various laser and small office multifunctional printers. These vulnerabilities may lead to remote code execution, and there are some interesting exploit opportunities<br/>
 <a href="https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers">https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers</a><br/>
Deepseek ClickHouse Database Leak<br/>
 <a href="https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak">https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9304" type="text/plain" language="en" />
<itunes:keywords>deepseek, clickhouse, canon, ai, lightning, netgear, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9302</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9302.mp3" length="4936546" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9302.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9302</link>
<pubDate>Thu, 30 Jan 2025 02:00:12 GMT</pubDate>
<description><![CDATA[<br/>
From PowerShell to a Python Obfuscation Race!<br/>
 This information stealer not only emulates a PDF document convincingly, but also includes its own Python environment for Windows<br/>
 <a href="https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634">https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634</a><br/>
Alleged Active Exploit Sale of CVE-2024-55591 on Fortinet Devices<br/>
 An exploit for this week's Fortinet vulnerability is for sale on russian forums. Fortinet also requires patching of devices without cloud license within seven days of patch release<br/>
 <a href="https://x.com/MonThreat/status/1884577840185643345">https://x.com/MonThreat/status/1884577840185643345</a><br/>
 <a href="https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376">https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376</a><br/>
The Tainted Voyage: Uncovering Voyager's Vulnerabilities<br/>
 Sonarcube identified vulnerabilities in the popular PHP package Voyager. One of them allows arbitrary file uploads.<br/>
<a href="https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/">https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/</a><br/>
Hackers exploit critical unpatched flaw in Zyxel CPE devices<br/>
 A currently unpatches vulnerablity in Zyxel devices is actively exploited.<br/>
<a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/">https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/</a><br/>
VMSA-2025-0002: VMware Avi Load Balancer addresses an unauthenticated blind SQL Injection vulnerability (CVE-2025-22217)<br/>
 VMWare released a patch for the AVI Load Balancer addressing an unauthenticated blink SQL injection vulnerability.<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9302" type="text/plain" language="en" />
<itunes:keywords>vmware, avi load balancer, sql injection, voyager, laravel, php, zyxel, fortinet, python, powershell, garmin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9300</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9300.mp3" length="5421254" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9300.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9300</link>
<pubDate>Wed, 29 Jan 2025 02:00:01 GMT</pubDate>
<description><![CDATA[<br/>
Learn about fileless crypto stealers written in Python, the ongoing exploitation of recent SimpleHelp vulnerablities, new Apple Silicon Sidechannel attacks a Team Viewer Vulnerablity and an odd QR Code<br/>
Fileless Python InfoStealer Targeting Exodus<br/>
 This Python script targets Exodus crypto wallet and password managers to steal crypto currencies. It does not save exfiltrated data in files, but keeps it in memory for exfiltration<br/>
 <a href="https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630">https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630</a><br/>
Campaign Exploiting SimpleHelp Vulnerablity<br/>
 Arcticwolf observed attacks exploiting SimpleHelp for initial access to networks. It has not been verified, but is assumed that vulnerabilities made public about a week ago are being exploited.<br/>
<a href="https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/">https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/</a><br/>
Two new Side Channel Vulnerabilities in Apple Silicon<br/>
 SLAP (Data Speculation Attacks via Load Address Prediction): This attack exploits the Load Address Predictor in Apple CPUs starting with the M2/A15, allowing unauthorized access to sensitive data by mispredicting memory addresses. FLOP (Breaking the Apple M3 CPU via False Load Output Predictions): This attack targets the Load Value Predictor in Apple's M3/A17 CPUs, enabling attackers to execute arbitrary computations on incorrect data, potentially leaking sensitive information.<br/>
 <a href="https://predictors.fail/">https://predictors.fail/</a><br/>
Teamviewer Security Bulletin<br/>
 Teamviewer patched a privilege escalation vulnerability CVE-2025-0065 <br/>
 <a href="https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/">https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/</a><br/>
Odd QR Code<br/>
 A QR code may resolve to a different URL if looked at at an angle.<br/>
 <a href="https://mstdn.social/@isziaui/113874436953157913">https://mstdn.social/@isziaui/113874436953157913</a><br/>
Limited Discount for SANS Baltimore<br/>
 <a href="https://sans.org/u/1zQd">https://sans.org/u/1zQd</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9300" type="text/plain" language="en" />
<itunes:keywords>qr code, teamviewer, apple silicon, sidechannel, python, exodus, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9298</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9298.mp3" length="5509203" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9298.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9298</link>
<pubDate>Tue, 28 Jan 2025 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
This episode shows how attackers are bypassing phishing filter by abusing the "shy" softhyphen HTML entitiy. We got an update from Apple fixing a 0-day vulnerability in addition to a number of other issues. watchTowr show how to exploit an interesting FortiOS vulnerability and we have patches for Github Desktop and Apache Solr<br/>
An unusal shy z-wasp phish<br/>
 <a href="https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626">https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626</a><br/>
 How the soft hyphen "shy" HTML entity can be abused to bypass e-mail filters<br/>
Apple Patches<br/>
 <a href="https://support.apple.com/en-us/100100">https://support.apple.com/en-us/100100</a><br/>
 Apple released patches for all of its operating systems, fixing a 0-day vulnerability among many others issues<br/>
Get Fortirekt I am the Super_admin now<br/>
 <a href="https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/">https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/</a><br/>
 Details about a recent FortiOS Vulnerability<br/>
GitHub Desktop Vulnerability<br/>
 <a href="https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html">https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html</a><br/>
Apache Solr Vulnerability<br/>
 <a href="https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access">https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9298" type="text/plain" language="en" />
<itunes:keywords>solr, github, desktop, fortinet, fortios, apple, shy, html, z-wasp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 27, 2025: Access Brokers; Llama Stack Vuln; ESXi SSH Tunnels; Zyxel Boot Loops; Subary StarLeak
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9296</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 27, 2025: Access Brokers; Llama Stack Vuln; ESXi SSH Tunnels; Zyxel Boot Loops; Subary StarLeak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 27, 2025: Access Brokers; Llama Stack Vuln; ESXi SSH Tunnels; Zyxel Boot Loops; Subary StarLeak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9296.mp3" length="5712795" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9296.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9296</link>
<pubDate>Mon, 27 Jan 2025 00:20:09 GMT</pubDate>
<description><![CDATA[<br/>
Guest Diary: How Access Brokers Maintain Persistence<br/>
 Explore how cybercriminals utilize access brokers to persist within networks and the impact this has on organizational security.<br/>
 <a href="https://isc.sans.edu/forums/diary/Guest+Diary+How+Access+Brokers+Maintain+Persistence/31600/">https://isc.sans.edu/forums/diary/Guest+Diary+How+Access+Brokers+Maintain+Persistence/31600/</a><br/>
Critical Vulnerability in Meta's Llama Stack (CVE-2024-50050)<br/>
 A deep dive into CVE-2024-50050, a critical vulnerability affecting Meta's Llama Stack, with exploitation details and mitigation strategies.<br/>
 <a href="https://www.oligo.security/blog/cve-2024-50050-critical-vulnerability-in-meta-llama-llama-stack">https://www.oligo.security/blog/cve-2024-50050-critical-vulnerability-in-meta-llama-llama-stack</a><br/>
ESXi Ransomware and SSH Tunneling Defense Strategies<br/>
 Learn how to fortify your infrastructure against ransomware targeting ESXi environments, focusing on SSH tunneling and proactive measures.<br/>
 <a href="https://www.sygnia.co/blog/esxi-ransomware-ssh-tunneling-defense-strategies/">https://www.sygnia.co/blog/esxi-ransomware-ssh-tunneling-defense-strategies/</a><br/>
Zyxel USG FLEX/ATP Series Application Signature Recovery Steps<br/>
 Addressing issues with Zyxel s USG FLEX/ATP Series application signatures as of January 24, 2025, with a detailed recovery guide.<br/>
 <a href="https://support.zyxel.eu/hc/en-us/articles/24159250192658-USG-FLEX-ATP-Series-Recovery-Steps-for-Application-Signature-Issue-on-January-24th-2025">https://support.zyxel.eu/hc/en-us/articles/24159250192658-USG-FLEX-ATP-Series-Recovery-Steps-for-Application-Signature-Issue-on-January-24th-2025</a><br/>
Subaru Starlink Vulnerability Exposed Cars to Remote Hacking<br/>
 Discussing how a vulnerability in Subaru s Starlink system left vehicles susceptible to remote exploitation and the steps taken to resolve it.<br/>
 <a href="https://www.securityweek.com/subaru-starlink-vulnerability-exposed-cars-to-remote-hacking/">https://www.securityweek.com/subaru-starlink-vulnerability-exposed-cars-to-remote-hacking/</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9296" type="text/plain" language="en" />
<itunes:keywords>subaru, starlink, zyxel, usg flex, atp, esci, meta, llama, access broker, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 24, 2025: XSS in Email, SonicWall Exploited; Cisco Vulnerablities; AI and SOAR (@sans_edu research paper by Anthony Russo)
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9294</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 24, 2025: XSS in Email, SonicWall Exploited; Cisco Vulnerablities; AI and SOAR (@sans_edu research paper by Anthony Russo)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 24, 2025: XSS in Email, SonicWall Exploited; Cisco Vulnerablities; AI and SOAR (@sans_edu research paper by Anthony Russo)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9294.mp3" length="12664452" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9294.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9294</link>
<pubDate>Fri, 24 Jan 2025 00:13:40 GMT</pubDate>
<description><![CDATA[<br/>
In today's episode, learn how an attacker attempted to exploit webmail XSS vulnerablities against us. Sonicwall released a critical patch fixing an already exploited vulnerability in its SMA 1000 appliance. Cisco fixed vulnerabilities in ClamAV and its Meeting Manager REST API. Learn from SANS.edu student Anthony Russo how to take advantage of AI for SOAR.<br/>
XSS Attempts via E-Mail<br/>
 <a href="https://isc.sans.edu/diary/XSS%20Attempts%20via%20E-Mail/31620">https://isc.sans.edu/diary/XSS%20Attempts%20via%20E-Mail/31620</a><br/>
 An analysis of a recent surge in email-based XSS attack attempts targeting users and organizations. Learn the implications and mitigation techniques.<br/>
SonicWall PSIRT Advisory: CVE-2025-23006<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002</a> CVE-2025-23006<br/>
 Details of a critical vulnerability in SonicWall appliances (SNWLID-2025-0002) and what you need to do to secure your systems.<br/>
Cisco ClamAV Advisory: OLE2 Parsing Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA</a><br/>
 A DoS vulnerability in the popular open source anti virus engine ClamAV<br/>
Cisco CMM Privilege Escalation Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc</a><br/>
 A patch of a privilege escalation flaw in Cisco s CMM module.<br/>
]]></description>
<itunes:duration>14:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9294" type="text/plain" language="en" />
<itunes:keywords>cisco, cmm, clamav, ole2, sonicwall, sma 1000, xss, email, webmail, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 23, 2025: PFSync Protocol; Oracle CPU; Korean VPN Supply Chain Attack; Ivanti Guidance
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9292</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 23, 2025: PFSync Protocol; Oracle CPU; Korean VPN Supply Chain Attack; Ivanti Guidance
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 23, 2025: PFSync Protocol; Oracle CPU; Korean VPN Supply Chain Attack; Ivanti Guidance
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9292.mp3" length="6844299" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9292.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9292</link>
<pubDate>Wed, 22 Jan 2025 23:45:03 GMT</pubDate>
<description><![CDATA[In today's episode, we start by talking about the PFSYNC protocol used to synchronize firewall states to support failover. Oracle released it's quarterly critical patch update. ESET is reporting about a critical VPN supply chain attack and CISA released guidance for victims of recent Ivanti related attacks.<br/>
Catching CARP: Fishing for Firewall States in PFSync Traffic<br/>
<a href="https://isc.sans.edu/diary/Catching%20CARP%3A%20Fishing%20for%20Firewall%20Stat%20es%20in%20PFSync%20Traffic/31616)**">https://isc.sans.edu/diary/Catching%20CARP%3A%20Fishing%20for%20Firewall%20Stat%20es%20in%20PFSync%20Traffic/31616)**</a>  <br/>
  Discover how attackers exploit PFSync traffic to manipulate firewall states. This deep dive explores vulnerabilities and mitigation strategies in network defense.<br/>
Oracle Critical Patch Update   January 2025<br/>
<a href="https://www.oracle.com/security-alerts/cpujan2025.html)**">https://www.oracle.com/security-alerts/cpujan2025.html)**</a>  <br/>
  Oracle's January 2025 patch release addresses numerous critical vulnerabilities across their product suite. Learn about key updates and how to secure your systems.<br/>
PlushDaemon: Compromising the Supply Chain of a Korean VPN Service<br/>
<a href="https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/">https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/</a><br/>
  ESET Research uncovers PlushDaemon, a sophisticated supply chain attack targeting a Korean VPN provider. Understand the implications for supply chain security.<br/>
CISA Cybersecurity Advisory: AA25-022A<br/>
<a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a</a><br/>
  The latest advisory highlights active threats and mitigation strategies for critical infrastructure. Stay ahead with CISA s guidance on emerging cyber risks.<br/>
]]></description>
<itunes:duration>7:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9292" type="text/plain" language="en" />
<itunes:keywords>cisa, ivanti, vpn, korea, oracle, carp, pfsync, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 22, 2025: Geolocation via Starlink and Cloudflare; AI Prompt Risks; Homebrew Phishing
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9290</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 22, 2025: Geolocation via Starlink and Cloudflare; AI Prompt Risks; Homebrew Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 22, 2025: Geolocation via Starlink and Cloudflare; AI Prompt Risks; Homebrew Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9290.mp3" length="8053444" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9290.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9290</link>
<pubDate>Wed, 22 Jan 2025 02:15:02 GMT</pubDate>
<description><![CDATA[This episodes covers how Starlink users can be geolocated and how Cloudflare may help deanonymize users. The increased use of AI helpers leads to leaking data via careless prompts.<br/>
Geolocation and Starlink<br/>
 <a href="https://isc.sans.edu/diary/Geolocation%20and%20Starlink/31612">https://isc.sans.edu/diary/Geolocation%20and%20Starlink/31612</a><br/>
 Discover the potential geolocation risks associated with Starlink and how they might be exploited. This diary entry dives into new concerns for satellite internet users.<br/>
Deanonymizing Users via Cloudflare<br/>
 <a href="https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117">https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117</a><br/>
 Deanonymizing users by identifying which cloudflare server cashed particular content<br/>
Sage's AI Assistant and Customer Data Concerns<br/>
 <a href="https://www.theregister.com/2025/01/20/sage_copilot_data_issue/">https://www.theregister.com/2025/01/20/sage_copilot_data_issue/</a><br/>
 Examine how a Sage AI tool inadvertently exposed sensitive customer data, raising questions about AI governance and trust in business applications.<br/>
The Threat of Sensitive Data in Generative AI Prompts<br/>
 <a href="https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts">https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts</a><br/>
 Analyze how employees  careless prompts to generative AI tools can lead to sensitive data breaches and the importance of awareness training.<br/>
Homebrew Phishing<br/>
 <a href="https://x.com/ryanchenkie/status/1880730173634699393">https://x.com/ryanchenkie/status/1880730173634699393</a><br/>
]]></description>
<itunes:duration>9:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9290" type="text/plain" language="en" />
<itunes:keywords>phishing, homebrew, ai, prompts, leakage, gelocation, starlink, cloudflare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 21, 2025: Downloading Partial ZIP files; Remote Tools Used in Attakcs; Azure DevOps SSRF
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9288</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 21, 2025: Downloading Partial ZIP files; Remote Tools Used in Attakcs; Azure DevOps SSRF
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 21, 2025: Downloading Partial ZIP files; Remote Tools Used in Attakcs; Azure DevOps SSRF
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9288.mp3" length="5596880" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9288.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9288</link>
<pubDate>Tue, 21 Jan 2025 01:47:05 GMT</pubDate>
<description><![CDATA[In this episode, we talk about downloading and analyzing partial ZIP files, how legitimate remote access tools are used in recent compromises and how a research found an SSRF vulnerability in Azure DevOps<br/>
Partial ZIP File Downloads<br/>
 A closer look at how attackers are leveraging partial ZIP file downloads to bypass file verification systems and plant malicious content.<br/>
 <a href="https://isc.sans.edu/diary/Partial%20ZIP%20File%20Downloads/31608">https://isc.sans.edu/diary/Partial%20ZIP%20File%20Downloads/31608</a><br/>
Ukrainian CERT Advisory on AnyDesk Threat<br/>
 The Ukrainian CERT provides detailed guidance on identifying and mitigating recent cyber threats exploiting AnyDesk for unauthorized access.<br/>
 <a href="https://cert.gov.ua/article/6282069">https://cert.gov.ua/article/6282069</a><br/>
Finding SSRFs in Azure DevOps<br/>
 An in-depth analysis of how server-side request forgery (SSRF) vulnerabilities are discovered and exploited in Azure DevOps pipelines.<br/>
 <a href="https://binarysecurity.no/posts/2025/01/finding-ssrfs-in-devops">https://binarysecurity.no/posts/2025/01/finding-ssrfs-in-devops</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9288" type="text/plain" language="en" />
<itunes:keywords>devops, azure, ssrf, ukraine, cert, anydesk, zip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 20, 2025: Honeypots for Offense; SimpleHelp and UEFI Secure Boot Vulnerabilities
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9286</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 20, 2025: Honeypots for Offense; SimpleHelp and UEFI Secure Boot Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 20, 2025: Honeypots for Offense; SimpleHelp and UEFI Secure Boot Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9286.mp3" length="3134530" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9286.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9286</link>
<pubDate>Mon, 20 Jan 2025 00:48:15 GMT</pubDate>
<description><![CDATA[In this episode, we cover how to use honeypot data to keep your offensive infrastructure alive longer, three critical vulnerabilities in SimpleHelp that must be patched now, and an interesting vulnerability affecting many systems allowing UEFI Secure Boot bypass.<br/>
Leveraging Honeypot Data for Offensive Security Operations [Guest Diary] A recent guest diary on the SANS Internet Storm Center discusses how offensive security professionals can utilize honeypot data to enhance their operations. The diary highlights the detection of scans from multiple IP addresses, emphasizing the importance of monitoring non-standard user-agent strings in web requests.<br/>
<a href="https://isc.sans.edu/diary/Leveraging%20Honeypot%20Data%20for%20Offensive%20Security%20Operations%20%5BGuest%20Diary%5D/31596">https://isc.sans.edu/diary/Leveraging%20Honeypot%20Data%20for%20Offensive%20Security%20Operations%20%5BGuest%20Diary%5D/31596</a><br/>
Security Vulnerabilities in SimpleHelp 5.5.7 and Earlier SimpleHelp has released version 5.5.8 to address critical security vulnerabilities present in versions 5.5.7 and earlier. Users are strongly advised to upgrade to the latest version to prevent potential exploits. Detailed information and upgrade instructions are available on SimpleHelp's official website. <br/>
<a href="https://simple-help.com/kb---security-vulnerabilities-01-2025#send-us-your-questions">https://simple-help.com/kb---security-vulnerabilities-01-2025#send-us-your-questions</a><br/>
Under the Cloak of UEFI Secure Boot: Introducing CVE-2024-7344 ESET researchers have identified a new vulnerability, CVE-2024-7344, that allows attackers to bypass UEFI Secure Boot on most UEFI-based systems. This flaw enables the execution of untrusted code during system boot, potentially leading to the deployment of malicious UEFI bootkits. Affected users should apply available patches to mitigate this risk. <br/>
<a href="https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/">https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/</a><br/>
]]></description>
<itunes:duration>3:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9286" type="text/plain" language="en" />
<itunes:keywords>uefi, simplehelp, honeypots, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 17, 2025: Analyzing Complex Datasets, Citrix Update Issues, Ivanti's Security Advisory, and the Future of Passkeys (@sans_edu)
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9284</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 17, 2025: Analyzing Complex Datasets, Citrix Update Issues, Ivanti's Security Advisory, and the Future of Passkeys (@sans_edu)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 17, 2025: Analyzing Complex Datasets, Citrix Update Issues, Ivanti's Security Advisory, and the Future of Passkeys (@sans_edu)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9284.mp3" length="11053957" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9284.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9284</link>
<pubDate>Fri, 17 Jan 2025 00:39:29 GMT</pubDate>
<description><![CDATA[In this episode, we explore the efficient storage of honeypot logs in databases, issues with Citrix's Session Recording Agent and Windows Update. Ivanti is having another interesting security event and our SANS.edu graduate student Rich Green talks about his research on Passkeys.<br/>
Extracting Practical Observations from Impractical Datasets: A SANS Internet Storm Center diary entry discusses strategies for analyzing complex datasets to derive actionable insights.<br/>
<a href="https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582">https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582</a><br/>
Citrix Session Recording Agent Update Issue: Citrix reports that Microsoft's January security update fails or reverts on machines with the 2411 Session Recording Agent installed, providing guidance on addressing this issue.<br/>
<a href="https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US">https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US</a><br/>
Ivanti Endpoint Manager Security Advisory: Ivanti releases a security advisory for Endpoint Manager versions 2024 and 2022 SU6, detailing vulnerabilities and recommended actions.<br/>
<a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US</a><br/>
Revolutionizing Enterprise Security: The Exciting Future of Passkeys Beyond Passwords: A SANS.edu research paper explores the shift from traditional passwords to passkeys, highlighting the benefits and challenges of adopting passwordless authentication methods.<br/>
<a href="https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/">https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/</a><br/>
]]></description>
<itunes:duration>12:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9284" type="text/plain" language="en" />
<itunes:keywords>passkeys, citrix, ivanti, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 16, 2025: Critical Vulnerabilities and Cybersecurity Updates You Need to Know
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9282</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 16, 2025: Critical Vulnerabilities and Cybersecurity Updates You Need to Know
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 16, 2025: Critical Vulnerabilities and Cybersecurity Updates You Need to Know
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9282.mp3" length="7860214" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9282.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9282</link>
<pubDate>Thu, 16 Jan 2025 00:48:36 GMT</pubDate>
<description><![CDATA[Today's episode covers an odd 12 year old Netgear vulnerability that only received a proper CVE number last year. Learn about how to properly identify OpenID connect users and avoid domain name resue. Good old rsync turns out to be in need of patching and Fortinet: Not sure if it needs patching. Probably it does. Go ahead and patch it.<br/>
The Curious Case of a 12-Year-Old Netgear Router Vulnerability<br/>
Outdated Netgear routers remain a security risk, with attackers actively exploiting a 2013 vulnerability to deploy crypto miners. Learn how to protect your network by updating or replacing legacy hardware.<br/>
URL: <a href="https://isc.sans.edu/diary/The%20Curious%20Case%20of%20a%2012-Year-Old%20Netgear%20Router%20Vulnerability/31592">https://isc.sans.edu/diary/The%20Curious%20Case%20of%20a%2012-Year-Old%20Netgear%20Router%20Vulnerability/31592</a><br/>
Millions at Risk Due to Google s OAuth Flaw<br/>
A flaw in Google s OAuth implementation enables attackers to exploit defunct domain accounts, exposing sensitive data. Tips on implementing MFA and domain monitoring to reduce risks.<br/>
URL: <a href="https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw">https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw</a><br/>
Rsync 3.4.0 Security Release<br/>
The latest rsync update fixes critical vulnerabilities, including buffer overflows and symbolic link issues. Upgrade immediately to protect your file synchronization processes.<br/>
URL: <a href="https://download.samba.org/pub/rsync/NEWS#3.4.0">https://download.samba.org/pub/rsync/NEWS#3.4.0</a><br/>
Fortinet PSIRT Advisories: Stay Secure<br/>
Fortinet's latest advisories address vulnerabilities in FortiOS, FortiProxy, and more. Review and apply patches promptly to secure your perimeter defenses.<br/>
URL: <a href="https://www.fortiguard.com/psirt">https://www.fortiguard.com/psirt</a><br/>
]]></description>
<itunes:duration>9:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9282" type="text/plain" language="en" />
<itunes:keywords>fortinet, rsync, google, oauth, openid connect, netgear, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 14 2025: Microsoft Patch Tuesday, FortiOS and FortiProxy Patches; Paessler PRTG Patches
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9280</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 14 2025: Microsoft Patch Tuesday, FortiOS and FortiProxy Patches; Paessler PRTG Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 14 2025: Microsoft Patch Tuesday, FortiOS and FortiProxy Patches; Paessler PRTG Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9280.mp3" length="6830373" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9280.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9280</link>
<pubDate>Wed, 15 Jan 2025 00:33:59 GMT</pubDate>
<description><![CDATA[  Today, Microsoft Patch Tuesday headlines our news with Microsoft patching 209 vulnerabilities, some<br/>
of which have already been exploited. Fortinet suspects a so far unpatched Node.js authentication<br/>
bypass to be behind some recent exploits of FortiOS and FortiProxy devices.<br/>
Microsoft January 2025 Patch Tuesday<br/>
 This month's Microsoft patch update addresses a total of 209 vulnerabilities, including 12 classified as critical. Among these, 3 vulnerabilities have been actively exploited in the wild, and 5 have been disclosed prior to the patch release, marking them as zero-days.<br/>
 <a href="https://isc.sans.edu/diary/rss/31590">https://isc.sans.edu/diary/rss/31590</a><br/>
Fortinet Security Advisory FG-IR-24-535 CVE-2024-55591<br/>
 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.<br/>
 <a href="https://fortiguard.fortinet.com/psirt/FG-IR-24-535">https://fortiguard.fortinet.com/psirt/FG-IR-24-535</a><br/>
PRTG Network Monitor Update:<br/>
  Update for an already exploited XSS vulnerability in Paesler PRTG Network Monitor CVE-2024-12833<br/>
  <a href="https://www.paessler.com/prtg/history/stable">https://www.paessler.com/prtg/history/stable</a><br/>
]]></description>
<itunes:duration>7:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9280" type="text/plain" language="en" />
<itunes:keywords>prtg, fortinet, network monitor, paessler, access, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 14, 2025: Brute-Forcing Hikvision Devices, macOS SIP Bypass, Linux Rootkits, Aviatrix Exploits, and AWS Ransomware Tactics
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9278</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 14, 2025: Brute-Forcing Hikvision Devices, macOS SIP Bypass, Linux Rootkits, Aviatrix Exploits, and AWS Ransomware Tactics
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 14, 2025: Brute-Forcing Hikvision Devices, macOS SIP Bypass, Linux Rootkits, Aviatrix Exploits, and AWS Ransomware Tactics
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9278.mp3" length="6868245" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9278.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9278</link>
<pubDate>Mon, 13 Jan 2025 22:59:28 GMT</pubDate>
<description><![CDATA[Episode Summary:<br/>
This episode covers brute-force attacks on the password reset functionality of Hikvision devices, a macOS SIP bypass vulnerability, Linux rootkit malware, and a novel ransomware campaign targeting AWS S3 buckets.<br/>
Topics Covered:<br/>
Hikvision Password Reset Brute Forcing<br/>
URL: <a href="https://isc.sans.edu/diary/Hikvision%20Password%20Reset%20Brute%20Forcing/31586">https://isc.sans.edu/diary/Hikvision%20Password%20Reset%20Brute%20Forcing/31586</a><br/>
Hikvision devices are being targeted using old brute-force attacks exploiting predictable password reset codes. <br/>
Analyzing CVE-2024-44243: A macOS System Integrity Protection Bypass<br/>
URL: <a href="https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/">https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/</a><br/>
Microsoft details a macOS vulnerability allowing attackers to bypass SIP using kernel extensions. <br/>
Rootkit Malware Controls Linux Systems Remotely<br/>
URL: <a href="https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/">https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/</a><br/>
A sophisticated rootkit targeting Linux systems uses zero-day vulnerabilities for remote control. <br/>
Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C<br/>
URL: <a href="https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c">https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c</a><br/>
Attackers are using AWS s SSE-C encryption to lock S3 buckets during ransomware campaigns. We cover how the attack works and how to protect your AWS environment.<br/>
]]></description>
<itunes:duration>7:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9278" type="text/plain" language="en" />
<itunes:keywords>aws, sse-c, rootkit, malware, linux, macos, sip, hikvision, password reset, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 13, 2025: Defender Updates, Ivanti RCE, Apple USB-C Hack and more 
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9276</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 13, 2025: Defender Updates, Ivanti RCE, Apple USB-C Hack and more 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 13, 2025: Defender Updates, Ivanti RCE, Apple USB-C Hack and more 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9276.mp3" length="5917754" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9276.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9276</link>
<pubDate>Mon, 13 Jan 2025 01:42:35 GMT</pubDate>
<description><![CDATA[In today's episode, we cover the latest updates in cybersecurity:<br/>
Windows Defender Enhances Chrome Extension Detection<br/>
Microsoft's Defender now catalogs Chrome extensions to identify malicious ones. Learn how this improves enterprise security.<br/>
<a href="https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574">https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574</a><br/>
Multi-OLE Analysis in Malicious Documents<br/>
A look at how attackers embed OLE files in Office documents to evade detection and the tools to combat it.<br/>
<a href="https://isc.sans.edu/diary/Multi-OLE/31580">https://isc.sans.edu/diary/Multi-OLE/31580</a><br/>
Ivanti Connect Secure RCE Vulnerability (CVE-2025-0282)<br/>
Details of a critical vulnerability affecting Ivanti products and the patching timelines.<br/>
<a href="https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/">https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/</a><br/>
Apple USB-C Controller Compromised<br/>
Researchers hacked Apple s ACE3 USB-C controller, highlighting hardware security challenges.<br/>
<a href="https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/">https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/</a><br/>
IRS Pushes for IP PIN Enrollment<br/>
Protect yourself from tax-related identity theft by securing your IP PIN for the 2025 tax season.<br/>
<a href="https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season">https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season</a><br/>
]]></description>
<itunes:duration>6:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9276" type="text/plain" language="en" />
<itunes:keywords>irs, ip, pin, apple, usb-c, ivanty, rce, ole, ooxml, extensions, chrome, defender, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast: Cryptomining Malware, Fake PoC Exploit, Malicious Browser Extensions, and Palo Alto Vulnerabilities. Jan 9th 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9274</itunes:episode>
<itunes:subtitle>Cryptomining Malware, Fake PoC Exploit, Malicious Browser Extensions, and Palo Alto Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cryptomining Malware, Fake PoC Exploit, Malicious Browser Extensions, and Palo Alto Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9274.mp3" length="6418303" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9274.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9274</link>
<pubDate>Fri, 10 Jan 2025 01:26:17 GMT</pubDate>
<description><![CDATA[In this episode, we explore the following stories:<br/>
"Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics"<br/>
Overview of Redtail's multi-architecture cryptomining malware exploiting vulnerabilities and deploying persistence techniques.<br/>
URL: Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics<br/>
"Information Stealer Masquerades as LDAPNightmare PoC Exploit"<br/>
A malware disguised as a PoC exploit targets users seeking to test vulnerabilities like LDAPNightmare.<br/>
URL: Information Stealer Masquerades as LDAPNightmare PoC Exploit<br/>
"How Extensions Trick CWS Search"<br/>
Research reveals how malicious browser extensions manipulate Chrome Web Store search to appear legitimate.<br/>
URL: How Extensions Trick CWS Search<br/>
"Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)"<br/>
Multiple vulnerabilities in the deprecated Expedition tool can expose credentials and lead to unauthorized file and command execution.<br/>
URL: Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)<br/>
]]></description>
<itunes:duration>7:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9274" type="text/plain" language="en" />
<itunes:keywords>palo alto, chrome web store, extensions, chrome, google, fake exploits, ldap, cryptomining, redtail, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 9, 2025: Critical Vulnerabilities in Ivanti, Aviatrix, and Hijacked Backdoors in Compromised Systems
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9272</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 9, 2025: Critical Vulnerabilities in Ivanti, Aviatrix, and Hijacked Backdoors in Compromised Systems
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 9, 2025: Critical Vulnerabilities in Ivanti, Aviatrix, and Hijacked Backdoors in Compromised Systems
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9272.mp3" length="5365523" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9272.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9272</link>
<pubDate>Thu, 09 Jan 2025 01:32:18 GMT</pubDate>
<description><![CDATA[In this episode, we discuss critical vulnerabilities in Ivanti Connect Secure and Policy Secure, command injection risks in Aviatrix Network Controllers, and the risks posed by hijacked abandoned backdoors.<br/>
Episode Links and Topics:<br/>
More Governments Backdoors in Your Backdoors<br/>
<a href="https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/">https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/</a><br/>
Researchers reveal how expired domains linked to abandoned backdoors can be hijacked, exposing systems to further compromise.<br/>
Security Update: Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways<br/>
<a href="https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways">https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways</a><br/>
Ivanti addresses critical vulnerabilities (CVE-2025-0282, CVE-2025-0283) in their secure gateway products, with active exploitation in the wild.<br/>
CVE-2024-50603: Aviatrix Network Controller Command Injection Vulnerability<br/>
<a href="https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/">https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/</a><br/>
A command injection vulnerability in Aviatrix Network Controllers allows unauthenticated code execution, posing severe risks to network environments.<br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9272" type="text/plain" language="en" />
<itunes:keywords>aviatrix, ivanti, backdoors, domains, dumpster diving, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>SANS ISC Stormcast, Jan 8, 2025: Critical Vulnerabilities in SonicWall, Moxa, and Windows BitLocker – Plus, Malware Targets PHP Servers and the Launch of U.S. Cyber Trust Mark
</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9270</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast, Jan 8, 2025: Critical Vulnerabilities in SonicWall, Moxa, and Windows BitLocker – Plus, Malware Targets PHP Servers and the Launch of U.S. Cyber Trust Mark
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast, Jan 8, 2025: Critical Vulnerabilities in SonicWall, Moxa, and Windows BitLocker – Plus, Malware Targets PHP Servers and the Launch of U.S. Cyber Trust Mark
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9270.mp3" length="5860069" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9270.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9270</link>
<pubDate>Wed, 08 Jan 2025 01:31:58 GMT</pubDate>
<description><![CDATA[In this episode, we dive into active exploitation of a zero-day in SonicWall SSL-VPN, privilege escalation vulnerabilities in Moxa devices, and a BitLocker bypass in Windows 11. We also cover cryptocurrency mining malware hitting PHP servers and the White House's launch of the U.S. Cyber Trust Mark to secure connected devices.<br/>
Episode Links and Topics:<br/>
PacketCrypt Classic Cryptocurrency Miner on PHP Servers<br/>
<a href="https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564">https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564</a><br/>
Malware exploiting PHP servers to mine PacketCrypt Classic cryptocurrency.<br/>
SonicOS Affected By Multiple Vulnerabilities<br/>
<a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003</a><br/>
A zero-day vulnerability in SonicWall SSL-VPN devices is under active attack.<br/>
Privilege Escalation and OS Command Injection Vulnerabilities in Moxa Devices<br/>
<a href="https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo">https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo</a><br/>
Critical vulnerabilities in Moxa routers and security appliances allow privilege escalation and OS command injection.<br/>
White House Launches U.S. Cyber Trust Mark<br/>
<a href="https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/">https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/</a><br/>
A new cybersecurity labeling program for connected devices aims to help consumers choose secure products.<br/>
Windows BitLocker: Screwed without a Screwdriver<br/>
<a href="https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761">https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761</a><br/>
(video in English)<br/>
A two-year-old vulnerability in Windows 11 allows bypassing BitLocker encryption.<br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9270" type="text/plain" language="en" />
<itunes:keywords>bitlocker, windows, cyber trust mark, moxa, sonicos, packetcrypt, php, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 7th, 2025</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9268</itunes:episode>
<itunes:subtitle>SANS ISC Stormcast Jan 7th 2025: Make Malware Happy and Critical Vulnerabilities in OpenSSH, BeyondTrust, and Nuclei
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS ISC Stormcast Jan 7th 2025: Make Malware Happy and Critical Vulnerabilities in OpenSSH, BeyondTrust, and Nuclei
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9268.mp3" length="4359513" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9268.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9268</link>
<pubDate>Tue, 07 Jan 2025 01:26:19 GMT</pubDate>
<description><![CDATA[In this episode of the SANS Internet Storm Center's Stormcast, we cover critical vulnerabilities affecting OpenSSH, BeyondTrust, and Nuclei, including the newly discovered "RegreSSHion" flaw and a bypass vulnerability in Nuclei. We also discuss how malware evasion techniques can impact analysis environments and highlight the dangers of fake exploits targeting researchers. Tune in for insights on patching, mitigation strategies, and staying ahead of emerging threats.<br/>
Topics Covered:<br/>
Make Malware Happy<br/>
<a href="https://isc.sans.edu/diary/Make%20Malware%20Happy/31560">https://isc.sans.edu/diary/Make%20Malware%20Happy/31560</a><br/>
A look at how malware adapts and detects analysis environments, and why replicating operational settings is critical during malware analysis.<br/>
Nuclei Signature Verification Bypass (CVE-2024-43405)<br/>
<a href="https://www.wiz.io/blog/nuclei-signature-verification-bypass">https://www.wiz.io/blog/nuclei-signature-verification-bypass</a><br/>
A critical vulnerability in Nuclei allows malicious templates to bypass signature verification, risking arbitrary code execution.<br/>
Critical Vulnerability in BeyondTrust (CVE-2024-12356)<br/>
<a href="https://censys.com/cve-2024-12356/">https://censys.com/cve-2024-12356/</a><br/>
A high-risk flaw in BeyondTrust products allows unauthenticated OS command execution, posing a significant threat to privileged access systems.<br/>
RegreSSHion Code Execution Vulnerability (CVE-2024-6387)<br/>
<a href="https://cybersecuritynews.com/regresshion-code-execution-vulnerability/">https://cybersecuritynews.com/regresshion-code-execution-vulnerability/</a><br/>
OpenSSH vulnerability "RegreSSHion" enables remote code execution, and fake exploits targeting security researchers are in circulation.<br/>
]]></description>
<itunes:duration>4:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9268" type="text/plain" language="en" />
<itunes:keywords>openssh, regresshion, beyondtrust, nuclei, malware, evasion, rce, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 6th, 2025</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9266</itunes:episode>
<itunes:subtitle>Stormcast for Jan 6th 2024: Python SweatRAT, Goodware Hash Sets, SSL/TLS Updates and more.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Stormcast for Jan 6th 2024: Python SweatRAT, Goodware Hash Sets, SSL/TLS Updates and more.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9266.mp3" length="7228051" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9266.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9266</link>
<pubDate>Mon, 06 Jan 2025 02:37:57 GMT</pubDate>
<description><![CDATA[In this episode of the SANS Internet Storm Center's Stormcast, we cover the latest cybersecurity threats and defenses, including Python-delivered malware, goodware hash sets, SSL/TLS protocol updates, and critical vulnerabilities in ASUS routers and Paessler PRTG. Stay informed and secure your systems!<br/>
Full details and links to all stories:<br/>
SwaetRAT via Python: <a href="https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554">https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554</a><br/>
Goodware Hash Sets: <a href="https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556">https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556</a><br/>
SSL/TLS Updates: <a href="https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550">https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550</a><br/>
Cyberhaven Extension Compromise: <a href="https://secureannex.com/blog/cyberhaven-extension-compromise/">https://secureannex.com/blog/cyberhaven-extension-compromise/</a><br/>
PRTG Vulnerability: <a href="https://www.zerodayinitiative.com/advisories/ZDI-24-1736/">https://www.zerodayinitiative.com/advisories/ZDI-24-1736/</a><br/>
ASUS Router Vulnerabilities: <a href="https://cybersecuritynews.com/asus-router-vulnerabilities/">https://cybersecuritynews.com/asus-router-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>8:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9266" type="text/plain" language="en" />
<itunes:keywords>cyberhaven, chrome, extensions, asus, prtg, goodware, swaetrat, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 20th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9264</itunes:episode>
<itunes:subtitle>PPUnit and Androxgh0st; Session Smart Router Attack; FortiWLM Patch; BadBox Update; Beyond Trust Advisory
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PPUnit and Androxgh0st; Session Smart Router Attack; FortiWLM Patch; BadBox Update; Beyond Trust Advisory
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9264.mp3" length="5341828" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9264.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9264</link>
<pubDate>Fri, 20 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[PHPUnit and Androxgh0st<br/>
 <a href="https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528">https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528</a><br/>
Mirai Attacks Session Smart Routers<br/>
 <a href="https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US">https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US</a><br/>
FortiWLM Unauthenticated limited file read vulnerability<br/>
 <a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-144">https://fortiguard.fortinet.com/psirt/FG-IR-23-144</a><br/>
 <a href="https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/">https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/</a><br/>
Beyond Trust Security Advisory<br/>
 <a href="https://www.beyondtrust.com/trust-center/security-advisories/bt24-10">https://www.beyondtrust.com/trust-center/security-advisories/bt24-10</a><br/>
BadBox Update<br/>
 <a href="https://www.bitsight.com/blog/badbox-botnet-back">https://www.bitsight.com/blog/badbox-botnet-back</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9264" type="text/plain" language="en" />
<itunes:keywords>badbox, beyond trust, fortiwlm, fortinet, mirai, phpunit, androxgh0st, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9262</itunes:episode>
<itunes:subtitle>TeamTNT Deep Diver; Complex RDP Attacks; Okta Social Engineering; TP-Link Ban
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TeamTNT Deep Diver; Complex RDP Attacks; Okta Social Engineering; TP-Link Ban
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9262.mp3" length="6261066" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9262.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9262</link>
<pubDate>Thu, 19 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[A Deep Dive into TeamTNT and Spinning YARN<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530</a><br/>
Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks<br/>
 <a href="https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html">https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html</a><br/>
Okta Social Engineering Impersonation Report<br/>
 <a href="https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation">https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation</a><br/>
US considers banning TP-Link routers over cybersecurity risks<br/>
 <a href="https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/">https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/</a><br/>
CISA Releases Best Practice Guidance for Mobile Communications<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications">https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications</a><br/>
]]></description>
<itunes:duration>7:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9262" type="text/plain" language="en" />
<itunes:keywords>cisa, mobile, tp-link, okta, koshchei, rdp, teamtnt, yarn, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9260</itunes:episode>
<itunes:subtitle>Python Installs Anydesk; Vishing, Teams and Anydesk; SS7 Attacks; CrushFTP Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Installs Anydesk; Vishing, Teams and Anydesk; SS7 Attacks; CrushFTP Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9260.mp3" length="4717742" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9260.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9260</link>
<pubDate>Wed, 18 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Python Delivering AnyDesk Client as RAT<br/>
 <a href="https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/">https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/</a><br/>
Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion<br/>
 <a href="https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html">https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html</a><br/>
SS7 Attacks<br/>
 <a href="https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/">https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/</a><br/>
CrushFTP Vulnerability<br/>
 <a href="https://crushftp.com/crush11wiki/Wiki.jsp?page=Update">https://crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9260" type="text/plain" language="en" />
<itunes:keywords>crushftp, ss7, vishing, teams, python, anydesk, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9258</itunes:episode>
<itunes:subtitle>MUT-1244 Targeting Offensive Actors; Golang SSH Issue; Meeten Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MUT-1244 Targeting Offensive Actors; Golang SSH Issue; Meeten Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9258.mp3" length="5571152" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9258.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9258</link>
<pubDate>Tue, 17 Dec 2024 02:00:01 GMT</pubDate>
<description><![CDATA[MUT-1244 Targeting Offensive Actors<br/>
 <a href="https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/">https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/</a><br/>
Golang Crypto Vulnerability<br/>
 <a href="https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909">https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909</a><br/>
Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows<br/>
 <a href="https://www.cadosecurity.com/blog/meeten-malware-threat">https://www.cadosecurity.com/blog/meeten-malware-threat</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9258" type="text/plain" language="en" />
<itunes:keywords>meeten, malware, voip, video conference, golang, crypto, mut-1244, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9256</itunes:episode>
<itunes:subtitle>Struts 2 Exploited; Citrix Password Spraying; 6 Day Certs; Certified Pre-Pw0n3d
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Struts 2 Exploited; Citrix Password Spraying; 6 Day Certs; Certified Pre-Pw0n3d
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9256.mp3" length="4919585" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9256.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9256</link>
<pubDate>Mon, 16 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Exploit Attempts Inspired by Recent Struts 2 File Upload Vulnerability<br/>
 <a href="https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520">https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520</a><br/>
Citrix Netscaler Password Spraying Mitigation<br/>
 <a href="https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/">https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/</a><br/>
Let's Encrypt Six Day Certifiates<br/>
 <a href="https://letsencrypt.org/2024/12/11/eoy-letter-2024/">https://letsencrypt.org/2024/12/11/eoy-letter-2024/</a><br/>
Devices in Germany Arrived Pre-Pw0n3d<br/>
 <a href="https://cybersecuritynews.com/30000-devices-in-germany-discovered-with-pre-installed-malware-badbox/">https://cybersecuritynews.com/30000-devices-in-germany-discovered-with-pre-installed-malware-badbox/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9256" type="text/plain" language="en" />
<itunes:keywords>germany, badbox, lets encrypt, citrix, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9254</itunes:episode>
<itunes:subtitle>Windows 11 and TPM; Azure MFA Bypass; Struts 2 Vuln; Secret Blizzard vs Ukraine
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows 11 and TPM; Azure MFA Bypass; Struts 2 Vuln; Secret Blizzard vs Ukraine
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9254.mp3" length="5601619" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9254.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9254</link>
<pubDate>Fri, 13 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Windows 11 and TPM <br/>
 <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066">https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066</a><br/>
 <a href="https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/">https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/</a><br/>
Microsoft Azure MFA Bypass<br/>
 <a href="https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass">https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass</a><br/>
Struts 2 Arbitrary File Upload CVE-2024-53677<br/>
 <a href="https://cwiki.apache.org/confluence/display/WW/S2-067">https://cwiki.apache.org/confluence/display/WW/S2-067</a><br/>
Russian actor Secret Blizzard using tools of other groups to attack Ukraine<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/">https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9254" type="text/plain" language="en" />
<itunes:keywords>secret blizzard, ukraine, struts, azure, mfa, windows 11, tpm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9252</itunes:episode>
<itunes:subtitle>vSphere Scans; Apple Updates; Cleo Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
vSphere Scans; Apple Updates; Cleo Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9252.mp3" length="5151658" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9252.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9252</link>
<pubDate>Thu, 12 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Vulnerability Symbiosis: vSphere's CVE-2024-38812 and CVE-2024-38813<br/>
 <a href="https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510">https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510</a><br/>
Apple Updates Everything (iOS, iPadOS, macOS, watchOS, tvOS, visionOS)<br/>
 <a href="https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/">https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/</a><br/>
Widespread exploitation of Cleo file transfer software (CVE-2024-50623)<br/>
 <a href="https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild">https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild</a><br/>
 <a href="https://labs.watchtowr.com/cleo-cve-2024-50623/">https://labs.watchtowr.com/cleo-cve-2024-50623/</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9252" type="text/plain" language="en" />
<itunes:keywords>cleo, apple, vsphere, vmware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9250</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; Ivanti Vuln; Visual Studio Code Tunnels; Mitigating NTLM Relay Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; Ivanti Vuln; Visual Studio Code Tunnels; Mitigating NTLM Relay Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9250.mp3" length="4913078" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9250.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9250</link>
<pubDate>Wed, 11 Dec 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday December 2024<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508</a><br/>
Ivanty Security Advisory<br/>
 <a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US</a><br/>
Visual Studio Code Tunnels<br/>
 <a href="https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/">https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/</a><br/>
Mitigating NTLM Relay Attacks<br/>
 <a href="https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/">https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9250" type="text/plain" language="en" />
<itunes:keywords>ntlm, ivanti, visual studio code, microsoft, patch, tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9248</itunes:episode>
<itunes:subtitle>CURLing DDoS; OpenWRT Vuln; Android Update; RCS Not Always Encrypted
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CURLing DDoS; OpenWRT Vuln; Android Update; RCS Not Always Encrypted
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9248.mp3" length="5591948" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9248.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9248</link>
<pubDate>Tue, 10 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[CURLing for Crypto on Honeypots<br/>
 <a href="https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502">https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502</a><br/>
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection<br/>
 <a href="https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/">https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/</a><br/>
Android Monthly Update<br/>
 <a href="https://source.android.com/docs/security/bulletin/pixel/2024-12-01">https://source.android.com/docs/security/bulletin/pixel/2024-12-01</a><br/>
RCS Not Always Encrypted<br/>
 <a href="https://daringfireball.net/linked/2024/12/04/shame-on-google-messages">https://daringfireball.net/linked/2024/12/04/shame-on-google-messages</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9248" type="text/plain" language="en" />
<itunes:keywords>rcs, android, openwrt, curl, ddos, crypto, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9246</itunes:episode>
<itunes:subtitle>Version Cookies; URL File NTLM Leak; Ultralytics Miner; DaMAgeCard
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Version Cookies; URL File NTLM Leak; Ultralytics Miner; DaMAgeCard
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9246.mp3" length="5038564" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9246.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9246</link>
<pubDate>Mon, 09 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Bypassing WAFs with the Phantom Version Cookie<br/>
 <a href="https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie">https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie</a><br/>
URL File NTLM Hash Disclosure<br/>
 <a href="https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html">https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html</a><br/>
Ultralytics Library Infected with Miner<br/>
 <a href="https://github.com/ultralytics/ultralytics/issues/18027#issuecomment-2521578169">https://github.com/ultralytics/ultralytics/issues/18027#issuecomment-2521578169</a><br/>
DaMAgeCard attack targets memory directly thru SD card reader<br/>
 <a href="https://swarm.ptsecurity.com/new-dog-old-tricks-damagecard-attack-targets-memory-directly-thru-sd-card-reader/">https://swarm.ptsecurity.com/new-dog-old-tricks-damagecard-attack-targets-memory-directly-thru-sd-card-reader/</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9246" type="text/plain" language="en" />
<itunes:keywords>damagecard, ultralytics, miner, ntml, url file, waf, version, cookie, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9244</itunes:episode>
<itunes:subtitle>BEC Step by Step; Mital MiCollab PoC; Lorex Camera, HPE Aruba Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BEC Step by Step; Mital MiCollab PoC; Lorex Camera, HPE Aruba Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9244.mp3" length="4894302" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9244.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9244</link>
<pubDate>Fri, 06 Dec 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Business E-Mail Compromise<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474</a><br/>
Where There s Smoke, There s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day<br/>
 <a href="https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/">https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/</a><br/>
 <a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029</a><br/>
Lorex 2K Indoor Wi-Fi Security Camera<br/>
 <a href="https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf">https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf</a><br/>
 <a href="https://www.lorex.com/products/2k-indoor-wi-fi-security-camera">https://www.lorex.com/products/2k-indoor-wi-fi-security-camera</a><br/>
HPE Aruba Vulnerabilities<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US</a><br/>
Alan Paller Inducted into the Cybersecurity Hall of Fame<br/>
 <a href="https://cybersecurityhalloffame.org/">https://cybersecurityhalloffame.org/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9244" type="text/plain" language="en" />
<itunes:keywords>alan paller, lorex, hp, aruba, hpe, mitel, micollab, bec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9242</itunes:episode>
<itunes:subtitle>Importance of Data Analysis; Stop using SMS; Identity IQ vuln; Solana web3.js Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Importance of Data Analysis; Stop using SMS; Identity IQ vuln; Solana web3.js Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9242.mp3" length="4366536" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9242.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9242</link>
<pubDate>Thu, 05 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Data Analysis: The Unsung Hero of Cybersecurity Expertise<br/>
 <a href="https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494">https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494</a><br/>
FBI Warns iPhone and Android Users Stop Sending Texts<br/>
 <a href="https://www.forbes.com/sites/zakdoffman/2024/12/03/fbi-warns-iphone-and-android-users-stop-sending-texts/">https://www.forbes.com/sites/zakdoffman/2024/12/03/fbi-warns-iphone-and-android-users-stop-sending-texts/</a><br/>
IdentityIQ Improper Access Control Vulnerability   CVE-2024-10905<br/>
 <a href="https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905">https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905</a><br/>
Solana web3.js Backdoor<br/>
 <a href="https://socket.dev/blog/supply-chain-attack-solana-web3-js-library">https://socket.dev/blog/supply-chain-attack-solana-web3-js-library</a><br/>
]]></description>
<itunes:duration>4:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9242" type="text/plain" language="en" />
<itunes:keywords>data analysis, fbi, sms, rcs, identityiq, solana, web3.js, encryption, backdoor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9240</itunes:episode>
<itunes:subtitle>Files in Word; Sat Receiver DDoS Agent; Veeam Vuln; CVE-2024-49039 PoC;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Files in Word; Sat Receiver DDoS Agent; Veeam Vuln; CVE-2024-49039 PoC;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9240.mp3" length="4723226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9240.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9240</link>
<pubDate>Wed, 04 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Extracting Files Embedded Inside Word Documents<br/>
 <a href="https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486">https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486</a><br/>
Korea arrests CEO for adding DDoS feature to satellite receivers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/">https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/</a><br/>
Veeam Vulnerabilities<br/>
 <a href="https://www.veeam.com/kb4679">https://www.veeam.com/kb4679</a><br/>
WPTaskScheduler Presistence and CVE-2024-49039 PoC<br/>
 <a href="https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039">https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9240" type="text/plain" language="en" />
<itunes:keywords>word, satteliter, korea, receiver, ddoc, veeam, wptaksscheduler, scheduler, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 3rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9238</itunes:episode>
<itunes:subtitle>Credential Guard; AWS Key Rotation; Corrupt Document Phishing; IBM Security Verify Access Appliance vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Credential Guard; AWS Key Rotation; Corrupt Document Phishing; IBM Security Verify Access Appliance vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9238.mp3" length="5538622" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9238.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9238</link>
<pubDate>Tue, 03 Dec 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Credential Guard and Kerberos delegation<br/>
 <a href="https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488">https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488</a><br/>
The Day We Unveiled the Secret Rotation Illusion<br/>
 <a href="https://www.clutch.security/blog/the-day-we-unveiled-the-secret-rotation-illusion">https://www.clutch.security/blog/the-day-we-unveiled-the-secret-rotation-illusion</a><br/>
Corrupt Word Documents used in Phshing<br/>
 <a href="https://x.com/anyrun_app/status/1861024182210900357">https://x.com/anyrun_app/status/1861024182210900357</a><br/>
IBM Security Verify Access Appliance Vulnerabilities<br/>
 <a href="https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-were-found-ibm-security-verify-access-appliance-cve-2024-49803-cve-2024-49804-cve-2024-49805-cve-2024-49806">https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-were-found-ibm-security-verify-access-appliance-cve-2024-49803-cve-2024-49804-cve-2024-49805-cve-2024-49806</a> <br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9238" type="text/plain" language="en" />
<itunes:keywords>ibm, credentials, static, word, corrupt, aws, keys, apis, credential guard, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 2nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9236</itunes:episode>
<itunes:subtitle>AWS Honeypot+SIEM; Obfuscated Infostealer; Magento Skimmer; LogoFAIL Exploit;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AWS Honeypot+SIEM; Obfuscated Infostealer; Magento Skimmer; LogoFAIL Exploit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9236.mp3" length="5163160" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9236.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9236</link>
<pubDate>Mon, 02 Dec 2024 02:00:01 GMT</pubDate>
<description><![CDATA[AWS DShield Sensor + DShield SIEM<br/>
 <a href="https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480">https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480</a><br/>
From a Regular Infostealer to its Obfuscated Version<br/>
 <a href="https://isc.sans.edu/diary/From%20a%20Regular%20Infostealer%20to%20its%20Obfuscated%20Version/31484">https://isc.sans.edu/diary/From%20a%20Regular%20Infostealer%20to%20its%20Obfuscated%20Version/31484</a><br/>
Credit Card Skimmer Malware Targeting Magento Checkout Pages<br/>
 <a href="https://blog.sucuri.net/2024/11/credit-card-skimmer-malware-targeting-magento-checkout-pages.html">https://blog.sucuri.net/2024/11/credit-card-skimmer-malware-targeting-magento-checkout-pages.html</a><br/>
LogoFAIL Exploited to Deploy Bootkitty, the first UEFI bootkit for Linux<br/>
 <a href="https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux">https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux</a><br/>
Stickers:<br/>
 <a href="https://isc.sans.edu/stickers.html">https://isc.sans.edu/stickers.html</a> (code PODCAST)<br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9236" type="text/plain" language="en" />
<itunes:keywords>stickers, logofail, bootkitty, skimmer, magento, infostealer, obfuscation, aws, dshield, sensor, siem, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 27th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9234</itunes:episode>
<itunes:subtitle>Network Detection for Redtail; Next Neighbor; NachoVPN; Keycloak, PAN and Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Network Detection for Redtail; Next Neighbor; NachoVPN; Keycloak, PAN and Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9234.mp3" length="5527843" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9234.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9234</link>
<pubDate>Wed, 27 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472</a><br/>
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access<br/>
 <a href="https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/">https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/</a><br/>
Introducing NachoVPN: One VPN Server to Pwn Them All<br/>
 <a href="https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/">https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/</a><br/>
Keycloak Patches<br/>
 <a href="https://github.com/keycloak/keycloak/security/advisories/GHSA-93ww-43rr-79v3">https://github.com/keycloak/keycloak/security/advisories/GHSA-93ww-43rr-79v3</a><br/>
Palo Alto Networks Global Protect App<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2024-5921">https://security.paloaltonetworks.com/CVE-2024-5921</a><br/>
PHP Updates<br/>
 <a href="https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff">https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9234" type="text/plain" language="en" />
<itunes:keywords>php, pan, keycloak, nachovpn, miner, wifi, next neighbor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9232</itunes:episode>
<itunes:subtitle>Quick JS Deobfuscation; PDFs with Passwords; Less Russian Servers; QNAP Bug; 7-ZIP Bug;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Quick JS Deobfuscation; PDFs with Passwords; Less Russian Servers; QNAP Bug; 7-ZIP Bug;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9232.mp3" length="3984026" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9232.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9232</link>
<pubDate>Tue, 26 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Quick & Dirty Obfuscated JavaScript Analysis<br/>
 <a href="https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468">https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468</a><br/>
Decrypting a PDF With a User Password<br/>
 <a href="https://isc.sans.edu/diary/Decrypting%20a%20PDF%20With%20a%20User%20Password/31466">https://isc.sans.edu/diary/Decrypting%20a%20PDF%20With%20a%20User%20Password/31466</a><br/>
The strange case of disappearing Russian servers<br/>
 <a href="https://isc.sans.edu/diary/The%20strange%20case%20of%20disappearing%20Russian%20servers/31476">https://isc.sans.edu/diary/The%20strange%20case%20of%20disappearing%20Russian%20servers/31476</a><br/>
QNAP Buggy Firmware Update<br/>
 <a href="https://community.qnap.com/t/firmware-qts-5-2-2-2950-build-20241114-released/254">https://community.qnap.com/t/firmware-qts-5-2-2-2950-build-20241114-released/254</a><br/>
7-ZIP Zstandard Decompression Integer Underflow<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-24-1532/">https://www.zerodayinitiative.com/advisories/ZDI-24-1532/</a><br/>
 <a href="https://7-zip.org/download.html">https://7-zip.org/download.html</a><br/>
]]></description>
<itunes:duration>4:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9232" type="text/plain" language="en" />
<itunes:keywords>7zip, qnap, russia, servers, shodan, pdf, javascript, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9230</itunes:episode>
<itunes:subtitle>SVG Phishing; FortiClient VPN Logging; Needrestart Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SVG Phishing; FortiClient VPN Logging; Needrestart Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9230.mp3" length="5021195" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9230.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9230</link>
<pubDate>Fri, 22 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Increase In Phishing SVG Attachments<br/>
 <a href="https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456">https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456</a><br/>
Logging blind spot revealed in FortiClient VPN<br/>
 <a href="https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/">https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/</a><br/>
Needrestart Vulnerability<br/>
 <a href="https://www.qualys.com/2024/11/19/needrestart/needrestart.txt">https://www.qualys.com/2024/11/19/needrestart/needrestart.txt</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9230" type="text/plain" language="en" />
<itunes:keywords>needrestart, logging, forticlient, phishing, svg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 21st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9228</itunes:episode>
<itunes:subtitle>Apple Patches; Oracle PLM Vulns; OFBiz Patches; D-Link EOL Product Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patches; Oracle PLM Vulns; OFBiz Patches; D-Link EOL Product Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9228.mp3" length="4554596" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9228.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9228</link>
<pubDate>Thu, 21 Nov 2024 08:50:04 GMT</pubDate>
<description><![CDATA[Apple Patches Two Exploited Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452">https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452</a><br/>
Oracle Patch for Agile Product Lifecycle Management CVE-2024-21287<br/>
 <a href="https://www.oracle.com/security-alerts/alert-cve-2024-21287.html">https://www.oracle.com/security-alerts/alert-cve-2024-21287.html</a><br/>
OFBiz Patches CVE-2024-47208 CVE-2024-48962<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47208">https://nvd.nist.gov/vuln/detail/CVE-2024-47208</a><br/>
 <a href="https://seclists.org/oss-sec/2024/q4/95">https://seclists.org/oss-sec/2024/q4/95</a><br/>
D-Link Warns of Vulnerability in EOL Devices<br/>
 <a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415</a><br/>
 <br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9228" type="text/plain" language="en" />
<itunes:keywords>ofbiz, d-link, oracle, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 20th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9226</itunes:episode>
<itunes:subtitle>Python Debugger Detection; PAN-OS Patches; VCenter Attacks; Veritas Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Debugger Detection; PAN-OS Patches; VCenter Attacks; Veritas Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9226.mp3" length="5514398" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9226.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9226</link>
<pubDate>Wed, 20 Nov 2024 02:45:06 GMT</pubDate>
<description><![CDATA[Detecting the Presence of a Debugger in Linux<br/>
 <a href="https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450">https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450</a><br/>
Palo Alto Patches<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2024-0012">https://security.paloaltonetworks.com/CVE-2024-0012</a><br/>
 <a href="https://security.paloaltonetworks.com/CVE-2024-9474">https://security.paloaltonetworks.com/CVE-2024-9474</a><br/>
VMware vCenter Server Attacks<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e</a><br/>
Veritas Enterprise Vault Vulnerability<br/>
 <a href="https://www.veritas.com/support/en_US/security/VTS24-014">https://www.veritas.com/support/en_US/security/VTS24-014</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9226" type="text/plain" language="en" />
<itunes:keywords>veritas, enterprise, vault, vmware, vcenter, server, palo alto, pan, debugger, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9224</itunes:episode>
<itunes:subtitle>Unpatched Citrix Vuln Exploited; Microsoft Power Pages Issues; Manageengine ADAudit Plus SQL Injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Unpatched Citrix Vuln Exploited; Microsoft Power Pages Issues; Manageengine ADAudit Plus SQL Injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9224.mp3" length="4696672" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9224.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9224</link>
<pubDate>Tue, 19 Nov 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Exploit attempts for unpatched Citrix vulnerability CVE-2024-8068/CVE-2024-8069<br/>
 <a href="https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446">https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446</a><br/>
 <a href="https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US">https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US</a><br/>
Microsoft Power Pages: Data Exposure Reviewed<br/>
 <a href="https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/">https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/</a><br/>
Zohocorp ManageEngine ADAudit Plus Vulnerable To SQL Injection Attacks CVE-2024-49574<br/>
 <a href="https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html">https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9224" type="text/plain" language="en" />
<itunes:keywords>zohocorp, manageengine, adaudit, microsoft, power pages, ctrix, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9222</itunes:episode>
<itunes:subtitle>Ancient Vulns; GitHub Impersonations; PaloAlto and Fortinet still not secure
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ancient Vulns; GitHub Impersonations; PaloAlto and Fortinet still not secure
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9222.mp3" length="5545209" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9222.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9222</link>
<pubDate>Mon, 18 Nov 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Ancient TP-Link Backdoor Discovered by Attackers<br/>
 <a href="https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442">https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442</a><br/>
GitHub Projects Targeted with Malicious Commits To Frame Researchers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/">https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/</a><br/>
PaloAlto and Fortinet Vulnerabilities<br/>
 <a href="https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/">https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/</a><br/>
 <a href="https://security.paloaltonetworks.com/PAN-SA-2024-0015">https://security.paloaltonetworks.com/PAN-SA-2024-0015</a><br/>
 <a href="https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/">https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9222" type="text/plain" language="en" />
<itunes:keywords>paloalto, pan, fortinet, github, impersonation, tp-link, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9220</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; CISA Top Exploited Vulns; APT Embeds Malware Using Flutter
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; CISA Top Exploited Vulns; APT Embeds Malware Using Flutter
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9220.mp3" length="5210296" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9220.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9220</link>
<pubDate>Wed, 13 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft November 2024 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438">https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438</a><br/>
CISA Top Routinely Exploited Vulnerabilities<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a</a><br/>
APT Actors Embed Malware within macOS Flutter Applications<br/>
 <a href="https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/">https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9220" type="text/plain" language="en" />
<itunes:keywords>apt, macos, flutter, cisa, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9218</itunes:episode>
<itunes:subtitle>PDF Phish Analysis; Mazda Vulns; Ruby SAML Vuln Details; Veeam Vuln; Fake FBI EDRs;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF Phish Analysis; Mazda Vulns; Ruby SAML Vuln Details; Veeam Vuln; Fake FBI EDRs;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9218.mp3" length="5394543" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9218.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9218</link>
<pubDate>Tue, 12 Nov 2024 02:00:01 GMT</pubDate>
<description><![CDATA[PDF Object Streams<br/>
 <a href="https://isc.sans.edu/diary/PDF%20Object%20Streams/31430">https://isc.sans.edu/diary/PDF%20Object%20Streams/31430</a><br/>
Mazda Infotainment Vulnerabilities<br/>
 <a href="https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system">https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system</a><br/>
Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight<br/>
 <a href="https://workos.com/blog/ruby-saml-cve-2024-45409">https://workos.com/blog/ruby-saml-cve-2024-45409</a><br/>
Veeam Backup Enterprise Manager Vulnerability<br/>
 <a href="https://www.veeam.com/kb4682">https://www.veeam.com/kb4682</a><br/>
Security Update for Dell Enterprise SONiC Distribution Vulnerabilities<br/>
 <a href="https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities">https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities</a><br/>
Easy Access to Information for Conducting Fraudulent<br/>
Emergency Data Requests Impacts US-Based Companies<br/>
and Law Enforcement Agencies<br/>
 <a href="https://www.ic3.gov/CSA/2024/241104.pdf">https://www.ic3.gov/CSA/2024/241104.pdf</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9218" type="text/plain" language="en" />
<itunes:keywords>fbi, dell, sonic, veeam, workos, ruby, saml, pdf, pdfid, pdf-parser, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9216</itunes:episode>
<itunes:subtitle>zipdump and PKZIP; Am I Isolated; iOS Lock Reboot; PAN Bulletin; D-Link Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
zipdump and PKZIP; Am I Isolated; iOS Lock Reboot; PAN Bulletin; D-Link Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9216.mp3" length="4765286" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9216.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9216</link>
<pubDate>Mon, 11 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[zipdump and pkzip records<br/>
 <a href="https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428">https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428</a><br/>
Am I Isolated<br/>
 <a href="https://github.com/edera-dev/am-i-isolated">https://github.com/edera-dev/am-i-isolated</a><br/>
Locked iPhones Reboot<br/>
 <a href="https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/">https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/</a><br/>
 <a href="https://x.com/naehrdine/status/1854896392797360484">https://x.com/naehrdine/status/1854896392797360484</a><br/>
Palo Alto Networks Bulletin<br/>
 <a href="https://security.paloaltonetworks.com/PAN-SA-2024-0015">https://security.paloaltonetworks.com/PAN-SA-2024-0015</a><br/>
D-Link Vulnerability<br/>
 <a href="https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07">https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9216" type="text/plain" language="en" />
<itunes:keywords>dlink, palo alto networks, pan, pan-os, iphones, docker, isolated, zipbdump, pkzip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9214</itunes:episode>
<itunes:subtitle>Malicious Steam Bruteforcer; Cisco and Veem Patches; ZIP file issues; File Upload Dangers; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Steam Bruteforcer; Cisco and Veem Patches; ZIP file issues; File Upload Dangers; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9214.mp3" length="5227066" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9214.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9214</link>
<pubDate>Fri, 08 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Steam Account Checker Poisoned with Infostealer<br/>
 <a href="https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420">https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420</a><br/>
Cisco Ultra Reliable Wireless Backhaul Vulnerability<br/>
 <a href="https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html">https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html</a><br/>
Breaking Down Multipart Parsers: File upload validation bypass<br/>
 <a href="https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/">https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/</a><br/>
Evasive ZIP Concatenation: Trojan Targets Windows Users<br/>
 <a href="https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/">https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/</a><br/>
Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)<br/>
 <a href="https://www.veeam.com/kb4682">https://www.veeam.com/kb4682</a><br/>
SANS Holiday Hack Challenge<br/>
 <a href="https://www.sans.org/mlp/holiday-hack-challenge-2024">https://www.sans.org/mlp/holiday-hack-challenge-2024</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9214" type="text/plain" language="en" />
<itunes:keywords>holiday, hack, challenge, sans, veeam, backup, zip, concatentation, file upload, parser, cisco, steam, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 7th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9212</itunes:episode>
<itunes:subtitle>Web Attack Surge; Air Fryer Privacy; Pygmy Goat Malware; Apple Vuln PoC; HPE Aruba critical vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Web Attack Surge; Air Fryer Privacy; Pygmy Goat Malware; Apple Vuln PoC; HPE Aruba critical vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9212.mp3" length="4207024" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9212.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9212</link>
<pubDate>Thu, 07 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Insights from August Web Traffic Surge<br/>
 <a href="https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/">https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/</a><br/>
Talkative Air Fryer<br/>
 <a href="https://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c">https://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c</a><br/>
Pygmy Goat Malware Report<br/>
 <a href="https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports">https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports</a><br/>
Apple CVE-2024-44258 PoC Exploit<br/>
 <a href="https://github.com/ifpdz/CVE-2024-44258">https://github.com/ifpdz/CVE-2024-44258</a><br/>
HPE Arruba vulnerabilities<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US</a><br/>
]]></description>
<itunes:duration>4:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9212" type="text/plain" language="en" />
<itunes:keywords>hpe, arruba, apple, Poc, pygmy, goat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9210</itunes:episode>
<itunes:subtitle>Python RAT Screen Share; Android Security Bulletin; VMs Delivery Malware; Fake Docusign Invoices
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python RAT Screen Share; Android Security Bulletin; VMs Delivery Malware; Fake Docusign Invoices
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9210.mp3" length="4871509" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9210.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9210</link>
<pubDate>Wed, 06 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Python RAT with a Nice Screensharing Feature<br/>
 <a href="https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414">https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414</a><br/>
Android Security Bulletin November 2024<br/>
 <a href="https://source.android.com/docs/security/bulletin/2024-11-01">https://source.android.com/docs/security/bulletin/2024-11-01</a><br/>
Malware Delivered as Virtual Machine<br/>
 <a href="https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/">https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/</a><br/>
Fake Docusign Invoices<br/>
 <a href="https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/">https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9210" type="text/plain" language="en" />
<itunes:keywords>docusign, malware, vm, android, november, python, rat, screensharing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9208</itunes:episode>
<itunes:subtitle>Analyzing Encrypted PDFs; Okta Passwordless Password Leak; QuRouter Patch; Google AI Tool finds SQLite vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing Encrypted PDFs; Okta Passwordless Password Leak; QuRouter Patch; Google AI Tool finds SQLite vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9208.mp3" length="4416243" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9208.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9208</link>
<pubDate>Tue, 05 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Analyzing an Encrypted Phishing PDF<br/>
 <a href="https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404">https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404</a><br/>
Okta Verify Desktop MFA For Windows Password Less Login CVE-2024-9191<br/>
 <a href="https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/">https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/</a><br/>
QNAP QuRouter Vulnerability and Patch<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-24-45">https://www.qnap.com/en/security-advisory/qsa-24-45</a><br/>
From Naptime to Big Sleep<br/>
 <a href="https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html">https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html</a><br/>
Authenticated SQL injection vulnerability - ManageEngine ADManager Plus CVE-2024-48878<br/>
 <a href="https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html">https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html</a><br/>
]]></description>
<itunes:duration>4:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9208" type="text/plain" language="en" />
<itunes:keywords>zoho, manage engine, admanager, naptime, big sleep, qnap, qurouter, Okta, PDF, qpdf, pdf-parser, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9206</itunes:episode>
<itunes:subtitle>Odd SSH Username; QPDF; Okta bcrypt issue; Synology Patches; Fake Lastpass Reviews;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd SSH Username; QPDF; Okta bcrypt issue; Synology Patches; Fake Lastpass Reviews;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9206.mp3" length="5174786" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9206.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9206</link>
<pubDate>Mon, 04 Nov 2024 02:00:02 GMT</pubDate>
<description><![CDATA[October Activity with Username chenzilong<br/>
 <a href="https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400">https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400</a><br/>
qpdf Extracting PDF Streams<br/>
 <a href="https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406">https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406</a><br/>
Okta bcrypt issue<br/>
 <a href="https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/">https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/</a><br/>
 <a href="https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5">https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5</a><br/>
Synology Vulnerabilities<br/>
 <a href="https://www.synology.com/de-de/security/advisory/Synology_SA_24_19">https://www.synology.com/de-de/security/advisory/Synology_SA_24_19</a><br/>
 <a href="https://www.synology.com/de-de/security/advisory/Synology_SA_24_18">https://www.synology.com/de-de/security/advisory/Synology_SA_24_18</a><br/>
Lastpass Fake Reviews<br/>
 <a href="https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data">https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9206" type="text/plain" language="en" />
<itunes:keywords>lastpass, synology, brcrypt, okta, chenzilong, qpdf, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 31st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9204</itunes:episode>
<itunes:subtitle>RDP Gateway Scans; CyberPanel Exploited; QNAP Patches; Facebook Malvertising
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RDP Gateway Scans; CyberPanel Exploited; QNAP Patches; Facebook Malvertising
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9204.mp3" length="5246246" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9204.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9204</link>
<pubDate>Thu, 31 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Scans for RDP Gateways<br/>
 <a href="https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398">https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398</a><br/>
CyberPanel Exploited<br/>
 <a href="https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/">https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/</a><br/>
Windows Themes Files Spoofing CVE-2024-38030<br/>
 <a href="https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html">https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html</a><br/>
QNAP Patches CVE-2024-50388, CVE-2024-50387<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-24-41">https://www.qnap.com/en/security-advisory/qsa-24-41</a><br/>
Facebook Malvertising<br/>
 <a href="https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/">https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9204" type="text/plain" language="en" />
<itunes:keywords>facebook, malvertising, bussiness pages, meta, qnap, patches, windows themes, cyberpanel, NTLM, RDP, gateway, scans, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 30th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9202</itunes:episode>
<itunes:subtitle>CyberPanel RCE; Spring WebFlux Vuln; MSFT Implements DANE; Attackers Enable RDP
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CyberPanel RCE; Spring WebFlux Vuln; MSFT Implements DANE; Attackers Enable RDP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9202.mp3" length="5501549" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9202.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9202</link>
<pubDate>Wed, 30 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Critical RCE Vulnerabilty in Cyberpanel<br/>
 <a href="https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce">https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce</a><br/>
Spring WebFlux Vulnerability<br/>
 <a href="https://access.redhat.com/security/cve/cve-2024-38821">https://access.redhat.com/security/cve/cve-2024-38821</a><br/>
 <a href="https://spring.io/security/cve-2024-38821">https://spring.io/security/cve-2024-38821</a><br/>
Inbound SMTP DANE with DNSSEC for Exchange Online<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292</a><br/>
HeptaX: Unauthorized RDP Connections for Cyberespionage Operations<br/>
 <a href="https://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/">https://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/</a><br/>
 <br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9202" type="text/plain" language="en" />
<itunes:keywords>heptax, dane, dnssec, rdp, spring, webflux, rce, cyberpanel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9200</itunes:episode>
<itunes:subtitle>Apple Updates; HTML File Phishing via Telegram; ChatGTP-4o Encoding Evasion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; HTML File Phishing via Telegram; ChatGTP-4o Encoding Evasion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9200.mp3" length="4874364" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9200.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9200</link>
<pubDate>Tue, 29 Oct 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Apple Update Everything<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390">https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390</a><br/>
Selfcontained HTML Phishing Attachment Using Telegram to Exfiltrate Credentials<br/>
 <a href="https://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/">https://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/</a><br/>
ChatGPT-4o Guardrail Jailbreak: Hex Encoding for Writing CVE Exploits<br/>
 <a href="https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits">https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9200" type="text/plain" language="en" />
<itunes:keywords>chatgpt, guardrails, apple, html phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 28th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9198</itunes:episode>
<itunes:subtitle>Old Ivanti Vulns Exploited; Arcadyan Wifi RCE; Okta iOS Vuln; TeamTNT Docker Hunt
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Old Ivanti Vulns Exploited; Arcadyan Wifi RCE; Okta iOS Vuln; TeamTNT Docker Hunt
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9198.mp3" length="5035437" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9198.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9198</link>
<pubDate>Mon, 28 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Two currently (old) exploited Ivanti vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384">https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384</a><br/>
Arcadyan FMIMG51AX000J (WiFi Alliance) RCE CVE-2024-41992<br/>
 <a href="https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/">https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/</a><br/>
Okta iOS App Vulnerability CVE-2024-10327<br/>
 <a href="https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/">https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/</a><br/>
Threat Alert TeamTNT's docker gatling gun campaign<br/>
 <a href="https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/">https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9198" type="text/plain" language="en" />
<itunes:keywords>teamtnt, docker, miner, okta, ios, arcadyan, wifi, alliance, ivanti, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 25th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9196</itunes:episode>
<itunes:subtitle>Dev Features in Prod; Cisco VPN DOS and Authenticed RCE; Hard Coded Cloud Credentials
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dev Features in Prod; Cisco VPN DOS and Authenticed RCE; Hard Coded Cloud Credentials
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9196.mp3" length="4697537" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9196.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9196</link>
<pubDate>Fri, 25 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Development Features Enabled in Production<br/>
 <a href="https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380">https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380</a><br/>
Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials<br/>
 <a href="https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/">https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/</a><br/>
Cisco Secure Firewall Management Center Software Command Injection Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7</a><br/>
Exposing the Danger Within: Hardcoded Cloud Credentials in Popular Mobile Apps<br/>
 <a href="https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps">https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9196" type="text/plain" language="en" />
<itunes:keywords>cloud, mobile app, cisco, ssh, dos, vpn, development, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 24th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9194</itunes:episode>
<itunes:subtitle>Shell Scripts; Fortimanager Mess; Sharepoint Exploit; OpenSSL Patch; Reduced Cert Lifetime
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shell Scripts; Fortimanager Mess; Sharepoint Exploit; OpenSSL Patch; Reduced Cert Lifetime
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9194.mp3" length="5898690" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9194.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9194</link>
<pubDate>Thu, 24 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Everybody Loves Bash Scripts Including Attackers<br/>
 <a href="https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376">https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376</a><br/>
Fortimanager Exploited Vulnerability<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-24-423">https://www.fortiguard.com/psirt/FG-IR-24-423</a><br/>
Sharepoint Exploit<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-catalog">https://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-catalog</a><br/>
 <a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC</a><br/>
OpenSSL Vulnerability<br/>
 <a href="https://openssl-library.org/news/secadv/20241016.txt">https://openssl-library.org/news/secadv/20241016.txt</a><br/>
Reduced Certificate Lifetime<br/>
 <a href="https://github.com/cabforum/servercert/pull/553">https://github.com/cabforum/servercert/pull/553</a><br/>
 <br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9194" type="text/plain" language="en" />
<itunes:keywords>certificate, openssl, cisa, sharepoint, fortinet, fortimanager, bash, scripts, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9192</itunes:episode>
<itunes:subtitle>HTTP vs. HTTPS; VMware, Unifi, Roundgroup, Atlassian, OneDev Patches, Vulnerability and Exploits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HTTP vs. HTTPS; VMware, Unifi, Roundgroup, Atlassian, OneDev Patches, Vulnerability and Exploits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9192.mp3" length="4801445" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9192.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9192</link>
<pubDate>Wed, 23 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?<br/>
 <a href="https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372">https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372</a><br/>
VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968</a><br/>
Unifi Security Advisory Bulletin 043<br/>
 <a href="https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7">https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7</a><br/>
Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability.<br/>
 <a href="https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability">https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability</a><br/>
Atlassian Security Bulletin - October 15 2024<br/>
 <a href="https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html">https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html</a><br/>
OneDev Arbitrary file reading for unauthenticated user<br/>
 <a href="https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489">https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9192" type="text/plain" language="en" />
<itunes:keywords>onedev, atlassian, roundcube, unifi, vmware, vcenter, http, https, tls, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9190</itunes:episode>
<itunes:subtitle>Emergency Preparedness; HM Surf Exploited; Fortinet and ScienLogic Vague Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emergency Preparedness; HM Surf Exploited; Fortinet and ScienLogic Vague Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9190.mp3" length="5712081" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9190.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9190</link>
<pubDate>Tue, 22 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[A Network Nerd's Take on Emergency Preparedness<br/>
 <a href="https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356">https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356</a><br/>
HM Surf Vulnerability Access to Camera Exploited CVE-2024-44133<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/">https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/</a><br/>
Fortinet releases patches for undisclosed critical FortiManager vulnerability<br/>
 <a href="https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/">https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/</a><br/>
ScienceLogic Vulnerability<br/>
 <a href="https://rackspace.service-now.com/system_status?id=detailed_status&service=4dafca5a87f41610568b206f8bbb35a6">https://rackspace.service-now.com/system_status?id=detailed_status&service=4dafca5a87f41610568b206f8bbb35a6</a><br/>
 <a href="https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm">https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9190" type="text/plain" language="en" />
<itunes:keywords>sciencelogic, rackspace, fortinet, fortimanager, hm surf, apple, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 21st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9188</itunes:episode>
<itunes:subtitle>Lost MSFT 365 Logs; Broken Cloud Storage; ESET Branded Malware; Synology, Spring and Grafana Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Lost MSFT 365 Logs; Broken Cloud Storage; ESET Branded Malware; Synology, Spring and Grafana Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9188.mp3" length="5102745" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9188.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9188</link>
<pubDate>Mon, 21 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft 365: Partially incomplete log data due to monitoring agent issue<br/>
 <a href="https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/">https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/</a><br/>
End-to-End Encrytped Cloud Storage in the Wild: A Broken Ecosystem<br/>
 <a href="https://brokencloudstorage.info/paper.pdf">https://brokencloudstorage.info/paper.pdf</a><br/>
ESET Branded Malware<br/>
 <a href="https://x.com/ESETresearch/status/1847192384448172387">https://x.com/ESETresearch/status/1847192384448172387</a><br/>
Synology Update<br/>
 <a href="https://www.synology.com/en-us/security/advisory/Synology_SA_24_17">https://www.synology.com/en-us/security/advisory/Synology_SA_24_17</a><br/>
Spring Framework Update CVe-2024-38819 CVE-2024-38820<br/>
 <a href="https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published">https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published</a><br/>
Grafana Security Release CVE-2024-9264<br/>
 <a href="https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/">https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9188" type="text/plain" language="en" />
<itunes:keywords>grafana, spring, synology, eset, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9186</itunes:episode>
<itunes:subtitle>AWS Scans; Gatekeeper Bypass; Oracle CPU; Cisco ATA 190 Patch; SAP Code Injection; Dept of Commerce Advertises Drugs;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AWS Scans; Gatekeeper Bypass; Oracle CPU; Cisco ATA 190 Patch; SAP Code Injection; Dept of Commerce Advertises Drugs;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9186.mp3" length="5241544" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9186.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9186</link>
<pubDate>Fri, 18 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Scanning Activity from Subnet 15.184.0.0/16.<br/>
 <a href="https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362">https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362</a><br/>
Gatekeeper Bypass<br/>
 /unit42.paloaltonetworks.com/gatekeeper-bypass-macos/<br/>
Oracle Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpuoct2024.html">https://www.oracle.com/security-alerts/cpuoct2024.html</a><br/>
Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy</a><br/>
SAP Vulnerability<br/>
 <a href="https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/">https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/</a><br/>
Dept. of Commerce Sites Advertising Medication<br/>
 <a href="https://x.com/tliston/status/1833542884047654984">https://x.com/tliston/status/1833542884047654984</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9186" type="text/plain" language="en" />
<itunes:keywords>doc, commerce, cisco, ata, oracle, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9184</itunes:episode>
<itunes:subtitle>Not so Common Passwords; Security Bad Practices; Kubernetes Image Builder Vuln; Solarwinds Helpdesk Exploited; noexec bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Not so Common Passwords; Security Bad Practices; Kubernetes Image Builder Vuln; Solarwinds Helpdesk Exploited; noexec bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9184.mp3" length="5040816" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9184.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9184</link>
<pubDate>Thu, 17 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[The Top 10 Not So Common SSH Usernames and Passwords<br/>
 <a href="https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360">https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360</a><br/>
CISA Product Security Bad Practices<br/>
 <a href="https://www.cisa.gov/resources-tools/resources/product-security-bad-practices">https://www.cisa.gov/resources-tools/resources/product-security-bad-practices</a><br/>
Kubernetes Image Builder Vulnerability CVE-2024-9486 CVE-2024-9594<br/>
 <a href="https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119">https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119</a><br/>
Solarwinds Hardcoded Password Exploited CVE-2024-28987<br/>
 <a href="https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/">https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/</a><br/>
Bypassing noexec and executing arbitrary binaries<br/>
 <a href="https://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries">https://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries</a><br/>
Workshop Website:<br/>
 <a href="https://www.sansapi.com/">https://www.sansapi.com/</a><br/>
 <a href="https://www.sansapi.com/docs">https://www.sansapi.com/docs</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9184" type="text/plain" language="en" />
<itunes:keywords>api, workdshop, noexec, solarwinds, kubernetes, cisa, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9182</itunes:episode>
<itunes:subtitle>Demo Script Exploits;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Demo Script Exploits;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9182.mp3" length="5970828" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9182.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9182</link>
<pubDate>Wed, 16 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Angular-base64-upload Demo Script Exploited<br/>
 <a href="https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354">https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354</a><br/>
Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage <br/>
 <a href="http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf">http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf</a><br/>
EDRSilencer<br/>
 <a href="https://github.com/netero1010/EDRSilencer">https://github.com/netero1010/EDRSilencer</a><br/>
Synchronizing Passkeys<br/>
 <a href="https://fidoalliance.org/specifications-credential-exchange-specifications/">https://fidoalliance.org/specifications-credential-exchange-specifications/</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9182" type="text/plain" language="en" />
<itunes:keywords>passkeys, edrsilencer, quantum annealing, quantum computing, crypto, quantum, angular, base64, upload, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 15th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9180</itunes:episode>
<itunes:subtitle>Blog Phishing; Fortigate Vuln Deep Dive; CLI Entrypoint Takeover
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Blog Phishing; Fortigate Vuln Deep Dive; CLI Entrypoint Takeover
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9180.mp3" length="5117768" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9180.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9180</link>
<pubDate>Tue, 15 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Phishing Page Delivered Through a Blob URL<br/>
 <a href="https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350">https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350</a><br/>
Fortinet Fortigate CVE 2024-23113 deep dive<br/>
 <a href="https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/">https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/</a><br/>
This New Supply Chain Attack Technique Can Trojanize All Your CLI Commands<br/>
 <a href="https://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/">https://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9180" type="text/plain" language="en" />
<itunes:keywords>python, npm, entrypoint, cli, developers, phishing, blog, fortinet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 14th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9178</itunes:episode>
<itunes:subtitle>Windows PPTP/L2TP Deprecation; BIG-IP Cookie Issues; Travel Platforms Targeted
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows PPTP/L2TP Deprecation; BIG-IP Cookie Issues; Travel Platforms Targeted
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9178.mp3" length="5289560" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9178.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9178</link>
<pubDate>Mon, 14 Oct 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Windows PPTP and L2TP Deprecation<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956</a><br/>
BIG-IP LTM Systems Unencrypted Cookie Exploitation<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookies">https://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookies</a><br/>
<a href="https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/">https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/</a><br/>
 <a href="https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/">https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9178" type="text/plain" language="en" />
<itunes:keywords>pptp, l2tp, big-ip, cookies, travel, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9176</itunes:episode>
<itunes:subtitle>PaloAlto "Exploit"; Firefox 0-Day; GitLab Vuln;</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PaloAlto "Exploit"; Firefox 0-Day; GitLab Vuln;</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9176.mp3" length="4626108" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9176.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9176</link>
<pubDate>Fri, 11 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Palo Alto Expedition: From N-Day to Full Compromise <br/>
 <a href="https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/">https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/</a><br/>
Firefox 0-Day<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/">https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/</a><br/>
GitLab Vulnerabilities Patched<br/>
 <a href="https://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/">https://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9176" type="text/plain" language="en" />
<itunes:keywords>gitlab, firefox, palo alto, expedition, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9174</itunes:episode>
<itunes:subtitle>Perfctl to Infostealer; Wazuh Malware Distribution; USB Airgab Bridge; Fortigate Vuln Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Perfctl to Infostealer; Wazuh Malware Distribution; USB Airgab Bridge; Fortigate Vuln Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9174.mp3" length="5061372" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9174.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9174</link>
<pubDate>Thu, 10 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[From Perfctl to InfoStealer<br/>
 <a href="https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334">https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334</a><br/>
Wazuh Abused by Miner Campaign<br/>
 <a href="https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/">https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/</a><br/>
USB Sticks Still Bridge Airgaps<br/>
 <a href="https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/">https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/</a><br/>
Fortigate Vulnerability now being exploited<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23113">https://nvd.nist.gov/vuln/detail/CVE-2024-23113</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9174" type="text/plain" language="en" />
<itunes:keywords>fortigate, usb, bridge, arigap, wazuh, miner, infostealer, perfctl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9172</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; .io ccTLD discontinuing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; .io ccTLD discontinuing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9172.mp3" length="5763503" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9172.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9172</link>
<pubDate>Wed, 09 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday - October 2024<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
The Disappearance of an Internet Domain<br/>
 <a href="https://every.to/p/the-disappearance-of-an-internet-domain">https://every.to/p/the-disappearance-of-an-internet-domain</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9172" type="text/plain" language="en" />
<itunes:keywords>.io, domain, adobe, patches, microsoft, october, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9170</itunes:episode>
<itunes:subtitle>Sequoia Update Issues; Cisco Vuln; iTunes Priv Esc PoC; ISP Wiretap Spying
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sequoia Update Issues; Cisco Vuln; iTunes Priv Esc PoC; ISP Wiretap Spying
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9170.mp3" length="5014048" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9170.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9170</link>
<pubDate>Tue, 08 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[macOS Sequoia: System/Network Admins, Hold On!<br/>
 <a href="https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330">https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330</a><br/>
Cisco Vulnerabilities<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms</a><br/>
Apple iTunes PoC<br/>
 <a href="https://github.com/mbog14/CVE-2024-44193">https://github.com/mbog14/CVE-2024-44193</a><br/>
Attackers used ISP's Wiretap System to Spy on Users<br/>
 <a href="https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835">https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/">https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9170" type="text/plain" language="en" />
<itunes:keywords>isp, wiretap, attackers, apple, itunes, cisco, macos, sequoia, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 7th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9168</itunes:episode>
<itunes:subtitle>CUPS Vuln Scans; Exposed LDAP Servers; Visual Studio Dump File Exploits; Apple Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CUPS Vuln Scans; Exposed LDAP Servers; Visual Studio Dump File Exploits; Apple Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9168.mp3" length="4977973" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9168.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9168</link>
<pubDate>Mon, 07 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Survey of CUPS exploit URLs<br/>
 <a href="https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326">https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326</a><br/>
Exposed LDAP Servers<br/>
 <a href="https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit">https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit</a><br/>
Exploiting Visual Studio via Dump Files<br/>
 <a href="https://ynwarcs.github.io/exploiting-vs-dump-files">https://ynwarcs.github.io/exploiting-vs-dump-files</a><br/>
Apple Security Updates<br/>
 <a href="https://support.apple.com/en-us/100100">https://support.apple.com/en-us/100100</a><br/>
Free API Security Workshop<br/>
 <a href="https://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/">https://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9168" type="text/plain" language="en" />
<itunes:keywords>apple, ldap, visual studio, cups, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9166</itunes:episode>
<itunes:subtitle>DShieldKickStarted; Abused Cloud Services; Pixel Phones Baseband Security; Optigo Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DShieldKickStarted; Abused Cloud Services; Pixel Phones Baseband Security; Optigo Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9166.mp3" length="5249608" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9166.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9166</link>
<pubDate>Fri, 04 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Kickstart Your DShield Honeypot<br/>
 <a href="https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320">https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320</a><br/>
CreanaKeeper Use of Cloud Services<br/>
 <a href="https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/">https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/</a><br/>
  <br/>
Pixel Addressing Vulnerabilities in Cellular Modems<br/>
 <a href="https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html">https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html</a><br/>
Optigo Spectra Vulnerabilities<br/>
 <a href="https://claroty.com/team82/disclosure-dashboard/cve-2024-41925">https://claroty.com/team82/disclosure-dashboard/cve-2024-41925</a><br/>
 <a href="https://claroty.com/team82/disclosure-dashboard/cve-2024-45367">https://claroty.com/team82/disclosure-dashboard/cve-2024-45367</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9166" type="text/plain" language="en" />
<itunes:keywords>optigo, spectra, php, pixel, modems, baseband, creanakeeper, dropbox, kickstart, dshield, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 3rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9164</itunes:episode>
<itunes:subtitle>Security Docker Containers; CUPS DDoS Attack; Draytek Vulnerabilities;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Security Docker Containers; CUPS DDoS Attack; Draytek Vulnerabilities;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9164.mp3" length="5833147" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9164.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9164</link>
<pubDate>Thu, 03 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Security Related Docker Containers<br/>
 <a href="https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318">https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318</a><br/>
CUPS DDoS Attack<br/>
 <a href="https://www.akamai.com/blog/security-research/october-cups-ddos-threat">https://www.akamai.com/blog/security-research/october-cups-ddos-threat</a><br/>
Draytek Vulnerabilities<br/>
 <a href="https://www.forescout.com/resources/draybreak-draytek-research/">https://www.forescout.com/resources/draybreak-draytek-research/</a><br/>
SANS Munich (free Community Night Tuesday October 15th)<br/>
 <a href="https://www.sans.org/cyber-security-training-events/munich-october-2024/">https://www.sans.org/cyber-security-training-events/munich-october-2024/</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9164" type="text/plain" language="en" />
<itunes:keywords>munich, bojan, draytek, cups, ddos, containers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 2nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9162</itunes:episode>
<itunes:subtitle>Hurricane Aftermath; Zimbra Vuln and Exploit; MSFT Edge Extension Security; Supermicro BMC flaw
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hurricane Aftermath; Zimbra Vuln and Exploit; MSFT Edge Extension Security; Supermicro BMC flaw
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9162.mp3" length="5109068" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9162.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9162</link>
<pubDate>Wed, 02 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Hurricane Helene Aftermath - Cyber Security Awareness Month<br/>
 <a href="https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314">https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314</a><br/>
Zimbra - Remote Command Execution (CVE-2024-45519)<br/>
 <a href="https://blog.projectdiscovery.io/zimbra-remote-code-execution/">https://blog.projectdiscovery.io/zimbra-remote-code-execution/</a><br/>
Enhancing the security of Microsoft Edge extensions with the new Publish API<br/>
 <a href="https://blogs.windows.com/msedgedev/2024/09/30/enhanced-security-for-extensions-with-new-publish-api/">https://blogs.windows.com/msedgedev/2024/09/30/enhanced-security-for-extensions-with-new-publish-api/</a><br/>
CVE-2024-36435 Deep-Dive: The Year s Most Critical BMC Security Flaw<br/>
 <a href="https://www.binarly.io/blog/cve-2024-36435-deep-dive-the-years-most-critical-bmc-security-flaw">https://www.binarly.io/blog/cve-2024-36435-deep-dive-the-years-most-critical-bmc-security-flaw</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9162" type="text/plain" language="en" />
<itunes:keywords>supermicro, bmc, edge, microsoft, extensions, zimbra, helene, cyber security awareness month, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 1st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9160</itunes:episode>
<itunes:subtitle>Mac-Robber Update; Recall Re-Released; Hybrid Cloud Attacks; Ransomware IDs; What's Up Gold Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mac-Robber Update; Recall Re-Released; Hybrid Cloud Attacks; Ransomware IDs; What's Up Gold Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9160.mp3" length="5571569" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9160.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9160</link>
<pubDate>Tue, 01 Oct 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Tool Update: mac-robber.py, le-hex-to-ip.py<br/>
 <a href="https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310">https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310</a><br/>
Ransomware Attacks Expanding to Hybrid Cloud Environments<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/">https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/</a><br/>
Update on Recall Security and Privacy Architecture<br/>
 <a href="https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/">https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/</a><br/>
Detecting Ransomware in Windows Event Logs<br/>
 <a href="https://blogs.jpcert.or.jp/en/2024/09/windows.html">https://blogs.jpcert.or.jp/en/2024/09/windows.html</a><br/>
Progress WhatsUp Gold Update<br/>
 <a href="https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024?popup=true&overview">https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024?popup=true&overview</a><br/>
Singapore Class<br/>
 <a href="https://jbu.me/singapore">https://jbu.me/singapore</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9160" type="text/plain" language="en" />
<itunes:keywords>singapore, ransomware, event logs, windows, whatsup gold, progress, recall, cloud, hybrid, mac-robber, le-hex-to-ip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 30th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9158</itunes:episode>
<itunes:subtitle>CUPS Vulnerability Update; PHP Updates; Chinese Firewall and DNS; HPE Aruba Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CUPS Vulnerability Update; PHP Updates; Chinese Firewall and DNS; HPE Aruba Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9158.mp3" length="6188144" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9158.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9158</link>
<pubDate>Mon, 30 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[CUPS Vulnerability<br/>
 <a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br/>
PHP Updates<br/>
 <a href="https://www.php.net/ChangeLog-8.php#8.1.30">https://www.php.net/ChangeLog-8.php#8.1.30</a><br/>
DNS And Big Chinese Firewall<br/>
 <a href="https://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewall">https://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewall</a><br/>
 <a href="https://isc.sans.edu/diary/Are+You+Piratebay+thepiratebayorg+Resolving+to+Various+Hosts/19175">https://isc.sans.edu/diary/Are+You+Piratebay+thepiratebayorg+Resolving+to+Various+Hosts/19175</a><br/>
HPE Aruba Networking Vulnerabilities<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US</a><br/>
]]></description>
<itunes:duration>7:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9158" type="text/plain" language="en" />
<itunes:keywords>hpe, aruba, dns, firewall, php, updates, cups, vulnerability, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 27th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9156</itunes:episode>
<itunes:subtitle>Patch for Critical CUPS vulnerability: Don't Panic
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Patch for Critical CUPS vulnerability: Don't Panic
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9156.mp3" length="6085745" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9156.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9156</link>
<pubDate>Fri, 27 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Patch for Critical CUPS vulnerability: Don't Panic<br/>
 <a href="https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302">https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9156" type="text/plain" language="en" />
<itunes:keywords>cups, browsed, filter, evilsocket, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9154</itunes:episode>
<itunes:subtitle>Corrupt DNS DDoS; SolarWindows Hard Coded Credentials; Watchguard Advisory; Infostealers and Encrypted Cookie Data
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Corrupt DNS DDoS; SolarWindows Hard Coded Credentials; Watchguard Advisory; Infostealers and Encrypted Cookie Data
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9154.mp3" length="6202612" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9154.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9154</link>
<pubDate>Thu, 26 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[DNS Reflection Update and Corrupted DNS Requests<br/>
 <a href="https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296">https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296</a><br/>
CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability<br/>
 <a href="https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/">https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/</a> cve-2024-28987<br/>
Watchguard Unauthenticated and Unencrypted SSO Protocol<br/>
 <a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/">https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/</a><br/>
 <a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014">https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014</a><br/>
Infostealers Overcome Chrome's App Bound Encryption<br/>
 <a href="https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/">https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/</a><br/>
]]></description>
<itunes:duration>7:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9154" type="text/plain" language="en" />
<itunes:keywords>chrome, cookies, infostealer, watchguard, solarwinds, helpdesk, dns, reflection, dos, ddos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 25th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9152</itunes:episode>
<itunes:subtitle>RAISECOM Exploit; Cellopoint Vuln; Cisco Smart Licensing Details; Ivanty Traffic Manager Exploited; Linux Vulnerablity Controversy;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RAISECOM Exploit; Cellopoint Vuln; Cisco Smart Licensing Details; Ivanty Traffic Manager Exploited; Linux Vulnerablity Controversy;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9152.mp3" length="4881636" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9152.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9152</link>
<pubDate>Wed, 25 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Exploitation of RAISECOM Gateway Devices CVE-2024-7120<br/>
 <a href="https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292">https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292</a><br/>
Cellopoint Vulnerability CVE-2024-9043<br/>
 <a href="https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html">https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html</a><br/>
Cisco Smart Licensing Vulnerability Details<br/>
 <a href="https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html">https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html</a><br/>
Ivanti Virtual Traffic Manager Exploited<br/>
 <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br/>
GNU Linux Systems Possible Critical Vulnerability<br/>
 <a href="https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/">https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9152" type="text/plain" language="en" />
<itunes:keywords>linux, gnu, vulnerability, controversy, ivanti, virtual traffic manager, cisco, smart licensing, cellopoint, raisecom, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 24th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9150</itunes:episode>
<itunes:subtitle>Resurected Phishing Tricks; Kaspersky installs Ultra AV; Microchip ASF tinydhcp Vulnerability;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Resurected Phishing Tricks; Kaspersky installs Ultra AV; Microchip ASF tinydhcp Vulnerability;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9150.mp3" length="4966612" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9150.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9150</link>
<pubDate>Tue, 24 Sep 2024 02:00:05 GMT</pubDate>
<description><![CDATA[Phishing Links With @ Sign<br/>
 <a href="https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288">https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288</a><br/>
Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning<br/>
 <a href="https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/">https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/</a><br/>
Microchip ASF tinydhcp Vulnerability<br/>
 <a href="https://kb.cert.org/vuls/id/138043">https://kb.cert.org/vuls/id/138043</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9150" type="text/plain" language="en" />
<itunes:keywords>microchip, asf, tinydhcp, kaspersky, ultraav, antivirus, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9148</itunes:episode>
<itunes:subtitle>WSUS Deprecation; Windows Hotpatches; WHOIS and Certificates; Versa Vuln; Apache HugeGraph Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WSUS Deprecation; Windows Hotpatches; WHOIS and Certificates; Versa Vuln; Apache HugeGraph Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9148.mp3" length="4695291" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9148.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9148</link>
<pubDate>Mon, 23 Sep 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Windows Server Update Services Deprecation<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436</a><br/>
Windows Server 2025 Hotpatches<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296">https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296</a><br/>
Google Suggests Not Using WHOIS for Certificate Validation<br/>
 <a href="https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html">https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html</a><br/>
Versa Director Vulnerability<br/>
 <a href="https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9">https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9</a><br/>
Apache Hugegraph Vulnerability Exploited<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27348">https://nvd.nist.gov/vuln/detail/CVE-2024-27348</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9148" type="text/plain" language="en" />
<itunes:keywords>apache, hugegraph, versa, director, google, whois, certificate, windows, server, hotpatches, Update, WSUS, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 20th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9146</itunes:episode>
<itunes:subtitle>Fake GitHub Notices; More Iventi CVS Vulns; Deanonymizing Tor; iPhone Unlockers;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake GitHub Notices; More Iventi CVS Vulns; Deanonymizing Tor; iPhone Unlockers;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9146.mp3" length="6680773" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9146.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9146</link>
<pubDate>Fri, 20 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Fake GitHub Site Targeting Developers<br/>
 <a href="https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282">https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282</a><br/>
Ivanti CSA 4.6 Advisory<br/>
 <a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US</a><br/>
German Police Deanonymizes Tor User<br/>
 <a href="https://blog.torproject.org/tor-is-still-safe/">https://blog.torproject.org/tor-is-still-safe/</a><br/>
Ever wonder how crooks get the credentials to unlock stolen phones?<br/>
 <a href="https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/">https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/</a><br/>
]]></description>
<itunes:duration>7:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9146" type="text/plain" language="en" />
<itunes:keywords>iphone, unlocker, police, tor, ivatny, csa, github, fake, phishing, developers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9144</itunes:episode>
<itunes:subtitle>Python Infostealer Targeting Exodus; Service Now KB Leaks; GitLab Patch; Aruba Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Infostealer Targeting Exodus; Service Now KB Leaks; GitLab Patch; Aruba Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9144.mp3" length="3853024" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9144.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9144</link>
<pubDate>Thu, 19 Sep 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Python Infostealer Patching Windows Exodus App<br/>
 <a href="https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276">https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276</a><br/>
Service Now Knoledge Bases Data Exposures<br/>
 <a href="https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/">https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/</a><br/>
Gitlab Patch<br/>
 <a href="https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/">https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/</a><br/>
Aruba Patch<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale=en_US">https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale=en_US</a><br/>
]]></description>
<itunes:duration>4:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9144" type="text/plain" language="en" />
<itunes:keywords>aruba, gitlab, service now, python, exodus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9142</itunes:episode>
<itunes:subtitle>Python Exfiltration; VMWare VCenter Patch; macOS Calendar Exploit; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Exfiltration; VMWare VCenter Patch; macOS Calendar Exploit; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9142.mp3" length="4759005" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9142.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9142</link>
<pubDate>Wed, 18 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[23:59, Time to Exfiltrate!<br/>
 <a href="https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272">https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272</a><br/>
Critical VMWare VCenter Vulnerability<br/>
 <a href="https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/">https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/</a><br/>
Zero-Click Calendar invite - Critical zero-click vulnerability chain in macOS<br/>
 <a href="https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b">https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b</a><br/>
Google Adds Latest Post Quantum Encryption Standard to Chrome<br/>
 <a href="https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html">https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9142" type="text/plain" language="en" />
<itunes:keywords>python, firebase, vmware, vcenter, calendar, macos, google, chrome, quantum, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9140</itunes:episode>
<itunes:subtitle>PE Overlays; Apple Updates; Ivanti EOL Issue; MSFT Patch Tuesday Revision; DLink Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PE Overlays; Apple Updates; Ivanti EOL Issue; MSFT Patch Tuesday Revision; DLink Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9140.mp3" length="4708037" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9140.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9140</link>
<pubDate>Tue, 17 Sep 2024 02:25:18 GMT</pubDate>
<description><![CDATA[Managing PE Files with Overlays<br/>
 <a href="https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/">https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/100100">https://support.apple.com/en-us/100100</a><br/>
Ivanti EOL Cloud Service Appliances<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance">https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance</a><br/>
Microsoft Revises September Update<br/>
 <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461</a><br/>
DLink Vulnerabilities<br/>
 <a href="https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html">https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html</a><br/>
 <a href="https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html">https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html</a><br/>
 <a href="https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html">https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9140" type="text/plain" language="en" />
<itunes:keywords>dlink, microsoft, september, mshtml, ivanti, csa, overlays, python, pe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9138</itunes:episode>
<itunes:subtitle>DBScan Examples; Credential Flusher; Ivanti Vulnerabilities; File Sender; Docker Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DBScan Examples; Credential Flusher; Ivanti Vulnerabilities; File Sender; Docker Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9138.mp3" length="5393040" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9138.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9138</link>
<pubDate>Mon, 16 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Finding Honeypot Clusters Using DBSCAN<br/>
 <a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194</a><br/>
Auto IT Credential Flusher<br/>
 <a href="https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html">https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html</a><br/>
Ivanti Patches<br/>
 <a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US</a><br/>
 <a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/">https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/</a><br/>
File Sender Vulnerability<br/>
 <a href="https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/">https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/</a><br/>
Docker Patches<br/>
 <a href="https://docs.docker.com/desktop/release-notes/#4342">https://docs.docker.com/desktop/release-notes/#4342</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9138" type="text/plain" language="en" />
<itunes:keywords>docker, file sender, ivanti, auto-it, honeypot, dbscan, credential flusher, kiosk mode, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9136</itunes:episode>
<itunes:subtitle>Whois Trust Issues; MSFT Security APIs; MSFT PQC Implementation; GitLbab Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Whois Trust Issues; MSFT Security APIs; MSFT PQC Implementation; GitLbab Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9136.mp3" length="4685161" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9136.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9136</link>
<pubDate>Fri, 13 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Compromise of old hostname .mobi whois server<br/>
 <a href="https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/">https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/</a><br/>
Microsoft Reconsidering Security Tool API<br/>
 <a href="https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/">https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/</a><br/>
Microsoft implents PQC in SymCrypt<br/>
 <a href="https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780">https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780</a><br/>
GitLab Patch<br/>
 <a href="https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job">https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9136" type="text/plain" language="en" />
<itunes:keywords>gitlab, microsoft, pqc, symcrypt, security tool, mobi, whois, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9134</itunes:episode>
<itunes:subtitle>Microsoft, Adobe and Ivanti Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft, Adobe and Ivanti Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9134.mp3" length="5350845" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9134.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9134</link>
<pubDate>Wed, 11 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254">https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Ivanti Patches<br/>
 <a href="https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9134" type="text/plain" language="en" />
<itunes:keywords>ivanti, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9132</itunes:episode>
<itunes:subtitle>LoadMaster Vuln; HAProxy Patch; Sonicwall SSLVPN Ransomware; Kibana Update; VSCode Abuse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LoadMaster Vuln; HAProxy Patch; Sonicwall SSLVPN Ransomware; Kibana Update; VSCode Abuse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9132.mp3" length="4072500" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9132.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9132</link>
<pubDate>Tue, 10 Sep 2024 03:20:05 GMT</pubDate>
<description><![CDATA[Critical Loadmaster Security Vulnerability<br/>
 <a href="https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591">https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591</a><br/>
HA Proxy Patch<br/>
 <a href="https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html">https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html</a><br/>
Akira Ransomware Campaign Targeting Sonicwall SSLVPN Accounts<br/>
 <a href="https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/">https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/</a><br/>
Kibana Deserializatio Vulnerability<br/>
 <a href="https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119">https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119</a><br/>
Stately Taurus Abuses VSCode<br/>
 <a href="https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/">https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/</a><br/>
]]></description>
<itunes:duration>4:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9132" type="text/plain" language="en" />
<itunes:keywords>china, taurus, vscode, kibana, elastic, sslvpn, sonicwall, ransomware, haproxy, loadmaster, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9130</itunes:episode>
<itunes:subtitle>Hashcat Power Use; Fake Job Ads; Android OCR Password Stealer; Spouse Sextortion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hashcat Power Use; Fake Job Ads; Android OCR Password Stealer; Spouse Sextortion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9130.mp3" length="5565193" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9130.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9130</link>
<pubDate>Mon, 09 Sep 2024 02:50:06 GMT</pubDate>
<description><![CDATA[Password Cracking Energy: More Details<br/>
 <a href="https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242">https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242</a><br/>
Python Notpad ++<br/>
 <a href="https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240">https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240</a><br/>
Fake LinkedIn Job Ads<br/>
 <a href="https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/">https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/</a><br/>
Android Crypto Passphrase Stealer with OCR<br/>
 <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/</a><br/>
Sextortion Scam Now use Your Chating Spouses Name as a Lure<br/>
 <a href="https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/">https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9130" type="text/plain" language="en" />
<itunes:keywords>sextortion, spouse, android, ocr, crypto wallet, stealer, notepad, power, hashcat, linkedin, job ad, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9128</itunes:episode>
<itunes:subtitle>Enriching Logs; Veeam Update; More OFBiz Issues; Cisco License Manager Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Enriching Logs; Veeam Update; More OFBiz Issues; Cisco License Manager Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9128.mp3" length="5402384" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9128.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9128</link>
<pubDate>Fri, 06 Sep 2024 02:25:06 GMT</pubDate>
<description><![CDATA[Enrichment Data: Keeping it Fresh<br/>
 <a href="https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236">https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236</a><br/>
Veeam Update<br/>
<a href="https://www.veeam.com/kb4649">https://www.veeam.com/kb4649</a><br/>
New OFBiz Vulnerabilities<br/>
 <a href="https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/">https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/</a><br/>
Cisco Smart License Manager Patches<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9128" type="text/plain" language="en" />
<itunes:keywords>cisco, ofbiz, veeam, enrichment, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9126</itunes:episode>
<itunes:subtitle>Moodle Scans; PyPi Revival Hijack; Android Updates; Mediatec Wifi PoC;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Moodle Scans; PyPi Revival Hijack; Android Updates; Mediatec Wifi PoC;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9126.mp3" length="6053857" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9126.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9126</link>
<pubDate>Thu, 05 Sep 2024 03:20:05 GMT</pubDate>
<description><![CDATA[Scans for Moodle Learning Platform Following Recent Update<br/>
 <a href="https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230">https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230</a><br/>
PyPi Rivival HiJack<br/>
 <a href="https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/">https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/</a><br/>
Android Updates<br/>
 <a href="https://source.android.com/docs/security/bulletin/2024-09-01">https://source.android.com/docs/security/bulletin/2024-09-01</a><br/>
Mediatec WAPPD PoC Exploit<br/>
 <a href="https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up">https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9126" type="text/plain" language="en" />
<itunes:keywords>mediatec, android, pypi, moodle, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9124</itunes:episode>
<itunes:subtitle>OOXML Text Docs; Photo Sextortion; Zyxel Vuln; DLink Vuln; VMWare Patch; YubiKey Sidechannel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OOXML Text Docs; Photo Sextortion; Zyxel Vuln; DLink Vuln; VMWare Patch; YubiKey Sidechannel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9124.mp3" length="5944953" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9124.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9124</link>
<pubDate>Wed, 04 Sep 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Protected OOXML Text Documents<br/>
 <a href="https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078">https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078</a><br/>
Sextortion E-Mails with Photos<br/>
 <a href="https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/">https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/</a><br/>
Zyxel OS Command Injection Vulnerability<br/>
 <a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024</a><br/>
D-Link DIR-846W Unpatched RCE Vulnerabilities <br/>
 <a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411</a><br/>
VMWare Priviledge Escalation Vulnerability CVe-2024-38811<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939</a><br/>
YubiKey Sidechannel Attack<br/>
 <a href="https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf">https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf</a><br/>
 <a href="https://www.yubico.com/support/security-advisories/ysa-2024-03/">https://www.yubico.com/support/security-advisories/ysa-2024-03/</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9124" type="text/plain" language="en" />
<itunes:keywords>yubikey, vmware, fusion, d-link, dir-846W, zyxel, Sextortion, ooxml, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 3rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9122</itunes:episode>
<itunes:subtitle>Convert Wireshark Filter; GitHub Comments Spreading Malware; Google Sheets C2; Jenkins PoC;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Convert Wireshark Filter; GitHub Comments Spreading Malware; Google Sheets C2; Jenkins PoC;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9122.mp3" length="5079017" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9122.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9122</link>
<pubDate>Tue, 03 Sep 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Wireshark 4.4: Converting Display Filters to BPF Capture Filters<br/>
 <a href="https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224">https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224</a><br/>
GitHub Comments Used to Spread Malware<br/>
 <a href="https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/">https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/</a><br/>
Voldemort Malware Curses Orgs Using Global Tax Authorities<br/>
<a href="https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities">https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities</a><br/>
Analysis of CVE-2024-43044 From file read to RCE in Jenkins through agents<br/>
 <a href="https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/">https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9122" type="text/plain" language="en" />
<itunes:keywords>jenkins, volemort, google sheets, github, wireshark, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 30th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9120</itunes:episode>
<itunes:subtitle>Python DLL Patching; Global Protect Phishing; BlackByte Ransomware; Exposed AI Services; Detecting Lateral Movement @sans_edu @BriPwn
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python DLL Patching; Global Protect Phishing; BlackByte Ransomware; Exposed AI Services; Detecting Lateral Movement @sans_edu @BriPwn
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9120.mp3" length="12085388" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9120.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9120</link>
<pubDate>Fri, 30 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Live Patching DLLs with Python<br/>
 <a href="https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218">https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218</a><br/>
Global Protect Phishing<br/>
 <a href="https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html">https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html</a><br/>
BlackByte Ransomware Update<br/>
 <a href="https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/">https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/</a><br/>
The Risks Lurking in Publicly Exposed GenAI Development Services<br/>
 <a href="https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services">https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services</a><br/>
Finding Lateral Movement of Adversaries Through the Noise of Systems Administration<br/>
 <a href="https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/">https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/</a><br/>
 YouTube Channel: <a href="https://www.youtube.com/c/CyberAttackDefense">https://www.youtube.com/c/CyberAttackDefense</a><br/>
]]></description>
<itunes:duration>14:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9120" type="text/plain" language="en" />
<itunes:keywords>lateral movement, sans_edu, genai, exposed, llm, blackbyte, vmware, global protect, pan, palo alto, patching, dlls, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9118</itunes:episode>
<itunes:subtitle>Kibana Vega; EDR Killers; Iran Ransomware; Confluence Exploit; Fortra Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kibana Vega; EDR Killers; Iran Ransomware; Confluence Exploit; Fortra Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9118.mp3" length="5191509" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9118.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9118</link>
<pubDate>Thu, 29 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Vega-Lite With Kibana To Parse and Display IP Activity Over Time<br/>
 <a href="https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210">https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210</a><br/>
Attack tool update impairs Windows computers<br/>
 <a href="https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/">https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/</a><br/>
Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a</a><br/>
Confluence Vulnerabilty Exploited for Crypto Miners<br/>
 <a href="https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html">https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html</a><br/>
Fortra FileCatalyst Workflow Hard Coded HSQLDB Credentials<br/>
 <a href="https://www.fortra.com/security/advisories/product-security/fi-2024-011">https://www.fortra.com/security/advisories/product-security/fi-2024-011</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9118" type="text/plain" language="en" />
<itunes:keywords>fortra, filecatalyst, workflow, hsqldb, confulence, miners, iran, vega, atlasian, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 28th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9116</itunes:episode>
<itunes:subtitle>Why Python; OFBiz Update; Versa Directory Exploit; Chrome Exploit; SGX Key Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Why Python; OFBiz Update; Versa Directory Exploit; Chrome Exploit; SGX Key Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9116.mp3" length="5465527" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9116.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9116</link>
<pubDate>Wed, 28 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Why is Python so Popular to Infect Windows Hosts<br/>
 <a href="https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208">https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208</a><br/>
OFBiz Vulnerability Update<br/>
 <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38856">https://nvd.nist.gov/vuln/detail/CVE-2024-38856</a><br/>
Versa Directory Vulnerability Exploited<br/>
 <a href="https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/">https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/</a><br/>
Google Chrome Vulnerability Exploited<br/>
 <a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br/>
SGX Key Leak<br/>
 <a href="https://x.com/_markel___/status/1828112469010596347">https://x.com/_markel___/status/1828112469010596347</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9116" type="text/plain" language="en" />
<itunes:keywords>sgx, intel, google, chrome, versa, ofbiz, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 27th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9114</itunes:episode>
<itunes:subtitle>Obfuscated XWorm/Redline; Windows IPv6 PoC CVE-2024-38063;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated XWorm/Redline; Windows IPv6 PoC CVE-2024-38063;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9114.mp3" length="4979174" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9114.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9114</link>
<pubDate>Tue, 27 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[From Highly Obfuscated Batch File to XWorm and Redline<br/>
 <a href="https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204">https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204</a><br/>
CVE-2024-38063 Windows IPv6 Issue PoC Exploit<br/>
 <a href="https://github.com/ynwarcs/CVE-2024-38063">https://github.com/ynwarcs/CVE-2024-38063</a><br/>
Not a vulnerability<br/>
 <a href="https://github.com/juwenyi/CVE-2024-42992">https://github.com/juwenyi/CVE-2024-42992</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9114" type="text/plain" language="en" />
<itunes:keywords>pandas, vulnerability, windows, ipv6, cve-2024-38063, xworm, redline, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9112</itunes:episode>
<itunes:subtitle>Pandas Encoding Errors; Crowdstrike Slowness; CopyBara; SonicWall Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Pandas Encoding Errors; Crowdstrike Slowness; CopyBara; SonicWall Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9112.mp3" length="4984488" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9112.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9112</link>
<pubDate>Mon, 26 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Pandas Erros: What encoding are my logs in?<br/>
 <a href="https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200">https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200</a><br/>
Crowdstrike Performance Issues<br/>
 <a href="https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/">https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/</a><br/>
CopyBara Malware<br/>
 <a href="https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion">https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion</a><br/>
SonicWall Vulnerability<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9112" type="text/plain" language="en" />
<itunes:keywords>pandas, parsing, encoding, crowdstriek, copybara, sonicwall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9110</itunes:episode>
<itunes:subtitle>OpenAI Scans; MSFT Broke Linux Boot; Chrome 0-Day; @Cisco Vuln; @Solarwinds Helpdesk; Memory Safety @sans_edu 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenAI Scans; MSFT Broke Linux Boot; Chrome 0-Day; @Cisco Vuln; @Solarwinds Helpdesk; Memory Safety @sans_edu 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9110.mp3" length="13196574" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9110.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9110</link>
<pubDate>Fri, 23 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[OpenAI Scans Honeypots<br/>
 <a href="https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196">https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196</a><br/>
Broken Linux Boot Partitions after August Microsoft Update<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc</a><br/>
Google Fixes Chrome 0-day<br/>
 <a href="https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html">https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html</a><br/>
Cisco Zero Day Exploited (now Patched)<br/>
 <a href="https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/">https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/</a><br/>
Solar Winds Helpdesk Backdoor<br/>
 <a href="https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2">https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2</a><br/>
Securing the Future: How Memory-Safe Programming Languages Impact Industry Safety (Christopher Ross)<br/>
 <a href="https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/">https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/</a><br/>
]]></description>
<itunes:duration>15:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9110" type="text/plain" language="en" />
<itunes:keywords>openai, msft, linux, boot, chrome, cisco, solarwinds, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9108</itunes:episode>
<itunes:subtitle>DNSTwist on New Domains; Slack AI Prompt Injection; PWA Phishing; QNAP Ransomware Security; @PromptArmor @sudo_Rem
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNSTwist on New Domains; Slack AI Prompt Injection; PWA Phishing; QNAP Ransomware Security; @PromptArmor @sudo_Rem
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9108.mp3" length="6257752" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9108.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9108</link>
<pubDate>Thu, 22 Aug 2024 01:23:00 GMT</pubDate>
<description><![CDATA[Mapping Threats wiht DNSTwist and the Internet Storm Center <br/>
 <a href="https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188">https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188</a><br/>
Slack AI Prompt Injection<br/>
 <a href="https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private">https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private</a><br/>
Phishing in PWA Applications<br/>
 <a href="https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/">https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/</a><br/>
QNAP Ransomware Security Center<br/>
 <a href="https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection">https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection</a><br/>
]]></description>
<itunes:duration>7:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9108" type="text/plain" language="en" />
<itunes:keywords>qnap, phishing, slack ai, dnstwist, dns, sans_edu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 21st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9106</itunes:episode>
<itunes:subtitle>MSFT IPv6 Vuln Update; MSFT August update and Linux boot issues; php cgi-bin exploited; f5 updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT IPv6 Vuln Update; MSFT August update and Linux boot issues; php cgi-bin exploited; f5 updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9106.mp3" length="4420004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9106.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9106</link>
<pubDate>Wed, 21 Aug 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability<br/>
 <a href="https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186">https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186</a><br/>
Microsoft August Update Prevents Linux from Booting<br/>
 <a href="https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354">https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354</a><br/>
PHP CGI Vulnerability Exploited CVE-2024-4577<br/>
 <a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns">https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns</a><br/>
F5 Updates<br/>
 <a href="https://my.f5.com/manage/s/article/K000140111">https://my.f5.com/manage/s/article/K000140111</a><br/>
 <a href="https://my.f5.com/manage/s/article/K000140108">https://my.f5.com/manage/s/article/K000140108</a><br/>
]]></description>
<itunes:duration>4:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9106" type="text/plain" language="en" />
<itunes:keywords>f5, big-ip, php, cgi, microsoft, august, secure boot, safe boot, ipv6, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 20th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9104</itunes:episode>
<itunes:subtitle>Marshal Python Obfuscation; MacOS Entitlements and MSFT Apps; Digital Wallet Loophole; MSFT CVE-2024-38063 Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Marshal Python Obfuscation; MacOS Entitlements and MSFT Apps; Digital Wallet Loophole; MSFT CVE-2024-38063 Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9104.mp3" length="6360185" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9104.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9104</link>
<pubDate>Tue, 20 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python<br/>
<a href="https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182">https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182</a><br/>
How Vulnerabilities in Microsoft Apps for MacOS allow Stealing Permissions<br/>
 <a href="https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/">https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/</a><br/>
Digital Wallet Security Loophole<br/>
 <a href="https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt">https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt</a><br/>
Microsoft IPv6 Vulnerability CVE-2024-38063<br/>
 <a href="https://x.com/f4rmpoet/status/1825472703223992323">https://x.com/f4rmpoet/status/1825472703223992323</a><br/>
YouTube Video (going live 10am ET) <br/>
 <a href="https://www.youtube.com/watch?v=miBb1llFOYQ">https://www.youtube.com/watch?v=miBb1llFOYQ</a><br/>
]]></description>
<itunes:duration>7:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9104" type="text/plain" language="en" />
<itunes:keywords>youtube, ipv6, microsoft, cve-2024-38063, digital wallet, credit card, marshal, python, donut, macos, apps, microsoft, entitlements, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9102</itunes:episode>
<itunes:subtitle>Summarizing WebHpot Logs; Exposed env files; Chrome Auto Redaction; Google Ad Scammers; Hacking Bike Shifters;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Summarizing WebHpot Logs; Exposed env files; Chrome Auto Redaction; Google Ad Scammers; Hacking Bike Shifters;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9102.mp3" length="5436286" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9102.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9102</link>
<pubDate>Mon, 19 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Summarizing Web Honeypot Logs<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170</a><br/>
Large Scale Cloud Extortion Operation<br/>
 <a href="https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/">https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/</a><br/>
Chrome Redacting Credit Cards and Passwords when you share Android Screens<br/>
 <a href="https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/">https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/</a><br/>
Google Products Targeted by Search Ad Scammers<br/>
 <a href="https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads">https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads</a><br/>
MakeShift: Security Analysis of Shimano Di2 Wireless Gear Shifting in Bicyles<br/>
 <a href="https://www.usenix.org/system/files/woot24-motallebighomi.pdf">https://www.usenix.org/system/files/woot24-motallebighomi.pdf</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9102" type="text/plain" language="en" />
<itunes:keywords>shimano, bike, shifter, google, ads, scams, chrome, cloud, env, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9100</itunes:episode>
<itunes:subtitle>Wireshark 4.4rc1; Github Aritfact Token Leaks; Bitlocker Fix Issues; Solarwinds Hotfix; Ed Skoudis: The Code of Honor @sans_edu 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wireshark 4.4rc1; Github Aritfact Token Leaks; Bitlocker Fix Issues; Solarwinds Hotfix; Ed Skoudis: The Code of Honor @sans_edu 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9100.mp3" length="14914019" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9100.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9100</link>
<pubDate>Fri, 16 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Wireshark 4.4.0 rc 1 Custom Columns<br/>
 <a href="https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174">https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174</a><br/>
Github Repo Artifact Leak Tokens<br/>
 <a href="https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/">https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/</a><br/>
BitLocker Security Feature Bypass Vulnerability<br/>
 <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058">https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058</a><br/>
Solarwindws Hotfix<br/>
 <a href="https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1">https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1</a><br/>
Ed Skoudis, Paul Maurer: The Code of Honor<br/>
 <a href="https://cybercodeofhonor.com/">https://cybercodeofhonor.com/</a><br/>
]]></description>
<itunes:duration>17:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9100" type="text/plain" language="en" />
<itunes:keywords>honor, code, ethids, skoudis, sans.edu, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 15th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9098</itunes:episode>
<itunes:subtitle>MSI Malware; Windows IPv6 Vuln; Critical Ivanti Patch; Adobe Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSI Malware; Windows IPv6 Vuln; Critical Ivanti Patch; Adobe Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9098.mp3" length="5921768" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9098.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9098</link>
<pubDate>Thu, 15 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[MSI Malware<br/>
 <a href="https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168">https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168</a><br/>
Microsoft IPv6 Vulnerablity CVE-2024-38063<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063</a><br/>
 <a href="https://x.com/XiaoWei___/status/1823532146679799993/photo/1">https://x.com/XiaoWei___/status/1823532146679799993/photo/1</a><br/>
Critical Ivanti Virtual Traffic Manager Patch CVE-2024-7593<br/>
 <a href="https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US">https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9098" type="text/plain" language="en" />
<itunes:keywords>ivanti, adobe, traffic manager, microsoft, ipv6, msi, malware, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 14th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9096</itunes:episode>
<itunes:subtitle>Microsoft Patches; Post Quantum Encryption; Zabbix Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Post Quantum Encryption; Zabbix Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9096.mp3" length="5498760" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9096.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9096</link>
<pubDate>Wed, 14 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft August 2024 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164">https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164</a><br/>
NIST Finalizes Post Quantum Encryption Standards<br/>
 <a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards">https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards</a><br/>
Zabbix Network Monitoring Updates<br/>
 <a href="https://support.zabbix.com/browse/ZBX-25016">https://support.zabbix.com/browse/ZBX-25016</a><br/>
 <a href="https://support.zabbix.com/browse/ZBX-25013">https://support.zabbix.com/browse/ZBX-25013</a><br/>
 (and others)<br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9096" type="text/plain" language="en" />
<itunes:keywords>zabbix, nist, microsoft, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9094</itunes:episode>
<itunes:subtitle>Quick Share Vulns; Chrome/Edge Malicious Extensions; AMD Vuln Patched;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Quick Share Vulns; Chrome/Edge Malicious Extensions; AMD Vuln Patched;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9094.mp3" length="4943090" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9094.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9094</link>
<pubDate>Tue, 13 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share<br/>
 <a href="https://www.safebreach.com/blog/rce-attack-chain-on-quick-share">https://www.safebreach.com/blog/rce-attack-chain-on-quick-share</a><br/>
Chrome, Edge users beset by malicious extensions that can t be easily removed<br/>
 <a href="https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/">https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/</a><br/>
AMD Guest Memory Vulnerabilities<br/>
 <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9094" type="text/plain" language="en" />
<itunes:keywords>amd, flaw, smm, chrome, edge, extension, quckshell, quick share, google, android, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9092</itunes:episode>
<itunes:subtitle>CORS/SameOrigin Video; E-Mail Parser Issues; Apache HTTP Confusion Attacks;  Office Spoofing 0-Day;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CORS/SameOrigin Video; E-Mail Parser Issues; Apache HTTP Confusion Attacks;  Office Spoofing 0-Day;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9092.mp3" length="5217017" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9092.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9092</link>
<pubDate>Mon, 12 Aug 2024 02:00:01 GMT</pubDate>
<description><![CDATA[CORS/SameOrigin Video<br/>
 <a href="https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/">https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/</a><br/>
Splitting the email atom: exploiting parsers to bypass access controls<br/>
 <a href="https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies">https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies</a><br/>
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!<br/>
 <a href="https://blog.orange.tw/2024/08/confusion-attacks-en.html">https://blog.orange.tw/2024/08/confusion-attacks-en.html</a><br/>
GL-Inet Patches<br/>
 <a href="https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/">https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/</a><br/>
Microsoft Office Spoofing Vulnerability<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9092" type="text/plain" language="en" />
<itunes:keywords>microsoft, office, gl-inet, confusion, apache, http, email, parsing, cors, sameorgin, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9090</itunes:episode>
<itunes:subtitle>Disabling Phish Warning; SSHAMBLE; macOS Permission Prompts; .internal Domain
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Disabling Phish Warning; SSHAMBLE; macOS Permission Prompts; .internal Domain
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9090.mp3" length="5588406" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9090.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9090</link>
<pubDate>Fri, 09 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Exploring Anti-Phishing Measures in Microsoft 365<br/>
 <a href="https://certitude.consulting/blog/en/o365-anti-phishing-measures/">https://certitude.consulting/blog/en/o365-anti-phishing-measures/</a><br/>
SSHamble Security Testing Tool<br/>
 <a href="https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/">https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/</a><br/>
macOS Sequoia Weekly Permission Prompts<br/>
 <a href="https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/">https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/</a><br/>
.internal domain<br/>
 <a href="https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024">https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9090" type="text/plain" language="en" />
<itunes:keywords>internal, macos, sequoia, sshamble, microsoft, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9088</itunes:episode>
<itunes:subtitle>0.0.0.0 Requests; Apple Gatekeeper Changes; Windows Downgrade
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
0.0.0.0 Requests; Apple Gatekeeper Changes; Windows Downgrade
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9088.mp3" length="5625801" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9088.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9088</link>
<pubDate>Thu, 08 Aug 2024 10:50:05 GMT</pubDate>
<description><![CDATA[0.0.0.0 Day Exploiting Localhost APIs from the Browser<br/>
 <a href="https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser">https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser</a><br/>
Apple Hardens Gatekeeper<br/>
 <a href="https://developer.apple.com/news/?id=saqachfa">https://developer.apple.com/news/?id=saqachfa</a><br/>
Downgrade Attacks Using Windows Updates<br/>
 <a href="https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/">https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9088" type="text/plain" language="en" />
<itunes:keywords>windows, updates, apple, gatekeeper, APIs, 0.0.0.0, loopback, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 7th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9086</itunes:episode>
<itunes:subtitle>GeoServer Update; Crowdstrike RCA; Kibana Vuln; Android Patch Day;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GeoServer Update; Crowdstrike RCA; Kibana Vuln; Android Patch Day;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9086.mp3" length="5323160" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9086.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9086</link>
<pubDate>Wed, 07 Aug 2024 02:00:01 GMT</pubDate>
<description><![CDATA[A Survey of Scans For GeoServer Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148">https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148</a><br/>
Crowdstrike Root Cause Analysis<br/>
 <a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br/>
Kibana Vulnerability<br/>
 <a href="https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424">https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424</a><br/>
Android August 2024 Bulletin<br/>
 <a href="https://source.android.com/docs/security/bulletin/2024-08-01">https://source.android.com/docs/security/bulletin/2024-08-01</a><br/>
Ubiquity Amplication Attack Vulnerability Update<br/>
 <a href="https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/">https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9086" type="text/plain" language="en" />
<itunes:keywords>geoserver, crowdstrike, kibana, android, ubiquity, unifi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9084</itunes:episode>
<itunes:subtitle>Function Confusion Obfuscation; Crowdstrike LPE Vuln; New OFBiz Vuln; Roundcube XSS Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Function Confusion Obfuscation; Crowdstrike LPE Vuln; New OFBiz Vuln; Roundcube XSS Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9084.mp3" length="5644379" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9084.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9084</link>
<pubDate>Tue, 06 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Script Obfuscation Using Multiple Instances of the Same Function<br/>
 <a href="https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144">https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144</a><br/>
Disclosure of key technical details of CrowdStrike's large-scale blue screen<br/>
 <a href="https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ">https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ</a><br/>
New OFBiz Vulnerability<br/>
 <a href="https://issues.apache.org/jira/browse/OFBIZ-13128">https://issues.apache.org/jira/browse/OFBIZ-13128</a><br/>
 <a href="https://www.youtube.com/watch?v=J_IxCBjd4Pw">https://www.youtube.com/watch?v=J_IxCBjd4Pw</a><br/>
Roundcube XSS Vulnerabilities<br/>
 <a href="https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/">https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9084" type="text/plain" language="en" />
<itunes:keywords>roundcube, xss, ofbiz, crowdstrike, objuscation, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9082</itunes:episode>
<itunes:subtitle>Secure Boot CA; OOXML Verifier Hashes; ISP Compromises; DARPA TRACTOR;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Secure Boot CA; OOXML Verifier Hashes; ISP Compromises; DARPA TRACTOR;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9082.mp3" length="5639109" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9082.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9082</link>
<pubDate>Mon, 05 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Current Secure Boot Certifiate Authority Expires in 2026<br/>
 <a href="https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140">https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140</a><br/>
OOXML Spreadsheets Protected by Verifier Hashes<br/>
 <a href="https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072">https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072</a><br/>
StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms<br/>
 <a href="https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/">https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/</a><br/>
DARPA TRACTOR Program for Translating C to Rust<br/>
 <a href="https://www.darpa.mil/news-events/2024-07-31a">https://www.darpa.mil/news-events/2024-07-31a</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9082" type="text/plain" language="en" />
<itunes:keywords>darpa, tractor, rust, c, stormbamboo, isp, evilgrade, updates, ooxml, xls, ole, verifier, hashes, secure boot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 2nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9080</itunes:episode>
<itunes:subtitle>ipv4.games; Fake Google Authenticator; Sitting Ducks Domains
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ipv4.games; Fake Google Authenticator; Sitting Ducks Domains
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9080.mp3" length="5536942" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9080.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9080</link>
<pubDate>Fri, 02 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Tracking Proxy Scans with IPv4.Games<br/>
 <a href="https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136">https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136</a><br/>
Threat Actor Impersonates Google via Fake Ad For Authenticator<br/>
 <a href="https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator">https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator</a><br/>
Who Knew? Domain Hijacking is so easy<br/>
 <a href="https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/">https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9080" type="text/plain" language="en" />
<itunes:keywords>domain, hijacking, google, ads, authenticator, proxy, scans, ip4.games, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 1st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9078</itunes:episode>
<itunes:subtitle>OFBiz Scans; Digicert Revocations; MSFT Azure DDoS; Google Chrome App Bound Encryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OFBiz Scans; Digicert Revocations; MSFT Azure DDoS; Google Chrome App Bound Encryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9078.mp3" length="5817476" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9078.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9078</link>
<pubDate>Thu, 01 Aug 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Increased Activity Against Apache OFBiz CVS-2024-32113<br/>
 <a href="https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132">https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132</a><br/>
Digicert Certificate Revocation Incident<br/>
 <a href="https://www.digicert.com/support/certificate-revocation-incident">https://www.digicert.com/support/certificate-revocation-incident</a><br/>
Microsoft Azure Outage<br/>
 <a href="https://azure.status.microsoft/en-us/status/history/">https://azure.status.microsoft/en-us/status/history/</a><br/>
Improving Security of Chrome Cookies<br/>
 <a href="https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html">https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9078" type="text/plain" language="en" />
<itunes:keywords>cookies, chrome, google, microsoft, azure, outage, ddos, digicert, revocation, apache, ofbiz, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 31st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9076</itunes:episode>
<itunes:subtitle>Apple Updates; VMWare Vuln Exploited; Weak VoWiFi Encryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; VMWare Vuln Exploited; Weak VoWiFi Encryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9076.mp3" length="4889528" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9076.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9076</link>
<pubDate>Wed, 31 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Updates Everything: July 2024 Edition<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128</a><br/>
VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/">https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/</a><br/>
Weak VoWiFi Encryption CVE-2024-22064<br/>
 <a href="https://idw-online.de/en/news837652">https://idw-online.de/en/news837652</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9076" type="text/plain" language="en" />
<itunes:keywords>vowifi, zte, vmware, esxi, apple, ios, macos, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 30th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9074</itunes:episode>
<itunes:subtitle>CrowdStrike Maldoc; HotJar XSS; Proofpoint Echospoofing;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CrowdStrike Maldoc; HotJar XSS; Proofpoint Echospoofing;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9074.mp3" length="5154405" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9074.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9074</link>
<pubDate>Tue, 30 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[CrowdStrike Outage Themed Maldoc<br/>
 <a href="https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116">https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116</a><br/>
HotJar XSS Puts OAuth at Risk<br/>
 <a href="https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss">https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss</a><br/>
Proofpoint Echospoofing<br/>
 <a href="https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6">https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9074" type="text/plain" language="en" />
<itunes:keywords>proofpoint, echospoofing, dkim, hotjar, xss, crowdstriek, maldoc, grammarly, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9072</itunes:episode>
<itunes:subtitle>ExelaStealer and more; BSOD Practice; PK Fail; @CrowdStrike Recovery; #pkfail #bsod
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ExelaStealer and more; BSOD Practice; PK Fail; @CrowdStrike Recovery; #pkfail #bsod
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9072.mp3" length="5392044" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9072.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9072</link>
<pubDate>Mon, 29 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[ExelaStealer Delivered "From Russia With Love"<br/>
 <a href="https://isc.sans.edu/diary/31118">https://isc.sans.edu/diary/31118</a><br/>
Create Your Own BSOD: NotMyFault<br/>
 <a href="https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120">https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120</a><br/>
PKFail Vulnerability<br/>
 <a href="https://pk.fail/">https://pk.fail/</a><br/>
CrowdStrike Recovery<br/>
 <a href="https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/">https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9072" type="text/plain" language="en" />
<itunes:keywords>crowdstrike, pkfail, bsod, notmyfaul, exelastealer, russia, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9070</itunes:episode>
<itunes:subtitle>XWorm Analysis; Private/Deleted GitHub Leak; Google Chrome Scanning Encrypted Files
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XWorm Analysis; Private/Deleted GitHub Leak; Google Chrome Scanning Encrypted Files
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9070.mp3" length="5263480" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9070.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9070</link>
<pubDate>Fri, 26 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[X-Worm Hidden With Process Hollowing<br/>
 <a href="https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112">https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112</a><br/>
Anyone Can Access Deleted and Private Repo Data on GitHub<br/>
 <a href="https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github">https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github</a><br/>
Google Chrome Scanning Encrypted Files<br/>
 <a href="https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/">https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9070" type="text/plain" language="en" />
<itunes:keywords>google, chrome, repo, github, leak, private, x-worm, xworm, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 25th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9068</itunes:episode>
<itunes:subtitle>Mouse Logger; Crowdstrike PIR; Fake Developers;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mouse Logger; Crowdstrike PIR; Fake Developers;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9068.mp3" length="4960766" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9068.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9068</link>
<pubDate>Thu, 25 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA["Mouse Logger" Malicious Python Script<br/>
 <a href="https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106">https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106</a><br/>
Crowdstrike Preliminary Post Incident Review<br/>
 <a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br/>
How a North Korean Fake IT Worker Tried to Infiltrate Us<br/>
 <a href="https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us">https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9068" type="text/plain" language="en" />
<itunes:keywords>north korea, developer, fake, crowdstrike, mouse logger, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 24th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9066</itunes:episode>
<itunes:subtitle>D-Link NAS Exploit; Android Fake Video Exp; Windows Hello For Bussines Phishing; The end of OCSP; Google Cookie Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
D-Link NAS Exploit; Android Fake Video Exp; Windows Hello For Bussines Phishing; The end of OCSP; Google Cookie Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9066.mp3" length="5672334" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9066.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9066</link>
<pubDate>Wed, 24 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[New Exploit Variation Against D-Link NAS Devices<br/>
 <a href="https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102">https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102</a><br/>
APKs Masquerading as Videos on Telegram<br/>
 <a href="https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/">https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/</a><br/>
Goodbye Attackers can Bypass Windows Hello Strong Authentication<br/>
 <a href="https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication">https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication</a><br/>
Let's Encrypt Intends to End OCSP Service<br/>
 <a href="https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html">https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html</a><br/>
Google Third-Party Cookies are hanging around<br/>
 <a href="https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/">https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9066" type="text/plain" language="en" />
<itunes:keywords>google, cookies, dlink, apk, video, telegram, windows, hello, ocsp, crl, let's encrypt, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9064</itunes:episode>
<itunes:subtitle>CrowdStrike Update; SANSFIRE Keynote Recording;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CrowdStrike Update; SANSFIRE Keynote Recording;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9064.mp3" length="4697905" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9064.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9064</link>
<pubDate>Tue, 23 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[CrowdStrike Update<br/>
 <a href="https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098">https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098</a><br/>
 <a href="https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/">https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/</a><br/>
Keynote Recording<br/>
 <a href="https://www.sans.org/webcasts/sansfire-2024-keynote-25-years-of-the-internet-storm-center-time-traveling-through-sensor-data/">https://www.sans.org/webcasts/sansfire-2024-keynote-25-years-of-the-internet-storm-center-time-traveling-through-sensor-data/</a>]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9064" type="text/plain" language="en" />
<itunes:keywords>sansfire, keynote, crowdstrike, linux, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9062</itunes:episode>
<itunes:subtitle>Crowdstrike Configuration File Update Crashes Windows Systems @crowdstrike
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Crowdstrike Configuration File Update Crashes Windows Systems @crowdstrike
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9062.mp3" length="7559382" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9062.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9062</link>
<pubDate>Mon, 22 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Widespread Windows Crashes Due to Crowdstrike Updates<br/>
 <a href="https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094">https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094</a><br/>
 <a href="https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/">https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/</a><br/>
 <a href="https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/">https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959">https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959</a><br/>
]]></description>
<itunes:duration>8:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9062" type="text/plain" language="en" />
<itunes:keywords>crowdstrike, windows, crash, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9060</itunes:episode>
<itunes:subtitle>Oracle CPU; DANE for Exchange Online; VPN Port Shadowing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oracle CPU; DANE for Exchange Online; VPN Port Shadowing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9060.mp3" length="5046352" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9060.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9060</link>
<pubDate>Fri, 19 Jul 2024 02:05:06 GMT</pubDate>
<description><![CDATA[Oracle Quarterly Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpujul2024.html">https://www.oracle.com/security-alerts/cpujul2024.html</a><br/>
Exchange Online Implementing Inbound SMTP DANE with DNSSEC<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257">https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257</a><br/>
VPN Port Shadowing Vulnerability<br/>
 <a href="https://petsymposium.org/popets/2024/popets-2024-0070.pdf">https://petsymposium.org/popets/2024/popets-2024-0070.pdf</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9060" type="text/plain" language="en" />
<itunes:keywords>vpn, shadow, port, shadowing, exchange, smtp, dane, dnssec, oracle, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9058</itunes:episode>
<itunes:subtitle>AndroxGh0st; Cisco SSM Vuln; Cisco Email Gateway Vuln; MSFT Checkpoint Updates; GeoServer Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AndroxGh0st; Cisco SSM Vuln; Cisco Email Gateway Vuln; MSFT Checkpoint Updates; GeoServer Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9058.mp3" length="5412745" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9058.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9058</link>
<pubDate>Thu, 18 Jul 2024 02:55:11 GMT</pubDate>
<description><![CDATA[Who You Gonna Call: Androx Gh0st Busters!<br/>
 <a href="https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086">https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086</a><br/>
Cisco Smart Software Manager Vulnerability CVE-2024-20419<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy</a><br/>
Critical Security Flaw in Cisco Secure Email Gateway: CVE-2024-20401<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH</a><br/>
Microsoft Introducing Checkpoint Updates<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552</a><br/>
GeoServer Patches<br/>
 <a href="https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv">https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9058" type="text/plain" language="en" />
<itunes:keywords>geoserver, msft, checkpoint, updates, cisco, email, ssm, smart software manager, androxghost, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9056</itunes:episode>
<itunes:subtitle>Reply Chain Phishing; TP-Link/Synology IP Camera Exploits; Adobe Commerce Exploit;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reply Chain Phishing; TP-Link/Synology IP Camera Exploits; Adobe Commerce Exploit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9056.mp3" length="5051152" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9056.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9056</link>
<pubDate>Wed, 17 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Reply Chain Phishing With a Twist<br/>
 <a href="https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084">https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084</a><br/>
Claroty TP-Link and Synology IP Camera Exploits<br/>
 <a href="https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera">https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera</a><br/>
 <a href="https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase">https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase</a><br/>
Cosmic Sting Hits Adobe Commerce Stores<br/>
 <a href="https://sansec.io/research/cosmicsting-hitting-major-stores">https://sansec.io/research/cosmicsting-hitting-major-stores</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9056" type="text/plain" language="en" />
<itunes:keywords>cosmic string, adobe, commerce, magento, claroty, tp-link, synology, replay chain, spam, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9054</itunes:episode>
<itunes:subtitle>OOXML Protected Spreadsheets; Leaked PyPi Secret; June MSFT Patch Issues;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OOXML Protected Spreadsheets; Leaked PyPi Secret; June MSFT Patch Issues;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9054.mp3" length="5333841" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9054.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9054</link>
<pubDate>Tue, 16 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Protected OOXML Spreadsheets<br/>
 <a href="https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070">https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070</a><br/>
Leaked PyPi Secret Token Revealed in Binary<br/>
 <a href="https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/">https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/</a><br/>
Microsoft 365 Defender Affected by June Update<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted">https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9054" type="text/plain" language="en" />
<itunes:keywords>microsoft, patch, defender, june, pypi, token, github, ooxml, protected, password, hashcat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 15th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9052</itunes:episode>
<itunes:subtitle>XLS Hash Collisions; Nette Attacks; Squarespace Domain Hijack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XLS Hash Collisions; Nette Attacks; Squarespace Domain Hijack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9052.mp3" length="5767998" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9052.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9052</link>
<pubDate>Mon, 15 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[16-Bit Hash Collisions in XLS Spreadsheets<br/>
 <a href="https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066">https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066</a><br/>
Attacks against the "Nette" PHP framework CVE-2020-15227<br/>
 <a href="https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/">https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/</a><br/>
Squarespace Hijacked Domains<br/>
 <a href="https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf">https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9052" type="text/plain" language="en" />
<itunes:keywords>squarespace, google, domains, nette, php, xls, spreadsheets, collisions, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9050</itunes:episode>
<itunes:subtitle>Honeypot Fingerprinting; Veeam Exploited; Juniper Patches; VMWAre Aria SQLi; SMS Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot Fingerprinting; Veeam Exploited; Juniper Patches; VMWAre Aria SQLi; SMS Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9050.mp3" length="6610690" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9050.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9050</link>
<pubDate>Fri, 12 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots<br/>
 <a href="https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064">https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064</a><br/>
Patch or Peril: A Veeam Vulnerability Incident<br/>
 <a href="https://www.group-ib.com/blog/estate-ransomware/">https://www.group-ib.com/blog/estate-ransomware/</a><br/>
Juniper Patches<br/>
 <a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&f:ctype=[Security%20Advisories]">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&f:ctype=[Security%20Advisories]</a><br/>
VMWare Aria Automation SQL Injection Vuln;<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598</a><br/>
Leaked SMS Messages<br/>
 <a href="https://www.ccc.de/de/updates/2024/2fa-sms">https://www.ccc.de/de/updates/2024/2fa-sms</a><br/>
]]></description>
<itunes:duration>7:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9050" type="text/plain" language="en" />
<itunes:keywords>ccc, sms, vmware, aria, juniper, veeam, ssh, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9048</itunes:episode>
<itunes:subtitle>DBSCAN and Honeypot Data; Another SSH Vuln; URL File Exploit; Sharepoint PoC; Citrix and OpenVPN updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DBSCAN and Honeypot Data; Another SSH Vuln; URL File Exploit; Sharepoint PoC; Citrix and OpenVPN updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9048.mp3" length="4979516" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9048.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9048</link>
<pubDate>Thu, 11 Jul 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Finding Honeypot Data Clusters Using DBSCAN Part 1<br/>
 <a href="https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050">https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050</a><br/>
Second RegreSSHion Like OpenSSH Vulnerability<br/>
 <a href="https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/">https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/</a><br/>
Resurrecting Internet Explorer: Threat Actors Using Zero-Day Tricks in Internet Shortcut File CVE-2024-38112<br/>
 <a href="https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/">https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/</a><br/>
SharePoint Proof of Concept Exploit CVE-2024-38094 CVE-2024-38024 CVE-2024-38023<br/>
 <a href="https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py">https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py</a><br/>
Citrix Netscaler, Agent and SDX Security Bulletin CVE-2024-6235 CVE-2024-6236<br/>
 <a href="https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236">https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236</a><br/>
OpenVPN Updates<br/>
 <a href="https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/">https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9048" type="text/plain" language="en" />
<itunes:keywords>openvpn, citrix, netscaler, sharepoint, internet explorer, mshtml, microsoft, url, regression, openssh, honeypot, dbscan, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9046</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches; RADIUS Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches; RADIUS Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9046.mp3" length="5696585" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9046.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9046</link>
<pubDate>Wed, 10 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday July 2024<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
RADIUS protocol susceptible to forgery attacks<br/>
 <a href="https://kb.cert.org/vuls/id/456537">https://kb.cert.org/vuls/id/456537</a><br/>
 <a href="https://www.inkbridgenetworks.com/blastradius/faq">https://www.inkbridgenetworks.com/blastradius/faq</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9046" type="text/plain" language="en" />
<itunes:keywords>radius, blastradius, adobe, microsoft, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9044</itunes:episode>
<itunes:subtitle>Kunai #kunai_project; DoNex Decryptor; Shelltorch Explained; Exim Vuln; Toshiba/Sharp Printer Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kunai #kunai_project; DoNex Decryptor; Shelltorch Explained; Exim Vuln; Toshiba/Sharp Printer Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9044.mp3" length="4965288" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9044.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9044</link>
<pubDate>Tue, 09 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Kunai: Keep an Eye on your Linux Hosts Activity<br/>
 <a href="https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054">https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054</a><br/>
Decryptor for DoNex Ransomware<br/>
 <a href="https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/">https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/</a><br/>
Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve)<br/>
 <a href="https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server">https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server</a><br/>
Exim Bypass Attachment Inspection<br/>
 <a href="https://bugs.exim.org/show_bug.cgi?id=3099#c4">https://bugs.exim.org/show_bug.cgi?id=3099#c4</a><br/>
Toshiba/Sharp Printer vulnerabilities<br/>
 <a href="https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html">https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html</a><br/>
 <a href="https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html">https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9044" type="text/plain" language="en" />
<itunes:keywords>toshiba, sharp, exim, shelltorch, pytorch, donex, avast, kunai, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9042</itunes:episode>
<itunes:subtitle>OpenSSH Vulnerablity; HE.Net Downtime; Cloudflare DNS Outage;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenSSH Vulnerablity; HE.Net Downtime; Cloudflare DNS Outage;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9042.mp3" length="8232693" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9042.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9042</link>
<pubDate>Mon, 08 Jul 2024 02:00:02 GMT</pubDate>
<description><![CDATA[OpenSSH RegreSSHion Vulnerability<br/>
 <a href="https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt">https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt</a><br/>
 <a href="https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046">https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046</a><br/>
Overlooked Domain Name Resliency Issues: Registrar Communications<br/>
 <a href="https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048">https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048</a><br/>
Cloudflare 1.1.1.1 incident on Juine 27th 2024<br/>
 <a href="https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024">https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024</a><br/>
]]></description>
<itunes:duration>9:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9042" type="text/plain" language="en" />
<itunes:keywords>cloudflare, dos, bgp, dns, registrar, hurricane electric, openssh, regresshion, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 28th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9040</itunes:episode>
<itunes:subtitle>Honeypot Lesons; TeamViewer Compromise; Fortra File Catalyst Vuln/PoC; GitLab Update; Vanna.AI RCE;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot Lesons; TeamViewer Compromise; Fortra File Catalyst Vuln/PoC; GitLab Update; Vanna.AI RCE;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9040.mp3" length="6595631" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9040.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9040</link>
<pubDate>Fri, 28 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[What Setting Live Traps For Cybercriminals Taught Me About Security<br/>
 <a href="https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038">https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038</a><br/>
TeamViewer Compromise<br/>
 <a href="https://www.teamviewer.com/en-us/resources/trust-center/statement/">https://www.teamviewer.com/en-us/resources/trust-center/statement/</a><br/>
Fortra File Catalyst Vulnerability and PoC<br/>
 <a href="https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0">https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0</a><br/>
 <a href="https://www.tenable.com/security/research/tra-2024-25">https://www.tenable.com/security/research/tra-2024-25</a><br/>
GitLab Critical Update<br/>
 <a href="https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/">https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/</a><br/>
When Prompts Go Rogue: Analyzing a Prompt Injection Code Execution in Vanna.AI<br/>
 <a href="https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/">https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/</a><br/>
]]></description>
<itunes:duration>7:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9040" type="text/plain" language="en" />
<itunes:keywords>vanna.ai, prompt injection, sql injection, remote code execution, sqli, rce, gitlab, fortra, teamviewer, honeypot, sans.edu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 27th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9038</itunes:episode>
<itunes:subtitle>New MOVEit Vulnerability; Polyfill Supply Chain Attack; Apple AirPods Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New MOVEit Vulnerability; Polyfill Supply Chain Attack; Apple AirPods Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9038.mp3" length="5660654" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9038.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9038</link>
<pubDate>Thu, 27 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Critical Progress MOVEit Authentication Bypass Vulnerability<br/>
 <a href="https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/">https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/</a><br/>
 <a href="https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806">https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806</a><br/>
Polyfill.io Supply Chain Attack<br/>
 <a href="https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack">https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack</a><br/>
Apple AirPods Firmware Update<br/>
 <a href="https://support.apple.com/en-us/HT214111">https://support.apple.com/en-us/HT214111</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9038" type="text/plain" language="en" />
<itunes:keywords>airpods, polyfill, moveit, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9036</itunes:episode>
<itunes:subtitle>TCP Latency Sidechannel; MMC Initial Access; Wyze Camera Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TCP Latency Sidechannel; MMC Initial Access; Wyze Camera Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9036.mp3" length="5675182" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9036.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9036</link>
<pubDate>Wed, 26 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[TCP Latency Sidechannel<br/>
 <a href="https://www.snailload.com/snailload.pdf">https://www.snailload.com/snailload.pdf</a><br/>
Microsoft Management Console for Intial Access and Evasion<br/>
 <a href="https://www.elastic.co/security-labs/grimresource">https://www.elastic.co/security-labs/grimresource</a><br/>
Wyze Camera Vulnerabilities<br/>
 <a href="https://forums.wyze.com/t/security-advisory/289256">https://forums.wyze.com/t/security-advisory/289256</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9036" type="text/plain" language="en" />
<itunes:keywords>wyze, camera, mmc, snailload, tcp, latency, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 25th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9034</itunes:episode>
<itunes:subtitle>Configuration Scans Expand; SQL Server Emergency Fix; Juniper Security Analytics; XNU Buffer Overflow PoC @0xjprx
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Configuration Scans Expand; SQL Server Emergency Fix; Juniper Security Analytics; XNU Buffer Overflow PoC @0xjprx
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9034.mp3" length="4860488" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9034.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9034</link>
<pubDate>Tue, 25 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Configuration Scans Expand<br/>
 <a href="https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032">https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032</a><br/>
SQL Server Emergency Fix<br/>
 <a href="https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1">https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1</a><br/>
Juniper Security Analytics Update<br/>
 <a href="https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US">https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US</a><br/>
MacOS/iOS XNU Buffer Overflow Exploit CVE-2024-27815<br/>
 <a href="https://jprx.io/cve-2024-27815/">https://jprx.io/cve-2024-27815/</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9034" type="text/plain" language="en" />
<itunes:keywords>macos, ios, buffer overflow, juniper, sql server, microsoft, java, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 24th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9032</itunes:episode>
<itunes:subtitle>Process Monitor Update; Kaspersky Sanctions; Phoenix UEFI Vuln; Ghostscript Vuln; js2py unpatched vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Process Monitor Update; Kaspersky Sanctions; Phoenix UEFI Vuln; Ghostscript Vuln; js2py unpatched vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9032.mp3" length="6268086" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9032.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9032</link>
<pubDate>Mon, 24 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Sysinternals Process Monitor Version 4 Released<br/>
 <a href="https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026">https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026</a><br/>
Kaspersky Sanctions<br/>
 <a href="https://home.treasury.gov/news/press-releases/jy2420">https://home.treasury.gov/news/press-releases/jy2420</a><br/>
Phoenix UEFI Buffer Overflow Affects Wide Range of Systems<br/>
 <a href="https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/">https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/</a><br/>
Ghostscript Update<br/>
 <a href="https://ghostscript.readthedocs.io/en/gs10.03.1/News.html">https://ghostscript.readthedocs.io/en/gs10.03.1/News.html</a><br/>
js2py vulnerability<br/>
 <a href="https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape">https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9032" type="text/plain" language="en" />
<itunes:keywords>js2py, ghostscript, pdf, postscript, ps, phoenix, uefi, kaspersky, sysinternals, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 21st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9030</itunes:episode>
<itunes:subtitle>Ubuntu Login Security; BOM Mime Files; Confluence Patches; Validating E-Mail Addresses; VMware Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ubuntu Login Security; BOM Mime Files; Confluence Patches; Validating E-Mail Addresses; VMware Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9030.mp3" length="4634145" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9030.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9030</link>
<pubDate>Fri, 21 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[No Excuses: Free Tools to Help Secure Authentication in Ubuntu<br/>
 <a href="https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024">https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024</a><br/>
Handling BOM MIME Files<br/>
 <a href="https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022">https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022</a><br/>
Atlasiun Confluence Data Center and Server Vuln<br/>
 <a href="https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html">https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html</a><br/>
Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes<br/>
 <a href="https://modzero.com/en/blog/beyond_the_at_symbol/">https://modzero.com/en/blog/beyond_the_at_symbol/</a><br/>
VMWare Patches<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9030" type="text/plain" language="en" />
<itunes:keywords>ubuntu, authentcation, mfa, vmware, email, validating, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9028</itunes:episode>
<itunes:subtitle>NetSupport Campaign; D-Link Backdoor; iTerm2 Vuln; NextCloud Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NetSupport Campaign; D-Link Backdoor; iTerm2 Vuln; NextCloud Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9028.mp3" length="4323331" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9028.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9028</link>
<pubDate>Tue, 18 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[New NetSupport Campaign Deleivered Through MSIX Packages<br/>
 <a href="https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018">https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018</a><br/>
D-Link Router Backdoor<br/>
 <a href="https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html">https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html</a><br/>
 <a href="https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398">https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398</a><br/>
iTerm2 Vulnerablity<br/>
 <a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html">https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html</a><br/>
NextCloud Vulnerability<br/>
 <a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c</a><br/>
]]></description>
<itunes:duration>4:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9028" type="text/plain" language="en" />
<itunes:keywords>nextcloud, iterm2, d-link, dlink, netsupport, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9026</itunes:episode>
<itunes:subtitle>Didier's Tools JSON use; Python Serialization Lab @markbaggett; Detecting Headless Chrome @xopek59; ExtensionTotal; ASUS Router Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Didier's Tools JSON use; Python Serialization Lab @markbaggett; Detecting Headless Chrome @xopek59; ExtensionTotal; ASUS Router Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9026.mp3" length="4875296" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9026.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9026</link>
<pubDate>Mon, 17 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Overview of My Tools That Handle JSON Data<br/>
 <a href="https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012">https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012</a><br/>
Python Serialization and "Sleepy Pickle"<br/>
 <a href="https://x.com/MarkBaggett/status/1801732554740969561">https://x.com/MarkBaggett/status/1801732554740969561</a><br/>
Detecting Headless Chrome<br/>
 <a href="https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024">https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024</a><br/>
Detecting Malicious VS Code Extensions<br/>
 <a href="https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1">https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1</a><br/>
ASUS Router Critical Vulnerability<br/>
 <a href="https://www.asus.com/content/asus-product-security-advisory/">https://www.asus.com/content/asus-product-security-advisory/</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9026" type="text/plain" language="en" />
<itunes:keywords>ASUS, vscode, headless, chrome, python, sleepy pickle, json, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 14th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9024</itunes:episode>
<itunes:subtitle>JQ Intro; Outlook Vuln Details; Outlook MFA Required; Pickle File Attacks;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JQ Intro; Outlook Vuln Details; Outlook MFA Required; Pickle File Attacks;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9024.mp3" length="4985620" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9024.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9024</link>
<pubDate>Fri, 14 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[The Art of JQ and Command-Line Fu<br/>
 <a href="https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006">https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006</a><br/>
Microsoft Outlook Vulnerablity Details<br/>
 <a href="https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability">https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability</a><br/>
Keeping our Outlook Personal Email Users Safe<br/>
 <a href="https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184">https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184</a><br/>
Exploiting ML models with pickle file attacks<br/>
 <a href="https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/">https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9024" type="text/plain" language="en" />
<itunes:keywords>ml, pickle, outlook, email, mfa, jq, json, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9022</itunes:episode>
<itunes:subtitle>MSMQ Packets; Adobe Updates; Black Basta used 0-day; Pixel Phone 0-day Patched
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSMQ Packets; Adobe Updates; Black Basta used 0-day; Pixel Phone 0-day Patched
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9022.mp3" length="4795282" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9022.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9022</link>
<pubDate>Thu, 13 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[MSMQ Packets<br/>
 <a href="https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004">https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb24-40.html">https://helpx.adobe.com/security/products/magento/apsb24-40.html</a><br/>
Black Basta Exploited CVE-2024-26169 Prior to Patch<br/>
 <a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day">https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day</a><br/>
Pixel Phone 0-Day Patched<br/>
 <a href="https://source.android.com/docs/security/bulletin/pixel/2024-06-01">https://source.android.com/docs/security/bulletin/pixel/2024-06-01</a><br/>
 <br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9022" type="text/plain" language="en" />
<itunes:keywords>pixel, phone, black basta, adobe, msmq, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9020</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; JetBrains InteliJ GitHub Vuln; More Veeam Vulns; Precor Threadmill Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; JetBrains InteliJ GitHub Vuln; More Veeam Vulns; Precor Threadmill Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9020.mp3" length="5060221" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9020.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9020</link>
<pubDate>Wed, 12 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000</a><br/>
JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability<br/>
 <a href="https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/">https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/</a><br/>
Veeam Recovery Orchestrator (VRO) vulnerability CVE-2024-29855<br/>
 <a href="https://www.veeam.com/kb4585">https://www.veeam.com/kb4585</a><br/>
Precor Threadmill Vulnerablity<br/>
 <a href="https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/">https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9020" type="text/plain" language="en" />
<itunes:keywords>precore, threadmill, veeam, jetbrains, inellij, ide, github, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9018</itunes:episode>
<itunes:subtitle>#Veeam Exploit CVE-2024-29849 @sinsinology; #SORBS Shutdown @ssharwood; Malicious #Comfui Modules;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#Veeam Exploit CVE-2024-29849 @sinsinology; #SORBS Shutdown @ssharwood; Malicious #Comfui Modules;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9018.mp3" length="5395052" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9018.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9018</link>
<pubDate>Tue, 11 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Veeam Exploit CVE-2024-29849<br/>
 <a href="https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/">https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/</a><br/>
SORBS Shutdown<br/>
 <a href="https://www.theregister.com/2024/06/07/sorbs_closed/">https://www.theregister.com/2024/06/07/sorbs_closed/</a><br/>
Rogue Cell Tower Shut Down in London<br/>
 <a href="https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/">https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/</a><br/>
Malicious Comfyui Modules<br/>
 <a href="https://www.youtube.com/watch?v=ntwGHjBCbeQ">https://www.youtube.com/watch?v=ntwGHjBCbeQ</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9018" type="text/plain" language="en" />
<itunes:keywords>comfyui, cell tower, sorbs, veeam, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9016</itunes:episode>
<itunes:subtitle>PHP Vulnerablity Exploited; PyTorch RPC Vulnerability; Malicious VSCode Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PHP Vulnerablity Exploited; PyTorch RPC Vulnerability; Malicious VSCode Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9016.mp3" length="7169887" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9016.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9016</link>
<pubDate>Mon, 10 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[PHP Unicode Remote Code Execution Exploit<br/>
 <a href="https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html">https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html</a><br/>
 <a href="https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/">https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/</a><br/>
PyTorch Distributed RPC Framework Remote Code Execution<br/>
 <a href="https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3">https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3</a><br/>
 <a href="https://www.cve.org/CVERecord?id=CVE-2024-5480">https://www.cve.org/CVERecord?id=CVE-2024-5480</a><br/>
Malicious VSCode Extensions Used by Researchers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/">https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/</a>]]></description>
<itunes:duration>8:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9016" type="text/plain" language="en" />
<itunes:keywords>vscode, extensions, pytorch, rpc, rce, php, unicode, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 7th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9014</itunes:episode>
<itunes:subtitle>"Best Before" Malware; FBI Offers Lockbit Help; UK Asks for EoL data; FCC proposes RPKI rules for BPG 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
"Best Before" Malware; FBI Offers Lockbit Help; UK Asks for EoL data; FCC proposes RPKI rules for BPG 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9014.mp3" length="5503715" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9014.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9014</link>
<pubDate>Fri, 07 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious Python Script with a "Best Before" Date<br/>
 <a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988</a><br/>
FBI Obtained 7,000 LockBit Ransomware Keys<br/>
 <a href="https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security">https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security</a><br/>
Apple Guarantees 5 Years of Security Updates<br/>
 <a href="https://www.androidauthority.com/iphone-software-support-commitment-3449135/">https://www.androidauthority.com/iphone-software-support-commitment-3449135/</a><br/>
FCC Proposes New Rule for Security Routing<br/>
 <a href="https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements">https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9014" type="text/plain" language="en" />
<itunes:keywords>fbi, lockbit, uk, apple, samsung, fcc, bgp, rpki, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9012</itunes:episode>
<itunes:subtitle>WatchGuard VPN Bruteforcing; TotalRecall; WebEx Flaw;  #webex @cisco #recall
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WatchGuard VPN Bruteforcing; TotalRecall; WebEx Flaw;  #webex @cisco #recall
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9012.mp3" length="5736091" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9012.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9012</link>
<pubDate>Thu, 06 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[WatchGuard VPN Brutefording<br/>
 <a href="https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984">https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984</a><br/>
TotalRecall Tool To Extract Data from Microsoft Recall<br/>
 <a href="https://github.com/xaitax/TotalRecall">https://github.com/xaitax/TotalRecall</a><br/>
WebEx Flaw<br/>
 <a href="https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/">https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/</a><br/>
 <a href="https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/">https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/</a> (in german)<br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9012" type="text/plain" language="en" />
<itunes:keywords>webex, totalrecall, recall, watchguard, vpn, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9010</itunes:episode>
<itunes:subtitle>No Defender Detection; Fake Job Ads; Zyxel NAS Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
No Defender Detection; Fake Job Ads; Zyxel NAS Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9010.mp3" length="4977741" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9010.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9010</link>
<pubDate>Wed, 05 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[No Defender Yes Defender<br/>
 <a href="https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980">https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980</a><br/>
Fake Job Ads Lead to Stolen Crypto Currency<br/>
 <a href="https://www.ic3.gov/Media/Y2024/PSA240604">https://www.ic3.gov/Media/Y2024/PSA240604</a><br/>
Zyxel NAS Vulnerabilities<br/>
 <a href="https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/">https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9010" type="text/plain" language="en" />
<itunes:keywords>zyxel, nas, fake job ads, defender, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9008</itunes:episode>
<itunes:subtitle>Custom Wireshark LUA Dissectors; COX Cable Modem API; Malicious Stack Overflow Answers;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Custom Wireshark LUA Dissectors; COX Cable Modem API; Malicious Stack Overflow Answers;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9008.mp3" length="4970797" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9008.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9008</link>
<pubDate>Tue, 04 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[A Wireshark Lua Dissector for Fixed Field Length Protocols<br/>
 <a href="https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976">https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976</a><br/>
COX Cable Modem Admin API Weakness<br/>
 <a href="https://samcurry.net/hacking-millions-of-modems">https://samcurry.net/hacking-millions-of-modems</a><br/>
Malicous Stack Overflow Answers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/">https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/</a><br/>
Atlasian Confluence Data Center and SErver Remote Code Execution Vuln CVE-2024-21683<br/>
 <a href="https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/">https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9008" type="text/plain" language="en" />
<itunes:keywords>atlasian, confluence, stack overflow, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 3rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9006</itunes:episode>
<itunes:subtitle>K1W1 Infostealer; Linux Malware Scanner; Snowflake Incident; HuggingFace Space secrets leak;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
K1W1 Infostealer; Linux Malware Scanner; Snowflake Incident; HuggingFace Space secrets leak;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9006.mp3" length="5034699" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9006.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9006</link>
<pubDate>Mon, 03 Jun 2024 02:00:02 GMT</pubDate>
<description><![CDATA[K1w1 Infostealer Uses gofile.io for Exfiltration<br/>
 <a href="https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972">https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972</a><br/>
Kaspersky Linux Malware Scanner<br/>
 <a href="https://www.kaspersky.com/blog/kvrt-for-linux/51375/">https://www.kaspersky.com/blog/kvrt-for-linux/51375/</a><br/>
Snowflake Incident<br/>
 <a href="https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/">https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/</a><br/>
HuggingFace Space Secrets Leak<br/>
 <a href="https://huggingface.co/blog/space-secrets-disclosure">https://huggingface.co/blog/space-secrets-disclosure</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9006" type="text/plain" language="en" />
<itunes:keywords>huggingface, ai, snowflake, credential stuffing, kaspersky, malware, scanner, k1w1, python, infostealer, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 31st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9004</itunes:episode>
<itunes:subtitle>OSSEC and MISP; Checkpoint VPN PoC Exploit; Massive October Windstream Outage; Cypher Injection; @sans_edu @watchtowrcyber @lumentechco
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OSSEC and MISP; Checkpoint VPN PoC Exploit; Massive October Windstream Outage; Cypher Injection; @sans_edu @watchtowrcyber @lumentechco
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9004.mp3" length="13248030" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9004.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9004</link>
<pubDate>Fri, 31 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Feeding MISP with OSSEC<br/>
 <a href="https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968">https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968</a><br/>
Checkpoint VPN<br/>
 <a href="https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/">https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/</a><br/>
The Pumpkin Eclipse<br/>
 <a href="https://blog.lumen.com/the-pumpkin-eclipse/">https://blog.lumen.com/the-pumpkin-eclipse/</a><br/>
Michael Dunking: Detecting Cypher Injection with Open-Source Network Intrusion Detection<br/>
 <a href="https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/">https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/</a><br/>
]]></description>
<itunes:duration>15:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9004" type="text/plain" language="en" />
<itunes:keywords>cypher, pumpkin, checkpoint, vpn, misp, ossec, path traversal, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 30th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9002</itunes:episode>
<itunes:subtitle>DShield SIEM; Checkpoint 0-Day; Okta Credential Stuffing; Bitcoin Wallet Bruteforce; @okta @joegrand 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DShield SIEM; Checkpoint 0-Day; Okta Credential Stuffing; Bitcoin Wallet Bruteforce; @okta @joegrand 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9002.mp3" length="4973409" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9002.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9002</link>
<pubDate>Thu, 30 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs<br/>
 <a href="https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962">https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962</a><br/>
Checkpoint 0-Day<br/>
 <a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture</a><br/>
Okta warns of Credential Stuffing Against Customer Identity Cloud<br/>
 <a href="https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks">https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks</a><br/>
Brute Forcing Old Bitcoin Wallet Password<br/>
 <a href="https://www.youtube.com/watch?v=o5IySpAkThg">https://www.youtube.com/watch?v=o5IySpAkThg</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9002" type="text/plain" language="en" />
<itunes:keywords>bitcoin, okta, checkpoint, siem, dshield, pcap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>9000</itunes:episode>
<itunes:subtitle>SQL Injection and Python; FortiSIEM RCE PoC; Bitlocker Ransomware;  iconv (glibc) and MacOS PoC; @Horizon3ai @WangTielei 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SQL Injection and Python; FortiSIEM RCE PoC; Bitlocker Ransomware;  iconv (glibc) and MacOS PoC; @Horizon3ai @WangTielei 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/9000.mp3" length="4286528" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/9000.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/9000</link>
<pubDate>Wed, 29 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Preventing SQL Injection with Python<br/>
 <a href="https://www.youtube.com/watch?v=1cQy9N1Xndk">https://www.youtube.com/watch?v=1cQy9N1Xndk</a><br/>
PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM<br/>
 <a href="https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/">https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/</a><br/>
ShrinkLocker: Turning BitLocker into ransomware<br/>
 <a href="https://securelist.com/ransomware-abuses-bitlocker/112643/">https://securelist.com/ransomware-abuses-bitlocker/112643/</a><br/>
iconv buffer overflow PoC 2024-2961<br/>
 <a href="https://github.com/ambionics/cnext-exploits/">https://github.com/ambionics/cnext-exploits/</a><br/>
PoC for Apple Priv. Escalation bug  CVE-2024-27842<br/>
 <a href="https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842">https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842</a><br/>
 <a href="https://x.com/WangTielei">https://x.com/WangTielei</a><br/>
]]></description>
<itunes:duration>4:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=9000" type="text/plain" language="en" />
<itunes:keywords>poc, apple, macos, iconv, php, shinklocker, ransomware, bitlocker, fortinet, fortisiem, sql injection, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 28th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8998</itunes:episode>
<itunes:subtitle>TXZ Malspam; 4th Google 0-Day; Google no trust in Globaltrust; Checkpoint Password Bruteforcing;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TXZ Malspam; 4th Google 0-Day; Google no trust in Globaltrust; Checkpoint Password Bruteforcing;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8998.mp3" length="5415316" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8998.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8998</link>
<pubDate>Tue, 28 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Files with TGZ Extension used as malspam attachements<br/>
 <a href="https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958">https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958</a><br/>
Google 0-Day<br/>
 <a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html</a><br/>
Google Stops Trusting Globaltrust CA<br/>
 <a href="https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ">https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ</a><br/>
Checkpoint warns of password bruteforcing<br/>
 <a href="https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&eid=guvrs&advisory=1">https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&eid=guvrs&advisory=1</a><br/>
SEC522: Defending Web Applications<br/>
 isc.sans.edu/j/sec522<br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8998" type="text/plain" language="en" />
<itunes:keywords>dc, washington, TXZ, malspam, chrome, 0-day, globaltrust, ccadb, checkpoint, vpm, mfa, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 24th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8996</itunes:episode>
<itunes:subtitle>Redtail Miner; Veeam, Ivanti and Firepower Vulns; Justice AV Backdoor; C-Root Server Lack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Redtail Miner; Veeam, Ivanti and Firepower Vulns; Justice AV Backdoor; C-Root Server Lack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8996.mp3" length="6397807" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8996.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8996</link>
<pubDate>Fri, 24 May 2024 02:35:05 GMT</pubDate>
<description><![CDATA[Analysis of 'redtail' file uploads to ISC Honeypot<br/>
 <a href="https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950">https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950</a><br/>
Veeam Vulnerablity<br/>
 <a href="https://www.veeam.com/kb4581">https://www.veeam.com/kb4581</a><br/>
C-Root Server Lost Touch With Peers<br/>
 <a href="https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/">https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/</a><br/>
Ivanti Vulnerabilities<br/>
 <a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US">https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US</a><br/>
Justice AV Solutions Software Backdoor<br/>
 <a href="https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/">https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8996" type="text/plain" language="en" />
<itunes:keywords>justice, av, ivanti, firepower, cisco, c-root, cogent, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8994</itunes:episode>
<itunes:subtitle>Scripting ipinfo in nmap; Wifi BSSID Location Databases: risks and opting out
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Scripting ipinfo in nmap; Wifi BSSID Location Databases: risks and opting out
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8994.mp3" length="8085426" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8994.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8994</link>
<pubDate>Thu, 23 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[NMAP Scanning Without Scanning - The ipinfo API<br/>
 <a href="https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948">https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948</a><br/>
Why Your WiFi Router Doubles As An Apple Airtag<br/>
 <a href="https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551">https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551</a><br/>
 <a href="https://account.microsoft.com/privacy/location-services-opt-out">https://account.microsoft.com/privacy/location-services-opt-out</a><br/>
 <a href="https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c">https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c</a><br/>
 <a href="https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html">https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html</a><br/>
 <a href="https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/">https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/</a><br/>
]]></description>
<itunes:duration>9:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8994" type="text/plain" language="en" />
<itunes:keywords>wps, wifi, location, gps, nmap, ipinfo, api, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8992</itunes:episode>
<itunes:subtitle>Shodan via nmap; iTerm2 Vulns; GitHub Enterprise Vuln; BitBucket Secret Leaks; MSFT Recall Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shodan via nmap; iTerm2 Vulns; GitHub Enterprise Vuln; BitBucket Secret Leaks; MSFT Recall Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8992.mp3" length="5894458" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8992.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8992</link>
<pubDate>Wed, 22 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Scanning without Scanning with nmap<br/>
 <a href="https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944">https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944</a><br/>
iTerm2 Vulnerablities<br/>
 <a href="https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html">https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html</a><br/>
GitHub Enterprise Vulnerablity CVE-2024-4985<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4985">https://nvd.nist.gov/vuln/detail/CVE-2024-4985</a><br/>
BitBucket Pipelines Leaking Secrets<br/>
 <a href="https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets">https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets</a><br/>
Microsoft Recall Privacy<br/>
 <a href="https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1">https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8992" type="text/plain" language="en" />
<itunes:keywords>microsoft, recall, bitbucket, pipelines, github, iterm2, nmap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 21st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8990</itunes:episode>
<itunes:subtitle>Analyzing MSG Files; Fluent Bit Vuln; Fortinet Vuln Details; Git and Google Chrome PoCs;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing MSG Files; Fluent Bit Vuln; Fortinet Vuln Details; Git and Google Chrome PoCs;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8990.mp3" length="5180096" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8990.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8990</link>
<pubDate>Tue, 21 May 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Analyzing MSG Files<br/>
 <a href="https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940">https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940</a><br/>
Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323<br/>
 <a href="https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323">https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323</a><br/>
Fortinet FortiSIEM Command Injection Deep-Dive CVE-2023-23992<br/>
 <a href="https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/">https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/</a><br/>
Git Vulnerability CVE-2024-32002 PoC<br/>
 <a href="https://amalmurali.me/posts/git-rce/">https://amalmurali.me/posts/git-rce/</a><br/>
Google Chrome CVE-2024-4947 PoC<br/>
 <a href="https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html">https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8990" type="text/plain" language="en" />
<itunes:keywords>msg, fluent bit, fortinet, fortisiem, git, google, chrome, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 20th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8988</itunes:episode>
<itunes:subtitle>Extrace JPEGs from PDFs; QNAP 0-Day PoC; Exploited D-Link Vulnerabilities; Ivanti PoC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Extrace JPEGs from PDFs; QNAP 0-Day PoC; Exploited D-Link Vulnerabilities; Ivanti PoC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8988.mp3" length="5662971" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8988.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8988</link>
<pubDate>Mon, 20 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Another PDF Streams Example: Extracting JPEGs<br/>
 <a href="https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924">https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924</a><br/>
QNAP QTS QNAPping At the Wheel<br/>
 <a href="https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/">https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/</a><br/>
May 2024 Security Update Problems with Windows 2019<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc</a><br/>
Dlink Vulnerabilities Exploited<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog">https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br/>
Ivanti PoC Exploit CVE 2024-22026<br/>
 <a href="https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core">https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8988" type="text/plain" language="en" />
<itunes:keywords>ivanti, poc, dlink, patch, windows, microsoft, 2019, qnap, qts, ping, share, pdf, jpeg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8986</itunes:episode>
<itunes:subtitle>yq parser; Quick Assist Misuse; Chrome 0-Days; Android Theft Protection; Git Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
yq parser; Quick Assist Misuse; Chrome 0-Days; Android Theft Protection; Git Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8986.mp3" length="4808878" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8986.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8986</link>
<pubDate>Fri, 17 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Why yq? Adventurs in XML<br/>
 <a href="https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930">https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930</a><br/>
Black Basta Uses Quick Assist<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/">https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/</a><br/>
Various Chrome 0-Day Vulnerabilities<br/>
 <a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html</a><br/>
Android Theft Protection Improvement<br/>
 <a href="https://blog.google/products/android/android-theft-protection/">https://blog.google/products/android/android-theft-protection/</a><br/>
Critical Git Update<br/>
 <a href="https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/">https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8986" type="text/plain" language="en" />
<itunes:keywords>git, android, chrome, quick assist, black basta, yq, xml, json, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8984</itunes:episode>
<itunes:subtitle>VPNs need MFA; SSID Confusion; FIDO2 Session Hijacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VPNs need MFA; SSID Confusion; FIDO2 Session Hijacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8984.mp3" length="4947581" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8984.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8984</link>
<pubDate>Thu, 16 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Got MFA? If not, now is the time!<br/>
 <a href="https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926">https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926</a><br/>
SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424<br/>
 <a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf">https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf</a><br/>
FIDO2 MitM Session Hijacking<br/>
 <a href="https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background">https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8984" type="text/plain" language="en" />
<itunes:keywords>fido2, mitm, ssid, wifi, mfa, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 15th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8982</itunes:episode>
<itunes:subtitle>Microsoft Patches; Bluetooth Trackers; VMWare Updates; Revoking Windows UEFI Certs; Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Bluetooth Trackers; VMWare Updates; Revoking Windows UEFI Certs; Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8982.mp3" length="6657544" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8982.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8982</link>
<pubDate>Wed, 15 May 2024 02:35:05 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920">https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920</a><br/>
Detecting Bluetooth Trackers<br/>
 <a href="https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html">https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html">https://helpx.adobe.com/security/products/acrobat/apsb24-29.html</a><br/>
VMWare Updates<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280</a><br/>
Revoking Vulnerability Windows Boot Managers<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735</a><br/>
]]></description>
<itunes:duration>7:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8982" type="text/plain" language="en" />
<itunes:keywords>boot managers, windows, patches, bluetooth, trackers, vmware, adobe, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 14th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8980</itunes:episode>
<itunes:subtitle>Apple Updates; JunOS OpenSSH Issues; Malicious Go in PyPi;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; JunOS OpenSSH Issues; Malicious Go in PyPi;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8980.mp3" length="5570226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8980.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8980</link>
<pubDate>Tue, 14 May 2024 02:35:05 GMT</pubDate>
<description><![CDATA[Apple Updates Everything<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916">https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916</a><br/>
Juniper OpenSSH Update<br/>
 <a href="https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US">https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US</a><br/>
Malicious Go Binary Delivered via Steganography in PyPi<br/>
 <a href="https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/">https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8980" type="text/plain" language="en" />
<itunes:keywords>go, pypi, openssh, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8978</itunes:episode>
<itunes:subtitle>Windows DNS Suffixes; Black Basta Ransomware; Arcserve UDP Exploits; Chrome 0-day; SolarWinds ARM Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows DNS Suffixes; Black Basta Ransomware; Arcserve UDP Exploits; Chrome 0-day; SolarWinds ARM Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8978.mp3" length="5006340" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8978.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8978</link>
<pubDate>Mon, 13 May 2024 03:00:05 GMT</pubDate>
<description><![CDATA[DNS Suffixes on Windows<br/>
 <a href="https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912">https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912</a><br/>
Black Basta Ransomware Advisory<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a</a><br/>
Possible Exploitation of Arcserve Unified Data Protection Vuln<br/>
 <a href="https://digital.nhs.uk/cyber-alerts/2024/cc-4487">https://digital.nhs.uk/cyber-alerts/2024/cc-4487</a><br/>
Chrome Patches 0-Day<br/>
 <a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html">https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html</a><br/>
Solarwinds ARM Vulnerablities<br/>
 <a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8978" type="text/plain" language="en" />
<itunes:keywords>dns, suffix, windows, black basta, ransomware, arcserve, chrome, 0-day, solarwinds, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8976</itunes:episode>
<itunes:subtitle>PDF Streams; F5 Central Manager Vuln; Veeam Patches; XenCenter Putty Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF Streams; F5 Central Manager Vuln; Veeam Patches; XenCenter Putty Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8976.mp3" length="5255608" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8976.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8976</link>
<pubDate>Fri, 10 May 2024 03:05:05 GMT</pubDate>
<description><![CDATA[Analyzing PDF Streams<br/>
 <a href="https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908">https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908</a><br/>
F5 Next Central Manager Vulnerabilities<br/>
 <a href="https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/">https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/</a><br/>
Veeam Patches<br/>
 <a href="https://www.veeam.com/kb4441">https://www.veeam.com/kb4441</a><br/>
 <a href="https://www.veeam.com/kb4509">https://www.veeam.com/kb4509</a><br/>
Citrix Hypervisor Security Update CVE-2024-31497<br/>
 <a href="https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497">https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8976" type="text/plain" language="en" />
<itunes:keywords>citrix, hypervisor, veeam, f5, pdf, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8974</itunes:episode>
<itunes:subtitle>Analyzing Synology Disks; RSA Panel; SANS.edu Research Journal
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing Synology Disks; RSA Panel; SANS.edu Research Journal
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8974.mp3" length="5477992" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8974.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8974</link>
<pubDate>Thu, 09 May 2024 04:45:05 GMT</pubDate>
<description><![CDATA[Analzying Synology Disks<br/>
 <a href="https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904">https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904</a><br/>
RSA Panel<br/>
 <a href="https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About">https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About</a><br/>
SANS.edu Research Journal<br/>
 <a href="https://www.sans.edu/cyber-security-research">https://www.sans.edu/cyber-security-research</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8974" type="text/plain" language="en" />
<itunes:keywords>sans.edu, research, journal, rsa, panel, synology, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8972</itunes:episode>
<itunes:subtitle>ISP DNS Spoofing; Weblogic PoC; PDF.js / React PDF Vuln; Tinyproxy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ISP DNS Spoofing; Weblogic PoC; PDF.js / React PDF Vuln; Tinyproxy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8972.mp3" length="7213077" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8972.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8972</link>
<pubDate>Wed, 08 May 2024 04:50:05 GMT</pubDate>
<description><![CDATA[Detecting XFinity/Comcast DNS Spoofing<br/>
 <a href="https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898">https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898</a><br/>
Weblogic PoC CVE-2024-21006<br/>
 <a href="https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/">https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/</a><br/>
 <a href="https://github.com/momika233/CVE-2024-21006">https://github.com/momika233/CVE-2024-21006</a><br/>
PDF.js React PDF Vulnerablity<br/>
 <a href="https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/">https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/</a><br/>
Tinyproxy Response <br/>
 <a href="https://github.com/tinyproxy/tinyproxy/issues/533">https://github.com/tinyproxy/tinyproxy/issues/533</a><br/>
]]></description>
<itunes:duration>8:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8972" type="text/plain" language="en" />
<itunes:keywords>tinyproxy, pdf.js, react, pdf, weblogic, xfinity, comcast, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 7th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8970</itunes:episode>
<itunes:subtitle>VPN Routing Leaks; Mullvad VPN Traffic Leak; Tiny Proxy unpatches RCE Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VPN Routing Leaks; Mullvad VPN Traffic Leak; Tiny Proxy unpatches RCE Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8970.mp3" length="5729162" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8970.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8970</link>
<pubDate>Tue, 07 May 2024 05:30:06 GMT</pubDate>
<description><![CDATA[DHCP Based VPN Routing Leaks<br/>
 <a href="https://www.leviathansecurity.com/blog/tunnelvision">https://www.leviathansecurity.com/blog/tunnelvision</a><br/>
Mullvad VPN DNS Traffic Leak<br/>
 <a href="https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android">https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android</a><br/>
Tiny Proxy Vulnerability <br/>
 <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889">https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8970" type="text/plain" language="en" />
<itunes:keywords>tiny proxy, vpn, mullvad, tunnelview, routing, leak, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8968</itunes:episode>
<itunes:subtitle>DNS Debugging; MSFT Zero Trust DNS; MSFT Graph API Abuse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Debugging; MSFT Zero Trust DNS; MSFT Graph API Abuse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8968.mp3" length="4958836" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8968.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8968</link>
<pubDate>Mon, 06 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[DNS Debugging with nslookup<br/>
 <a href="https://isc.sans.edu/diary/nslookups+Debug+Options/30894/">https://isc.sans.edu/diary/nslookups+Debug+Options/30894/</a><br/>
Microsoft Plans DNS Lockdown<br/>
 <a href="https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366">https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366</a><br/>
Microsoft Graph API Abuse<br/>
 <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats</a><br/>
SANSFIRE SEC522 Defending Web Applications<br/>
 <a href="https://www.sans.org/cyber-security-training-events/sansfire-2024/">https://www.sans.org/cyber-security-training-events/sansfire-2024/</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8968" type="text/plain" language="en" />
<itunes:keywords>microsoft, graph, api, dns, zero trust, ztdns, nslookup, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 3rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8966</itunes:episode>
<itunes:subtitle>Scans for Stupid Router Vuln; npm xml-crypt Vuln; Cuddlefish; ArubaOS Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Scans for Stupid Router Vuln; npm xml-crypt Vuln; Cuddlefish; ArubaOS Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8966.mp3" length="4975415" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8966.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8966</link>
<pubDate>Fri, 03 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[<a href="https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890">https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890</a><br/>
 Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796<br/>
Buffer Overflow Vulnerabilities in ArubaOS<br/>
 <a href="https://www.arubanetworks.com/support-services/security-bulletins/">https://www.arubanetworks.com/support-services/security-bulletins/</a><br/>
The Cuttlefish Malware<br/>
 <a href="https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/">https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8966" type="text/plain" language="en" />
<itunes:keywords>routers, npm, cuddlefix, arubaos, https, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 2nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8964</itunes:episode>
<itunes:subtitle>Linux Trojan; Denial of Wallet Attack; EU iOS Appstore User Tracking; BentoML Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Linux Trojan; Denial of Wallet Attack; EU iOS Appstore User Tracking; BentoML Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8964.mp3" length="6060626" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8964.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8964</link>
<pubDate>Thu, 02 May 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Linux Trojan - Xorddos with Filename eyshcjdmzg<br/>
 <a href="https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880">https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880</a><br/>
AWS S3 Denial of Wallet Amplification Attack<br/>
 <a href="https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1">https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1</a><br/>
 <a href="https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d">https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d</a><br/>
EU iOS Safari Allows User Tracking<br/>
 <a href="https://www.mysk.blog/2024/04/28/safari-tracking/">https://www.mysk.blog/2024/04/28/safari-tracking/</a><br/>
BentoML Critical Deserialization Vuln CVE-2024-2912<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-2912">https://nvd.nist.gov/vuln/detail/CVE-2024-2912</a><br/>
]]></description>
<itunes:duration>6:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8964" type="text/plain" language="en" />
<itunes:keywords>bentoml, ios, safari, tracking, aws, s3, cost, wallet, linux, trojan, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 1st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8962</itunes:episode>
<itunes:subtitle>Zyxel NAS Attacks; R Vulnerability; Malicious Containers; NVMe-oF/TCP Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zyxel NAS Attacks; R Vulnerability; Malicious Containers; NVMe-oF/TCP Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8962.mp3" length="5885169" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8962.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8962</link>
<pubDate>Wed, 01 May 2024 10:15:05 GMT</pubDate>
<description><![CDATA[Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474<br/>
 <a href="https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884">https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884</a><br/>
R-Bitrary Code Execution: Vulnearbility in R's Deserialization<br/>
 <a href="https://hiddenlayer.com/research/r-bitrary-code-execution/">https://hiddenlayer.com/research/r-bitrary-code-execution/</a><br/>
Coordinated Docker Hub Attacks using Malicious Repositories<br/>
 <a href="https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/">https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/</a><br/>
NVMe-oF/TCP Vulnerabilities<br/>
 <a href="https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller">https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller</a><br/>
]]></description>
<itunes:duration>6:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8962" type="text/plain" language="en" />
<itunes:keywords>nvme, tcp, docker, hub, malicious, repos, nas, zyxel, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 30th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8960</itunes:episode>
<itunes:subtitle>DLink NAS Exploit Variation; DNS and Great Firewall of China; Android TV Data Leakage
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DLink NAS Exploit Variation; DNS and Great Firewall of China; Android TV Data Leakage
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8960.mp3" length="6118457" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8960.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8960</link>
<pubDate>Tue, 30 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[DLink NAS Exploit Variation<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-24-09">https://www.qnap.com/en/security-advisory/qsa-24-09</a><br/>
Muddling Meerkat DNS Abuse<br/>
 <a href="https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/">https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/</a><br/>
Android TV Data Leakage<br/>
 <a href="https://www.youtube.com/watch?v=QiyBXXO8QpA">https://www.youtube.com/watch?v=QiyBXXO8QpA</a><br/>
 <a href="https://www.404media.co/android-tvs-can-expose-user-email-inboxes/">https://www.404media.co/android-tvs-can-expose-user-email-inboxes/</a><br/>
SEC522: SANSFIRE<br/>
 <a href="https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/">https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/</a><br/>
SEC522 Demo (requires free account):<br/>
 <a href="https://www.sans.org/ondemand/get-demo/316">https://www.sans.org/ondemand/get-demo/316</a><br/>
]]></description>
<itunes:duration>6:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8960" type="text/plain" language="en" />
<itunes:keywords>sec522, sansfire, demo, android, muddling, meerkat, dns, great firewall, china, dlink, nas, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8958</itunes:episode>
<itunes:subtitle>Credential Stuffing Increase; Fake Payment Cards; USPS Phishing; Chrome Post Quantum TLS Issues;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Credential Stuffing Increase; Fake Payment Cards; USPS Phishing; Chrome Post Quantum TLS Issues;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8958.mp3" length="5852528" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8958.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8958</link>
<pubDate>Mon, 29 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Okta warns of increase in credential stuffing<br/>
 <a href="https://sec.okta.com/blockanonymizers">https://sec.okta.com/blockanonymizers</a><br/>
Fake payment cards used by Police in Japan<br/>
 <a href="https://twitter.com/vxunderground/status/1783522097425211887">https://twitter.com/vxunderground/status/1783522097425211887</a><br/>
Phishing Campaigns Targeting USPS<br/>
 <a href="https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic">https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic</a><br/>
Chrome 124 Breaks TLS Handshake<br/>
 <a href="https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/">https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8958" type="text/plain" language="en" />
<itunes:keywords>chrome, tls, phishing, usps, japan, okta, credential stuffing, brute forcing, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8956</itunes:episode>
<itunes:subtitle>Honeypot Firewalls; Unplugging PlugX; pfsense and GitLab Updates; Blocking LOLBins @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot Firewalls; Unplugging PlugX; pfsense and GitLab Updates; Blocking LOLBins @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8956.mp3" length="17501610" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8956.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8956</link>
<pubDate>Fri, 26 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Does it matter if iptables isn't running on my honeypot?<br/>
 <a href="https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/">https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/</a><br/>
Unplugging PlugX: Singholing the PlugX USB worm botnet<br/>
 <a href="https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/">https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/</a><br/>
pfSense Updates<br/>
 <a href="https://docs.netgate.com/advisories/index.html">https://docs.netgate.com/advisories/index.html</a><br/>
GitLab Updates<br/>
 <a href="https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/">https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/</a><br/>
Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usage<br/>
 <a href="https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/">https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/</a><br/>
]]></description>
<itunes:duration>20:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8956" type="text/plain" language="en" />
<itunes:keywords>sans.edu, research, gitlab, lolbins, pfsense, plugx, iptables, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 25th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8954</itunes:episode>
<itunes:subtitle>NVD API Updates; Cisco Patches and Backdoor; Keyboard App Vulns; node-mysql2 vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NVD API Updates; Cisco Patches and Backdoor; Keyboard App Vulns; node-mysql2 vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8954.mp3" length="5477300" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8954.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8954</link>
<pubDate>Thu, 25 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[API Rug Pull - The NIST NVD Database and API<br/>
 <a href="https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868">https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868</a><br/>
Cisco Patches Vulnerabilities and Discovers Arcane Backdoor<br/>
 <a href="https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/">https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/</a><br/>
Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers<br/>
 <a href="https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/">https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/</a><br/>
MySQL2: Dangers of User-Defined Database Connections<br/>
 <a href="https://blog.slonser.info/posts/mysql2-attacker-configuration/">https://blog.slonser.info/posts/mysql2-attacker-configuration/</a><br/>
Netgear Nighthawk Vulnerabilities<br/>
 <a href="https://jvn.jp/en/vu/JVNVU91883072/">https://jvn.jp/en/vu/JVNVU91883072/</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8954" type="text/plain" language="en" />
<itunes:keywords>netgear, nighthawk, mysql2, node, keyboard, cisco, backdoor, arcanedoor, api, nvd, nist, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 24th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8952</itunes:episode>
<itunes:subtitle>struts2 devmode scans; Russian PrinterNightmare; Exchange Server Fix; Flowmon Exploit; GuptiMiner;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
struts2 devmode scans; Russian PrinterNightmare; Exchange Server Fix; Flowmon Exploit; GuptiMiner;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8952.mp3" length="5657420" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8952.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8952</link>
<pubDate>Wed, 24 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Struts2 devmode Still a Problem Ten Years Later<br/>
 <a href="https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/">https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/</a><br/>
Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/">https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/</a><br/>
April 2024 Exchange Server Hotfix Update<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536</a><br/>
CVE-2024-2389: Command Injection Vulnerability in Progress Flowmon<br/>
 <a href="https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/">https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/</a><br/>
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining<br/>
 <a href="https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/">https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8952" type="text/plain" language="en" />
<itunes:keywords>guptiminer, progress, flowmon, exchange server, hotfix, forest blizard, printnightmware, struts2, devmode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8950</itunes:episode>
<itunes:subtitle>Exposed ICS; Evil XDR; GitLab Comment Bug;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exposed ICS; Evil XDR; GitLab Comment Bug;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8950.mp3" length="5425120" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8950.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8950</link>
<pubDate>Tue, 23 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years<br/>
 <a href="https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860">https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860</a><br/>
Evil XDR: Turning an XDR into an Offensive Tool<br/>
 <a href="https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware">https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware</a><br/>
GitLab Comment Bug<br/>
 <a href="https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/">https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/</a><br/>
SEC522 Demo: <a href="https://www.sans.org/ondemand/get-demo/316">https://www.sans.org/ondemand/get-demo/316</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8950" type="text/plain" language="en" />
<itunes:keywords>gitlab, xdr, evil xdr, ics, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8948</itunes:episode>
<itunes:subtitle>CVE Changes; CrushFTP 0-Day; GitHub Comment Bug; YubiKey Manager Bug; PAN GlobalProtect Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE Changes; CrushFTP 0-Day; GitHub Comment Bug; YubiKey Manager Bug; PAN GlobalProtect Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8948.mp3" length="5011362" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8948.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8948</link>
<pubDate>Mon, 22 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[The CVE's They are A-Changing<br/>
 <a href="https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850">https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850</a><br/>
CrushFTP 0-Day Vulnerability<br/>
 <a href="https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update">https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update</a><br/>
 <a href="https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/">https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/</a><br/>
GitHub Comment Bug Used to Distribute Malware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/">https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/</a><br/>
YubiKey Manager Privilege Escalation<br/>
 <a href="https://www.yubico.com/support/security-advisories/ysa-2024-01/">https://www.yubico.com/support/security-advisories/ysa-2024-01/</a><br/>
Palo Alto Networks GlobalProtect Update<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2024-3400">https://security.paloaltonetworks.com/CVE-2024-3400</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8948" type="text/plain" language="en" />
<itunes:keywords>cve, crushftp, github, yubikey, palo alto, PAN, globalprotect, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8946</itunes:episode>
<itunes:subtitle>Delinea PoC; Ivanti Avalanche PoC; Advanced Phishing Campaign; go-getter update; OfflRouter Virus
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Delinea PoC; Ivanti Avalanche PoC; Advanced Phishing Campaign; go-getter update; OfflRouter Virus
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8946.mp3" length="4600797" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8946.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8946</link>
<pubDate>Fri, 19 Apr 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Delinea Secret Server Authn Authz Bypass<br/>
 <a href="https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3">https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3</a><br/>
Ivanti Avalanche Poc/Details<br/>
 <a href="https://www.tenable.com/security/research/tra-2024-10">https://www.tenable.com/security/research/tra-2024-10</a><br/>
Advanced Phishing Campaign<br/>
 <a href="https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit">https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit</a><br/>
Hashicorp go-getter update CVE-2024-3817<br/>
 <a href="https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040">https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040</a><br/>
OfflRouter Virus<br/>
 <a href="https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/">https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8946" type="text/plain" language="en" />
<itunes:keywords>offlrouter, ukraine, hashicorp, go-getter, phishing, ivanti, delinea, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8944</itunes:episode>
<itunes:subtitle>AgentTesla via PDF; GlobalProtect Updates; Open Source Takeovers; OpenMetaData Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AgentTesla via PDF; GlobalProtect Updates; Open Source Takeovers; OpenMetaData Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8944.mp3" length="4779531" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8944.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8944</link>
<pubDate>Thu, 18 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious PDF File As Delivery Mechanism<br/>
 <a href="https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848">https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848</a><br/>
Updated Palo Alto Networks GlobalProtect Guidance<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2024-3400">https://security.paloaltonetworks.com/CVE-2024-3400</a><br/>
Coordinated Social Engineering Takeovers of Open Source Projects;<br/>
 <a href="https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/">https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/</a><br/>
OpenMetaData Attacks<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/">https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8944" type="text/plain" language="en" />
<itunes:keywords>openmetadata, social engineering, open source, openssf, openjs, pan, globalprotect, pdf, agenttesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8942</itunes:episode>
<itunes:subtitle>GlobalProtect Exploit Public; Putty Private Key Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GlobalProtect Exploit Public; Putty Private Key Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8942.mp3" length="4977956" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8942.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8942</link>
<pubDate>Wed, 17 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400<br/>
 <a href="https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/">https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/</a><br/>
Putty Private Key Recovery<br/>
 <a href="https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html">https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html</a><br/>
Oracle Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpuapr2024.html">https://www.oracle.com/security-alerts/cpuapr2024.html</a><br/>
Ivanti Avalanche MDM Patches<br/>
 <a href="https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US">https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8942" type="text/plain" language="en" />
<itunes:keywords>ivanti, avalanche, oracle, cpu, putty, ssh, pan, globalprotect, palo alto, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8940</itunes:episode>
<itunes:subtitle>GlobalProtect Updates; Delinea Patch; Lancom PW reset; PHP Patch; Duo leak; LastPass Deepfake
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GlobalProtect Updates; Delinea Patch; Lancom PW reset; PHP Patch; Duo leak; LastPass Deepfake
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8940.mp3" length="5587860" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8940.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8940</link>
<pubDate>Tue, 16 Apr 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400<br/>
 <a href="https://isc.sans.edu/diary/30838">https://isc.sans.edu/diary/30838</a><br/>
Delinea patches critical vulnerability in secret manager<br/>
 <a href="https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3">https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3</a><br/>
Lancom Windows Setup Assistant May Reset Password<br/>
 <a href="https://www.lancom-systems.com/service-support/general-security-information">https://www.lancom-systems.com/service-support/general-security-information</a><br/>
PHP Patches<br/>
 <a href="https://seclists.org/oss-sec/2024/q2/113">https://seclists.org/oss-sec/2024/q2/113</a><br/>
Duo SMS and VoiP Logs Leaked<br/>
 <a href="https://app.securitymsp.cisco.com/e/es?e=2785&eid=opguvrs&elq=bd1c1886a59e40c09915b029a74be94e">https://app.securitymsp.cisco.com/e/es?e=2785&eid=opguvrs&elq=bd1c1886a59e40c09915b029a74be94e</a><br/>
Lastpass Stops Deepfake Attack<br/>
 <a href="https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee">https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8940" type="text/plain" language="en" />
<itunes:keywords>Delinea, secret manager, lancom, php, duo, sms, voip, lastpass, deepfake, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, April 14th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8938</itunes:episode>
<itunes:subtitle>Palo Alto Networks GlobalProtect 0-Day Vulnerability Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Palo Alto Networks GlobalProtect 0-Day Vulnerability Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8938.mp3" length="5079188" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8938.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8938</link>
<pubDate>Sat, 13 Apr 2024 19:58:48 GMT</pubDate>
<description><![CDATA[Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2024-3400">https://security.paloaltonetworks.com/CVE-2024-3400</a><br/>
 <a href="https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise">https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8938" type="text/plain" language="en" />
<itunes:keywords>palo alto networks, pan, panos, 0-day, globalprotect, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8936</itunes:episode>
<itunes:subtitle>BatBadBut Vulnerability; FortiClient Linux RCE; Apple Notifications; GitHub Search Tricks;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BatBadBut Vulnerability; FortiClient Linux RCE; Apple Notifications; GitHub Search Tricks;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8936.mp3" length="5509514" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8936.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8936</link>
<pubDate>Fri, 12 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[BatBadBut: You can't securely execute commands on Windows<br/>
 <a href="https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/">https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/</a><br/>
FortiClient Linux Remote Code Execution<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-23-087">https://www.fortiguard.com/psirt/FG-IR-23-087</a><br/>
Apple Threat Notifications and Protecting Against Mercenary Spyware<br/>
 <a href="https://support.apple.com/en-us/102174">https://support.apple.com/en-us/102174</a><br/>
New Technique to Trick Developers Detected in an Open Source Supply Chain Attack<br/>
 <a href="https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/">https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8936" type="text/plain" language="en" />
<itunes:keywords>github, supply chain, search, mercenary, spyware, apple, forticlient, linux, batbadbut, windows, bat, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8934</itunes:episode>
<itunes:subtitle>Rust Vulnerability; Adobe Updates; Fortinet Patches; Malicious Windows Driver
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Rust Vulnerability; Adobe Updates; Fortinet Patches; Malicious Windows Driver
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8934.mp3" length="5329921" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8934.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8934</link>
<pubDate>Thu, 11 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Rust Command API code execution vulnerability CVE-2024-24576<br/>
 <a href="https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html">https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html</a> <br/>
Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb24-18.html">https://helpx.adobe.com/security/products/magento/apsb24-18.html</a><br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Fortinet FortiOS And FortiProxy Vulnerability CVE-2023-41677<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-23-493">https://www.fortiguard.com/psirt/FG-IR-23-493</a><br/>
Smoke and Screen Mirrors Signed Backdoor CVE-2024-26234 <br/>
 <a href="https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/">https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8934" type="text/plain" language="en" />
<itunes:keywords>driver, backdoor, fortinet, fortios, fortiproxy, adobe, magento, commerce, rust, command, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8932</itunes:episode>
<itunes:subtitle>Microsoft Patches; D-Link NAS Backdoor; LG WebOS TV Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; D-Link NAS Backdoor; LG WebOS TV Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8932.mp3" length="5778164" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8932.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8932</link>
<pubDate>Wed, 10 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/">https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/</a><br/>
D-Link NAS Backdoor<br/>
 <a href="https://github.com/netsecfish/dlink">https://github.com/netsecfish/dlink</a><br/>
LG SmartTV Vulnerabilities<br/>
 <a href="https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/">https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8932" type="text/plain" language="en" />
<itunes:keywords>lg, smarttv, d-link, nas, backdoor, microsoft, patches, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8930</itunes:episode>
<itunes:subtitle>Why Threat Hunting; Notepad++ Domain Issue; Pickle ML Vulns; V8 Sandbox
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Why Threat Hunting; Notepad++ Domain Issue; Pickle ML Vulns; V8 Sandbox
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8930.mp3" length="5332082" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8930.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8930</link>
<pubDate>Tue, 09 Apr 2024 02:00:01 GMT</pubDate>
<description><![CDATA[A Use Case for Adding Threat Hunting to Your Security Operations Team.<br/>
 <a href="https://isc.sans.edu/diary/30816">https://isc.sans.edu/diary/30816</a><br/>
Notepad++ Parasite Site<br/>
 <a href="https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/">https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/</a><br/>
Hugging Face Pickle File Vulnerablities<br/>
 <a href="https://huggingface.co/blog/hugging-face-wiz-security-blog">https://huggingface.co/blog/hugging-face-wiz-security-blog</a><br/>
Google Considers V8 Sandbox no longer experimental<br/>
 <a href="https://v8.dev/blog/sandbox">https://v8.dev/blog/sandbox</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8930" type="text/plain" language="en" />
<itunes:keywords>v8, google, hugging face, pickle, notepad, parasite, plus, threat hunting, soc, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8928</itunes:episode>
<itunes:subtitle>Heartbleed 10th Anniversary; Magento Backdoor; Fighting DNS Spoofing; Brocade Vuln; @sans_emea evening talk
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Heartbleed 10th Anniversary; Magento Backdoor; Fighting DNS Spoofing; Brocade Vuln; @sans_emea evening talk
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8928.mp3" length="4917328" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8928.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8928</link>
<pubDate>Mon, 08 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Heartbleed 10th Anniversary<br/>
 <a href="https://heartbleed.com/">https://heartbleed.com/</a><br/>
Possible Libarchive Backdoor Vulnerability<br/>
 <a href="https://github.com/libarchive/libarchive/pull/1609">https://github.com/libarchive/libarchive/pull/1609</a><br/>
Magento XML Backdoor<br/>
 <a href="https://sansec.io/research/magento-xml-backdoor">https://sansec.io/research/magento-xml-backdoor</a><br/>
Google Public DNS's approach to fight against cache poisoning attacks<br/>
 <a href="https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html">https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html</a><br/>
Remote code execution (RCE)vulnerability in Brocade Fabric OS (CVE-2023-3454)<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215</a><br/>
SANS London April Evening Talk<br/>
 <a href="https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration">https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8928" type="text/plain" language="en" />
<itunes:keywords>heartbleed, xz-utils, magento, libarchive, google, dns, cache poisoning, brocade, fabric os, sans, london, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8926</itunes:episode>
<itunes:subtitle>Reversing DoNex; HTTP/2 Continuation Flood; Kobold Letters; Infostealers in Automotive Headunits @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing DoNex; HTTP/2 Continuation Flood; Kobold Letters; Infostealers in Automotive Headunits @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8926.mp3" length="13068938" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8926.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8926</link>
<pubDate>Fri, 05 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Slicing up DoNex with Binary Ninja<br/>
 <a href="https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812">https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812</a><br/>
HTTP/2 Continuation Flood<br/>
 <a href="https://nowotarski.info/http2-continuation-flood-technical-details/">https://nowotarski.info/http2-continuation-flood-technical-details/</a><br/>
Dangers of CSS in HTML Email<br/>
 <a href="https://lutrasecurity.com/en/articles/kobold-letters/">https://lutrasecurity.com/en/articles/kobold-letters/</a><br/>
Dan Mazzella: Infostealers in Automotive Headunits<br/>
 <a href="https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/">https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/</a><br/>
]]></description>
<itunes:duration>15:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8926" type="text/plain" language="en" />
<itunes:keywords>donex, binary ninja, http2, css, html, email, infostealers, automotive, headunits, android, carplay, android auto, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8924</itunes:episode>
<itunes:subtitle>Playing with xzbot; Device Bound Session Credentials; Ivanti Vulns; Google Pixel 0-Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Playing with xzbot; Device Bound Session Credentials; Ivanti Vulns; Google Pixel 0-Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8924.mp3" length="5380070" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8924.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8924</link>
<pubDate>Thu, 04 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Playing with xzbot: Some things you can learn from SSH traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/">https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/</a><br/>
Google Proposes Device Bound Session Credentials (DBSC)<br/>
 <a href="https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html">https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html</a><br/>
 <br/>
Four More Ivanti Vulnerabilities<br/>
 <a href="https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US">https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br/>
Google Pixel Zero Day<br/>
 <a href="https://source.android.com/docs/security/bulletin/pixel/2024-04-01">https://source.android.com/docs/security/bulletin/pixel/2024-04-01</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8924" type="text/plain" language="en" />
<itunes:keywords>google, pixel, cookies, sessions, ivanti, dbsc, ssh, xzbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 3rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8922</itunes:episode>
<itunes:subtitle>Chrome Incognito Mode; GMail Anti-Spam; Cisco Updates; Apache Pulsar Updates; Progress Flowmon Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chrome Incognito Mode; GMail Anti-Spam; Cisco Updates; Apache Pulsar Updates; Progress Flowmon Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8922.mp3" length="5061444" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8922.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8922</link>
<pubDate>Wed, 03 Apr 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Chrome Incognito Mode Settlement<br/>
 <a href="https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/">https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/</a><br/>
Google E-Mail Sender Guidelines FAQ<br/>
 <a href="https://support.google.com/a/answer/14229414?hl=en&fl=1&sjid=2270464422796374445-NC">https://support.google.com/a/answer/14229414?hl=en&fl=1&sjid=2270464422796374445-NC</a><br/>
Cisco Updates and VPN Best Practices<br/>
 <a href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html">https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html</a><br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/publicationListing.x">https://sec.cloudapps.cisco.com/security/center/publicationListing.x</a><br/>
Apache Pulsar Vulnerability<br/>
 <a href="https://pulsar.apache.org/security/CVE-2024-29834/">https://pulsar.apache.org/security/CVE-2024-29834/</a><br/>
Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389<br/>
 <a href="https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability">https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability</a><br/>
Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDST<br/>
 <a href="https://isc.sans.edu/j/xzutils">https://isc.sans.edu/j/xzutils</a> (link will redirect once episode is live)<br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8922" type="text/plain" language="en" />
<itunes:keywords>progress, flowmon, apache, pulsar, cisco, chrome, google, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 2nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8920</itunes:episode>
<itunes:subtitle>xz-utils update; csv files; MacOS Infostealer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
xz-utils update; csv files; MacOS Infostealer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8920.mp3" length="6315950" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8920.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8920</link>
<pubDate>Tue, 02 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[The amazingly scary xz sshd backdoor<br/>
 <a href="https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802">https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802</a><br/>
The xz-utils backdoor in security advisories by national CSIRTs<br/>
 <a href="https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800">https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800</a><br/>
Checking CSV Files<br/>
 <a href="https://isc.sans.edu/diary/Checking%20CSV%20Files/30796">https://isc.sans.edu/diary/Checking%20CSV%20Files/30796</a><br/>
Infostealers Pose Threat to macOS<br/>
 <a href="https://www.jamf.com/blog/infostealers-pose-threat-to-macos/">https://www.jamf.com/blog/infostealers-pose-threat-to-macos/</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8920" type="text/plain" language="en" />
<itunes:keywords>infostealers, macos, cvs, xz-utils, backdoor, ssh, sshd, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 1st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8918</itunes:episode>
<itunes:subtitle>xz-utils Backdoor (CVE-2024-3094)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
xz-utils Backdoor (CVE-2024-3094)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8918.mp3" length="6709262" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8918.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8918</link>
<pubDate>Mon, 01 Apr 2024 02:00:02 GMT</pubDate>
<description><![CDATA[xz-utils Backdoor CVE-2024-3094<br/>
 <a href="https://www.openwall.com/lists/oss-security/2024/03/29/4">https://www.openwall.com/lists/oss-security/2024/03/29/4</a><br/>
 <a href="https://tukaani.org/xz-backdoor/">https://tukaani.org/xz-backdoor/</a><br/>
 <a href="https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27">https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27</a><br/>
Backdoor reverse analysis<br/>
 <a href="https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b">https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b</a><br/>
YARA Rule<br/>
 <a href="https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar">https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar</a><br/>
Social Engineering Attempts to Include Backdoor in Distros<br/>
 <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708</a><br/>
 <a href="https://news.ycombinator.com/item?id=39866275">https://news.ycombinator.com/item?id=39866275</a><br/>
Github Repo (now disabled)<br/>
 <a href="https://github.com/tukaani-project/xz">https://github.com/tukaani-project/xz</a><br/>
Statements from Distributions<br/>
 <a href="https://www.kali.org/blog/about-the-xz-backdoor/">https://www.kali.org/blog/about-the-xz-backdoor/</a><br/>
 <a href="https://archlinux.org/news/the-xz-package-has-been-backdoored/">https://archlinux.org/news/the-xz-package-has-been-backdoored/</a><br/>
 <a href="https://access.redhat.com/security/cve/CVE-2024-3094">https://access.redhat.com/security/cve/CVE-2024-3094</a><br/>
 <a href="https://bugs.gentoo.org/928134">https://bugs.gentoo.org/928134</a><br/>
 <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024</a><br/>
 <br/>
]]></description>
<itunes:duration>7:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8918" type="text/plain" language="en" />
<itunes:keywords>xz-utils, backdoor, xz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8916</itunes:episode>
<itunes:subtitle>JavaScript to AsyncRAT; TeamCity Patch; Okta Verify Patch; Google 0-Day Report
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JavaScript to AsyncRAT; TeamCity Patch; Okta Verify Patch; Google 0-Day Report
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8916.mp3" length="5016585" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8916.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8916</link>
<pubDate>Fri, 29 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[From JavaScript to AsyncRAT<br/>
 <a href="https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788">https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788</a><br/>
TeamCity Patches<br/>
 <a href="https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&version=2024.03">https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&version=2024.03</a><br/>
Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980<br/>
 <a href="https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/">https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/</a><br/>
Google Zero Day Report<br/>
 <a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf">https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8916" type="text/plain" language="en" />
<itunes:keywords>google, zero day, okta, teamcity, javascript, asyncrat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 28th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8914</itunes:episode>
<itunes:subtitle>OfBiz Scans; Wall-Escape; Apple MFA Bombing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OfBiz Scans; Wall-Escape; Apple MFA Bombing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8914.mp3" length="4792897" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8914.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8914</link>
<pubDate>Thu, 28 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Scans for Apache OfBiz<br/>
 <a href="https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784">https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784</a><br/>
Wall-Escape (CVE-2024-28085)<br/>
 <a href="https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt">https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt</a><br/>
Recent "MFA Bombing" Attacks Targeting Apple Users<br/>
 <a href="https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/">https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8914" type="text/plain" language="en" />
<itunes:keywords>apple, mfa, bombing, wall, escape, apache, ofbiz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 27th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8912</itunes:episode>
<itunes:subtitle>linux-pkgs.sh; Suspect NuGet Packages; QUIC vs UDP Loops; AI System Miners; ASUS to TheMoon;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
linux-pkgs.sh; Suspect NuGet Packages; QUIC vs UDP Loops; AI System Miners; ASUS to TheMoon;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8912.mp3" length="5185050" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8912.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8912</link>
<pubDate>Wed, 27 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[New tool: linux-pkgs.sh<br/>
 <a href="https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/">https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/</a><br/>
Suspicious NuGet package grabs data from industrial systems<br/>
 <a href="https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems">https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems</a><br/>
Preventing Cross Service UDP Loops in QUIC<br/>
 <a href="https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic">https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic</a><br/>
ShadowRay Attacks AI Workloads Actively Exploited in the Wild<br/>
 <a href="https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild">https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild</a><br/>
TheMoon Malware Infects 6,000 ASUS Routers in 72 Hours for Proxy Service<br/>
 <a href="https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/">https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8912" type="text/plain" language="en" />
<itunes:keywords>linux packages, themoon, asus, shadowray, quic, nuget, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8910</itunes:episode>
<itunes:subtitle>Tool Updates; Apple Updates; Fake Python Infrastructure; OpenVPN Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tool Updates; Apple Updates; Fake Python Infrastructure; OpenVPN Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8910.mp3" length="5375517" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8910.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8910</link>
<pubDate>Tue, 26 Mar 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Tool updates: le-hex-to-ip.py and sigs.py<br/>
 <a href="https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772">https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772</a><br/>
Apple Updates for MacOS, iOS/iPadOS, visionOS;<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778">https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778</a><br/>
Fake Python Infrastructure<br/>
 <a href="https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/">https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/</a><br/>
OpenVPN Update<br/>
 <a href="https://openvpn.net/community-downloads/">https://openvpn.net/community-downloads/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8910" type="text/plain" language="en" />
<itunes:keywords>openvpn, python, apple, macos, ios, ipados, visionos, le-hex-to-ip, sigs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 25th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8908</itunes:episode>
<itunes:subtitle>1768.py Experimental Mode; Loop DoS; Windows Server Crash Fix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
1768.py Experimental Mode; Loop DoS; Windows Server Crash Fix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8908.mp3" length="4943916" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8908.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8908</link>
<pubDate>Mon, 25 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[1768.py's Experimental Mode<br/>
 <a href="https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770">https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770</a><br/>
CISCP Advisory on Application-Layer Loop DoS<br/>
 <a href="https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit">https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit</a><br/>
Fixes for Windows Server LSASS Memory Leak<br/>
 <a href="https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update">https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8908" type="text/plain" language="en" />
<itunes:keywords>lsass, windows, server, ciscp, loop, dos, dns, ntp, tftp, 1768, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8906</itunes:episode>
<itunes:subtitle>Geofeed; Apple Updates and Bugs; GitHub AutoFix; Fortinet POC; new Ivanti Breakage;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Geofeed; Apple Updates and Bugs; GitHub AutoFix; Fortinet POC; new Ivanti Breakage;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8906.mp3" length="5686958" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8906.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8906</link>
<pubDate>Fri, 22 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Geofeed<br/>
 <a href="https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/">https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Apple Bug<br/>
 <a href="https://gofetch.fail/">https://gofetch.fail/</a><br/>
GitHub Copilot AutoFix<br/>
 <a href="https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/">https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/</a><br/>
Fortinet PoC<br/>
 <a href="https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/">https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/</a><br/>
Ivanti Standalone Sentry<br/>
 <a href="https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US">https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8906" type="text/plain" language="en" />
<itunes:keywords>geofeed, apple, apple bug, github, copilot, autofix, fortinet, ivanti, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 21st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8904</itunes:episode>
<itunes:subtitle>FortiOS Scans; Tax Scams; Abusing DHCP Administrators Group
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
FortiOS Scans; Tax Scams; Abusing DHCP Administrators Group
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8904.mp3" length="5293351" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8904.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8904</link>
<pubDate>Thu, 21 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability<br/>
 <a href="https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762">https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762</a><br/>
Microsoft Reminder: It is Tax Season (at least in the US)<br/>
 <a href="https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/">https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/</a><br/>
Abusing DHCP Administrators Group for Privilege Escalation in Windows Domains;<br/>
 <a href="https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains">https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8904" type="text/plain" language="en" />
<itunes:keywords>dhcp, administrators, windows, domains, tax season, irs, fortinet, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 20th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8902</itunes:episode>
<itunes:subtitle>Hunting Firewalls; Fortigate Exploit; IC3 Annual Report; macOS 14.4 Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hunting Firewalls; Fortigate Exploit; IC3 Annual Report; macOS 14.4 Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8902.mp3" length="4859729" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8902.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8902</link>
<pubDate>Wed, 20 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Attacker Hunting Firewalls<br/>
 <a href="https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758">https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758</a><br/>
Fortigate Vulnerability Exploit Available<br/>
 <a href="https://github.com/h4x0r-dz/CVE-2024-21762">https://github.com/h4x0r-dz/CVE-2024-21762</a><br/>
IC3 Annual Report 2023<br/>
 <a href="https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf">https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf</a><br/>
Issues with macOS 14.4 Update<br/>
 <a href="https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/">https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8902" type="text/plain" language="en" />
<itunes:keywords>macos, ic3, fortigate, firewalls, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8900</itunes:episode>
<itunes:subtitle>MSFT 1024 Bit RSA Keys; Real-Time Safe Browsing; Fortra FileCatalyst Vuln; Spring inSecurity; TrendNet Router Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT 1024 Bit RSA Keys; Real-Time Safe Browsing; Fortra FileCatalyst Vuln; Spring inSecurity; TrendNet Router Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8900.mp3" length="4835457" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8900.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8900</link>
<pubDate>Tue, 19 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft announced deprecation of 1024 bit RSA Keys<br/>
 <a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features</a><br/>
Chrome Real-Time Safe Browsing Protection<br/>
 <a href="https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/">https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/</a><br/>
Fortra FileCatalyst Vulnerability CVE-2024-25153<br/>
 <a href="https://www.fortra.com/security/advisory/fi-2024-002">https://www.fortra.com/security/advisory/fi-2024-002</a><br/>
Spring Security CVE-2024-22257<br/>
 <a href="https://spring.io/security/cve-2024-22257/">https://spring.io/security/cve-2024-22257/</a><br/>
TrendNet TWEW-827DRU Router Vulnerability CVE-2024-28353 CVE-2024-28354<br/>
 <a href="https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791">https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8900" type="text/plain" language="en" />
<itunes:keywords>trendnet, spring, security, chrome, safe browsing, safebrowsing, fortra, microsoft, tls, ssl, rsa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8898</itunes:episode>
<itunes:subtitle>5GHoul Update; Cobalt Strike Hex Encoded; ChatGPT related OAUTH Issues; Help Desk Attacks; CRL/OCSP Changes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
5GHoul Update; Cobalt Strike Hex Encoded; ChatGPT related OAUTH Issues; Help Desk Attacks; CRL/OCSP Changes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8898.mp3" length="5900024" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8898.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8898</link>
<pubDate>Mon, 18 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[5GHoul Revisted: Thress Months Later<br/>
 <a href="https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746">https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746</a><br/>
Obfuscated Hexadecimal Payload<br/>
 <a href="https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750">https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750</a><br/>
ChatGPT Related OAUTH Issues<br/>
 <a href="https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&utm_medium=reddit">https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&utm_medium=reddit</a><br/>
RedCanary Threat Detection Report<br/>
 <a href="https://redcanary.com/threat-detection-report/">https://redcanary.com/threat-detection-report/</a><br/>
CRL/OCSP Changes<br/>
 <a href="https://github.com/cabforum/servercert/blob/main/docs/BR.md">https://github.com/cabforum/servercert/blob/main/docs/BR.md</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8898" type="text/plain" language="en" />
<itunes:keywords>crl, ocsp, cab forum, revocation, certificates, redcanacy, help desks, oauth, 5GHOUL, hexadecimal, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 15th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8896</itunes:episode>
<itunes:subtitle>R2/IPFS Phishing; Fortinet Updates/new Vulns; Arcserve UDP PoC; Michael Holcomb ICS/PLC Security @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
R2/IPFS Phishing; Fortinet Updates/new Vulns; Arcserve UDP PoC; Michael Holcomb ICS/PLC Security @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8896.mp3" length="17631870" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8896.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8896</link>
<pubDate>Fri, 15 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Increase in the number of phishing messages pointing to IPFS and to R2 buckets<br/>
 <a href="https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744">https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744</a><br/>
Fortinet New Vulnerabilities<br/>
 <a href="https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/">https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/</a><br/>
Fortinet Updates<br/>
 <a href="https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/">https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/</a><br/>
Arcserve UDP Vulnerability and PoC<br/>
 <a href="https://www.tenable.com/security/research/tra-2024-07">https://www.tenable.com/security/research/tra-2024-07</a><br/>
Michael Holcomb: Mode Matters: Monitoring PLCs for Detecting Potential ICS/OT Incidents<br/>
 <a href="https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/">https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/</a><br/>
]]></description>
<itunes:duration>20:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8896" type="text/plain" language="en" />
<itunes:keywords>holcomb, sans.edu, ics, plc, mode, udp, arcserve, fortinet, horizon3, ipfs, r2, spam, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 14th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8894</itunes:episode>
<itunes:subtitle>ChatGPT Deobfuscation; Fortinet Patches; Adobe Patches; Kubernetes Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ChatGPT Deobfuscation; Fortinet Patches; Adobe Patches; Kubernetes Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8894.mp3" length="4897930" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8894.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8894</link>
<pubDate>Thu, 14 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Using ChatGPT to Deofuscate Malicious Scripts<br/>
 <a href="https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740">https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740</a><br/>
Critical Fortinet Vulnerabilities<br/>
 <a href="https://fortiguard.fortinet.com/psirt">https://fortiguard.fortinet.com/psirt</a><br/>
Adobe Security Bulletins<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Kubernetes Local Volumes Command Injection Vulnerability<br/>
 <a href="https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges">https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8894" type="text/plain" language="en" />
<itunes:keywords>kubernetes, adobe, fortinet, chatgpt, obfuscation, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8892</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; NVD Issues; ZOHO ManageEngine Vuln; Arube Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; NVD Issues; ZOHO ManageEngine Vuln; Arube Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8892.mp3" length="5055247" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8892.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8892</link>
<pubDate>Wed, 13 Mar 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday March 2024<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736</a><br/>
Death Knell of NVD<br/>
 <a href="https://resilientcyber.substack.com/p/death-knell-of-the-nvd">https://resilientcyber.substack.com/p/death-knell-of-the-nvd</a><br/>
Unrestricted file upload vulnerability in ManageEngine Desktop Central<br/>
 <a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central">https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central</a><br/>
Siemens Fire Protection System Updates<br/>
 <a href="https://cert-portal.siemens.com/productcert/html/ssa-225840.html">https://cert-portal.siemens.com/productcert/html/ssa-225840.html</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8892" type="text/plain" language="en" />
<itunes:keywords>siemens, manageengine, nvd, nist, microsoft, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8890</itunes:episode>
<itunes:subtitle>Leaked API Keys; Fake Calendly Links; SCCM Problems and Misconfiguration Manager @SpecterOps
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Leaked API Keys; Fake Calendly Links; SCCM Problems and Misconfiguration Manager @SpecterOps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8890.mp3" length="5586149" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8890.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8890</link>
<pubDate>Tue, 12 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[What happens when you accidentially leak your AWS API Keys<br/>
 <a href="https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730">https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730</a><br/>
How Crypto Imposters are using Calendly to infect Macs with Malware<br/>
 <a href="https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/">https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/</a><br/>
 <a href="https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/">https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/</a><br/>
Misconfiguration Manager: Overlooked and Overprivileged<br/>
 <a href="https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d">https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8890" type="text/plain" language="en" />
<itunes:keywords>misconfiguration, configuration manager, sccm, crypto, calendly, aws, api keys, github, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8888</itunes:episode>
<itunes:subtitle>Wordpress Brute Force Trick and CORS; Cisco VPN Client Vuln; Fortinet Exploits; pgAdmin; Font Vulnerabilities; QNAP;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wordpress Brute Force Trick and CORS; Cisco VPN Client Vuln; Fortinet Exploits; pgAdmin; Font Vulnerabilities; QNAP;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8888.mp3" length="6430576" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8888.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8888</link>
<pubDate>Mon, 11 Mar 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Attack Wrangles Thousands of Web Users into a Password Cracking Botnet<br/>
 <a href="https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet">https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet</a><br/>
Cisco VPN Client Vuln<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7</a><br/>
Fortinet Vulnerability Exploited<br/>
 <a href="https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls">https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls</a><br/>
pgAdmin Path Traversal<br/>
 <a href="https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/">https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/</a><br/>
Font Vulnerabilities<br/>
 <a href="https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/">https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/</a><br/>
 <br/>
QNAP Flaws<br/>
 <a href="https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/">https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/</a><br/>
]]></description>
<itunes:duration>7:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8888" type="text/plain" language="en" />
<itunes:keywords>qnap, fonts, canva, pgadmin, fortinet, cisco, javascript, cors, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8886</itunes:episode>
<itunes:subtitle>AWS vs. Azure Honeypots; Apple Patches; NSA/CISA Cloud Security Guides
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AWS vs. Azure Honeypots; Apple Patches; NSA/CISA Cloud Security Guides
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8886.mp3" length="4688309" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8886.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8886</link>
<pubDate>Fri, 08 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[AWS Deploymnet Risks - Configuration and Credential File Targeting<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722</a><br/>
Apple Updates<br/>
 <a href="https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726">https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726</a><br/>
NSA/CISA Secure Cloud Guides<br/>
 <a href="https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF">https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF</a><br/>
 <a href="https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF">https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF</a><br/>
 <a href="https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF">https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF</a><br/>
 <a href="https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF">https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF</a><br/>
 <a href="https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF">https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8886" type="text/plain" language="en" />
<itunes:keywords>nsa, cisa, cloud, apple, honeypot, aws, azure, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 7th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8884</itunes:episode>
<itunes:subtitle>#QUIC Scanning; Google Chrome Update; YARN Miner; Teamcity Exploited; #quicmap
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#QUIC Scanning; Google Chrome Update; YARN Miner; Teamcity Exploited; #quicmap
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8884.mp3" length="5439389" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8884.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8884</link>
<pubDate>Thu, 07 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Scanning and Abusing the QUIC Protocol<br/>
 <a href="https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720">https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html</a><br/>
Spinning YARN<br/>
 <a href="https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/">https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/</a><br/>
Teamcity Exploited<br/>
 <a href="https://twitter.com/leak_ix/status/1765460190621581347">https://twitter.com/leak_ix/status/1765460190621581347</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8884" type="text/plain" language="en" />
<itunes:keywords>teamcity, yarn, hadoop, chrome, quic, quicmap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8882</itunes:episode>
<itunes:subtitle>iOS Updates; Perimeter Security Survival Time; #QEMU Tunnel; #VMware Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iOS Updates; Perimeter Security Survival Time; #QEMU Tunnel; #VMware Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8882.mp3" length="5909665" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8882.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8882</link>
<pubDate>Wed, 06 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[iOS/iPadOS Updates with Zero Day Fixes<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716">https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716</a><br/>
Why Your Firewall Will Kill You<br/>
 <a href="https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/">https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/</a><br/>
QEMU Tunnel<br/>
 <a href="https://securelist.com/network-tunneling-with-qemu/111803/">https://securelist.com/network-tunneling-with-qemu/111803/</a><br/>
VMware Vulnerabilities Patched<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2024-0006.html">https://www.vmware.com/security/advisories/VMSA-2024-0006.html</a><br/>
]]></description>
<itunes:duration>6:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8882" type="text/plain" language="en" />
<itunes:keywords>vmware, qemu, tunnel, firewall, permiter, security, ios, ipados, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8880</itunes:episode>
<itunes:subtitle>TAPs at Home; TeamCity Vuln; GitHub Push Protections; Android Update; Linksys Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TAPs at Home; TeamCity Vuln; GitHub Push Protections; Android Update; Linksys Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8880.mp3" length="5071737" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8880.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8880</link>
<pubDate>Tue, 05 Mar 2024 02:15:05 GMT</pubDate>
<description><![CDATA[Capturing DShield Packets with a LAN Tap<br/>
 <a href="https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708">https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708</a><br/>
Additional Critical Security Issues Affecting Teamcity<br/>
 <a href="https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/">https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/</a><br/>
GitHub Push Protection Now On By Default<br/>
 <a href="https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/">https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/</a><br/>
Android Updates<br/>
 <a href="https://source.android.com/docs/security/bulletin/2024-03-01">https://source.android.com/docs/security/bulletin/2024-03-01</a><br/>
Linksys E-2000 Vulnerablity<br/>
 <a href="https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8">https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8880" type="text/plain" language="en" />
<itunes:keywords>linksys, android, github, tap, network, teamcity, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8878</itunes:episode>
<itunes:subtitle>Old Confluence Vuln Scan; Google CSP Difficulties;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Old Confluence Vuln Scan; Google CSP Difficulties;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8878.mp3" length="4900425" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8878.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8878</link>
<pubDate>Mon, 04 Mar 2024 02:00:05 GMT</pubDate>
<description><![CDATA[Scanning for Confluence CVE-2022-26134<br/>
 <a href="https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704">https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704</a><br/>
Exploiting CSP Wildcards for Google Domains<br/>
 <a href="https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google">https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google</a><br/>
Silver SAML: Golden SAML in the Cloud<br/>
 <a href="https://www.semperis.com/blog/meet-silver-saml/">https://www.semperis.com/blog/meet-silver-saml/</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8878" type="text/plain" language="en" />
<itunes:keywords>saml, csp, confluence, cve-2022-26134, cloud, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 1st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8876</itunes:episode>
<itunes:subtitle>DarkGate Update; Ivanti IR; Github Repo Flood; NoName Doorbell Cameras; @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DarkGate Update; Ivanti IR; Github Repo Flood; NoName Doorbell Cameras; @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8876.mp3" length="5730506" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8876.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8876</link>
<pubDate>Fri, 01 Mar 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Dissecting DarkGate: Module Malware Delivery and Persistence as a Service<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700</a><br/>
Ivanti Incident Response Update<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b">https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b</a><br/>
Github Flooded with Infected Repos<br/>
 <a href="https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack">https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack</a><br/>
Security Flaws in NoName Doorbell Cameras<br/>
 <a href="https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/">https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8876" type="text/plain" language="en" />
<itunes:keywords>doorbells, github, repos, flood, ivanti, darkgate, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8874</itunes:episode>
<itunes:subtitle>Odd Confluence Scan; ALPH/Blackcat Healthcare Attacks; GlobalBlock Released
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd Confluence Scan; ALPH/Blackcat Healthcare Attacks; GlobalBlock Released
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8874.mp3" length="5032633" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8874.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8874</link>
<pubDate>Thu, 29 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Exploit Attempts for Unknown Password Reset Vulnerability<br/>
 <a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698</a><br/>
StopRansomware: Updated ALPHV Blackcat Advisory<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a</a><br/>
GlobalBlock Service To Prevent Trademark abuse<br/>
 <a href="https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/">https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8874" type="text/plain" language="en" />
<itunes:keywords>GlobalBlock, trademark, registrars, stopransomware, alphv, healthcare, blackcat, altassian, confluence, password, reset, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 28th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8872</itunes:episode>
<itunes:subtitle>Ubiquity Takedown Aftermath; New Govt Botnet Advisory; SVR Cloud Attacks; Hugging Face ML Models
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ubiquity Takedown Aftermath; New Govt Botnet Advisory; SVR Cloud Attacks; Hugging Face ML Models
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8872.mp3" length="5530850" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8872.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8872</link>
<pubDate>Wed, 28 Feb 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Take Downs and the Rest of Us: Do they matter?<br/>
 <a href="https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694">https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694</a><br/>
Joint Cybersecurity Advisory<br/>
 <a href="https://www.ic3.gov/Media/News/2024/240227.pdf">https://www.ic3.gov/Media/News/2024/240227.pdf</a><br/>
SVR Cyber Actors Adapt Tactics for Initial Cloud Access<br/>
 <a href="https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access">https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access</a><br/>
Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor<br/>
 <a href="https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/">https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8872" type="text/plain" language="en" />
<itunes:keywords>Machine learning, ml, backdoor, hugging face, svr, cloud, advisory, routers, ubiquity, take downs, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 27th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8870</itunes:episode>
<itunes:subtitle>VirusTotal API and Honeypots; WPA2 Auth Bypass; Subdomain Spam;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VirusTotal API and Honeypots; WPA2 Auth Bypass; Subdomain Spam;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8870.mp3" length="5642700" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8870.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8870</link>
<pubDate>Tue, 27 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot<br/>
 <a href="https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688">https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688</a><br/>
New WiFi Authentication Vulnerabilities Discovered<br/>
 <a href="https://www.top10vpn.com/research/wifi-vulnerabilities/">https://www.top10vpn.com/research/wifi-vulnerabilities/</a><br/>
Subdomain Takeover Spam<br/>
 <a href="https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935">https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8870" type="text/plain" language="en" />
<itunes:keywords>subdomain, spam, malspam, wifi, wpa, authentication, vulnerability, honeypots, virustotal, cookoo, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8868</itunes:episode>
<itunes:subtitle>Magellan Scans; Mouse Sandbox Check; Salesforce Apex Vuln; IBM ODM PoC; Linux kTLS Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Magellan Scans; Mouse Sandbox Check; Salesforce Apex Vuln; IBM ODM PoC; Linux kTLS Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8868.mp3" length="5176029" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8868.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8868</link>
<pubDate>Mon, 26 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Update MGLNDD * Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/">https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/</a><br/>
Simple Anti-Sandbox Technique: Where's the Mouse<br/>
 <a href="https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684">https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684</a><br/>
Security Vulnerabilities in Apex Code Could Leak Salesforce Data<br/>
 <a href="https://www.varonis.com/blog/apex-code-vulnerabilities">https://www.varonis.com/blog/apex-code-vulnerabilities</a><br/>
IBM Operation Decision Manager Exploit CVE-2024-22319 CVE-2024-22320<br/>
 <a href="https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/">https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/</a><br/>
Linux Kernel TLS Vulnerability CVE-2024-26582<br/>
 <a href="https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/">https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8868" type="text/plain" language="en" />
<itunes:keywords>linux, tls, ibm, odm, exploit, vulnerability, apex, salesforce, mouse, sandbox, mglndd, ripe, atlas, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8866</itunes:episode>
<itunes:subtitle>Friend of Foe; AT&amp;T Wireless Outage; LockBit Uses Screenconnect; SSH Snake
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Friend of Foe; AT&amp;T Wireless Outage; LockBit Uses Screenconnect; SSH Snake
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8866.mp3" length="5216417" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8866.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8866</link>
<pubDate>Fri, 23 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Friend, Foe or Something In Between<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670</a><br/>
Large AT&T Wireless Network Outage <br/>
 <a href="https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680">https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680</a><br/>
Connect Wise Screenconnect Userd by LockBit<br/>
 <a href="https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/">https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/</a><br/>
SSH Snake Abused in the Wild<br/>
 <a href="https://github.com/MegaManSec/SSH-Snake">https://github.com/MegaManSec/SSH-Snake</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8866" type="text/plain" language="en" />
<itunes:keywords>ssh snake, ssh, connectwise, screenconnect, atT, modbus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8864</itunes:episode>
<itunes:subtitle>Archive.org Phish; ScreenConnect PoC; Post Quantum iMessage;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Archive.org Phish; ScreenConnect PoC; Post Quantum iMessage;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8864.mp3" length="5789777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8864.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8864</link>
<pubDate>Thu, 22 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Phishing Pages Hosted on Archive.org<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/">https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/</a><br/>
ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)<br/>
 <a href="https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass">https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass</a><br/>
iMessage with PQ3<br/>
 <a href="https://security.apple.com/blog/imessage-pq3/">https://security.apple.com/blog/imessage-pq3/</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8864" type="text/plain" language="en" />
<itunes:keywords>imessage, pq3, screenconnect, archive, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 21st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8862</itunes:episode>
<itunes:subtitle>Dynamic Sandbox Detection; Screenconnect Vulns; VMWare EAP; VoltSchemer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dynamic Sandbox Detection; Screenconnect Vulns; VMWare EAP; VoltSchemer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8862.mp3" length="5639353" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8862.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8862</link>
<pubDate>Wed, 21 Feb 2024 02:45:05 GMT</pubDate>
<description><![CDATA[Python InfoStealer Wtih Dynamic Sandbox Detection<br/>
 <a href="https://isc.sans.edu/diary/Python%20InfoStealer%20With%20Dynamic%20Sandbox%20Detection/30668">https://isc.sans.edu/diary/Python%20InfoStealer%20With%20Dynamic%20Sandbox%20Detection/30668</a><br/>
Connectwise Screenconnect Vulnerabilities<br/>
 <a href="https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8">https://www.connectwise.com/company/trust/security-bulletins/connectwise-screenconnect-23.9.8</a><br/>
Remove VMWare Enhanced Authentication Plugin (EAP)  VE-2024-22245 CVE-2024-22250<br/>
 <a href="https://kb.vmware.com/s/article/96442">https://kb.vmware.com/s/article/96442</a><br/>
Voltage Noise to Manipulate Wireless Chargers<br/>
 <a href="https://arxiv.org/pdf/2402.11423.pdf">https://arxiv.org/pdf/2402.11423.pdf</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8862" type="text/plain" language="en" />
<itunes:keywords>voltage, voltschemer, qi, wireless charging, vmware, screenconnect, sandbox, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 20th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8860</itunes:episode>
<itunes:subtitle>Mirai Again; KeyTrap PoC; AI File Type Recon; Unsynced Clock Issue
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mirai Again; KeyTrap PoC; AI File Type Recon; Unsynced Clock Issue
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8860.mp3" length="4962521" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8860.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8860</link>
<pubDate>Tue, 20 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Old Mirai New Exploits<br/>
 <a href="https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658">https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658</a><br/>
KeyTrap PoC Exploit<br/>
 <a href="https://github.com/knqyf263/CVE-2023-50387">https://github.com/knqyf263/CVE-2023-50387</a><br/>
Google Open Sources Magika File ID System<br/>
 <a href="https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html">https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html</a><br/>
Exploiting Unsynchronised Clocks<br/>
 <a href="https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks">https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8860" type="text/plain" language="en" />
<itunes:keywords>clocks, ntp, caching, google, magika, ai, libmagic, file id, keytrap, poc, mirai, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8858</itunes:episode>
<itunes:subtitle>SolarWinds Patch; Chrome CORS Extension; Biometrics Theft
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SolarWinds Patch; Chrome CORS Extension; Biometrics Theft
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8858.mp3" length="6726175" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8858.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8858</link>
<pubDate>Mon, 19 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[SolarWinds Security Advisories<br/>
 <a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm</a><br/>
Google Chrome Adds Private Network Checks<br/>
 <a href="https://chromestatus.com/feature/4869685172764672">https://chromestatus.com/feature/4869685172764672</a><br/>
Gold Factory iOS Trojan<br/>
 <a href="https://www.group-ib.com/blog/goldfactory-ios-trojan/">https://www.group-ib.com/blog/goldfactory-ios-trojan/</a><br/>
]]></description>
<itunes:duration>7:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8858" type="text/plain" language="en" />
<itunes:keywords>goldfactory, ios, trojan, chrome, network, cors, solarwinds, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8856</itunes:episode>
<itunes:subtitle>AWS SNS Smishing; Linux CVEs; Pulse Secure Issues; Rogue Ethernet Switches; @sans_edu @sansinstitute
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AWS SNS Smishing; Linux CVEs; Pulse Secure Issues; Rogue Ethernet Switches; @sans_edu @sansinstitute
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8856.mp3" length="11383737" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8856.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8856</link>
<pubDate>Fri, 16 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[USPS Anchors Snowballing Smishing Campaigns<br/>
 <a href="https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/">https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/</a><br/>
Linux Issuing CVEs<br/>
 <a href="http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/">http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/</a><br/>
Analyzing Pulse Secure Firmware and Bypassing Integrity Checking<br/>
 <a href="https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/">https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/</a><br/>
Jennifer Walker: Detecting Rogue Ethernet Switches Using Layer 1 Techniques<br/>
 <a href="https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/">https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/</a><br/>
]]></description>
<itunes:duration>13:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8856" type="text/plain" language="en" />
<itunes:keywords>jennifer walker, switches, ethernet, ivanty, linux, cves, usps, phishing, smishing, sns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 15th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8854</itunes:episode>
<itunes:subtitle>Troubleshooting Honeypots; Dangerous Suggestions; MonikerLink Bug; Adobe and AMD patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Troubleshooting Honeypots; Dangerous Suggestions; MonikerLink Bug; Adobe and AMD patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8854.mp3" length="5119464" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8854.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8854</link>
<pubDate>Thu, 15 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting<br/>
 <a href="https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648">https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648</a><br/>
Snap Trap: The Hidden Dangers within Ubuntu's Package Suggestion System<br/>
 <a href="https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/">https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/</a><br/>
The Risks of the Monikerlink Bug in Microsoft Outlook<br/>
 <a href="https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/">https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
AMD Patches<br/>
 <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html">https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8854" type="text/plain" language="en" />
<itunes:keywords>monikerlink, outlook, smb, snap trap, troubleshooting, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 14th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8852</itunes:episode>
<itunes:subtitle>Microsoft Patches; DNSSEC DoS Vuln; Zoom and QNAP Vulnerablities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; DNSSEC DoS Vuln; Zoom and QNAP Vulnerablities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8852.mp3" length="5684301" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8852.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8852</link>
<pubDate>Wed, 14 Feb 2024 03:20:05 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646">https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646</a><br/>
DNSSEC DoS Vulnerability CVE-2023-50387<br/>
 <a href="https://www.presseportal.de/pm/173495/5713546">https://www.presseportal.de/pm/173495/5713546</a><br/>
Zoom Desktop Client Vuln<br/>
 <a href="https://www.zoom.com/en/trust/security-bulletin">https://www.zoom.com/en/trust/security-bulletin</a><br/>
QNAP Vulnerablity<br/>
 <a href="https://www.qnap.com/de-de/security-advisory/qsa-23-57">https://www.qnap.com/de-de/security-advisory/qsa-23-57</a><br/>
 <a href="https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/">https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8852" type="text/plain" language="en" />
<itunes:keywords>qnap, zoom, dnssec, dos, bind, unbound, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 13th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8850</itunes:episode>
<itunes:subtitle>Mirai vs BYTEVALUE; Targeted Cloud Attack; Repo Security; Postgresql Vuln; Comma vs MSFT Defender
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mirai vs BYTEVALUE; Targeted Cloud Attack; Repo Security; Postgresql Vuln; Comma vs MSFT Defender
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8850.mp3" length="4970157" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8850.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8850</link>
<pubDate>Tue, 13 Feb 2024 03:00:05 GMT</pubDate>
<description><![CDATA[Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai<br/>
 <a href="https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642">https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642</a><br/>
Senior Executives Targeted in Ongoing Azure Account Takeover<br/>
 <a href="https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover">https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover</a><br/>
CISA Parners With OpenSSF To Secure Software Repositories<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package">https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package</a><br/>
PostgreSQL Vulnerability<br/>
 <a href="https://www.postgresql.org/support/security/CVE-2024-0985/">https://www.postgresql.org/support/security/CVE-2024-0985/</a><br/>
Microsoft Defender Bypass via Comma<br/>
 <a href="https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt">https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8850" type="text/plain" language="en" />
<itunes:keywords>microsoft, defender, comma, postgresql, cisa, openssf, repository, mirai, bytevalue, azure, cloud, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8848</itunes:episode>
<itunes:subtitle>Obfuscated MSIX Powershell; Too Many Honeypots; ClamAV Vuln; ExpressVPN Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated MSIX Powershell; Too Many Honeypots; ClamAV Vuln; ExpressVPN Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8848.mp3" length="5210026" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8848.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8848</link>
<pubDate>Mon, 12 Feb 2024 02:25:05 GMT</pubDate>
<description><![CDATA[MSIX With Heaviliy Obfuscated PowerShell Script<br/>
 <a href="https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636">https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636</a><br/>
Too Many Honeypots<br/>
 <a href="https://vulncheck.com/blog/too-many-honeypots">https://vulncheck.com/blog/too-many-honeypots</a><br/>
ClamAV Command Injection Vulnerability CVE-2024-20328<br/>
 <a href="https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/">https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/</a><br/>
ExpressVPN DNS Leaks<br/>
 <a href="https://www.expressvpn.com/blog/windows-app-dns-requests/">https://www.expressvpn.com/blog/windows-app-dns-requests/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8848" type="text/plain" language="en" />
<itunes:keywords>expressvpn, dns, leak, clamav, honeypots, msix, powershell, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8846</itunes:episode>
<itunes:subtitle>Podcast Aniversary; Keylogger MP3 Player; Fake LastPass; Ivanti Vuln; @sans_edu @SANSInstitute
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Podcast Aniversary; Keylogger MP3 Player; Fake LastPass; Ivanti Vuln; @sans_edu @SANSInstitute
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8846.mp3" length="5146976" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8846.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8846</link>
<pubDate>Fri, 09 Feb 2024 03:10:06 GMT</pubDate>
<description><![CDATA[A Python MP3 Player With Builtin Keylogger Capability<br/>
 <a href="https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632">https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632</a><br/>
Fake LastPass App in Apple App Store<br/>
 <a href="https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/">https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/</a><br/>
Ivanti XXE Vulnerability<br/>
 <a href="https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure">https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure</a><br/>
FortiOS sslvpnd vulnerability<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-24-015">https://www.fortiguard.com/psirt/FG-IR-24-015</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8846" type="text/plain" language="en" />
<itunes:keywords>fortios, sslvpnd, ivanti, xxe, lastpass, python, mp3, player, app store, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8844</itunes:episode>
<itunes:subtitle>Possible Balena Scans; Critical shim vulnerability; Volt Typhoon Living of the Land
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Possible Balena Scans; Critical shim vulnerability; Volt Typhoon Living of the Land
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8844.mp3" length="4919966" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8844.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8844</link>
<pubDate>Thu, 08 Feb 2024 02:55:05 GMT</pubDate>
<description><![CDATA[Anybody knows what this URL is about? Maybe Balena API request?<br/>
 <a href="https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/">https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/</a><br/>
Critical shim vulnerability and patch<br/>
 <a href="https://github.com/rhboot/shim/releases/tag/15.8">https://github.com/rhboot/shim/releases/tag/15.8</a><br/>
Volt Typhoon Lessons Learned<br/>
 <a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques">https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8844" type="text/plain" language="en" />
<itunes:keywords>volt, typhoon, shim, bios, uefi, url, balena, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 7th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8842</itunes:episode>
<itunes:subtitle>40 Years of Viruses; Infected Toothbrushes; TeamCity Vuln; Resume Looters; Malicious Facebook Job Ads
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
40 Years of Viruses; Infected Toothbrushes; TeamCity Vuln; Resume Looters; Malicious Facebook Job Ads
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8842.mp3" length="5852617" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8842.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8842</link>
<pubDate>Wed, 07 Feb 2024 03:05:05 GMT</pubDate>
<description><![CDATA[Computer viruses are celebrating their 40th birthday (well, 54th, really)<br/>
 <a href="https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624">https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624</a><br/>
Three million malware-infected smart toothbrushes used in Swiss DDoS attacks<br/>
 <a href="https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages">https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages</a><br/>
Critical Security Issue Affecting TeamCity On-Premises CVE-2024-23917<br/>
 <a href="https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/">https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/</a><br/>
Resume Looters<br/>
 <a href="https://www.group-ib.com/blog/resumelooters/">https://www.group-ib.com/blog/resumelooters/</a><br/>
Facebook Advertising Spreads Novel Malware Variant<br/>
 <a href="https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf">https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8842" type="text/plain" language="en" />
<itunes:keywords>facebook, advertising, malware, resume, teamcity, toothbrushes, ddos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 6th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8840</itunes:episode>
<itunes:subtitle>Time to Spam; Anydesk Update; Latest Ivanti Exploit; Deepfake Exploits;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Time to Spam; Anydesk Update; Latest Ivanti Exploit; Deepfake Exploits;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8840.mp3" length="5269053" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8840.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8840</link>
<pubDate>Tue, 06 Feb 2024 02:40:07 GMT</pubDate>
<description><![CDATA[Public Information and Email Spam<br/>
 <a href="https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/">https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/</a><br/>
Anydesk Update<br/>
 <a href="https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/">https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/</a><br/>
 <a href="https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf">https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf</a><br/>
Ivanti POC For CVE-2024-21893<br/>
 <a href="https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis">https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis</a><br/>
Deepfake Exploits<br/>
 <a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage">https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage</a><br/>
 <a href="https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/">https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/</a><br/>
 <br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8840" type="text/plain" language="en" />
<itunes:keywords>deepfake, ivanti, poc, cve-2024-21893, ssrf, anydesk, email, spam, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8838</itunes:episode>
<itunes:subtitle>DShield Honeypot Dashboard; Anydesk Breach; Docker Leaks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DShield Honeypot Dashboard; Anydesk Breach; Docker Leaks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8838.mp3" length="5138541" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8838.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8838</link>
<pubDate>Mon, 05 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[DShield Sensor Log Collection with Elasticsearch<br/>
 <a href="https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/">https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/</a><br/>
Anydesk Breach<br/>
 <a href="https://anydesk.com/en/public-statement">https://anydesk.com/en/public-statement</a><br/>
Leaky Vessels<br/>
 <a href="https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/">https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8838" type="text/plain" language="en" />
<itunes:keywords>docker, dshield, elastic, kibana, anydesk, leaky vessels, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 2nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8836</itunes:episode>
<itunes:subtitle>What is a TLD; CISA Ivanti Policy; Cloudflare Breach; Vision Pro Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
What is a TLD; CISA Ivanti Policy; Cloudflare Breach; Vision Pro Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8836.mp3" length="6224951" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8836.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8836</link>
<pubDate>Fri, 02 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[What is a Top Level Domain<br/>
 <a href="https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/">https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/</a><br/>
Updated CISA Ivanti Policy<br/>
 <a href="https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure">https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure</a><br/>
Cloudflare Publishes Breach Details<br/>
 <a href="https://blog.cloudflare.com/thanksgiving-2023-security-incident">https://blog.cloudflare.com/thanksgiving-2023-security-incident</a><br/>
Vision Pro Update<br/>
 <a href="https://support.apple.com/en-us/HT214070">https://support.apple.com/en-us/HT214070</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8836" type="text/plain" language="en" />
<itunes:keywords>vision pro, cisa, ivanti, cloudflare, okta, tld, domain, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 1st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8834</itunes:episode>
<itunes:subtitle>Internal Domains/TLDs; Ivanti Patches and Vulns; glibc syslog vuln; modsecurity vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Internal Domains/TLDs; Ivanti Patches and Vulns; glibc syslog vuln; modsecurity vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8834.mp3" length="5244505" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8834.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8834</link>
<pubDate>Thu, 01 Feb 2024 02:00:02 GMT</pubDate>
<description><![CDATA[The Fun and Dangers of Top Level Domains (TLDs)<br/>
 <a href="https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608">https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608</a><br/>
Ivanti Releases Patches and New Vulnerabilities<br/>
 <a href="https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US">https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US</a><br/>
glibc syslog() vulnerablity<br/>
 <a href="https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt">https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt</a><br/>
modsecurity WAF bypass<br/>
 <a href="https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30">https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8834" type="text/plain" language="en" />
<itunes:keywords>modsecurity, waf, glibc, syslog, ivanti, tld, internal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 31st, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8832</itunes:episode>
<itunes:subtitle>Detecting Honeypots; TLD for Internal Use; Juniper Patches Patching; ChatGPT Leaks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Detecting Honeypots; TLD for Internal Use; Juniper Patches Patching; ChatGPT Leaks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8832.mp3" length="6053586" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8832.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8832</link>
<pubDate>Wed, 31 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[What did I say to make you stop talking to me<br/>
 <a href="https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604">https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604</a><br/>
Identification of a top-level domain for private use<br/>
 <a href="https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf">https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf</a><br/>
Juniper Patches Patching<br/>
 <a href="https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US">https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US</a><br/>
 <a href="https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/">https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/</a><br/>
Chat GPT Leaking Conversations Again<br/>
 <a href="https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/">https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8832" type="text/plain" language="en" />
<itunes:keywords>chatgpt, juniper, patches, tld, internal, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 30th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8830</itunes:episode>
<itunes:subtitle>Another Confluence Scan; PyPI Infostealer; Linux IPv6 Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Another Confluence Scan; PyPI Infostealer; Linux IPv6 Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8830.mp3" length="5081516" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8830.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8830</link>
<pubDate>Tue, 30 Jan 2024 02:15:05 GMT</pubDate>
<description><![CDATA[Exploit Flare Up Against Older Atlassian Confluence Vulnerability<br/>
 <a href="https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600">https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600</a><br/>
Malicious Python Packages install Infostealer<br/>
 <a href="https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi">https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi</a><br/>
Linux ICMPv6 Router Adv. RCE<br/>
 <a href="https://access.redhat.com/security/cve/cve-2023-6200">https://access.redhat.com/security/cve/cve-2023-6200</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8830" type="text/plain" language="en" />
<itunes:keywords>linux, icmpv6, router adv, RCE, python, atlassian, confluence, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 29th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8828</itunes:episode>
<itunes:subtitle>Batch Comments; .box TLD abuse; Jenkins CVE-2024-23897 PoC; Malicious Chinese Google Ads
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Batch Comments; .box TLD abuse; Jenkins CVE-2024-23897 PoC; Malicious Chinese Google Ads
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8828.mp3" length="6210829" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8828.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8828</link>
<pubDate>Mon, 29 Jan 2024 02:15:04 GMT</pubDate>
<description><![CDATA[A Batch File With Multiple Payloads<br/>
 <a href="https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592">https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592</a><br/>
fritz.box domain used to advertise NFTs<br/>
 <a href="https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html">https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html</a><br/>
Jenkins CVE-2024-23897 PoC<br/>
 <a href="https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263">https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263</a><br/>
Malicious Google Ads Target Chinese Users<br/>
 <a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users</a><br/>
]]></description>
<itunes:duration>7:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8828" type="text/plain" language="en" />
<itunes:keywords>google, ads, malware, china, jenkins, fritz.box, batch file, payloads, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 26th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8826</itunes:episode>
<itunes:subtitle>Facebook AdsManager Cookie Theft; iOS Push Notification Abuse; Mobile Spy Ads;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Facebook AdsManager Cookie Theft; iOS Push Notification Abuse; Mobile Spy Ads;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8826.mp3" length="5732502" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8826.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8826</link>
<pubDate>Fri, 26 Jan 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Fecebook AdsManager Targeted by a Python Infostealer<br/>
 <a href="https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590">https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590</a><br/>
Privacy Concerns about Apple Push Notifications<br/>
 <a href="https://twitter.com/mysk_co/status/1750502700112916504">https://twitter.com/mysk_co/status/1750502700112916504</a><br/>
 <a href="https://www.youtube.com/watch?v=4ZPTjGG9t7s">https://www.youtube.com/watch?v=4ZPTjGG9t7s</a><br/>
Inside a Global Phone Spy Tool Monitoring Billions<br/>
 <a href="https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/">https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8826" type="text/plain" language="en" />
<itunes:keywords>patternz, phone, mobile, spy, tracking, ios, apple, push notifications, facebook adsmanager, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 25th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8824</itunes:episode>
<itunes:subtitle>Bad Infosec UI; Google Sys:All Loophole; Automotive Pwn2Own; Android Bluetooth Exploit; @sans_edu Deans List
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bad Infosec UI; Google Sys:All Loophole; Automotive Pwn2Own; Android Bluetooth Exploit; @sans_edu Deans List
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8824.mp3" length="4920879" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8824.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8824</link>
<pubDate>Thu, 25 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[How Bad User Interfaces Make Security Tools Harmful<br/>
 <a href="https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586">https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586</a><br/>
Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production<br/>
 <a href="https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/">https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/</a><br/>
Automotive Pwn2Own<br/>
 <a href="https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule">https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule</a><br/>
Android Keystroke Injection Vulnerability Exploit<br/>
 <a href="https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/">https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/</a><br/>
CVE-2024-0769 D-Link DIR-859<br/>
 <a href="https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/">https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/</a><br/>
SANS.edu Dean's List<br/>
 <a href="https://www.sans.edu/students/awards">https://www.sans.edu/students/awards</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8824" type="text/plain" language="en" />
<itunes:keywords>sans.edu, deans list, d-link, android, keystroke, pwn2own, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 24th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8822</itunes:episode>
<itunes:subtitle>Atlassian Attacks; GoAnywhere PoC; Baracuda WAF Update; SSH Key Exfil via GitHub
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Atlassian Attacks; GoAnywhere PoC; Baracuda WAF Update; SSH Key Exfil via GitHub
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8822.mp3" length="5093324" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8822.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8822</link>
<pubDate>Wed, 24 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Update on Atlassian Exploit Activity<br/>
 <a href="https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/">https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/</a><br/>
POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204<br/>
 <a href="https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/">https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/</a><br/>
Baracuda Web Application Firewall<br/>
 <a href="https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/">https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/</a><br/>
GitGot: GitHub leveraged by cybercriminals to store stolen data<br/>
 <a href="https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data">https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8822" type="text/plain" language="en" />
<itunes:keywords>gitgot, github, baracuda, firewall, Forta, goanywhere, mft, atlassian, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 23rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8820</itunes:episode>
<itunes:subtitle>Apple Updates; Atlassian Confluence Exploited; Ivanti Mitigation Problems; Czech IPv4 Shutdown Date
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Atlassian Confluence Exploited; Ivanti Mitigation Problems; Czech IPv4 Shutdown Date
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8820.mp3" length="6420665" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8820.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8820</link>
<pubDate>Tue, 23 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Updates Everything<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/">https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/</a><br/>
Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527<br/>
 <a href="https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/">https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/</a><br/>
Updated Ivanti Mitigation Advise<br/>
 <a href="https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US">https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US</a><br/>
Czech Republic Sets IPv4 Shutdown date<br/>
 <a href="https://konecipv4.cz/en/">https://konecipv4.cz/en/</a><br/>
]]></description>
<itunes:duration>7:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8820" type="text/plain" language="en" />
<itunes:keywords>czech, ivanti, atlassian, ipv6, confluence, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 22nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8818</itunes:episode>
<itunes:subtitle>macOS Malware; Microsoft Breach; Juniper 0-Day Details; Brave 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
macOS Malware; Microsoft Breach; Juniper 0-Day Details; Brave 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8818.mp3" length="5867345" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8818.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8818</link>
<pubDate>Mon, 22 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[macOS Python Script Replacing Walling Applications with Rogue Apps<br/>
 <a href="https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572">https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572</a><br/>
Microsoft Breach<br/>
 <a href="https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/">https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/</a><br/>
Juniper Vulnerabilities<br/>
 <a href="https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/">https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/</a><br/>
Brave Removing Strict Fingerprint Mode<br/>
 <a href="https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/">https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8818" type="text/plain" language="en" />
<itunes:keywords>macos, brave, microsoft, python, apps, juniper, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 19th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8816</itunes:episode>
<itunes:subtitle>Ivanti Updates; Postgres Attacks; Outlook Vuln PoC;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ivanti Updates; Postgres Attacks; Outlook Vuln PoC;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8816.mp3" length="5885177" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8816.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8816</link>
<pubDate>Fri, 19 Jan 2024 02:00:01 GMT</pubDate>
<description><![CDATA[More Scans for Ivanti Connect "Secure" VPN. Exploits Public<br/>
 <a href="https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568">https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568</a><br/>
Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082<br/>
 <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br/>
Attacks against Exposed Databases<br/>
 <a href="https://twitter.com/fasterthanlime/status/1741935393413402739">https://twitter.com/fasterthanlime/status/1741935393413402739</a><br/>
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes<br/>
 <a href="https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes">https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes</a><br/>
]]></description>
<itunes:duration>6:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8816" type="text/plain" language="en" />
<itunes:keywords>outlook, postgres, ivanti, vpn, mobileiron, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 18th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8814</itunes:episode>
<itunes:subtitle>Numbers and Password; Detecting iOS Malware; Androxgh0st Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Numbers and Password; Detecting iOS Malware; Androxgh0st Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8814.mp3" length="5982354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8814.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8814</link>
<pubDate>Thu, 18 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Number Usage in Passwords<br/>
 <a href="https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540">https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540</a><br/>
A Lightweight Method to Detect Potential iOS Malware<br/>
 <a href="https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/">https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/</a><br/>
CISA and FBI Release Known IOCs Associated with Androxgh0st Malware<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware">https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8814" type="text/plain" language="en" />
<itunes:keywords>passwords, numbers, ios malware, androxgh0st, reboot.log, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 17th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8812</itunes:episode>
<itunes:subtitle>Ivanti Exploited; Citrix 0-Day; Confluence Patch; Mac Infostealer; Chrome 0-day; GitHub Key Rotation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ivanti Exploited; Citrix 0-Day; Confluence Patch; Mac Infostealer; Chrome 0-day; GitHub Key Rotation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8812.mp3" length="5100194" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8812.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8812</link>
<pubDate>Wed, 17 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Ivanti Vulnerability Widespread Scanning<br/>
 <a href="https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562">https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562</a><br/>
 <a href="https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/">https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/</a><br/>
Citrix Patches Already Exploited Vulnerability <br/>
 <a href="https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549">https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549</a><br/>
Atlassian Confluence Remote Code Execution Vulnerability<br/>
 <a href="https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html">https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html</a><br/>
macOS Infostealers<br/>
 <a href="https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/">https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/</a><br/>
Google Chrome 0-day<br/>
 <a href="https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html">https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html</a><br/>
GitHub Key Rotation<br/>
 <a href="https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/">https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8812" type="text/plain" language="en" />
<itunes:keywords>github, chrome, macos, infostealers, atlassian, confluence, citrix, ivanti, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 16th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8810</itunes:episode>
<itunes:subtitle>Malware Obfuscation; Ivanti Updates; NVidia Firmware Vuln; GitLab Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Obfuscation; Ivanti Updates; NVidia Firmware Vuln; GitLab Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8810.mp3" length="5344333" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8810.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8810</link>
<pubDate>Tue, 16 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[One File, Two Payloads<br/>
 <a href="https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558">https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558</a><br/>
Ivanti Vulnerability Updates<br/>
 <a href="https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/">https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/</a><br/>
NVidia DGX H100 and A100 Updates<br/>
 <a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5510">https://nvidia.custhelp.com/app/answers/detail/a_id/5510</a><br/>
GitLab Vulnerability<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7028">https://nvd.nist.gov/vuln/detail/CVE-2023-7028</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8810" type="text/plain" language="en" />
<itunes:keywords>gitlab, nvidia, ivanti, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 12th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8808</itunes:episode>
<itunes:subtitle>OpenSSH Removing DSA; Juniper Patches; ManageEngine Update; Atomic Stealer;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenSSH Removing DSA; Juniper Patches; ManageEngine Update; Atomic Stealer;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8808.mp3" length="5178683" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8808.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8808</link>
<pubDate>Fri, 12 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Timeline to Remove DSA Support in OpenSSH<br/>
 <a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html">https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html</a><br/>
Juniper Patches<br/>
 <a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories]">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories]</a><br/>
ManageEngine ADSelfService Plus Patch CVE-2024-0252<br/>
 <a href="https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html">https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html</a><br/>
Atomic Stealer for Mac Update<br/>
 <a href="https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version">https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8808" type="text/plain" language="en" />
<itunes:keywords>atomic, stealer, mac, malware, manageengine, juniper, dsa, openssh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 11th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8806</itunes:episode>
<itunes:subtitle>Jenkins Scans; Ivanti VPN Exploited; Zoom Update; Hadoop Attacks; infosec toolshed
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Jenkins Scans; Ivanti VPN Exploited; Zoom Update; Hadoop Attacks; infosec toolshed
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8806.mp3" length="4673885" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8806.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8806</link>
<pubDate>Thu, 11 Jan 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Jenkins Brute Force Scans<br/>
 <a href="https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546">https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546</a><br/>
Ivanti Connect Security VPN Vulnerability Exploited<br/>
 <a href="https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/">https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/</a><br/>
Zoom Privilege Escalation Vulnerability<br/>
 <a href="https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/">https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/</a><br/>
Apache Applictions Targeted by Stealthy Attacker<br/>
 <a href="https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker">https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker</a><br/>
Infosec Toolshed<br/>
 <a href="https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M">https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M</a><br/>
]]></description>
<itunes:duration>5:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8806" type="text/plain" language="en" />
<itunes:keywords>infosec, toolshed, apache, hadoop, fink, yarn, zoom, ivanti, vpn, jenkins, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 10th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8804</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches; Kyocera Vuln; Hacked Wrenches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches; Kyocera Vuln; Hacked Wrenches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8804.mp3" length="5428418" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8804.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8804</link>
<pubDate>Wed, 10 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft January 2024 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/">https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/</a><br/>
Adobe Vulnerabilities<br/>
 <a href="https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html">https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html</a><br/>
CVE-2023-50916: Authentication Coercion Vulnerablity in Kyocera Device Manager<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/</a><br/>
Network Connected Wrenches Used in Factories can be hacked<br/>
 <a href="https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/">https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8804" type="text/plain" language="en" />
<itunes:keywords>network, wrench, hack, kyocera, adobe, microsoft, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 9th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8802</itunes:episode>
<itunes:subtitle>Honeypot User Agents; KyberSlash; netfilter DoS; Cacti RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot User Agents; KyberSlash; netfilter DoS; Cacti RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8802.mp3" length="5412204" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8802.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8802</link>
<pubDate>Tue, 09 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[What is That User Agent<br/>
 <a href="https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536">https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536</a><br/>
KyberSlash Vulnerability<br/>
 <a href="https://kyberslash.cr.yp.to/faq.html">https://kyberslash.cr.yp.to/faq.html</a><br/>
Netfilter DoS Vulnerability CVE-2024-0193<br/>
 <a href="https://access.redhat.com/security/cve/CVE-2024-0193">https://access.redhat.com/security/cve/CVE-2024-0193</a><br/>
Cacti Vulnerability<br/>
 <a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp">https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8802" type="text/plain" language="en" />
<itunes:keywords>cacti, netfilter, kyberslash, user agent, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 8th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8800</itunes:episode>
<itunes:subtitle>Better Netstat in PS; Phishing Tricks; Prometei Botnet; Spectral Blur; Google Auth API Issue;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Better Netstat in PS; Phishing Tricks; Prometei Botnet; Spectral Blur; Google Auth API Issue;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8800.mp3" length="4625180" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8800.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8800</link>
<pubDate>Mon, 08 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Netstat But Better and in PowerShell<br/>
 <a href="https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532">https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532</a><br/>
Double Phishing Submission<br/>
 <a href="https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534">https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534</a><br/>
Suspicious Prometei Botnet Activity<br/>
 <a href="https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538">https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538</a><br/>
Spectral Blur Mac Malware<br/>
 <a href="https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html">https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html</a><br/>
Google Malware Abusing API is Standard Token Theft not an API Issue<br/>
 <a href="https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/">https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8800" type="text/plain" language="en" />
<itunes:keywords>google, authentiction, api, spectral blur, mac, malware, prometei, botnet, phishing, netstat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 5th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8798</itunes:episode>
<itunes:subtitle>Wireshark Updates; Android Updates; Ivanti Critical Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wireshark Updates; Android Updates; Ivanti Critical Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8798.mp3" length="4612033" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8798.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8798</link>
<pubDate>Fri, 05 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Wireshark Updates<br/>
 <a href="https://isc.sans.edu/diary/Wireshark%20updates/30528">https://isc.sans.edu/diary/Wireshark%20updates/30528</a><br/>
Android Updates<br/>
 <a href="https://source.android.com/docs/security/bulletin/2024-01-01">https://source.android.com/docs/security/bulletin/2024-01-01</a><br/>
Ivanti Critical Vulnerability<br/>
 <a href="https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US">https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US</a><br/>
Malicious PyPi Packages<br/>
 <a href="https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices">https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices</a><br/>
Everything npm package<br/>
 <a href="https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/">https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/</a><br/>
]]></description>
<itunes:duration>5:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8798" type="text/plain" language="en" />
<itunes:keywords>pypi, npm, everything, ivanti, android, wireshark, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 4th, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8796</itunes:episode>
<itunes:subtitle>Malware Review; Orange Spain RIPE Compromise; Bitwarden Weakness; iOS PoC Exploits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Review; Orange Spain RIPE Compromise; Bitwarden Weakness; iOS PoC Exploits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8796.mp3" length="5715927" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8796.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8796</link>
<pubDate>Thu, 04 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Interesting large and small malspam attachments from 2023<br/>
 <a href="https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524">https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524</a><br/>
Orange Spain RIPE Account Compromise<br/>
 <a href="https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/">https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/</a><br/>
Bitwarden Heist<br/>
 <a href="https://blog.redteam-pentesting.de/2024/bitwarden-heist/">https://blog.redteam-pentesting.de/2024/bitwarden-heist/</a><br/>
Apple iOS PoC Exploits<br/>
 <a href="https://github.com/felix-pb/kfd/blob/main/writeups/smith.md">https://github.com/felix-pb/kfd/blob/main/writeups/smith.md</a><br/>
 <a href="https://github.com/felix-pb/kfd/blob/main/writeups/landa.md">https://github.com/felix-pb/kfd/blob/main/writeups/landa.md</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8796" type="text/plain" language="en" />
<itunes:keywords>apple, ios, poc, bitwarden, organe, spain, ripe, rpki, bgp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 3rd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8794</itunes:episode>
<itunes:subtitle>SSH ID Strings; Google Authentication Weakness Exploited; Novel DNS Amplification (#TsuKing)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SSH ID Strings; Google Authentication Weakness Exploited; Novel DNS Amplification (#TsuKing)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8794.mp3" length="7673052" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8794.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8794</link>
<pubDate>Wed, 03 Jan 2024 02:00:02 GMT</pubDate>
<description><![CDATA[Fingerprinting SSH Identification Strings<br/>
 <a href="https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520">https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520</a><br/>
Google OAUTH2 Exploited by Malware<br/>
 <a href="https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking">https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking</a><br/>
TsuKing DNS Amplification<br/>
 <a href="https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf">https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf</a><br/>
]]></description>
<itunes:duration>8:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8794" type="text/plain" language="en" />
<itunes:keywords>dns, tsuking, google, oauth, cookies, fingerprinting, ssh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 2nd, 2024</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8792</itunes:episode>
<itunes:subtitle>Malicious Python Game; Mailtrap.io Exfil; Pi Hole Docker; Barracuda 0-Day; Apache OFBiz 0-Day (Atlassian JIRA)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Python Game; Mailtrap.io Exfil; Pi Hole Docker; Barracuda 0-Day; Apache OFBiz 0-Day (Atlassian JIRA)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8792.mp3" length="5492616" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8792.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8792</link>
<pubDate>Tue, 02 Jan 2024 02:00:01 GMT</pubDate>
<description><![CDATA[Shall We Play a Game<br/>
 <a href="https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510">https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510</a><br/>
Mailtrap.io Exfiltration<br/>
 <a href="https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512">https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512</a><br/>
Pi Hole Docker<br/>
 <a href="https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/">https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/</a><br/>
Mirai Update<br/>
 <a href="https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514">https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514</a><br/>
Barracuda 0-Day Vulnerability<br/>
 <a href="https://www.barracuda.com/company/legal/esg-vulnerability">https://www.barracuda.com/company/legal/esg-vulnerability</a><br/>
Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)<br/>
 <a href="https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/">https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8792" type="text/plain" language="en" />
<itunes:keywords>apache, ofbiz, altassian, jira, barracuda, mirai, pihole, maitrap, game, python, excel, perl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 22nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8790</itunes:episode>
<itunes:subtitle>Securing Webservers; Chrome 0-Day; Holiday Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Securing Webservers; Chrome 0-Day; Holiday Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8790.mp3" length="4347438" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8790.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8790</link>
<pubDate>Fri, 22 Dec 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Securing Web Servers<br/>
 <a href="https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504">https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504</a><br/>
Chrome 0-Day (last one for the year?)<br/>
 <a href="https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html">https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html</a><br/>
Note that there will be no daily stormcast for the rest of the year. Returning January 2nd<br/>
SANS Cloud Defender 2024<br/>
 <a href="https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/">https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/</a><br/>
]]></description>
<itunes:duration>4:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8790" type="text/plain" language="en" />
<itunes:keywords>chrome, web, apache, holidays, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 21st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8788</itunes:episode>
<itunes:subtitle>Atlassian Confluence Scans; F5 BigIP Fake Update; Google OAUTH issue; Remembering Adrian;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Atlassian Confluence Scans; F5 BigIP Fake Update; Google OAUTH issue; Remembering Adrian;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8788.mp3" length="6411186" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8788.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8788</link>
<pubDate>Thu, 21 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)<br/>
 <a href="https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502">https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502</a><br/>
Fake F5 BigIP Update<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/">https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/</a><br/>
Google OAUTH Problems<br/>
 <a href="https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/">https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/</a><br/>
Remembering Adrien de Beaupre<br/>
 <a href="https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php">https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php</a><br/>
]]></description>
<itunes:duration>7:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8788" type="text/plain" language="en" />
<itunes:keywords>adrien, google, oauth, f5, bigip, atlassian, confluence, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8786</itunes:episode>
<itunes:subtitle>Citrixbleed Activity; SSH Terrapin Attack; ALPHV/Blackcat Disruption and Decryptor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrixbleed Activity; SSH Terrapin Attack; ALPHV/Blackcat Disruption and Decryptor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8786.mp3" length="5501061" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8786.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8786</link>
<pubDate>Wed, 20 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[What are they looking for? Scans for OpenID Connect Configuration<br/>
 <a href="https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498">https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498</a><br/>
Terrapin Attack Against SSH<br/>
 <a href="https://terrapin-attack.com/TerrapinAttack.pdf">https://terrapin-attack.com/TerrapinAttack.pdf</a><br/>
ALPHV/Blackcat Ransomware Disrupted and Decryptor Available<br/>
 <a href="https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant">https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8786" type="text/plain" language="en" />
<itunes:keywords>alphv, blackcat, ransomware, decryuptor, terrapin, ssh, openid, citrix, citrixleak, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 19th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8784</itunes:episode>
<itunes:subtitle>SMTP Smuggling; Ledger Attack; December Patch Breaks Win11 Wifi;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SMTP Smuggling; Ledger Attack; December Patch Breaks Win11 Wifi;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8784.mp3" length="5491252" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8784.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8784</link>
<pubDate>Tue, 19 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[SMTP Smuggling - Spoofing E-Mails Worldwide<br/>
 <a href="https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/">https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/</a><br/>
Ledger Supply Chain Attack<br/>
 <a href="https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit">https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit</a><br/>
December Windows 11 Patch Breacks Wi-Fi Connectivity<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/">https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8784" type="text/plain" language="en" />
<itunes:keywords>windows 11, wifi, ledger, smtp, smuggling, e-mail, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8782</itunes:episode>
<itunes:subtitle>Rocket MQ Exploit; C# Payload; 3CX Vuln; QNAP NVR Exploit; PFSense Vulnerabilith; #holidayhack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Rocket MQ Exploit; C# Payload; 3CX Vuln; QNAP NVR Exploit; PFSense Vulnerabilith; #holidayhack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8782.mp3" length="8981230" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8782.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8782</link>
<pubDate>Mon, 18 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[An Example of a RocketMQ Exploit Scanner<br/>
 <a href="https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492">https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492</a><br/>
C# Payload Phoning to a Cobalt Strike Server<br/>
 <a href="https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490">https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490</a><br/>
3CX SQL Injection Vulnerability<br/>
 <a href="https://www.3cx.com/blog/news/sql-database-integration/">https://www.3cx.com/blog/news/sql-database-integration/</a><br/>
QNAP Viostor 0-Day Vulnerablity<br/>
 <a href="https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched">https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched</a><br/>
PFSense Vulnerability<br/>
 <a href="https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/">https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/</a><br/>
SANS Holiday Hack Challenge<br/>
 <a href="https://sans.org/holidayhack">https://sans.org/holidayhack</a><br/>
]]></description>
<itunes:duration>10:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8782" type="text/plain" language="en" />
<itunes:keywords>sans, holiday, hack, challenge, qnap, viostor, 3cx, sql, injection, rocketmq, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8780</itunes:episode>
<itunes:subtitle>Terraforming Honeypots; Unifi Camera Mixup; Zoom VISS; Squid DoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Terraforming Honeypots; Unifi Camera Mixup; Zoom VISS; Squid DoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8780.mp3" length="4836734" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8780.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8780</link>
<pubDate>Fri, 15 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[T-shooting Terraform for DShield Honeypot in Azure<br/>
 <a href="https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484">https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484</a><br/>
Ubiquity Unifi Cameras Visible in Wrong Account<br/>
 <a href="https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7">https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7</a><br/>
Zoom Vulnerabilities and VISS<br/>
 <a href="https://viss.zoom.com/specifications">https://viss.zoom.com/specifications</a><br/>
 <a href="https://www.zoom.com/en/trust/security-bulletin/">https://www.zoom.com/en/trust/security-bulletin/</a><br/>
Squid Denial of Service Vulnerability<br/>
 <a href="https://github.com/squid-cache/squid/security/advisories/GHSA-wgq4-4cfg-c4x3">https://github.com/squid-cache/squid/security/advisories/GHSA-wgq4-4cfg-c4x3</a>]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8780" type="text/plain" language="en" />
<itunes:keywords>squid, zoom, ubiquity, unifi, cameras, terraform, honeypot, protect, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8778</itunes:episode>
<itunes:subtitle>GUI Python Malware; Adobe Updates; TeamCity Exploited; Sophos Patches EOL Devices
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GUI Python Malware; Adobe Updates; TeamCity Exploited; Sophos Patches EOL Devices
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8778.mp3" length="4640247" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8778.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8778</link>
<pubDate>Thu, 14 Dec 2023 02:10:05 GMT</pubDate>
<description><![CDATA[Malicious Python Script with a TCL/TK GUI<br/>
 <a href="https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478">https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
TeamCity Exploited<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a</a><br/>
Sophos Firewall Exploit for EOL Devices CVE-2022-3236<br/>
 <a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8778" type="text/plain" language="en" />
<itunes:keywords>sophos, teamcity, adobe, python, tcl/tk, gui, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8776</itunes:episode>
<itunes:subtitle>Microsoft Patches; Malicious OAUTH; Apache Struts2 Exploit;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Malicious OAUTH; Apache Struts2 Exploit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8776.mp3" length="5386652" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8776.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8776</link>
<pubDate>Wed, 13 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480</a><br/>
Microsoft Warns of Malicious OAUTH Applications<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/">https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/</a><br/>
Apache Struts2 Exploit CVE-2023-50164<br/>
 <a href="https://xz.aliyun.com/t/13172">https://xz.aliyun.com/t/13172</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8776" type="text/plain" language="en" />
<itunes:keywords>struts2, microsoft, patches, oauth, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8774</itunes:episode>
<itunes:subtitle>Sitemap.xml; Apple Patches; Android Password Autospill
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sitemap.xml; Apple Patches; Android Password Autospill
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8774.mp3" length="5000685" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8774.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8774</link>
<pubDate>Tue, 12 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[What is Sitemap.xml and Why a Pentester Should Care<br/>
 <a href="https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472">https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472</a><br/>
Apple Patches Everything<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/">https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/</a><br/>
Android Password Manager Auto Spill<br/>
 <a href="https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf">https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8774" type="text/plain" language="en" />
<itunes:keywords>sitemap.xml, apple patches, android, password manager, autospill, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8772</itunes:episode>
<itunes:subtitle>IPv4 Mapped Addresses; Honeypots; Bluetooth Attacks; Syrus 4 Vuln; MSFT Edge Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IPv4 Mapped Addresses; Honeypots; Bluetooth Attacks; Syrus 4 Vuln; MSFT Edge Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8772.mp3" length="5557316" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8772.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8772</link>
<pubDate>Mon, 11 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[IPv4 Mapped IPv6 Addresses<br/>
 <a href="https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466">https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466</a><br/>
Honeypots From the Skeptical Beginner to the Tactical Enthusiast<br/>
 <a href="https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468">https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468</a><br/>
Bluetooth Weakness CVE-2023-45866<br/>
 <a href="https://github.com/skysafe/reblog/tree/main/cve-2023-45866">https://github.com/skysafe/reblog/tree/main/cve-2023-45866</a><br/>
Syrus 4 IoT Gateway Vulnerability CVE-2023-6248<br/>
 <a href="https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/">https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/</a><br/>
Microsoft Edge Vulnerability CVE-2023-35618<br/>
 <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8772" type="text/plain" language="en" />
<itunes:keywords>microsoft, edge, syrus, iot, gateway, bluetooth, keyboard, honeypots, ipv4, ipv6, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8770</itunes:episode>
<itunes:subtitle>5G Vulnerabilities; QR Codes; Windows 10 EOS; Apache Struts RCE Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
5G Vulnerabilities; QR Codes; Windows 10 EOS; Apache Struts RCE Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8770.mp3" length="5542157" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8770.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8770</link>
<pubDate>Fri, 08 Dec 2023 02:00:01 GMT</pubDate>
<description><![CDATA[5G Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462">https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462</a><br/>
Revealing the hidden Risks of QR Codes<br/>
 <a href="https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458">https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458</a><br/>
Window 10 End of Support<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414</a><br/>
Apache Struts 2 Vulnerability CVE-2023-50164<br/>
 <a href="https://cwiki.apache.org/confluence/display/WW/S2-066">https://cwiki.apache.org/confluence/display/WW/S2-066</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8770" type="text/plain" language="en" />
<itunes:keywords>apache, struts, windows 10, end of support, qr codes, 5g vulnerabilities, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8768</itunes:episode>
<itunes:subtitle>Research Scan Attribution; MLFlow and Atlasian Vulns; AWS STS; #holidayhack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Research Scan Attribution; MLFlow and Atlasian Vulns; AWS STS; #holidayhack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8768.mp3" length="5203792" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8768.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8768</link>
<pubDate>Thu, 07 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Whose packet is is anyway: a new RFC for attribution of internet probes<br/>
 <a href="https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/">https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/</a><br/>
MLFlow Vulnerability<br/>
 <a href="https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security">https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security</a><br/>
 <a href="https://mlflow.org/category/news/index.html">https://mlflow.org/category/news/index.html</a><br/>
Abusing STS Tokens<br/>
 <a href="https://redcanary.com/blog/aws-sts/">https://redcanary.com/blog/aws-sts/</a><br/>
Atlasian Vulnerabilities<br/>
 <a href="https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html">https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html</a><br/>
Holiday Hack Challenge<br/>
 <a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8768" type="text/plain" language="en" />
<itunes:keywords>holiday hack challenge, atlasian, sts tokens, aws, mlflow, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8766</itunes:episode>
<itunes:subtitle>Cobalt Strike Analysis; ColdFusion Exploited; Atos Unify Vuln; ExteremXOS Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobalt Strike Analysis; ColdFusion Exploited; Atos Unify Vuln; ExteremXOS Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8766.mp3" length="4988445" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8766.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8766</link>
<pubDate>Wed, 06 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Cobalt Strike's "Runtime Configuration"<br/>
 <a href="https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426">https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426</a><br/>
Adobe ColdFusion Exploit Abused<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a</a><br/>
Atos Unify OpenScape Vulnerability<br/>
 <a href="https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/">https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/</a><br/>
ExtremeXOS Vulnerabilities<br/>
 <a href="https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/">https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8766" type="text/plain" language="en" />
<itunes:keywords>extremexos, atos, unify, openscape, adobe, coldfusion, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 5th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8764</itunes:episode>
<itunes:subtitle>Zarya Hacktivists; ICAN RDRS; Android and Gitlab Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zarya Hacktivists; ICAN RDRS; Android and Gitlab Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8764.mp3" length="5348777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8764.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8764</link>
<pubDate>Tue, 05 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Zarya Hacktivists: More than just Sharepoint<br/>
 <a href="https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450">https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450</a><br/>
ICANN Registration Data Request Service (RDRS)<br/>
 <a href="https://rdrs.icann.org/">https://rdrs.icann.org/</a><br/>
Android Updates<br/>
 <a href="https://source.android.com/docs/security/bulletin/2023-12-01">https://source.android.com/docs/security/bulletin/2023-12-01</a><br/>
GitLab Patches<br/>
 <a href="https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/">https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8764" type="text/plain" language="en" />
<itunes:keywords>gitlab, android, icann, rdrs, zarya, hacktivists, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 4th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8762</itunes:episode>
<itunes:subtitle>LogoFail; Fake WordPress Exploit; Qlik Sense Exploited; VMWare Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LogoFail; Fake WordPress Exploit; Qlik Sense Exploited; VMWare Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8762.mp3" length="5360990" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8762.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8762</link>
<pubDate>Mon, 04 Dec 2023 02:00:02 GMT</pubDate>
<description><![CDATA[UEFI Exploit via Boot Image<br/>
 <a href="https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html">https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html</a><br/>
Fake Phishing Scan Tricks Users into Installing Backdoor Plugin<br/>
 <a href="https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/">https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/</a><br/>
Qlik Sense Exploited by Cactus Ransomware<br/>
 <a href="https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/">https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/</a><br/>
 <a href="https://www.praetorian.com/blog/qlik-sense-technical-exploit/">https://www.praetorian.com/blog/qlik-sense-technical-exploit/</a><br/>
VMWare Vulnerability Patched<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0026.html">https://www.vmware.com/security/advisories/VMSA-2023-0026.html</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8762" type="text/plain" language="en" />
<itunes:keywords>vmware, qlik, ransomware, phishing, wordpress, uefi, logofail, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8760</itunes:episode>
<itunes:subtitle>Apple Updates; Mirai Expansion; Zyxel Vulns; Solarwinds Update; DNS Looking Glass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Mirai Expansion; Zyxel Vulns; Solarwinds Update; DNS Looking Glass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8760.mp3" length="5002077" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8760.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8760</link>
<pubDate>Fri, 01 Dec 2023 03:08:45 GMT</pubDate>
<description><![CDATA[Apple Updates<br/>
 <a href="https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444">https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444</a><br/>
Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today<br/>
 <a href="https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/">https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/</a><br/>
Zyxel Vulnerabilities<br/>
 <a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products</a><br/>
Solarwinds Update<br/>
 <a href="https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3">https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3</a><br/>
DNS Looking Glass<br/>
 <a href="https://isc.sans.edu/tools/dnslookup/">https://isc.sans.edu/tools/dnslookup/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8760" type="text/plain" language="en" />
<itunes:keywords>dns, looking glass, solarwinds, zyxel, mirai, apple, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 30th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8758</itunes:episode>
<itunes:subtitle>3 Months Honeypot Summary; Arcserver PoC; Hikvision Vuln; Custom GPT Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
3 Months Honeypot Summary; Arcserver PoC; Hikvision Vuln; Custom GPT Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8758.mp3" length="4939532" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8758.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8758</link>
<pubDate>Thu, 30 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Decoding the Patterns: Analzying DShield Honeypot Activity<br/>
 <a href="https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428">https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428</a><br/>
Arcserve Unified Data Protection Multiple Vulnerabilities<br/>
 <a href="https://www.tenable.com/security/research/tra-2023-37">https://www.tenable.com/security/research/tra-2023-37</a><br/>
Hikvision Vulnerabilities<br/>
 <a href="https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/">https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/</a><br/>
Assessing Prompt Injection Risks in 200+ Custom GPTs<br/>
 <a href="https://arxiv.org/pdf/2311.11538.pdf">https://arxiv.org/pdf/2311.11538.pdf</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8758" type="text/plain" language="en" />
<itunes:keywords>gpt, prompt injection, hikvision, arserve, dshield, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 29th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8756</itunes:episode>
<itunes:subtitle>Sharepoint Attack; MSFT removes Defender App Guard for Office; Synology , Tomcat and Chrome Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sharepoint Attack; MSFT removes Defender App Guard for Office; Synology , Tomcat and Chrome Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8756.mp3" length="5014883" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8756.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8756</link>
<pubDate>Wed, 29 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357<br/>
 <a href="https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436">https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436</a><br/>
Microsoft Deprecates Microsoft Defender Application Guard for Office<br/>
 <a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br/>
Synology Vulnerability<br/>
 <a href="https://www.synology.com/en-global/security/advisory/Synology_SA_23_16">https://www.synology.com/en-global/security/advisory/Synology_SA_23_16</a><br/>
Apache Tomcat Request Smuggling Vulnerability CVE-2023-46589<br/>
 <a href="https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr">https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8756" type="text/plain" language="en" />
<itunes:keywords>apache, tomcat, synology, microsoft, defender, application guard, sharepoint, russia, ukraine, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8754</itunes:episode>
<itunes:subtitle>OwnCloud Exploited; Fingerprint Reader Weakness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OwnCloud Exploited; Fingerprint Reader Weakness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8754.mp3" length="5860853" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8754.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8754</link>
<pubDate>Tue, 28 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Scans for ownCloud Vulnerability (CVE-2023-49103)<br/>
 <a href="https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432">https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432</a><br/>
Windows Hello Fingerprint Reader Weakness<br/>
 <a href="https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/">https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8754" type="text/plain" language="en" />
<itunes:keywords>windows, hello, fingerprint, owncloud, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8752</itunes:episode>
<itunes:subtitle>DShield Birthday; Mirai Exploits; OVA Files; OpenCart Vuln; Holiday Hack Challenge
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DShield Birthday; Mirai Exploits; OVA Files; OpenCart Vuln; Holiday Hack Challenge
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8752.mp3" length="5358057" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8752.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8752</link>
<pubDate>Mon, 27 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[DShield Birthday<br/>
 <a href="https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420">https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420</a><br/>
Mirai uses CVE-2023-1389<br/>
 <a href="https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418">https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418</a><br/>
More Mirai Vulnerabilities<br/>
 <a href="https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days">https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days</a><br/>
Analyzing OVA Files<br/>
 <a href="https://isc.sans.edu/diary/OVA%20Files/30424">https://isc.sans.edu/diary/OVA%20Files/30424</a><br/>
Static Code Injections in OpenCart (CVE-2023-47444)<br/>
 <a href="https://github.com/opencart/opencart/issues/12947">https://github.com/opencart/opencart/issues/12947</a><br/>
Holiday Hackchallenge<br/>
 <a href="https://www.sans.org/mlp/holiday-hack-challenge-2023/">https://www.sans.org/mlp/holiday-hack-challenge-2023/</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8752" type="text/plain" language="en" />
<itunes:keywords>holiday, hackchallenge, opencart, ova, ovf, mirai, nvr, dvr, tplink, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8750</itunes:episode>
<itunes:subtitle>Faster tcpdump; Zimbra Exploit Details; FortiSIEM Vuln; AI-Exploits; CrushFTP and FortiSIEM Patches; @sans_edu Research: Scott Poley; Storing Less
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Faster tcpdump; Zimbra Exploit Details; FortiSIEM Vuln; AI-Exploits; CrushFTP and FortiSIEM Patches; @sans_edu Research: Scott Poley; Storing Less
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8750.mp3" length="13247860" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8750.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8750</link>
<pubDate>Fri, 17 Nov 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Beyond -n: Optimizign tcpdump performance<br/>
 <a href="https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/">https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/</a><br/>
Zimbra 0-day used to target international government organizations<br/>
 <a href="https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/">https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/</a><br/>
FortiSIEM OS command injection in Report Server<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-23-135">https://www.fortiguard.com/psirt/FG-IR-23-135</a><br/>
AI Exploit Collection<br/>
 <a href="https://github.com/protectai/ai-exploits">https://github.com/protectai/ai-exploits</a><br/>
CrushFTP Remote Code Execution<br/>
 <a href="https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/">https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/</a><br/>
Scott Poley: The Cyber Date Paradox: Storing Less, Discovering More<br/>
 <a href="https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/">https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/</a><br/>
]]></description>
<itunes:duration>15:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8750" type="text/plain" language="en" />
<itunes:keywords>crushftp, ai, exploit, fortisiem, zimbra, 0-day, tcpdump, scott poley, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8748</itunes:episode>
<itunes:subtitle>MSIX to Redline; ChatGPT Code Interpreter vuln; Aruba and Netty Vulns; HARArmor @FronteggForSaaS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSIX to Redline; ChatGPT Code Interpreter vuln; Aruba and Netty Vulns; HARArmor @FronteggForSaaS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8748.mp3" length="5305468" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8748.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8748</link>
<pubDate>Thu, 16 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Redline Dropped Through MSIX Package<br/>
 <a href="https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404">https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404</a><br/>
ChatGPT Code Interpreter Security Hole<br/>
 <a href="https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole">https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole</a><br/>
Directory Traversal in Reactor Netty CVE-2023-34062<br/>
 <a href="https://spring.io/security/cve-2023-34062">https://spring.io/security/cve-2023-34062</a><br/>
Aruba Networking Product Vulnerabilities<br/>
 <a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt</a><br/>
HARArmor<br/>
 <a href="https://harmor.dev/">https://harmor.dev/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8748" type="text/plain" language="en" />
<itunes:keywords>harmor, aruba, netty, reactor, chatgpt, interpreter, code, redline, msix, msi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8746</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches; Intel CPU Glitch State Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches; Intel CPU Glitch State Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8746.mp3" length="6333004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8746.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8746</link>
<pubDate>Wed, 15 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400">https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Intel CPU Glitch State Patch<br/>
 <a href="https://lock.cmpxchg8b.com/reptar.html">https://lock.cmpxchg8b.com/reptar.html</a><br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html</a><br/>
]]></description>
<itunes:duration>7:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8746" type="text/plain" language="en" />
<itunes:keywords>intel, cpu, glitch, adobe, microsoft, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8744</itunes:episode>
<itunes:subtitle>Discovering DNS C&amp;C; Passive SSH Key Compromise; Juniper Vuln Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Discovering DNS C&amp;C; Passive SSH Key Compromise; Juniper Vuln Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8744.mp3" length="4570338" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8744.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8744</link>
<pubDate>Tue, 14 Nov 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Noticing command control channels by reviewing DNS protocols<br/>
 <a href="https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396">https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396</a><br/>
Passive SSH Key Compromise via Lattices<br/>
 <a href="https://eprint.iacr.org/2023/1711.pdf">https://eprint.iacr.org/2023/1711.pdf</a><br/>
Juniper Vulnerabilities Exploited<br/>
 <a href="https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US">https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8744" type="text/plain" language="en" />
<itunes:keywords>juniper, passive, ssh, dns, secret key, rsa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8742</itunes:episode>
<itunes:subtitle>Gafgyt Update; ScreenConnect Healthcare Breach; Fake Assessment Websites
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Gafgyt Update; ScreenConnect Healthcare Breach; Fake Assessment Websites
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8742.mp3" length="5155125" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8742.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8742</link>
<pubDate>Mon, 13 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Routers Targeted for Gafgyt Botnet<br/>
 <a href="https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/">https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/</a><br/>
ScreenConnect used to Attack Healthcare<br/>
 <a href="https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack">https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack</a><br/>
Fake Skills Assessment Portals Associated with Sapphire Sleet<br/>
 <a href="https://twitter.com/MsftSecIntel/status/1722316019920728437">https://twitter.com/MsftSecIntel/status/1722316019920728437</a><br/>
OpenVPN Access Server Vulnerabilities<br/>
 <a href="https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/">https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8742" type="text/plain" language="en" />
<itunes:keywords>openvpn, saphire sleet, job portals, assessment, screen connect, healthcare, rotuers, gafgyt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8740</itunes:episode>
<itunes:subtitle>Visualizing Code Injection; SysAid Exploit; WS_FTP Update; CPU-Z Impersonation; pyArrow Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Visualizing Code Injection; SysAid Exploit; WS_FTP Update; CPU-Z Impersonation; pyArrow Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8740.mp3" length="4861531" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8740.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8740</link>
<pubDate>Fri, 10 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Visual Examples of Code Injection<br/>
 <a href="https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388">https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388</a><br/>
SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)<br/>
 <a href="https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification">https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification</a><br/>
WS_FTP Server Update CVE-2023-42659<br/>
 <a href="https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023">https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023</a><br/>
Malvertiser copies PC news site to delivery infostealer<br/>
 <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer">https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer</a><br/>
pyArrow/Apache Arrow Vulnerability<br/>
 <a href="https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n">https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8740" type="text/plain" language="en" />
<itunes:keywords>pyarrow, apache, arrow, cpu-z, malvertiser, google, ws_ftp, moveit, sysaid, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8738</itunes:episode>
<itunes:subtitle>Project Phishing; Azure Automation Mining; Windows Firewall Changes; SLP DoS Vuln added to KEV;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Project Phishing; Azure Automation Mining; Windows Firewall Changes; SLP DoS Vuln added to KEV;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8738.mp3" length="4801354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8738.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8738</link>
<pubDate>Thu, 09 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Example of a Phishing Campaing Project File<br/>
 <a href="https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384">https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384</a><br/>
Cryptomining with Microsoft Azure Automation Services<br/>
 <a href="https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure">https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure</a><br/>
Windows 11 Insider Changing Firewall Behaviour<br/>
 <a href="https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/">https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/</a><br/>
CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog">https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8738" type="text/plain" language="en" />
<itunes:keywords>cisa, slp, windows 11, smb, ntlm, firewall, cryptomining, azure, automation, phishing, project, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8736</itunes:episode>
<itunes:subtitle>Discovery of Designated Resolvers; BlueNoroff macOS Malware; MSFT hardens MFA;</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Discovery of Designated Resolvers; BlueNoroff macOS Malware; MSFT hardens MFA;</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8736.mp3" length="5657862" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8736.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8736</link>
<pubDate>Wed, 08 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)<br/>
 <a href="https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380">https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380</a><br/>
BlueNoroff macOS Malware<br/>
 <a href="https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/">https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/</a><br/>
Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130">https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8736" type="text/plain" language="en" />
<itunes:keywords>microsoft, authenticator, macos, malware, bluenoroff, dns, ddr, designated resolvers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8734</itunes:episode>
<itunes:subtitle>Confluence CVE-2023-22518 Exploited; Calender Data Exfil; Veeam and QNAP Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Confluence CVE-2023-22518 Exploited; Calender Data Exfil; Veeam and QNAP Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8734.mp3" length="5506916" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8734.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8734</link>
<pubDate>Tue, 07 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Confluence CVe-2023-22518 Exploited<br/>
 <a href="https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376">https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376</a><br/>
Google Threat Horizons Report<br/>
 <a href="https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf">https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf</a><br/>
 <a href="https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/">https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/</a><br/>
Veeam Update<br/>
 <a href="https://www.veeam.com/kb4508">https://www.veeam.com/kb4508</a><br/>
QNAP Update<br/>
 <a href="https://www.qnap.com/de-de/security-advisory/qsa-23-35">https://www.qnap.com/de-de/security-advisory/qsa-23-35</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8734" type="text/plain" language="en" />
<itunes:keywords>qnap, veeam, google, horizons, calendar, confluence, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8732</itunes:episode>
<itunes:subtitle>Possible Exchange Flaws; Sriped Fly Botnet; Send My 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Possible Exchange Flaws; Sriped Fly Botnet; Send My 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8732.mp3" length="6288937" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8732.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8732</link>
<pubDate>Mon, 06 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[New Microsoft Exchange Zero Days<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/">https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/</a><br/>
StripedFly: Perennially Flying under the Radar<br/>
 <a href="https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/">https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/</a><br/>
Send My: Sending Data over Apple's Find My Network<br/>
 <a href="https://github.com/positive-security/send-my">https://github.com/positive-security/send-my</a><br/>
]]></description>
<itunes:duration>7:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8732" type="text/plain" language="en" />
<itunes:keywords>send my, apple, find my, stripedfly, miner, exchange, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8730</itunes:episode>
<itunes:subtitle>Inflated PE Files; ActiveMQ Exploit; Firepower Vuln; Malicious NPM;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Inflated PE Files; ActiveMQ Exploit; Firepower Vuln; Malicious NPM;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8730.mp3" length="4820407" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8730.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8730</link>
<pubDate>Fri, 03 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Quick Tip for Artificially Inflated PE Files<br/>
 <a href="https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370">https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370</a><br/>
Apache ActiveMQ Flaw Exploited<br/>
 <a href="https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt">https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt</a><br/>
 <a href="https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/">https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/</a><br/>
Critical Firepower Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN</a><br/>
Dozens of npm Packages Caught Attempting to Deploy Reverse Shell<br/>
 <a href="https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/">https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8730" type="text/plain" language="en" />
<itunes:keywords>reverse shell, npm, rsh.js, firepower, activemq, apache, pe files, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8728</itunes:episode>
<itunes:subtitle>ZPAQ Archives; CVSS 4.0;  Slack Impersonation; MOZI Demise; URL Shorteners
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ZPAQ Archives; CVSS 4.0;  Slack Impersonation; MOZI Demise; URL Shorteners
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8728.mp3" length="5108588" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8728.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8728</link>
<pubDate>Thu, 02 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Malware Dropped Through a ZPAQ Archive<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/">https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/</a><br/>
CVSS 4.0 Now Official<br/>
 <a href="https://www.first.org/cvss/v4-0/index.html">https://www.first.org/cvss/v4-0/index.html</a><br/>
MOZI Botnet Killswitch<br/>
 <a href="https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/">https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/</a><br/>
URL Shorteners in .us<br/>
 <a href="https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/">https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/</a><br/>
Impersonating Slack Users<br/>
 <a href="https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html">https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8728" type="text/plain" language="en" />
<itunes:keywords>slack, url, us, mozi, botnet, cvss, zpaq, malware, archive, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8726</itunes:episode>
<itunes:subtitle>Anti-Sandboxing; Confluence Vuln; PyCharm Malvertisement; Thorn SFTP Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Anti-Sandboxing; Confluence Vuln; PyCharm Malvertisement; Thorn SFTP Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8726.mp3" length="3828456" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8726.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8726</link>
<pubDate>Wed, 01 Nov 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Multiple Layers of Anti-Sandboxing Techniques<br/>
 <a href="https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362">https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362</a><br/>
CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server<br/>
 <a href="https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html">https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html</a><br/>
Malvertisement Promotes Malicious PyCharm Version<br/>
 <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza</a><br/>
Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174<br/>
 <a href="https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/">https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/</a><br/>
]]></description>
<itunes:duration>4:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8726" type="text/plain" language="en" />
<itunes:keywords>thron, sftp, pycharm, malvertisement, confluence, anti-sandboxing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 31st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8724</itunes:episode>
<itunes:subtitle>Multicast DNS; Kubernetes ingress-nginx; HTTPS Upgrade; Wordpad PoC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Multicast DNS; Kubernetes ingress-nginx; HTTPS Upgrade; Wordpad PoC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8724.mp3" length="5544151" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8724.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8724</link>
<pubDate>Tue, 31 Oct 2023 00:05:28 GMT</pubDate>
<description><![CDATA[Flying under the Radar: The Privacy Impact of Mulicast DNS<br/>
 <a href="https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/">https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/</a><br/>
Kubernetes ingress-nginx vulnerability<br/>
 <a href="https://github.com/kubernetes/ingress-nginx/issues/10571">https://github.com/kubernetes/ingress-nginx/issues/10571</a><br/>
Google Chrome HTTPS Upgrade<br/>
 <a href="https://github.com/dadrian/https-upgrade/blob/main/explainer.md">https://github.com/dadrian/https-upgrade/blob/main/explainer.md</a><br/>
Wordpad POC CVE-2023-36563<br/>
 <a href="https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/">https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8724" type="text/plain" language="en" />
<itunes:keywords>wordpad, google, chrome, https, kubernetes, ingress-nginx, mdns, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 30th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8722</itunes:episode>
<itunes:subtitle>Size Matters; Spam or Phishing; iOS MAC Leaks; ZDI Summary; Octo Tempest
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Size Matters; Spam or Phishing; iOS MAC Leaks; ZDI Summary; Octo Tempest
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8722.mp3" length="5443287" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8722.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8722</link>
<pubDate>Mon, 30 Oct 2023 01:43:13 GMT</pubDate>
<description><![CDATA[Size Matters for Many Security Controls<br/>
 <a href="https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352">https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352</a><br/>
Spam or Phishing? Looking for Credentials and Passwords<br/>
 <a href="https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354">https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354</a><br/>
iOS Leaks MAC Address<br/>
 <a href="https://www.youtube.com/watch?v=T3XABxNogTA">https://www.youtube.com/watch?v=T3XABxNogTA</a><br/>
Zero Day Initiative Pwn2Own Summary<br/>
 <a href="https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results">https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results</a><br/>
 <a href="https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results">https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results</a><br/>
 <a href="https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results">https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results</a><br/>
Microsoft Octo Tempest Writeup<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/">https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8722" type="text/plain" language="en" />
<itunes:keywords>octo, tempest, microsoft, zdi, pwn2own, apple, mac address, privacy, size, spam, phishing, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8720</itunes:episode>
<itunes:subtitle>IPv4 Addresses; F5 BigIP Vuln; Apple iLeakage;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IPv4 Addresses; F5 BigIP Vuln; Apple iLeakage;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8720.mp3" length="5384979" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8720.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8720</link>
<pubDate>Fri, 27 Oct 2023 10:45:02 GMT</pubDate>
<description><![CDATA[Adventures in Validating IPv4 Addresses<br/>
 <a href="https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/">https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/</a><br/>
BIG-IP Configuration Utility Unauthenticated Remote Code Execution<br/>
 <a href="https://my.f5.com/manage/s/article/K000137353">https://my.f5.com/manage/s/article/K000137353</a><br/>
 <a href="https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/">https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/</a><br/>
iLeakage Vulnerability<br/>
 <a href="https://ileakage.com/">https://ileakage.com/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8720" type="text/plain" language="en" />
<itunes:keywords>ileakage, big-ip, f5, ipv4, addresses, input, validation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 26th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8718</itunes:episode>
<itunes:subtitle>Apple Updates; Confluence Server Scans; Critical VMWare Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Confluence Server Scans; Critical VMWare Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8718.mp3" length="5436878" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8718.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8718</link>
<pubDate>Thu, 26 Oct 2023 00:56:27 GMT</pubDate>
<description><![CDATA[Apple Updates<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344">https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344</a><br/>
Confluence Server Scans CVE-2023-22515<br/>
 <a href="https://isc.sans.edu/diary/30342">https://isc.sans.edu/diary/30342</a><br/>
Critical VMVware vCenter Patch CVE-2023-34048<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0023.html">https://www.vmware.com/security/advisories/VMSA-2023-0023.html</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8718" type="text/plain" language="en" />
<itunes:keywords>vmware, vcenter, confluence, server, apple, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 25th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8716</itunes:episode>
<itunes:subtitle>Google Samsung False Positive; OAuth Hijacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Samsung False Positive; OAuth Hijacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8716.mp3" length="5690345" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8716.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8716</link>
<pubDate>Wed, 25 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google<br/>
 <a href="https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/">https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/</a><br/>
OAuth Hijacking<br/>
 <a href="https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts">https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts</a><br/>
Microsoft Exchange Server CVe-2023-36745 PoC<br/>
 <a href="https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/">https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/</a><br/>
Citrix Bleed PoC CVe-2023-4966<br/>
 <a href="https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966">https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966</a><br/>
VMWare VRealize Exploit CVE-2023-34051 CVE0-2023-34052<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0021.html">https://www.vmware.com/security/advisories/VMSA-2023-0021.html</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8716" type="text/plain" language="en" />
<itunes:keywords>vmware, vrealize, exploit, poc, exchange, citrix, oauth, samsung, google, false positive, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8714</itunes:episode>
<itunes:subtitle>Apple TV IPv6 DoS; Squid Patches; Critical Citrix Patch; Cisco Vuln Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple TV IPv6 DoS; Squid Patches; Critical Citrix Patch; Cisco Vuln Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8714.mp3" length="5689893" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8714.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8714</link>
<pubDate>Tue, 24 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Apple TV IPv6 DoS<br/>
 <a href="https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336">https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336</a><br/>
Squid Patches<br/>
 <a href="https://github.com/squid-cache/squid/security/advisories">https://github.com/squid-cache/squid/security/advisories</a><br/>
Critical Citrix Update<br/>
 <a href="https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/">https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/</a><br/>
Cisco Vulnerablity Updates CVE-2023-20198<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8714" type="text/plain" language="en" />
<itunes:keywords>cisco, ios xe, apple, tv, ipv6, router advertisements, squid, citrix, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 23rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8712</itunes:episode>
<itunes:subtitle>Base64Dump; OAUTH Redirect; Okta Breach; VMWare and Solarwinds Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Base64Dump; OAUTH Redirect; Okta Breach; VMWare and Solarwinds Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8712.mp3" length="5899196" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8712.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8712</link>
<pubDate>Mon, 23 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[base64dump.py Handles More Encodings Than Just BASE64<br/>
 <a href="https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332">https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332</a><br/>
Stealing OAuth Tokens via Open Redirects<br/>
 <a href="https://eval.blog/research/microsoft-account-token-leaks-in-harvest/">https://eval.blog/research/microsoft-account-token-leaks-in-harvest/</a><br/>
VMWare Patches<br/>
 <a href="https://www.vmware.com/security/advisories.html">https://www.vmware.com/security/advisories.html</a><br/>
Solarwinds Patches<br/>
 <a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm">https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8712" type="text/plain" language="en" />
<itunes:keywords>solarwinds, vmware, oauth, microsoft, harvest, oauth, base64, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8710</itunes:episode>
<itunes:subtitle>honeypot update; Malicious Keepass Ad; JavaScript in Blockchain;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
honeypot update; Malicious Keepass Ad; JavaScript in Blockchain;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8710.mp3" length="5864784" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8710.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8710</link>
<pubDate>Fri, 20 Oct 2023 00:37:38 GMT</pubDate>
<description><![CDATA[Honeypot Update<br/>
 <a href="https://github.com/DShield-ISC/dshield/blob/main/README.md">https://github.com/DShield-ISC/dshield/blob/main/README.md</a><br/>
Malicious Keepass Ads<br/>
 <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website">https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website</a><br/>
Malicious JavaScript in Smart Contracts<br/>
 <a href="https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16">https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8710" type="text/plain" language="en" />
<itunes:keywords>javascript, binance, smart contracts, keepass, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 19th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8708</itunes:episode>
<itunes:subtitle>Hex Decode; Oracle CPU; Citrix Vuln Exploited; Exposed Jupyter Notebooks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hex Decode; Oracle CPU; Citrix Vuln Exploited; Exposed Jupyter Notebooks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8708.mp3" length="5075777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8708.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8708</link>
<pubDate>Thu, 19 Oct 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Hiding in Hex<br/>
 <a href="https://isc.sans.edu/diary/Hiding%20in%20Hex/30322">https://isc.sans.edu/diary/Hiding%20in%20Hex/30322</a><br/>
Oracle Quarterly Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpuoct2023.html">https://www.oracle.com/security-alerts/cpuoct2023.html</a><br/>
Citrix Vulnerability Exploited CVE-2023-4966<br/>
 <a href="https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966">https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966</a><br/>
Exposed Jupyter Notebooks Exploited<br/>
 <a href="https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/">https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8708" type="text/plain" language="en" />
<itunes:keywords>jupyter, citrix, oracle, cpu, hex, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8706</itunes:episode>
<itunes:subtitle>SMS Phishing; Fake Paper Ticket QR Codes; Synology Random; Milesight Routers Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SMS Phishing; Fake Paper Ticket QR Codes; Synology Random; Milesight Routers Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8706.mp3" length="5987335" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8706.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8706</link>
<pubDate>Wed, 18 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Changes to SMS Delivery and How it Effects MFA and Phishing<br/>
 <a href="https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320">https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320</a><br/>
Fake Traffic Tickets with QR Code<br/>
 <a href="https://twitter.com/polizeiberlin/status/1713867011837567411">https://twitter.com/polizeiberlin/status/1713867011837567411</a><br/>
Synology NAS DSM Account Takeover: Not Random Randomnumbers<br/>
 <a href="https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure">https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure</a><br/>
Milesight Routers CVe-2023-43261<br/>
 <a href="https://github.com/win3zz/CVE-2023-43261">https://github.com/win3zz/CVE-2023-43261</a><br/>
]]></description>
<itunes:duration>6:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8706" type="text/plain" language="en" />
<itunes:keywords>milesight, routers, synology, random, qr code, traffic tickets, sms, spam, smishing, qishing, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8704</itunes:episode>
<itunes:subtitle>Phishing and Typos; Cisco IOS XE 0-Day; LEMMINGS; SAMBA Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing and Typos; Cisco IOS XE 0-Day; LEMMINGS; SAMBA Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8704.mp3" length="4906060" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8704.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8704</link>
<pubDate>Tue, 17 Oct 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Are Typos Still relevant As An Indicator of Phishing<br/>
 <a href="https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316">https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316</a><br/>
Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln<br/>
 <a href="https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/">https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/</a><br/>
Mail traffic to cancelled domain names<br/>
 <a href="https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names">https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names</a><br/>
SAMBA Update<br/>
 <a href="https://www.samba.org/samba/history/security.html">https://www.samba.org/samba/history/security.html</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8704" type="text/plain" language="en" />
<itunes:keywords>samba, email, domains, netherlands, nl, lemmings, cisco, 0day, typos, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8702</itunes:episode>
<itunes:subtitle>Odd MAC Addresses; Domains as Passwords; PoC for WebKit Vuln; AvosLocker; Darkgate
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd MAC Addresses; Domains as Passwords; PoC for WebKit Vuln; AvosLocker; Darkgate
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8702.mp3" length="4863320" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8702.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8702</link>
<pubDate>Mon, 16 Oct 2023 02:00:01 GMT</pubDate>
<description><![CDATA[What's Normal: Odd Mac Addresses<br/>
 <a href="https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/">https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/</a><br/>
Domain Name Used as Password Captured by DShield Sensor<br/>
 <a href="https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/">https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/</a><br/>
PoC Exploit for CVE-2023-41993<br/>
 <a href="https://github.com/po6ix/POC-for-CVE-2023-41993">https://github.com/po6ix/POC-for-CVE-2023-41993</a><br/>
AvosLocker Ransomware Details<br/>
 <a href="https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf">https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf</a><br/>
DarkGate Spreading via Skype and Teams<br/>
 <a href="https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html">https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8702" type="text/plain" language="en" />
<itunes:keywords>darkcate, avoslocker, poc, ios, ipados, mac addresses, domain names, passwords, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8700</itunes:episode>
<itunes:subtitle>SeroXen RAT in nuGet; Hex IPs; Juniper Patches; Unpatched Squid Issues; @bsidexjax
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SeroXen RAT in nuGet; Hex IPs; Juniper Patches; Unpatched Squid Issues; @bsidexjax
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8700.mp3" length="5537201" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8700.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8700</link>
<pubDate>Fri, 13 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[SeroXen RAT in Typosquatted NuGet Packages<br/>
 <a href="https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/">https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/</a><br/>
Hexadecimal IP Addresses<br/>
 <a href="https://asec.ahnlab.com/en/57635/">https://asec.ahnlab.com/en/57635/</a><br/>
Juniper Vulnerabilities<br/>
 <a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories]">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories]</a><br/>
Unpatched Squid Vulnerabilities<br/>
 <a href="https://joshua.hu/squid-security-audit-35-0days-45-exploits">https://joshua.hu/squid-security-audit-35-0days-45-exploits</a><br/>
BSIDES Jacksonville<br/>
 <a href="https://bsidesjax.org">https://bsidesjax.org</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8700" type="text/plain" language="en" />
<itunes:keywords>bsides, jacksonville, squid, juniper, hexadecimal, shellbot, seroxen, rat, nuget, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8698</itunes:episode>
<itunes:subtitle>Atlasian Exploited; curl vuln; Acrobat Exploited; Goolge Passkey Advances; VBScript Deprectated
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Atlasian Exploited; curl vuln; Acrobat Exploited; Goolge Passkey Advances; VBScript Deprectated
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8698.mp3" length="4897989" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8698.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8698</link>
<pubDate>Thu, 12 Oct 2023 02:00:01 GMT</pubDate>
<description><![CDATA[CVE-2023-22515 Activately Exploited<br/>
 <a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html">https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html</a><br/>
curl SOCKS5 oversized hostname vulnerability CVe-2023-38545<br/>
 <a href="https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304">https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304</a><br/>
Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608<br/>
 <a href="https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog">https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog</a><br/>
Google Makes Passkey the Default<br/>
 <a href="https://blog.google/technology/safety-security/passkeys-default-google-accounts/">https://blog.google/technology/safety-security/passkeys-default-google-accounts/</a><br/>
VBScript Deprecated from Windows<br/>
 <a href="https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features">https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8698" type="text/plain" language="en" />
<itunes:keywords>atlassian, curl, vbscript adobe, acrobat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8696</itunes:episode>
<itunes:subtitle>Rapid Reset; Microsoft Patch Tuesday
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Rapid Reset; Microsoft Patch Tuesday
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8696.mp3" length="6952370" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8696.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8696</link>
<pubDate>Wed, 11 Oct 2023 02:00:01 GMT</pubDate>
<description><![CDATA[http2 rapid reset<br/>
 <a href="https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/">https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/</a><br/>
microsoft patch tuesday<br/>
 <a href="https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300">https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300</a><br/>
]]></description>
<itunes:duration>7:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8696" type="text/plain" language="en" />
<itunes:keywords>microsoft, patch, tuesday, http2, rapid reset, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8694</itunes:episode>
<itunes:subtitle>ZIP DOSTIME and DATE; Updated Magecart Trick; Sophos Exim Flaw; WatchGuard "Feature";
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ZIP DOSTIME and DATE; Updated Magecart Trick; Sophos Exim Flaw; WatchGuard "Feature";
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8694.mp3" length="4826712" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8694.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8694</link>
<pubDate>Tue, 10 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[ZIP's DOSTIME and DOSDATE Formats<br/>
 <a href="https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296">https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296</a><br/>
New Magecart Campaign Abusing 404 Pages<br/>
 <a href="https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer">https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer</a><br/>
Sophos Effected by Exim Flaw<br/>
 <a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln">https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln</a><br/>
Turn OFF This WatchGuard Feature: GuardLapse<br/>
 <a href="https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/">https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8694" type="text/plain" language="en" />
<itunes:keywords>watchguard, guardlaps, sophos, exim, magecart, 404, dosdate, dostime, zip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8692</itunes:episode>
<itunes:subtitle>Binary IPv6; Wireshark Updates; GitHub Secret Scanning; Prerooted Android Devices; curl update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Binary IPv6; Wireshark Updates; GitHub Secret Scanning; Prerooted Android Devices; curl update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8692.mp3" length="5502897" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8692.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8692</link>
<pubDate>Mon, 09 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Binary IPv6 Address Conversion<br/>
 <a href="https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290">https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290</a><br/>
Wireshark Updates<br/>
 <a href="https://www.wireshark.org/">https://www.wireshark.org/</a><br/>
 <br/>
Improved GitHub Secret Scanning<br/>
 <a href="https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/">https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/</a><br/>
Prerooted Android Devices<br/>
 <a href="https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/">https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/</a><br/>
curl update<br/>
 <a href="https://github.com/curl/curl/discussions/12026">https://github.com/curl/curl/discussions/12026</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8692" type="text/plain" language="en" />
<itunes:keywords>curl, android, github, secrets, wireshark, binary, ipv6, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8690</itunes:episode>
<itunes:subtitle>le-hex-to-ip; Cisco Emergency Responder; Loony Tunables PoC; Malicious Python; SMC BMC Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
le-hex-to-ip; Cisco Emergency Responder; Loony Tunables PoC; Malicious Python; SMC BMC Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8690.mp3" length="4827831" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8690.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8690</link>
<pubDate>Fri, 06 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[New tool: le-hex-to-ip.py<br/>
 <a href="https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284">https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284</a><br/>
Cisco Emergency Responder Static Credentials Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9</a><br/>
Loony Tunables PoC CVE-2023-4911<br/>
 <a href="https://haxx.in/files/gnu-acme.py">https://haxx.in/files/gnu-acme.py</a><br/>
Malicious Python Packages<br/>
 <a href="https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/">https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/</a><br/>
Supermicro BMC Vulnerability<br/>
 <a href="https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html">https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8690" type="text/plain" language="en" />
<itunes:keywords>supermicro, bmc, python, loony, tunables, cve, poc, cisco, 911, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 5th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8688</itunes:episode>
<itunes:subtitle>Normal Connections; Apple Patches; Looney Tunables; Atlasian Confluence 0-day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Normal Connections; Apple Patches; Looney Tunables; Atlasian Confluence 0-day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8688.mp3" length="4929144" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8688.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8688</link>
<pubDate>Thu, 05 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Normal Connections<br/>
 <a href="https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/">https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/</a><br/>
Apple Patches<br/>
 <a href="https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280">https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280</a><br/>
Looney Tunables Linux Privilege Escalation<br/>
 <a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so">https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so</a><br/>
Atlasian Confluence Server Vulnerability<br/>
 <a href="https://jira.atlassian.com/browse/CONFSERVER-92475">https://jira.atlassian.com/browse/CONFSERVER-92475</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8688" type="text/plain" language="en" />
<itunes:keywords>atlasian, confluence, 0-day, looney toonables, linux, qualys, apple, patches, normal, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 4th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8686</itunes:episode>
<itunes:subtitle>LLMs for IR; Pytorch Vuln; BING Reads Captchas; Evilproxy and Indeed;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LLMs for IR; Pytorch Vuln; BING Reads Captchas; Evilproxy and Indeed;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8686.mp3" length="5019453" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8686.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8686</link>
<pubDate>Wed, 04 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Are Local LLMs Useful in Incident Response?<br/>
 <a href="https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274">https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274</a><br/>
Pytorch Vulnerability<br/>
 <a href="https://github.com/advisories/GHSA-4mqg-h5jf-j9m7">https://github.com/advisories/GHSA-4mqg-h5jf-j9m7</a><br/>
BING Reads Captchas<br/>
 <a href="https://twitter.com/literallydenis/status/1708283962399846459">https://twitter.com/literallydenis/status/1708283962399846459</a><br/>
Evilproxy vs. Microsoft 365<br/>
 <a href="https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/">https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8686" type="text/plain" language="en" />
<itunes:keywords>evilproxy, microsoft, indeed, phishing, bing, captchas, pytorch, llm, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8684</itunes:episode>
<itunes:subtitle>ZIP Metadata; EXIM Update; ARM GPU Driver Vuln; Bing Malicious Ads; robots.txt AI restrictions;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ZIP Metadata; EXIM Update; ARM GPU Driver Vuln; Bing Malicious Ads; robots.txt AI restrictions;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8684.mp3" length="5081429" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8684.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8684</link>
<pubDate>Tue, 03 Oct 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Friendly Reminder: ZIP Metadata is Not Encrypted<br/>
 <a href="https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268">https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268</a><br/>
EXIM New Version Released<br/>
 <a href="https://www.exim.org/static/doc/security/CVE-2023-zdi.txt">https://www.exim.org/static/doc/security/CVE-2023-zdi.txt</a><br/>
Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations<br/>
 <a href="https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities">https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities</a><br/>
Bing AI Serves Malicous Ads<br/>
 <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot">https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot</a><br/>
Google Announces Robots.txt Ad-Restrictions<br/>
 <a href="https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android">https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8684" type="text/plain" language="en" />
<itunes:keywords>arm, gpu, mali, exim, bing, google, robots.txt, malicious ads, zip, encrypted, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8682</itunes:episode>
<itunes:subtitle>MIME File Analysis; Infostealer; MIME Files; EXIM Update; WS_FTP Exploit;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MIME File Analysis; Infostealer; MIME Files; EXIM Update; WS_FTP Exploit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8682.mp3" length="4636470" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8682.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8682</link>
<pubDate>Mon, 02 Oct 2023 10:10:02 GMT</pubDate>
<description><![CDATA[Analyzing MIME Files: a Quick Tip<br/>
 <a href="https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266">https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266</a><br/>
Infostealers Looking for Password Files<br/>
 <a href="https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/">https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/</a><br/>
Simple Netcat Backdoor<br/>
 <a href="https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/">https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/</a><br/>
EXIM Response to the ZDI Release<br/>
 <a href="https://exim.org/static/doc/security/CVE-2023-zdi.txt">https://exim.org/static/doc/security/CVE-2023-zdi.txt</a><br/>
Exploit for WS_FTP Vulnerability<br/>
 <a href="https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044">https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8682" type="text/plain" language="en" />
<itunes:keywords>ws_ftp, exploit, exim, vulnerability, mime, infostealer, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 29th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8680</itunes:episode>
<itunes:subtitle>Windows IPs; Chrome 0-Day; Unpatched EXIM Vuln; WS-FTP Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows IPs; Chrome 0-Day; Unpatched EXIM Vuln; WS-FTP Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8680.mp3" length="4316690" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8680.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8680</link>
<pubDate>Fri, 29 Sep 2023 02:15:02 GMT</pubDate>
<description><![CDATA[IPv4 Addresses in Little Endian Decimal Format<br/>
 <a href="https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256">https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256</a><br/>
Chrome Update fixes 0-day Vulnerability<br/>
 <a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html</a><br/>
Unpatched EXIM Vulnerabilities<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1469/">https://www.zerodayinitiative.com/advisories/ZDI-23-1469/</a><br/>
WS_FTP Vulnerabilities<br/>
 <a href="https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023">https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023</a><br/>
]]></description>
<itunes:duration>4:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8680" type="text/plain" language="en" />
<itunes:keywords>ws-ftp, exim, chrome, 0-day, ipv4, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8678</itunes:episode>
<itunes:subtitle>GPU Sidechannels; Compromised Routers; More libwebp Confusion; Fake Dependabot 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GPU Sidechannels; Compromised Routers; More libwebp Confusion; Fake Dependabot 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8678.mp3" length="6139093" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8678.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8678</link>
<pubDate>Thu, 28 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[GPU Sidechannel Attack<br/>
 <a href="https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf">https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf</a><br/>
Router Firmware Compromised for Persistent Access<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023</a><br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a</a><br/>
More libwebp vulnerability confusion<br/>
 <a href="https://www.cve.org/CVERecord?id=CVE-2023-5129">https://www.cve.org/CVERecord?id=CVE-2023-5129</a><br/>
 <a href="https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/">https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/</a><br/>
Fake Dependabot Commits<br/>
 <a href="https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/">https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8678" type="text/plain" language="en" />
<itunes:keywords>dependabot, libwebp, router, persistent, backdoor, sidechannel, GPU, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8676</itunes:episode>
<itunes:subtitle>ZeroFont Phishing; Apple Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ZeroFont Phishing; Apple Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8676.mp3" length="5785210" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8676.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8676</link>
<pubDate>Wed, 27 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[A new spint on the ZeroFont phishing technique<br/>
 <a href="https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248">https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248</a><br/>
macOS Sonoma Updates<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252">https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8676" type="text/plain" language="en" />
<itunes:keywords>macos, sonoma, zerofont, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 26th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8674</itunes:episode>
<itunes:subtitle>LuaJIT Malware; NPM systeminformation; Team City Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LuaJIT Malware; NPM systeminformation; Team City Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8674.mp3" length="4597208" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8674.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8674</link>
<pubDate>Tue, 26 Sep 2023 12:10:02 GMT</pubDate>
<description><![CDATA[LuaJIT Malware<br/>
 <a href="https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/">https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/</a><br/>
NPM systeminformation flaw<br/>
 <a href="https://systeminformation.io/security.html">https://systeminformation.io/security.html</a><br/>
Team City Authentication Bypass<br/>
 <a href="https://twitter.com/ptswarm/status/1706223917008834748">https://twitter.com/ptswarm/status/1706223917008834748</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8674" type="text/plain" language="en" />
<itunes:keywords>team city, jetbrains, npm, systeminformation, luajit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 25th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8672</itunes:episode>
<itunes:subtitle>Laravel Scans; Backdoored WinRAR PoC; Fake Booking.com; @BSidesJAX
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Laravel Scans; Backdoored WinRAR PoC; Fake Booking.com; @BSidesJAX
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8672.mp3" length="6306232" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8672.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8672</link>
<pubDate>Mon, 25 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Scanning for Laravel - a PHP Framework for Web Artisants<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/">https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/</a><br/>
Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT<br/>
 <a href="https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/">https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/</a><br/>
Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests<br/>
 <a href="https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality">https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality</a><br/>
BSides JAX October 14th<br/>
 <a href="https://www.bsidesjax.org/">https://www.bsidesjax.org/</a><br/>
 tickets: <a href="https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator">https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator</a><br/>
]]></description>
<itunes:duration>7:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8672" type="text/plain" language="en" />
<itunes:keywords>bsides, jax, phishing, hotels, booking, venomrat, winrar, laravel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 22nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8670</itunes:episode>
<itunes:subtitle>Apple 0-Days; WebP Vuln Details; MoveIT Vuln; Win11 Improved Passkeys
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple 0-Days; WebP Vuln Details; MoveIT Vuln; Win11 Improved Passkeys
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8670.mp3" length="5384640" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8670.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8670</link>
<pubDate>Fri, 22 Sep 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Apple Patches Three 0-Days<br/>
 <a href="https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238">https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238</a><br/>
WebP Vulnerability<br/>
 <a href="https://blog.isosceles.com/the-webp-0day/">https://blog.isosceles.com/the-webp-0day/</a><br/>
MOVEit Transfer Service Pack<br/>
 <a href="https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023">https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023</a><br/>
Improved Passkey Support in Windows 11<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/">https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8670" type="text/plain" language="en" />
<itunes:keywords>moveit, windows 11, passkeys, apple, webp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 21st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8668</itunes:episode>
<itunes:subtitle>DNS TTls; Snatch Ransomware; npm packages; nagios xi vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS TTls; Snatch Ransomware; npm packages; nagios xi vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8668.mp3" length="5317132" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8668.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8668</link>
<pubDate>Thu, 21 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[What's Normal: DNS TTL Values<br/>
 <a href="https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/">https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/</a><br/>
CISA Highlights Snatch Ransomware<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a</a><br/>
npm packages caught exfiltrating Kubernetes config, SSH keys<br/>
 <a href="https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys">https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys</a><br/>
Nagios XI Vulnerabilities<br/>
 <a href="https://outpost24.com/blog/nagios-xi-vulnerabilities/">https://outpost24.com/blog/nagios-xi-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8668" type="text/plain" language="en" />
<itunes:keywords>nagios, npm, kubernetes, ssh, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8666</itunes:episode>
<itunes:subtitle>Adobe Experience Manager; Trend Micro 0-Day; SprySOCKS Backdoor; Gitlab Patches; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe Experience Manager; Trend Micro 0-Day; SprySOCKS Backdoor; Gitlab Patches; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8666.mp3" length="4825381" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8666.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8666</link>
<pubDate>Wed, 20 Sep 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230">https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230</a><br/>
Trend Micro Apex One 0-day<br/>
 <a href="https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US">https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US</a><br/>
SprySOCKS Backdoor<br/>
 <a href="https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html">https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html</a><br/>
GitLab Patches<br/>
 <a href="https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/">https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8666" type="text/plain" language="en" />
<itunes:keywords>gitlab, sprysocks, backdoor, trend micro, apex one, adobe, experience, manager, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 19th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8664</itunes:episode>
<itunes:subtitle>VPN Recon Scans; iOS Update; Juniper Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VPN Recon Scans; iOS Update; Juniper Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8664.mp3" length="4868302" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8664.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8664</link>
<pubDate>Tue, 19 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Internet Wide Multi VPN Search from Single /24 Network<br/>
 <a href="https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226">https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226</a><br/>
iOS/iPadOS/tvOS/WatchOS Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Juniper Vuln Details/Exploit CVE-2023-36845<br/>
 <a href="https://vulncheck.com/blog/juniper-cve-2023-36845">https://vulncheck.com/blog/juniper-cve-2023-36845</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8664" type="text/plain" language="en" />
<itunes:keywords>juniper, exploit, ios, apple, ipados, vpn, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8662</itunes:episode>
<itunes:subtitle>MFA Issue; QNAP Patches; Keychain Passkey Access; Fortinet and vBulletin XSS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MFA Issue; QNAP Patches; Keychain Passkey Access; Fortinet and vBulletin XSS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8662.mp3" length="5166148" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8662.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8662</link>
<pubDate>Mon, 18 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[When MFA isn't actually MFA<br/>
 <a href="https://retool.com/blog/mfa-isnt-mfa/">https://retool.com/blog/mfa-isnt-mfa/</a><br/>
QNAP Patches<br/>
 <a href="https://www.qnap.com/en/security-advisories?ref=security_advisory_details">https://www.qnap.com/en/security-advisories?ref=security_advisory_details</a><br/>
Chrome able to use Apple Keychain Passkeys<br/>
 <a href="https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/">https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/</a><br/>
Fortinet XSS<br/>
 <a href="https://fortiguard.fortinet.com/psirt/FG-IR-23-106">https://fortiguard.fortinet.com/psirt/FG-IR-23-106</a><br/>
vBulletin XSS<br/>
 <a href="https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c">https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8662" type="text/plain" language="en" />
<itunes:keywords>vbulletin, fortinet, xss, chrome, passkeys, keychain, qnap, mfa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8660</itunes:episode>
<itunes:subtitle>qemu rPi emulation; ncurses vuln; windows themes PoC; 3AM ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
qemu rPi emulation; ncurses vuln; windows themes PoC; 3AM ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8660.mp3" length="5030003" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8660.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8660</link>
<pubDate>Fri, 15 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G<br/>
 <a href="https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216">https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216</a><br/>
Uncursing the ncurses memory corruption vulnerabilities<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/">https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/</a><br/>
Arbitrary code execution via Windows Themes (CVE-2023-38146)<br/>
 <a href="https://exploits.forsale/themebleed/">https://exploits.forsale/themebleed/</a><br/>
3AM Ransomware used if LockBit Fails<br/>
 <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8660" type="text/plain" language="en" />
<itunes:keywords>dshield, qemu, raspberry pi, ncurses, windows themes, lockbit, 3am, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8658</itunes:episode>
<itunes:subtitle>Fake FreeDownloadManager; Foxit PDF Reader Update; macOS Metastealer; blocking NTML Hashes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake FreeDownloadManager; Foxit PDF Reader Update; macOS Metastealer; blocking NTML Hashes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8658.mp3" length="5099838" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8658.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8658</link>
<pubDate>Thu, 14 Sep 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Backdoored Free DownloadManager<br/>
 <a href="https://securelist.com/backdoored-free-download-manager-linux-malware/110465/">https://securelist.com/backdoored-free-download-manager-linux-malware/110465/</a><br/>
Foxit PDF Reader Updates<br/>
 <a href="https://www.foxit.com/support/security-bulletins.html">https://www.foxit.com/support/security-bulletins.html</a><br/>
macOS MetaStealer: New Family of Obfuscated Go Infostealers<br/>
 <a href="https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/">https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/</a><br/>
Windows 11 to Support Blocking SMB NTLM Hashes<br/>
 <a href="https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206">https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8658" type="text/plain" language="en" />
<itunes:keywords>macos, metastealer, windows 11, smb, ntlm, downloadmanager, foxit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8656</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; OpenSSL 1.1.1 EoL; Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; OpenSSL 1.1.1 EoL; Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8656.mp3" length="5313872" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8656.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8656</link>
<pubDate>Wed, 13 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214">https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214</a><br/>
OpenSSL 1.1.1 End of Life<br/>
 <a href="https://www.openssl.org/blog/blog/2023/09/11/eol-111/">https://www.openssl.org/blog/blog/2023/09/11/eol-111/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8656" type="text/plain" language="en" />
<itunes:keywords>adobe, openssl, microsoft, patch, tuesday, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8654</itunes:episode>
<itunes:subtitle>More Apple Patches; Wiki Eve Attack; Google Looker Studio Phish; HPE One View Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Apple Patches; Wiki Eve Attack; Google Looker Studio Phish; HPE One View Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8654.mp3" length="5240752" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8654.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8654</link>
<pubDate>Tue, 12 Sep 2023 10:10:01 GMT</pubDate>
<description><![CDATA[Apple Patches Older Operating Systems<br/>
 <a href="https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210">https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210</a><br/>
Wi-Fi Enabled Practical Keystroke Eavesdropping<br/>
 <a href="https://arxiv.org/pdf/2309.03492.pdf">https://arxiv.org/pdf/2309.03492.pdf</a><br/>
Phishing via Google Looker Studio<br/>
 <a href="https://blog.checkpoint.com/security/phishing-via-google-looker-studio">https://blog.checkpoint.com/security/phishing-via-google-looker-studio</a><br/>
HPE One View Authentication Bypass<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8654" type="text/plain" language="en" />
<itunes:keywords>apple, patches, ios, macos, wifi, keystroke logging, phishing, google, looker, phe, oneview, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8652</itunes:episode>
<itunes:subtitle>Honeypot Data and Powershell; Apple 0-Day Details; Cisco 0-Day Exploited; Odd Password Solution
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot Data and Powershell; Apple 0-Day Details; Cisco 0-Day Exploited; Odd Password Solution
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8652.mp3" length="6043796" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8652.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8652</link>
<pubDate>Mon, 11 Sep 2023 03:25:01 GMT</pubDate>
<description><![CDATA[Augmenting Honeypot Logs<br/>
 <a href="https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204">https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204</a><br/>
More details about Apple 0-day<br/>
 <a href="https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/">https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/</a><br/>
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs</a><br/>
Odd Password Solution<br/>
 <a href="https://notpickard.com/@rdp/111009868239846779">https://notpickard.com/@rdp/111009868239846779</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8652" type="text/plain" language="en" />
<itunes:keywords>password, cisco, taiwan, keyboard, honeypot, logs, augmentation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8650</itunes:episode>
<itunes:subtitle>Apple Patches 0-Days; iOS Scareware; Aruba and TP Link Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patches 0-Days; iOS Scareware; Aruba and TP Link Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8650.mp3" length="4600296" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8650.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8650</link>
<pubDate>Fri, 08 Sep 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Apple Patches 0-Days<br/>
 <a href="https://isc.sans.edu/diary/30200">https://isc.sans.edu/diary/30200</a><br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
iOS Fleezeware/Scareware<br/>
 <a href="https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198">https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198</a><br/>
Aruba Vulnerabilities<br/>
 <a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt</a><br/>
TP Link Vulnerabilities<br/>
 <a href="https://jvn.jp/en/vu/JVNVU99392903/">https://jvn.jp/en/vu/JVNVU99392903/</a><br/>
]]></description>
<itunes:duration>5:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8650" type="text/plain" language="en" />
<itunes:keywords>tplink, aruba, ios, fleezeware, scareware, apple, 0-day, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8648</itunes:episode>
<itunes:subtitle>DNS Security; MSFT Key Loss Details; Android Updates; Chrome Updates; Atlas VPN Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Security; MSFT Key Loss Details; Android Updates; Chrome Updates; Atlas VPN Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8648.mp3" length="5112449" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8648.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8648</link>
<pubDate>Thu, 07 Sep 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Security Related DNS Records<br/>
 <a href="https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194">https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194</a><br/>
Microsoft Reveleas Details about Key Loss<br/>
 <a href="https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/">https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/</a><br/>
September Android Updates<br/>
 <a href="https://source.android.com/docs/security/bulletin/2023-09-01">https://source.android.com/docs/security/bulletin/2023-09-01</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html</a><br/>
Atlas VPN Tunnel Termination Vulnerability<br/>
 <a href="https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/">https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8648" type="text/plain" language="en" />
<itunes:keywords>atlas, vpn, google, chrome, android, microsoft, key loss, dns, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8646</itunes:episode>
<itunes:subtitle>Honeypot Usernames; TPM LUKS Bypass; Social Engineering Helpdesks for MFA Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot Usernames; TPM LUKS Bypass; Social Engineering Helpdesks for MFA Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8646.mp3" length="4991430" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8646.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8646</link>
<pubDate>Wed, 06 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Common Usernames Submitted to Honeypots<br/>
 <a href="https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188">https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188</a><br/>
TPM LUKS Bypass<br/>
 <a href="https://pulsesecurity.co.nz/advisories/tpm-luks-bypass">https://pulsesecurity.co.nz/advisories/tpm-luks-bypass</a><br/>
Cross Tenant Impersonation Prevention and Detection<br/>
 <a href="https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection">https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8646" type="text/plain" language="en" />
<itunes:keywords>2fa, impersonation, social engineering, luks, tpm, usernames, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 5th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8644</itunes:episode>
<itunes:subtitle>Password Origins; YARA Rules for Obfuscated Strings; VMware Aria Keys; Windows TLS 1.0/1.1;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Password Origins; YARA Rules for Obfuscated Strings; VMware Aria Keys; Windows TLS 1.0/1.1;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8644.mp3" length="5581764" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8644.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8644</link>
<pubDate>Tue, 05 Sep 2023 02:00:02 GMT</pubDate>
<description><![CDATA[What is the Origin of Passwords Submitted to Honeypots<br/>
 <a href="https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182">https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182</a><br/>
Creating a YARA Rule to Detect Obfuscated Strings<br/>
 <a href="https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186">https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186</a><br/>
VMware Aria Operations for Networks Hardcoded Keys 2023-34039 <br/>
 <a href="https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/">https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/</a><br/>
 <a href="https://github.com/sinsinology/CVE-2023-34039/">https://github.com/sinsinology/CVE-2023-34039/</a><br/>
Windows will Disable TLS 1.0/1.1<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8644" type="text/plain" language="en" />
<itunes:keywords>windows, tls, vmware, aira, ssh, keys, yara, passwords, origins, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8642</itunes:episode>
<itunes:subtitle>Cheap Phishing; Unpinnable Actions; Cisco Brute Force; Splunk Vuln; TLD issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cheap Phishing; Unpinnable Actions; Cisco Brute Force; Splunk Vuln; TLD issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8642.mp3" length="5631523" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8642.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8642</link>
<pubDate>Fri, 01 Sep 2023 02:00:01 GMT</pubDate>
<description><![CDATA[The low, low cost of (committing) cybercrime<br/>
 <a href="https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/">https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/</a><br/>
Unpinnable Github Actions<br/>
 <a href="https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/">https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/</a><br/>
Exploitation of Cisco ASA SSL VPNs<br/>
 <a href="https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/">https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/</a><br/>
Splunk Vulnerabilities<br/>
 <a href="https://advisory.splunk.com/advisories">https://advisory.splunk.com/advisories</a><br/>
Top Level Domain Issues<br/>
 <a href="https://blog.talosintelligence.com/whats-in-a-name/">https://blog.talosintelligence.com/whats-in-a-name/</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8642" type="text/plain" language="en" />
<itunes:keywords>tld, splunk, cisco, asa, ssl vpn, github, phishing, actions, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 31st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8640</itunes:episode>
<itunes:subtitle>Hurricane Prep; Notepad++ Vulns; 7zip Vuln; BGP Error Handling;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hurricane Prep; Notepad++ Vulns; 7zip Vuln; BGP Error Handling;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8640.mp3" length="4991153" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8640.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8640</link>
<pubDate>Thu, 31 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Home Office/Small Business Hurricane Prep<br/>
 <a href="https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166">https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166</a><br/>
Notepad++ Vulnerabilities<br/>
 <a href="https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/">https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/</a><br/>
7-Zip Vulnerability<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1164/">https://www.zerodayinitiative.com/advisories/ZDI-23-1164/</a><br/>
BGP Error Handling Issues<br/>
 <a href="https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling">https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8640" type="text/plain" language="en" />
<itunes:keywords>bgp, 7zip, notepad++, hurricane, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 30th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8638</itunes:episode>
<itunes:subtitle>Website Survivaltime; ActiveMime Maldocs; RocketMQ Exploited; ManageEnging Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Website Survivaltime; ActiveMime Maldocs; RocketMQ Exploited; ManageEnging Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8638.mp3" length="5395050" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8638.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8638</link>
<pubDate>Wed, 30 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Survival Time for Web Sites<br/>
 <a href="https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170">https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170</a><br/>
PDF/ActiveMime Polyglot Maldocs<br/>
 <a href="https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html">https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html</a><br/>
 <a href="https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/">https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/</a><br/>
RocketMQ Vulnerability Exploited<br/>
 <a href="https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability">https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability</a><br/>
ManageEngine Vulnerabilty<br/>
 <a href="https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html">https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html</a><br/>
 <br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8638" type="text/plain" language="en" />
<itunes:keywords>manageengine, zoho, vulnerability, rocketmq, exploit, pdf, activemime, polyglot, survival time, websites, certificate transparency, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 29th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8636</itunes:episode>
<itunes:subtitle>WINRAR Exploit Analysis; Juniper PoC; Exchange EP Default; Rust Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WINRAR Exploit Analysis; Juniper PoC; Exchange EP Default; Rust Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8636.mp3" length="5786010" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8636.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8636</link>
<pubDate>Tue, 29 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Analysis of RAR Exploit Files (CVE-2023-38831)<br/>
 <a href="https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164">https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164</a><br/>
Juniper Exploit  CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847<br/>
 <a href="https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/">https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/</a><br/>
Microsoft Will Enabled Extended Protection for Exchange Server by Default<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849">https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849</a><br/>
Rust Malware Stages on Crates.io<br/>
 <a href="https://blog.phylum.io/rust-malware-staged-on-crates-io/">https://blog.phylum.io/rust-malware-staged-on-crates-io/</a><br/>
 <br/>
SANS Community Night London Signup<br/>
 <a href="https://www.sans.org/mlp/community-night-cloud-security-london-september-2023">https://www.sans.org/mlp/community-night-cloud-security-london-september-2023</a>]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8636" type="text/plain" language="en" />
<itunes:keywords>rar, winrar, exploit, juniper, poc, exchange, ep, cu, rust, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8634</itunes:episode>
<itunes:subtitle>Postgresql C2; MacOS Network Connections; Fake/Bad CVEs; Windows Cert Confusion; Bad NPM Package
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Postgresql C2; MacOS Network Connections; Fake/Bad CVEs; Windows Cert Confusion; Bad NPM Package
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8634.mp3" length="5869580" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8634.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8634</link>
<pubDate>Mon, 28 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Python Malware Using Postgresql for C2 Communications<br/>
 <a href="https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158">https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158</a><br/>
macOS: Who is Behind This Network Connection?<br/>
 <a href="https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160">https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160</a><br/>
CVE-2020-19909 Is Everything that is Wrong with CVEs<br/>
 <a href="https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/">https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/</a><br/>
Windows Certificate Confusion<br/>
 <a href="https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/">https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/</a><br/>
NPM E-Mail Validator Package Malware<br/>
 <a href="https://blog.phylum.io/npm-emails-validator-package-malware/">https://blog.phylum.io/npm-emails-validator-package-malware/</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8634" type="text/plain" language="en" />
<itunes:keywords>npm, windows, certificate, cve-2020-19909, curl, macos, python, postgresql, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 25th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8632</itunes:episode>
<itunes:subtitle>Keyboard Walk; Barracuda ESG Warning; Ivanti Sentry Update; Smoke Loader Geolocation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Keyboard Walk; Barracuda ESG Warning; Ivanti Sentry Update; Smoke Loader Geolocation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8632.mp3" length="5232981" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8632.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8632</link>
<pubDate>Fri, 25 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT<br/>
 <a href="https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152">https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152</a><br/>
FBI Warns of Persistent Barracuda Backdoors<br/>
 <a href="https://www.ic3.gov/Media/News/2023/230823.pdf">https://www.ic3.gov/Media/News/2023/230823.pdf</a><br/>
Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035<br/>
 <a href="https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/">https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/</a><br/>
Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware<br/>
 <a href="https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware">https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8632" type="text/plain" language="en" />
<itunes:keywords>smoke loader, whiffy, recon, wifi, ivanty, sentry, fbi, barracuda, qwerty, sans.edu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8630</itunes:episode>
<itunes:subtitle>XLAM Files; WinRAR 0-Day (new!); Aruba Vulnerablities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XLAM Files; WinRAR 0-Day (new!); Aruba Vulnerablities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8630.mp3" length="4783758" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8630.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8630</link>
<pubDate>Thu, 24 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[More Exotic Excel Files Dropping AgentTesla<br/>
 <a href="https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150">https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150</a><br/>
CVE-2023-38831 WinRAR Vulnerability Exploited<br/>
 <a href="https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/">https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/</a><br/>
Aruba Vulnerabilities<br/>
 <a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8630" type="text/plain" language="en" />
<itunes:keywords>aruba, winrar, xlam, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 23rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8628</itunes:episode>
<itunes:subtitle>Fernet Encryption; inotify triage; Coldfusion Exploit; Openfire Exploit; New XLoader;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fernet Encryption; inotify triage; Coldfusion Exploit; Openfire Exploit; New XLoader;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8628.mp3" length="5372452" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8628.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8628</link>
<pubDate>Wed, 23 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Fernet Encryption in Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/">https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/</a><br/>
Malware Triage With Inotify Tools<br/>
 <a href="https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/">https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/</a><br/>
Adobe Coldfusion Exploited<br/>
 <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br/>
Openfire Admin Console Vulnerability Exploited<br/>
 <a href="https://vulncheck.com/blog/openfire-cve-2023-32315">https://vulncheck.com/blog/openfire-cve-2023-32315</a><br/>
XLoader Mac Malware Updates<br/>
 <a href="https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/">https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8628" type="text/plain" language="en" />
<itunes:keywords>xloader, mac, openfire, adobe, coldfusion, malwre, inotify, triage, fernet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 22nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8626</itunes:episode>
<itunes:subtitle>SystemBC Scans; Exchange SU Rerelease; Ivanti Exploit; DUO Outages; mTLS vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SystemBC Scans; Exchange SU Rerelease; Ivanti Exploit; DUO Outages; mTLS vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8626.mp3" length="5444306" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8626.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8626</link>
<pubDate>Tue, 22 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[SystemBC Scans and ProxyNation<br/>
 <a href="https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138">https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138</a><br/>
 <a href="https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware">https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware</a><br/>
Exchange Server Security Update Re-Release<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025">https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025</a><br/>
Ivanti Sentry Vulnerability Exploited<br/>
 <a href="https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US">https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US</a><br/>
DUO Security Outage<br/>
 <a href="https://status.duo.com/incidents/rw7g0q7ztj8f">https://status.duo.com/incidents/rw7g0q7ztj8f</a><br/>
mTLS Vulnerabilities<br/>
 <a href="https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/">https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8626" type="text/plain" language="en" />
<itunes:keywords>mtls, duo, ivanti, sentry, exchange, rerelease, update, systembc, proxy, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 21st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8624</itunes:episode>
<itunes:subtitle>Zalando Phish/RAT; WinRAR Code Exec; Hotmail SPF Fail; Ivacy VPN Cert Abused; Chrome Extension Warning;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zalando Phish/RAT; WinRAR Code Exec; Hotmail SPF Fail; Ivacy VPN Cert Abused; Chrome Extension Warning;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8624.mp3" length="5002495" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8624.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8624</link>
<pubDate>Mon, 21 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[From a Zalando Phish to a RAT<br/>
 <a href="https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136">https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136</a><br/>
RARLAB WinRAR Recovery Volume Vulnerability<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1152/">https://www.zerodayinitiative.com/advisories/ZDI-23-1152/</a><br/>
Hotmail SPF Record Error Leads to spam false positives<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/">https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/</a><br/>
Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector<br/>
 <a href="https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/">https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/</a><br/>
Google Chrome to Warn Users of Malicious Extensions<br/>
 <a href="https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/">https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8624" type="text/plain" language="en" />
<itunes:keywords>chrome, extensions, warning, vpn, cert, winrar, zelando, phishing, spf, hotmail, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8622</itunes:episode>
<itunes:subtitle>Whitespaces; Fake Airplane Mode; LinkedIn Attacks; Robot Vacuum Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Whitespaces; Fake Airplane Mode; LinkedIn Attacks; Robot Vacuum Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8622.mp3" length="5121971" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8622.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8622</link>
<pubDate>Fri, 18 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Command Line Parsing - Are These Really Unique Strings?<br/>
 <a href="https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126">https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126</a><br/>
iOS 16 Fake Airplane Mode<br/>
 <a href="https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/">https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/</a><br/>
LinkedIn Attacks<br/>
 <a href="https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/">https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/</a><br/>
Robot Vacuum Privacy Issues<br/>
 <a href="https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf">https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf</a><br/>
 <a href="https://dontvacuum.me/">https://dontvacuum.me/</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8622" type="text/plain" language="en" />
<itunes:keywords>robots, vacuum, privacy, linkedin, ios, airplane mode, whitespaces, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8620</itunes:episode>
<itunes:subtitle>PowerShell Gallery Malware; Windows Time Issues; Malicious QR Codes; Citrix Scanner
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PowerShell Gallery Malware; Windows Time Issues; Malicious QR Codes; Citrix Scanner
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8620.mp3" length="5915799" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8620.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8620</link>
<pubDate>Thu, 17 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks<br/>
 <a href="https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks">https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks</a><br/>
Windows Random Time Issues<br/>
 <a href="https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/">https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/</a><br/>
Energy Company Targeted in QR Code Campaign<br/>
 <a href="https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/">https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/</a><br/>
New Citrix Scanner from Mandiant<br/>
 <a href="https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner">https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner</a><br/>
]]></description>
<itunes:duration>6:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8620" type="text/plain" language="en" />
<itunes:keywords>citrix, energey, qr, time, windows, powershell, gallery, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8618</itunes:episode>
<itunes:subtitle>macOS Background Task Manager; Ivanti Avalanche Vuln; Synology Cloud Access Vuln; Fake Beta Crypto Apps
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
macOS Background Task Manager; Ivanti Avalanche Vuln; Synology Cloud Access Vuln; Fake Beta Crypto Apps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8618.mp3" length="5255461" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8618.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8618</link>
<pubDate>Wed, 16 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[macOS Background Task Manager Bypass<br/>
 <a href="https://www.wired.com/story/apple-mac-background-task-management-flaw/">https://www.wired.com/story/apple-mac-background-task-management-flaw/</a><br/>
Ivanti Avalanche Vulnerability<br/>
 <a href="https://www.tenable.com/security/research/tra-2023-27">https://www.tenable.com/security/research/tra-2023-27</a><br/>
Exploiting Synology NAS Cloud Connectivity<br/>
 <a href="https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition">https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition</a><br/>
Fake Crypto Currency Apps Offered as "Beta" versions<br/>
 <a href="https://www.ic3.gov/Media/Y2023/PSA230814">https://www.ic3.gov/Media/Y2023/PSA230814</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8618" type="text/plain" language="en" />
<itunes:keywords>fbi, crypto, apps, beta, synology, nas, cloud, ivanti, avalanche, macos, background task manager, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8616</itunes:episode>
<itunes:subtitle>PDFiD False Pos; CVE-2023-32019 Fix Update; CyberPower/Dataprobe Vulns; Ford Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDFiD False Pos; CVE-2023-32019 Fix Update; CyberPower/Dataprobe Vulns; Ford Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8616.mp3" length="5220656" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8616.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8616</link>
<pubDate>Tue, 15 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[PDFiD False Positives Revisited<br/>
 <a href="https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122">https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122</a><br/>
CVE-2023-32019 Fix Enabled by Default;<br/>
 <a href="https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080">https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080</a><br/>
CyberPower and Dataprobe Vulnerabilities<br/>
 <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html">https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html</a><br/>
Ford WiFi Driver Vulnerability<br/>
 <a href="https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&ref_url=https%253A%252F%252Fmedia.ford.com%252F">https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&ref_url=https%253A%252F%252Fmedia.ford.com%252F</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8616" type="text/plain" language="en" />
<itunes:keywords>ford, wifi, cyberpower, dataprobe, cve-2023-32019, microsoft, pdfid, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8614</itunes:episode>
<itunes:subtitle>Python Anti-Debugging; Zoom Zero Touch Vuln; DNS Spoofing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Anti-Debugging; Zoom Zero Touch Vuln; DNS Spoofing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8614.mp3" length="4931025" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8614.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8614</link>
<pubDate>Mon, 14 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Show Me All Your Windows<br/>
 <a href="https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116">https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116</a><br/>
Zero Touch Pwn<br/>
 <a href="https://blog.syss.com/posts/zero-touch-pwn/">https://blog.syss.com/posts/zero-touch-pwn/</a><br/>
Maginot DNS Spoofing Attack<br/>
 <a href="https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang">https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8614" type="text/plain" language="en" />
<itunes:keywords>windows, python, anti-debugging, zero touch, zoom, dns, spoofing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8612</itunes:episode>
<itunes:subtitle>SQL Auth Weakness; Windows Defender Pretender; Dell Compellent Static Key; Sogou Keyboard Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SQL Auth Weakness; Windows Defender Pretender; Dell Compellent Static Key; Sogou Keyboard Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8612.mp3" length="5360855" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8612.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8612</link>
<pubDate>Fri, 11 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Some things never change, such as SQL Authentication "Encryption"<br/>
 <a href="https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112">https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112</a><br/>
Defender Pretender: When Windows Defender Updates Become a Security Risk<br/>
 <a href="https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706">https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706</a><br/>
Dell Compellent Hardcoded Key<br/>
 <a href="https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities">https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities</a><br/>
Vulnerabilities in Sogou Keyboard<br/>
 <a href="https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/">https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8612" type="text/plain" language="en" />
<itunes:keywords>sogou, keyboard, dell, compellent, hardcoded, defender, pretender, sql, sql server, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8610</itunes:episode>
<itunes:subtitle>Tunnelcrack VPN vuln; Mozilla VPN Issue; Exchange Patch Trouble; VSCode Secrets
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tunnelcrack VPN vuln; Mozilla VPN Issue; Exchange Patch Trouble; VSCode Secrets
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8610.mp3" length="5552319" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8610.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8610</link>
<pubDate>Thu, 10 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Tunnelcrack VPN Vulnerability<br/>
 <a href="https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf">https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf</a><br/>
Mozilla VPN Vulnerablity<br/>
 <a href="https://www.openwall.com/lists/oss-security/2023/08/03/1">https://www.openwall.com/lists/oss-security/2023/08/03/1</a><br/>
Non English Exchange Server Patch Issues<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true</a><br/>
VSCode Token Security<br/>
 <a href="https://cycode.com/blog/exposing-vscode-secrets/">https://cycode.com/blog/exposing-vscode-secrets/</a><br/>
Weekly Updates for Google Chrome<br/>
 <a href="https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html">https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8610" type="text/plain" language="en" />
<itunes:keywords>google, chrome, updates, vscode, token, security, exhcnage, patch, problems, vpn, mozilla, tunnelcrack, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8608</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8608.mp3" length="5373505" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8608.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8608</link>
<pubDate>Wed, 09 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106">https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8608" type="text/plain" language="en" />
<itunes:keywords>adobe, adobe commerce, reader, acrobat, microsoft, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8606</itunes:episode>
<itunes:subtitle>Research Scan IPs; OpenBullet Malware; Cloudflare Tunnel Abuse;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Research Scan IPs; OpenBullet Malware; Cloudflare Tunnel Abuse;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8606.mp3" length="5723161" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8606.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8606</link>
<pubDate>Tue, 08 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Update: Researchers Scanning the Internet<br/>
 <a href="https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102">https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102</a><br/>
Malicious OpenBullet Configuration Files<br/>
 <a href="https://www.kasada.io/threat-intel-openbullet-malware/">https://www.kasada.io/threat-intel-openbullet-malware/</a><br/>
Abusing Cloudflare Tunnels<br/>
 <a href="https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/">https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8606" type="text/plain" language="en" />
<itunes:keywords>cloudflare, cloudflared, openbullet, internet, scanning, research, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8604</itunes:episode>
<itunes:subtitle>Leaked Credentials; PaperCut RCE Vuln; MSFT Fixes Power Platform Bug; Token Theft Playbook;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Leaked Credentials; PaperCut RCE Vuln; MSFT Fixes Power Platform Bug; Token Theft Playbook;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8604.mp3" length="4727098" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8604.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8604</link>
<pubDate>Mon, 07 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Are Leaked Credential Dumps Used by Attackers?<br/>
 <a href="https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098">https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098</a><br/>
New PaperCut RCE Vulnerability<br/>
 <a href="https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/">https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/</a><br/>
Microsoft mitigates Power Platform Custom Code information disclosure vulnerability<br/>
 <a href="https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/">https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/</a><br/>
Microsoft Publishes Token theft Playbook<br/>
 <a href="https://learn.microsoft.com/en-us/security/operations/token-theft-playbook">https://learn.microsoft.com/en-us/security/operations/token-theft-playbook</a><br/>
]]></description>
<itunes:duration>5:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8604" type="text/plain" language="en" />
<itunes:keywords>microsoft, cloud, azure, playbook, tokens, power platform, papercut, rce, credential dump, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 4th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8602</itunes:episode>
<itunes:subtitle>From LNK to BAT; MSFT Teams Scams; MSFT Office LOLBAS; Android App Versioning; Aruba; Mitel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
From LNK to BAT; MSFT Teams Scams; MSFT Office LOLBAS; Android App Versioning; Aruba; Mitel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8602.mp3" length="5001034" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8602.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8602</link>
<pubDate>Fri, 04 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[From small LNK to large malicious BAT file with zero VT score<br/>
 <a href="https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094">https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094</a><br/>
Social Engineering via Microsoft Teams<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/">https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/</a><br/>
Automating the Search for LOLBAS<br/>
 <a href="https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/">https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/</a><br/>
Sneaky Versioning Used to Bypass Scanners<br/>
 <a href="https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html">https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html</a><br/>
Aruba Patches<br/>
 <a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt</a><br/>
Mitel Patches<br/>
 <a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8602" type="text/plain" language="en" />
<itunes:keywords>versioning, android, google play store, aruba, mitel, lolbas, teams, lnk, bat, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8600</itunes:episode>
<itunes:subtitle>Zeek on Windows; More Ivanti Vulns; Salesforce Phishing; AWS SSM Agent Abuse;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zeek on Windows; More Ivanti Vulns; Salesforce Phishing; AWS SSM Agent Abuse;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8600.mp3" length="5460335" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8600.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8600</link>
<pubDate>Thu, 03 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Zeek and Defender Endpoint<br/>
 <a href="https://isc.sans.edu/diary/Zeek%20and%20Defender%20Endpoint/30088">https://isc.sans.edu/diary/Zeek%20and%20Defender%20Endpoint/30088</a><br/>
New Ivanti MobileIron Core Vulnerability<br/>
 <a href="https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US">https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US</a><br/>
Salesforce Phishing<br/>
 <a href="https://labs.guard.io/phishforce-vulnerability-uncovered-in-salesforces-email-services-exploited-for-phishing-32024ad4b5fa">https://labs.guard.io/phishforce-vulnerability-uncovered-in-salesforces-email-services-exploited-for-phishing-32024ad4b5fa</a><br/>
Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan<br/>
 <a href="https://www.mitiga.io/blog/abusing-the-amazon-web-services-ssm-agent-as-a-remote-access-trojan">https://www.mitiga.io/blog/abusing-the-amazon-web-services-ssm-agent-as-a-remote-access-trojan</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8600" type="text/plain" language="en" />
<itunes:keywords>Amazone, AWS, EC2, SSM, RAT, salesforce, meta, phishing, ivanti, mobileiron, zeek, defender, endpoint, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8598</itunes:episode>
<itunes:subtitle>DNS over HTTPS; Airgap Bridging Malware; Google Inactive Accounts;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS over HTTPS; Airgap Bridging Malware; Google Inactive Accounts;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8598.mp3" length="4758671" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8598.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8598</link>
<pubDate>Wed, 02 Aug 2023 02:00:01 GMT</pubDate>
<description><![CDATA[DNS Over HTTPS Summary<br/>
 <a href="https://isc.sans.edu/diary/Summary%20of%20DNS%20over%20HTTPS%20requests%20against%20our%20honeypots./30084">https://isc.sans.edu/diary/Summary%20of%20DNS%20over%20HTTPS%20requests%20against%20our%20honeypots./30084</a><br/>
Malware Infects Airgapped Networks<br/>
 <a href="https://usa.kaspersky.com/about/press-releases/2023_kaspersky-uncovers-malware-for-targeted-data-exfiltration-from-air-gapped-environments">https://usa.kaspersky.com/about/press-releases/2023_kaspersky-uncovers-malware-for-targeted-data-exfiltration-from-air-gapped-environments</a><br/>
Google Deleting Inactive Accounts<br/>
 <a href="https://support.google.com/accounts/answer/12418290?visit_id=638264210155158507-1346504535&p=inactive_account_policy_blog&rd=1">https://support.google.com/accounts/answer/12418290?visit_id=638264210155158507-1346504535&p=inactive_account_policy_blog&rd=1</a><br/>
Google AMP Service Used for Phishing<br/>
 <a href="https://cofense.com/blog/google-amp-the-newest-of-evasive-phishing-tactic/">https://cofense.com/blog/google-amp-the-newest-of-evasive-phishing-tactic/</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8598" type="text/plain" language="en" />
<itunes:keywords>google, amp, phishing, inactive accounts, airgap, dns, https, http, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8596</itunes:episode>
<itunes:subtitle>Ivanti Patches New 0-Day; Redis Malware; Android 0-Day Summary; Wiping Canon Printers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ivanti Patches New 0-Day; Redis Malware; Android 0-Day Summary; Wiping Canon Printers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8596.mp3" length="5223676" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8596.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8596</link>
<pubDate>Tue, 01 Aug 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Ivanti End Point Manager 2nd Zero Day<br/>
 <a href="https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US">https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US</a><br/>
New Redis Malware Uses Unknown Initial Access Vector<br/>
 <a href="https://www.cadosecurity.com/redis-p2pinfect/">https://www.cadosecurity.com/redis-p2pinfect/</a><br/>
 <a href="https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/">https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/</a><br/>
Google Android 0-Day Summary<br/>
 <a href="https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html">https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html</a><br/>
Wiping Sensitive Data from Printers<br/>
 <a href="https://psirt.canon/advisory-information/cp2023-003/">https://psirt.canon/advisory-information/cp2023-003/</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8596" type="text/plain" language="en" />
<itunes:keywords>canon, printers, google, android, 0-day, redis, malware, replication, ivanti, manager, 0day, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 31st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8594</itunes:episode>
<itunes:subtitle>iMessage Phish; IPv6 Attacks; Steganography in Python; Mobileiron Exploit Released
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iMessage Phish; IPv6 Attacks; Steganography in Python; Mobileiron Exploit Released
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8594.mp3" length="4772180" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8594.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8594</link>
<pubDate>Mon, 31 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[USPS Phishing Scam Targeting iOS Users<br/>
 <a href="https://isc.sans.edu/forums/diary/USPS+Phishing+Scam+Targeting+iOS+Users/30078/">https://isc.sans.edu/forums/diary/USPS+Phishing+Scam+Targeting+iOS+Users/30078/</a><br/>
Do Attackers Pay More Attention to IPv6<br/>
 <a href="https://isc.sans.edu/diary/Do%20Attackers%20Pay%20More%20Attention%20to%20IPv6%3F/30076">https://isc.sans.edu/diary/Do%20Attackers%20Pay%20More%20Attention%20to%20IPv6%3F/30076</a><br/>
Shell Code in Images<br/>
 <a href="https://isc.sans.edu/diary/ShellCode%20Hidden%20with%20Steganography/30074">https://isc.sans.edu/diary/ShellCode%20Hidden%20with%20Steganography/30074</a><br/>
Ivanti Mobileiron Exploit Public<br/>
 <a href="https://github.com/vchan-in/CVE-2023-35078-Exploit-POC/blob/main/cve_2023_35078_poc.py">https://github.com/vchan-in/CVE-2023-35078-Exploit-POC/blob/main/cve_2023_35078_poc.py</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8594" type="text/plain" language="en" />
<itunes:keywords>ivanti, mobileiron, exploit, shell code, ipv6, usps, phishing, imessage, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8592</itunes:episode>
<itunes:subtitle>OverlayFS Ubuntu Vuln; CISA warns of IDOR; Sophos UTM Patch; Aruba Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OverlayFS Ubuntu Vuln; CISA warns of IDOR; Sophos UTM Patch; Aruba Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8592.mp3" length="5169825" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8592.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8592</link>
<pubDate>Fri, 28 Jul 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Ubuntu OverlayFS Vulnerability<br/>
 <a href="https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability">https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability</a><br/>
CISA Warns of Insecure Direct Option Reference Vulnerabilities<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-208a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-208a</a><br/>
Sophos UTM Patch<br/>
 <a href="https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=utm&versionID=9.7">https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=utm&versionID=9.7</a><br/>
Aruba Patches<br/>
 <a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8592" type="text/plain" language="en" />
<itunes:keywords>Aruba, Sophos, CISA, IDOR, Ubuntu, OverlayFS, patches, vulnerabilities, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8590</itunes:episode>
<itunes:subtitle>Malware Blocked IPs; MLS Protocol; PySecDB; MacOS Infostealer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Blocked IPs; MLS Protocol; PySecDB; MacOS Infostealer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8590.mp3" length="5322910" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8590.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8590</link>
<pubDate>Thu, 27 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Suspicious IP Addresses Avoided By Malware Samples<br/>
 <a href="https://isc.sans.edu/diary/Suspicious%20IP%20Addresses%20Avoided%20by%20Malware%20Samples/30068">https://isc.sans.edu/diary/Suspicious%20IP%20Addresses%20Avoided%20by%20Malware%20Samples/30068</a><br/>
Messaging Layer Security (MLS) Protocol<br/>
 <a href="https://datatracker.ietf.org/doc/html/rfc9420">https://datatracker.ietf.org/doc/html/rfc9420</a><br/>
PySecDB: Security Commit Dataset in Python<br/>
 <a href="https://github.com/SunLab-GMU/PySecDB">https://github.com/SunLab-GMU/PySecDB</a><br/>
MacOS Infostealer<br/>
 <a href="https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/">https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8590" type="text/plain" language="en" />
<itunes:keywords>malware, ips, mls, encryption, pysecdb, macos, realst, infostealer, rust, sonoma, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 26th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8588</itunes:episode>
<itunes:subtitle>Ivanti Patch; Atlassian Patches; AMD Zen-2 Vuln; VMWare Tanzu Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ivanti Patch; Atlassian Patches; AMD Zen-2 Vuln; VMWare Tanzu Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8588.mp3" length="4504667" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8588.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8588</link>
<pubDate>Wed, 26 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Ivanti Patches Endpoint Manager Mobile<br/>
 <a href="https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US">https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US</a><br/>
Atlassian Patches<br/>
 <a href="https://confluence.atlassian.com/security/security-bulletin-july-18-2023-1251417643.html">https://confluence.atlassian.com/security/security-bulletin-july-18-2023-1251417643.html</a><br/>
AMD Zen-2 Vulnerability<br/>
 <a href="https://lock.cmpxchg8b.com/zenbleed.html">https://lock.cmpxchg8b.com/zenbleed.html</a><br/>
VMWare CVE-2023-20891<br/>
 <a href="https://socradar.io/vmwares-response-to-the-critical-cve-2023-20891-vulnerability-exposing-cf-api-admin-credentials/">https://socradar.io/vmwares-response-to-the-critical-cve-2023-20891-vulnerability-exposing-cf-api-admin-credentials/</a><br/>
 <br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8588" type="text/plain" language="en" />
<itunes:keywords>iventi, atlassian, amd, zen2, vmware, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 25th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8586</itunes:episode>
<itunes:subtitle>Apple Updates; jq parsing; TETRA Radio Backdoor;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; jq parsing; TETRA Radio Backdoor;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8586.mp3" length="5427138" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8586.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8586</link>
<pubDate>Tue, 25 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20%28again%29/30062/">https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20%28again%29/30062/</a><br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Parsing Data with jq<br/>
 <a href="https://isc.sans.edu/diary/JQ%3A%20Another%20Tool%20We%20Thought%20We%20Knew/30060">https://isc.sans.edu/diary/JQ%3A%20Another%20Tool%20We%20Thought%20We%20Knew/30060</a><br/>
TETRA Radio Backdoor<br/>
 <a href="https://www.wired.com/story/tetra-radio-encryption-backdoor/">https://www.wired.com/story/tetra-radio-encryption-backdoor/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8586" type="text/plain" language="en" />
<itunes:keywords>tetra, radio, backdoor, apple, jq, updates, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8584</itunes:episode>
<itunes:subtitle>Shodan API; MSFT Stolen Key Scope; Okta Logs; Citrix Exploits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shodan API; MSFT Stolen Key Scope; Okta Logs; Citrix Exploits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8584.mp3" length="5537055" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8584.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8584</link>
<pubDate>Mon, 24 Jul 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Shodan's API for the (Recon) Win!<br/>
 <a href="https://isc.sans.edu/diary/Shodan%27s%20API%20For%20The%20%28Recon%29%20Win!/30050">https://isc.sans.edu/diary/Shodan%27s%20API%20For%20The%20%28Recon%29%20Win!/30050</a><br/>
Stolen Microsoft Key May Have Opened Up a lot more than US Government E-Mail Inboxes<br/>
 <a href="https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr">https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr</a><br/>
 <a href="https://www.theregister.com/2023/07/21/microsoft_key_skeleton/">https://www.theregister.com/2023/07/21/microsoft_key_skeleton/</a><br/>
Okta Logs Decoded<br/>
 <a href="https://www.rezonate.io/blog/okta-logs-decoded-unveiling-identity-threats-through-threat-hunting/">https://www.rezonate.io/blog/okta-logs-decoded-unveiling-identity-threats-through-threat-hunting/</a><br/>
Threat Actors Exploiting Citrix CVE-2023-3519<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a</a><br/>
 <a href="https://github.com/securekomodo/citrixInspector">https://github.com/securekomodo/citrixInspector</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8584" type="text/plain" language="en" />
<itunes:keywords>citrix, okta, microsoft, key, wiz, shodan, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 21st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8582</itunes:episode>
<itunes:subtitle>Obfuscated .bat file; Citrix CVE-2023-3519 IoCs; ssh-agent exploit; MegaRAC Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated .bat file; Citrix CVE-2023-3519 IoCs; ssh-agent exploit; MegaRAC Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8582.mp3" length="3263192" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8582.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8582</link>
<pubDate>Fri, 21 Jul 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Deobfuscation of Malware Delivered Through a .bat File<br/>
 <a href="https://isc.sans.edu/diary/Deobfuscation%20of%20Malware%20Delivered%20Through%20a%20.bat%20File/30048">https://isc.sans.edu/diary/Deobfuscation%20of%20Malware%20Delivered%20Through%20a%20.bat%20File/30048</a><br/>
Citrix CVE-2023-3519 Indicators of Compromise<br/>
 <a href="https://www.deyda.net/index.php/en/2023/07/19/checklist-for-citrix-adc-cve-2023-3519/">https://www.deyda.net/index.php/en/2023/07/19/checklist-for-citrix-adc-cve-2023-3519/</a><br/>
ssh-agent vulnerability<br/>
 <a href="https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt">https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt</a><br/>
Spring Security: WebFlux Security Bypass with Un-Prefixed Double Wildcard Pattern<br/>
 <a href="https://spring.io/security/cve-2023-34034">https://spring.io/security/cve-2023-34034</a><br/>
American Megatrends (AMI) MegaRAC BMC Vulnerabilities<br/>
 <a href="https://eclypsium.com/research/bmcc-lights-out-forever/">https://eclypsium.com/research/bmcc-lights-out-forever/</a><br/>
]]></description>
<itunes:duration>3:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8582" type="text/plain" language="en" />
<itunes:keywords>.bat, obfuscation, citrix, ios, ssh-agent, megarac, megatrend, ami, bmc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8580</itunes:episode>
<itunes:subtitle>Citrix Vulnerability; Enigma Challenge; Oracle CPU; Microsoft Expanding Cloud Logging
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix Vulnerability; Enigma Challenge; Oracle CPU; Microsoft Expanding Cloud Logging
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8580.mp3" length="2973632" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8580.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8580</link>
<pubDate>Thu, 20 Jul 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Citrix ADC Vulneraiblity CVE-2023-3519, CVE-2023-3466, CVE-2023-3467<br/>
 <a href="https://isc.sans.edu/forums/diary/Citrix%20ADC%20Vulnerability%20CVE-2023-3519%2C%203466%20and%203467%20-%20Patch%20Now!/30044/">https://isc.sans.edu/forums/diary/Citrix%20ADC%20Vulnerability%20CVE-2023-3519%2C%203466%20and%203467%20-%20Patch%20Now!/30044/</a><br/>
HAM Radio Enigma Machine Challenge<br/>
 <a href="https://isc.sans.edu/diary/HAM%20Radio%20%2B%20Enigma%20Machine%20Challenge/30042">https://isc.sans.edu/diary/HAM%20Radio%20%2B%20Enigma%20Machine%20Challenge/30042</a><br/>
Oracle Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpujul2023.html">https://www.oracle.com/security-alerts/cpujul2023.html</a><br/>
Microsoft Expanding Cloud Logging<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/">https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/</a><br/>
]]></description>
<itunes:duration>3:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8580" type="text/plain" language="en" />
<itunes:keywords>microsoft, cloud, logging, oracle, cpu, ham radio, enigma, citrix, adc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 19th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8578</itunes:episode>
<itunes:subtitle>Jira Plugin Exploit; Citrix Vulnerabilities; Google Cloud Build Service Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Jira Plugin Exploit; Citrix Vulnerabilities; Google Cloud Build Service Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8578.mp3" length="5132673" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8578.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8578</link>
<pubDate>Wed, 19 Jul 2023 11:30:02 GMT</pubDate>
<description><![CDATA[Exploit Attempts for "Stagil navigation for Jira Menus & Themes"<br/>
 <a href="https://isc.sans.edu/diary/Exploit%20Attempts%20for%20%22Stagil%20navigation%20for%20Jira%20Menus%20%26%20Themes%22%20CVE-2023-26255%20and%20CVE-2023-26256/30038">https://isc.sans.edu/diary/Exploit%20Attempts%20for%20%22Stagil%20navigation%20for%20Jira%20Menus%20%26%20Themes%22%20CVE-2023-26255%20and%20CVE-2023-26256/30038</a><br/>
Citrix Vulnerabilities<br/>
 <a href="https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467">https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467</a><br/>
Google Cloud Build Service Vulnerability<br/>
 <a href="https://orca.security/resources/blog/bad-build-google-cloud-build-potential-supply-chain-attack-vulnerability">https://orca.security/resources/blog/bad-build-google-cloud-build-potential-supply-chain-attack-vulnerability</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8578" type="text/plain" language="en" />
<itunes:keywords>stagil, jira, plugin, directory traversal, citrix, google, cloud, build, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8576</itunes:episode>
<itunes:subtitle>Exploited Vulnerabilities in Zimbra, WooCommerce, Coldfusion; CISA free cloud tools; Jumpcloud Breach
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exploited Vulnerabilities in Zimbra, WooCommerce, Coldfusion; CISA free cloud tools; Jumpcloud Breach
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8576.mp3" length="4678516" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8576.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8576</link>
<pubDate>Tue, 18 Jul 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Zimbra Vulnerability Exploited<br/>
 <a href="https://blog.zimbra.com/2023/07/security-update-for-zimbra-collaboration-suite-version-8-8-15">https://blog.zimbra.com/2023/07/security-update-for-zimbra-collaboration-suite-version-8-8-15</a><br/>
Woocommerce Vulnerability Actively Being Exploited<br/>
 <a href="https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/">https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/</a><br/>
Adobe Coldfusion Flaws exploited<br/>
 <a href="https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-rce-bug-exploited-in-attacks/">https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-rce-bug-exploited-in-attacks/</a><br/>
CISA Cloud Security Fact Sheet: Free Tools for Cloud Environments<br/>
 <a href="https://www.cisa.gov/sites/default/files/2023-07/Free%20Tools%20for%20Cloud%20Environments_508c.pdf">https://www.cisa.gov/sites/default/files/2023-07/Free%20Tools%20for%20Cloud%20Environments_508c.pdf</a><br/>
JumpCloud Breach<br/>
 <a href="https://arstechnica.com/security/2023/07/jumpcloud-says-nation-state-hacker-breach-targeted-some-of-its-customers/">https://arstechnica.com/security/2023/07/jumpcloud-says-nation-state-hacker-breach-targeted-some-of-its-customers/</a><br/>
]]></description>
<itunes:duration>5:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8576" type="text/plain" language="en" />
<itunes:keywords>zimbra, coldfusion, woocommerce, adobe, cisa, cloud, jumpcloud, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8574</itunes:episode>
<itunes:subtitle>MSFT Driver Certs Details; Threads Threats;  CVSS 4.0 Preview
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Driver Certs Details; Threads Threats;  CVSS 4.0 Preview
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8574.mp3" length="6317344" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8574.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8574</link>
<pubDate>Mon, 17 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Driver Certs Details<br/>
 <a href="https://blog.talosintelligence.com/old-certificate-new-signature/">https://blog.talosintelligence.com/old-certificate-new-signature/</a><br/>
Threads App Lures<br/>
 <a href="https://www.helpnetsecurity.com/2023/07/14/threads-app-lure/">https://www.helpnetsecurity.com/2023/07/14/threads-app-lure/</a><br/>
First Releases CVSS 4.0 Preview<br/>
 <a href="https://www.first.org/cvss/">https://www.first.org/cvss/</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8574" type="text/plain" language="en" />
<itunes:keywords>first, cvss, threads, microsoft, driver, signatures, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8572</itunes:episode>
<itunes:subtitle>Honeypot Logs; MSFT Outlook 365 compromise; Fake PoC; Ghostscript PoC;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot Logs; MSFT Outlook 365 compromise; Fake PoC; Ghostscript PoC;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8572.mp3" length="5022307" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8572.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8572</link>
<pubDate>Fri, 14 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[DShield Honeypot Maintenance and Data Retention<br/>
 <a href="https://isc.sans.edu/diary/DShield%20Honeypot%20Maintenance%20and%20Data%20Retention/30024">https://isc.sans.edu/diary/DShield%20Honeypot%20Maintenance%20and%20Data%20Retention/30024</a><br/>
Enhanced Monitoring to Detect APT Activity Targeting Outlook Online<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a</a><br/>
PoC Exploit: Fake Proof of Concept with Backdoor Malware<br/>
 <a href="https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware">https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware</a><br/>
GhostScript CVE-2023-36664 PoC Exploit<br/>
 <a href="https://www.kroll.com/en/insights/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability">https://www.kroll.com/en/insights/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8572" type="text/plain" language="en" />
<itunes:keywords>ghostscript, poc, malware, backdoor, github, apt, outlook, online, honeypot, dshield, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8570</itunes:episode>
<itunes:subtitle>Apple Fixes Patch; Formbook QM18; Adobe Patches; Fortinet Patches; Citrix Patches; Sonicwall Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Fixes Patch; Formbook QM18; Adobe Patches; Fortinet Patches; Citrix Patches; Sonicwall Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8570.mp3" length="5478435" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8570.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8570</link>
<pubDate>Thu, 13 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Re-Releases Rapid Security Update for iOS/MacOS<br/>
 <a href="https://support.apple.com/HT201224">https://support.apple.com/HT201224</a><br/>
Loader Activity For Formbook "QM18"<br/>
 <a href="https://isc.sans.edu/diary/Loader%20activity%20for%20Formbook%20%22QM18%22/30020">https://isc.sans.edu/diary/Loader%20activity%20for%20Formbook%20%22QM18%22/30020</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html">https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html</a><br/>
FortiOS/FortiProxy Stack Based Overflow<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-23-183">https://www.fortiguard.com/psirt/FG-IR-23-183</a><br/>
Citrix Secure Access Client for Ubuntu<br/>
 <a href="https://support.citrix.com/article/CTX564169/citrix-secure-access-client-for-ubuntu-security-bulletin-for-cve202324492">https://support.citrix.com/article/CTX564169/citrix-secure-access-client-for-ubuntu-security-bulletin-for-cve202324492</a><br/>
Sonicwall Updates<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8570" type="text/plain" language="en" />
<itunes:keywords>sonicwall, citrix, fortios, forinet, fortiproxy, adobe, coldfusion, formbook, qm18, macos, ios, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8568</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Apple Withdraws Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Apple Withdraws Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8568.mp3" length="5804009" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8568.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8568</link>
<pubDate>Wed, 12 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/July%202023%20Microsoft%20Patch%20Update/30018/">https://isc.sans.edu/forums/diary/July%202023%20Microsoft%20Patch%20Update/30018/</a><br/>
 <a href="https://blog.talosintelligence.com/old-certificate-new-signature/">https://blog.talosintelligence.com/old-certificate-new-signature/</a><br/>
Apple Withdraws Rapid Security Response Update<br/>
 <a href="https://support.apple.com/en-us/HT213827">https://support.apple.com/en-us/HT213827</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8568" type="text/plain" language="en" />
<itunes:keywords>apple, withdraws, rsr, rapid security response, microsoft, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8566</itunes:episode>
<itunes:subtitle>Apple 0-Day Patch; Edgerouter/Aircube PoC; Firefox Quarantined Domains/Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple 0-Day Patch; Edgerouter/Aircube PoC; Firefox Quarantined Domains/Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8566.mp3" length="5106509" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8566.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8566</link>
<pubDate>Tue, 11 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Rapid Security Update Patches Three Exploited Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Rapid%20Security%20Update%20Patches%20Three%20Exploited%20Vulnerabilities/30012">https://isc.sans.edu/diary/Apple%20Rapid%20Security%20Update%20Patches%20Three%20Exploited%20Vulnerabilities/30012</a><br/>
Ubiquity Edgerouter and AirCube miniupnpd Heap Overflow<br/>
 <a href="https://ssd-disclosure.com/ssd-advisory-edgerouters-and-aircube-miniupnpd-heap-overflow/">https://ssd-disclosure.com/ssd-advisory-edgerouters-and-aircube-miniupnpd-heap-overflow/</a><br/>
Mozilla Restricting Extensions on Quarantined Domains<br/>
 <a href="https://support.mozilla.org/en-US/kb/quarantined-domains">https://support.mozilla.org/en-US/kb/quarantined-domains</a><br/>
 <a href="https://www.mozilla.org/en-US/firefox/115.0/releasenotes/">https://www.mozilla.org/en-US/firefox/115.0/releasenotes/</a><br/>
 <a href="https://lapcatsoftware.com/articles/2023/7/1.html">https://lapcatsoftware.com/articles/2023/7/1.html</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8566" type="text/plain" language="en" />
<itunes:keywords>mozilla, firefox, ubiquity, edgerouter, aircube, miniupnd, apple, ios, macos, security, update, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8564</itunes:episode>
<itunes:subtitle>DSSuite Update; New MoveIT Flaw; Nexus 9000 Flaw;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DSSuite Update; New MoveIT Flaw; Nexus 9000 Flaw;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8564.mp3" length="3899154" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8564.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8564</link>
<pubDate>Mon, 10 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[DSSuite Didier Toolbox Cokcer Image Update<br/>
 <a href="https://isc.sans.edu/diary/DSSuite%20%28Didier%27s%20Toolbox%29%20Docker%20Image%20Update/30008">https://isc.sans.edu/diary/DSSuite%20%28Didier%27s%20Toolbox%29%20Docker%20Image%20Update/30008</a><br/>
More MoveIT Flaws and new Service Pack<br/>
 <a href="https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023">https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023</a><br/>
Cisco Nexus 9000 Flaw<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX</a><br/>
]]></description>
<itunes:duration>4:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8564" type="text/plain" language="en" />
<itunes:keywords>nexus, 9000, encryption, moveit, sql injection, sqli, dssuite, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8562</itunes:episode>
<itunes:subtitle>IDS Honeypot Logs; Truebot vs Netwrix Auditor; Stackrot; TeamsPhisher
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IDS Honeypot Logs; Truebot vs Netwrix Auditor; Stackrot; TeamsPhisher
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8562.mp3" length="5233760" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8562.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8562</link>
<pubDate>Fri, 07 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[IDS Comparisons with DShield Honeypot Data<br/>
 <a href="https://isc.sans.edu/diary/IDS%20Comparisons%20with%20DShield%20Honeypot%20Data/30002">https://isc.sans.edu/diary/IDS%20Comparisons%20with%20DShield%20Honeypot%20Data/30002</a><br/>
Truebot Exploits Netwrix Auditor<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-187a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-187a</a><br/>
Stackrot Linux Priviledge Escalation Vulnerability<br/>
 <a href="https://www.openwall.com/lists/oss-security/2023/07/05/1">https://www.openwall.com/lists/oss-security/2023/07/05/1</a><br/>
TeamsPhisher Exploit<br/>
 <a href="https://github.com/Octoberfest7/TeamsPhisher">https://github.com/Octoberfest7/TeamsPhisher</a><br/>
VMWare Update<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0015.html">https://www.vmware.com/security/advisories/VMSA-2023-0015.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8562" type="text/plain" language="en" />
<itunes:keywords>ids, honeypot, suricata, pan, truebot, netwrix, auditor, Teamsphisher, vmware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8560</itunes:episode>
<itunes:subtitle>DShield pfSense Client; Exposed ICS; Custom Encoding; SNAPPY; RUSTBUCKET
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DShield pfSense Client; Exposed ICS; Custom Encoding; SNAPPY; RUSTBUCKET
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8560.mp3" length="6150876" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8560.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8560</link>
<pubDate>Thu, 06 Jul 2023 02:00:02 GMT</pubDate>
<description><![CDATA[DShield pfSense Client Update<br/>
 <a href="https://isc.sans.edu/diary/DShield%20pfSense%20Client%20Update/29994">https://isc.sans.edu/diary/DShield%20pfSense%20Client%20Update/29994</a><br/>
Exposed Industrial Control Systems<br/>
 <a href="https://isc.sans.edu/diary/Controlling%20network%20access%20to%20ICS%20systems/30000">https://isc.sans.edu/diary/Controlling%20network%20access%20to%20ICS%20systems/30000</a><br/>
Analysis Method for Custom Encoding<br/>
 <a href="https://isc.sans.edu/diary/Analysis%20Method%20for%20Custom%20Encoding/29946">https://isc.sans.edu/diary/Analysis%20Method%20for%20Custom%20Encoding/29946</a><br/>
SNAPPY: Detecting Rogue WiFi Access Points<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/snappy-detecting-rogue-and-fake-80211-wireless-access-points-through-fingerprinting-beacon-management-frames/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/snappy-detecting-rogue-and-fake-80211-wireless-access-points-through-fingerprinting-beacon-management-frames/</a><br/>
RUSTBUCKET Mac Malware<br/>
 <a href="https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket">https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket</a><br/>
]]></description>
<itunes:duration>6:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8560" type="text/plain" language="en" />
<itunes:keywords>rustbucket, snappy, encoding, ics, hmi, dshield, pfsense, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 30th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8558</itunes:episode>
<itunes:subtitle>From Adobe Remcos RAT; ArcServe PoC Exploit; Sysmon Update; Drone Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
From Adobe Remcos RAT; ArcServe PoC Exploit; Sysmon Update; Drone Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8558.mp3" length="5942258" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8558.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8558</link>
<pubDate>Fri, 30 Jun 2023 02:00:01 GMT</pubDate>
<description><![CDATA[GuLoader or BatLoader/Modiloader infection fro Remcos RAT<br/>
 <a href="https://isc.sans.edu/diary/GuLoader-%20or%20DBatLoader%20ModiLoader-style%20infection%20for%20Remcos%20RAT/29990">https://isc.sans.edu/diary/GuLoader-%20or%20DBatLoader%20ModiLoader-style%20infection%20for%20Remcos%20RAT/29990</a><br/>
CVE-2023-26258 Remote Code Execution in Arcserve UDP Backup<br/>
 <a href="https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/">https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/</a><br/>
Sysmon Update<br/>
 <a href="https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon">https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon</a><br/>
 <a href="https://medium.com/@olafhartong/sysmon-15-0-file-executable-detected-40fd64349f36">https://medium.com/@olafhartong/sysmon-15-0-file-executable-detected-40fd64349f36</a><br/>
Drone Security and Fault Injection Attacks<br/>
 <a href="https://labs.ioactive.com/2023/06/applying-fault-injection-to-firmware.html">https://labs.ioactive.com/2023/06/applying-fault-injection-to-firmware.html</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8558" type="text/plain" language="en" />
<itunes:keywords>drone, sysmon, arcserve, udp, backup, guloader, batloader, remcos rat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 29th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8556</itunes:episode>
<itunes:subtitle>SSLv2 Survey; NPM manifests; Mockingjay;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SSLv2 Survey; NPM manifests; Mockingjay;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8556.mp3" length="5055453" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8556.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8556</link>
<pubDate>Thu, 29 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Kazkhastan: The world's last SSLv2 Super Power<br/>
 <a href="https://isc.sans.edu/diary/Kazakhstan%20-%20the%20world%27s%20last%20SSLv2%20superpower...%20and%20a%20country%20with%20potentially%20vulnerable%20last-mile%20internet%20infrastructure/29988">https://isc.sans.edu/diary/Kazakhstan%20-%20the%20world%27s%20last%20SSLv2%20superpower...%20and%20a%20country%20with%20potentially%20vulnerable%20last-mile%20internet%20infrastructure/29988</a><br/>
npm manifest issues<br/>
 <a href="https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem">https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem</a><br/>
Process Mockingjay: Echoing RWX In Userland To Achieve Code Execution<br/>
 <a href="https://www.securityjoes.com/post/process-mockingjay-echoing-rwx-in-userland-to-achieve-code-execution">https://www.securityjoes.com/post/process-mockingjay-echoing-rwx-in-userland-to-achieve-code-execution</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8556" type="text/plain" language="en" />
<itunes:keywords>mockingjay, rwx, npm, manifest, sslv2, ssl2, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8554</itunes:episode>
<itunes:subtitle>Malware Triage; RowPress Attack; Dell BIOS Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Triage; RowPress Attack; Dell BIOS Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8554.mp3" length="4648425" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8554.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8554</link>
<pubDate>Wed, 28 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[The Importance of Malware Triage<br/>
 <a href="https://isc.sans.edu/diary/The+Importance+of+Malware+Triage/29984/">https://isc.sans.edu/diary/The+Importance+of+Malware+Triage/29984/</a><br/>
RowPress: Amplifying Read Disturbance in Modern DRAM Chips<br/>
 <a href="https://dl.acm.org/doi/abs/10.1145/3579371.3589063">https://dl.acm.org/doi/abs/10.1145/3579371.3589063</a><br/>
Dell BIOS Updates<br/>
 <a href="https://www.dell.com/support/kbdoc/de-de/000214778/dsa-2023-174-dell-client-bios-security-update-for-an-out-of-bounds-write-vulnerability">https://www.dell.com/support/kbdoc/de-de/000214778/dsa-2023-174-dell-client-bios-security-update-for-an-out-of-bounds-write-vulnerability</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html">https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8554" type="text/plain" language="en" />
<itunes:keywords>malware, triage, rowpress, dell, bios, google chrome, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8552</itunes:episode>
<itunes:subtitle>BlackLotus Mitigation; Camaro Dragon; Grafana Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BlackLotus Mitigation; Camaro Dragon; Grafana Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8552.mp3" length="4720226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8552.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8552</link>
<pubDate>Tue, 27 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[BlackLotus Mitigation Guide<br/>
 <a href="https://media.defense.gov/2023/Jun/22/2003245723/-1/-1/0/CSI_BlackLotus_Mitigation_Guide.PDF">https://media.defense.gov/2023/Jun/22/2003245723/-1/-1/0/CSI_BlackLotus_Mitigation_Guide.PDF</a><br/>
Camaro Dragon Infects USB Drives as well as Network Drives<br/>
 <a href="https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/">https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/</a><br/>
Grafana Security Release<br/>
 <a href="https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/">https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8552" type="text/plain" language="en" />
<itunes:keywords>grafana, microsoft ad, oauth, camaro, dragon, usb, blacklotos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 26th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8550</itunes:episode>
<itunes:subtitle>Modiloader Spam; Word Templates; Quakbot Obama271; MSFT Teams Phishing; Free Smart Watches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Modiloader Spam; Word Templates; Quakbot Obama271; MSFT Teams Phishing; Free Smart Watches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8550.mp3" length="6129502" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8550.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8550</link>
<pubDate>Mon, 26 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Email Spam With Modiloader Attached<br/>
 <a href="https://isc.sans.edu/diary/Email%20Spam%20with%20Attachment%20Modiloader/29978">https://isc.sans.edu/diary/Email%20Spam%20with%20Attachment%20Modiloader/29978</a><br/>
Word Document with an Online Attached Template<br/>
 <a href="https://isc.sans.edu/diary/Word%20Document%20with%20an%20Online%20Attached%20Template/29976">https://isc.sans.edu/diary/Word%20Document%20with%20an%20Online%20Attached%20Template/29976</a><br/>
Quakbot Activity Obama271 Distrubution Tag<br/>
 <a href="https://isc.sans.edu/diary/Qakbot%20%28Qbot%29%20activity%2C%20obama271%20distribution%20tag/29968">https://isc.sans.edu/diary/Qakbot%20%28Qbot%29%20activity%2C%20obama271%20distribution%20tag/29968</a><br/>
Microsoft Teams External Tenant Confusion<br/>
 <a href="https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/">https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/</a><br/>
Free Smart Watches<br/>
 <a href="https://www.darkreading.com/threat-intelligence/suspicious-smartwatches-mailed-us-army-personnel">https://www.darkreading.com/threat-intelligence/suspicious-smartwatches-mailed-us-army-personnel</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8550" type="text/plain" language="en" />
<itunes:keywords>obama, qbot, qakbot, smart watches, microsoft, teams, email, office, word, template, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 23rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8548</itunes:episode>
<itunes:subtitle>Apple Updates; VCenter Vuln.; GitHub RepoJacking;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; VCenter Vuln.; GitHub RepoJacking;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8548.mp3" length="4878593" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8548.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8548</link>
<pubDate>Fri, 23 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Updates Already Exploited Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerabilities%20in%20iOS%20iPadOS%2C%20macOS%2C%20watchOS%20and%20Safari/29972">https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerabilities%20in%20iOS%20iPadOS%2C%20macOS%2C%20watchOS%20and%20Safari/29972</a><br/>
Heap Buffer Overflow in VMWare VCenter<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0014.html">https://www.vmware.com/security/advisories/VMSA-2023-0014.html</a><br/>
GitHub RepoJacking<br/>
 <a href="https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking">https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8548" type="text/plain" language="en" />
<itunes:keywords>apple, ios, ipados, macos, vmware, vcenter, github, repojacking, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 22nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8546</itunes:episode>
<itunes:subtitle>YouTube Creator Phishing; Autodesk Maya Malware; Zyxel, Asus and Huawei Vuln; VMware Aria Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
YouTube Creator Phishing; Autodesk Maya Malware; Zyxel, Asus and Huawei Vuln; VMware Aria Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8546.mp3" length="5081637" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8546.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8546</link>
<pubDate>Thu, 22 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Analyzing a YouTube Sponsorship Phishing E-Mail<br/>
 <a href="https://isc.sans.edu/diary/Analyzing%20a%20YouTube%20Sponsorship%20Phishing%20Mail%20and%20Malware%20Targeting%20Content%20Creators/29966">https://isc.sans.edu/diary/Analyzing%20a%20YouTube%20Sponsorship%20Phishing%20Mail%20and%20Malware%20Targeting%20Content%20Creators/29966</a><br/>
Malicious Code Can Be Anywhere<br/>
 <a href="https://isc.sans.edu/diary/Malicious%20Code%20Can%20Be%20Anywhere/29964">https://isc.sans.edu/diary/Malicious%20Code%20Can%20Be%20Anywhere/29964</a><br/>
Zyxel Vulnerability<br/>
 <a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products</a><br/>
Huawei Vulnerability<br/>
 <a href="https://www.huawei.com/en/psirt/security-advisories/2023/huawei-sa-thvihr-7015cbae-en">https://www.huawei.com/en/psirt/security-advisories/2023/huawei-sa-thvihr-7015cbae-en</a><br/>
Asus Vulnerability<br/>
 <a href="https://www.asus.com/content/asus-product-security-advisory/">https://www.asus.com/content/asus-product-security-advisory/</a><br/>
VMWare Aria Vuln Exploited<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0012.html">https://www.vmware.com/security/advisories/VMSA-2023-0012.html</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8546" type="text/plain" language="en" />
<itunes:keywords>vmware, aria, asus, huawei, zyxel, Autodesk, Maya, creators, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8544</itunes:episode>
<itunes:subtitle>More Formbook; ZIP Bruteforcing; .inf Malware; FortiNAC PoCs;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Formbook; ZIP Bruteforcing; .inf Malware; FortiNAC PoCs;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8544.mp3" length="5230010" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8544.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8544</link>
<pubDate>Tue, 20 Jun 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Formbook From Possible ModiLoaeder (DBatLoader)<br/>
 <a href="https://isc.sans.edu/diary/Formbook%20from%20Possible%20ModiLoader%20%28DBatLoader%29%20/29958">https://isc.sans.edu/diary/Formbook%20from%20Possible%20ModiLoader%20%28DBatLoader%29%20/29958</a><br/>
Brute-Force ZIP Password Cracking with zipdump.py<br/>
 <a href="https://isc.sans.edu/diary/Brute-Force%20ZIP%20Password%20Cracking%20with%20zipdump.py/29948">https://isc.sans.edu/diary/Brute-Force%20ZIP%20Password%20Cracking%20with%20zipdump.py/29948</a><br/>
Malware Delivered Through .inf File<br/>
 <a href="https://isc.sans.edu/diary/Malware%20Delivered%20Through%20.inf%20File/29960">https://isc.sans.edu/diary/Malware%20Delivered%20Through%20.inf%20File/29960</a><br/>
FortiNAC - Just a few more RCEs<br/>
 <a href="https://frycos.github.io/vulns4free/2023/06/18/fortinac.html">https://frycos.github.io/vulns4free/2023/06/18/fortinac.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8544" type="text/plain" language="en" />
<itunes:keywords>fortinac, moveit, inf file, zip, password, formbook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8542</itunes:episode>
<itunes:subtitle>Vulnerability Management; More MOVEit vulns; Critrix Sharefile; Chromeloader News; npm bignum compromise;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Vulnerability Management; More MOVEit vulns; Critrix Sharefile; Chromeloader News; npm bignum compromise;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8542.mp3" length="4968170" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8542.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8542</link>
<pubDate>Fri, 16 Jun 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Supervision and Verfication in Vulnerability Management<br/>
 <a href="https://isc.sans.edu/diary/Supervision%20and%20Verification%20in%20Vulnerability%20Management/29952">https://isc.sans.edu/diary/Supervision%20and%20Verification%20in%20Vulnerability%20Management/29952</a><br/>
More MOVEit issues<br/>
 <a href="https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023">https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023</a><br/>
Critical Citrix Sharefile Storagezones Controller<br/>
 <a href="https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489">https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489</a><br/>
Chromeloader Malware Update<br/>
 <a href="https://threatresearch.ext.hp.com/shampoo-a-new-chromeloader-campaign/">https://threatresearch.ext.hp.com/shampoo-a-new-chromeloader-campaign/</a><br/>
Bignum NPM Package Compromise<br/>
 <a href="https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers">https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8542" type="text/plain" language="en" />
<itunes:keywords>bignum, npm, chromeloader, malware, citrix, sharefile, storagezones, moveit, vulnerability management, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8540</itunes:episode>
<itunes:subtitle>Deobfuscating VBS; Broken OOXML Sigs; CVE-2023-32019 Patch Not Enabled By Default; Fortigate Updates; Zoom Updates; Fake GitHub Exploits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Deobfuscating VBS; Broken OOXML Sigs; CVE-2023-32019 Patch Not Enabled By Default; Fortigate Updates; Zoom Updates; Fake GitHub Exploits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8540.mp3" length="5292195" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8540.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8540</link>
<pubDate>Thu, 15 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Deobfuscating a VBS Script With Custom Encoding<br/>
 <a href="https://isc.sans.edu/diary/Deobfuscating%20a%20VBS%20Script%20With%20Custom%20Encoding/29940">https://isc.sans.edu/diary/Deobfuscating%20a%20VBS%20Script%20With%20Custom%20Encoding/29940</a><br/>
Every Signature is Broken: On the Insecurity of Microsoft Office s OOXML Signatures<br/>
 <a href="https://www.usenix.org/conference/usenixsecurity23/presentation/rohlmann">https://www.usenix.org/conference/usenixsecurity23/presentation/rohlmann</a><br/>
How to Manage the Vulnerailbity Associated with CVE-2023-32019<br/>
 <a href="https://support.microsoft.com/en-gb/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080">https://support.microsoft.com/en-gb/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080</a><br/>
Fake Security Research GitHub Repos<br/>
 <a href="https://vulncheck.com/blog/fake-repos-deliver-malicious-implant">https://vulncheck.com/blog/fake-repos-deliver-malicious-implant</a><br/>
Fortigate Vuln Details<br/>
 <a href="https://blog.lexfo.fr/xortigate-cve-2023-27997.html">https://blog.lexfo.fr/xortigate-cve-2023-27997.html</a><br/>
Zoom Updates<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8540" type="text/plain" language="en" />
<itunes:keywords>zoom, fortigate, github, fake exploits, windows, vbs, ooxml signatures, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8538</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; VMWare 0-Day; SAP Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; VMWare 0-Day; SAP Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8538.mp3" length="4913441" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8538.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8538</link>
<pubDate>Wed, 14 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/June%202023%20Microsoft%20Patch%20Tuesday/29942/">https://isc.sans.edu/forums/diary/June%202023%20Microsoft%20Patch%20Tuesday/29942/</a><br/>
VMWare 0-Day<br/>
 <a href="https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass">https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass</a><br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0013.html">https://www.vmware.com/security/advisories/VMSA-2023-0013.html</a><br/>
SAP Patches<br/>
 <a href="https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html">https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8538" type="text/plain" language="en" />
<itunes:keywords>patches, tuesday, patch tuesday, microsoft, vmware, 0-day, sap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8536</itunes:episode>
<itunes:subtitle>Geoserver Cryptominer Attacks; Fortinet Update; Bitwarden Key Leak; Western Digital SMART abuse;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Geoserver Cryptominer Attacks; Fortinet Update; Bitwarden Key Leak; Western Digital SMART abuse;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8536.mp3" length="4976866" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8536.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8536</link>
<pubDate>Tue, 13 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Geoserver Attack Details: More Cryptominers Against Unconfigured WebApps<br/>
 <a href="https://isc.sans.edu/diary/Geoserver%20Attack%20Details%3A%20More%20Cryptominers%20against%20Unconfigured%20WebApps/29936">https://isc.sans.edu/diary/Geoserver%20Attack%20Details%3A%20More%20Cryptominers%20against%20Unconfigured%20WebApps/29936</a><br/>
Fortinet Update CVE-2023-27997<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-23-097">https://www.fortiguard.com/psirt/FG-IR-23-097</a><br/>
Bitwarden Key Accessible By Low Privileged User<br/>
 <a href="https://hackerone.com/reports/1874155">https://hackerone.com/reports/1874155</a><br/>
Western Digital SMART Flag Abuse<br/>
 <a href="https://arstechnica.com/gadgets/2023/06/clearly-predatory-western-digital-sparks-panic-anger-for-age-shaming-hdds/">https://arstechnica.com/gadgets/2023/06/clearly-predatory-western-digital-sparks-panic-anger-for-age-shaming-hdds/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8536" type="text/plain" language="en" />
<itunes:keywords>western digital, smart, bitwarden, fortinet, geoserver, kensing, cryptominer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8534</itunes:episode>
<itunes:subtitle>Powershell Profiles; Honeypot Activity; More flaws in MOVEit and Fortinet SSLVPN
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Powershell Profiles; Honeypot Activity; More flaws in MOVEit and Fortinet SSLVPN
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8534.mp3" length="5027219" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8534.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8534</link>
<pubDate>Mon, 12 Jun 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Undetected PowerShell Backdoor Disduigsed as a Profiled File<br/>
 <a href="https://isc.sans.edu/diary/Undetected%20PowerShell%20Backdoor%20Disguised%20as%20a%20Profile%20File/29930">https://isc.sans.edu/diary/Undetected%20PowerShell%20Backdoor%20Disguised%20as%20a%20Profile%20File/29930</a><br/>
DShield Honeypot Activity for May 2023<br/>
 <a href="https://isc.sans.edu/diary/DShield%20Honeypot%20Activity%20for%20May%202023%20/29932">https://isc.sans.edu/diary/DShield%20Honeypot%20Activity%20for%20May%202023%20/29932</a><br/>
Second MOVEit Vulnerability<br/>
 <a href="https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability">https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability</a><br/>
Fortinet Patches CVE-2023-27997<br/>
 <a href="https://twitter.com/cfreal_/status/1667852157536616451">https://twitter.com/cfreal_/status/1667852157536616451</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8534" type="text/plain" language="en" />
<itunes:keywords>fortniet, moveit, dshield, honeypot, powershell, backdoor, patches, vulnerabilities, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8532</itunes:episode>
<itunes:subtitle>Geoserver Scans; Barracuda ESG Replacement; Google Chrome Password Manager; Minecraft Mods; Trend Micro Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Geoserver Scans; Barracuda ESG Replacement; Google Chrome Password Manager; Minecraft Mods; Trend Micro Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8532.mp3" length="4872900" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8532.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8532</link>
<pubDate>Fri, 09 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Geoserver Scans<br/>
 <a href="https://isc.sans.edu/diary/Ongoing%20scans%20for%20Geoserver/29926">https://isc.sans.edu/diary/Ongoing%20scans%20for%20Geoserver/29926</a><br/>
Barracuda Recommends Replacing Compromised Devices<br/>
 <a href="https://www.barracuda.com/company/legal/esg-vulnerability">https://www.barracuda.com/company/legal/esg-vulnerability</a><br/>
Google improves Chrome Password Manager<br/>
 <a href="https://www.msn.com/en-us/news/other/chrome-adds-windows-biometric-logins-to-its-password-powers/ar-AA1ciCCf">https://www.msn.com/en-us/news/other/chrome-adds-windows-biometric-logins-to-its-password-powers/ar-AA1ciCCf</a><br/>
Minecraft Mods Include Malicious Code<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-fractureiser-malware-used-curseforge-minecraft-mods-to-infect-windows-linux/">https://www.bleepingcomputer.com/news/security/new-fractureiser-malware-used-curseforge-minecraft-mods-to-infect-windows-linux/</a><br/>
Trend Micro Service Pack<br/>
 <a href="https://files.trendmicro.com/documentation/readme/Apex%20One/2020/apex_one_2019_win_cp_b12033_EN_Critical_Patch_Readme.html">https://files.trendmicro.com/documentation/readme/Apex%20One/2020/apex_one_2019_win_cp_b12033_EN_Critical_Patch_Readme.html</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8532" type="text/plain" language="en" />
<itunes:keywords>trend micro, minecraft, google, password manager, barracuda, geoserver, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8530</itunes:episode>
<itunes:subtitle>DMARC in .co; VMware Aria Patch; SpinOK Spyware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DMARC in .co; VMware Aria Patch; SpinOK Spyware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8530.mp3" length="5138846" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8530.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8530</link>
<pubDate>Thu, 08 Jun 2023 02:00:01 GMT</pubDate>
<description><![CDATA[DMARC in .co TLD<br/>
 <a href="https://isc.sans.edu/diary/Management%20of%20DMARC%20control%20for%20email%20impersonation%20of%20domains%20in%20the%20.co%20TLD%20-%20part%202/29922">https://isc.sans.edu/diary/Management%20of%20DMARC%20control%20for%20email%20impersonation%20of%20domains%20in%20the%20.co%20TLD%20-%20part%202/29922</a><br/>
Three Vulnerabilities in VMWare Aria Operations for Networks<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0012.html">https://www.vmware.com/security/advisories/VMSA-2023-0012.html</a><br/>
SpinOK Spyware SDK found in Android Apps<br/>
 <a href="https://vms.drweb.com/search/?q=Android.Spy.SpinOk&lng=en">https://vms.drweb.com/search/?q=Android.Spy.SpinOk&lng=en</a><br/>
 <a href="https://www.cloudsek.com/threatintelligence/supply-chain-attack-infiltrates-android-apps-with-malicious-sdk">https://www.cloudsek.com/threatintelligence/supply-chain-attack-infiltrates-android-apps-with-malicious-sdk</a><br/>
Cisco Anyconnect Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw</a><br/>
RSA Webcast<br/>
 <a href="https://www.rsaconference.com/library/webcast/149-sans-followup-2023">https://www.rsaconference.com/library/webcast/149-sans-followup-2023</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8530" type="text/plain" language="en" />
<itunes:keywords>rsa, webcast, cisco, anyconnect, spinok, spyware, sdk, android, vmware, ario, dmarc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8528</itunes:episode>
<itunes:subtitle>Copilot vs. Google; Android and Chrome 0-Days; Fake Sextortion;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Copilot vs. Google; Android and Chrome 0-Days; Fake Sextortion;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8528.mp3" length="5402122" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8528.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8528</link>
<pubDate>Wed, 07 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Github Copilot vs Google: Which Code is More Secure<br/>
 <a href="https://isc.sans.edu/forums/diary/Github%20Copilot%20vs.%20Google%3A%20Which%20code%20is%20more%20secure/29918/">https://isc.sans.edu/forums/diary/Github%20Copilot%20vs.%20Google%3A%20Which%20code%20is%20more%20secure/29918/</a><br/>
Android Update<br/>
 <a href="https://source.android.com/docs/security/bulletin/2023-06-01">https://source.android.com/docs/security/bulletin/2023-06-01</a><br/>
Chrome Updates<br/>
 <a href="https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html</a><br/>
FBI Warns of Manipulated Photos and Videos For Sextortion<br/>
 <a href="https://www.ic3.gov/Media/Y2023/PSA230605">https://www.ic3.gov/Media/Y2023/PSA230605</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8528" type="text/plain" language="en" />
<itunes:keywords>fbi, photos, sextortion, chrom, android, github, copilot, google, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8526</itunes:episode>
<itunes:subtitle>Simple Archive Bruteforcer; Keepass Patch; Splunk Advisories; Chrome Extensions; Symantec Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Simple Archive Bruteforcer; Keepass Patch; Splunk Advisories; Chrome Extensions; Symantec Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8526.mp3" length="4899557" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8526.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8526</link>
<pubDate>Tue, 06 Jun 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Brute Forcing Simple Archive Passwords<br/>
 <a href="https://isc.sans.edu/diary/Brute%20Forcing%20Simple%20Archive%20Passwords/29914">https://isc.sans.edu/diary/Brute%20Forcing%20Simple%20Archive%20Passwords/29914</a><br/>
KeePass 2.54 Released<br/>
 <a href="https://keepass.info/news/n230603_2.54.html">https://keepass.info/news/n230603_2.54.html</a><br/>
Splunk Advisories<br/>
 <a href="https://advisory.splunk.com/advisories">https://advisory.splunk.com/advisories</a><br/>
Malicious Google Chrome Extensions<br/>
 <a href="https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/">https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/</a><br/>
Symantec Updates<br/>
 <a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/22217">https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/22217</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8526" type="text/plain" language="en" />
<itunes:keywords>symantec, google, chrome, extensions, keepass, brute forcing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 5th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8524</itunes:episode>
<itunes:subtitle>MoveIT Transfer Exploited; Atomic Wallet Theft; Magecart Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MoveIT Transfer Exploited; Atomic Wallet Theft; Magecart Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8524.mp3" length="5296802" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8524.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8524</link>
<pubDate>Mon, 05 Jun 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Critical Vulnerability in MoveIT Transfer Actively Exploited<br/>
 <a href="https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023">https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023</a><br/>
 <a href="https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/">https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/</a><br/>
 <a href="https://www.mandiant.com/resources/blog/zero-day-moveit-data-theft">https://www.mandiant.com/resources/blog/zero-day-moveit-data-theft</a><br/>
Atomic Wallet Compromise<br/>
 <a href="https://www.bleepingcomputer.com/news/security/atomic-wallet-hacks-lead-to-over-35-million-in-crypto-stolen/">https://www.bleepingcomputer.com/news/security/atomic-wallet-hacks-lead-to-over-35-million-in-crypto-stolen/</a><br/>
Magecart Update<br/>
 <a href="https://www.akamai.com/blog/security-research/new-magecart-hides-behind-legit-domains">https://www.akamai.com/blog/security-research/new-magecart-hides-behind-legit-domains</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8524" type="text/plain" language="en" />
<itunes:keywords>magecart, atomic wallet, moveit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8522</itunes:episode>
<itunes:subtitle>SSLv2 Remnants; iOS Malware; MOVEit and Reportslab PDF Library Vulnerabilities; Brandon Helms (@sans_edu): CTI For Containers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SSLv2 Remnants; iOS Malware; MOVEit and Reportslab PDF Library Vulnerabilities; Brandon Helms (@sans_edu): CTI For Containers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8522.mp3" length="14710532" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8522.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8522</link>
<pubDate>Fri, 02 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[After 28 Years, SSLv2 is Still Not Gone <br/>
 <a href="https://isc.sans.edu/forums/diary/After%2028%20years%2C%20SSLv2%20is%20still%20not%20gone%20from%20the%20internet...%20but%20we're%20getting%20there/29908/">https://isc.sans.edu/forums/diary/After%2028%20years%2C%20SSLv2%20is%20still%20not%20gone%20from%20the%20internet...%20but%20we're%20getting%20there/29908/</a><br/>
Operation Triangulation: iOS Devices Targeted With Previously Unknown Malware<br/>
 <a href="https://securelist.com/operation-triangulation/109842/">https://securelist.com/operation-triangulation/109842/</a><br/>
MOVEit Transfer Criticial Vulnerability<br/>
 <a href="https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023">https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023</a><br/>
Code Injection Vulnerablity in Reportlab Python Library<br/>
 <a href="https://github.com/c53elyas/CVE-2023-33733">https://github.com/c53elyas/CVE-2023-33733</a><br/>
]]></description>
<itunes:duration>17:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8522" type="text/plain" language="en" />
<itunes:keywords>reportlab, pdf, moveit, ios, 0-Day, sslv2, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8520</itunes:episode>
<itunes:subtitle>Apache NiFi Attacks; Gigabyte Backdoor; SalesForce Ghost Sites; ImageMagick Shell Command Injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apache NiFi Attacks; Gigabyte Backdoor; SalesForce Ghost Sites; ImageMagick Shell Command Injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8520.mp3" length="6063733" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8520.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8520</link>
<pubDate>Thu, 01 Jun 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Apache NiFi Attacks<br/>
 <a href="https://isc.sans.edu/diary/Your%20Business%20Data%20and%20Machine%20Learning%20at%20Risk%3A%20Attacks%20Against%20Apache%20NiFi/29900">https://isc.sans.edu/diary/Your%20Business%20Data%20and%20Machine%20Learning%20at%20Risk%3A%20Attacks%20Against%20Apache%20NiFi/29900</a><br/>
Gigabyte App Center Backdoor;<br/>
 <a href="https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/">https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/</a><br/>
Salesforce Ghost Sites<br/>
 <a href="https://www.varonis.com/blog/salesforce-ghost-sites">https://www.varonis.com/blog/salesforce-ghost-sites</a><br/>
CVE-2023-34152: Shell Command Injection in ImageMagick<br/>
 <a href="https://securityonline.info/cve-2023-34152-shell-command-injection-bug-affecting-imagemagick/">https://securityonline.info/cve-2023-34152-shell-command-injection-bug-affecting-imagemagick/</a><br/>
]]></description>
<itunes:duration>6:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8520" type="text/plain" language="en" />
<itunes:keywords>imagemagick, salesforce, ghost sites, gigabyte, app-center, backdoor, apache, nifi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 31st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8518</itunes:episode>
<itunes:subtitle>ModiLoader Sample; MacOS SIP Bypass; OpenSSL Update; Barracuda Vuln Details; Nextcloud, Zyxel Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ModiLoader Sample; MacOS SIP Bypass; OpenSSL Update; Barracuda Vuln Details; Nextcloud, Zyxel Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8518.mp3" length="5262635" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8518.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8518</link>
<pubDate>Wed, 31 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Malspam Pushes ModiLoader Infection for Remocs Rat<br/>
 <a href="https://isc.sans.edu/diary/Malspam%20pushes%20ModiLoader%20%28DBatLoader%29%20infection%20for%20Remcos%20RAT/29896">https://isc.sans.edu/diary/Malspam%20pushes%20ModiLoader%20%28DBatLoader%29%20infection%20for%20Remcos%20RAT/29896</a><br/>
MacOS SIP Bypass<br/>
<a href="https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integrity-protection/">https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integrity-protection/</a><br/>
OpenSSL Update<br/>
<a href="https://www.openssl.org/news/secadv/20230530.txt">https://www.openssl.org/news/secadv/20230530.txt</a><br/>
Barracuda Email Security Gateway Applicance Vulnerability Details<br/>
 <a href="https://www.barracuda.com/company/legal/esg-vulnerability#:~:text=the%20section%20below.-,Endpoint%20IOCs,-Table%204%20lists">https://www.barracuda.com/company/legal/esg-vulnerability#:~:text=the%20section%20below.-,Endpoint%20IOCs,-Table%204%20lists</a><br/>
Void Rabisu RomCom Backdoor <br/>
 <a href="https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html">https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html</a><br/>
Nextcloud Vulnerability<br/>
 <a href="https://github.com/nextcloud/security-advisories/security/advisories/GHSA-mr7q-xf62-fw54">https://github.com/nextcloud/security-advisories/security/advisories/GHSA-mr7q-xf62-fw54</a><br/>
Zyxel NAS Vulnerability<br/>
 <a href="https://sternumiot.com/iot-blog/ntp-textbox-vulnerability-in-zyxel-nas326-nas540-and-nas542-devices/">https://sternumiot.com/iot-blog/ntp-textbox-vulnerability-in-zyxel-nas326-nas540-and-nas542-devices/</a><br/>
Wait Just An Infosec: Higher Ed<br/>
 <a href="https://www.youtube.com/watch?v=ufEuo-096yc&list=PLtgaAEEmVe6B2kqkE9KdgPJdtbqNiaiOn&index=8">https://www.youtube.com/watch?v=ufEuo-096yc&list=PLtgaAEEmVe6B2kqkE9KdgPJdtbqNiaiOn&index=8</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8518" type="text/plain" language="en" />
<itunes:keywords>ed, higher ed, zyxel, nas, nextcloud, romcom, barracuda, sip, apple, modiloader, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 30th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8516</itunes:episode>
<itunes:subtitle>Word in PPT; DocuSign Malspam; Archiver in Browser; Casandra and MXsecurity Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Word in PPT; DocuSign Malspam; Archiver in Browser; Casandra and MXsecurity Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8516.mp3" length="5204264" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8516.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8516</link>
<pubDate>Tue, 30 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Analyzing Office Documents Embedded Inside PowerPoint Files<br/>
 <a href="https://isc.sans.edu/diary/Analyzing%20Office%20Documents%20Embedded%20Inside%20PPT%20%28PowerPoint%29%20Files/29894">https://isc.sans.edu/diary/Analyzing%20Office%20Documents%20Embedded%20Inside%20PPT%20%28PowerPoint%29%20Files/29894</a><br/>
DocuSign Themed Email Leads to Script-Based Infection<br/>
 <a href="https://isc.sans.edu/diary/DocuSign-themed%20email%20leads%20to%20script-based%20infection/29888">https://isc.sans.edu/diary/DocuSign-themed%20email%20leads%20to%20script-based%20infection/29888</a><br/>
File Archiver In The Browser<br/>
 <a href="https://mrd0x.com/file-archiver-in-the-browser/">https://mrd0x.com/file-archiver-in-the-browser/</a><br/>
Securing PyPI accounts via Two-Factor Authentication<br/>
 <a href="https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/">https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/</a><br/>
Apache Casandra Vulnerabilities<br/>
 <a href="https://lists.apache.org/thread/mwd02nrw2go8shg29rnp3o4hgompvkp5">https://lists.apache.org/thread/mwd02nrw2go8shg29rnp3o4hgompvkp5</a><br/>
MOXA MXsecurity Vulerabilities<br/>
 <a href="https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities">https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8516" type="text/plain" language="en" />
<itunes:keywords>pypi, zip, tld, docusign, office, powerpoint, word, ppt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 26th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8514</itunes:episode>
<itunes:subtitle>IR Case/Alert Mgnmt; GitLab Exploit; Expo OAUTH Vuln Details; Mitel MiVoice and DLink Vulnerabilities;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IR Case/Alert Mgnmt; GitLab Exploit; Expo OAUTH Vuln Details; Mitel MiVoice and DLink Vulnerabilities;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8514.mp3" length="4815191" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8514.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8514</link>
<pubDate>Fri, 26 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[IR Case/Alert Management<br/>
 <a href="https://isc.sans.edu/diary/IR%20Case%20Alert%20Management/29880">https://isc.sans.edu/diary/IR%20Case%20Alert%20Management/29880</a><br/>
Exploit for CVE-2023-2825 GitLab Vulnerability<br/>
 <a href="https://github.com/Occamsec/CVE-2023-2825">https://github.com/Occamsec/CVE-2023-2825</a><br/>
Expo Framework OAUTH Vulnerability CVE-2023-28131<br/>
 <a href="https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services">https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services</a><br/>
Mitel MiVoice Vulnerability CVE-2023-31457 CVE-2023-32748<br/>
 <a href="https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0004">https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0004</a><br/>
D-Link Vulnerabilities<br/>
 <a href="https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332">https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8514" type="text/plain" language="en" />
<itunes:keywords>dlink, d-link, mitel, mivoice, expo, oauth, gitlab, ir, case, alert, management, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 25th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8512</itunes:episode>
<itunes:subtitle>Enriching Cowrie; Volt Typhoon; Android Spy App; Zyxel, Baracuda and GitLab Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Enriching Cowrie; Volt Typhoon; Android Spy App; Zyxel, Baracuda and GitLab Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8512.mp3" length="4947416" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8512.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8512</link>
<pubDate>Thu, 25 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[More Data Enrichment for Cowrie Logs<br/>
 <a href="https://isc.sans.edu/diary/More%20Data%20Enrichment%20for%20Cowrie%20Logs/29878">https://isc.sans.edu/diary/More%20Data%20Enrichment%20for%20Cowrie%20Logs/29878</a><br/>
Volt Typhoon: Living of the Land<br/>
 <a href="https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF">https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF</a><br/>
Android App Breaking Bad<br/>
 <a href="https://www.welivesecurity.com/2023/05/23/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration/">https://www.welivesecurity.com/2023/05/23/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration/</a><br/>
Zyxel Updates<br/>
 <a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls</a><br/>
Baracuda Email Security Gateway Vulnerability<br/>
 <a href="https://status.barracuda.com/incidents/34kx82j5n4q9">https://status.barracuda.com/incidents/34kx82j5n4q9</a><br/>
Gitlab Patch<br/>
 <a href="https://about.gitlab.com/releases/2023/05/23/critical-security-release-gitlab-16-0-1-released/">https://about.gitlab.com/releases/2023/05/23/critical-security-release-gitlab-16-0-1-released/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8512" type="text/plain" language="en" />
<itunes:keywords>gitlab, baracuda, email, zyxel, android, breaking bad, app, volt typhoon, cowrie, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8510</itunes:episode>
<itunes:subtitle>Apache NiFi Scans; Samsung 0-Day Fix;  Lenovo Bricked; Dell VX Rail; BrutePrint
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apache NiFi Scans; Samsung 0-Day Fix;  Lenovo Bricked; Dell VX Rail; BrutePrint
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8510.mp3" length="5607042" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8510.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8510</link>
<pubDate>Wed, 24 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Apache Nifi Scans<br/>
 <a href="https://isc.sans.edu/diary/Help+us+figure+this+out+Scans+for+Apache+Nifi/29874/">https://isc.sans.edu/diary/Help+us+figure+this+out+Scans+for+Apache+Nifi/29874/</a><br/>
Samsung Updates fix 0-Day<br/>
 <a href="https://security.samsungmobile.com/securityUpdate.smsb">https://security.samsungmobile.com/securityUpdate.smsb</a><br/>
Lenovo All-In One Bricked by Windows Update<br/>
 <a href="https://www.reddit.com/r/Lenovo/comments/136tatm/lenovo_firmware_10055_bricking_thinkcentre_v53024/">https://www.reddit.com/r/Lenovo/comments/136tatm/lenovo_firmware_10055_bricking_thinkcentre_v53024/</a><br/>
Dell VxRail Security Update<br/>
 <a href="https://www.dell.com/support/kbdoc/en-us/000213011/dsa-2023-071-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities-7-0-450">https://www.dell.com/support/kbdoc/en-us/000213011/dsa-2023-071-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities-7-0-450</a><br/>
BrutePrint: Expose Smartphone Fingerprint Authentication to Brute-force Attack<br/>
 <a href="https://arxiv.org/pdf/2305.10791.pdf">https://arxiv.org/pdf/2305.10791.pdf</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8510" type="text/plain" language="en" />
<itunes:keywords>bruteprint, android, ios, fingerprint, dell, vxrail, lenovo, samsung, nifi, apache, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 23rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8508</itunes:episode>
<itunes:subtitle>ABUS Camera Vuln; .ZIP vs Virustotal; Nissan Car Key Replay; Synology DSM 6.2; Jenkins Plugins; PyPi Suspension Lifted;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ABUS Camera Vuln; .ZIP vs Virustotal; Nissan Car Key Replay; Synology DSM 6.2; Jenkins Plugins; PyPi Suspension Lifted;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8508.mp3" length="4692667" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8508.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8508</link>
<pubDate>Tue, 23 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Probes for recent ABUS Security Camera Vulnerability<br/>
 <a href="https://isc.sans.edu/diary/Probes%20for%20recent%20ABUS%20Security%20Camera%20Vulnerability%3A%20Attackers%20keep%20an%20eye%20on%20everything./29870">https://isc.sans.edu/diary/Probes%20for%20recent%20ABUS%20Security%20Camera%20Vulnerability%3A%20Attackers%20keep%20an%20eye%20on%20everything./29870</a><br/>
.ZIP Domains Confuse Virustotal<br/>
 <a href="https://twitter.com/imohanasundaram/status/1660678184977805316">https://twitter.com/imohanasundaram/status/1660678184977805316</a><br/>
Synology DSM 6.2 Patch<br/>
 <a href="https://www.synology.com/en-global/security/advisory/Synology_SA_22_25">https://www.synology.com/en-global/security/advisory/Synology_SA_22_25</a><br/>
Jenkins Fixes Multiple Plugin Vulnerabilities<br/>
 <a href="https://www.jenkins.io/security/advisory/2023-05-16/">https://www.jenkins.io/security/advisory/2023-05-16/</a><br/>
PyPi Suspension Lifted<br/>
 <a href="https://status.python.org/incidents/qy2t9mjjcc7g">https://status.python.org/incidents/qy2t9mjjcc7g</a><br/>
Nissan Sylphy Classic Key Vulnerability<br/>
 <a href="https://vulmon.com/vulnerabilitydetails?qid=CVE-2023-33281">https://vulmon.com/vulnerabilitydetails?qid=CVE-2023-33281</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8508" type="text/plain" language="en" />
<itunes:keywords>nissan, sylphy, key, pypi, jenkins, synology, abus, virustotal, zip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 22nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8506</itunes:episode>
<itunes:subtitle>HTA Analysis; Encoding Mistakes; PyPi Attack; PyPi PGP Signatures; npm RATs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HTA Analysis; Encoding Mistakes; PyPi Attack; PyPi PGP Signatures; npm RATs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8506.mp3" length="4928414" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8506.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8506</link>
<pubDate>Mon, 22 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Another Malicious HTA File Analysis - Part 3<br/>
 <a href="https://isc.sans.edu/forums/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%203/29678/">https://isc.sans.edu/forums/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%203/29678/</a><br/>
When the Phisher Messes Up With Encoding<br/>
 <a href="https://isc.sans.edu/diary/When%20the%20Phisher%20Messes%20Up%20With%20Encoding/29864">https://isc.sans.edu/diary/When%20the%20Phisher%20Messes%20Up%20With%20Encoding/29864</a><br/>
PyPi Suspends New Users and Projects<br/>
 <a href="https://status.python.org/incidents/qy2t9mjjcc7g">https://status.python.org/incidents/qy2t9mjjcc7g</a><br/>
PGP Signatures on PyPi: Worse than useless<br/>
 <a href="https://blog.yossarian.net/2023/05/21/PGP-signatures-on-PyPI-worse-than-useless">https://blog.yossarian.net/2023/05/21/PGP-signatures-on-PyPI-worse-than-useless</a><br/>
RATs found hiding in the npm attic<br/>
 <a href="https://www.reversinglabs.com/blog/rats-found-hiding-in-the-npm-attic">https://www.reversinglabs.com/blog/rats-found-hiding-in-the-npm-attic</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8506" type="text/plain" language="en" />
<itunes:keywords>RATs, npm, pgp, pypi, phishing, encoding, HTA, reverse analysis, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 19th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8504</itunes:episode>
<itunes:subtitle>Apple Updates; .zip Survey; Dell/EMC Networker Vuln; Keepass Master PW Exposure
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; .zip Survey; Dell/EMC Networker Vuln; Keepass Master PW Exposure
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8504.mp3" length="6060398" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8504.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8504</link>
<pubDate>Fri, 19 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Apple Updates Everything<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything/29860">https://isc.sans.edu/diary/Apple%20Updates%20Everything/29860</a><br/>
A Quick Survey of .zip Domains<br/>
 <a href="https://isc.sans.edu/diary/A%20Quick%20Survey%20of%20.zip%20Domains%3A%20Your%20highest%20risk%20is%20running%20into%20Rick%20Astley./29858">https://isc.sans.edu/diary/A%20Quick%20Survey%20of%20.zip%20Domains%3A%20Your%20highest%20risk%20is%20running%20into%20Rick%20Astley./29858</a><br/>
Dell NetWorker Security Update<br/>
 <a href="https://www.dell.com/support/kbdoc/en-us/000211267/dsa-2023-060-dell-networker-security-update-for-an-nsrcapinfo-vulnerability?lwp=rt">https://www.dell.com/support/kbdoc/en-us/000211267/dsa-2023-060-dell-networker-security-update-for-an-nsrcapinfo-vulnerability?lwp=rt</a><br/>
KeePass 2.X Master Password Dumper<br/>
 <a href="https://github.com/vdohney/keepass-password-dumper">https://github.com/vdohney/keepass-password-dumper</a><br/>
]]></description>
<itunes:duration>6:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8504" type="text/plain" language="en" />
<itunes:keywords>keepass, dell, networker, backup, .zip, domains, apple, updates, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8502</itunes:episode>
<itunes:subtitle>RAR SFX Files; Wemo Vuln; Wago Vuln; Router Vuln to Proxies; TP-Link Malicous Firmware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RAR SFX Files; Wemo Vuln; Wago Vuln; Router Vuln to Proxies; TP-Link Malicous Firmware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8502.mp3" length="5162783" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8502.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8502</link>
<pubDate>Thu, 18 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Increase in Malicious RAR SFX Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Increase%20in%20Malicious%20RAR%20SFX%20files/29852/">https://isc.sans.edu/forums/diary/Increase%20in%20Malicious%20RAR%20SFX%20files/29852/</a><br/>
FriendlyName Buffer Overflow in Wemo Smartplug<br/>
 <a href="https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/">https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/</a><br/>
Wago License Page Exploit<br/>
 <a href="https://onekey.com/blog/security-advisory-wago-unauthenticated-remote-command-execution/">https://onekey.com/blog/security-advisory-wago-unauthenticated-remote-command-execution/</a><br/>
Routers Turned Into Proxies<br/>
 <a href="https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/">https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8502" type="text/plain" language="en" />
<itunes:keywords>tp-link, routers, wago, wemo, rar, sfx, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8500</itunes:episode>
<itunes:subtitle>Testing Faraday Bags; Sharepoint Scans Encrypted Files; vm2 Escape; geocon for MacOS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Testing Faraday Bags; Sharepoint Scans Encrypted Files; vm2 Escape; geocon for MacOS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8500.mp3" length="5017259" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8500.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8500</link>
<pubDate>Wed, 17 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Signals Defense With Faraday Bags<br/>
 <a href="https://isc.sans.edu/forums/diary/Signals%20Defense%20With%20Faraday%20Bags%20%26%20Flipper%20Zero/29840/">https://isc.sans.edu/forums/diary/Signals%20Defense%20With%20Faraday%20Bags%20%26%20Flipper%20Zero/29840/</a><br/>
Microsoft Sharepoint Scans Password Protected Files<br/>
 <a href="https://infosec.exchange/@threatresearch/110373860063222707#">https://infosec.exchange/@threatresearch/110373860063222707#</a><br/>
Critical Sandbox Escape Vulnerability in VM2<br/>
 <a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5">https://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5</a><br/>
Geacon Brings Cobalt Strike Capabilities to MacOS Threat Actors<br/>
 <a href="https://www.sentinelone.com/blog/geacon-brings-cobalt-strike-capabilities-to-macos-threat-actors/">https://www.sentinelone.com/blog/geacon-brings-cobalt-strike-capabilities-to-macos-threat-actors/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8500" type="text/plain" language="en" />
<itunes:keywords>geacon, cobalt strike, macos, vm2, sandbox escape, sharepoint av scanning, fraday bag, flipper zero, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8498</itunes:episode>
<itunes:subtitle>Facebook Phish; No Intel Microcode Vuln; Fake Trezor Wallets; TP-Link Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Facebook Phish; No Intel Microcode Vuln; Fake Trezor Wallets; TP-Link Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8498.mp3" length="4770678" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8498.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8498</link>
<pubDate>Tue, 16 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Ongoing Facebook Phishing campaign Without a Sender and (almost) without Links<br/>
 <a href="https://isc.sans.edu/diary/Ongoing%20Facebook%20phishing%20campaign%20without%20a%20sender%20and%20%28almost%29%20without%20links/29848">https://isc.sans.edu/diary/Ongoing%20Facebook%20phishing%20campaign%20without%20a%20sender%20and%20%28almost%29%20without%20links/29848</a><br/>
Intel Microcode Updates Do Not Patch Vulnerability<br/>
 <a href="https://www.theregister.com/2023/05/15/intel_mystery_microcode/">https://www.theregister.com/2023/05/15/intel_mystery_microcode/</a><br/>
Fake Trezor Hardware Crypto Wallet<br/>
 <a href="https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/">https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/</a><br/>
TP-Link Archer AX-21 Command Injection CVE-2023-1389 Exploited<br/>
 <a href="https://www.fortiguard.com/threat-signal-report/5157/tp-link-archer-ax-21-command-injection-vulnerability-cve-2023-1389-exploited-in-the-wild">https://www.fortiguard.com/threat-signal-report/5157/tp-link-archer-ax-21-command-injection-vulnerability-cve-2023-1389-exploited-in-the-wild</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8498" type="text/plain" language="en" />
<itunes:keywords>facebook, phishing, intel, microcode, trezor, wallet, fake, tp-link, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8496</itunes:episode>
<itunes:subtitle>.zip/.mov domains;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
.zip/.mov domains;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8496.mp3" length="6270578" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8496.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8496</link>
<pubDate>Mon, 15 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[The .zip gTLD: Risks and Opportunities<br/>
 <a href="https://isc.sans.edu/forums/diary/The+zip+gTLD+Risks+and+Opportunities/29838/">https://isc.sans.edu/forums/diary/The+zip+gTLD+Risks+and+Opportunities/29838/</a><br/>
Brave Forgetful Browsing<br/>
 <a href="https://brave.com/privacy-updates/25-forgetful-browsing/">https://brave.com/privacy-updates/25-forgetful-browsing/</a><br/>
Intel Mystery Microcode Patch<br/>
 <a href="https://www.phoronix.com/news/Intel-12-May-2023-Microcode">https://www.phoronix.com/news/Intel-12-May-2023-Microcode</a><br/>
Netgear Updates<br/>
 <a href="https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilities-on-the-RAX30-PSV-2022-0348">https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilities-on-the-RAX30-PSV-2022-0348</a><br/>
Synology Updates<br/>
 <a href="https://www.synology.com/en-global/security/advisory/Synology_SA_23_04">https://www.synology.com/en-global/security/advisory/Synology_SA_23_04</a><br/>
 <a href="https://claroty.com/team82/research/chaining-five-vulnerabilities-to-exploit-netgear-nighthawk-rax30-routers-at-pwn2own-toronto-2022">https://claroty.com/team82/research/chaining-five-vulnerabilities-to-exploit-netgear-nighthawk-rax30-routers-at-pwn2own-toronto-2022</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8496" type="text/plain" language="en" />
<itunes:keywords>zip, mov, brave, forgetful, browsing, intel, microcode, netgear, synology, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8494</itunes:episode>
<itunes:subtitle>Geolocation Difficulties; Pre-Infected Phones; Dragos Breach; Ruckus Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Geolocation Difficulties; Pre-Infected Phones; Dragos Breach; Ruckus Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8494.mp3" length="5635382" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8494.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8494</link>
<pubDate>Fri, 12 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Geolocating IPs is Harder Than You Think<br/>
 <a href="https://isc.sans.edu/diary/Geolocating%20IPs%20is%20harder%20than%20you%20think/29834">https://isc.sans.edu/diary/Geolocating%20IPs%20is%20harder%20than%20you%20think/29834</a><br/>
Pre-Infected Mobile Phones<br/>
 <a href="https://www.theregister.com/2023/05/11/bh_asia_mobile_phones/">https://www.theregister.com/2023/05/11/bh_asia_mobile_phones/</a><br/>
Dragos Breach<br/>
 <a href="https://www.dragos.com/blog/deconstructing-a-cybersecurity-event/">https://www.dragos.com/blog/deconstructing-a-cybersecurity-event/</a><br/>
AndoryuBot Targets Ruckus Admin RCE Vulnerability<br/>
 <a href="https://www.fortinet.com/blog/threat-research/andoryubot-new-botnet-campaign-targets-ruckus-wireless-admin-remote-code-execution-vulnerability-cve-2023-25717">https://www.fortinet.com/blog/threat-research/andoryubot-new-botnet-campaign-targets-ruckus-wireless-admin-remote-code-execution-vulnerability-cve-2023-25717</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8494" type="text/plain" language="en" />
<itunes:keywords>geolocation, mobile phones, android, dragos, andoryubot, ruckus, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8492</itunes:episode>
<itunes:subtitle>CISSM Data Anlysis; Outlook "re-patch"; Snake Malware; Fake System Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CISSM Data Anlysis; Outlook "re-patch"; Snake Malware; Fake System Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8492.mp3" length="5234508" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8492.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8492</link>
<pubDate>Thu, 11 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Exploratory Data Analysis with CISSM Cyber Attacks Database Part 2<br/>
 <a href="https://isc.sans.edu/diary/Exploratory%20Data%20Analysis%20with%20CISSM%20Cyber%20Attacks%20Database%20-%20Part%202/29828">https://isc.sans.edu/diary/Exploratory%20Data%20Analysis%20with%20CISSM%20Cyber%20Attacks%20Database%20-%20Part%202/29828</a><br/>
Microsoft Patched Outlook (actually Windows) vulnerability again<br/>
 <a href="https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api">https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api</a><br/>
Law Enforcement and Intelligence Agencies Disable "Snake" Malware<br/>
 <a href="https://media.defense.gov/2023/May/09/2003218554/-1/-1/1/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF">https://media.defense.gov/2023/May/09/2003218554/-1/-1/1/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF</a><br/>
Fake System Update Drop Malware<br/>
 <a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/05/fake-system-update-drops-new-highly-evasive-loader">https://www.malwarebytes.com/blog/threat-intelligence/2023/05/fake-system-update-drops-new-highly-evasive-loader</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8492" type="text/plain" language="en" />
<itunes:keywords>fake updates, system updates, snake, malware, outlook, patch, cissm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8490</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; GitHub Push Protection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; GitHub Push Protection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8490.mp3" length="5312671" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8490.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8490</link>
<pubDate>Wed, 10 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20May%202023%20Patch%20Tuesday/29826">https://isc.sans.edu/diary/Microsoft%20May%202023%20Patch%20Tuesday/29826</a><br/>
GitHub  "Push Protection" now out of Beta<br/>
 <a href="https://github.blog/2023-05-09-push-protection-is-generally-available-and-free-for-all-public-repositories/">https://github.blog/2023-05-09-push-protection-is-generally-available-and-free-for-all-public-repositories/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8490" type="text/plain" language="en" />
<itunes:keywords>microsoft patch tuesday, push protection, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8488</itunes:episode>
<itunes:subtitle>QR Code Threats; Microsoft Edge Update; Fake ChatGPT
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
QR Code Threats; Microsoft Edge Update; Fake ChatGPT
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8488.mp3" length="5641447" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8488.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8488</link>
<pubDate>Tue, 09 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[QR Codes Used in Fake Parking Tickets and Surveys<br/>
 <a href="https://www.bleepingcomputer.com/news/security/qr-codes-used-in-fake-parking-tickets-surveys-to-steal-your-money/">https://www.bleepingcomputer.com/news/security/qr-codes-used-in-fake-parking-tickets-surveys-to-steal-your-money/</a><br/>
Microsoft Edge Update<br/>
 <a href="https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel">https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel</a><br/>
Facebook Sees More Fake ChatGPT<br/>
 <a href="https://about.fb.com/news/2023/05/metas-q1-2023-security-reports/">https://about.fb.com/news/2023/05/metas-q1-2023-security-reports/</a><br/>
CyberGhost VPN Vulnerability<br/>
 <a href="https://www.pentestpartners.com/security-blog/bullied-by-bugcrowd-over-kape-cyberghost-disclosure/">https://www.pentestpartners.com/security-blog/bullied-by-bugcrowd-over-kape-cyberghost-disclosure/</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8488" type="text/plain" language="en" />
<itunes:keywords>qr codes, microsoft, edge, facebook, chatgpt, cyberghost, vpn, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8486</itunes:episode>
<itunes:subtitle>Decoding PPAMs; Exploratory Analysis; Colorcpl.exe LOLBIN; Leaked MSI Keys; PHP Packages Compromised;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Decoding PPAMs; Exploratory Analysis; Colorcpl.exe LOLBIN; Leaked MSI Keys; PHP Packages Compromised;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8486.mp3" length="5508258" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8486.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8486</link>
<pubDate>Mon, 08 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Quickly Finding Encoded Payloads in Office Documents<br/>
 <a href="https://isc.sans.edu/forums/diary/Quickly+Finding+Encoded+Payloads+in+Office+Documents/29818/">https://isc.sans.edu/forums/diary/Quickly+Finding+Encoded+Payloads+in+Office+Documents/29818/</a><br/>
Exploratory Data Analysis with CISSM Cyber Attacks Database Part 1<br/>
 <a href="https://isc.sans.edu/forums/diary/Exploratory+Data+Analysis+with+CISSM+Cyber+Attacks+Database+Part+1/29816/">https://isc.sans.edu/forums/diary/Exploratory+Data+Analysis+with+CISSM+Cyber+Attacks+Database+Part+1/29816/</a><br/>
Guildma is now Abusing Colorcpl.exe LOLBIN<br/>
 <a href="https://isc.sans.edu/forums/diary/Guildma+is+now+abusing+colorcplexe+LOLBIN/29814/">https://isc.sans.edu/forums/diary/Guildma+is+now+abusing+colorcplexe+LOLBIN/29814/</a><br/>
Leaked MSI Keys<br/>
 <a href="https://github.com/binarly-io/SupplyChainAttacks/blob/main/MSI/ImpactedDevices.md">https://github.com/binarly-io/SupplyChainAttacks/blob/main/MSI/ImpactedDevices.md</a><br/>
 <a href="https://twitter.com/matrosov/status/1654560343295934464">https://twitter.com/matrosov/status/1654560343295934464</a><br/>
PHP Packages Compromised<br/>
 <a href="https://blog.packagist.com/packagist-org-maintainer-account-takeover/">https://blog.packagist.com/packagist-org-maintainer-account-takeover/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8486" type="text/plain" language="en" />
<itunes:keywords>php, msi, safe boot, keys, guildma, lolbin, colocpl.exe, decoding, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 5th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8484</itunes:episode>
<itunes:subtitle>Word Infostealer; Cisco SPA-112; Fortinet May Updates; PaperCut New Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Word Infostealer; Cisco SPA-112; Fortinet May Updates; PaperCut New Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8484.mp3" length="5353434" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8484.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8484</link>
<pubDate>Fri, 05 May 2023 02:05:02 GMT</pubDate>
<description><![CDATA[Infostealer Embedded in a Word Document<br/>
 <a href="https://isc.sans.edu/diary/Infostealer%20Embedded%20in%20a%20Word%20Document/29810">https://isc.sans.edu/diary/Infostealer%20Embedded%20in%20a%20Word%20Document/29810</a><br/>
Cisco SPA-112 Vulnerability<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-unauth-upgrade-UqhyTWW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-unauth-upgrade-UqhyTWW</a><br/>
Fortinet May Updates<br/>
 <a href="https://www.fortiguard.com/psirt?date=05-2023">https://www.fortiguard.com/psirt?date=05-2023</a><br/>
PaperCut exploitation - A Different Path to Code Execution<br/>
 <a href="https://vulncheck.com/blog/papercut-rce">https://vulncheck.com/blog/papercut-rce</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8484" type="text/plain" language="en" />
<itunes:keywords>papercut, protinet, cisco, spa-112, infostealer, word, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 4th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8482</itunes:episode>
<itunes:subtitle>Config File Scans; Google Enables Passkeys; Chrome Dropping TLS Lock; AMD TPM Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Config File Scans; Google Enables Passkeys; Chrome Dropping TLS Lock; AMD TPM Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8482.mp3" length="6713605" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8482.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8482</link>
<pubDate>Thu, 04 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Increased Number of Configuration File Scans<br/>
 <a href="https://isc.sans.edu/diary/Increased%20Number%20of%20Configuration%20File%20Scans/29806">https://isc.sans.edu/diary/Increased%20Number%20of%20Configuration%20File%20Scans/29806</a><br/>
Google Enabling Passkeys<br/>
 <a href="https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/">https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/</a><br/>
Chrome to Drop Lock Icon from HTTPS<br/>
 <a href="https://blog.chromium.org/2023/05/an-update-on-lock-icon.html">https://blog.chromium.org/2023/05/an-update-on-lock-icon.html</a><br/>
Attack Against AMD TPM Implementation<br/>
 <a href="https://arxiv.org/abs/2304.14717">https://arxiv.org/abs/2304.14717</a><br/>
]]></description>
<itunes:duration>7:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8482" type="text/plain" language="en" />
<itunes:keywords>amd, tpm, https, google, passkeys, file scans, configuration files, lock icon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8480</itunes:episode>
<itunes:subtitle>VBA Project References; FRRouting Vuln; JWT ECDSA Algo Confusion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBA Project References; FRRouting Vuln; JWT ECDSA Algo Confusion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8480.mp3" length="5196652" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8480.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8480</link>
<pubDate>Wed, 03 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[VBA Project References<br/>
 <a href="https://isc.sans.edu/diary/VBA%20Project%20References/29800">https://isc.sans.edu/diary/VBA%20Project%20References/29800</a><br/>
BGP Message Parsing Vulnerabilities in FRRouting<br/>
 <a href="https://www.forescout.com/blog/three-new-bgp-message-parsing-vulnerabilities-disclosed-in-frrouting-software/">https://www.forescout.com/blog/three-new-bgp-message-parsing-vulnerabilities-disclosed-in-frrouting-software/</a><br/>
JWT ECDSA Algorithm Confusion<br/>
 <a href="https://blog.pentesterlab.com/exploring-algorithm-confusion-attacks-on-jwt-exploiting-ecdsa-23f7ff83390f">https://blog.pentesterlab.com/exploring-algorithm-confusion-attacks-on-jwt-exploiting-ecdsa-23f7ff83390f</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8480" type="text/plain" language="en" />
<itunes:keywords>jwt, ecdsa, bpg, routing, dos, vba, project references, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8478</itunes:episode>
<itunes:subtitle>Passive Phish Analysis; Apple Rapid Security Response; Grafana Vuln; Illumina Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Passive Phish Analysis; Apple Rapid Security Response; Grafana Vuln; Illumina Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8478.mp3" length="5066429" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8478.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8478</link>
<pubDate>Tue, 02 May 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Passive Analysis of a Phishing Attachment<br/>
 <a href="https://isc.sans.edu/diary/%22Passive%22%20analysis%20of%20a%20phishing%20attachment/29798">https://isc.sans.edu/diary/%22Passive%22%20analysis%20of%20a%20phishing%20attachment/29798</a><br/>
Apple Rapid Security Response<br/>
 <a href="https://www.macrumors.com/2023/05/01/rapid-security-response-16-4-1/">https://www.macrumors.com/2023/05/01/rapid-security-response-16-4-1/</a><br/>
Grafana Security Release<br/>
 <a href="https://grafana.com/blog/2023/04/26/grafana-security-release-new-versions-of-grafana-with-security-fixes-for-cve-2023-28119-and-cve-2023-1387/">https://grafana.com/blog/2023/04/26/grafana-security-release-new-versions-of-grafana-with-security-fixes-for-cve-2023-28119-and-cve-2023-1387/</a><br/>
Illumina Vulnerability<br/>
 <a href="https://www.fda.gov/medical-devices/letters-health-care-providers/illumina-cybersecurity-vulnerability-affecting-universal-copy-service-software-may-present-risks">https://www.fda.gov/medical-devices/letters-health-care-providers/illumina-cybersecurity-vulnerability-affecting-universal-copy-service-software-may-present-risks</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8478" type="text/plain" language="en" />
<itunes:keywords>illumina, grafana, dna sequencing, apple, rapid security response, passive analysis, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8476</itunes:episode>
<itunes:subtitle>Loki in Docker; UTF-16 Encoded Malware; AT&amp;T Email Compromise; MacOS Crypto Stealer; Zyxel Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Loki in Docker; UTF-16 Encoded Malware; AT&amp;T Email Compromise; MacOS Crypto Stealer; Zyxel Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8476.mp3" length="4880848" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8476.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8476</link>
<pubDate>Mon, 01 May 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Quick IOC Scan With Docker<br/>
 <a href="https://isc.sans.edu/diary/Quick%20IOC%20Scan%20With%20Docker/29788">https://isc.sans.edu/diary/Quick%20IOC%20Scan%20With%20Docker/29788</a><br/>
Dobfuscation Scripts When Encodings Help<br/>
 <a href="https://isc.sans.edu/diary/Deobfuscating%20Scripts%3A%20When%20Encodings%20Help/29792">https://isc.sans.edu/diary/Deobfuscating%20Scripts%3A%20When%20Encodings%20Help/29792</a><br/>
Hackers Are Breaking Into AT&T Email Accounts To Steal Cryptocurrency<br/>
 <a href="https://techcrunch.com/2023/04/26/hackers-are-breaking-into-att-email-accounts-to-steal-cryptocurrency/">https://techcrunch.com/2023/04/26/hackers-are-breaking-into-att-email-accounts-to-steal-cryptocurrency/</a><br/>
Trheat Actor Selling New Atomic MacOS AMOS Stealer on Telegram<br/>
 <a href="https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/">https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/</a><br/>
Zyxel Firewall Vulnerability<br/>
 <a href="https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls">https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8476" type="text/plain" language="en" />
<itunes:keywords>loki, docker, malware, utf-16, att, macos, crypto, zyxel, vulnerability, firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8474</itunes:episode>
<itunes:subtitle>Veeam Vuln Ransomware; Google Authenticator Sync; Keycloak Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Veeam Vuln Ransomware; Google Authenticator Sync; Keycloak Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8474.mp3" length="5556182" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8474.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8474</link>
<pubDate>Fri, 28 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Ransomware Gang Exploiting Unpatches Veeam Backup Products<br/>
 <a href="https://www.computerweekly.com/news/365535586/Ransomware-gang-exploiting-unpatched-Veeam-backup-products">https://www.computerweekly.com/news/365535586/Ransomware-gang-exploiting-unpatched-Veeam-backup-products</a><br/>
Google Authenticator Sync Encryption<br/>
 <a href="https://security.googleblog.com/2023/04/google-authenticator-now-supports.html">https://security.googleblog.com/2023/04/google-authenticator-now-supports.html</a><br/>
Keycloak Vulnerability<br/>
 <a href="https://out.reddit.com/t3_130km04?url=https%3A%2F%2Fwww.offensity.com%2Fen%2Fblog%2Fuser-impersonation-via-stolen-uuid-code-in-keycloak-cve-2023-0264%2F&token=AQAAjSdLZJTzQM37107hVzYY-tbz6ak81pMNqN9qv3m2SWXEOMIm&app_name=web2x&user_id=33629461&web_redirect=true">https://out.reddit.com/t3_130km04?url=https%3A%2F%2Fwww.offensity.com%2Fen%2Fblog%2Fuser-impersonation-via-stolen-uuid-code-in-keycloak-cve-2023-0264%2F&token=AQAAjSdLZJTzQM37107hVzYY-tbz6ak81pMNqN9qv3m2SWXEOMIm&app_name=web2x&user_id=33629461&web_redirect=true</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8474" type="text/plain" language="en" />
<itunes:keywords>keycloak, google, authenticator, ransomwre, veeam, backup, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8472</itunes:episode>
<itunes:subtitle>Hunting Phishing Sites; RSA Top Attack Panel; @sans_edu research journal
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hunting Phishing Sites; RSA Top Attack Panel; @sans_edu research journal
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8472.mp3" length="5143796" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8472.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8472</link>
<pubDate>Thu, 27 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Strolling Through Cyberspace and Hunting for Phishing Sites<br/>
 <a href="https://isc.sans.edu/diary/Strolling%20through%20Cyberspace%20and%20Hunting%20for%20Phishing%20Sites/29780">https://isc.sans.edu/diary/Strolling%20through%20Cyberspace%20and%20Hunting%20for%20Phishing%20Sites/29780</a><br/>
RSA Panel: Five most dangerous new attack techniques<br/>
 <a href="https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques">https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques</a><br/>
SANS.edu Research Journal<br/>
 <a href="https://www.sans.edu/cyber-security-research">https://www.sans.edu/cyber-security-research</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8472" type="text/plain" language="en" />
<itunes:keywords>sans.edu, research journal, rsa panel, attack techniques, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 26th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8470</itunes:episode>
<itunes:subtitle>ChatGPT CVSS Scores; SLP Amplification; Apache Superset RCE; Sophos Web Appliance PoC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ChatGPT CVSS Scores; SLP Amplification; Apache Superset RCE; Sophos Web Appliance PoC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8470.mp3" length="5645138" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8470.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8470</link>
<pubDate>Wed, 26 Apr 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Calculating CVSS Scores with ChatGPT<br/>
 <a href="https://isc.sans.edu/diary/Calculating%20CVSS%20Scores%20with%20ChatGPT/29774">https://isc.sans.edu/diary/Calculating%20CVSS%20Scores%20with%20ChatGPT/29774</a> <br/>
Amplifying SLP Traffic<br/>
 <a href="https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp">https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp</a><br/>
Insecure Default Configuration in Apache Superset<br/>
 <a href="https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/">https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/</a> SLP Amplification; Apache Superset RCE;<br/>
PoC Exploit for Sophos Web Appliciance<br/>
 <a href="https://github.com/W01fh4cker/CVE-2023-1671-POC">https://github.com/W01fh4cker/CVE-2023-1671-POC</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8470" type="text/plain" language="en" />
<itunes:keywords>sophos, poc, exploit, apache, superset, slp, dos, amplification, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 25th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8468</itunes:episode>
<itunes:subtitle>Aukill BYOVD Ransomware; Papercut Exploit; Solarwinds Patch; APC UPS Software Patch; Virustotal Code Insight
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Aukill BYOVD Ransomware; Papercut Exploit; Solarwinds Patch; APC UPS Software Patch; Virustotal Code Insight
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8468.mp3" length="5418166" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8468.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8468</link>
<pubDate>Tue, 25 Apr 2023 05:20:43 GMT</pubDate>
<description><![CDATA[Aukill EDR Killer Malware Abuses Process Explorer Driver<br/>
 <a href="https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/">https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/</a><br/>
Papercut Vulnerability Deep Dive<br/>
 <a href="https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise">https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise</a><br/>
Solarwinds Patches<br/>
 <a href="https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-2_release_notes.htm">https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-2_release_notes.htm</a><br/>
Schneider Electric Update<br/>
 <a href="https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security%20and%20Safety%20Notice&p_File_Name=SEVD-2023-101-04.pdf">https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security%20and%20Safety%20Notice&p_File_Name=SEVD-2023-101-04.pdf</a><br/>
Virustotal Code Insight<br/>
 <a href="https://blog.virustotal.com/2023/04/introducing-virustotal-code-insight.html">https://blog.virustotal.com/2023/04/introducing-virustotal-code-insight.html</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8468" type="text/plain" language="en" />
<itunes:keywords>virustotal, code, insight, ups, apc, schneider electric, solarwinds, papercut, driver, process explorer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8466</itunes:episode>
<itunes:subtitle>DMARC in .co; X_Trader Fallout; Car Hacking; DNS Decoy Dog
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DMARC in .co; X_Trader Fallout; Car Hacking; DNS Decoy Dog
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8466.mp3" length="5142284" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8466.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8466</link>
<pubDate>Mon, 24 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Management of DMARC control for email impersonation fo domains in the .co TLD<br/>
 <a href="https://isc.sans.edu/forums/diary/Management+of+DMARC+control+for+email+impersonation+of+domains+in+the+co+TLD+part+1/29768/">https://isc.sans.edu/forums/diary/Management+of+DMARC+control+for+email+impersonation+of+domains+in+the+co+TLD+part+1/29768/</a><br/>
X_Trader Supply Chain Attack Fallout<br/>
 <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain</a><br/>
Car Hacking with Old Nokia Phones<br/>
 <a href="https://www.vice.com/en/article/v7beyj/car-thieves-tech-hidden-old-nokia-phones-bluetooth-speakers-emergency-engine-start-keyless">https://www.vice.com/en/article/v7beyj/car-thieves-tech-hidden-old-nokia-phones-bluetooth-speakers-emergency-engine-start-keyless</a><br/>
Dog Hunt Finding Decoy Dog Toolkit<br/>
 <a href="https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory/dog-hunt-finding-decoy-dog-toolkit-via-anomalous-dns-traffic/">https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory/dog-hunt-finding-decoy-dog-toolkit-via-anomalous-dns-traffic/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8466" type="text/plain" language="en" />
<itunes:keywords>dog, decoy dog, dns, car hacking, nokia, x_trader, dmarc, columbia, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 21st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8464</itunes:episode>
<itunes:subtitle>Password Expiry; 3CX Update; Google Ghosttokens; PyPi Trusted Publishers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Password Expiry; 3CX Update; Google Ghosttokens; PyPi Trusted Publishers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8464.mp3" length="5838000" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8464.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8464</link>
<pubDate>Fri, 21 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Taking a Bite Out of Password Expiry Helpdesk Calls<br/>
 <a href="https://isc.sans.edu/diary/Taking%20a%20Bite%20Out%20of%20Password%20Expiry%20Helpdesk%20Calls/29758">https://isc.sans.edu/diary/Taking%20a%20Bite%20Out%20of%20Password%20Expiry%20Helpdesk%20Calls/29758</a><br/>
3CX Software Supply Chain Compromise<br/>
 <a href="https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise">https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise</a><br/>
Google Ghost Tokens<br/>
 <a href="https://astrix.security/ghosttoken-exploiting-gcp-application-infrastructure-to-create-invisible-unremovable-trojan-app-on-google-accounts/">https://astrix.security/ghosttoken-exploiting-gcp-application-infrastructure-to-create-invisible-unremovable-trojan-app-on-google-accounts/</a><br/>
PyPi Trusted Publishers<br/>
 <a href="https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/">https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8464" type="text/plain" language="en" />
<itunes:keywords>pypi, google, ghost tokens, 3xc, password, expiration, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8462</itunes:episode>
<itunes:subtitle>Chrome 0-Day; Oracle CPU; Github npm Prvenance; MSFT Threat Actor Naming;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chrome 0-Day; Oracle CPU; Github npm Prvenance; MSFT Threat Actor Naming;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8462.mp3" length="4353799" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8462.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8462</link>
<pubDate>Thu, 20 Apr 2023 10:10:54 GMT</pubDate>
<description><![CDATA[Yet Another Google Chrome 0-Day<br/>
 <a href="https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html">https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html</a><br/>
Oracle Critical Patch Update April 2023<br/>
 <a href="https://www.oracle.com/security-alerts/cpuapr2023.html">https://www.oracle.com/security-alerts/cpuapr2023.html</a><br/>
Github Provenance Action for npm Packages<br/>
 <a href="https://www.theregister.com/2023/04/19/github_actions_npm_origins/">https://www.theregister.com/2023/04/19/github_actions_npm_origins/</a><br/>
Microsoft Revises Threat Actor Naming<br/>
 <a href="https://learn.microsoft.com/de-de/microsoft-365/security/intelligence/microsoft-threat-actor-naming">https://learn.microsoft.com/de-de/microsoft-365/security/intelligence/microsoft-threat-actor-naming</a><br/>
]]></description>
<itunes:duration>4:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8462" type="text/plain" language="en" />
<itunes:keywords>microsoft, github, threat actors, npm, provenance, oracle, cpu, chrome 0-day, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 19th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8460</itunes:episode>
<itunes:subtitle>UDDIExplorer; SNMP Against Routers; Data from Discarded Routers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
UDDIExplorer; SNMP Against Routers; Data from Discarded Routers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8460.mp3" length="4823120" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8460.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8460</link>
<pubDate>Wed, 19 Apr 2023 02:00:01 GMT</pubDate>
<description><![CDATA[UDDIs Are Back: Attackers Rediscovering Old Exploits.<br/>
 <a href="https://isc.sans.edu/diary/UDDIs%20are%20back%3F%20Attackers%20rediscovering%20old%20exploits./29754UDDIExplorer;">https://isc.sans.edu/diary/UDDIs%20are%20back%3F%20Attackers%20rediscovering%20old%20exploits./29754UDDIExplorer;</a><br/>
UDDIExplorer;<br/>
Russian Attacks against Routers<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108</a><br/>
Information Leakage on Discarded Routers<br/>
 <a href="https://www.welivesecurity.com/2023/04/18/discarded-not-destroyed-old-routers-reveal-corporate-secrets/">https://www.welivesecurity.com/2023/04/18/discarded-not-destroyed-old-routers-reveal-corporate-secrets/</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8460" type="text/plain" language="en" />
<itunes:keywords>routers, snmp, leaks, ebay, russia, uddi, exploits, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8458</itunes:episode>
<itunes:subtitle>Increase in Honeypots in China; Mac Ransomware; GC2 in Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Increase in Honeypots in China; Mac Ransomware; GC2 in Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8458.mp3" length="4828640" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8458.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8458</link>
<pubDate>Tue, 18 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[The strange case of the Great Honeypot of China<br/>
 <a href="https://isc.sans.edu/diary/The%20strange%20case%20of%20Great%20honeypot%20of%20China/29750">https://isc.sans.edu/diary/The%20strange%20case%20of%20Great%20honeypot%20of%20China/29750</a><br/>
The LockBit ransomware (kinda) comes for macOS<br/>
 <a href="https://objective-see.org/blog/blog_0x75.html">https://objective-see.org/blog/blog_0x75.html</a><br/>
Google Cloud Used as C&C <br/>
 <a href="https://thehackernews.com/2023/04/google-uncovers-apt41s-use-of-open.html">https://thehackernews.com/2023/04/google-uncovers-apt41s-use-of-open.html</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8458" type="text/plain" language="en" />
<itunes:keywords>GC3, C2, malware, taiwan, china, lockbit, macos, honeypot, medical devices, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8456</itunes:episode>
<itunes:subtitle>Fake Chrome Errors; Chromium 0-Day; LAPS Compatibility Issues; Manage Engine
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake Chrome Errors; Chromium 0-Day; LAPS Compatibility Issues; Manage Engine
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8456.mp3" length="4855329" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8456.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8456</link>
<pubDate>Mon, 17 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Attack Campaing Tht Uses Fake Google Chrome Errors<br/>
 <a href="https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com">https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com</a><br/>
Chromium Publishes Emergency Update<br/>
 <a href="https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html">https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html</a><br/>
LAPS Update Errors<br/>
 <a href="https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview">https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview</a><br/>
Manage Engine Vulnerability<br/>
 <a href="https://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/">https://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8456" type="text/plain" language="en" />
<itunes:keywords>manage engine, laps, chromium, chorme, errors, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8454</itunes:episode>
<itunes:subtitle>OCSP Messages; NTP Vuln Update; SecurePoint Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OCSP Messages; NTP Vuln Update; SecurePoint Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8454.mp3" length="5758866" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8454.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8454</link>
<pubDate>Fri, 14 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[HTTP: What's Left of it and the OCSP Problem<br/>
 <a href="https://isc.sans.edu/diary/HTTP%3A%20What%27s%20Left%20of%20it%20and%20the%20OCSP%20Problem/29744">https://isc.sans.edu/diary/HTTP%3A%20What%27s%20Left%20of%20it%20and%20the%20OCSP%20Problem/29744</a><br/>
NTP Vulnerability Update<br/>
 <a href="https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321">https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321</a><br/>
SecurePoint UTM Vulnerability CVE-2023-22897<br/>
 <a href="https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/">https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/</a><br/>
 <a href="https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/">https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/</a><br/>
Google Cloud Assured Open Source Software Services<br/>
 <a href="https://cloud.google.com/blog/products/identity-security/google-cloud-assured-open-source-software-service-now-ga">https://cloud.google.com/blog/products/identity-security/google-cloud-assured-open-source-software-service-now-ga</a><br/>
]]></description>
<itunes:duration>6:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8454" type="text/plain" language="en" />
<itunes:keywords>google, assured open source software, open source, securepoint, utm, ntp, http, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8452</itunes:episode>
<itunes:subtitle>IcedID (Bokbot); MSMQ Vuln Details; ntpd vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IcedID (Bokbot); MSMQ Vuln Details; ntpd vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8452.mp3" length="5629356" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8452.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8452</link>
<pubDate>Thu, 13 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Recent IcedID (Bokbot) activity<br/>
 <a href="https://isc.sans.edu/forums/diary/Recent%20IcedID%20%28Bokbot%29%20activity/29740/">https://isc.sans.edu/forums/diary/Recent%20IcedID%20%28Bokbot%29%20activity/29740/</a><br/>
Microsoft Message Queue Vulnerabilities Details<br/>
 <a href="https://research.checkpoint.com/2023/queuejumper-critical-unauthorized-rce-vulnerability-in-msmq-service/">https://research.checkpoint.com/2023/queuejumper-critical-unauthorized-rce-vulnerability-in-msmq-service/</a><br/>
NTP Vulnerabilities<br/>
 <a href="https://github.com/spwpun/ntp-4.2.8p15-cves">https://github.com/spwpun/ntp-4.2.8p15-cves</a><br/>
 <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0938">https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0938</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8452" type="text/plain" language="en" />
<itunes:keywords>ntp, ntp.org, microsoft, msmq, icedid, bokbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8450</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Windows LAPS Update; SAP and Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Windows LAPS Update; SAP and Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8450.mp3" length="5396870" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8450.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8450</link>
<pubDate>Wed, 12 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20April%202023%20Patch%20Tuesday/29736">https://isc.sans.edu/diary/Microsoft%20April%202023%20Patch%20Tuesday/29736</a><br/>
Windows LAPS Available as part of Windows<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/by-popular-demand-windows-laps-available-now/ba-p/3788747">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/by-popular-demand-windows-laps-available-now/ba-p/3788747</a><br/>
SAP Patches<br/>
 <a href="https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html">https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8450" type="text/plain" language="en" />
<itunes:keywords>adobe, sap, patches, windows, laps, micorsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8448</itunes:episode>
<itunes:subtitle>Analysising HTA Files; Apple Updates; MSI Attacks; MSFT Altered Netlogon Update Schedule
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analysising HTA Files; Apple Updates; MSI Attacks; MSFT Altered Netlogon Update Schedule
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8448.mp3" length="5049314" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8448.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8448</link>
<pubDate>Tue, 11 Apr 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Another Malicious HTA File Analysis - Part 2<br/>
 <a href="https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%202/29676">https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%202/29676</a><br/>
Apple Updates for Older Operating Systems<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
MSI Attack May Affect BIOS Updates<br/>
 <a href="https://www.msi.com/news/detail/MSI-Statement-141688">https://www.msi.com/news/detail/MSI-Statement-141688</a><br/>
KB5021130: How to manage the Netlogon protocol changes related to CVE-2022-38023<br/>
 <a href="https://support.microsoft.com/en-us/topic/kb5021130-how-to-manage-the-netlogon-protocol-changes-related-to-cve-2022-38023-46ea3067-3989-4d40-963c-680fd9e8ee25">https://support.microsoft.com/en-us/topic/kb5021130-how-to-manage-the-netlogon-protocol-changes-related-to-cve-2022-38023-46ea3067-3989-4d40-963c-680fd9e8ee25</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8448" type="text/plain" language="en" />
<itunes:keywords>netlogon, msi, bios, firmware, apple, hta, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8446</itunes:episode>
<itunes:subtitle>YARA API Usage Rules; Apple 0-Day; VM2 Library Vuln; Netlogon Changes Coming
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
YARA API Usage Rules; Apple 0-Day; VM2 Library Vuln; Netlogon Changes Coming
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8446.mp3" length="6121662" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8446.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8446</link>
<pubDate>Mon, 10 Apr 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Detecting Suspicious API Usage with YARA Rules<br/>
 <a href="https://isc.sans.edu/diary/Detecting%20Suspicious%20API%20Usage%20with%20YARA%20Rules/29724">https://isc.sans.edu/diary/Detecting%20Suspicious%20API%20Usage%20with%20YARA%20Rules/29724</a><br/>
Apple Patching Two 0-Day Vulnerabilities in iOS and macOS<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Patching%20Two%200-Day%20Vulnerabilities%20in%20iOS%20and%20macOS/29726">https://isc.sans.edu/diary/Apple%20Patching%20Two%200-Day%20Vulnerabilities%20in%20iOS%20and%20macOS/29726</a><br/>
VM2 Sandbox Escape<br/>
 <a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-7jxr-cg7f-gpgv">https://github.com/patriksimek/vm2/security/advisories/GHSA-7jxr-cg7f-gpgv</a><br/>
 <a href="https://gist.github.com/seongil-wi/2a44e082001b959bfe304b62121fb76d">https://gist.github.com/seongil-wi/2a44e082001b959bfe304b62121fb76d</a><br/>
Microsoft Netlogon: Potential Upcoming Impacts of CVE-2022-38023<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Netlogon%3A%20Potential%20Upcoming%20Impacts%20of%20CVE-2022-38023/29728">https://isc.sans.edu/diary/Microsoft%20Netlogon%3A%20Potential%20Upcoming%20Impacts%20of%20CVE-2022-38023/29728</a><br/>
]]></description>
<itunes:duration>6:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8446" type="text/plain" language="en" />
<itunes:keywords>microsoft, netlogon, vm2, apple, ios, macos, safari, webkit, 0-day, api, yara, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8444</itunes:episode>
<itunes:subtitle>Malicious SFX Files; loldrivers; Trellix Priv Esc; HP LasterJet Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious SFX Files; loldrivers; Trellix Priv Esc; HP LasterJet Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8444.mp3" length="5867670" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8444.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8444</link>
<pubDate>Fri, 07 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Self Extracting Archives<br/>
 <a href="https://www.crowdstrike.com/blog/self-extracting-archives-decoy-files-and-their-hidden-payloads/">https://www.crowdstrike.com/blog/self-extracting-archives-decoy-files-and-their-hidden-payloads/</a><br/>
loldrivers<br/>
 <a href="https://www.loldrivers.io">https://www.loldrivers.io</a><br/>
Trellix Privilege Escalation<br/>
 <a href="https://kcm.trellix.com/corporate/index?page=content&id=SB10396">https://kcm.trellix.com/corporate/index?page=content&id=SB10396</a><br/>
HP LaserJet Vuln.<br/>
 <a href="https://support.hp.com/us-en/document/ish_7905330-7905358-16/hpsbpi03838">https://support.hp.com/us-en/document/ish_7905330-7905358-16/hpsbpi03838</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8444" type="text/plain" language="en" />
<itunes:keywords>hp, lasterjet, trellix, loldrivers, sfx, self extracting archives, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8442</itunes:episode>
<itunes:subtitle>jq and cowrie; NEXX Vulnerability; OneNote Changes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
jq and cowrie; NEXX Vulnerability; OneNote Changes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8442.mp3" length="6082191" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8442.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8442</link>
<pubDate>Thu, 06 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Exploration of DShield Cowrie Data with jq<br/>
 <a href="https://isc.sans.edu/diary/Exploration%20of%20DShield%20Cowrie%20Data%20with%20jq/29714">https://isc.sans.edu/diary/Exploration%20of%20DShield%20Cowrie%20Data%20with%20jq/29714</a><br/>
NEXX Garage Door Vulnerability<br/>
 <a href="https://medium.com/@samsabetan/the-uninvited-guest-idors-garage-doors-and-stolen-secrets-e4b49e02dadc">https://medium.com/@samsabetan/the-uninvited-guest-idors-garage-doors-and-stolen-secrets-e4b49e02dadc</a><br/>
OneNote Changes<br/>
 <a href="https://learn.microsoft.com/en-us/deployoffice/security/onenote-extension-block">https://learn.microsoft.com/en-us/deployoffice/security/onenote-extension-block</a><br/>
MSFT Changes to Auto-Update<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3060">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3060</a><br/>
NPM Spam DDoS Attacks<br/>
 <a href="https://www.helpnetsecurity.com/2023/04/05/flood-of-malicious-packages-results-in-npm-registry-dos/">https://www.helpnetsecurity.com/2023/04/05/flood-of-malicious-packages-results-in-npm-registry-dos/</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8442" type="text/plain" language="en" />
<itunes:keywords>npm, spam, ddos, microsoft, patching, one note, nexx, jq, cowrie, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 5th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8440</itunes:episode>
<itunes:subtitle>efile.com Malware; Veritas Backup Exploited; Sophos Web Applicance; Zimbra Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
efile.com Malware; Veritas Backup Exploited; Sophos Web Applicance; Zimbra Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8440.mp3" length="5594892" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8440.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8440</link>
<pubDate>Wed, 05 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Analyzing the efile.com Malware<br/>
 <a href="https://isc.sans.edu/diary/Analyzing+the+efilecom+Malware+efail/29712">https://isc.sans.edu/diary/Analyzing+the+efilecom+Malware+efail/29712</a><br/>
ALPHV Ransomware Targets Backup Installations<br/>
 <a href="https://www.mandiant.com/resources/blog/alphv-ransomware-backup">https://www.mandiant.com/resources/blog/alphv-ransomware-backup</a><br/>
Sophos Web Appliance Vulnerability (and EoL)<br/>
 <a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce">https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce</a><br/>
Zimbra Exploited in Targeted Attacks<br/>
 <a href="https://www.proofpoint.com/us/blog/threat-insight/exploitation-dish-best-served-cold-winter-vivern-uses-known-zimbra-vulnerability">https://www.proofpoint.com/us/blog/threat-insight/exploitation-dish-best-served-cold-winter-vivern-uses-known-zimbra-vulnerability</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8440" type="text/plain" language="en" />
<itunes:keywords>zimbra, sophos, alphv, ransomware, backups, veritas, efile.com, malware, phython, php, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 4th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8438</itunes:episode>
<itunes:subtitle>efile.com Compromise; MyCloud Breach; 3CX GoPuram Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
efile.com Compromise; MyCloud Breach; 3CX GoPuram Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8438.mp3" length="6832169" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8438.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8438</link>
<pubDate>Tue, 04 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[efile.com compromise<br/>
 <a href="https://isc.sans.edu/forums/diary/Supply%20Chain%20Compromise%20or%20False%20Positive%3A%20The%20Intriguing%20Case%20of%20efile.com%20%5Bupdated%20-%20confirmed%20malicious%20code%5D/29708/">https://isc.sans.edu/forums/diary/Supply%20Chain%20Compromise%20or%20False%20Positive%3A%20The%20Intriguing%20Case%20of%20efile.com%20%5Bupdated%20-%20confirmed%20malicious%20code%5D/29708/</a><br/>
Western Digital MyCloud Breach<br/>
 <a href="https://www.bleepingcomputer.com/news/security/western-digital-discloses-network-breach-my-cloud-service-down/">https://www.bleepingcomputer.com/news/security/western-digital-discloses-network-breach-my-cloud-service-down/</a><br/>
3CX Compromise Affected Cryptocoin Exchanges<br/>
 <a href="https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/">https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/</a><br/>
]]></description>
<itunes:duration>7:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8438" type="text/plain" language="en" />
<itunes:keywords>efile.com, irs, taxes, western digital, 3cx, crypto, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8436</itunes:episode>
<itunes:subtitle>Preventing Framing; Oledump Supports MSI; 3CX Update; PinDuoDuo App Issues;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Preventing Framing; Oledump Supports MSI; 3CX Update; PinDuoDuo App Issues;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8436.mp3" length="5304514" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8436.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8436</link>
<pubDate>Mon, 03 Apr 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Use of X-Frame-Options and CSP frame-ancestors security headers<br/>
 <a href="https://isc.sans.edu/diary/Use%20of%20X-Frame-Options%20and%20CSP%20frame-ancestors%20security%20headers%20on%201%20million%20most%20popular%20domains/29698">https://isc.sans.edu/diary/Use%20of%20X-Frame-Options%20and%20CSP%20frame-ancestors%20security%20headers%20on%201%20million%20most%20popular%20domains/29698</a><br/>
oledump supporting MSI Files<br/>
 <a href="https://isc.sans.edu/diary/Update+oledump+MSI+Files/29700/">https://isc.sans.edu/diary/Update+oledump+MSI+Files/29700/</a><br/>
3CX Update<br/>
 <a href="https://www.3cx.com/blog/news/chrome-blocks-latest-msi/">https://www.3cx.com/blog/news/chrome-blocks-latest-msi/</a><br/>
PinDuoDuo App shows anomalous behaviour<br/>
 <a href="https://edition.cnn.com/2023/04/02/tech/china-pinduoduo-malware-cybersecurity-analysis-intl-hnk/index.html">https://edition.cnn.com/2023/04/02/tech/china-pinduoduo-malware-cybersecurity-analysis-intl-hnk/index.html</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8436" type="text/plain" language="en" />
<itunes:keywords>pinduoduo, temu, 3cx, oledump, msi, x-frame-options, csp, frame-ancestors, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 31st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8434</itunes:episode>
<itunes:subtitle>Malicious 3CX Desktop App Update; Reverse Engineering Obfuscated Powershell via Debugger
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious 3CX Desktop App Update; Reverse Engineering Obfuscated Powershell via Debugger
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8434.mp3" length="5489704" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8434.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8434</link>
<pubDate>Fri, 31 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious 3CX Dekstop App Update<br/>
 Lifestream (Friday March 31st 1400 ET, 1800 UTC) <a href="https://www.youtube.com/watch?v=cCf3Km_j5bY">https://www.youtube.com/watch?v=cCf3Km_j5bY</a><br/>
 3CX Update: <a href="https://www.3cx.com/blog/news/desktopapp-security-alert/">https://www.3cx.com/blog/news/desktopapp-security-alert/</a><br/>
 SentinelOne: <a href="https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/">https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/</a><br/>
 Objective-See Blog Post: <a href="https://objective-see.org/blog/blog_0x73.html">https://objective-see.org/blog/blog_0x73.html</a><br/>
 Crowdstrike: <a href="https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/">https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/</a><br/>
Bypassing PowerShell Strong Obfuscation<br/>
 <a href="https://isc.sans.edu/diary/Bypassing%20PowerShell%20Strong%20Obfuscation/29692">https://isc.sans.edu/diary/Bypassing%20PowerShell%20Strong%20Obfuscation/29692</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8434" type="text/plain" language="en" />
<itunes:keywords>3cx, voip, supply chain, powershell, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 30th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8432</itunes:episode>
<itunes:subtitle>Multi Stream Extraction; 3CX Compromise; MSFT Defender False Positive;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Multi Stream Extraction; 3CX Compromise; MSFT Defender False Positive;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8432.mp3" length="4915587" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8432.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8432</link>
<pubDate>Thu, 30 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Extracting Multiple Streams From OLE Files<br/>
 <a href="https://isc.sans.edu/diary/Extracting%20Multiple%20Streams%20From%20OLE%20Files/29688">https://isc.sans.edu/diary/Extracting%20Multiple%20Streams%20From%20OLE%20Files/29688</a><br/>
3CXDesktop App Compromise<br/>
 <a href="https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/">https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/</a><br/>
Microsoft Defender False Positives<br/>
 <a href="https://twitter.com/MSFT365Status/status/1641048649525260289">https://twitter.com/MSFT365Status/status/1641048649525260289</a><br/>
 <a href="https://admin.microsoft.com/Adminportal/Home?ref=/servicehealth/:/alerts/DZ534539">https://admin.microsoft.com/Adminportal/Home?ref=/servicehealth/:/alerts/DZ534539</a> (requires login)<br/>
Active Exploitation of IBM Aspera Faspex CVE-2022-47986<br/>
 <a href="https://www.rapid7.com/blog/post/2023/03/28/etr-active-exploitation-of-ibm-aspera-faspex-cve-2022-47986/">https://www.rapid7.com/blog/post/2023/03/28/etr-active-exploitation-of-ibm-aspera-faspex-cve-2022-47986/</a><br/>
QNAP Patch for sudo vulnerablity<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-23-11">https://www.qnap.com/en/security-advisory/qsa-23-11</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8432" type="text/plain" language="en" />
<itunes:keywords>qnap, aspera, ibm, faspex, microsoft, false positives, 3cx, voip, supply chain, excel, multiple stream, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 29th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8430</itunes:episode>
<itunes:subtitle>Sensor Placement; Exchange Online Throtteling Exchange; WiFi Vulnerablity;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sensor Placement; Exchange Online Throtteling Exchange; WiFi Vulnerablity;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8430.mp3" length="4745165" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8430.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8430</link>
<pubDate>Wed, 29 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Network Data Collector Placement Makes a Difference<br/>
 <a href="https://isc.sans.edu/diary/Network%20Data%20Collector%20Placement%20Makes%20a%20Difference/29664">https://isc.sans.edu/diary/Network%20Data%20Collector%20Placement%20Makes%20a%20Difference/29664</a><br/>
Throttling and Blocking Email from Persistently Vulnerable Exchange Servers to Exchange Online<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/ba-p/3762078">https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/ba-p/3762078</a><br/>
Bypassing Wi-Fi Encryption by Manipulating Transmit Queues <br/>
 <a href="https://papers.mathyvanhoef.com/usenix2023-wifi.pdf">https://papers.mathyvanhoef.com/usenix2023-wifi.pdf</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8430" type="text/plain" language="en" />
<itunes:keywords>wifi, throttling, exchange server, network monitor, sniffer, span, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8428</itunes:episode>
<itunes:subtitle>Reversing HTA Files Part 1; Apple Patches; New MacStealer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing HTA Files Part 1; Apple Patches; New MacStealer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8428.mp3" length="4696733" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8428.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8428</link>
<pubDate>Tue, 28 Mar 2023 02:20:01 GMT</pubDate>
<description><![CDATA[Another Malicious HTA File Analysis Part 1<br/>
 <a href="https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%201/29674">https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%201/29674</a><br/>
Apple Updates Everything<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything%20%28including%20Studio%20Display%29/29682">https://isc.sans.edu/diary/Apple%20Updates%20Everything%20%28including%20Studio%20Display%29/29682</a><br/>
MacStealer Malware Exfiltrates Mac Secrets<br/>
 <a href="https://www.uptycs.com/blog/macstealer-command-and-control-c2-malware">https://www.uptycs.com/blog/macstealer-command-and-control-c2-malware</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8428" type="text/plain" language="en" />
<itunes:keywords>macstealer, apple, ipados, ios, macos, watchos, tvos, hta, reversing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8426</itunes:episode>
<itunes:subtitle>Windows Snipping Tool Updates; GitHub SSH Key Leaked; Redis-py/ChatGPT Vuln; YouTube Hacks 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Snipping Tool Updates; GitHub SSH Key Leaked; Redis-py/ChatGPT Vuln; YouTube Hacks 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8426.mp3" length="4494554" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8426.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8426</link>
<pubDate>Mon, 27 Mar 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Update for Windows Snipping Tool<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20Released%20an%20Update%20for%20Windows%20Snipping%20Tool%20Vulnerability/29670">https://isc.sans.edu/diary/Microsoft%20Released%20an%20Update%20for%20Windows%20Snipping%20Tool%20Vulnerability/29670</a><br/>
GitHub Rotates SSH Keys<br/>
 <a href="https://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key/">https://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key/</a><br/>
redis-py vulnerability leads to mixed up sessions, affects ChatGPT<br/>
 <a href="https://openai.com/blog/march-20-chatgpt-outage">https://openai.com/blog/march-20-chatgpt-outage</a><br/>
Linux Tech Tips YouTube Hack<br/>
 <a href="https://www.theverge.com/2023/3/23/23653115/linus-tech-tips-youtube-hack-crypto-scam">https://www.theverge.com/2023/3/23/23653115/linus-tech-tips-youtube-hack-crypto-scam</a><br/>
 <a href="https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434">https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434</a><br/>
CyberChef Update<br/>
 <a href="https://github.com/gchq/CyberChef/wiki/Character-encoding,-EOL-separators,-and-editor-features">https://github.com/gchq/CyberChef/wiki/Character-encoding,-EOL-separators,-and-editor-features</a><br/>
]]></description>
<itunes:duration>4:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8426" type="text/plain" language="en" />
<itunes:keywords>windows snipping tool, image cropping, github, ssh, redis-py, chatgpt, youtube hacks, cyber chef update, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8424</itunes:episode>
<itunes:subtitle>Safe Redactions; Untitled Goose; Veeam Vulnerability; Python Unicode Evasion;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Safe Redactions; Untitled Goose; Veeam Vulnerability; Python Unicode Evasion;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8424.mp3" length="5049875" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8424.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8424</link>
<pubDate>Fri, 24 Mar 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Cropping and Redacting Images Safely<br/>
 <a href="https://isc.sans.edu/diary/Cropping%20and%20Redacting%20Images%20Safely/29666">https://isc.sans.edu/diary/Cropping%20and%20Redacting%20Images%20Safely/29666</a><br/>
Untitled Goose Tool<br/>
 <a href="https://github.com/cisagov/untitledgoosetool">https://github.com/cisagov/untitledgoosetool</a><br/>
Veeam Vulnerability Details<br/>
 <a href="https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/">https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/</a><br/>
Unicode Support in Python used to Evade Detection<br/>
 <a href="https://blog.phylum.io/malicious-actors-use-unicode-support-in-python-to-evade-detection">https://blog.phylum.io/malicious-actors-use-unicode-support-in-python-to-evade-detection</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8424" type="text/plain" language="en" />
<itunes:keywords>redactions, untitled goose, veeam, python unicode, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 23rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8422</itunes:episode>
<itunes:subtitle>Detecting Badly Cropped PNGs; WooCommerce Skimmer; Orbi Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Detecting Badly Cropped PNGs; WooCommerce Skimmer; Orbi Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8422.mp3" length="5104874" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8422.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8422</link>
<pubDate>Thu, 23 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Windows Snipping Tool Privacy Bug: Inspecting PNG Files<br/>
 <a href="https://isc.sans.edu/diary/Windows%2011%20Snipping%20Tool%20Privacy%20Bug%3A%20Inspecting%20PNG%20Files/29660">https://isc.sans.edu/diary/Windows%2011%20Snipping%20Tool%20Privacy%20Bug%3A%20Inspecting%20PNG%20Files/29660</a><br/>
Acropalypse Detection and Sanitization Tools<br/>
 <a href="https://github.com/infobyte/CVE-2023-21036">https://github.com/infobyte/CVE-2023-21036</a><br/>
WooCommerce Skimmer Reveals Tampered Gateway Plugin<br/>
 <a href="https://blog.sucuri.net/2023/03/woocommerce-skimmer-reveals-tampered-gateway-plugin.html">https://blog.sucuri.net/2023/03/woocommerce-skimmer-reveals-tampered-gateway-plugin.html</a><br/>
Netgear Orbi Router Vulnerable<br/>
 <a href="https://blog.talosintelligence.com/vulnerability-spotlight-netgear-orbi-router-vulnerable-to-arbitrary-command-execution/">https://blog.talosintelligence.com/vulnerability-spotlight-netgear-orbi-router-vulnerable-to-arbitrary-command-execution/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8422" type="text/plain" language="en" />
<itunes:keywords>netgear, orbi, woocommerce, acropalypse, detection, pngdump, snipping, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 22nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8420</itunes:episode>
<itunes:subtitle>Character Pair Reversal; Windows Snipping Tool Bug; Malicious .Net; Spring Vuln; Snappy PHP Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Character Pair Reversal; Windows Snipping Tool Bug; Malicious .Net; Spring Vuln; Snappy PHP Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8420.mp3" length="5259778" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8420.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8420</link>
<pubDate>Wed, 22 Mar 2023 02:00:01 GMT</pubDate>
<description><![CDATA[String Obfuscation: Character Pair Reversal<br/>
 <a href="https://isc.sans.edu/diary/String%20Obfuscation%3A%20Character%20Pair%20Reversal/29654">https://isc.sans.edu/diary/String%20Obfuscation%3A%20Character%20Pair%20Reversal/29654</a><br/>
Windows 11 Snipping Tool Privacy Bug<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/">https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/</a><br/>
Malicious .Net Packages<br/>
 <a href="https://jfrog.com/blog/attackers-are-starting-to-target-net-developers-with-malicious-code-nuget-packages/">https://jfrog.com/blog/attackers-are-starting-to-target-net-developers-with-malicious-code-nuget-packages/</a><br/>
Spring Framework Vulnerability<br/>
 <a href="https://spring.io/blog/2023/03/20/spring-framework-6-0-7-and-5-3-26-fix-cve-2023-20860-and-cve-2023-20861">https://spring.io/blog/2023/03/20/spring-framework-6-0-7-and-5-3-26-fix-cve-2023-20860-and-cve-2023-20861</a><br/>
Snappy Vulnerability<br/>
 <a href="https://github.com/KnpLabs/snappy/security/advisories/GHSA-gq6w-q6wh-jggc">https://github.com/KnpLabs/snappy/security/advisories/GHSA-gq6w-q6wh-jggc</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8420" type="text/plain" language="en" />
<itunes:keywords>snappy, php, spring, .Net, nuget, windows 11, cropping images, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 21st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8418</itunes:episode>
<itunes:subtitle>More Telegram Phishing; Emotet OneNote; WSUS Update; DOTRUNPEX;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Telegram Phishing; Emotet OneNote; WSUS Update; DOTRUNPEX;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8418.mp3" length="4657048" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8418.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8418</link>
<pubDate>Tue, 21 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[From Phishing Kit to Telegram ... or Not<br/>
 <a href="https://isc.sans.edu/diary/From%20Phishing%20Kit%20To%20Telegram...%20or%20Not!/29650">https://isc.sans.edu/diary/From%20Phishing%20Kit%20To%20Telegram...%20or%20Not!/29650</a><br/>
Emotet uses OneNote<br/>
 <a href="https://cofense.com/blog/emotet-sending-malicious-emails-after-three-month-hiatus/">https://cofense.com/blog/emotet-sending-malicious-emails-after-three-month-hiatus/</a><br/>
WSUS Update<br/>
 <a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/plan/plan-your-wsus-deployment#uup-considerations">https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/plan/plan-your-wsus-deployment#uup-considerations</a><br/>
DOTRUNPEX .Net Injector<br/>
 <a href="https://research.checkpoint.com/2023/dotrunpex-demystifying-new-virtualized-net-injector-used-in-the-wild/">https://research.checkpoint.com/2023/dotrunpex-demystifying-new-virtualized-net-injector-used-in-the-wild/</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8418" type="text/plain" language="en" />
<itunes:keywords>telegram, emotet, onenote, wsus, update, dotrunpex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8416</itunes:episode>
<itunes:subtitle>Obfuscated Backdoor; Samsung Exynos Vuln; Android Image Cropping Problem; Bitwarden PIN
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated Backdoor; Samsung Exynos Vuln; Android Image Cropping Problem; Bitwarden PIN
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8416.mp3" length="6009252" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8416.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8416</link>
<pubDate>Mon, 20 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Old Backdoor, New Obfuscation<br/>
 <a href="https://isc.sans.edu/diary/Old%20Backdoor%2C%20New%20Obfuscation/29646">https://isc.sans.edu/diary/Old%20Backdoor%2C%20New%20Obfuscation/29646</a><br/>
Samsung Exynos Chip Vulnerability<br/>
 <a href="https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html">https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html</a><br/>
Android Image Cropping Problem<br/>
 <a href="https://twitter.com/ItsSimonTime/status/1636857478263750656/photo/1">https://twitter.com/ItsSimonTime/status/1636857478263750656/photo/1</a><br/>
 <a href="https://acropalypse.app/">https://acropalypse.app/</a><br/>
Bitwarden Pins<br/>
 <a href="https://ambiso.github.io/bitwarden-pin/">https://ambiso.github.io/bitwarden-pin/</a><br/>
]]></description>
<itunes:duration>6:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8416" type="text/plain" language="en" />
<itunes:keywords>bitwarden, android, image cropping, redaction, samsung, exynos, backdoor, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8414</itunes:episode>
<itunes:subtitle>Dissecting Shellcode; Telerik Exploit; Adobe Acrobat Sign Abuse; Patches for Zoom, Array Networks and Aruba
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dissecting Shellcode; Telerik Exploit; Adobe Acrobat Sign Abuse; Patches for Zoom, Array Networks and Aruba
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8414.mp3" length="6359017" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8414.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8414</link>
<pubDate>Fri, 17 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Simple Shellcode Dissection<br/>
 <a href="https://isc.sans.edu/diary/Simple%20Shellcode%20Dissection/29642">https://isc.sans.edu/diary/Simple%20Shellcode%20Dissection/29642</a><br/>
Threat Actors Exploit Progress Telerik Vulnerablity<br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-074a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-074a</a><br/>
Abusing Adobe Acrobat Sign to Distribute Malware<br/>
 <a href="https://blog.avast.com/adobe-acrobat-sign-malware">https://blog.avast.com/adobe-acrobat-sign-malware</a><br/>
Zoom Patches<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
Array Networks Advisory<br/>
 <a href="https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf">https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf</a><br/>
Aruba Patches<br/>
 <a href="https://www.arubanetworks.com/support-services/security-bulletins/">https://www.arubanetworks.com/support-services/security-bulletins/</a><br/>
]]></description>
<itunes:duration>7:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8414" type="text/plain" language="en" />
<itunes:keywords>array, advisorsy, zoom, aruba, adobe, acrobat sign, malware, telerik, shellcode, excel, equation editor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8412</itunes:episode>
<itunes:subtitle>IPFS Phishing and iFrames; CVE-2023-23997 Exploit; Windows ICMP RCE; 90 Day Cert Limit;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IPFS Phishing and iFrames; CVE-2023-23997 Exploit; Windows ICMP RCE; 90 Day Cert Limit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8412.mp3" length="5854909" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8412.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8412</link>
<pubDate>Thu, 16 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[IPFS Phishing and the need for correctly set HTTP security headers<br/>
 <a href="https://isc.sans.edu/diary/IPFS%20phishing%20and%20the%20need%20for%20correctly%20set%20HTTP%20security%20headers/29638">https://isc.sans.edu/diary/IPFS%20phishing%20and%20the%20need%20for%20correctly%20set%20HTTP%20security%20headers/29638</a><br/>
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability<br/>
 <a href="https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/">https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/</a><br/>
CVE-2023-23415 ICMP RCE<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23415">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23415</a><br/>
Chromium Certificate Proposals<br/>
 <a href="https://www.chromium.org/Home/chromium-security/root-ca-policy/moving-forward-together/">https://www.chromium.org/Home/chromium-security/root-ca-policy/moving-forward-together/</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8412" type="text/plain" language="en" />
<itunes:keywords>certificates, lifetime, icmp, rce, outlook, exploit, ipfs, phishing, iframes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8410</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches; SAP Patches; Firefox Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches; SAP Patches; Firefox Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8410.mp3" length="5704700" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8410.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8410</link>
<pubDate>Wed, 15 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20March%202023%20Patch%20Tuesday/29634">https://isc.sans.edu/diary/Microsoft%20March%202023%20Patch%20Tuesday/29634</a><br/>
Adobe Cold Fusion and Magento (Adobe Commerce) patches<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb23-17.html">https://helpx.adobe.com/security/products/magento/apsb23-17.html</a><br/>
 <a href="https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html">https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html</a><br/>
SAP Patches<br/>
 <a href="https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html">https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html</a><br/>
Firefox Patches<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2023-09/">https://www.mozilla.org/en-US/security/advisories/mfsa2023-09/</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8410" type="text/plain" language="en" />
<itunes:keywords>firefox, SAP, Adobe, Cold Fusion, Magento, Adobe Commerce, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8408</itunes:episode>
<itunes:subtitle>#SVB Scams; CISO KEV List Additions; FortiOS Vuln Exploited;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#SVB Scams; CISO KEV List Additions; FortiOS Vuln Exploited;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8408.mp3" length="4766206" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8408.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8408</link>
<pubDate>Tue, 14 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[SVB Scams and New Domain Registrations<br/>
 <a href="https://isc.sans.edu/diary/Incoming%20Silicon%20Valley%20Bank%20Related%20Scams/29630">https://isc.sans.edu/diary/Incoming%20Silicon%20Valley%20Bank%20Related%20Scams/29630</a><br/>
CISA Adds Older PLEX and VMWare Vulnerablities to Known-Exploited List<br/>
 <a href="https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-plex-bug-after-lastpass-breach/">https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-plex-bug-after-lastpass-breach/</a><br/>
FortiOS Vulnerability Exploited<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-22-369">https://www.fortiguard.com/psirt/FG-IR-22-369</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8408" type="text/plain" language="en" />
<itunes:keywords>fortios, cisa, svb, scams, domains, plex, vmware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8406</itunes:episode>
<itunes:subtitle>AsynRAT Trojan; Mirai Payload Generator; Browser Hijack; OneNote Embeded File Protection; No more Chrome Cleanup Tool
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AsynRAT Trojan; Mirai Payload Generator; Browser Hijack; OneNote Embeded File Protection; No more Chrome Cleanup Tool
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8406.mp3" length="5077025" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8406.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8406</link>
<pubDate>Mon, 13 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[AsynRAT Trojan - Bill Payment (Pago de la factura)<br/>
 <a href="https://isc.sans.edu/diary/AsynRAT+Trojan+Bill+Payment+Pago+de+la+factura/29626">https://isc.sans.edu/diary/AsynRAT+Trojan+Bill+Payment+Pago+de+la+factura/29626</a><br/>
Mirai Payload Generator<br/>
 <a href="https://isc.sans.edu/diary/Overview%20of%20a%20Mirai%20Payload%20Generator/29624">https://isc.sans.edu/diary/Overview%20of%20a%20Mirai%20Payload%20Generator/29624</a><br/>
Multi-Technology Script Leading to Browser Hijacking<br/>
 <a href="https://isc.sans.edu/diary/Multi-Technology%20Script%20Leading%20to%20Browser%20Hijacking/29620">https://isc.sans.edu/diary/Multi-Technology%20Script%20Leading%20to%20Browser%20Hijacking/29620</a><br/>
OneNote will warn users of embeded content<br/>
 <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=OneNote%2CIn%20development&searchterms=122277">https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=OneNote%2CIn%20development&searchterms=122277</a><br/>
Google Removing Chrome Cleanup Tool<br/>
 <a href="https://security.googleblog.com/2023/03/thank-you-and-goodbye-to-chrome-cleanup.html">https://security.googleblog.com/2023/03/thank-you-and-goodbye-to-chrome-cleanup.html</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8406" type="text/plain" language="en" />
<itunes:keywords>google, chrome, clenaup tool, onenote, browser hijacking, mirai, asynrat, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8404</itunes:episode>
<itunes:subtitle>Sonicwall Backdoor; WebLogic "Crypter"; Home Assistant Vuln; Fake ChatGPT
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sonicwall Backdoor; WebLogic "Crypter"; Home Assistant Vuln; Fake ChatGPT
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8404.mp3" length="5671674" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8404.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8404</link>
<pubDate>Fri, 10 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Suspected Chinese Campaign to Persist on SonicWall Devices<br/>
 <a href="https://www.mandiant.com/resources/blog/suspected-chinese-persist-sonicwall">https://www.mandiant.com/resources/blog/suspected-chinese-persist-sonicwall</a><br/>
Old Cyber Gang Uses New Crypted - ScrubCrypt<br/>
 <a href="https://www.fortinet.com/blog/threat-research/old-cyber-gang-uses-new-crypter-scrubcrypt">https://www.fortinet.com/blog/threat-research/old-cyber-gang-uses-new-crypter-scrubcrypt</a><br/>
Home Assistant Supervisor Security Vulnerability<br/>
 <a href="https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure/">https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure/</a><br/>
Fake ChatGPT Chrome Extensions<br/>
 <a href="https://www.helpnetsecurity.com/2023/03/09/fake-chatgpt-extension/">https://www.helpnetsecurity.com/2023/03/09/fake-chatgpt-extension/</a><br/>
Criminals Steal Crytocurrency through Play-to-Earn Games<br/>
 <a href="https://www.ic3.gov/Media/Y2023/PSA230309">https://www.ic3.gov/Media/Y2023/PSA230309</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8404" type="text/plain" language="en" />
<itunes:keywords>crytocurrency, gold farming, play-to-earn, chatgpt, home assistant, scrybcrypt, sonicwall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8402</itunes:episode>
<itunes:subtitle>Joomla Exploits; Jenkins RCE Vuln; Bitwarden Vuln; FortiOS Update; Veeam Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Joomla Exploits; Jenkins RCE Vuln; Bitwarden Vuln; FortiOS Update; Veeam Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8402.mp3" length="5664455" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8402.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8402</link>
<pubDate>Thu, 09 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Increase in exploits against Joomla (CVE-2023-23752)<br/>
 <a href="https://isc.sans.edu/diary/Increase%20in%20exploits%20agains%20Joomla%20%28CVE-2023-23752%29/29614">https://isc.sans.edu/diary/Increase%20in%20exploits%20agains%20Joomla%20%28CVE-2023-23752%29/29614</a><br/>
Jenkins RCE Vulnerability<br/>
 <a href="https://blog.aquasec.com/jenkins-server-vulnerabilities">https://blog.aquasec.com/jenkins-server-vulnerabilities</a><br/>
Bitwarden: The Curious Use-Case of Password Pilfering<br/>
 <a href="https://flashpoint.io/blog/bitwarden-password-pilfering/">https://flashpoint.io/blog/bitwarden-password-pilfering/</a><br/>
FortiOS Vulnerabilities<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-23-001">https://www.fortiguard.com/psirt/FG-IR-23-001</a><br/>
Veeam Backup Vulnerabilities<br/>
 <a href="https://www.veeam.com/kb4245">https://www.veeam.com/kb4245</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8402" type="text/plain" language="en" />
<itunes:keywords>veeam, fortios, bitwarden, jenkins, joomla, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8400</itunes:episode>
<itunes:subtitle>VSCode SFTP Creds Leak; Clipboard Protection; Sys01 Facebook Info Stealer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VSCode SFTP Creds Leak; Clipboard Protection; Sys01 Facebook Info Stealer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8400.mp3" length="5067975" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8400.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8400</link>
<pubDate>Wed, 08 Mar 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Hackers Love This VSCode Extension: What You Can Do to Stay Safe<br/>
 <a href="https://isc.sans.edu/diary/Hackers%20Love%20This%20VSCode%20Extension%3A%20What%20You%20Can%20Do%20to%20Stay%20Safe/29610">https://isc.sans.edu/diary/Hackers%20Love%20This%20VSCode%20Extension%3A%20What%20You%20Can%20Do%20to%20Stay%20Safe/29610</a><br/>
Protecting Android Clipboard Content from Unintended Exposure<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/">https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/</a><br/>
SYS01 Stealer Targeting Facebook Accounts<br/>
 <a href="https://blog.morphisec.com/sys01stealer-facebook-info-stealer">https://blog.morphisec.com/sys01stealer-facebook-info-stealer</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8400" type="text/plain" language="en" />
<itunes:keywords>sys01 stealer, facebook, android, clipboard, vscode, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8398</itunes:episode>
<itunes:subtitle>S3 Scanning; Router Malware; SonicWall Vuln; Word RCE PoC; Remcos RAT Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
S3 Scanning; Router Malware; SonicWall Vuln; Word RCE PoC; Remcos RAT Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8398.mp3" length="4590334" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8398.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8398</link>
<pubDate>Tue, 07 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Scanning s3 Buckets<br/>
 <a href="https://isc.sans.edu/diary/Scanning%20s3%20buckets/29606">https://isc.sans.edu/diary/Scanning%20s3%20buckets/29606</a><br/>
HiatusRAT Router Malware<br/>
 <a href="https://blog.lumen.com/new-hiatusrat-router-malware-covertly-spies-on-victims/">https://blog.lumen.com/new-hiatusrat-router-malware-covertly-spies-on-victims/</a><br/>
SonicWall Vulnerability<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004</a><br/>
Windows Word RCE Proof-of-Concept<br/>
 <a href="https://twitter.com/jduck/status/1632471544935923712">https://twitter.com/jduck/status/1632471544935923712</a> <br/>
 <a href="https://qoop.org/publications/cve-2023-21716-rtf-fonttbl.md">https://qoop.org/publications/cve-2023-21716-rtf-fonttbl.md</a><br/>
DBatLoader and Remcos RAT<br/>
 <a href="https://www.sentinelone.com/blog/dbatloader-and-remcos-rat-sweep-eastern-europe/">https://www.sentinelone.com/blog/dbatloader-and-remcos-rat-sweep-eastern-europe/</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8398" type="text/plain" language="en" />
<itunes:keywords>dbatloader, remcos rat, windows, word, rce, poc, sonicwall, hiatusrat, s3 buckets, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8396</itunes:episode>
<itunes:subtitle>SANS.edu Commencement; SCARLETEEL Cloud Attacks; Preventing OneNote Exploits; Redis Exploits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS.edu Commencement; SCARLETEEL Cloud Attacks; Preventing OneNote Exploits; Redis Exploits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8396.mp3" length="4590009" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8396.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8396</link>
<pubDate>Mon, 06 Mar 2023 02:00:01 GMT</pubDate>
<description><![CDATA[SANS.edu Commencement<br/>
 <a href="https://www.linkedin.com/feed/update/urn:li:activity:7037794067266625536/">https://www.linkedin.com/feed/update/urn:li:activity:7037794067266625536/</a><br/>
SCARLETEEL: Operation Leverating Terraform, Kubernetes and AWS for data theft<br/>
 <a href="https://sysdig.com/blog/cloud-breach-terraform-data-theft/">https://sysdig.com/blog/cloud-breach-terraform-data-theft/</a><br/>
Preventing Malicious OneNote Files<br/>
 <a href="https://www.bleepingcomputer.com/news/security/how-to-prevent-microsoft-onenote-files-from-infecting-windows-with-malware/">https://www.bleepingcomputer.com/news/security/how-to-prevent-microsoft-onenote-files-from-infecting-windows-with-malware/</a><br/>
Redis Miner Leverages Command Line File Hosting Service<br/>
 <a href="https://www.cadosecurity.com/redis-miner-leverages-command-line-file-hosting-service/">https://www.cadosecurity.com/redis-miner-leverages-command-line-file-hosting-service/</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8396" type="text/plain" language="en" />
<itunes:keywords>redis, miner, onenote, scarleteel, sans.edu, commencement, crypto miner, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8394</itunes:episode>
<itunes:subtitle>Malicious OneNote and YARA; DroneID Security; OAuth Flaw; Marco Gfeller Malware Analysis Pipeline #sans_edu 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious OneNote and YARA; DroneID Security; OAuth Flaw; Marco Gfeller Malware Analysis Pipeline #sans_edu 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8394.mp3" length="12263322" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8394.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8394</link>
<pubDate>Fri, 03 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[YARA: Detect the Unexpected<br/>
 <a href="https://isc.sans.edu/diary/YARA%3A%20Detect%20The%20Unexpected%20.../29598">https://isc.sans.edu/diary/YARA%3A%20Detect%20The%20Unexpected%20.../29598</a><br/>
Drone Security and the Mysterious Case of DJI's DroneID<br/>
 <a href="https://github.com/RUB-SysSec/DroneSecurity">https://github.com/RUB-SysSec/DroneSecurity</a><br/>
Booking.com OAuth Flaw<br/>
 <a href="https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com">https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com</a><br/>
SANS.edu Student Marco Gfeller: Lightweight Python-Based Malware Analysis Pipeline<br/>
 <a href="https://www.sans.org/white-papers/lightweight-python-based-malware-analysis-pipeline/">https://www.sans.org/white-papers/lightweight-python-based-malware-analysis-pipeline/</a><br/>
]]></description>
<itunes:duration>14:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8394" type="text/plain" language="en" />
<itunes:keywords>malware, python, pipeline, sans.edu, booking, oauth, drone, dji, droneid, yara, onenote, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8392</itunes:episode>
<itunes:subtitle>Game Infostealer; DNS Abuse Matrix; BlackLotus; TPM Vuln; Aruba Vuln; Cisco Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Game Infostealer; DNS Abuse Matrix; BlackLotus; TPM Vuln; Aruba Vuln; Cisco Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8392.mp3" length="5067026" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8392.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8392</link>
<pubDate>Thu, 02 Mar 2023 02:05:02 GMT</pubDate>
<description><![CDATA[Python Infostealer Targeting Gamers<br/>
 <a href="https://isc.sans.edu/diary/Python%20Infostealer%20Targeting%20Gamers/29596">https://isc.sans.edu/diary/Python%20Infostealer%20Targeting%20Gamers/29596</a><br/>
DNS Abuse Techniques Matrix<br/>
 <a href="https://www.first.org/global/sigs/dns/DNS-Abuse-Techniques-Matrix_v1.1.pdf">https://www.first.org/global/sigs/dns/DNS-Abuse-Techniques-Matrix_v1.1.pdf</a><br/>
BlackLotus UEFI Bootkit<br/>
 <a href="https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/">https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/</a><br/>
TCG TPM2.0 implementations vulnerable to memory corruption<br/>
 <a href="https://kb.cert.org/vuls/id/782720">https://kb.cert.org/vuls/id/782720</a><br/>
Aruba Vulnerability<br/>
 <a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-002.txt">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-002.txt</a><br/>
Cisco VoIP Phone WebUI RCE<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8392" type="text/plain" language="en" />
<itunes:keywords>Cisco, voip, webui, arbua, tcg, tpm, dns abuse, python, infostealer, gamers, steam, telegram, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8390</itunes:episode>
<itunes:subtitle>BB17 and Qakbot; LastPass Details; CISA RedTeam Lessons; Jailbreak Chat
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BB17 and Qakbot; LastPass Details; CISA RedTeam Lessons; Jailbreak Chat
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8390.mp3" length="5418607" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8390.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8390</link>
<pubDate>Wed, 01 Mar 2023 02:00:02 GMT</pubDate>
<description><![CDATA[BB11 Distribution Qakbot (Qbot) activity<br/>
 <a href="https://isc.sans.edu/diary/BB17%20distribution%20Qakbot%20%28Qbot%29%20activity/29592">https://isc.sans.edu/diary/BB17%20distribution%20Qakbot%20%28Qbot%29%20activity/29592</a><br/>
LastPass Incident Details<br/>
 <a href="https://support.lastpass.com/help/incident-1-additional-details-of-the-attack">https://support.lastpass.com/help/incident-1-additional-details-of-the-attack</a><br/>
 <a href="https://support.lastpass.com/help/incident-2-additional-details-of-the-attack">https://support.lastpass.com/help/incident-2-additional-details-of-the-attack</a><br/>
CISA Red Team Shares Key Findings <br/>
 <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-059a">https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-059a</a><br/>
Jailbreak Chat<br/>
 <a href="https://www.jailbreakchat.com">https://www.jailbreakchat.com</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8390" type="text/plain" language="en" />
<itunes:keywords>jailbreak, cisa, lastpass, bb11, qakbot, qbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 28th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8388</itunes:episode>
<itunes:subtitle>Phishing Again; Unlocked Phone Stealing; More Fake Auth Apps; Zoneminder Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing Again; Unlocked Phone Stealing; More Fake Auth Apps; Zoneminder Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8388.mp3" length="4742454" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8388.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8388</link>
<pubDate>Tue, 28 Feb 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Phishing Again and Again<br/>
 <a href="https://isc.sans.edu/diary/Phishing%20Again%20and%20Again/29588">https://isc.sans.edu/diary/Phishing%20Again%20and%20Again/29588</a><br/>
Unlocked Phone Stealing<br/>
 <a href="https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a">https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a</a><br/>
More Fake Authenticator Apps<br/>
 <a href="https://nakedsecurity.sophos.com/2023/02/27/beware-rogue-2fa-apps-in-app-store-and-google-play-dont-get-hacked/">https://nakedsecurity.sophos.com/2023/02/27/beware-rogue-2fa-apps-in-app-store-and-google-play-dont-get-hacked/</a><br/>
Zoneminder Vulnerability<br/>
 <a href="https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-72rg-h4vf-29gr">https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-72rg-h4vf-29gr</a><br/>
WebLogic Exploit (not verified) CVE-2023-21839<br/>
 <a href="https://github.com/4ra1n/CVE-2023-21839/blob/master/cmd/main.go">https://github.com/4ra1n/CVE-2023-21839/blob/master/cmd/main.go</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8388" type="text/plain" language="en" />
<itunes:keywords>weblogic, zoneminder, fake authenticator, unlocked, phone, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8386</itunes:episode>
<itunes:subtitle>WebDav Leads to IcedID; oledump msi plugin; Automatic BEC/Ransomware Discrution; Cisco Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebDav Leads to IcedID; oledump msi plugin; Automatic BEC/Ransomware Discrution; Cisco Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8386.mp3" length="5686453" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8386.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8386</link>
<pubDate>Mon, 27 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[URL Files and WebDav used for IcedId Bockbot Infection<br/>
 <a href="https://isc.sans.edu/diary/URL%20files%20and%20WebDAV%20used%20for%20IcedID%20%28Bokbot%29%20infection/29578">https://isc.sans.edu/diary/URL%20files%20and%20WebDAV%20used%20for%20IcedID%20%28Bokbot%29%20infection/29578</a><br/>
oledump msi file plugin<br/>
 <a href="https://isc.sans.edu/diary/oledump%20%26%20MSI%20Files/29584">https://isc.sans.edu/diary/oledump%20%26%20MSI%20Files/29584</a><br/>
Automatic Disruption of Ransomware and BEC attacks with Microsoft 365 Defender<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/automatic-disruption-of-ransomware-and-bec-attacks-with/ba-p/3738294">https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/automatic-disruption-of-ransomware-and-bec-attacks-with/ba-p/3738294</a><br/>
Cisco Vulnerabilities<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-csrfv-DMx6KSwV">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-csrfv-DMx6KSwV</a><br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-lldp-dos-ySCNZOpX">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-lldp-dos-ySCNZOpX</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8386" type="text/plain" language="en" />
<itunes:keywords>cisco, ransomware, bec, microsoft 365, defender, oledump, msi, webdav, icedid, bockbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8384</itunes:episode>
<itunes:subtitle>Updated Exchange AV Guidance; Home Network Security; Datacenter Attacks; npm spam; more malicious pypi
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Updated Exchange AV Guidance; Home Network Security; Datacenter Attacks; npm spam; more malicious pypi
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8384.mp3" length="4847296" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8384.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8384</link>
<pubDate>Fri, 24 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Updated Exchange AV Guidance<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/update-on-the-exchange-server-antivirus-exclusions/ba-p/3751464">https://techcommunity.microsoft.com/t5/exchange-team-blog/update-on-the-exchange-server-antivirus-exclusions/ba-p/3751464</a><br/>
Best Practices for Securing Your Home Network<br/>
 <a href="https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF">https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF</a><br/>
Attacks on Data Center Organizations<br/>
 <a href="https://www.resecurity.com/blog/article/cyber-attacks-on-data-center-organizations">https://www.resecurity.com/blog/article/cyber-attacks-on-data-center-organizations</a><br/>
NPM Package Phishing<br/>
 <a href="https://checkmarx.com/blog/how-npm-packages-were-used-to-spread-phishing-links/">https://checkmarx.com/blog/how-npm-packages-were-used-to-spread-phishing-links/</a><br/>
Malicious PyPi Packages<br/>
 <a href="https://www.fortinet.com/blog/threat-research/more-supply-chain-attacks-via-new-malicious-python-packages-in-pypi">https://www.fortinet.com/blog/threat-research/more-supply-chain-attacks-via-new-malicious-python-packages-in-pypi</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8384" type="text/plain" language="en" />
<itunes:keywords>pypi, npm, data centers, home network, av guidance, exchange, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 23rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8382</itunes:episode>
<itunes:subtitle>Confluence Scans; Apple Advisories Updates; Odd 2FA Apps in Apple Appstore; VMware Carbon Black Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Confluence Scans; Apple Advisories Updates; Odd 2FA Apps in Apple Appstore; VMware Carbon Black Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8382.mp3" length="5014601" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8382.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8382</link>
<pubDate>Thu, 23 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Internet Wide Scan Fingerprinting Confluence Servers<br/>
 <a href="https://isc.sans.edu/diary/Internet%20Wide%20Scan%20Fingerprinting%20Confluence%20Servers/29574">https://isc.sans.edu/diary/Internet%20Wide%20Scan%20Fingerprinting%20Confluence%20Servers/29574</a><br/>
Apple Updates Advisories<br/>
 <a href="https://support.apple.com/en-us/HT213606">https://support.apple.com/en-us/HT213606</a><br/>
 <a href="https://support.apple.com/en-us/HT213605">https://support.apple.com/en-us/HT213605</a><br/>
 <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/trellix-advanced-research-center-discovers-a-new-privilege-escalation-bug-class-on-macos-and-ios.html">https://www.trellix.com/en-us/about/newsroom/stories/research/trellix-advanced-research-center-discovers-a-new-privilege-escalation-bug-class-on-macos-and-ios.html</a><br/>
Questionable two-factor Apps<br/>
 <a href="https://twitter.com/mysk_co/status/1627097291063435264">https://twitter.com/mysk_co/status/1627097291063435264</a><br/>
VMWare Carbon Black App Control Vulnerability<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0004.html">https://www.vmware.com/security/advisories/VMSA-2023-0004.html</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8382" type="text/plain" language="en" />
<itunes:keywords>vmware, carbon black, two-factor, apple, vulnerability, confluence, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 22nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8380</itunes:episode>
<itunes:subtitle>Customized Phishing; FortiNAC Exploit; Apache Commons FileUpload Fix; VMWare Win Server 2022 Fix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Customized Phishing; FortiNAC Exploit; Apache Commons FileUpload Fix; VMWare Win Server 2022 Fix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8380.mp3" length="4459211" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8380.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8380</link>
<pubDate>Wed, 22 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Phishing Page Branded with Your Corporate Website<br/>
 <a href="https://isc.sans.edu/diary/Phishing%20Page%20Branded%20with%20Your%20Corporate%20Website/29570">https://isc.sans.edu/diary/Phishing%20Page%20Branded%20with%20Your%20Corporate%20Website/29570</a><br/>
Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs<br/>
 <a href="https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/">https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/</a><br/>
Apache Commons FileUpload Vulnerability<br/>
 <a href="https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy">https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy</a><br/>
VMWare Windows Server 2022 Fix<br/>
 <a href="https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-esxi-70u3k-release-notes.html#resolvedissues">https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-esxi-70u3k-release-notes.html#resolvedissues</a><br/>
]]></description>
<itunes:duration>4:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8380" type="text/plain" language="en" />
<itunes:keywords>vmware, windows, server, 2022, apache, commons, fileupload, fortinac, fortinet, cve-2022-39952, phishing, thum.io, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 21st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8378</itunes:episode>
<itunes:subtitle>OneNote Suricata Rules; New IIS Backdoor; Outlook Spam; Godaddy Breach
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OneNote Suricata Rules; New IIS Backdoor; Outlook Spam; Godaddy Breach
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8378.mp3" length="5151720" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8378.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8378</link>
<pubDate>Tue, 21 Feb 2023 02:00:01 GMT</pubDate>
<description><![CDATA[OneNote Suricata Rules<br/>
 <a href="https://isc.sans.edu/diary/OneNote%20Suricata%20Rules/29564">https://isc.sans.edu/diary/OneNote%20Suricata%20Rules/29564</a><br/>
New IIS Backdoor<br/>
 <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/frebniis-malware-iis">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/frebniis-malware-iis</a><br/>
Outlook Spam<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/">https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/</a><br/>
Godaddy Breach and Website Redirects<br/>
 <a href="https://aboutus.godaddy.net/newsroom/company-news/news-details/2023/Statement-on-recent-website-redirect-issues/default.aspx">https://aboutus.godaddy.net/newsroom/company-news/news-details/2023/Statement-on-recent-website-redirect-issues/default.aspx</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8378" type="text/plain" language="en" />
<itunes:keywords>godaddy, outlook, iis, onenote, suricata, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8376</itunes:episode>
<itunes:subtitle>Phishing Emails; Twitter 2FA; Fortinet; Cisco Patches related to ClamAV
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing Emails; Twitter 2FA; Fortinet; Cisco Patches related to ClamAV
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8376.mp3" length="5159366" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8376.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8376</link>
<pubDate>Mon, 20 Feb 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Phishing Emails to out Handlers Inbox<br/>
 <a href="https://isc.sans.edu/diary/Spear%20Phishing%20Handlers%20for%20Username%20Password/29560">https://isc.sans.edu/diary/Spear%20Phishing%20Handlers%20for%20Username%20Password/29560</a><br/>
Twitter Alters 2FA<br/>
 <a href="https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter">https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter</a><br/>
Fortinet Updates<br/>
 <a href="https://www.fortiguard.com/psirt-monthly-advisory/february-2023-vulnerability-advisories">https://www.fortiguard.com/psirt-monthly-advisory/february-2023-vulnerability-advisories</a><br/>
 <a href="https://twitter.com/Horizon3Attack/status/1626692778062237713">https://twitter.com/Horizon3Attack/status/1626692778062237713</a><br/>
Cisco ClamAV Patches<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8376" type="text/plain" language="en" />
<itunes:keywords>cisco, clamav, fortnet, twitter, 2fa, sms, phishing, ipfs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8374</itunes:episode>
<itunes:subtitle>Browser in Browser; Windows VM Issues; ESXi Args Update; PHP Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Browser in Browser; Windows VM Issues; ESXi Args Update; PHP Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8374.mp3" length="4760526" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8374.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8374</link>
<pubDate>Fri, 17 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[HTML Phishing Attachment with Browser-in-the-Browser Technique<br/>
 <a href="https://isc.sans.edu/diary/HTML%20phishing%20attachment%20with%20browser-in-the-browser%20technique/29556">https://isc.sans.edu/diary/HTML%20phishing%20attachment%20with%20browser-in-the-browser%20technique/29556</a><br/>
Windows Server 2022 Might Not Start Up After Updates<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#windows-server-2022-might-not-start-up">https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#windows-server-2022-might-not-start-up</a><br/>
New ESXiArgs Encryption Routing Outmaneuvers Recovery Methods<br/>
 <a href="https://www.malwarebytes.com/blog/news/2023/02/new-esxiargs-encryption-routine-outmaneuvers-recovery-methods">https://www.malwarebytes.com/blog/news/2023/02/new-esxiargs-encryption-routine-outmaneuvers-recovery-methods</a><br/>
PHP Updates<br/>
 <a href="https://www.php.net">https://www.php.net</a><br/>
ClamAV Patches<br/>
 <a href="https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html">https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8374" type="text/plain" language="en" />
<itunes:keywords>clamav, php, esxiargs, windows server 2022, patches, problmes, html, browser in the browser, bib, bitb, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8372</itunes:episode>
<itunes:subtitle>Passive DNS; GitHub Copilot Update; Hyundai Patches; Firefox, Citrix and HAProxy Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Passive DNS; GitHub Copilot Update; Hyundai Patches; Firefox, Citrix and HAProxy Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8372.mp3" length="4967157" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8372.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8372</link>
<pubDate>Thu, 16 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[DNS Recon Redux<br/>
 <a href="https://isc.sans.edu/diary/DNS%20Recon%20Redux%20-%20Zone%20Transfers%20%28plus%20a%20time%20machine%29%20for%20When%20You%20Can%27t%20do%20a%20Zone%20Transfer/29552">https://isc.sans.edu/diary/DNS%20Recon%20Redux%20-%20Zone%20Transfers%20%28plus%20a%20time%20machine%29%20for%20When%20You%20Can%27t%20do%20a%20Zone%20Transfer/29552</a><br/>
GitHub Copilot Update<br/>
 <a href="https://github.blog/2023-02-14-github-copilot-now-has-a-better-ai-model-and-new-capabilities/">https://github.blog/2023-02-14-github-copilot-now-has-a-better-ai-model-and-new-capabilities/</a><br/>
Hyundai Software Update<br/>
 <a href="https://www.hyundaiantitheft.com">https://www.hyundaiantitheft.com</a><br/>
Citrix Patches CVE-2023-24486, CVE-2023-24484, CVE-2023-24485, and CVE-2023-24483<br/>
 <a href="https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/citrix-releases-security-updates-workspace-apps-virtual-apps-and">https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/citrix-releases-security-updates-workspace-apps-virtual-apps-and</a><br/>
HA Proxy Patch CVE-2023-25725<br/>
 <a href="https://www.mail-archive.com/haproxy@formilux.org/msg43229.html">https://www.mail-archive.com/haproxy@formilux.org/msg43229.html</a><br/>
Firefox Patches<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2023-05/">https://www.mozilla.org/en-US/security/advisories/mfsa2023-05/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8372" type="text/plain" language="en" />
<itunes:keywords>firefox, haproxy, citrix, hyundai, github, copilot, dns, passive dns, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 15th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8370</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; Intel OpenBMC Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; Intel OpenBMC Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8370.mp3" length="5507169" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8370.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8370</link>
<pubDate>Wed, 15 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft February 2023 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20February%202023%20Patch%20Tuesday/29548">https://isc.sans.edu/diary/Microsoft%20February%202023%20Patch%20Tuesday/29548</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Intel OpenBMC Vulnerabilities<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8370" type="text/plain" language="en" />
<itunes:keywords>intel, openbmc, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 14th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8368</itunes:episode>
<itunes:subtitle>Apple Patches Everything; Venmo Phish via LinkedIn; Malicious Python;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patches Everything; Venmo Phish via LinkedIn; Malicious Python;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8368.mp3" length="5282313" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8368.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8368</link>
<pubDate>Tue, 14 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Patches Exploited Vulnerablity<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/29544">https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/29544</a><br/>
Venmo Phishing Abusing LinkedIn "slink"<br/>
 <a href="https://isc.sans.edu/diary/Venmo+Phishing+Abusing+LinkedIn+slink/29542/">https://isc.sans.edu/diary/Venmo+Phishing+Abusing+LinkedIn+slink/29542/</a><br/>
Malicious PyPi Packages Install Browser Extensions<br/>
 <a href="https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack">https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8368" type="text/plain" language="en" />
<itunes:keywords>python, pypi, chinese, typosquatting, venmo, slink, linkedin, apple, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8366</itunes:episode>
<itunes:subtitle>Script Block Logging Deactivation; Zeek and pcaps; Prompt Injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Script Block Logging Deactivation; Zeek and pcaps; Prompt Injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8366.mp3" length="4685304" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8366.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8366</link>
<pubDate>Mon, 13 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Obfuscated Deactivation of Script Block Logging<br/>
 <a href="https://isc.sans.edu/diary/Obfuscated%20Deactivation%20of%20Script%20Block%20Logging/29538">https://isc.sans.edu/diary/Obfuscated%20Deactivation%20of%20Script%20Block%20Logging/29538</a><br/>
PCAP Data Analysis with Zeek<br/>
 <a href="https://isc.sans.edu/diary/PCAP%20Data%20Analysis%20with%20Zeek/29530">https://isc.sans.edu/diary/PCAP%20Data%20Analysis%20with%20Zeek/29530</a><br/>
Bing Chat Prompt Injection<br/>
 <a href="https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/">https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/</a><br/>
More Malicious Python Packages<br/>
 <a href="https://blog.sonatype.com/malicious-aptx-python-package-drops-meterpreter-shell-deletes-netstat">https://blog.sonatype.com/malicious-aptx-python-package-drops-meterpreter-shell-deletes-netstat</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8366" type="text/plain" language="en" />
<itunes:keywords>python, bing, pcap, zeek, script block logging, prompt injection, chat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8364</itunes:episode>
<itunes:subtitle>Screenshot Backdoor; Keypass Update; Google Ads AWS Phishing; Kafka Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Screenshot Backdoor; Keypass Update; Google Ads AWS Phishing; Kafka Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8364.mp3" length="4845942" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8364.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8364</link>
<pubDate>Fri, 10 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[A Backdoor with Smart Screenshot Capability<br/>
 <a href="https://isc.sans.edu/diary/A%20Backdoor%20with%20Smart%20Screenshot%20Capability/29534">https://isc.sans.edu/diary/A%20Backdoor%20with%20Smart%20Screenshot%20Capability/29534</a><br/>
KeePass Patches Issue Allowing Password Export<br/>
 <a href="https://keepass.info/news/n230109_2.53.html">https://keepass.info/news/n230109_2.53.html</a><br/>
AWS Phishing via Google Ads<br/>
 <a href="https://www.sentinelone.com/blog/cloud-credentials-phishing-malicious-google-ads-target-aws-logins/">https://www.sentinelone.com/blog/cloud-credentials-phishing-malicious-google-ads-target-aws-logins/</a><br/>
Apache Kafka Vulnerability<br/>
 <a href="https://lists.apache.org/thread/vy1c7fqcdqvq5grcqp6q5jyyb302khyz">https://lists.apache.org/thread/vy1c7fqcdqvq5grcqp6q5jyyb302khyz</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8364" type="text/plain" language="en" />
<itunes:keywords>apache, kafka, aws, google, ads, keepass, patch, backdoor, screenshot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8362</itunes:episode>
<itunes:subtitle>Telegram Phish; ESXIArgs Ransomware Help; IoT Crypto Standard; Sonicwall Filter Issues; Chrome early-stable
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Telegram Phish; ESXIArgs Ransomware Help; IoT Crypto Standard; Sonicwall Filter Issues; Chrome early-stable
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8362.mp3" length="5120510" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8362.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8362</link>
<pubDate>Thu, 09 Feb 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Simple HTML Phishing via Telegram Bot<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple%20HTML%20Phishing%20via%20Telegram%20Bot/29528/">https://isc.sans.edu/forums/diary/Simple%20HTML%20Phishing%20via%20Telegram%20Bot/29528/</a><br/>
Recovering from ESXiArgs Ransomware<br/>
 <a href="https://www.cisa.gov/uscert/ncas/alerts/aa23-039a">https://www.cisa.gov/uscert/ncas/alerts/aa23-039a</a><br/>
NIST Standardizes Lightweight Cryptography<br/>
 <a href="https://csrc.nist.gov/Projects/lightweight-cryptography">https://csrc.nist.gov/Projects/lightweight-cryptography</a><br/>
Sonicwall Web Content Filtering on Windows 11 22H2<br/>
 <a href="https://www.sonicwall.com/support/product-notification/limitation-with-web-content-filtering-on-windows-11-22h2/230208075107457/">https://www.sonicwall.com/support/product-notification/limitation-with-web-content-filtering-on-windows-11-22h2/230208075107457/</a><br/>
Google Chrome Release Changes<br/>
 <a href="https://developer.chrome.com/blog/early-stable/">https://developer.chrome.com/blog/early-stable/</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8362" type="text/plain" language="en" />
<itunes:keywords>google, chrome, sonicwall, nist, esxiargs, iot, telegram, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 8th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8360</itunes:episode>
<itunes:subtitle>Bluetooth Vuln Trends; OpenSSL Update; GoAnywhere Patch and PoC; Quakbot via OneNote
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bluetooth Vuln Trends; OpenSSL Update; GoAnywhere Patch and PoC; Quakbot via OneNote
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8360.mp3" length="5800525" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8360.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8360</link>
<pubDate>Wed, 08 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[A Survey of Bluetooth Vulnerabilities Trends<br/>
 <a href="https://isc.sans.edu/diary/A%20Survey%20of%20Bluetooth%20Vulnerabilities%20Trends%20%282023%20Edition%29/29522">https://isc.sans.edu/diary/A%20Survey%20of%20Bluetooth%20Vulnerabilities%20Trends%20%282023%20Edition%29/29522</a><br/>
OpenSSL Vulnerabilities / Patches<br/>
 <a href="https://www.openssl.org/news/secadv/20230207.txt">https://www.openssl.org/news/secadv/20230207.txt</a><br/>
Packet Tuesday: Most Frequent DNS Query ID / DNS Notify<br/>
 <a href="https://www.youtube.com/watch?v=QgCuE_zKyMY">https://www.youtube.com/watch?v=QgCuE_zKyMY</a><br/>
GoAnywhere MFT Patch Available (and PoC)<br/>
 <a href="https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html">https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html</a><br/>
 <a href="https://my.goanywhere.com/webclient/Dashboard.xhtml">https://my.goanywhere.com/webclient/Dashboard.xhtml</a><br/>
Qakbot Mechanizes Distribution of Malicous OneNote Notebooks<br/>
 <a href="https://news.sophos.com/en-us/2023/02/06/qakbot-onenote-attacks/">https://news.sophos.com/en-us/2023/02/06/qakbot-onenote-attacks/</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8360" type="text/plain" language="en" />
<itunes:keywords>quakbot, onenote, goanywhere, packet tuesday, openssl, bluetooth, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 7th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8358</itunes:episode>
<itunes:subtitle>Earthquake Scams; IP Lookup Detection; OpenSSH Vuln Details; Redis Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Earthquake Scams; IP Lookup Detection; OpenSSH Vuln Details; Redis Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8358.mp3" length="5847149" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8358.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8358</link>
<pubDate>Tue, 07 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Earthquake Scams<br/>
 <a href="https://isc.sans.edu/diary/Earthquake%20in%20Turkey%20and%20Syria%3A%20Be%20Aware%20of%20Possible%20Donation%20Scams/29518">https://isc.sans.edu/diary/Earthquake%20in%20Turkey%20and%20Syria%3A%20Be%20Aware%20of%20Possible%20Donation%20Scams/29518</a><br/>
APIs Used By Bots to Detect Public IP Addresses<br/>
 <a href="https://isc.sans.edu/diary/APIs+Used+by+Bots+to+Detect+Public+IP+address/29516/">https://isc.sans.edu/diary/APIs+Used+by+Bots+to+Detect+Public+IP+address/29516/</a><br/>
OpenSSH Vulnerablity Details CVE 2023-25136<br/>
 <a href="https://blog.qualys.com/vulnerabilities-threat-research/2023/02/03/cve-2023-25136-pre-auth-double-free-vulnerability-in-openssh-server-9-1">https://blog.qualys.com/vulnerabilities-threat-research/2023/02/03/cve-2023-25136-pre-auth-double-free-vulnerability-in-openssh-server-9-1</a><br/>
A Novel State-of-the-Art Redis Malware<br/>
 <a href="https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware?&web_view=true">https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware?&web_view=true</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8358" type="text/plain" language="en" />
<itunes:keywords>redis, openssh, api, ip addresses, earthquake, syria, turkey, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8356</itunes:episode>
<itunes:subtitle>Assemblyline Sandbox; GoAnywhere MFT 0-Day; VMWare ESXi Ransomware; Jira Service Managemnt Server Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Assemblyline Sandbox; GoAnywhere MFT 0-Day; VMWare ESXi Ransomware; Jira Service Managemnt Server Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8356.mp3" length="4874495" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8356.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8356</link>
<pubDate>Mon, 06 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Assemblyline as a Malware Analysis Sandbox<br/>
 <a href="https://isc.sans.edu/diary/Assemblyline%20as%20a%20Malware%20Analysis%20Sandbox/29510">https://isc.sans.edu/diary/Assemblyline%20as%20a%20Malware%20Analysis%20Sandbox/29510</a><br/>
GoAnywhere MFT zero-day Exploited<br/>
 <a href="https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/">https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/</a><br/>
Ransomware targeting VMware ESXi<br/>
 <a href="https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/">https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/</a><br/>
Jira Service Managment Server and Data Center Advisory CVE-2023-22501<br/>
 <a href="https://confluence.atlassian.com/jira/jira-service-management-server-and-data-center-advisory-cve-2023-22501-1188786458.html">https://confluence.atlassian.com/jira/jira-service-management-server-and-data-center-advisory-cve-2023-22501-1188786458.html</a><br/>
OpenSSH Update<br/>
 <a href="https://www.openssh.com/releasenotes.html">https://www.openssh.com/releasenotes.html</a><br/>
F5 BigIP Vulnerability CVE-2023-22374<br/>
 <a href="https://my.f5.com/manage/s/article/K000130415">https://my.f5.com/manage/s/article/K000130415</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8356" type="text/plain" language="en" />
<itunes:keywords>f5, bigip, openssh, jira, vmware, esxi, goanywhere mft, assemblyline, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8354</itunes:episode>
<itunes:subtitle>tcpdump in pfsense; BEC visa Third-Parties; More Malvertising; Cisco Persistence
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
tcpdump in pfsense; BEC visa Third-Parties; More Malvertising; Cisco Persistence
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8354.mp3" length="4477633" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8354.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8354</link>
<pubDate>Fri, 03 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Rotating Packet Captures with pfSense<br/>
 <a href="https://isc.sans.edu/diary/Rotating%20Packet%20Captures%20with%20pfSense/29500">https://isc.sans.edu/diary/Rotating%20Packet%20Captures%20with%20pfSense/29500</a><br/>
BEC Group Incorporates Secondary Impersonated Personas<br/>
 <a href="https://intelligence.abnormalsecurity.com/blog/firebrick-ostrich-third-party-reconnaissance-attacks">https://intelligence.abnormalsecurity.com/blog/firebrick-ostrich-third-party-reconnaissance-attacks</a><br/>
MalVirt .Net Virtualization Thrives in Malvertising Attacks<br/>
 <a href="https://www.sentinelone.com/labs/malvirt-net-virtualization-thrives-in-malvertising-attacks/">https://www.sentinelone.com/labs/malvirt-net-virtualization-thrives-in-malvertising-attacks/</a><br/>
Cisco Remote Code Execution with Persistence<br/>
 <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/when-pwning-cisco-persistence-is-key-when-pwning-supply-chain-cisco-is-key.html">https://www.trellix.com/en-us/about/newsroom/stories/research/when-pwning-cisco-persistence-is-key-when-pwning-supply-chain-cisco-is-key.html</a><br/>
]]></description>
<itunes:duration>4:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8354" type="text/plain" language="en" />
<itunes:keywords>packets, pfsense, tcpdump, pec, malvirt, .net, malvertising, cisco, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8352</itunes:episode>
<itunes:subtitle>Detecting OneNote; MSFT Defender and Linux; Chromebook Exploit; ImageMagik Vuln; dompdf vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Detecting OneNote; MSFT Defender and Linux; Chromebook Exploit; ImageMagik Vuln; dompdf vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8352.mp3" length="5543488" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8352.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8352</link>
<pubDate>Thu, 02 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Detecting Malicious OneNote Files<br/>
 <a href="https://isc.sans.edu/diary/Detecting%20%28Malicious%29%20OneNote%20Files/29494">https://isc.sans.edu/diary/Detecting%20%28Malicious%29%20OneNote%20Files/29494</a><br/>
Microsoft Defender Device Isolation for Linux<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-device-isolation-support-for-linux/ba-p/3676400">https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-device-isolation-support-for-linux/ba-p/3676400</a><br/>
SH1MMER Exploit for Chromebooks<br/>
 <a href="https://sh1mmer.me">https://sh1mmer.me</a><br/>
DOMPDF SVG Parsing Vulnerability<br/>
 <a href="https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg">https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8352" type="text/plain" language="en" />
<itunes:keywords>dompdf, svg, sh1mmer, microsoft, defender, linux, onenote, detection, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 1st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8350</itunes:episode>
<itunes:subtitle>Honeypot with pfSense; Abusing "Verified Published"; PoS Malware Blocks NFC; Detecting AV Blindspots
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot with pfSense; Abusing "Verified Published"; PoS Malware Blocks NFC; Detecting AV Blindspots
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8350.mp3" length="6786785" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8350.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8350</link>
<pubDate>Wed, 01 Feb 2023 02:00:02 GMT</pubDate>
<description><![CDATA[DShield Honeypot Setup with pfSense<br/>
 <a href="https://isc.sans.edu/diary/DShield%20Honeypot%20Setup%20with%20pfSense/29490">https://isc.sans.edu/diary/DShield%20Honeypot%20Setup%20with%20pfSense/29490</a><br/>
Threat Actors Abusing Microsoft's "Verified Publisher" Status<br/>
 <a href="https://www.proofpoint.com/us/blog/cloud-security/dangerous-consequences-threat-actors-abusing-microsofts-verified-publisher">https://www.proofpoint.com/us/blog/cloud-security/dangerous-consequences-threat-actors-abusing-microsofts-verified-publisher</a><br/>
PoS Malware Can Block Contactless Payments<br/>
 <a href="https://securelist.com/prilex-modification-now-targeting-contactless-credit-card-transactions/108569/">https://securelist.com/prilex-modification-now-targeting-contactless-credit-card-transactions/108569/</a><br/>
Detecting Files Exempt from Anti Malware Scans<br/>
 <a href="https://github.com/bananabr/TimeException">https://github.com/bananabr/TimeException</a><br/>
]]></description>
<itunes:duration>7:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8350" type="text/plain" language="en" />
<itunes:keywords>timeexcept, blindspot, antivirus, pos, contactless, credit card, microsoft, oauth, verified publisher, phishing, honeypot, pfsense, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 31st, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8348</itunes:episode>
<itunes:subtitle>DoH Scans; GitHub Replaces Signing Cert; GitHub ZIP Algo Changes;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DoH Scans; GitHub Replaces Signing Cert; GitHub ZIP Algo Changes;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8348.mp3" length="6378138" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8348.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8348</link>
<pubDate>Tue, 31 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Decoding DNS over HTTP(s) Requests<br/>
 <a href="https://isc.sans.edu/diary/Decoding%20DNS%20over%20HTTP%28s%29%20Requests/29488">https://isc.sans.edu/diary/Decoding%20DNS%20over%20HTTP%28s%29%20Requests/29488</a><br/>
Action Needed for GitHub Desktop and Atom Users<br/>
 <a href="https://github.blog/2023-01-30-action-needed-for-github-desktop-and-atom-users/">https://github.blog/2023-01-30-action-needed-for-github-desktop-and-atom-users/</a><br/>
GitHub Checksum Mismatches for .tar.gz Files<br/>
 <a href="https://github.com/orgs/community/discussions/45830">https://github.com/orgs/community/discussions/45830</a><br/>
Facebook 2FA Bypass<br/>
 <a href="https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c">https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c</a><br/>
Fortinet Exploit<br/>
 <a href="https://wzt.ac.cn/2022/12/15/CVE-2022-42475/">https://wzt.ac.cn/2022/12/15/CVE-2022-42475/</a><br/>
QNAP Vulnerability<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-23-01">https://www.qnap.com/en/security-advisory/qsa-23-01</a><br/>
]]></description>
<itunes:duration>7:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8348" type="text/plain" language="en" />
<itunes:keywords>facebook, 2fa, qnap, fortinet, github, zip, tar.gz, desktop, dns, https, doh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 30th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8346</itunes:episode>
<itunes:subtitle>MSFT Exchange Patching Hints; FCC vs. Twilio; PlugX Spreads via USB
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Exchange Patching Hints; FCC vs. Twilio; PlugX Spreads via USB
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8346.mp3" length="5230744" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8346.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8346</link>
<pubDate>Mon, 30 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Tips to Patch Your Exchange Servers<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/protect-your-exchange-servers/ba-p/3726001">https://techcommunity.microsoft.com/t5/exchange-team-blog/protect-your-exchange-servers/ba-p/3726001</a><br/>
FCC Treatens to Take Action Against Twilio over Robocalls<br/>
 <a href="https://www.fcc.gov/document/fcc-takes-mortgage-scam-robocall-campaign-targeting-homeowners">https://www.fcc.gov/document/fcc-takes-mortgage-scam-robocall-campaign-targeting-homeowners</a><br/>
PlugX Variant Spreads via USB<br/>
 <a href="https://unit42.paloaltonetworks.com/plugx-variants-in-usbs/">https://unit42.paloaltonetworks.com/plugx-variants-in-usbs/</a><br/>
Adware in Google Play Store<br/>
 <a href="https://news.drweb.com/show/review/?lng=en&i=14652">https://news.drweb.com/show/review/?lng=en&i=14652</a><br/>
Tails 5.9 Update<br/>
 <a href="https://tails.boum.org/news/version_5.9/index.de.html">https://tails.boum.org/news/version_5.9/index.de.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8346" type="text/plain" language="en" />
<itunes:keywords>google, play, adware, plugx, usb, fcc, twilio, robocalls, microsoft, exchange, patching, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 27th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8344</itunes:episode>
<itunes:subtitle>Unix IR with UAC; Bitwarden Phishing; PY#RATION Websockets; SkyHigh Security Gateway; Win Crypto API; BIND Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Unix IR with UAC; Bitwarden Phishing; PY#RATION Websockets; SkyHigh Security Gateway; Win Crypto API; BIND Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8344.mp3" length="5562348" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8344.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8344</link>
<pubDate>Fri, 27 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Live Linux IR with UAC<br/>
 <a href="https://isc.sans.edu/diary/Live%20Linux%20IR%20with%20UAC/29480">https://isc.sans.edu/diary/Live%20Linux%20IR%20with%20UAC/29480</a><br/>
Bitwarden Phishing<br/>
 <a href="https://community.bitwarden.com/t/phishing-website-bitwardenlogin-com/49704">https://community.bitwarden.com/t/phishing-website-bitwardenlogin-com/49704</a><br/>
 <a href="https://www.reddit.com/r/Bitwarden/comments/10k2aj5/google_search_ads_showing_fake_bitwarden_web/">https://www.reddit.com/r/Bitwarden/comments/10k2aj5/google_search_ads_showing_fake_bitwarden_web/</a><br/>
PY#RATION Attack Campaign Leverages Fernet Encyrption and Websockets<br/>
 <a href="https://www.securonix.com/blog/security-advisory-python-based-pyration-attack-campaign/">https://www.securonix.com/blog/security-advisory-python-based-pyration-attack-campaign/</a><br/>
Skyhigh Security Secure Web Gateway: XSS in Single Sign On Plugin<br/>
 <a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2022-002/-skyhigh-security-secure-web-gateway-cross-site-scripting-in-single-sign-on-plugin">https://www.redteam-pentesting.de/en/advisories/rt-sa-2022-002/-skyhigh-security-secure-web-gateway-cross-site-scripting-in-single-sign-on-plugin</a><br/>
Windows Crypto API Vuln PoC<br/>
 <a href="https://github.com/akamai/akamai-security-research/tree/main/PoCs/CVE-2022-34689">https://github.com/akamai/akamai-security-research/tree/main/PoCs/CVE-2022-34689</a><br/>
BIND Patches<br/>
 <a href="https://kb.isc.org/docs/cve-2022-3094">https://kb.isc.org/docs/cve-2022-3094</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8344" type="text/plain" language="en" />
<itunes:keywords>bind, windows, crypto api, poc, skyhigh, xss, sso, py#ration, websocket, bitwarden, phishing, UAC, linux, IR, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 26th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8342</itunes:episode>
<itunes:subtitle>Malicious OneNote Expample; Secure Remote Monitoring; Cloud Kerberos Attacks; XLL Block;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious OneNote Expample; Secure Remote Monitoring; Cloud Kerberos Attacks; XLL Block;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8342.mp3" length="5160528" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8342.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8342</link>
<pubDate>Thu, 26 Jan 2023 02:05:01 GMT</pubDate>
<description><![CDATA[First Malicious OneNote Document<br/>
 <a href="https://isc.sans.edu/diary/A%20First%20Malicious%20OneNote%20Document/29470">https://isc.sans.edu/diary/A%20First%20Malicious%20OneNote%20Document/29470</a><br/>
Guidance for Securing Remote Monitoring and Management Software<br/>
 <a href="https://media.defense.gov/2023/Jan/25/2003149873/-1/-1/0/JOINT_CSA_RMM.PDF">https://media.defense.gov/2023/Jan/25/2003149873/-1/-1/0/JOINT_CSA_RMM.PDF</a><br/>
Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts<br/>
 <a href="https://www.darkreading.com/cloud/microsoft-azure-kerberos-attacks-open-cloud-accounts">https://www.darkreading.com/cloud/microsoft-azure-kerberos-attacks-open-cloud-accounts</a><br/>
Microsoft Blocking XLL Files Downloaded From Internet<br/>
 <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=115485">https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=115485</a><br/>
Lexmark Vulnerablities<br/>
 <a href="https://publications.lexmark.com/publications/security-alerts/CVE-2023-23560.pdf">https://publications.lexmark.com/publications/security-alerts/CVE-2023-23560.pdf</a><br/>
VMware VRealize Update<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2023-0001.html">https://www.vmware.com/security/advisories/VMSA-2023-0001.html</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8342" type="text/plain" language="en" />
<itunes:keywords>microsoft, xll, blocking, azure, kerberos, cloud, onenote, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 25th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8340</itunes:episode>
<itunes:subtitle>Apple Patch Summary; ManageEngine News; KSMBD News; Bitwarden Weakness;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patch Summary; ManageEngine News; KSMBD News; Bitwarden Weakness;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8340.mp3" length="6040144" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8340.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8340</link>
<pubDate>Wed, 25 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Apple Patch Summary<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple%20Updates%20%28almost%29%20Everything%3A%20Patch%20Overview/29472/">https://isc.sans.edu/forums/diary/Apple%20Updates%20%28almost%29%20Everything%3A%20Patch%20Overview/29472/</a><br/>
ManageEngine News;<br/>
 <a href="https://github.com/vonahisec/CVE-2022-47966-Scan">https://github.com/vonahisec/CVE-2022-47966-Scan</a><br/>
KSMBD Vulnerability<br/>
 <a href="https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/">https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/</a><br/>
BitWarden Server Side Iterations<br/>
 <a href="https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterations/">https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterations/</a><br/>
Packet Tuesday: Neighbor Advertisements<br/>
 <a href="https://www.youtube.com/watch?v=CoaZjuuY1do">https://www.youtube.com/watch?v=CoaZjuuY1do</a><br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8340" type="text/plain" language="en" />
<itunes:keywords>bitwarden, ksmbd, manageengine, apple, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 24th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8338</itunes:episode>
<itunes:subtitle>Who Resolved What? Apple Updates Everything; NSA IPv6 Guidance; Roaming Mantis
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Who Resolved What? Apple Updates Everything; NSA IPv6 Guidance; Roaming Mantis
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8338.mp3" length="5123528" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8338.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8338</link>
<pubDate>Tue, 24 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Who's Resolving This Domain<br/>
 <a href="https://isc.sans.edu/forums/diary/Who's%20Resolving%20This%20Domain%3F/29462/">https://isc.sans.edu/forums/diary/Who's%20Resolving%20This%20Domain%3F/29462/</a><br/>
Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
NSA IPv6 Security Guidance<br/>
 <a href="https://media.defense.gov/2023/Jan/18/2003145994/-1/-1/0/CSI_IPV6_SECURITY_GUIDANCE.PDF">https://media.defense.gov/2023/Jan/18/2003145994/-1/-1/0/CSI_IPV6_SECURITY_GUIDANCE.PDF</a><br/>
Roaming Mantis Implements new DNS Changer in tis malicious mobile app<br/>
 <a href="https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html">https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8338" type="text/plain" language="en" />
<itunes:keywords>roaming mantis, nsa, ipv6, Apple, patches, dns, resolution sysmon, linux, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 23rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8336</itunes:episode>
<itunes:subtitle>Windows Auth Signing; Fanduel/Mailchimp Leak; Malicious OneNotes; Cisco Vuln; Possible KeePass Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Auth Signing; Fanduel/Mailchimp Leak; Malicious OneNotes; Cisco Vuln; Possible KeePass Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8336.mp3" length="5709105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8336.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8336</link>
<pubDate>Mon, 23 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Imortance of Signing in Windows Environments<br/>
 <a href="https://isc.sans.edu/diary/Importance%20of%20signing%20in%20Windows%20environments/29456">https://isc.sans.edu/diary/Importance%20of%20signing%20in%20Windows%20environments/29456</a><br/>
FanDuel Discloses Data Breach Caused by Recent Mailchimp Hack<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fanduel-discloses-data-breach-caused-by-recent-mailchimp-hack/">https://www.bleepingcomputer.com/news/security/fanduel-discloses-data-breach-caused-by-recent-mailchimp-hack/</a><br/>
OneNote Documents Used to Embed Malicious Office Documents<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/</a><br/>
Cisco Unified Communications Manager SQL Injection<br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n</a><br/>
Possible KeePass Vulnerability<br/>
 <a href="https://twitter.com/vomanc/status/1617135599030530054">https://twitter.com/vomanc/status/1617135599030530054</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8336" type="text/plain" language="en" />
<itunes:keywords>keepass, cisco, sql injection, unified communications manager, onenote, office, macros, signing, windows, ntlm, relay attack, fanduel, mailchimp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 20th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8334</itunes:episode>
<itunes:subtitle>Popular Domains and SPF/DMARC; Sysmon Exploit; ManageEngine Exploit; Netcomm Patch; Outdated Office Check
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Popular Domains and SPF/DMARC; Sysmon Exploit; ManageEngine Exploit; Netcomm Patch; Outdated Office Check
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8334.mp3" length="5001336" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8334.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8334</link>
<pubDate>Fri, 20 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[SPF and DMARC use on 100k most popular domains<br/>
 <a href="https://isc.sans.edu/diary/SPF%20and%20DMARC%20use%20on%20100k%20most%20popular%20domains/29452">https://isc.sans.edu/diary/SPF%20and%20DMARC%20use%20on%20100k%20most%20popular%20domains/29452</a><br/>
Sysmon Exploit Released CVE-2022-41120, CVE-2022-44704<br/>
 <a href="https://github.com/Wh04m1001/SysmonEoP">https://github.com/Wh04m1001/SysmonEoP</a><br/>
ManageEngine CVE-2022-47966 Technical Deep Dive<br/>
 <a href="https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/">https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/</a><br/>
Netcomm Router Vulnerablities<br/>
 <a href="https://kb.cert.org/vuls/id/986018">https://kb.cert.org/vuls/id/986018</a><br/>
Microsoft Pushes Outdated Office Install Check<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-pushes-kb5021751-to-check-for-outdated-office-installs/">https://www.bleepingcomputer.com/news/microsoft/microsoft-pushes-kb5021751-to-check-for-outdated-office-installs/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8334" type="text/plain" language="en" />
<itunes:keywords>office, microsoft, netcomm, router, manageengine, sysmon, spf, dmarc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 19th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8332</itunes:episode>
<itunes:subtitle>More Malicous Google Ads; Oracle Patches; QT/QML Bug/Vuln; Sudo Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Malicous Google Ads; Oracle Patches; QT/QML Bug/Vuln; Sudo Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8332.mp3" length="5621505" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8332.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8332</link>
<pubDate>Thu, 19 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Malicious Google Ads for Fake Notepad++ Lead to Aurora Stealer<br/>
 <a href="https://isc.sans.edu/diary/Malicious%20Google%20Ad%20--%3E%20Fake%20Notepad%2B%2B%20Page%20--%3E%20Aurora%20Stealer%20malware/29448">https://isc.sans.edu/diary/Malicious%20Google%20Ad%20--%3E%20Fake%20Notepad%2B%2B%20Page%20--%3E%20Aurora%20Stealer%20malware/29448</a><br/>
Oracle Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpujan2023.html">https://www.oracle.com/security-alerts/cpujan2023.html</a><br/>
QT QML Vulnerability<br/>
 <a href="https://blog.talosintelligence.com/vulnerability-spotlight-integer-and-buffer-overflow-vulnerabilities-found-in-qt-qml/">https://blog.talosintelligence.com/vulnerability-spotlight-integer-and-buffer-overflow-vulnerabilities-found-in-qt-qml/</a><br/>
sudo sudoedit vulnerablity<br/>
 <a href="https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf">https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf</a><br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8332" type="text/plain" language="en" />
<itunes:keywords>sudo, sudoedit, qt, qml, oracle, google ads, aurora, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 18th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8330</itunes:episode>
<itunes:subtitle>Finding GPO Settings; git audit and vulns; Azure SSRF Flaws; Windows 11 Pro Nixes Guest Auth
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding GPO Settings; git audit and vulns; Azure SSRF Flaws; Windows 11 Pro Nixes Guest Auth
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8330.mp3" length="5209337" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8330.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8330</link>
<pubDate>Wed, 18 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Finding that one GPO setting in a pool of hundreds of GPOs<br/>
 <a href="https://isc.sans.edu/diary/Finding%20that%20one%20GPO%20Setting%20in%20a%20Pool%20of%20Hundreds%20of%20GPOs/29442">https://isc.sans.edu/diary/Finding%20that%20one%20GPO%20Setting%20in%20a%20Pool%20of%20Hundreds%20of%20GPOs/29442</a><br/>
GIT Code Audit<br/>
 <a href="https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/">https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/</a><br/>
Azure SSRF Flaws<br/>
 <a href="https://orca.security/resources/blog/ssrf-vulnerabilities-in-four-azure-services/">https://orca.security/resources/blog/ssrf-vulnerabilities-in-four-azure-services/</a><br/>
SMB Insecure Guest Auth Off By Default In Windows 11 Pro<br/>
<a href="https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-insecure-guest-auth-now-off-by-default-in-windows-insider/ba-p/3715014">https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-insecure-guest-auth-now-off-by-default-in-windows-insider/ba-p/3715014</a><br/>
Packet Tuesday: IPv6 Router Advertisements<br/>
 <a href="https://www.youtube.com/watch?v=uRWpB_lYIZ8">https://www.youtube.com/watch?v=uRWpB_lYIZ8</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8330" type="text/plain" language="en" />
<itunes:keywords>Packet tuesday, ipv6, router advertisement, smb, windows 11 pro, ssrf, azure, git, GPO, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 17th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8328</itunes:episode>
<itunes:subtitle>Malicious Google Ads; NortonLifeLock Password Manager Bruteforcing; nftables vulnerability; MSI insecure boot;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Google Ads; NortonLifeLock Password Manager Bruteforcing; nftables vulnerability; MSI insecure boot;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8328.mp3" length="5580927" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8328.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8328</link>
<pubDate>Tue, 17 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[PSA: Why you must run an ad blocker when using Google<br/>
 <a href="https://isc.sans.edu/diary/PSA%3A%20Why%20you%20must%20run%20an%20ad%20blocker%20when%20using%20Google/29438">https://isc.sans.edu/diary/PSA%3A%20Why%20you%20must%20run%20an%20ad%20blocker%20when%20using%20Google/29438</a><br/>
NortonLifeLock Password Manager Bruteforcing<br/>
 <a href="https://webcache.googleusercontent.com/search?q=cache%3A91Bmx_jTJIkJ%3Ahttps%3A%2F%2Fago.vermont.gov%2Fwp-content%2Fuploads%2F2023%2F01%2F2023-01-09-NortonLifeLock-Gen-Digital-Data-Breach-Notice-to-Consumers.pdf&cd=3&hl=de&ct=clnk&gl=de">https://webcache.googleusercontent.com/search?q=cache%3A91Bmx_jTJIkJ%3Ahttps%3A%2F%2Fago.vermont.gov%2Fwp-content%2Fuploads%2F2023%2F01%2F2023-01-09-NortonLifeLock-Gen-Digital-Data-Breach-Notice-to-Consumers.pdf&cd=3&hl=de&ct=clnk&gl=de</a><br/>
CVE-2023-0179 Linux kernel stack buffer overflow in nftables: PoC and writeup<br/>
 <a href="https://seclists.org/oss-sec/2023/q1/20">https://seclists.org/oss-sec/2023/q1/20</a><br/>
MSI (in)Secure Boot<br/>
 <a href="https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/">https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8328" type="text/plain" language="en" />
<itunes:keywords>msi, secure boot, nftables, linux, kernel, nortonlifelock, password managers, pse, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 16th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8326</itunes:episode>
<itunes:subtitle>YouTube Crypto Scam; Voice Impersonation; Missing Start Menu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
YouTube Crypto Scam; Voice Impersonation; Missing Start Menu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8326.mp3" length="4627914" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8326.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8326</link>
<pubDate>Mon, 16 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Elon Musk Themed Crypto Scams Flooding YouTube Today<br/>
 <a href="https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434">https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434</a><br/>
Microsoft Text to Speech Synthesizer<br/>
 <a href="https://arxiv.org/pdf/2301.02111.pdf">https://arxiv.org/pdf/2301.02111.pdf</a><br/>
Missing Windows Start Menu<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#2998msgdesc">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#2998msgdesc</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8326" type="text/plain" language="en" />
<itunes:keywords>start menu, windows, defender, text to speech, musk, crypto, scan, youtube, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 13th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8324</itunes:episode>
<itunes:subtitle>Prowler Cloud Assessments; Pre-Pw0ned Android TV; RevoLTE LTE Sniffing; NGFW Exfiltration;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Prowler Cloud Assessments; Pre-Pw0ned Android TV; RevoLTE LTE Sniffing; NGFW Exfiltration;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8324.mp3" length="6169942" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8324.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8324</link>
<pubDate>Fri, 13 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Prowler v3: AWS & Azure security assessments<br/>
 <a href="https://isc.sans.edu/diary/Prowler%20v3%3A%20AWS%20%26%20Azure%20security%20assessments/29430">https://isc.sans.edu/diary/Prowler%20v3%3A%20AWS%20%26%20Azure%20security%20assessments/29430</a><br/>
Certified Pre-Pw0ned Android TV<br/>
 <a href="https://github.com/DesktopECHO/T95-H616-Malware">https://github.com/DesktopECHO/T95-H616-Malware</a><br/>
Revolte Attack<br/>
 <a href="https://revolte-attack.net">https://revolte-attack.net</a><br/>
NGFW Data Exfiltration<br/>
 <a href="https://cymulate.com/blog/data-exfiltration-firewall/">https://cymulate.com/blog/data-exfiltration-firewall/</a><br/>
]]></description>
<itunes:duration>6:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8324" type="text/plain" language="en" />
<itunes:keywords>ngfw, exfiltration, revolte, lte, decryption, android, tv, malware, prowler, aws, azure, cloud, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 12th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8322</itunes:episode>
<itunes:subtitle>Shodan KEV Scans; New KSMBD Issue; Cisco RVx Vulnerabilities; Gootkit Abusing VLC; Zoom Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shodan KEV Scans; New KSMBD Issue; Cisco RVx Vulnerabilities; Gootkit Abusing VLC; Zoom Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8322.mp3" length="5533842" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8322.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8322</link>
<pubDate>Thu, 12 Jan 2023 02:10:02 GMT</pubDate>
<description><![CDATA[Passive Detection of Internet-Connected Systems Affected by Exploited Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Passive%20detection%20of%20internet-connected%20systems%20affected%20by%20vulnerabilities%20from%20the%20CISA%20KEV%20catalog/29426">https://isc.sans.edu/diary/Passive%20detection%20of%20internet-connected%20systems%20affected%20by%20vulnerabilities%20from%20the%20CISA%20KEV%20catalog/29426</a><br/>
Unauthenticed Remote DoS in ksmbd NTLMv2 Authentication<br/>
 <a href="https://seclists.org/oss-sec/2023/q1/4">https://seclists.org/oss-sec/2023/q1/4</a><br/>
Cisco RV Series Vulnerabilities CVE-2023-20025 <br/>
 <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5</a><br/>
Zoom Updates<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
Gootkit Abusing VLC<br/>
 <a href="https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html">https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8322" type="text/plain" language="en" />
<itunes:keywords>Gootkit, VLC, Zoom, Cisco, ksmbd, shodan, kev, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 11th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8320</itunes:episode>
<itunes:subtitle>Patch Tuesday; Cacti Vuln Details; Text-to-SQL Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Patch Tuesday; Cacti Vuln Details; Text-to-SQL Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8320.mp3" length="5166973" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8320.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8320</link>
<pubDate>Wed, 11 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft January 2023 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20January%202023%20Patch%20Tuesday/29420">https://isc.sans.edu/diary/Microsoft%20January%202023%20Patch%20Tuesday/29420</a><br/>
Cacti Unauthenticated Remote Code Execution<br/>
 <a href="https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/">https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/</a><br/>
On the Security Vulnerabilities of Text-to-SQL Models<br/>
 <a href="https://arxiv.org/pdf/2211.15363.pdf">https://arxiv.org/pdf/2211.15363.pdf</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8320" type="text/plain" language="en" />
<itunes:keywords>text-to-sql, nlp, ai, cacti, remote code execution, microsoft, patch tuesday, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 10th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8318</itunes:episode>
<itunes:subtitle>CircleCI Config File Hunt; AWS S3 Encryption; MatrixSSL RCE; Auth0 JWT Library Vulnerablity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CircleCI Config File Hunt; AWS S3 Encryption; MatrixSSL RCE; Auth0 JWT Library Vulnerablity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8318.mp3" length="5385124" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8318.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8318</link>
<pubDate>Tue, 10 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[New Year Old Tricks: Hunting for CircleCI Configuration Files<br/>
 <a href="https://isc.sans.edu/diary/New%20year%2C%20old%20tricks%3A%20Hunting%20for%20CircleCI%20configuration%20files/29416">https://isc.sans.edu/diary/New%20year%2C%20old%20tricks%3A%20Hunting%20for%20CircleCI%20configuration%20files/29416</a><br/>
Amazon S3 Encrypts New Objects By Default <br/>
 <a href="https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/">https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/</a><br/>
MatrixSSL Buffer Overflow<br/>
 <a href="https://github.com/matrixssl/matrixssl/security/advisories/GHSA-fmwc-gwc5-2g29">https://github.com/matrixssl/matrixssl/security/advisories/GHSA-fmwc-gwc5-2g29</a><br/>
Auth0 JsonWebToken Vulnerability CVE-2022-23529<br/>
 <a href="https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerability-cve-2022-23529/">https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerability-cve-2022-23529/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8318" type="text/plain" language="en" />
<itunes:keywords>auth0, jsonwebtoken, jwt, matrixssl, amazone, s3, encryption, cricleci, configuration, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 9th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8316</itunes:episode>
<itunes:subtitle>Reversing AutoIT; VSCode Extensions; Malicious Pypi Cloudflare Tunnel;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing AutoIT; VSCode Extensions; Malicious Pypi Cloudflare Tunnel;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8316.mp3" length="5184937" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8316.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8316</link>
<pubDate>Mon, 09 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Reversing AutoIT Scripts<br/>
 <a href="https://isc.sans.edu/diary/AutoIT%20Remains%20Popular%20in%20the%20Malware%20Landscape/29408">https://isc.sans.edu/diary/AutoIT%20Remains%20Popular%20in%20the%20Malware%20Landscape/29408</a><br/>
Can You Trust Your VSCode Extensions<br/>
 <a href="https://blog.aquasec.com/can-you-trust-your-vscode-extensions">https://blog.aquasec.com/can-you-trust-your-vscode-extensions</a><br/>
A Deep Dive Into Powerat<br/>
 <a href="https://blog.phylum.io/a-deep-dive-into-powerat-a-newly-discovered-stealer/rat-combo-polluting-pypi">https://blog.phylum.io/a-deep-dive-into-powerat-a-newly-discovered-stealer/rat-combo-polluting-pypi</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8316" type="text/plain" language="en" />
<itunes:keywords>pypi, powerat, cloudflare, vscode, visual code, extensions, autoit, reversing, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 6th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8314</itunes:episode>
<itunes:subtitle>Malware AutoIT Script; CircleCI Breach; Twitter Leak; Slack Breach; Control Web Panel Bug; Turla USB Hack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware AutoIT Script; CircleCI Breach; Twitter Leak; Slack Breach; Control Web Panel Bug; Turla USB Hack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8314.mp3" length="5234158" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8314.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8314</link>
<pubDate>Fri, 06 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[More Brazil Malspam Pushing Astaroth (Guildma) in January 2023<br/>
 <a href="https://isc.sans.edu/forums/diary/More%20Brazil%20malspam%20pushing%20Astaroth%20%28Guildma%29%20in%20January%202023/29404/">https://isc.sans.edu/forums/diary/More%20Brazil%20malspam%20pushing%20Astaroth%20%28Guildma%29%20in%20January%202023/29404/</a><br/>
CircleCI Breach<br/>
 <a href="https://circleci.com/blog/january-4-2023-security-alert/">https://circleci.com/blog/january-4-2023-security-alert/</a><br/>
Twitter Leak<br/>
 <a href="https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/">https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/</a><br/>
Slack Source Code Leak<br/>
 <a href="https://slack.com/blog/news/slack-security-update">https://slack.com/blog/news/slack-security-update</a><br/>
Control Web Panel Patch CVE-2022-44877<br/>
 <a href="https://github.com/numanturle/CVE-2022-44877">https://github.com/numanturle/CVE-2022-44877</a><br/>
Turla: A Galaxy of Opportunity<br/>
 <a href="https://www.mandiant.com/resources/blog/turla-galaxy-opportunity">https://www.mandiant.com/resources/blog/turla-galaxy-opportunity</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8314" type="text/plain" language="en" />
<itunes:keywords>turla, control web panel, slack, twitter, circleci, brazil, malware, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 5th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8312</itunes:episode>
<itunes:subtitle>RTRBK diff feature; Google Legacy Windows Support Ending; SHC Malware; ManageEngine SQLi; ForiADC command injection;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RTRBK diff feature; Google Legacy Windows Support Ending; SHC Malware; ManageEngine SQLi; ForiADC command injection;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8312.mp3" length="6375285" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8312.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8312</link>
<pubDate>Thu, 05 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Update to RTRBK - Diff and File Dates in PowerShell<br/>
 <a href="https://isc.sans.edu/diary/Update%20to%20RTRBK%20-%20Diff%20and%20File%20Dates%20in%20PowerShell/29400">https://isc.sans.edu/diary/Update%20to%20RTRBK%20-%20Diff%20and%20File%20Dates%20in%20PowerShell/29400</a><br/>
Google Chrome Sunsetting Legacy Windows Support<br/>
 <a href="https://support.google.com/chrome/thread/185534985/sunsetting-support-for-windows-7-8-8-1-in-early-2023?hl=en">https://support.google.com/chrome/thread/185534985/sunsetting-support-for-windows-7-8-8-1-in-early-2023?hl=en</a><br/>
SHC used to compile cryptominer malware<br/>
 <a href="https://asec.ahnlab.com/en/45182/">https://asec.ahnlab.com/en/45182/</a><br/>
ManageEngine Password Manager Pro SQL Injection<br/>
 <a href="https://pitstop.manageengine.com/portal/en/community/topic/manageengine-security-advisory">https://pitstop.manageengine.com/portal/en/community/topic/manageengine-security-advisory</a> important-security-fix-released-for-manageengine-password-manager-pro-2-1-2023#:~:text=critical%20security%20vulnerability<br/>
ForiADC Command Injection in Web Interface<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-22-061">https://www.fortiguard.com/psirt/FG-IR-22-061</a><br/>
Raspberry Robin Developments<br/>
 <a href="https://www.securityjoes.com/post/raspberry-robin-detected-itw-targeting-insurance-financial-institutes-in-europe">https://www.securityjoes.com/post/raspberry-robin-detected-itw-targeting-insurance-financial-institutes-in-europe</a><br/>
]]></description>
<itunes:duration>7:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8312" type="text/plain" language="en" />
<itunes:keywords>raspberry robin, foriadc, manageengine, password manager, cryptominer, shc, google chrome, windows, router, backup, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 4th, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8310</itunes:episode>
<itunes:subtitle>NTP Fingerprinting; Misc Car Vulnerabilities; Flipper Zero Phish; Trend Micro Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NTP Fingerprinting; Misc Car Vulnerabilities; Flipper Zero Phish; Trend Micro Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8310.mp3" length="5784667" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8310.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8310</link>
<pubDate>Wed, 04 Jan 2023 02:00:01 GMT</pubDate>
<description><![CDATA[NTP Fingerprinting<br/>
 <a href="https://isc.sans.edu/diary/Its%20about%20time%3A%20OS%20Fingerprinting%20using%20NTP/29394">https://isc.sans.edu/diary/Its%20about%20time%3A%20OS%20Fingerprinting%20using%20NTP/29394</a><br/>
Misc Car Vulnerabilities<br/>
 <a href="https://samcurry.net/web-hackers-vs-the-auto-industry/">https://samcurry.net/web-hackers-vs-the-auto-industry/</a><br/>
Flipper Zero Phishing<br/>
 <a href="https://twitter.com/AlvieriD/status/1609945425871609858">https://twitter.com/AlvieriD/status/1609945425871609858</a><br/>
Trend Micro Patch<br/>
 <a href="https://helpcenter.trendmicro.com/en-us/article/TMKA-11252">https://helpcenter.trendmicro.com/en-us/article/TMKA-11252</a><br/>
Packet Tuesday: IP Options<br/>
 <a href="https://www.youtube.com/watch?v=HldNL3SLLwM">https://www.youtube.com/watch?v=HldNL3SLLwM</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8310" type="text/plain" language="en" />
<itunes:keywords>packettuesday, trend micro, Flipper zero, car, vulnerability, ntp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 3rd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8308</itunes:episode>
<itunes:subtitle>Kyverno image swap vuln; Google Home Vuln; 3G CDMA Decomissioning; EarSpy Cell Phone Evesdropping
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kyverno image swap vuln; Google Home Vuln; 3G CDMA Decomissioning; EarSpy Cell Phone Evesdropping
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8308.mp3" length="5239525" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8308.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8308</link>
<pubDate>Tue, 03 Jan 2023 02:00:02 GMT</pubDate>
<description><![CDATA[Kyverno's container image signature verification bypass<br/>
 <a href="https://www.armosec.io/blog/cve-2022-47633-kyvernos-container-image-signature-verification/">https://www.armosec.io/blog/cve-2022-47633-kyvernos-container-image-signature-verification/</a><br/>
Google Smart Spaeker Vulnerability<br/>
 <a href="https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html">https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html</a><br/>
Verizon Decomissions 3G CDMA Network<br/>
 <a href="https://www.fiercewireless.com/wireless/verizon-tells-3g-customers-upgrade-they-lose-service">https://www.fiercewireless.com/wireless/verizon-tells-3g-customers-upgrade-they-lose-service</a><br/>
EarSpy: Spying Caller Speech and Identity Through Speaker Vibrations<br/>
 <a href="https://arxiv.org/pdf/2212.12151.pdf">https://arxiv.org/pdf/2212.12151.pdf</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8308" type="text/plain" language="en" />
<itunes:keywords>earspy, evesdropping, google, home, smart speaker, verizon, cdma, 3g, kyversno, container, signature, kubernetes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 2nd, 2023</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8306</itunes:episode>
<itunes:subtitle>GOV Domain SPF/DMARC Use; ksmbd vuln; netgear patch; PyTorch dependency polution
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GOV Domain SPF/DMARC Use; ksmbd vuln; netgear patch; PyTorch dependency polution
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8306.mp3" length="5673940" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8306.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8306</link>
<pubDate>Mon, 02 Jan 2023 02:40:01 GMT</pubDate>
<description><![CDATA[SPF and DMARC use on GOV domains in different ccTLDs<br/>
 <a href="https://isc.sans.edu/forums/diary/SPF+and+DMARC+use+on+GOV+domains+in+different+ccTLDs/29384/">https://isc.sans.edu/forums/diary/SPF+and+DMARC+use+on+GOV+domains+in+different+ccTLDs/29384/</a><br/>
CVE-2022-47939 ksmbd Vulnerability<br/>
 <a href="https://ubuntu.com/security/CVE-2022-47939">https://ubuntu.com/security/CVE-2022-47939</a><br/>
Netgear Vulnerabilities<br/>
 <a href="https://kb.netgear.com/000065495/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2019-0208">https://kb.netgear.com/000065495/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2019-0208</a><br/>
PyTorch Malicious Dependency<br/>
 <a href="https://pytorch.org/blog/compromised-nightly-dependency/">https://pytorch.org/blog/compromised-nightly-dependency/</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8306" type="text/plain" language="en" />
<itunes:keywords>pytorch, netgear, ksmbd, cve-2022-47939, spf, dmark, gov, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 23rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8304</itunes:episode>
<itunes:subtitle>OWASSRF Exploit Variant; ksmbd RCE Vulnerability; LastPass Incident Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OWASSRF Exploit Variant; ksmbd RCE Vulnerability; LastPass Incident Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8304.mp3" length="5833522" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8304.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8304</link>
<pubDate>Fri, 23 Dec 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Exchange OWASSRF Exploited for Remote Code Execution<br/>
 <a href="https://isc.sans.edu/forums/diary/Exchange%20OWASSRF%20Exploited%20for%20Remote%20Code%20Execution/29374/">https://isc.sans.edu/forums/diary/Exchange%20OWASSRF%20Exploited%20for%20Remote%20Code%20Execution/29374/</a><br/>
ksmbd Vulnerability<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-22-1690/">https://www.zerodayinitiative.com/advisories/ZDI-22-1690/</a><br/>
LastPass Incident Update<br/>
 <a href="https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/">https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8304" type="text/plain" language="en" />
<itunes:keywords>lastpass, ksmbd, exchange, owassrf, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8302</itunes:episode>
<itunes:subtitle>Quick NTP Measurement; FBI favors Ad Blockers; Parental Control Issues; ProxyNotShell Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Quick NTP Measurement; FBI favors Ad Blockers; Parental Control Issues; ProxyNotShell Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8302.mp3" length="5353746" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8302.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8302</link>
<pubDate>Thu, 22 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Quick NTP Measurement<br/>
 <a href="https://isc.sans.edu/diary/Can%20you%20please%20tell%20me%20what%20time%20it%20is%3F%20Adventures%20with%20public%20NTP%20servers./29368">https://isc.sans.edu/diary/Can%20you%20please%20tell%20me%20what%20time%20it%20is%3F%20Adventures%20with%20public%20NTP%20servers./29368</a><br/>
FBI Favors Ad Blockers<br/>
 <a href="https://www.ic3.gov/Media/Y2022/PSA221221">https://www.ic3.gov/Media/Y2022/PSA221221</a><br/>
Hidden Costs of Parental Control Apps<br/>
 <a href="https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/">https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/</a><br/>
ProxyNotShell Mitigtation Bypass<br/>
 <a href="https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/">https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8302" type="text/plain" language="en" />
<itunes:keywords>proxynotshell, exchange, mitigation, bypass, parental control, fbi, ad blockers, ntp, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8300</itunes:episode>
<itunes:subtitle>Monitoring Linux Files; NTP and Mostodon IP Feeds; Android Root Cert Updates; Elastic IP Hijack; HyperV Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Monitoring Linux Files; NTP and Mostodon IP Feeds; Android Root Cert Updates; Elastic IP Hijack; HyperV Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8300.mp3" length="6468630" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8300.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8300</link>
<pubDate>Wed, 21 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Linux File System Monitoring and Actions<br/>
 <a href="https://isc.sans.edu/diary/Linux%20File%20System%20Monitoring%20%26%20Actions/29362">https://isc.sans.edu/diary/Linux%20File%20System%20Monitoring%20%26%20Actions/29362</a><br/>
Feed of NTP Server IP Addresses<br/>
 <a href="https://isc.sans.edu/api/threatlist/ntpservers?json">https://isc.sans.edu/api/threatlist/ntpservers?json</a><br/>
Feed of Mastodon Server IP Addresses<br/>
 <a href="https://isc.sans.edu/api/threatlist/mastodon?json">https://isc.sans.edu/api/threatlist/mastodon?json</a><br/>
Packet Tuesday TLS Server Hello<br/>
 <a href="https://www.youtube.com/watch?v=2HymU4dxWEQ">https://www.youtube.com/watch?v=2HymU4dxWEQ</a><br/>
Android Preparing Support for Updatable Root Certificates<br/>
 <a href="https://blog.esper.io/android-14-updatable-certificates/">https://blog.esper.io/android-14-updatable-certificates/</a><br/>
Elastic IP Hijacking<br/>
 <a href="https://www.mitiga.io/blog/elastic-ip-hijacking-a-new-attack-vector-in-aws">https://www.mitiga.io/blog/elastic-ip-hijacking-a-new-attack-vector-in-aws</a><br/>
Microsoft Fixes HyperV issues With Latest Patch<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#2988">https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#2988</a><br/>
]]></description>
<itunes:duration>7:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8300" type="text/plain" language="en" />
<itunes:keywords>microsoft, hyperv, elastic ip, amazon, aws, android, root certs, packet tuesday, tls, ntp, mastodon, linux, monitoring, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8298</itunes:episode>
<itunes:subtitle>Hunting Mastodons; IE Disabled in February; Gatekeeper Bypass Details; Corsair Keyboard Bug; SentinelOne Fake Python Package
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hunting Mastodons; IE Disabled in February; Gatekeeper Bypass Details; Corsair Keyboard Bug; SentinelOne Fake Python Package
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8298.mp3" length="5619521" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8298.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8298</link>
<pubDate>Tue, 20 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Hunting for Mastodon Servers<br/>
 <a href="https://isc.sans.edu/diary/Hunting%20for%20Mastodon%20Servers/29358">https://isc.sans.edu/diary/Hunting%20for%20Mastodon%20Servers/29358</a><br/>
KB5021233 Blue Screen<br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22H2#2986msgdesc">https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22H2#2986msgdesc</a><br/>
Edge Update will disable Internet Explorer in February<br/>
 <a href="https://learn.microsoft.com/en-us/deployedge/edge-learnmore-neededge">https://learn.microsoft.com/en-us/deployedge/edge-learnmore-neededge</a><br/>
Gatekeeper's Achilles heel: Unearthin a macOS vulnerability<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/">https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/</a><br/>
Corsair Bug not causing keystroke logging<br/>
 <a href="https://arstechnica.com/gadgets/2022/12/corsair-says-bug-not-keylogger-behind-some-k100-keyboards-creepy-behavior/">https://arstechnica.com/gadgets/2022/12/corsair-says-bug-not-keylogger-behind-some-k100-keyboards-creepy-behavior/</a><br/>
SentinelSneak: Malicious PyPi module poses as security software development kit<br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8298" type="text/plain" language="en" />
<itunes:keywords>sentinelone, pypi, sentinelsneak, mastodon, corsair, gatekeeper, macos, edge, internet explorer, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8296</itunes:episode>
<itunes:subtitle>HSBC Malware; GMail Encryption; OSV Scanner; Samba PAtches; Zyxel Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HSBC Malware; GMail Encryption; OSV Scanner; Samba PAtches; Zyxel Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8296.mp3" length="5412198" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8296.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8296</link>
<pubDate>Mon, 19 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Infostealer Malware with Double Extension<br/>
 <a href="https://isc.sans.edu/diary/Infostealer%20Malware%20with%20Double%20Extension/29354">https://isc.sans.edu/diary/Infostealer%20Malware%20with%20Double%20Extension/29354</a><br/>
Client Side Encryption For GMail<br/>
 <a href="https://workspaceupdates.googleblog.com/2022/12/client-side-encryption-for-gmail-beta.html">https://workspaceupdates.googleblog.com/2022/12/client-side-encryption-for-gmail-beta.html</a><br/>
Google Releases OSV Scanner<br/>
 <a href="https://github.com/google/osv-scanner/releases/tag/v1.0.1">https://github.com/google/osv-scanner/releases/tag/v1.0.1</a><br/>
Samba Security Patches<br/>
 <a href="https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html">https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html</a><br/>
Zyxel Router Buffer Overflow<br/>
 <a href="https://sec-consult.com/blog/detail/enemy-within-unauthenticated-buffer-overflows-zyxel-routers/">https://sec-consult.com/blog/detail/enemy-within-unauthenticated-buffer-overflows-zyxel-routers/</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8296" type="text/plain" language="en" />
<itunes:keywords>hsbc, infostealer, malware, gmail, encryption, osv, samba, zyxel, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8294</itunes:episode>
<itunes:subtitle>Google Ads and IcedId; SVG Malware; GitHub Improvements; SHA-1 Retirement
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Ads and IcedId; SVG Malware; GitHub Improvements; SHA-1 Retirement
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8294.mp3" length="5397656" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8294.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8294</link>
<pubDate>Fri, 16 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Google ads lead to fake software pages pushing IcedID (Bokbot)<br/>
 <a href="https://isc.sans.edu/diary/Google%20ads%20lead%20to%20fake%20software%20pages%20pushing%20IcedID%20%28Bokbot%29/29344">https://isc.sans.edu/diary/Google%20ads%20lead%20to%20fake%20software%20pages%20pushing%20IcedID%20%28Bokbot%29/29344</a><br/>
HTML smugglers turn to SVG images<br/>
 <a href="https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/">https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/</a><br/>
GitHub Improvements<br/>
 <a href="https://github.blog/2022-12-14-raising-the-bar-for-software-security-next-steps-for-github-com-2fa/">https://github.blog/2022-12-14-raising-the-bar-for-software-security-next-steps-for-github-com-2fa/</a><br/>
NIST Retires SHA-1<br/>
 <a href="https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm">https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8294" type="text/plain" language="en" />
<itunes:keywords>sha1, github, html, svg, icedid, bokbot, google, ads, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8292</itunes:episode>
<itunes:subtitle>MSFT Patch Issues; SPNEGO Vuln now Critical; VMWare Escape; Veem Exploited; Repository Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Issues; SPNEGO Vuln now Critical; VMWare Escape; Veem Exploited; Repository Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8292.mp3" length="5479573" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8292.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8292</link>
<pubDate>Thu, 15 Dec 2022 11:40:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Issues:<br/>
 <a href="https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45">https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/so-you-say-your-dc-s-memory-is-getting-all-used-up-after/ba-p/3696318">https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/so-you-say-your-dc-s-memory-is-getting-all-used-up-after/ba-p/3696318</a><br/>
Critical Remote Code Execution Vulneraiblity in SPNEGO Extended Negotiation Security Mechanism<br/>
 <a href="https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/">https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/</a><br/>
VMWare EHCI Controller Vulnerability CVE-2022-31705<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0033.html">https://www.vmware.com/security/advisories/VMSA-2022-0033.html</a><br/>
Veem Vulnerability now Exploited<br/>
 <a href="https://www.veeam.com/kb4288">https://www.veeam.com/kb4288</a><br/>
nuget / npm / pypi used to host phishing pages<br/>
 <a href="https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/">https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8292" type="text/plain" language="en" />
<itunes:keywords>npm, npm, pypi, phishing, veem, backup, vmware, spnego, windows, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8290</itunes:episode>
<itunes:subtitle>Microsoft Patches; Apple Patches; Citrix Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Apple Patches; Citrix Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8290.mp3" length="5745149" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8290.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8290</link>
<pubDate>Wed, 14 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20December%202022%20Patch%20Tuesday/29336">https://isc.sans.edu/diary/Microsoft%20December%202022%20Patch%20Tuesday/29336</a><br/>
Apple Patches<br/>
 <a href="https://isc.sans.edu/diary/Apple%20Updates%20Everything/29338">https://isc.sans.edu/diary/Apple%20Updates%20Everything/29338</a><br/>
Citrix Patches<br/>
 <a href="https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/">https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8290" type="text/plain" language="en" />
<itunes:keywords>citrix, apple, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8288</itunes:episode>
<itunes:subtitle>CyberChef Sorting; FortiOS sslvpnd vuln; Python VMWare Backdoor; Fuzzing Ping
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CyberChef Sorting; FortiOS sslvpnd vuln; Python VMWare Backdoor; Fuzzing Ping
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8288.mp3" length="5637172" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8288.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8288</link>
<pubDate>Tue, 13 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Quickie: CyberChef Sorting By String Length<br/>
 <a href="https://isc.sans.edu/diary/Quickie%3A%20CyberChef%20Sorting%20By%20String%20Length/29328">https://isc.sans.edu/diary/Quickie%3A%20CyberChef%20Sorting%20By%20String%20Length/29328</a><br/>
FortiOS Buffer Overlow<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-22-398">https://www.fortiguard.com/psirt/FG-IR-22-398</a><br/>
A Custom Python Backdoor for VMWare ESXi Servers<br/>
 <a href="https://blogs.juniper.net/en-us/threat-research/a-custom-python-backdoor-for-vmware-esxi-servers">https://blogs.juniper.net/en-us/threat-research/a-custom-python-backdoor-for-vmware-esxi-servers</a><br/>
Fuzzing Ping<br/>
 <a href="https://tlakh.xyz/fuzzing-ping.html">https://tlakh.xyz/fuzzing-ping.html</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8288" type="text/plain" language="en" />
<itunes:keywords>ping, fuzzing, python backdoor, vmware, esxi, fortios, cyberchef, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8286</itunes:episode>
<itunes:subtitle>Fast PS Portscanner; Bypassing WAFs; Invisible npm malware; PCI Software Security; vmware advisory
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fast PS Portscanner; Bypassing WAFs; Invisible npm malware; PCI Software Security; vmware advisory
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8286.mp3" length="5940770" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8286.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8286</link>
<pubDate>Mon, 12 Dec 2022 03:10:01 GMT</pubDate>
<description><![CDATA[Fast Port Scanning in Powershell<br/>
 <a href="https://isc.sans.edu/diary/Port%20Scanning%20in%20Powershell%20Redux%3A%20Speeding%20Up%20the%20Results%20%28challenge%20accepted!%29/29324">https://isc.sans.edu/diary/Port%20Scanning%20in%20Powershell%20Redux%3A%20Speeding%20Up%20the%20Results%20%28challenge%20accepted!%29/29324</a><br/>
Bypassing WAFs with JSON<br/>
 <a href="https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf">https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf</a><br/>
Invisbile npm malware evading security checks<br/>
 <a href="https://jfrog.com/blog/invisible-npm-malware-evading-security-checks-with-crafted-versions/">https://jfrog.com/blog/invisible-npm-malware-evading-security-checks-with-crafted-versions/</a><br/>
PCI Secre Software Standard V 1.2<br/>
 <a href="https://docs-prv.pcisecuritystandards.org/Software%20Security/Standard/PCI-Secure-Software-Standard-v1_2.pdf">https://docs-prv.pcisecuritystandards.org/Software%20Security/Standard/PCI-Secure-Software-Standard-v1_2.pdf</a><br/>
VMWare/VCenter Patches<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0030.html">https://www.vmware.com/security/advisories/VMSA-2022-0030.html</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8286" type="text/plain" language="en" />
<itunes:keywords>vmware, vcenter, powershell, nmap, portscanner, json, wab, npm, version, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8284</itunes:episode>
<itunes:subtitle>Finding Log Gaps; IE Exploit; Zombinder; Cisco IP Phone Vuln; daloRADIUS vuln; SANS Holiday Hack Challenge
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding Log Gaps; IE Exploit; Zombinder; Cisco IP Phone Vuln; daloRADIUS vuln; SANS Holiday Hack Challenge
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8284.mp3" length="5107184" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8284.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8284</link>
<pubDate>Fri, 09 Dec 2022 04:36:56 GMT</pubDate>
<description><![CDATA[Finding Gaps in Syslog <br/>
 <a href="https://isc.sans.edu/diary/Finding%20Gaps%20in%20Syslog%20-%20How%20to%20find%20when%20nothing%20happened/29314">https://isc.sans.edu/diary/Finding%20Gaps%20in%20Syslog%20-%20How%20to%20find%20when%20nothing%20happened/29314</a><br/>
Internet Explorer Vulnerabilty used in Malicious Word Document<br/>
 <a href="https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/">https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/</a><br/>
Zombinder Obfuscation Service used by Ermac<br/>
 <a href="https://www.threatfabric.com/blogs/zombinder-ermac-and-desktop-stealers.html">https://www.threatfabric.com/blogs/zombinder-ermac-and-desktop-stealers.html</a><br/>
Cisco IP Phone Vulnerability CVE-2022-20968<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipp-oobwrite-8cMF5r7U">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipp-oobwrite-8cMF5r7U</a><br/>
daloRADIUS Vulnerablity CVE-2022-23475<br/>
 <a href="https://securityonline.info/cve-2022-23475-account-take-over-flaw-in-open-source-radius-web-management-app/">https://securityonline.info/cve-2022-23475-account-take-over-flaw-in-open-source-radius-web-management-app/</a><br/>
SANS Holiday Hack Challenge<br/>
 <a href="https://www.sans.org/mlp/holiday-hack-challenge/">https://www.sans.org/mlp/holiday-hack-challenge/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8284" type="text/plain" language="en" />
<itunes:keywords>cisco, logs, syslog, holiday, hack challenge, daloradius, ip phone, zombinder, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8282</itunes:episode>
<itunes:subtitle>IoT Bot WSZero; Cacti Vulnerability; Wireshark Updates; Apple iCloud Encryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IoT Bot WSZero; Cacti Vulnerability; Wireshark Updates; Apple iCloud Encryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8282.mp3" length="4644758" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8282.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8282</link>
<pubDate>Thu, 08 Dec 2022 04:55:01 GMT</pubDate>
<description><![CDATA[ZeroBot / WSZero IoT Botnet<br/>
 <a href="https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities">https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities</a><br/>
 <a href="https://blog.netlab.360.com/new-ddos-botnet-wszeor/">https://blog.netlab.360.com/new-ddos-botnet-wszeor/</a><br/>
Cacti Vulnerability CVE-2022-46169<br/>
 <a href="https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf">https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf</a><br/>
Wireshark Updates<br/>
 <a href="https://www.wireshark.org/docs/relnotes/wireshark-4.0.2.html">https://www.wireshark.org/docs/relnotes/wireshark-4.0.2.html</a><br/>
Apple iCloud Security Improvements<br/>
 <a href="https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/">https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8282" type="text/plain" language="en" />
<itunes:keywords>apple, icloud, wireshark, cacti, zerobot, wszero, wss, websocket, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8280</itunes:episode>
<itunes:subtitle>Gafgyt/Mirai Sample; Packet Tuesday; Defcon Skimming; Fake D-Link Vuln; Android Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Gafgyt/Mirai Sample; Packet Tuesday; Defcon Skimming; Fake D-Link Vuln; Android Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8280.mp3" length="4957280" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8280.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8280</link>
<pubDate>Wed, 07 Dec 2022 03:30:02 GMT</pubDate>
<description><![CDATA[Mirai Botnet and Gafgyt DDoS Team Up<br/>
 <a href="https://isc.sans.edu/forums/diary/Mirai%20Botnet%20and%20Gafgyt%20DDoS%20Team%20Up%20Against%20SOHO%20Routers./29304/Gafgyt/Mirai">https://isc.sans.edu/forums/diary/Mirai%20Botnet%20and%20Gafgyt%20DDoS%20Team%20Up%20Against%20SOHO%20Routers./29304/Gafgyt/Mirai</a> Sample; Packet Tuesday; <br/>
Packet Tuesday Episode 4: TLS Client Hello<br/>
 <a href="https://www.youtube.com/playlist?list=PLs4eo9Tja8biVteSW4a3GHY8qi0t1lFLL">https://www.youtube.com/playlist?list=PLs4eo9Tja8biVteSW4a3GHY8qi0t1lFLL</a><br/>
Defcon Skimming: A new batch of Web Skimming attacks<br/>
 <a href="https://blog.jscrambler.com/defcon-skimming-a-new-batch-of-web-skimming-attacks">https://blog.jscrambler.com/defcon-skimming-a-new-batch-of-web-skimming-attacks</a><br/>
Fake D-Link Vulnerability used by Moobot<br/>
 <a href="https://vulncheck.com/blog/moobot-uses-fake-vulnerability">https://vulncheck.com/blog/moobot-uses-fake-vulnerability</a><br/>
Android Patches CVE-2022-20411<br/>
 <a href="https://source.android.com/docs/security/bulletin/2022-12-01?hl=en">https://source.android.com/docs/security/bulletin/2022-12-01?hl=en</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8280" type="text/plain" language="en" />
<itunes:keywords>android, bluetooth, d-link, moobot, defcon, tls, packet tuesday, mirai, gafgyt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 6th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8278</itunes:episode>
<itunes:subtitle>VLC Update Issues; AMI MegaRAC BMC Vuln; Netgear IPv6; Veritas NetBackup
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VLC Update Issues; AMI MegaRAC BMC Vuln; Netgear IPv6; Veritas NetBackup
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8278.mp3" length="5147391" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8278.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8278</link>
<pubDate>Tue, 06 Dec 2022 16:07:18 GMT</pubDate>
<description><![CDATA[VLCs Check For Updates No Updates<br/>
 <a href="https://isc.sans.edu/diary/VLCs+Check+For+Updates+No+Updates/29300">https://isc.sans.edu/diary/VLCs+Check+For+Updates+No+Updates/29300</a><br/>
AMI MegaRAC Baseboard Managment Controller Vulnerabilities<br/>
 <a href="https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/">https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/</a><br/>
Netgear IPv6 Firewall Misconfiguration<br/>
 <a href="https://medium.com/tenable-techblog/netgear-router-network-misconfiguration-70ac695c81a6">https://medium.com/tenable-techblog/netgear-router-network-misconfiguration-70ac695c81a6</a><br/>
Veritas NetBackup Patch <br/>
 <a href="https://www.veritas.com/content/support/en_US/security/VTS22-019">https://www.veritas.com/content/support/en_US/security/VTS22-019</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8278" type="text/plain" language="en" />
<itunes:keywords>videolan, vlc, bmc, megarac, ami, netgear, ipv6, veritas, netbackup, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 5th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8276</itunes:episode>
<itunes:subtitle>QBot Update; Linux LOLBins in Windows; Crowdstrike Falcon; Android Cert Leak; Github Artifcat Poisoning
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
QBot Update; Linux LOLBins in Windows; Crowdstrike Falcon; Android Cert Leak; Github Artifcat Poisoning
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8276.mp3" length="7902767" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8276.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8276</link>
<pubDate>Mon, 05 Dec 2022 04:40:02 GMT</pubDate>
<description><![CDATA[QBot Update<br/>
<a href="https://isc.sans.edu/forums/diary/obama224%20distribution%20Qakbot%20tries%20.vhd%20%28virtual%20hard%20disk%29%20images/29294/">https://isc.sans.edu/forums/diary/obama224%20distribution%20Qakbot%20tries%20.vhd%20%28virtual%20hard%20disk%29%20images/29294/</a><br/>
Living of the Land: Unix tools in Windows<br/>
<a href="https://isc.sans.edu/diary/Linux%20LOLBins%20Applications%20Available%20in%20Windows/29296">https://isc.sans.edu/diary/Linux%20LOLBins%20Applications%20Available%20in%20Windows/29296</a><br/>
<a href="https://isc.sans.edu/forums/diary/Fingerexe+LOLBin/29298/">https://isc.sans.edu/forums/diary/Fingerexe+LOLBin/29298/</a><br/>
CVE-2022-44721 Crowdstrike Falcon Uninstaller<br/>
 <a href="https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller">https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller</a><br/>
Android Platform Key Leak<br/>
 <a href="https://twitter.com/MishaalRahman/status/1598426974594433025">https://twitter.com/MishaalRahman/status/1598426974594433025</a><br/>
GitHub Pipeline Vulnerability<br/>
 <a href="https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust">https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust</a><br/>
]]></description>
<itunes:duration>9:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8276" type="text/plain" language="en" />
<itunes:keywords>github, android, crowdstrike, lolbin, finger, windows, unix, qbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8274</itunes:episode>
<itunes:subtitle>Quarkus Java RCE; FreeBSD Ping RCE; NVidia Updates; TrustCor Untrusted; Android Platform Certs Abused
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Quarkus Java RCE; FreeBSD Ping RCE; NVidia Updates; TrustCor Untrusted; Android Platform Certs Abused
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8274.mp3" length="5693169" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8274.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8274</link>
<pubDate>Fri, 02 Dec 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Quarkus Java Framework Vulnerability CVE-2022-4116<br/>
 <a href="https://www.contrastsecurity.com/security-influencers/localhost-attack-against-quarkus-developers-contrast-security">https://www.contrastsecurity.com/security-influencers/localhost-attack-against-quarkus-developers-contrast-security</a><br/>
 <a href="https://access.redhat.com/security/cve/CVE-2022-4116">https://access.redhat.com/security/cve/CVE-2022-4116</a><br/>
FreeBSD Ping RCE CVE-2022-23093<br/>
 <a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc">https://www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc</a><br/>
NVidia GPU Display Driver Vulnerablities CVE-2022-34669<br/>
 <a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5415">https://nvidia.custhelp.com/app/answers/detail/a_id/5415</a><br/>
TrustCor CA Revoked<br/>
 <a href="https://www.washingtonpost.com/technology/2022/11/30/trustcor-internet-authority-mozilla/">https://www.washingtonpost.com/technology/2022/11/30/trustcor-internet-authority-mozilla/</a><br/>
Android Platform Certificates Used to Sign Malware<br/>
 <a href="https://bugs.chromium.org/p/apvi/issues/detail?id=100">https://bugs.chromium.org/p/apvi/issues/detail?id=100</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8274" type="text/plain" language="en" />
<itunes:keywords>android, trustcor, nvidia, drivers, certificates, freebsd, ping, quarkus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8272</itunes:episode>
<itunes:subtitle>Vulnerability Mysteries: Netgear, DLink, Apple; VLC Update; Unlock Cars thx to SirusXM
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Vulnerability Mysteries: Netgear, DLink, Apple; VLC Update; Unlock Cars thx to SirusXM
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8272.mp3" length="5090541" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8272.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8272</link>
<pubDate>Thu, 01 Dec 2022 02:00:02 GMT</pubDate>
<description><![CDATA[What is the deal wtih these router vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Whats+the+deal+with+these+router+vulnerabilities/29288/">https://isc.sans.edu/diary/Whats+the+deal+with+these+router+vulnerabilities/29288/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
VLC Media Player Updates CVE-2022-41325<br/>
 <a href="https://www.videolan.org/security/sb-vlc3018.html">https://www.videolan.org/security/sb-vlc3018.html</a><br/>
VIN used to authenticate to Sirius XM Connected Vehicle Services<br/>
 <a href="https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/">https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8272" type="text/plain" language="en" />
<itunes:keywords>sirius xm, vin, car hacking, vlc, videolan, apple, dlink, linksys, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 30th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8270</itunes:episode>
<itunes:subtitle>LinkedIn Bots; Oracle Fusion Exploited; Windows IKE Exploit; Anker Eufy Privacy; SANS Holiday Hack Challenge
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LinkedIn Bots; Oracle Fusion Exploited; Windows IKE Exploit; Anker Eufy Privacy; SANS Holiday Hack Challenge
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8270.mp3" length="5990727" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8270.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8270</link>
<pubDate>Wed, 30 Nov 2022 02:35:01 GMT</pubDate>
<description><![CDATA[LinkedIn Bots<br/>
 <a href="https://isc.sans.edu/diary/Identifying%20Groups%20of%20%22Bot%22%20Accounts%20on%20LinkedIn/29282">https://isc.sans.edu/diary/Identifying%20Groups%20of%20%22Bot%22%20Accounts%20on%20LinkedIn/29282</a><br/>
Oracle Fusion Middle Ware Exploited CVE-2021-35587<br/>
 <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">https://www.cisa.gov/known-exploited-vulnerabilities-catalog</a><br/>
Windows IKE Flaw Exploited CVE-2022-34721<br/>
 <a href="https://www.cyfirma.com/outofband/windows-internet-key-exchange-ike-remote-code-execution-vulnerability-analysis/">https://www.cyfirma.com/outofband/windows-internet-key-exchange-ike-remote-code-execution-vulnerability-analysis/</a><br/>
Anker Eufy Cameras Sending Images to Cloud even if asked not to<br/>
 <a href="https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/">https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/</a><br/>
Packet Tuesday<br/>
 <a href="https://packettuesday.com">https://packettuesday.com</a><br/>
SANS Holiday Hack Challenge Sign Up<br/>
 <a href="https://www.sans.org/mlp/holiday-hack-challenge/">https://www.sans.org/mlp/holiday-hack-challenge/</a><br/>
]]></description>
<itunes:duration>6:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8270" type="text/plain" language="en" />
<itunes:keywords>holiday hack challenge, packet tuesday, anker, eufy, privacy, cloud, aws, windows, ike, oracle, fusion, linkedin, bots, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 29th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8268</itunes:episode>
<itunes:subtitle>Ukraine Scareware; Google Maps Privacy; ASUS BIOS Patch; OpenSSL and UEFI
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ukraine Scareware; Google Maps Privacy; ASUS BIOS Patch; OpenSSL and UEFI
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8268.mp3" length="6251461" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8268.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8268</link>
<pubDate>Tue, 29 Nov 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Ukraine Themed Twitter Spam Pushing iOS Scareware<br/>
 <a href="https://isc.sans.edu/diary/Ukraine%20Themed%20Twitter%20Spam%20Pushing%20iOS%20Scareware/29276">https://isc.sans.edu/diary/Ukraine%20Themed%20Twitter%20Spam%20Pushing%20iOS%20Scareware/29276</a><br/>
Google Maps Privacy Issues<br/>
 <a href="https://garrit.xyz/posts/2022-11-24-smart-move-google">https://garrit.xyz/posts/2022-11-24-smart-move-google</a><br/>
ACER UEFI BIOS Vulnerabilities<br/>
 <a href="https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings">https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings</a><br/>
OpenSSL Usage in UEFI Firmware Exposes Weakness in SBOMs<br/>
 <a href="https://www.binarly.io/posts/OpenSSL_Usage_in_UEFI_Firmware_Exposes_Weakness_in_SBOMs/index.html">https://www.binarly.io/posts/OpenSSL_Usage_in_UEFI_Firmware_Exposes_Weakness_in_SBOMs/index.html</a><br/>
]]></description>
<itunes:duration>7:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8268" type="text/plain" language="en" />
<itunes:keywords>ukraine, google, maps, privacy, scareware, asus, bios, openssl, uefi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8266</itunes:episode>
<itunes:subtitle>Log4J Rev. Shell With Nashorn; Phishing with Urgency; BOA Risks; Chrome 0-Day; Smartwatch Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Log4J Rev. Shell With Nashorn; Phishing with Urgency; BOA Risks; Chrome 0-Day; Smartwatch Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8266.mp3" length="6190901" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8266.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8266</link>
<pubDate>Mon, 28 Nov 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Log4Shell campaigns are using Nashorn to get reverse shell on victim's machines<br/>
 <a href="https://isc.sans.edu/diary/Log4Shell%20campaigns%20are%20using%20Nashorn%20to%20get%20reverse%20shell%20on%20victim%27s%20machines/29266">https://isc.sans.edu/diary/Log4Shell%20campaigns%20are%20using%20Nashorn%20to%20get%20reverse%20shell%20on%20victim%27s%20machines/29266</a><br/>
Attackers Keep Phishing Victms Under Stress<br/>
 <a href="https://isc.sans.edu/diary/Attackers%20Keep%20Phishing%20Victims%20Under%20Stress/29270">https://isc.sans.edu/diary/Attackers%20Keep%20Phishing%20Victims%20Under%20Stress/29270</a><br/>
Vulnerable SDK components lead to supply chian risks in IoT and OT environments<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/">https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/</a><br/>
Google Chrome Patches 0-Day<br/>
 <a href="https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html">https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html</a><br/>
Hacking Smartwatches for Spear Phishing<br/>
 <a href="https://cybervelia.com/?p=1380">https://cybervelia.com/?p=1380</a><br/>
]]></description>
<itunes:duration>7:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8266" type="text/plain" language="en" />
<itunes:keywords>chrome, sdk, smartwatch, phishing, stress, log4shell, nashorn, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8264</itunes:episode>
<itunes:subtitle>Ping vs. TMobile; Bitbucked Vuln; AWS RDS Leaks; Adobe Commerce; Antonio Piazza interview detecting and mitigating MacOS Gatekeeper Override @sans_edu</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ping vs. TMobile; Bitbucked Vuln; AWS RDS Leaks; Adobe Commerce; Antonio Piazza interview detecting and mitigating MacOS Gatekeeper Override @sans_edu</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8264.mp3" length="12140382" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8264.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8264</link>
<pubDate>Fri, 18 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Lessons Learned from Automatic Failover<br/>
 <a href="https://isc.sans.edu/diary/Lessons%20Learned%20from%20Automatic%20Failover%3A%20When%208.8.8.8%20%22disappears%22.%20IPv6%20to%20the%20Rescue%3F/29260">https://isc.sans.edu/diary/Lessons%20Learned%20from%20Automatic%20Failover%3A%20When%208.8.8.8%20%22disappears%22.%20IPv6%20to%20the%20Rescue%3F/29260</a><br/>
Bitbucket Server and Data Center Vulnerability<br/>
 <a href="https://jira.atlassian.com/browse/BSERV-13522">https://jira.atlassian.com/browse/BSERV-13522</a><br/>
Amazon RDS Snapshot Leaks<br/>
 <a href="https://www.mitiga.io/blog/how-mitiga-found-pii-in-exposed-amazon-rds-snapshots">https://www.mitiga.io/blog/how-mitiga-found-pii-in-exposed-amazon-rds-snapshots</a><br/>
Adobe Commerce merchants to be hit with TrojanOrders this season<br/>
 <a href="https://sansec.io/research/trojanorder-magento">https://sansec.io/research/trojanorder-magento</a><br/>
SANS EDU Research: Detecting and Mitigating the GateKeeper User Override on macOS in an Enterprise Environment; Antonio Piazza<br/>
 <a href="https://www.sans.edu/cyber-research/detecting-and-mitigating-the-gatekeeper-user-override-on-macos-in-an-enterprise-environment/">https://www.sans.edu/cyber-research/detecting-and-mitigating-the-gatekeeper-user-override-on-macos-in-an-enterprise-environment/</a><br/>
]]></description>
<itunes:duration>14:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8264" type="text/plain" language="en" />
<itunes:keywords>adobe, magento, trojanorders, rds, amazon, aws, bitbucket, server, failover, tmobile, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8262</itunes:episode>
<itunes:subtitle>Cheap Evil Maid Defenses; F5 Big-IP PoC; CVE-2022-32899 iOS Neural Engine; Disneyland Malware Team
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cheap Evil Maid Defenses; F5 Big-IP PoC; CVE-2022-32899 iOS Neural Engine; Disneyland Malware Team
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8262.mp3" length="5823549" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8262.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8262</link>
<pubDate>Thu, 17 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Evil Maid Attacks - Remediation for the Cheap<br/>
 <a href="https://isc.sans.edu/diary/Evil%20Maid%20Attacks%20-%20Remediation%20for%20the%20Cheap/29256">https://isc.sans.edu/diary/Evil%20Maid%20Attacks%20-%20Remediation%20for%20the%20Cheap/29256</a><br/>
F5 Big IP CVE-2022-41622 and CVE-2022-41800 Vulnerability Details<br/>
 <a href="https://www.rapid7.com/blog/post/2022/11/16/cve-2022-41622-and-cve-2022-41800-fixed-f5-big-ip-and-icontrol-rest-vulnerabilities-and-exposures/">https://www.rapid7.com/blog/post/2022/11/16/cve-2022-41622-and-cve-2022-41800-fixed-f5-big-ip-and-icontrol-rest-vulnerabilities-and-exposures/</a><br/>
Details about iPad/iOS Neural Engine Vulnerability CVE-2022-32899<br/>
 <a href="https://github.com/0x36/weightBufs/">https://github.com/0x36/weightBufs/</a><br/>
Disneyland Malware Team: It's a Puny World After All<br/>
 <a href="https://krebsonsecurity.com/2022/11/disneyland-malware-team-its-a-puny-world-after-all/#more-61870">https://krebsonsecurity.com/2022/11/disneyland-malware-team-its-a-puny-world-after-all/#more-61870</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8262" type="text/plain" language="en" />
<itunes:keywords>disneyland, malware, punycode, ipad, ios, neural engine, evil maid, f5, big-ip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8260</itunes:episode>
<itunes:subtitle>Packet Tuesday; Mastodon Bug; Zendesk SQLi; EV Charger Security;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Packet Tuesday; Mastodon Bug; Zendesk SQLi; EV Charger Security;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8260.mp3" length="4844396" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8260.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8260</link>
<pubDate>Wed, 16 Nov 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Packet Tuesday<br/>
 <a href="https://packettuesday.com">https://packettuesday.com</a><br/>
Stealing Passwords From Infosec Mastodon - Without Bypassing CSP<br/>
 <a href="https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp">https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp</a><br/>
SQLi and Access Flaws in Zendesk<br/>
 <a href="https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws">https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws</a><br/>
Electric Vehicle Charging Infrastructure<br/>
 <a href="https://newsreleases.sandia.gov/ev_security/">https://newsreleases.sandia.gov/ev_security/</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8260" type="text/plain" language="en" />
<itunes:keywords>packets, packet tuesday, dns, idn, punycode, passwords, mastodon, csp, sqli, zendesk, graphql, ev, chargers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8258</itunes:episode>
<itunes:subtitle>CONNECT Scans; Windows Kerberos Bug; Cookies vs MFA;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CONNECT Scans; Windows Kerberos Bug; Cookies vs MFA;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8258.mp3" length="4872650" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8258.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8258</link>
<pubDate>Tue, 15 Nov 2022 02:45:02 GMT</pubDate>
<description><![CDATA[Extracting "HTTP CONNECT" Requests with Python<br/>
 <a href="https://isc.sans.edu/diary/Extracting%20%27HTTP%20CONNECT%27%20Requests%20with%20Python/29246">https://isc.sans.edu/diary/Extracting%20%27HTTP%20CONNECT%27%20Requests%20with%20Python/29246</a><br/>
Windows Kerberos Authentication Breaks After November Updates<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-after-november-updates/">https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-after-november-updates/</a><br/>
 <a href="https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22h2#2953msgdesc">https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22h2#2953msgdesc</a><br/>
Cookies for MFA Bypass Gain Traction Among Cyberattackers<br/>
 <a href="https://www.darkreading.com/threat-intelligence/cookies-mfa-bypass-cyberattackers">https://www.darkreading.com/threat-intelligence/cookies-mfa-bypass-cyberattackers</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8258" type="text/plain" language="en" />
<itunes:keywords>cookies, mfa, kerberos, november, patch tuesday, updates, connect, proxy, scans, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8256</itunes:episode>
<itunes:subtitle>logfmt and Cyberchef; Worldcup Risks; CA Concerns; OpenLiteSpeed Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
logfmt and Cyberchef; Worldcup Risks; CA Concerns; OpenLiteSpeed Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8256.mp3" length="5415202" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8256.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8256</link>
<pubDate>Mon, 14 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Extracting Information From "logfmt" Files with CyberChef<br/>
 <a href="https://isc.sans.edu/diary/Extracting%20Information%20From%20%22logfmt%22%20Files%20With%20CyberChef/29244">https://isc.sans.edu/diary/Extracting%20Information%20From%20%22logfmt%22%20Files%20With%20CyberChef/29244</a><br/>
Soccer Worldcup Risks<br/>
 <a href="https://www.theregister.com/2022/11/11/world_cup_security/">https://www.theregister.com/2022/11/11/world_cup_security/</a><br/>
 <a href="https://www.welivesecurity.com/2022/11/11/fifa-world-cup-2022-scams-fake-lotteries-ticket-fraud/">https://www.welivesecurity.com/2022/11/11/fifa-world-cup-2022-scams-fake-lotteries-ticket-fraud/</a><br/>
Mysterious Company With Government Ties Plays Key Internet Role<br/>
 <a href="https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/">https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/</a><br/>
Extortion Scams Hit Website Owners<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-extortion-scam-threatens-to-damage-sites-reputation-leak-data/">https://www.bleepingcomputer.com/news/security/new-extortion-scam-threatens-to-damage-sites-reputation-leak-data/</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8256" type="text/plain" language="en" />
<itunes:keywords>extortion, scam, webserver, trustcor, certificate authorities, cyberchef, soccer, fifa, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8254</itunes:episode>
<itunes:subtitle>Observable vs IOC; Android Update; libxml vuln details; xterm vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Observable vs IOC; Android Update; libxml vuln details; xterm vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8254.mp3" length="6039580" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8254.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8254</link>
<pubDate>Fri, 11 Nov 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Do you collect "Observables" or "IOCs"<br/>
 <a href="https://isc.sans.edu/diary/Do%20you%20collect%20%22Observables%22%20or%20%22IOCs%22%3F/29238">https://isc.sans.edu/diary/Do%20you%20collect%20%22Observables%22%20or%20%22IOCs%22%3F/29238</a><br/>
Android Update fixes Lock Screen Bypass<br/>
 <a href="https://source.android.com/docs/security/bulletin/2022-11-01">https://source.android.com/docs/security/bulletin/2022-11-01</a><br/>
 <a href="https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/">https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/</a><br/>
libxml Vulnerability Details<br/>
 <a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/381">https://gitlab.gnome.org/GNOME/libxml2/-/issues/381</a><br/>
CVE-2022-45063: xterm remote code execution vulnerability<br/>
 <a href="https://www.openwall.com/lists/oss-security/2022/11/10/1">https://www.openwall.com/lists/oss-security/2022/11/10/1</a><br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8254" type="text/plain" language="en" />
<itunes:keywords>cve-2022-45063, xterm, rce, libxml, android, lock screen, observables, ioc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8252</itunes:episode>
<itunes:subtitle>PS Ransomware; iOS/MacOS XML Patches; Lenovo UEFI Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PS Ransomware; iOS/MacOS XML Patches; Lenovo UEFI Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8252.mp3" length="4712301" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8252.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8252</link>
<pubDate>Thu, 10 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Another Script-Based Ransomware<br/>
 <a href="https://isc.sans.edu/diary/Another%20Script-Based%20Ransomware/29234">https://isc.sans.edu/diary/Another%20Script-Based%20Ransomware/29234</a><br/>
Apple Security Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Lenovo UEFI Patch<br/>
 <a href="https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/">https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/</a><br/>
FoxIT Update<br/>
 <a href="https://www.foxit.com/support/security-bulletins.html">https://www.foxit.com/support/security-bulletins.html</a><br/>
SAP Update<br/>
 <a href="https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10">https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8252" type="text/plain" language="en" />
<itunes:keywords>ransomware, powershell, apple, ipados, ios, xml, CVE-2022-40303, CVE-2022-40304, lenovo, uefi, secure boot, CVE‑2021-3971, CVE-2021-3972, CVE-2021-3970, foxit, CVE-2022-32774, CVE-2022-38097, CVE-2022-37332, CVE-2022-40129, sap, cyber, business</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8250</itunes:episode>
<itunes:subtitle>Microsoft, VMWare and Citrix Patches and maybe Exchange Patches too?
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft, VMWare and Citrix Patches and maybe Exchange Patches too?
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8250.mp3" length="6601422" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8250.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8250</link>
<pubDate>Wed, 09 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches <br/>
 <a href="https://isc.sans.edu/diary/Microsoft%20November%202022%20Patch%20Tuesday/29230">https://isc.sans.edu/diary/Microsoft%20November%202022%20Patch%20Tuesday/29230</a><br/>
VMWare Workspace One Updates CVE-2022-31686, CVE-2022-31687, CVE-2022-31688<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0028.html">https://www.vmware.com/security/advisories/VMSA-2022-0028.html</a><br/>
Citrix Gateway / Citrix ADC Vulnerabilities CVE-2022-27510 <br/>
 <a href="https://support.citrix.com/article/CTX463706/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516">https://support.citrix.com/article/CTX463706/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516</a><br/>
Microsoft Exchange Updates<br/>
 <a href="https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/">https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045">https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045</a><br/>
]]></description>
<itunes:duration>7:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8250" type="text/plain" language="en" />
<itunes:keywords>citrix, adc, gateway, vmware, workspace, one, patches, microsoft, vulnerablities, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8248</itunes:episode>
<itunes:subtitle>IPv4 Addresses; Azure AD CBA; Twitter Scams; Facebook Info Removal; Wifi Data Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IPv4 Addresses; Azure AD CBA; Twitter Scams; Facebook Info Removal; Wifi Data Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8248.mp3" length="5394485" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8248.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8248</link>
<pubDate>Tue, 08 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[IPv4 Address Representations<br/>
 <a href="https://isc.sans.edu/diary/IPv4%20Address%20Representations/29224">https://isc.sans.edu/diary/IPv4%20Address%20Representations/29224</a><br/>
Azure AD Certificate-based Authentication (CBA) on Mobile<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/azure-ad-certificate-based-authentication-cba-on-mobile/ba-p/2365672">https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/azure-ad-certificate-based-authentication-cba-on-mobile/ba-p/2365672</a><br/>
Twitter Scams<br/>
 <a href="https://nakedsecurity.sophos.com/2022/11/04/twitter-blue-badge-email-scams-dont-fall-for-them/">https://nakedsecurity.sophos.com/2022/11/04/twitter-blue-badge-email-scams-dont-fall-for-them/</a><br/>
Facebook Personal Information Removal<br/>
 <a href="https://www.facebook.com/contacts/removal">https://www.facebook.com/contacts/removal</a><br/>
RSA Conference Finds Unencrypted Confidential Data in WiFi Traffic<br/>
 <a href="https://www.darkreading.com/remote-workforce/unencrypted-traffic-weak-e-mail-passwords-still-undermining-wifi-security">https://www.darkreading.com/remote-workforce/unencrypted-traffic-weak-e-mail-passwords-still-undermining-wifi-security</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8248" type="text/plain" language="en" />
<itunes:keywords>rsa, wifi, facebook, remove information, twitter, azure, ad, cba, certificates, yubikey, ip addresses, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8246</itunes:episode>
<itunes:subtitle>Remcos RAT and Unicode; VHD Malware; PyPi w4sp Stealer;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Remcos RAT and Unicode; VHD Malware; PyPi w4sp Stealer;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8246.mp3" length="4989412" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8246.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8246</link>
<pubDate>Mon, 07 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Remcos Downloader With Unicode Obfuscation<br/>
 <a href="https://isc.sans.edu/diary/Remcos%20Downloader%20with%20Unicode%20Obfuscation/29220">https://isc.sans.edu/diary/Remcos%20Downloader%20with%20Unicode%20Obfuscation/29220</a><br/>
Windows Malware With VHD Extension<br/>
 <a href="https://isc.sans.edu/diary/Windows%20Malware%20with%20VHD%20Extension/29222">https://isc.sans.edu/diary/Windows%20Malware%20with%20VHD%20Extension/29222</a><br/>
PyPi Packages Attempting to Deliver w4sp Stealer<br/>
 <a href="https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack">https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8246" type="text/plain" language="en" />
<itunes:keywords>pypi, w4sp stealer, vhd, malware, remcos, unicode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8244</itunes:episode>
<itunes:subtitle>Burp Breakpoints; TA589 JavaScript Injection; Hitachi, Fortinet, Nessus Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Burp Breakpoints; TA589 JavaScript Injection; Hitachi, Fortinet, Nessus Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8244.mp3" length="6151160" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8244.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8244</link>
<pubDate>Fri, 04 Nov 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Breakpoints in Burp<br/>
 <a href="https://isc.sans.edu/forums/diary/Breakpoints%20in%20Burp/29214/">https://isc.sans.edu/forums/diary/Breakpoints%20in%20Burp/29214/</a><br/>
TA569 Supply Chain Attack Injects JavaScript<br/>
 <a href="https://twitter.com/threatinsight/status/1587865920130752515">https://twitter.com/threatinsight/status/1587865920130752515</a><br/>
 <a href="https://www.darkreading.com/application-security/supply-chain-attack-pushes-out-malware-to-more-than-250-media-websites">https://www.darkreading.com/application-security/supply-chain-attack-pushes-out-malware-to-more-than-250-media-websites</a><br/>
Link to old story similar to the above JavaScript injection<br/>
 <a href="https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/">https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/</a><br/>
Hitachi Infrastructure Analytics Advisor<br/>
 <a href="https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2022-134/index.html">https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2022-134/index.html</a><br/>
FortiNet Patches<br/>
 <a href="https://fortiguard.fortinet.com/psirt?date=11-2022">https://fortiguard.fortinet.com/psirt?date=11-2022</a><br/>
Nessus Patches<br/>
 <a href="https://www.tenable.com/security/tns-2022-24">https://www.tenable.com/security/tns-2022-24</a><br/>
]]></description>
<itunes:duration>6:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8244" type="text/plain" language="en" />
<itunes:keywords>nessus, fortinet, hitachi, javascript, ta569, breakpoints, burp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8242</itunes:episode>
<itunes:subtitle>DarkVNC History; Sigstore; URLScan.io Leak; Checkmk Exploitation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DarkVNC History; Sigstore; URLScan.io Leak; Checkmk Exploitation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8242.mp3" length="5522870" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8242.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8242</link>
<pubDate>Thu, 03 Nov 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Who Put the "Dark" in DarkVNC?<br/>
 <a href="https://isc.sans.edu/forums/diary/Who+put+the+Dark+in+DarkVNC/29210">https://isc.sans.edu/forums/diary/Who+put+the+Dark+in+DarkVNC/29210</a><br/>
sigstore General Availability<br/>
 <a href="https://openssf.org/press-release/2022/10/25/sigstore-announces-general-availability-at-sigstorecon/">https://openssf.org/press-release/2022/10/25/sigstore-announces-general-availability-at-sigstorecon/</a><br/>
 <a href="https://github.blog/2022-10-25-why-were-excited-about-the-sigstore-general-availability/">https://github.blog/2022-10-25-why-were-excited-about-the-sigstore-general-availability/</a><br/>
URLScan.io's SOAR Spot: Chatty Security Tools Leaking Private Data<br/>
 <a href="https://positive.security/blog/urlscan-data-leaks">https://positive.security/blog/urlscan-data-leaks</a><br/>
Checkmk: Remote Code Execution by Chaining Multiple Bugs<br/>
 <a href="https://blog.sonarsource.com/checkmk-rce-chain-1/">https://blog.sonarsource.com/checkmk-rce-chain-1/</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8242" type="text/plain" language="en" />
<itunes:keywords>checkmk, urlscan, urlscan.io, sigstore, darkvnc, hiddenvnc, vnc, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8240</itunes:episode>
<itunes:subtitle>OpenSSL 3.0 Punycode Vulnerability Fix CVE-2022-3786, CVE-2022-3602
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenSSL 3.0 Punycode Vulnerability Fix CVE-2022-3786, CVE-2022-3602
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8240.mp3" length="7112231" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8240.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8240</link>
<pubDate>Wed, 02 Nov 2022 02:00:01 GMT</pubDate>
<description><![CDATA[OpenSSL 3.0 Punycode Vulnerability Fix<br/>
 <a href="https://isc.sans.edu/forums/diary/Critical+OpenSSL+30+Update+Released+Patches+CVE20223786+CVE20223602/29208">https://isc.sans.edu/forums/diary/Critical+OpenSSL+30+Update+Released+Patches+CVE20223786+CVE20223602/29208</a><br/>
 <a href="https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/">https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/</a><br/>
 <br/>
]]></description>
<itunes:duration>8:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8240" type="text/plain" language="en" />
<itunes:keywords>openssl, punycode, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8238</itunes:episode>
<itunes:subtitle>nmap without nmap; ConnectWise Vuln; Chrome 0-DAy; LODEINFO; Spring Insecurity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
nmap without nmap; ConnectWise Vuln; Chrome 0-DAy; LODEINFO; Spring Insecurity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8238.mp3" length="5705202" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8238.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8238</link>
<pubDate>Tue, 01 Nov 2022 02:00:02 GMT</pubDate>
<description><![CDATA[NMAP without NMAP - Port Testing and Scanning with PowerShell<br/>
 <a href="https://isc.sans.edu/diary/NMAP+without+NMAP+Port+Testing+and+Scanning+with+PowerShell/29202">https://isc.sans.edu/diary/NMAP+without+NMAP+Port+Testing+and+Scanning+with+PowerShell/29202</a><br/>
ConnectWise Recover and R1Soft Server Backup Critical Vulnerability<br/>
 <a href="https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin">https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin</a><br/>
Google Chrome 0-Day Patch<br/>
 <a href="https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html">https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html</a><br/>
LODEINFO 2022 Abusing Security Software<br/>
 <a href="https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/">https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/</a><br/>
Spring Security Vulnerability<br/>
 <a href="https://tanzu.vmware.com/security/cve-2022-31692">https://tanzu.vmware.com/security/cve-2022-31692</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8238" type="text/plain" language="en" />
<itunes:keywords>spring, java, spring security, lodeinfo, google, chrome, 0-day, connectwise, recover, r1soft, nmap, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 31st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8236</itunes:episode>
<itunes:subtitle>DUO and O365; Win IPv6 ESP Vuln Details; JunOS Exploit; Raspberry Robin
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DUO and O365; Win IPv6 ESP Vuln Details; JunOS Exploit; Raspberry Robin
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8236.mp3" length="5314547" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8236.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8236</link>
<pubDate>Mon, 31 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Supersizing you DUO and 365 Integration<br/>
 <a href="https://isc.sans.edu/forums/diary/Supersizing%20your%20DUO%20and%20365%20Integration/29194/">https://isc.sans.edu/forums/diary/Supersizing%20your%20DUO%20and%20365%20Integration/29194/</a><br/>
TCP/IP Vulnerability CVE-2022 34718 PoC Restoration and Analysis<br/>
 <a href="https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf">https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf</a><br/>
Juniper SSLVON / JunOS RCE Vulnerabilities<br/>
 <a href="https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/">https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/</a><br/>
 <br/>
Raspberry Robin Update<br/>
 <a href="https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/">https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8236" type="text/plain" language="en" />
<itunes:keywords>raspberry, robin, juniper, sslvpn, junos, rce, tcp/ip, fragments, ipv6, ipsec, duo, 2fa, mfa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8234</itunes:episode>
<itunes:subtitle>OpenSSL Versions; Apple Updates; 1Tbps Fodcha Botnet;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenSSL Versions; Apple Updates; 1Tbps Fodcha Botnet;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8234.mp3" length="5302472" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8234.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8234</link>
<pubDate>Fri, 28 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Upcoming Critical OpenSSL Vulnerability: What will be Affected?<br/>
 <a href="https://isc.sans.edu/forums/diary/Upcoming+Critical+OpenSSL+Vulnerability+What+will+be+Affected/29192">https://isc.sans.edu/forums/diary/Upcoming+Critical+OpenSSL+Vulnerability+What+will+be+Affected/29192</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Fodcha Botnet Reaches 1Tbps<br/>
 <a href="https://blog.netlab.360.com/ddosmonster_the_return_of__fodcha_cn/">https://blog.netlab.360.com/ddosmonster_the_return_of__fodcha_cn/</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/fodcha-ddos-botnet-reaches-1tbps-in-power-injects-ransoms-in-packets/">https://www.bleepingcomputer.com/news/security/fodcha-ddos-botnet-reaches-1tbps-in-power-injects-ransoms-in-packets/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8234" type="text/plain" language="en" />
<itunes:keywords>openssl, apple, fodcha, dos, extortion, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 27th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8232</itunes:episode>
<itunes:subtitle>Catfeeder Spy; OpenSSL Patch Preannouncement; Ventura Bug; VMWare Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Catfeeder Spy; OpenSSL Patch Preannouncement; Ventura Bug; VMWare Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8232.mp3" length="5517832" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8232.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8232</link>
<pubDate>Thu, 27 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Why is My Cat Using Baidu And Other IoT DNS Oddities<br/>
 <a href="https://isc.sans.edu/forums/diary/Why+is+My+Cat+Using+Baidu+And+Other+IoT+DNS+Oddities/29188">https://isc.sans.edu/forums/diary/Why+is+My+Cat+Using+Baidu+And+Other+IoT+DNS+Oddities/29188</a><br/>
OpenSSL Critical Flaw to Be Patched <br/>
 <a href="https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html">https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html</a><br/>
MacOS Ventura Blocks Security Tools<br/>
 <a href="https://www.wired.com/story/apple-macos-ventura-bug-security-tools/">https://www.wired.com/story/apple-macos-ventura-bug-security-tools/</a><br/>
Critical VMWare Security Tools<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0027.html">https://www.vmware.com/security/advisories/VMSA-2022-0027.html</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8232" type="text/plain" language="en" />
<itunes:keywords>vmware, macos, ventura, tcc, openssl, biadu, cat feeder, iot, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 26th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8230</itunes:episode>
<itunes:subtitle>GitHub Cryptomining; Healthcare Ransomware; Cisco Anyconnect Exploit; sqlite PoC Exploit;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GitHub Cryptomining; Healthcare Ransomware; Cisco Anyconnect Exploit; sqlite PoC Exploit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8230.mp3" length="5249282" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8230.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8230</link>
<pubDate>Wed, 26 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Massing Cryptomining Operation via Github Actions<br/>
 <a href="https://sysdig.com/blog/massive-cryptomining-operation-github-actions/">https://sysdig.com/blog/massive-cryptomining-operation-github-actions/</a><br/>
Daixin Team Ransomware Targeting Healthcare Providers<br/>
 <a href="https://www.ic3.gov/Media/News/2022/221021.pdf">https://www.ic3.gov/Media/News/2022/221021.pdf</a><br/>
Cisco Anyconnect Client Exploited in the Wild<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW</a><br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj</a><br/>
SQLite Vulnerability Details<br/>
 <a href="https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/">https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8230" type="text/plain" language="en" />
<itunes:keywords>sqlite, cisco, anyconnect, daixin team, healthcare, cryptomining, githbu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8228</itunes:episode>
<itunes:subtitle>Outlook.com C2; Apple Patches; Cisco Vuln; Dormant Colors
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Outlook.com C2; Apple Patches; Cisco Vuln; Dormant Colors
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8228.mp3" length="5626221" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8228.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8228</link>
<pubDate>Tue, 25 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[C2 Communications Through Outlook.com<br/>
 <a href="https://isc.sans.edu/forums/diary/C2+Communications+Through+outlookcom/29180">https://isc.sans.edu/forums/diary/C2+Communications+Through+outlookcom/29180</a><br/>
Apple Patches Everything October 2022 Edition<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything%3A%20October%202022%20Edition/29182/">https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything%3A%20October%202022%20Edition/29182/</a><br/>
Cisco ISE Patch<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM</a><br/>
Dormant Colors Live Campaign With Over 1m Data Stealing Extensions Installed<br/>
 <a href="https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849">https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8228" type="text/plain" language="en" />
<itunes:keywords>dormant colors, chrome, browser extensions, cisco, ise, apple, patches, 0-day, c2, outlook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 24th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8226</itunes:episode>
<itunes:subtitle>Sczriptzzb and Netsupport; rtfdump; Windows MotW Bypass; Fake GitHub Exploits; F5 and Synology Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sczriptzzb and Netsupport; rtfdump; Windows MotW Bypass; Fake GitHub Exploits; F5 and Synology Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8226.mp3" length="6008176" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8226.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8226</link>
<pubDate>Mon, 24 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Sczriptzzbn Inject Pushes Malware for NetSupport RAT<br/>
 <a href="https://isc.sans.edu/forums/diary/sczriptzzbn%20inject%20pushes%20malware%20for%20NetSupport%20RAT/29170/">https://isc.sans.edu/forums/diary/sczriptzzbn%20inject%20pushes%20malware%20for%20NetSupport%20RAT/29170/</a><br/>
rtfdump find options<br/>
 <a href="https://isc.sans.edu/forums/diary/rtfdumps+Find+Option/29174">https://isc.sans.edu/forums/diary/rtfdumps+Find+Option/29174</a><br/>
Exploited Windows Zero Day Lets JavaScript Files Bypass Security Warnings<br/>
 <a href="https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/">https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/</a><br/>
A study of malicious CVE proof of concept exploits in GitHub<br/>
 <a href="https://arxiv.org/pdf/2210.08374.pdf">https://arxiv.org/pdf/2210.08374.pdf</a><br/>
F5 Patches<br/>
 <a href="https://support.f5.com/csp/article/K11830089">https://support.f5.com/csp/article/K11830089</a><br/>
 <a href="https://support.f5.com/csp/article/K30425568">https://support.f5.com/csp/article/K30425568</a><br/>
Synology Updates<br/>
 <a href="https://www.synology.com/en-global/security/advisory/Synology_SA_22_17">https://www.synology.com/en-global/security/advisory/Synology_SA_22_17</a><br/>
]]></description>
<itunes:duration>6:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8226" type="text/plain" language="en" />
<itunes:keywords>github, f5, nginx, synology, windows, javascript, motw, signature, authenticode, rtfdump, sczriptzzbn, netsupport, rat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8224</itunes:episode>
<itunes:subtitle>Value of Prefetch; Win 10 TLS Fix; ScubaGear released; HTTP/3 Contamination;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Value of Prefetch; Win 10 TLS Fix; ScubaGear released; HTTP/3 Contamination;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8224.mp3" length="5268229" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8224.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8224</link>
<pubDate>Fri, 21 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Forensic Value of Prefetch<br/>
 <a href="https://isc.sans.edu/forums/diary/Forensic%20Value%20of%20Prefetch/29168/">https://isc.sans.edu/forums/diary/Forensic%20Value%20of%20Prefetch/29168/</a><br/>
Microsoft TLS Fix<br/>
 <a href="https://support.microsoft.com/en-us/topic/october-17-2022-kb5020435-os-builds-19042-2132-19043-2132-and-19044-2132-out-of-band-243f34de-2f44-4015-a224-1b68a4132ca5">https://support.microsoft.com/en-us/topic/october-17-2022-kb5020435-os-builds-19042-2132-19043-2132-and-19044-2132-out-of-band-243f34de-2f44-4015-a224-1b68a4132ca5</a><br/>
CISA Releases ScubaGear to Audit M365<br/>
 <a href="https://github.com/cisagov/ScubaGear">https://github.com/cisagov/ScubaGear</a><br/>
HTTP/3 Connection Contamination<br/>
 <a href="https://portswigger.net/research/http-3-connection-contamination">https://portswigger.net/research/http-3-connection-contamination</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8224" type="text/plain" language="en" />
<itunes:keywords>http/3, connection contaminiation, proxy, cdn, load balancers, cisa, m365, scuba, tls, microsoft, prefetch, forensics, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8222</itunes:episode>
<itunes:subtitle>Internet Wide Scanning; studentaid scams; undetectable command and control
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Internet Wide Scanning; studentaid scams; undetectable command and control
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8222.mp3" length="5434944" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8222.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8222</link>
<pubDate>Thu, 20 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Are Internet Scanning Services Good or Bad for You?<br/>
 <a href="https://isc.sans.edu/forums/diary/Are+Internet+Scanning+Services+Good+or+Bad+for+You/29164">https://isc.sans.edu/forums/diary/Are+Internet+Scanning+Services+Good+or+Bad+for+You/29164</a><br/>
FBI Warns of Student Loan Foregiveness Scams<br/>
 <a href="https://www.ic3.gov/Media/Y2022/PSA221018">https://www.ic3.gov/Media/Y2022/PSA221018</a><br/>
Fully Undetectable Powershell Backdoor<br/>
 <a href="https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/">https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8222" type="text/plain" language="en" />
<itunes:keywords>backdoor, powershell, undetectable, fbi, student loan, studentaid.gov, scanning, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8220</itunes:episode>
<itunes:subtitle>Obfuscating Python; Oracle CPU; Office 365 Encryption;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscating Python; Oracle CPU; Office 365 Encryption;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8220.mp3" length="4883889" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8220.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8220</link>
<pubDate>Wed, 19 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Python Obfuscation for Dummies<br/>
 <a href="https://isc.sans.edu/forums/diary/Python%20Obfuscation%20for%20Dummies/29160/">https://isc.sans.edu/forums/diary/Python%20Obfuscation%20for%20Dummies/29160/</a><br/>
Oracle October 2022 Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpuoct2022.html">https://www.oracle.com/security-alerts/cpuoct2022.html</a><br/>
Weak Encryption in Microsoft Office 365<br/>
 <a href="https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation">https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation</a><br/>
Tesla 3 Hack<br/>
 <a href="https://www.synacktiv.com/sites/default/files/2022-10/tesla_hexacon.pdf">https://www.synacktiv.com/sites/default/files/2022-10/tesla_hexacon.pdf</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8220" type="text/plain" language="en" />
<itunes:keywords>tesla, encryption, microsoft office, oracle, cpu, python, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8218</itunes:episode>
<itunes:subtitle>Fileless Dropper; Apache Commons Text Vuln; MSFT Driver Blocklist NOOP;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fileless Dropper; Apache Commons Text Vuln; MSFT Driver Blocklist NOOP;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8218.mp3" length="5687681" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8218.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8218</link>
<pubDate>Tue, 18 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Fileless Powershell Dropper<br/>
 <a href="https://isc.sans.edu/forums/diary/Fileless%20Powershell%20Dropper/29156/">https://isc.sans.edu/forums/diary/Fileless%20Powershell%20Dropper/29156/</a><br/>
Apache Commons Text Vulnerablity<br/>
 <a href="https://www.openwall.com/lists/oss-security/2022/10/13/4">https://www.openwall.com/lists/oss-security/2022/10/13/4</a><br/>
How a Microsoft Blunder Opened Millions of PCs to Potent Malware Attacks<br/>
 <a href="https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/">https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8218" type="text/plain" language="en" />
<itunes:keywords>fileless, dropper, powershell, apache, commons, text, msft, microsoft, driver, blocklist, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8216</itunes:episode>
<itunes:subtitle>FortiOS Exploit; Exchange Workaround Bypass;  QBot in HTML; Malware in PDF; VMWare End of Life
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
FortiOS Exploit; Exchange Workaround Bypass;  QBot in HTML; Malware in PDF; VMWare End of Life
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8216.mp3" length="5316377" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8216.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8216</link>
<pubDate>Mon, 17 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Horizon3 Publishes FortiOS Vulnerablity Details and Exploit<br/>
 <a href="https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/">https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/</a><br/>
More Exchange Vulnerability Workaround Bypasses<br/>
 <a href="https://twitter.com/wdormann/status/1576922677675102208">https://twitter.com/wdormann/status/1576922677675102208</a><br/>
Analysis of a Malicious HTML File and QBot<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+Malicious+HTML+File+QBot/29146">https://isc.sans.edu/forums/diary/Analysis+of+a+Malicious+HTML+File+QBot/29146</a><br/>
End of Life VMWare ESXi Versions<br/>
 <a href="https://www.lansweeper.com/eol/vmware-esxi-end-of-life/">https://www.lansweeper.com/eol/vmware-esxi-end-of-life/</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8216" type="text/plain" language="en" />
<itunes:keywords>vmware, esxi, end of life, eol, html, qbot, covid, pdf, exchange, workaround, bypass, fortios, fortiproxy, horizon3, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8214</itunes:episode>
<itunes:subtitle>Alchimist/Insekt C&amp;C; vm2 vuln; npm package disclosure; Zimbra Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Alchimist/Insekt C&amp;C; vm2 vuln; npm package disclosure; Zimbra Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8214.mp3" length="5296246" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8214.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8214</link>
<pubDate>Fri, 14 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Alchimist Offensive Framework<br/>
<a href="https://blog.talosintelligence.com/2022/10/alchimist-offensive-framework.html#more">https://blog.talosintelligence.com/2022/10/alchimist-offensive-framework.html#more</a><br/>
VM2 Sandbox Vulnerability<br/>
<a href="https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067">https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067</a><br/>
private npm package disclosure<br/>
 <a href="https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm">https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm</a><br/>
Zimbra Updates<br/>
 <a href="https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P27#Security_Fixes">https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P27#Security_Fixes</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8214" type="text/plain" language="en" />
<itunes:keywords>zimbra, npm, packages, vm2, sandbox, alchimist, insekt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8212</itunes:episode>
<itunes:subtitle>Adobe Patches; Fortinet Details and New Patches; iOS and Android VPN Issues; Aruba Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe Patches; Fortinet Details and New Patches; iOS and Android VPN Issues; Aruba Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8212.mp3" length="4546678" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8212.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8212</link>
<pubDate>Thu, 13 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Adobe October Patch Tuesday<br/>
 <a href="https://helpx.adobe.com/sa_en/security/security-bulletin.html">https://helpx.adobe.com/sa_en/security/security-bulletin.html</a><br/>
Fortinet Guidance<br/>
 <a href="https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/">https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Scans+for+old+Fortigate+Vulnerability+Building+Target+Lists/29142">https://isc.sans.edu/forums/diary/Scans+for+old+Fortigate+Vulnerability+Building+Target+Lists/29142</a><br/>
Android VPN Issues<br/>
 <a href="https://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/">https://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/</a><br/>
iOS VPN Issues<br/>
 <a href="https://9to5mac.com/2022/10/12/ios-vpn-apps-2/">https://9to5mac.com/2022/10/12/ios-vpn-apps-2/</a><br/>
Aruba Patches<br/>
 <a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-015.txt">https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-015.txt</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8212" type="text/plain" language="en" />
<itunes:keywords>aruba, ios, vpn, android, fortinet, adobe, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8210</itunes:episode>
<itunes:subtitle>Microsoft October 2022 Patches; SAP Patch Day; CISA Chinese State Sponsored Vuln List
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft October 2022 Patches; SAP Patch Day; CISA Chinese State Sponsored Vuln List
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8210.mp3" length="5299346" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8210.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8210</link>
<pubDate>Wed, 12 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft October 2022 Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/October%202022%20Microsoft%20Patch%20Tuesday/29138/">https://isc.sans.edu/forums/diary/October%202022%20Microsoft%20Patch%20Tuesday/29138/</a><br/>
SAP Patchday<br/>
 <a href="https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10">https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10</a><br/>
Top CVEs Actively Exploited By People s Republic of China State-Sponsored Cyber Actors<br/>
 <a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-279a">https://www.cisa.gov/uscert/ncas/alerts/aa22-279a</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8210" type="text/plain" language="en" />
<itunes:keywords>cisa, cves, china, sap, october, microsoft, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8208</itunes:episode>
<itunes:subtitle>Wireshark Update; Fortinet Vulnerability; BazarCall; RPKI Rate Limiting
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wireshark Update; Fortinet Vulnerability; BazarCall; RPKI Rate Limiting
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8208.mp3" length="5557165" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8208.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8208</link>
<pubDate>Tue, 11 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Wireshark Display Filter Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Wireshark+Specifying+a+Protocol+Stack+Layer+in+Display+Filters/29130">https://isc.sans.edu/forums/diary/Wireshark+Specifying+a+Protocol+Stack+Layer+in+Display+Filters/29130</a><br/>
Fortinet Vulnerablity Update<br/>
 <a href="https://twitter.com/Horizon3Attack/status/1579285863108087810">https://twitter.com/Horizon3Attack/status/1579285863108087810</a><br/>
BazarCall Social Engineering Tactics<br/>
 <a href="https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html">https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html</a><br/>
RPKI Rate Limiting<br/>
 <a href="https://www.usenix.org/system/files/sec22-hlavacek.pdf">https://www.usenix.org/system/files/sec22-hlavacek.pdf</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8208" type="text/plain" language="en" />
<itunes:keywords>rpki, bazarcall, fortniet, wireshark, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8206</itunes:episode>
<itunes:subtitle>Fortinet Update; Zimbra (cpio) vuln; Exchange Workaround Update; Ikea Smart Buld Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fortinet Update; Zimbra (cpio) vuln; Exchange Workaround Update; Ikea Smart Buld Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8206.mp3" length="5658524" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8206.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8206</link>
<pubDate>Mon, 10 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Fortinet Update<br/>
 <a href="https://docs.fortinet.com/document/fortigate/7.2.2/fortios-release-notes/760203/introduction-and-supported-models">https://docs.fortinet.com/document/fortigate/7.2.2/fortios-release-notes/760203/introduction-and-supported-models</a><br/>
Zimbra Vulnerability<br/>
 <a href="https://twitter.com/iagox86/status/1578084484720734209">https://twitter.com/iagox86/status/1578084484720734209</a><br/>
 <a href="https://attackerkb.com/topics/1DDTvUNFzH/cve-2022-41352/rapid7-analysis?referrer=activityFeed">https://attackerkb.com/topics/1DDTvUNFzH/cve-2022-41352/rapid7-analysis?referrer=activityFeed</a><br/>
Microsoft Exchange Workaround Improved Again<br/>
 <a href="https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/">https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/</a><br/>
Ikea Smart Bulb Exploit<br/>
 <a href="https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/">https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8206" type="text/plain" language="en" />
<itunes:keywords>fortinet, zimbra, cpio, pax, amavisd, exchange, ikea, smart bulb, zigbee, zwave, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8204</itunes:episode>
<itunes:subtitle>Infosec Calendar; OnionPoison; MacOS Archives and MOTW
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Infosec Calendar; OnionPoison; MacOS Archives and MOTW
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8204.mp3" length="5276442" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8204.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8204</link>
<pubDate>Fri, 07 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Infosec Calendar<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+in+your+Infosec+Calendar/29118">https://isc.sans.edu/forums/diary/What+is+in+your+Infosec+Calendar/29118</a><br/>
OnionPoison: infected Tor Browser installer distributed through popular YouTube channel<br/>
 <a href="https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/">https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/</a><br/>
MacOS Architve Utility Vulnerability Details<br/>
 <a href="https://www.jamf.com/blog/jamf-threat-labs-macos-archive-utility-vulnerability/">https://www.jamf.com/blog/jamf-threat-labs-macos-archive-utility-vulnerability/</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8204" type="text/plain" language="en" />
<itunes:keywords>ncsam, infosec, calendar, motw, macos, onionpoison, tor, browser, china, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 5th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8202</itunes:episode>
<itunes:subtitle>Phishing via Telegram; Updated MSFT Exchange fix; PHP Packagist Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing via Telegram; Updated MSFT Exchange fix; PHP Packagist Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8202.mp3" length="4806925" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8202.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8202</link>
<pubDate>Wed, 05 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Credential Harvesting with Telegram<br/>
 <a href="https://isc.sans.edu/forums/diary/Credential%20Harvesting%20with%20Telegram%20API/29112/">https://isc.sans.edu/forums/diary/Credential%20Harvesting%20with%20Telegram%20API/29112/</a><br/>
Updated Microsoft Exchange Fix<br/>
 <a href="https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/">https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/</a><br/>
Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization<br/>
 <a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-277a">https://www.cisa.gov/uscert/ncas/alerts/aa22-277a</a><br/>
A New Supply Chain Attack on PHP<br/>
 <a href="https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/">https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8202" type="text/plain" language="en" />
<itunes:keywords>supply chain, packagist, php, microsoft, exchange, telegram, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8200</itunes:episode>
<itunes:subtitle>Exchange Fix Bypass; Schneider UMAS Patch Bypass; Comm100 Compromise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exchange Fix Bypass; Schneider UMAS Patch Bypass; Comm100 Compromise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8200.mp3" length="4518392" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8200.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8200</link>
<pubDate>Tue, 04 Oct 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Exchange Vulnerability Fix Bypassed<br/>
 <a href="https://twitter.com/testanull/status/1576774007826718720">https://twitter.com/testanull/status/1576774007826718720</a><br/>
Schneider Electric UMAS Patch Bypass<br/>
 <a href="https://securelist.com/the-secrets-of-schneider-electrics-umas-protocol/107435/">https://securelist.com/the-secrets-of-schneider-electrics-umas-protocol/107435/</a><br/>
Supply Chain Attack via Trojanized Comm100 Chat Installer<br/>
 <a href="https://www.crowdstrike.com/blog/new-supply-chain-attack-leverages-comm100-chat-installer/">https://www.crowdstrike.com/blog/new-supply-chain-attack-leverages-comm100-chat-installer/</a><br/>
]]></description>
<itunes:duration>5:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8200" type="text/plain" language="en" />
<itunes:keywords>comm100, supply chain, trojan, chat, installer, microsoft, exchange, schneider, umas, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8198</itunes:episode>
<itunes:subtitle>Exchange 0-Day Update; Bitbucket Exploited; Apple TCC Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exchange 0-Day Update; Bitbucket Exploited; Apple TCC Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8198.mp3" length="4756426" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8198.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8198</link>
<pubDate>Mon, 03 Oct 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Exchange 0-Day Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Exchange+Server+0Day+Actively+Exploited/29106">https://isc.sans.edu/forums/diary/Exchange+Server+0Day+Actively+Exploited/29106</a><br/>
 <a href="https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/">https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/</a><br/>
CISA Adds Atlasian Bitbucket Vulnerability to Exploited List<br/>
 <a href="https://www.cisa.gov/uscert/ncas/current-activity/2022/09/30/cisa-adds-three-known-exploited-vulnerabilities-catalog">https://www.cisa.gov/uscert/ncas/current-activity/2022/09/30/cisa-adds-three-known-exploited-vulnerabilities-catalog</a><br/>
Every unsandboxed app has Full Disk Access if Terminal Does<br/>
 <a href="https://lapcatsoftware.com/articles/FullDiskAccess.html">https://lapcatsoftware.com/articles/FullDiskAccess.html</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8198" type="text/plain" language="en" />
<itunes:keywords>sandbox, tcc, macos, terminal, cisa, atlasian, bitbucket, exchange, 0-day, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 30th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8196</itunes:episode>
<itunes:subtitle>PNG Analysis; Possible Exchange 0-Day; New VMWAre ESXi Persistence
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PNG Analysis; Possible Exchange 0-Day; New VMWAre ESXi Persistence
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8196.mp3" length="5386358" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8196.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8196</link>
<pubDate>Fri, 30 Sep 2022 02:00:01 GMT</pubDate>
<description><![CDATA[PNG Analysis with pngdump.py<br/>
 <a href="https://isc.sans.edu/forums/diary/PNG%20Analysis/29100/">https://isc.sans.edu/forums/diary/PNG%20Analysis/29100/</a><br/>
Possible Exchange Server 0-Day Vulnerability<br/>
 <a href="https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html">https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html</a><br/>
 <a href="https://success.trendmicro.com/dcx/s/solution/000291651?language=en_US">https://success.trendmicro.com/dcx/s/solution/000291651?language=en_US</a><br/>
Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors<br/>
 <a href="https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence">https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8196" type="text/plain" language="en" />
<itunes:keywords>VIB, vmware, vsphere, exchange server, 0-day, proxy logon, proxy shell, png, pngdump, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 29th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8194</itunes:episode>
<itunes:subtitle>Old Flaw to Access VoIP Creds; IRS SMS Scam; Turnstile vs CAPTCHA; Cisco, Arista, Juniper and Chrome Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Old Flaw to Access VoIP Creds; IRS SMS Scam; Turnstile vs CAPTCHA; Cisco, Arista, Juniper and Chrome Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8194.mp3" length="5833100" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8194.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8194</link>
<pubDate>Thu, 29 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[10 Years Later: Attacker re-discovering old VTiger CRM Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/10+Years+Later+Attacker+rediscovering+old+VTiger+CRM+Vulnerability/29098">https://isc.sans.edu/forums/diary/10+Years+Later+Attacker+rediscovering+old+VTiger+CRM+Vulnerability/29098</a><br/>
IRS Reports Significant Increase in Texting Scams<br/>
 <a href="https://www.irs.gov/newsroom/irs-reports-significant-increase-in-texting-scams-warns-taxpayers-to-remain-vigilant">https://www.irs.gov/newsroom/irs-reports-significant-increase-in-texting-scams-warns-taxpayers-to-remain-vigilant</a><br/>
Cloudflare Releases Turnsitle, a user-friendly, privacy-preserving CAPTCHA alternative<br/>
 <a href="https://blog.cloudflare.com/turnstile-private-captcha-alternative/">https://blog.cloudflare.com/turnstile-private-captcha-alternative/</a><br/>
Cisco Patches<br/>
 <a href="https://kb.cert.org/vuls/id/855201">https://kb.cert.org/vuls/id/855201</a><br/>
Chrome 106 Release<br/>
 <a href="https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html?m=1">https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html?m=1</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8194" type="text/plain" language="en" />
<itunes:keywords>chrome, cisco, arista, juniper, vlan, cloudflare, turnstile, captcha, irs, texting, smishing, vtiger, crm, asterisk, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8192</itunes:episode>
<itunes:subtitle>DNS Option 15; YARI for YARA; HTTP Archive Almanac
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Option 15; YARI for YARA; HTTP Archive Almanac
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8192.mp3" length="6278111" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8192.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8192</link>
<pubDate>Wed, 28 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[DNS Option 15 and Debugging DNSSEC Errors<br/>
 <a href="https://isc.sans.edu/forums/diary/DNS+Option+15+Debugging+DNSSEC+Errors/29094">https://isc.sans.edu/forums/diary/DNS+Option+15+Debugging+DNSSEC+Errors/29094</a><br/>
Yari: A New Era of Yara Debugging<br/>
 <a href="https://engineering.avast.io/yari-a-new-era-of-yara-debugging/">https://engineering.avast.io/yari-a-new-era-of-yara-debugging/</a><br/>
HTTP Archive Almanac<br/>
 <a href="https://almanac.httparchive.org/en/2022/security">https://almanac.httparchive.org/en/2022/security</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8192" type="text/plain" language="en" />
<itunes:keywords>almanac, http archive, https, hsts, dns, option 15, dnssec, yari, yara, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 27th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8190</itunes:episode>
<itunes:subtitle>Python vs Sandboxes; Mouseover Malware; Redis RCE Flaw; Scoreboard Hacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python vs Sandboxes; Mouseover Malware; Redis RCE Flaw; Scoreboard Hacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8190.mp3" length="5289252" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8190.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8190</link>
<pubDate>Tue, 27 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Easy Python Sandbox Detection<br/>
 <a href="https://isc.sans.edu/forums/diary/Easy+Python+Sandbox+Detection/29090">https://isc.sans.edu/forums/diary/Easy+Python+Sandbox+Detection/29090</a><br/>
Hackers use PowerPoint Files for "Mouseover" Malware Delivery<br/>
 <a href="https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/">https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/</a><br/>
Redis 7.0 XAUTOCLAIM Heap Overflow<br/>
 <a href="https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9">https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9</a><br/>
Scoreboard Hacking<br/>
 <a href="https://maxwelldulin.com/BlogPost?post=7118102528">https://maxwelldulin.com/BlogPost?post=7118102528</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8190" type="text/plain" language="en" />
<itunes:keywords>scoreboard, redis, xautoclaim, overflow, rce, powerpoint, mouseover, python, sandbox, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 26th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8188</itunes:episode>
<itunes:subtitle>MSFT Teams Token Stealer; Downloading Malware; WhatsApp Patch; Sophos RCE Flaw; CircleCI Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Teams Token Stealer; Downloading Malware; WhatsApp Patch; Sophos RCE Flaw; CircleCI Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8188.mp3" length="5146990" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8188.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8188</link>
<pubDate>Mon, 26 Sep 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Kids Like Cookies and Malware Likes them Too<br/>
 <a href="https://isc.sans.edu/forums/diary/Kids+Like+Cookies+Malware+Too/29082">https://isc.sans.edu/forums/diary/Kids+Like+Cookies+Malware+Too/29082</a><br/>
Downloading Files from Removed Domains<br/>
 <a href="https://isc.sans.edu/forums/diary/Downloading%20Samples%20From%20Takendown%20Domains/29086/">https://isc.sans.edu/forums/diary/Downloading%20Samples%20From%20Takendown%20Domains/29086/</a><br/>
WhatsApp Security Updates<br/>
 <a href="https://www.whatsapp.com/security/advisories/2022/">https://www.whatsapp.com/security/advisories/2022/</a><br/>
Sophos RCE Flaw<br/>
 <a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce</a><br/>
CircleCI Phishing Attacks Used to Access GitHub Accounts<br/>
 <a href="https://discuss.circleci.com/t/circleci-security-alert-warning-phishing-attempt-for-login-credentials/45408">https://discuss.circleci.com/t/circleci-security-alert-warning-phishing-attempt-for-login-credentials/45408</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8188" type="text/plain" language="en" />
<itunes:keywords>circleci, github, phishing, sophos, rce, whatsapp, domains, takedown, malware, cookies, malware, teams, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 23rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8186</itunes:episode>
<itunes:subtitle>FODHelper Delivers RAT; MSFT Endpoing Conf Manager Updates; Fuzzing Tool; Apple Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
FODHelper Delivers RAT; MSFT Endpoing Conf Manager Updates; Fuzzing Tool; Apple Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8186.mp3" length="4800554" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8186.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8186</link>
<pubDate>Fri, 23 Sep 2022 02:00:01 GMT</pubDate>
<description><![CDATA[RAT Delivered Through FODHelper<br/>
 <a href="https://isc.sans.edu/forums/diary/RAT+Delivered+Through+FODHelper/29078">https://isc.sans.edu/forums/diary/RAT+Delivered+Through+FODHelper/29078</a><br/>
Microsoft Endpoint Configuration Manager Spoofing Vulnerability<br/>
 <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37972">https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37972</a><br/>
New Fuzzing Tool: cifuzz<br/>
 <a href="https://github.com/CodeIntelligenceTesting/cifuzz">https://github.com/CodeIntelligenceTesting/cifuzz</a><br/>
No Security Updates from Apple<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8186" type="text/plain" language="en" />
<itunes:keywords>apple, ios, watchos, fuzzing, cifuzz, microsoft, endpoint configuration manager, fodhelper, rat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8184</itunes:episode>
<itunes:subtitle>Free Phishing; Insecure tarfile.extract; Twitter Logout
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Free Phishing; Insecure tarfile.extract; Twitter Logout
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8184.mp3" length="6024601" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8184.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8184</link>
<pubDate>Thu, 22 Sep 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Phishing Campaigns Use Free Only Resources<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing%20Campaigns%20Use%20Free%20Online%20Resources/29074/">https://isc.sans.edu/forums/diary/Phishing%20Campaigns%20Use%20Free%20Online%20Resources/29074/</a><br/>
Insecure use of tarfile.extract in Python<br/>
 <a href="https://bugs.python.org/issue1044#msg55464">https://bugs.python.org/issue1044#msg55464</a><br/>
Twitter Failed to Logout Users After Password Reset<br/>
 <a href="https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password-resets">https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password-resets</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8184" type="text/plain" language="en" />
<itunes:keywords>twitter, token, oauth, logout, password, tarfile, extract, python, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8182</itunes:episode>
<itunes:subtitle>Chainsaw Hunt; Exploit Cloud PDUs; Default Tamper Protection;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chainsaw Hunt; Exploit Cloud PDUs; Default Tamper Protection;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8182.mp3" length="5738405" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8182.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8182</link>
<pubDate>Wed, 21 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Chainsaw: Hunt, search and extract event log records<br/>
 <a href="https://isc.sans.edu/diary/Chainsaw%3A+Hunt%2C+search%2C+and+extract+event+log+records/29066">https://isc.sans.edu/diary/Chainsaw%3A+Hunt%2C+search%2C+and+extract+event+log+records/29066</a><br/>
PDU Exploits past NAT<br/>
 <a href="https://claroty.com/team82/research/jumping-nat-to-shut-down-electric-devices">https://claroty.com/team82/research/jumping-nat-to-shut-down-electric-devices</a><br/>
Tamper Protection will be turned on for all Enterprise Customers<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478">https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8182" type="text/plain" language="en" />
<itunes:keywords>pdu, nat, cloud, tamper protection, enterprise, microsoft, defender, chainsaw, hunt, triage, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8180</itunes:episode>
<itunes:subtitle>Preventing ISO Malware; Emotet Update/History; MSFT Teams Tokens
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Preventing ISO Malware; Emotet Update/History; MSFT Teams Tokens
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8180.mp3" length="5744050" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8180.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8180</link>
<pubDate>Tue, 20 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[<br/>
Preventing ISO Malware<br/>
 <a href="https://isc.sans.edu/diary/Preventing+ISO+Malware+/29062">https://isc.sans.edu/diary/Preventing+ISO+Malware+/29062</a><br/>
State of Emotet<br/>
 <a href="https://www.advintel.io/post/advintel-s-state-of-emotet-aka-spmtools-displays-over-million-compromised-machines-through-2022">https://www.advintel.io/post/advintel-s-state-of-emotet-aka-spmtools-displays-over-million-compromised-machines-through-2022</a><br/>
Undermining Microsoft Teams Security by Mining Tokens<br/>
 <a href="https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens">https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8180" type="text/plain" language="en" />
<itunes:keywords>teams, tokens, microsoft, emotet, iso, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8178</itunes:episode>
<itunes:subtitle>CustomXML Word Doc; 2FA on Locked Phones; Spellcheck Password Leak; Reflected Content
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CustomXML Word Doc; 2FA on Locked Phones; Spellcheck Password Leak; Reflected Content
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8178.mp3" length="5297232" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8178.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8178</link>
<pubDate>Mon, 19 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Word Maldoc With CustomXML and Renamed VBAProject.bin<br/>
 <a href="https://isc.sans.edu/diary/Word+Maldoc+With+CustomXML+and+Renamed+VBAProject.bin/29056">https://isc.sans.edu/diary/Word+Maldoc+With+CustomXML+and+Renamed+VBAProject.bin/29056</a><br/>
2FA on Lock Screens<br/>
 <a href="https://www.bbc.com/news/uk-england-london-62809151">https://www.bbc.com/news/uk-england-london-62809151</a><br/>
Chrome and Edge Enhances Spellcheck Features Expose PII, Even Your Password<br/>
 <a href="https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords">https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords</a><br/>
Reconstructing Content Reflected in Glasses<br/>
 <a href="https://arxiv.org/abs/2205.03971">https://arxiv.org/abs/2205.03971</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8178" type="text/plain" language="en" />
<itunes:keywords>glasses, zoom, videoconference, chrome, edge, pii, spell check, 2fa, lock screen, word, maldoc, customxml, vba, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8176</itunes:episode>
<itunes:subtitle>Frameset Word Doc; Windows IKE PoC; Trojaned Putty; EZVIZ Cam Vuln; Lenovo BIOS updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Frameset Word Doc; Windows IKE PoC; Trojaned Putty; EZVIZ Cam Vuln; Lenovo BIOS updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8176.mp3" length="5959033" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8176.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8176</link>
<pubDate>Fri, 16 Sep 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Malicous Word Document With a Frameset<br/>
 <a href="https://isc.sans.edu/diary/Malicious+Word+Document+with+a+Frameset/29052">https://isc.sans.edu/diary/Malicious+Word+Document+with+a+Frameset/29052</a><br/>
CVE-2022-34721 Exploit<br/>
 <a href="https://github.com/78ResearchLab/PoC/tree/main/CVE-2022-34721">https://github.com/78ResearchLab/PoC/tree/main/CVE-2022-34721</a><br/>
Trojaned Putty Used in Attacks<br/>
 <a href="https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing">https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing</a><br/>
Lenovo BIOS Updates<br/>
 <a href="https://support.lenovo.com/us/en/product_security/LEN-94953#Desktop">https://support.lenovo.com/us/en/product_security/LEN-94953#Desktop</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8176" type="text/plain" language="en" />
<itunes:keywords>lenovo, putty, mandiant, korea, cve-2022-34721, ipv6, ike, word, frameset, iframe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8174</itunes:episode>
<itunes:subtitle>Python Process Injection; Queen Elizabeth Phishing;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Process Injection; Queen Elizabeth Phishing;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8174.mp3" length="4987238" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8174.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8174</link>
<pubDate>Thu, 15 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Easy Process Injection within Python<br/>
 <a href="https://isc.sans.edu/diary/Easy+Process+Injection+within+Python/29048">https://isc.sans.edu/diary/Easy+Process+Injection+within+Python/29048</a><br/>
Queen Elizabeth Related Phishing<br/>
 <a href="https://twitter.com/threatinsight/status/1570092339984584705">https://twitter.com/threatinsight/status/1570092339984584705</a><br/>
Microsoft 365 Auto Updates Apps on Locked or Idle Devices<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-under-lock-improved-update-experience-for-microsoft-365/ba-p/3618901">https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-under-lock-improved-update-experience-for-microsoft-365/ba-p/3618901</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8174" type="text/plain" language="en" />
<itunes:keywords>phishing, queen, elizabeth, process injection, hollowing, python, idle, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8172</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; Magento Extension Hack;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; Magento Extension Hack;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8172.mp3" length="5670020" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8172.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8172</link>
<pubDate>Wed, 14 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+September+2022+Patch+Tuesday/29044/">https://isc.sans.edu/forums/diary/Microsoft+September+2022+Patch+Tuesday/29044/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Magento Vendor Fishpig Hacked, Backdoors Added<br/>
 <a href="https://sansec.io/research/rekoobe-fishpig-magento">https://sansec.io/research/rekoobe-fishpig-magento</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8172" type="text/plain" language="en" />
<itunes:keywords>microsoft, patch tuesday, patches, ipv6, ipsec, ike, adobe, patches, magento, fishpig, backdoor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8170</itunes:episode>
<itunes:subtitle>Honeypot vs VirusTotal; Apple Patches; Ransomware Enters via MiVoice Voip Device
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot vs VirusTotal; Apple Patches; Ransomware Enters via MiVoice Voip Device
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8170.mp3" length="6762962" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8170.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8170</link>
<pubDate>Tue, 13 Sep 2022 02:00:01 GMT</pubDate>
<description><![CDATA[VirusTotal Result Comparisons for Honeypot Malware<br/>
 <a href="https://isc.sans.edu/diary/VirusTotal+Result+Comparisons+for+Honeypot+Malware/29040">https://isc.sans.edu/diary/VirusTotal+Result+Comparisons+for+Honeypot+Malware/29040</a><br/>
Apple Patches<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Lorenz Ransomware Group Cracks MiVoice and Calls Back For Free<br/>
 <a href="https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/">https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/</a><br/>
]]></description>
<itunes:duration>7:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8170" type="text/plain" language="en" />
<itunes:keywords>lorenz, mivoice, mitel, voip, apple, ios, ipados, macos, patches, virustotal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8168</itunes:episode>
<itunes:subtitle>File Exchange Malware; Bypassing Github Code Review; Intermittent Encryption; CRLs are Back;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
File Exchange Malware; Bypassing Github Code Review; Intermittent Encryption; CRLs are Back;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8168.mp3" length="7468414" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8168.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8168</link>
<pubDate>Mon, 12 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Malware Abusing File Exchange Site<br/>
 <a href="https://isc.sans.edu/diary/Phishing+Word+Documents+with+Suspicious+URL/29034">https://isc.sans.edu/diary/Phishing+Word+Documents+with+Suspicious+URL/29034</a><br/>
Bypassing GitHub Required Reviewers to Submit Malicious Code<br/>
 <a href="https://www.legitsecurity.com/blog/bypassing-github-required-reviewers-to-submit-malicious-code">https://www.legitsecurity.com/blog/bypassing-github-required-reviewers-to-submit-malicious-code</a><br/>
Crimeware Trends: Ransomware Developers Turn to Intermittent Encryption<br/>
 <a href="https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection/">https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection/</a><br/>
Lets Encrypt Reviving Certificate Revocation Lists<br/>
 <a href="https://letsencrypt.org/2022/09/07/new-life-for-crls.html">https://letsencrypt.org/2022/09/07/new-life-for-crls.html</a><br/>
]]></description>
<itunes:duration>8:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8168" type="text/plain" language="en" />
<itunes:keywords>lets encrypt, certificates, ocsp, crl, revocation lists, malware, file exchange, github, protected branch, crimeware, ransomware, intermittent encryption, partial, encryption, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8166</itunes:episode>
<itunes:subtitle>VBS vs CyberChef; pfBlockerNG RCE; MSFT Teams Data Exfil;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBS vs CyberChef; pfBlockerNG RCE; MSFT Teams Data Exfil;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8166.mp3" length="6229951" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8166.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8166</link>
<pubDate>Fri, 09 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Analyzing Obfuscated VBS with CyberChef<br/>
 <a href="https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/2902">https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/2902</a><br/>
pfBlockerNG Unauthenticated RCE<br/>
 <a href="https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/">https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/</a><br/>
GifShell attack creates reverse shell using microsoft teams gifs<br/>
 <a href="https://www.bleepingcomputer.com/news/security/gifshell-attack-creates-reverse-shell-using-microsoft-teams-gifs/">https://www.bleepingcomputer.com/news/security/gifshell-attack-creates-reverse-shell-using-microsoft-teams-gifs/</a>]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8166" type="text/plain" language="en" />
<itunes:keywords>gifshell, microsoft, teams, pfblockerng, rce, exploit, pfsense, vbs, cyberchef, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8164</itunes:episode>
<itunes:subtitle>PHP Deserialization; TeslaGun; Cisco RV Router Vulns; Shikitega Malware;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PHP Deserialization; TeslaGun; Cisco RV Router Vulns; Shikitega Malware;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8164.mp3" length="5238416" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8164.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8164</link>
<pubDate>Thu, 08 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[PHP Deserialization Exploit Attempt<br/>
 <a href="https://isc.sans.edu/diary/PHP+Deserialization+Exploit+attempt/29024">https://isc.sans.edu/diary/PHP+Deserialization+Exploit+attempt/29024</a><br/>
TA505 Group's TeslaGun In-Depth Analysis<br/>
 <a href="https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis">https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis</a><br/>
Cisco publishes unpatched Small Business Router Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-vpnbypass-Cpheup9O">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-vpnbypass-Cpheup9O</a><br/>
Shikitega - New stealthy malware targeting Linux<br/>
 <a href="https://thehackernews.com/2022/09/new-stealthy-shikitega-malware.html">https://thehackernews.com/2022/09/new-stealthy-shikitega-malware.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8164" type="text/plain" language="en" />
<itunes:keywords>shikitega, att, iot, malware, linux, cisco, router, patch, eol, ta505, teslagun, php, deserialization, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8162</itunes:episode>
<itunes:subtitle>Encoded Cobalt Strike; EvilProxy PaaS; Zyxel NAS RCE; Moobot vs D-Link
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encoded Cobalt Strike; EvilProxy PaaS; Zyxel NAS RCE; Moobot vs D-Link
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8162.mp3" length="5601350" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8162.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8162</link>
<pubDate>Wed, 07 Sep 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Analysis of an Encoded Cobalt Strike Beacon<br/>
 <a href="https://isc.sans.edu/diary/Analysis+of+an+Encoded+Cobalt+Strike+Beacon/29014">https://isc.sans.edu/diary/Analysis+of+an+Encoded+Cobalt+Strike+Beacon/29014</a><br/>
EvilProxy Phishing-As-A-Service with MFA Bypass<br/>
 <a href="https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web">https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web</a><br/>
Zyxel Patches RCE Vulnerability<br/>
 <a href="https://www.zyxel.com/support/Zyxel-security-advisory-for-format-string-vulnerability-in-NAS.shtml">https://www.zyxel.com/support/Zyxel-security-advisory-for-format-string-vulnerability-in-NAS.shtml</a><br/>
Moobot Going after D-Link Devices<br/>
 <a href="https://unit42.paloaltonetworks.com/moobot-d-link-devices/">https://unit42.paloaltonetworks.com/moobot-d-link-devices/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8162" type="text/plain" language="en" />
<itunes:keywords>moobot, mirai, d-link, zyxel, evilproxy, mfa, proxy, cober strike, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 6th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8160</itunes:episode>
<itunes:subtitle>Webb Malware; Defender False Postives; Chrome 0-Day; Sharkbot;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Webb Malware; Defender False Postives; Chrome 0-Day; Sharkbot;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8160.mp3" length="5153510" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8160.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8160</link>
<pubDate>Tue, 06 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[James Webb JPEG With Malware<br/>
 <a href="https://isc.sans.edu/diary/James+Webb+JPEG+With+Malware/29010">https://isc.sans.edu/diary/James+Webb+JPEG+With+Malware/29010</a><br/>
Windows Defender False Positive<br/>
 <a href="https://www.theregister.com/2022/09/05/windows_defender_chrome_false_positive/">https://www.theregister.com/2022/09/05/windows_defender_chrome_false_positive/</a><br/>
Google Chrome 0-Day<br/>
 <a href="https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html</a><br/>
Sharkbot Android Infostealer in Google Play Store<br/>
 <a href="https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play/">https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play/</a><br/>
Nmap 7.93 - 25th Anniversary Release<br/>
 <a href="https://seclists.org/nmap-announce/2022/1">https://seclists.org/nmap-announce/2022/1</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8160" type="text/plain" language="en" />
<itunes:keywords>nmap, sharkbot, google play store, google chrome, windows defender, flase positive, hive, james webb, jpeg, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8158</itunes:episode>
<itunes:subtitle>Jolokia Scans (maybe Geode?); Exchange Basic Auth; AWS Access Keys; Gitlab;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Jolokia Scans (maybe Geode?); Exchange Basic Auth; AWS Access Keys; Gitlab;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8158.mp3" length="5804047" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8158.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8158</link>
<pubDate>Fri, 02 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Jolokie Scans: Possible Hunt for Vulnerable Apache Geode Servers<br/>
 <a href="https://isc.sans.edu/diary/Jolokia+Scans%3A+Possible+Hunt+for+Vulnerable+Apache+Geode+Servers+%28CVE-2022-37021%29/29006">https://isc.sans.edu/diary/Jolokia+Scans%3A+Possible+Hunt+for+Vulnerable+Apache+Geode+Servers+%28CVE-2022-37021%29/29006</a><br/>
Microsoft Basic Authentication Deprecation in Exchange Online<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-deprecation-in-exchange-online-september/ba-p/3609437">https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-deprecation-in-exchange-online-september/ba-p/3609437</a><br/>
Mobile App Supply Chain Vulnerabilities Could Endanger Sensitive Business Information<br/>
 <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mobile-supply-chain-aws">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mobile-supply-chain-aws</a><br/>
Gitlab Update<br/>
 <a href="https://about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/#brute-force-attack-may-guess-a-password-even-when-2fa-is-enabled">https://about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/#brute-force-attack-may-guess-a-password-even-when-2fa-is-enabled</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8158" type="text/plain" language="en" />
<itunes:keywords>gitlab, mobile apps, fingerprints, aws, access keys, authentication, basic, basic auth, exchange, online, jolokie, geode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8156</itunes:episode>
<itunes:subtitle>QNAME Minimization; iOS 12 Update; Translate Miner; Geode and Foxit PDF Reader Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
QNAME Minimization; iOS 12 Update; Translate Miner; Geode and Foxit PDF Reader Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8156.mp3" length="5021912" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8156.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8156</link>
<pubDate>Thu, 01 Sep 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Underscores and DNS: The Privacy Story<br/>
 <a href="https://isc.sans.edu/diary/Underscores+and+DNS%3A+The+Privacy+Story/29002">https://isc.sans.edu/diary/Underscores+and+DNS%3A+The+Privacy+Story/29002</a><br/>
iOS 12.5.6 Update<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Malware Disguised as Google Translate Desktop App <br/>
 <a href="https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/">https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/</a><br/>
Apache Geode Deserialization Flaw<br/>
 <a href="https://lists.apache.org/thread/qrvhmytsshsk5xcb68pwccw3y6m8o8nr">https://lists.apache.org/thread/qrvhmytsshsk5xcb68pwccw3y6m8o8nr</a><br/>
Foxit PDF Reader Update<br/>
 <a href="https://sec-consult.com/vulnerability-lab/advisory/outdated-javascript-engine-leads-to-rce-in-foxit-pdf-reader/">https://sec-consult.com/vulnerability-lab/advisory/outdated-javascript-engine-leads-to-rce-in-foxit-pdf-reader/</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8156" type="text/plain" language="en" />
<itunes:keywords>foxit, apache, geode, translate, app, miner, ios, dns, qname, minimization, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 31st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8154</itunes:episode>
<itunes:subtitle>IRC Bot in Bash; Webb Image Malware; Malicious Chrome Extension; Chromium Clipboard Access
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IRC Bot in Bash; Webb Image Malware; Malicious Chrome Extension; Chromium Clipboard Access
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8154.mp3" length="5913729" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8154.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8154</link>
<pubDate>Wed, 31 Aug 2022 02:35:02 GMT</pubDate>
<description><![CDATA[Two things that will never die: bash scripts and irc<br/>
 <a href="https://isc.sans.edu/diary/Two+things+that+will+never+die%3A+bash+scripts+and+IRC%21/28998">https://isc.sans.edu/diary/Two+things+that+will+never+die%3A+bash+scripts+and+IRC%21/28998</a><br/>
Malware using James Webb Telescope images<br/>
 <a href="https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/">https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/</a><br/>
Malicious Chrome Extensions<br/>
 <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/</a><br/>
Chromium Based Browsers Allow Access to Clipboard<br/>
 <a href="https://bugs.chromium.org/p/chromium/issues/detail?id=1334203">https://bugs.chromium.org/p/chromium/issues/detail?id=1334203</a><br/>
]]></description>
<itunes:duration>6:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8154" type="text/plain" language="en" />
<itunes:keywords>chromium, chrome, extension, clipboard, malware, james webb, bash, irc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 30th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8152</itunes:episode>
<itunes:subtitle>UTF7 Update; Twilio Breach Aftermath; PDF Reader Adware; Google Block Blockers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
UTF7 Update; Twilio Breach Aftermath; PDF Reader Adware; Google Block Blockers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8152.mp3" length="5480874" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8152.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8152</link>
<pubDate>Tue, 30 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Update: VBA Malcode & UTF7 (APT-C-35)<br/>
 <a href="https://isc.sans.edu/diary/Update%3A+VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28994">https://isc.sans.edu/diary/Update%3A+VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28994</a><br/>
Twilio Breach used to access 2FA Tokens<br/>
 <a href="https://sec.okta.com/scatterswine">https://sec.okta.com/scatterswine</a><br/>
Popular PDF Reader Adware<br/>
 <a href="https://www.malwarebytes.com/blog/news/2022/08/adware-found-on-google-play-pdf-reader-servicing-up-full-screen-ads">https://www.malwarebytes.com/blog/news/2022/08/adware-found-on-google-play-pdf-reader-servicing-up-full-screen-ads</a><br/>
Google changing its VPN Ad Blocker Policy<br/>
 <a href="https://support.google.com/googleplay/android-developer/answer/12253906?hl=en">https://support.google.com/googleplay/android-developer/answer/12253906?hl=en</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8152" type="text/plain" language="en" />
<itunes:keywords>google, vpn, adblocker, adware, pdf reader, twilio, 2fa, breach, utf7, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 29th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8150</itunes:episode>
<itunes:subtitle>Cobalt Strike False Pos; Analyzing HTTP/2; Sysmon Update; Paypal/Coinbase Phish; eth.link at risk
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobalt Strike False Pos; Analyzing HTTP/2; Sysmon Update; Paypal/Coinbase Phish; eth.link at risk
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8150.mp3" length="5721991" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8150.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8150</link>
<pubDate>Mon, 29 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Dealing With False Positives when Scanning Memory Dumps for Cobalt Strike Beacons<br/>
 <a href="https://isc.sans.edu/diary/Dealing+With+False+Positives+when+Scanning+Memory+Dumps+for+Cobalt+Strike+Beacons/28990">https://isc.sans.edu/diary/Dealing+With+False+Positives+when+Scanning+Memory+Dumps+for+Cobalt+Strike+Beacons/28990</a><br/>
HTTP2 Packet Analysis with Wireshark<br/>
 <a href="https://isc.sans.edu/diary/HTTP2+Packet+Analysis+with+Wireshark/28986">https://isc.sans.edu/diary/HTTP2+Packet+Analysis+with+Wireshark/28986</a><br/>
Paypal Phishing/Coinbase in One Image<br/>
 <a href="https://isc.sans.edu/diary/Paypal+PhishingCoinbase+in+One+Image/28984">https://isc.sans.edu/diary/Paypal+PhishingCoinbase+in+One+Image/28984</a><br/>
Sysinternals Updates: Sysmon v14.0 and ZoomIt v6.01<br/>
 <a href="https://isc.sans.edu/diary/Sysinternals+Updates%3A+Sysmon+v14.0+and+ZoomIt+v6.01/28988">https://isc.sans.edu/diary/Sysinternals+Updates%3A+Sysmon+v14.0+and+ZoomIt+v6.01/28988</a><br/>
eth.link domain at risk<br/>
 <a href="https://www.coindesk.com/tech/2022/08/26/web3-domain-name-service-could-lose-its-web-address-because-programmer-who-can-renew-it-sits-in-jail/">https://www.coindesk.com/tech/2022/08/26/web3-domain-name-service-could-lose-its-web-address-because-programmer-who-can-renew-it-sits-in-jail/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8150" type="text/plain" language="en" />
<itunes:keywords>eth, domain, ethereum, sysinternals, sysmon, paypal, coinbase, http2, cobalt strike, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 26th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8148</itunes:episode>
<itunes:subtitle>URL Shorteners; PyPi Phishing; Oktapus; Genshin Impact Driver; LastPass; Bitbucket Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
URL Shorteners; PyPi Phishing; Oktapus; Genshin Impact Driver; LastPass; Bitbucket Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8148.mp3" length="5839352" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8148.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8148</link>
<pubDate>Fri, 26 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Taking Apart URL Shorteners<br/>
 <a href="https://isc.sans.edu/diary/Taking+Apart+URL+Shorteners/28980">https://isc.sans.edu/diary/Taking+Apart+URL+Shorteners/28980</a><br/>
Python Developers Phished for PyPi Credentials<br/>
 <a href="https://twitter.com/pypi/status/1562442188285308929">https://twitter.com/pypi/status/1562442188285308929</a><br/>
Group IB Connects Twilio and Cloudflare Phishing attacks to others<br/>
 <a href="https://www.helpnetsecurity.com/2022/08/25/0ktapus-twilio-cloudflare-phishers-targets/">https://www.helpnetsecurity.com/2022/08/25/0ktapus-twilio-cloudflare-phishers-targets/</a><br/>
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus<br/>
 <a href="https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html">https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html</a><br/>
LastPass Security Incident<br/>
 <a href="https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/">https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/</a><br/>
Bitbucket Vulnerability<br/>
 <a href="https://securityonline.info/cve-2022-36804-bitbucket-server-and-data-center-command-injection-vulnerability/">https://securityonline.info/cve-2022-36804-bitbucket-server-and-data-center-command-injection-vulnerability/</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8148" type="text/plain" language="en" />
<itunes:keywords>bitbucket, lastpass, ransomware, genshin, impact, driver, twilio, cloudflare, oktapus, pypi, phishing, url shorteners, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8146</itunes:episode>
<itunes:subtitle>Monster Libra; Tox Coinminers; Carbon Black Blue Screen; GitLab Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Monster Libra; Tox Coinminers; Carbon Black Blue Screen; GitLab Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8146.mp3" length="4934817" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8146.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8146</link>
<pubDate>Thu, 25 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Monster Libra -> IcedID -> Cobalt Strike and DarkVNC<br/>
 <a href="https://isc.sans.edu/forums/diary/VNC/28974/">https://isc.sans.edu/forums/diary/VNC/28974/</a><br/>
Is Tox the New C&C Method for Coinminers?<br/>
 <a href="https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers">https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers</a><br/>
Carbon Black Blue Screens<br/>
 <a href="https://community.carbonblack.com/t5/Knowledge-Base/Endpoint-Standard-Sudden-Blue-Screens-on-Windows-Devices-23rd/ta-p/114369">https://community.carbonblack.com/t5/Knowledge-Base/Endpoint-Standard-Sudden-Blue-Screens-on-Windows-Devices-23rd/ta-p/114369</a><br/>
Gitlab Vulnerability<br/>
 <a href="https://about.gitlab.com/releases/2022/08/22/critical-security-release-gitlab-15-3-1-released/#Remote%20Command%20Execution%20via%20Github%20import">https://about.gitlab.com/releases/2022/08/22/critical-security-release-gitlab-15-3-1-released/#Remote%20Command%20Execution%20via%20Github%20import</a><br/>
 <br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8146" type="text/plain" language="en" />
<itunes:keywords>gitlab, carbon black, tox, coinmainers, monster libra, icedid, darkvnc, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 24th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8144</itunes:episode>
<itunes:subtitle>security.txt file; Detecting Python Malware; Hyperscrape; Firefox and IBM MQ Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
security.txt file; Detecting Python Malware; Hyperscrape; Firefox and IBM MQ Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8144.mp3" length="6028986" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8144.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8144</link>
<pubDate>Wed, 24 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Who's Looking at Your security.txt File<br/>
 <a href="https://isc.sans.edu/diary/Who%27s+Looking+at+Your+security.txt+File%3F/28972">https://isc.sans.edu/diary/Who%27s+Looking+at+Your+security.txt+File%3F/28972</a><br/>
Assessing Python Malware Detectors with a Benchmark Dataset<br/>
 <a href="https://blog.chainguard.dev/taming-python-malware-scanners/">https://blog.chainguard.dev/taming-python-malware-scanners/</a><br/>
New Iranian APT Data Extraction Tool<br/>
 <a href="https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool/">https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool/</a><br/>
Firefox Update<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/">https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/</a><br/>
IBM MQ Update<br/>
 <a href="https://www.ibm.com/support/pages/node/6613021">https://www.ibm.com/support/pages/node/6613021</a><br/>
 <br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8144" type="text/plain" language="en" />
<itunes:keywords>ibm, mq, firefox, iran, hypberscrpe, gmail, python, malware, detector, security.txt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 23rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8142</itunes:episode>
<itunes:subtitle>32/64 Bit Malware; FBI Home Proxy Warning
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
32/64 Bit Malware; FBI Home Proxy Warning
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8142.mp3" length="6284187" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8142.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8142</link>
<pubDate>Tue, 23 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[32 or 64 Bits Malware<br/>
 <a href="https://isc.sans.edu/diary/32+or+64+bits+Malware%3F/28968">https://isc.sans.edu/diary/32+or+64+bits+Malware%3F/28968</a><br/>
Proxies and Configurations Used for Credential Stuffing Attacks<br/>
 <a href="https://www.ic3.gov/Media/News/2022/220818.pdf">https://www.ic3.gov/Media/News/2022/220818.pdf</a><br/>
DirtyCred Linux Privilege Escalation Vulnerablity<br/>
 <a href="https://www.blackhat.com/us-22/briefings/schedule/#cautious-a-new-exploitation-method-no-pipe-but-as-nasty-as-dirty-pipe-27169">https://www.blackhat.com/us-22/briefings/schedule/#cautious-a-new-exploitation-method-no-pipe-but-as-nasty-as-dirty-pipe-27169</a><br/>
Fake DDos Pages on WordPress Sites Lead to Drive-By-Downloads<br/>
 <a href="https://blog.sucuri.net/2022/08/fake-ddos-pages-on-wordpress-lead-to-drive-by-downloads.html">https://blog.sucuri.net/2022/08/fake-ddos-pages-on-wordpress-lead-to-drive-by-downloads.html</a><br/>
]]></description>
<itunes:duration>7:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8142" type="text/plain" language="en" />
<itunes:keywords>ddos, fake, wordpress, malware, dirtycred, proxies, credential stuffing, 32bit, 64bit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8140</itunes:episode>
<itunes:subtitle>Astaroth Malware targeting Brazil; Android Ring App XSS;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Astaroth Malware targeting Brazil; Android Ring App XSS;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8140.mp3" length="5082526" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8140.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8140</link>
<pubDate>Mon, 22 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Brazil malspam pushes Astaroth (Guildma) malware<br/>
 <a href="https://isc.sans.edu/diary/Brazil+malspam+pushes+Astaroth+%28Guildma%29+malware/28962">https://isc.sans.edu/diary/Brazil+malspam+pushes+Astaroth+%28Guildma%29+malware/28962</a><br/>
Android Ring App XSS<br/>
 <a href="https://checkmarx.com/blog/amazon-quickly-fixed-a-vulnerability-in-ring-android-app-that-could-expose-users-camera-recordings/">https://checkmarx.com/blog/amazon-quickly-fixed-a-vulnerability-in-ring-android-app-that-could-expose-users-camera-recordings/</a><br/>
iOS in App Browser Security Issues<br/>
 <a href="https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser">https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser</a><br/>
iOS in-App Browser Issues<br/>
 <a href="https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser">https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser</a><br/>
 <a href="https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser">https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8140" type="text/plain" language="en" />
<itunes:keywords>ios, android, browser, inappbrowser, ring, amazon, xss, privacy, astaroth, malspam, malware, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8138</itunes:episode>
<itunes:subtitle>Cowrie Summaries; TP-Link; Safari Update; iOS VPN Leaks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cowrie Summaries; TP-Link; Safari Update; iOS VPN Leaks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8138.mp3" length="5175982" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8138.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8138</link>
<pubDate>Fri, 19 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Honeypot Attack Summaries with Python<br/>
 <a href="https://isc.sans.edu/diary/Honeypot+Attack+Summaries+with+Python/28956">https://isc.sans.edu/diary/Honeypot+Attack+Summaries+with+Python/28956</a><br/>
TP-Link Vulnerability<br/>
 <a href="https://blog.viettelcybersecurity.com/1day-to-0day-on-tl-link-tl-wr841n/">https://blog.viettelcybersecurity.com/1day-to-0day-on-tl-link-tl-wr841n/</a><br/>
Safari Update<br/>
 <a href="https://support.apple.com/en-us/HT213414">https://support.apple.com/en-us/HT213414</a><br/>
iOS VPN Leaks<br/>
 <a href="https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php">https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php</a><br/>
Janet Jackson Hard Drive DDoS<br/>
 <a href="https://devblogs.microsoft.com/oldnewthing/20220816-00/?p=106994">https://devblogs.microsoft.com/oldnewthing/20220816-00/?p=106994</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8138" type="text/plain" language="en" />
<itunes:keywords>cowrie, tp-link, safari, ios, vpn, janet jackson, ddos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8136</itunes:episode>
<itunes:subtitle>Voip Experiment; Apple 0-Days; Chrome 0-Day; Insufficient Cisco Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Voip Experiment; Apple 0-Days; Chrome 0-Day; Insufficient Cisco Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8136.mp3" length="5235192" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8136.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8136</link>
<pubDate>Thu, 18 Aug 2022 02:00:01 GMT</pubDate>
<description><![CDATA[A Quick VoIP Experiment<br/>
 <a href="https://isc.sans.edu/diary/A+Quick+VoIP+Experiment/28950">https://isc.sans.edu/diary/A+Quick+VoIP+Experiment/28950</a><br/>
Apple Patches Two Exploited Vulnerabilities<br/>
 <a href="https://isc.sans.edu/diary/Apple+Patches+Two+Exploited+Vulnerabilities/28952">https://isc.sans.edu/diary/Apple+Patches+Two+Exploited+Vulnerabilities/28952</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html">https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html</a><br/>
Cisco staystaystay exploit tool<br/>
 <a href="https://www.youtube.com/watch?v=ySgbHClk9HE">https://www.youtube.com/watch?v=ySgbHClk9HE</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8136" type="text/plain" language="en" />
<itunes:keywords>voip, cisco, astersik, sip, google, chrome, apple, iPadOS, iOS, macOS, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8134</itunes:episode>
<itunes:subtitle>UTF7 Maldoc; SEABORGIUM Shutdown; UWB RTLS Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
UTF7 Maldoc; SEABORGIUM Shutdown; UWB RTLS Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8134.mp3" length="5677752" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8134.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8134</link>
<pubDate>Wed, 17 Aug 2022 02:00:01 GMT</pubDate>
<description><![CDATA[VBA Maldoc and UTF7 (APT-C-35)<br/>
 <a href="https://isc.sans.edu/diary/VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28946">https://isc.sans.edu/diary/VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28946</a><br/>
Disrupting SEABORGIUM's Ongoing Phishing Operations<br/>
 <a href="https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations/">https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations/</a><br/>
UWB Real Time Location Systems: How Secure Radio Communcations May Fail in Practice. <br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8134" type="text/plain" language="en" />
<itunes:keywords>utf7, maldoc, vba, seaborgium, linkedin, uwb, rtls, wifi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8132</itunes:episode>
<itunes:subtitle>Realtek Vuln Followup; MacOS Priv Escalatio; Zoom; Vuln Bootloaders; HPE ILO
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Realtek Vuln Followup; MacOS Priv Escalatio; Zoom; Vuln Bootloaders; HPE ILO
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8132.mp3" length="5780293" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8132.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8132</link>
<pubDate>Tue, 16 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Realtek CVE-2022-27255 Followup (snort signature and presentation)<br/>
 <a href="https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940">https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940</a><br/>
MacOS Privilege Escalation<br/>
 <a href="https://sector7.computest.nl/post/2022-08-process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability/">https://sector7.computest.nl/post/2022-08-process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability/</a><br/>
Zoom Update<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
Microsoft Block Vulnerable Bootloaders<br/>
 <a href="https://eclypsium.com/2022/08/11/vulnerable-bootloaders-2022/">https://eclypsium.com/2022/08/11/vulnerable-bootloaders-2022/</a><br/>
HPE Integrated Lights Out 5 Vulnerablities<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf04333en_us">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf04333en_us</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8132" type="text/plain" language="en" />
<itunes:keywords>hpe, ilo, light out, microsoft, bios, bootloader, uefi, zoom, macos, realtek, deserialization, object, sip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8130</itunes:episode>
<itunes:subtitle>CVE-2022-27255 Realtek SDK Vuln; Voicmail HTML Phish; Palo Alto DDoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2022-27255 Realtek SDK Vuln; Voicmail HTML Phish; Palo Alto DDoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8130.mp3" length="10067479" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8130.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8130</link>
<pubDate>Mon, 15 Aug 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Realtek eCOS SDK SIP ALG Vulnerability <br/>
<a href="https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940">https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940</a><br/>
Phishing HTML Attachment as Voicemail Audio Transcription<br/>
 <a href="https://isc.sans.edu/diary/Phishing+HTML+Attachment+as+Voicemail+Audio+Transcription/28938">https://isc.sans.edu/diary/Phishing+HTML+Attachment+as+Voicemail+Audio+Transcription/28938</a><br/>
CVE-2022-0028 PAN-OS: Reflected Amplification Denial-of-Service Vulnerability<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2022-0028">https://security.paloaltonetworks.com/CVE-2022-0028</a><br/>
]]></description>
<itunes:duration>11:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8130" type="text/plain" language="en" />
<itunes:keywords>realtek, ecos, sdk, sip, alg, phishing, html, voicemail, cve-2022-0028, pan-os, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8128</itunes:episode>
<itunes:subtitle>Infostealing with NSudo; Cisco Breach; Pulse Connect Secure Vuln; Cisco Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Infostealing with NSudo; Cisco Breach; Pulse Connect Secure Vuln; Cisco Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8128.mp3" length="6085157" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8128.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8128</link>
<pubDate>Fri, 12 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[InfoStealer Script Based on Curl and NSudo<br/>
 <a href="https://isc.sans.edu/diary/InfoStealer+Script+Based+on+Curl+and+NSudo/28932">https://isc.sans.edu/diary/InfoStealer+Script+Based+on+Curl+and+NSudo/28932</a><br/>
Cisco Breach Details<br/>
 <a href="https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html">https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html</a><br/>
Ivanti Pulse Connect Secure Privilege Escalation Vulnerability<br/>
 <a href="https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84">https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84</a><br/>
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerablity<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-rsa-key-leak-Ms7UEfZz">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-rsa-key-leak-Ms7UEfZz</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8128" type="text/plain" language="en" />
<itunes:keywords>cisco, asa, firepower, rsa, ivanti, pulse secure, breach, infostealer, nsudo, curl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8126</itunes:episode>
<itunes:subtitle>DNS Attacks; Defaultinator; Zimbra Compromise; vRealize Vuln; Snort/O365 false pos; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Attacks; Defaultinator; Zimbra Compromise; vRealize Vuln; Snort/O365 false pos; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8126.mp3" length="5662061" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8126.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8126</link>
<pubDate>Thu, 11 Aug 2022 02:00:01 GMT</pubDate>
<description><![CDATA[And Here They Come Again: DNS Reflection Attacks<br/>
 <a href="https://isc.sans.edu/diary/And+Here+They+Come+Again%3A+DNS+Reflection+Attacks/28928">https://isc.sans.edu/diary/And+Here+They+Come+Again%3A+DNS+Reflection+Attacks/28928</a><br/>
Rapid 7 Defaultinator<br/>
 <a href="https://defaultinator.com">https://defaultinator.com</a><br/>
Zimbra Mass Compromise<br/>
 <a href="https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/">https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/</a><br/>
VMWare vRealize Vulnerability<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0022.html">https://www.vmware.com/security/advisories/VMSA-2022-0022.html</a><br/>
Microsoft Vulnerability and IPS/Snort<br/>
 <a href="https://community.meraki.com/t5/Meraki-Service-Notices/Microsoft-vulnerability-and-IPS-SNORT/ba-p/156649">https://community.meraki.com/t5/Meraki-Service-Notices/Microsoft-vulnerability-and-IPS-SNORT/ba-p/156649</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8126" type="text/plain" language="en" />
<itunes:keywords>snort, microsoft 365, vmware, flase positive, vrealize, zimbra, rapid 7, defaultinator, dns, ddos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8124</itunes:episode>
<itunes:subtitle>Microsoft Patches; AEPIC Leak; Adobe Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; AEPIC Leak; Adobe Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8124.mp3" length="5052648" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8124.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8124</link>
<pubDate>Wed, 10 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft August 2022 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft+August+2022+Patch+Tuesday/28924">https://isc.sans.edu/diary/Microsoft+August+2022+Patch+Tuesday/28924</a><br/>
AEPIC Leak<br/>
 <a href="https://aepicleak.com">https://aepicleak.com</a><br/>
Adobe security bulletins<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8124" type="text/plain" language="en" />
<itunes:keywords>adobe, amd, intel, aepic, microsoft, patch tuesday, exchange server, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8122</itunes:episode>
<itunes:subtitle>JSON Logs; Edge Security; Malicious Python; New Orchard Botnet
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JSON Logs; Edge Security; Malicious Python; New Orchard Botnet
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8122.mp3" length="5715173" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8122.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8122</link>
<pubDate>Tue, 09 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[JSON All the Logs!<br/>
 <a href="https://isc.sans.edu/diary/JSON+All+the+Logs%21/28920">https://isc.sans.edu/diary/JSON+All+the+Logs%21/28920</a><br/>
Microsoft Edge Enhanced Security<br/>
 <a href="https://docs.microsoft.com/en-us/deployedge/microsoft-edge-security-browse-safer">https://docs.microsoft.com/en-us/deployedge/microsoft-edge-security-browse-safer</a><br/>
Malicious Python Packages<br/>
 <a href="https://www.darkreading.com/application-security/10-malicious-packages-slither-pypi-registry">https://www.darkreading.com/application-security/10-malicious-packages-slither-pypi-registry</a><br/>
New Orchard Botnet<br/>
 <a href="https://blog.netlab.360.com/a-new-botnet-orchard-generates-dga-domains-with-bitcoin-transaction-information/">https://blog.netlab.360.com/a-new-botnet-orchard-generates-dga-domains-with-bitcoin-transaction-information/</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8122" type="text/plain" language="en" />
<itunes:keywords>json, logs, elk, edge, javascript, python, pypi, setup.py, orchard, dga, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8120</itunes:episode>
<itunes:subtitle>Exim Vuln; DockDockGo and Microsoft; Emergency Alerts; Slack Hash Leak; Zimbra flaw exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exim Vuln; DockDockGo and Microsoft; Emergency Alerts; Slack Hash Leak; Zimbra flaw exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8120.mp3" length="5660318" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8120.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8120</link>
<pubDate>Mon, 08 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Exim Vulnerability Silently Patched<br/>
 <a href="https://github.com/ivd38/exim_overflow">https://github.com/ivd38/exim_overflow</a><br/>
DuckDuckGo Stopping Microsoft Tracking Code<br/>
 <a href="https://spreadprivacy.com/more-privacy-and-transparency/">https://spreadprivacy.com/more-privacy-and-transparency/</a><br/>
Emergency Broadcast Messaging System Vulnerabilities<br/>
 <a href="https://content.govdelivery.com/accounts/USDHSFEMA/bulletins/3263326">https://content.govdelivery.com/accounts/USDHSFEMA/bulletins/3263326</a><br/>
Slack Leaks Hashed Passwords<br/>
 <a href="https://slack.com/intl/en-in/blog/news/notice-about-slack-password-resets">https://slack.com/intl/en-in/blog/news/notice-about-slack-password-resets</a><br/>
Zimbra Flaw Exploited<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27924">https://nvd.nist.gov/vuln/detail/CVE-2022-27924</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8120" type="text/plain" language="en" />
<itunes:keywords>IPAWS, EAS, emergency alert system, fema, duckduckgo, microsoft, tracking, exim, zimbra, slack, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 5th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8118</itunes:episode>
<itunes:subtitle>TLP 2.0; Cloudflare Mail Routing Bug; rsync vuln; Kaspersky VPN Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TLP 2.0; Cloudflare Mail Routing Bug; rsync vuln; Kaspersky VPN Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8118.mp3" length="6333178" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8118.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8118</link>
<pubDate>Fri, 05 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[TLP 2.0 is Here<br/>
 <a href="https://isc.sans.edu/diary/TLP+2.0+is+here/28914">https://isc.sans.edu/diary/TLP+2.0+is+here/28914</a><br/>
Hijacking email with Cloudflare Email Routing<br/>
 <a href="https://albertpedersen.com/blog/hijacking-email-with-cloudflare-email-routing/">https://albertpedersen.com/blog/hijacking-email-with-cloudflare-email-routing/</a><br/>
rsync arbitrary file write vulnerablity<br/>
 <a href="https://www.openwall.com/lists/oss-security/2022/08/02/1">https://www.openwall.com/lists/oss-security/2022/08/02/1</a><br/>
Local privilege escalation in Kaspersky VPN<br/>
 <a href="https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/">https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/</a><br/>
]]></description>
<itunes:duration>7:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8118" type="text/plain" language="en" />
<itunes:keywords>kaspersky, vpn, rsync, cloudflar, email, routing, tlp, first, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8116</itunes:episode>
<itunes:subtitle>l9explore User Agent; Arris Vulnerability; Malicious Fork Flood; Paloalto Master key; Laravel; Cisco and DrayTek Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
l9explore User Agent; Arris Vulnerability; Malicious Fork Flood; Paloalto Master key; Laravel; Cisco and DrayTek Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8116.mp3" length="5893547" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8116.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8116</link>
<pubDate>Thu, 04 Aug 2022 02:00:01 GMT</pubDate>
<description><![CDATA[l9explore and LeakIX Internet Wide Recon Scans<br/>
 <a href="https://isc.sans.edu/diary/l9explore+and+LeakIX+Internet+wide+recon+scans./28910">https://isc.sans.edu/diary/l9explore+and+LeakIX+Internet+wide+recon+scans./28910</a><br/>
Arris / Arris Variant DSL/Fiber Router Critical Vulnerability<br/>
 <a href="http://derekabdine.com/blog/2022-arris-advisory">http://derekabdine.com/blog/2022-arris-advisory</a><br/>
35,000 Malicious Repo Forks Flood GitHub<br/>
 <a href="https://www.bleepingcomputer.com/news/security/35-000-code-repos-not-hacked-but-clones-flood-github-to-serve-malware/">https://www.bleepingcomputer.com/news/security/35-000-code-repos-not-hacked-but-clones-flood-github-to-serve-malware/</a><br/>
Palo Alto Master Key<br/>
 <a href="https://twitter.com/rqu50/status/1554566757704089600#m">https://twitter.com/rqu50/status/1554566757704089600#m</a><br/>
Laravel Unserialize RCE<br/>
 <a href="https://github.com/beicheng-maker/vulns/issues/1">https://github.com/beicheng-maker/vulns/issues/1</a><br/>
Unuathenticated Remote Code Execution in DrayTek Vigor Routers<br/>
 <a href="https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/rce-in-dratyek-routers.html">https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/rce-in-dratyek-routers.html</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8116" type="text/plain" language="en" />
<itunes:keywords>cisco, laravel, draytek, paloalto, global protect, github, arris, l9explore, leakix, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8114</itunes:episode>
<itunes:subtitle>Chinese Hacktivists; Zoho Password Manager Exploit; VMWare Update; Manjusaka
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chinese Hacktivists; Zoho Password Manager Exploit; VMWare Update; Manjusaka
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8114.mp3" length="4936672" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8114.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8114</link>
<pubDate>Wed, 03 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Increase in Chinese "Hacktivism" Attacks<br/>
 <a href="https://isc.sans.edu/diary/Increase+in+Chinese+%22Hacktivism%22+Attacks/28906">https://isc.sans.edu/diary/Increase+in+Chinese+%22Hacktivism%22+Attacks/28906</a><br/>
Zoho Password Manager Exploit<br/>
 <a href="https://xz.aliyun.com/t/11578">https://xz.aliyun.com/t/11578</a><br/>
VMWare Updates<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0021.html">https://www.vmware.com/security/advisories/VMSA-2022-0021.html</a><br/>
 <a href="https://twitter.com/VietPetrus">https://twitter.com/VietPetrus</a><br/>
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike<br/>
 <a href="https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html">https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8114" type="text/plain" language="en" />
<itunes:keywords>manjusaka, chinese, sliver, cobalt strike, vmware, zoho, password manager, hacktivism, china, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8112</itunes:episode>
<itunes:subtitle>DDoS Post Mortem; Exposed Twitter Keys; TCL LinkHub Vuln; Jenkins Plugin Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DDoS Post Mortem; Exposed Twitter Keys; TCL LinkHub Vuln; Jenkins Plugin Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8112.mp3" length="5902673" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8112.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8112</link>
<pubDate>Tue, 02 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[A Little DDoS in the Morning<br/>
 <a href="https://isc.sans.edu/diary/A+Little+DDoS+In+the+Morning/28900">https://isc.sans.edu/diary/A+Little+DDoS+In+the+Morning/28900</a><br/>
Exposed Twitter API Keys<br/>
 <a href="https://cloudsek.com/whitepapers_reports/how-leaked-twitter-api-keys-can-be-used-to-build-a-bot-army/">https://cloudsek.com/whitepapers_reports/how-leaked-twitter-api-keys-can-be-used-to-build-a-bot-army/</a><br/>
TCL LinkHub Serialization Issues<br/>
 <a href="https://blog.talosintelligence.com/2022/08/vulnerability-spotlight-how-misusing.html">https://blog.talosintelligence.com/2022/08/vulnerability-spotlight-how-misusing.html</a><br/>
Jenkins Plugin Updates<br/>
 <a href="https://www.jenkins.io/security/advisory/2022-07-27/">https://www.jenkins.io/security/advisory/2022-07-27/</a><br/>
]]></description>
<itunes:duration>6:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8112" type="text/plain" language="en" />
<itunes:keywords>jenkins, tcl linkhub, twitter, api, ddos, china, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8110</itunes:episode>
<itunes:subtitle>PDF Analysis Primer; IPFS Phishing; Mail Stealing Browser Extension; NPM Package Issues; IP Cameras;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF Analysis Primer; IPFS Phishing; Mail Stealing Browser Extension; NPM Package Issues; IP Cameras;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8110.mp3" length="7506266" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8110.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8110</link>
<pubDate>Mon, 01 Aug 2022 02:00:02 GMT</pubDate>
<description><![CDATA[PDF Analysis Introduction and OpenActions Entries<br/>
 <a href="https://isc.sans.edu/diary/PDF+Analysis+Intro+and+OpenActions+Entries/28894">https://isc.sans.edu/diary/PDF+Analysis+Intro+and+OpenActions+Entries/28894</a><br/>
IPFS The New Hotbed of Phishing<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/ipfs-the-new-hotbed-of-phishing/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/ipfs-the-new-hotbed-of-phishing/</a><br/>
Mail Stealing Browser Extension<br/>
 <a href="https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/">https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/</a><br/>
Lofylife Malicious NPM Packages<br/>
 <a href="https://securelist.com/lofylife-malicious-npm-packages/107014/">https://securelist.com/lofylife-malicious-npm-packages/107014/</a><br/>
IP Camera Vulnerability<br/>
 <a href="https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/">https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/</a><br/>
Nuki Smart Lock Vulnerabilities<br/>
 <a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/">https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/</a><br/>
Foxit PDF Reader<br/>
 <a href="https://www.foxit.com/support/security-bulletins.html">https://www.foxit.com/support/security-bulletins.html</a><br/>
]]></description>
<itunes:duration>8:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8110" type="text/plain" language="en" />
<itunes:keywords>foxit, pdf, nuki, dahua, camera, lofylife, npm, email, aol, browser extension, ipfs, openactions, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 29th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8108</itunes:episode>
<itunes:subtitle>Covert Bookmarks; SAMBA Bug; Apple BGP Hijack; Veritas and IBM Patches @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Covert Bookmarks; SAMBA Bug; Apple BGP Hijack; Veritas and IBM Patches @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8108.mp3" length="6315379" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8108.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8108</link>
<pubDate>Fri, 29 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Exfiltrating Data with Bookmarks<br/>
 <a href="https://isc.sans.edu/diary/Exfiltrating+Data+With+Bookmarks/28890">https://isc.sans.edu/diary/Exfiltrating+Data+With+Bookmarks/28890</a><br/>
Critical Samba Bug Could Let Anyone Become Domain Admin<br/>
 <a href="https://nakedsecurity.sophos.com/2022/07/27/critical-samba-bug-could-let-anyone-become-domain-admin-patch-now/">https://nakedsecurity.sophos.com/2022/07/27/critical-samba-bug-could-let-anyone-become-domain-admin-patch-now/</a><br/>
Apple IP Address Range Hijacked by Rostelecom<br/>
 <a href="https://www.manrs.org/2022/07/for-12-hours-was-part-of-apple-engineerings-network-hijacked-by-russias-rostelecom/">https://www.manrs.org/2022/07/for-12-hours-was-part-of-apple-engineerings-network-hijacked-by-russias-rostelecom/</a><br/>
Veritas Patches<br/>
 <a href="https://www.veritas.com/content/support/en_US/security/VTS22-004#c1">https://www.veritas.com/content/support/en_US/security/VTS22-004#c1</a><br/>
IBM Patches<br/>
 <a href="https://www.ibm.com/support/pages/node/6606251">https://www.ibm.com/support/pages/node/6606251</a><br/>
 <a href="https://www.ibm.com/support/pages/node/6607135">https://www.ibm.com/support/pages/node/6607135</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8108" type="text/plain" language="en" />
<itunes:keywords>IBM, Veritas, QRadar, BGP, Hijack, Rostelecom, Apple, Samba, Bookmarks, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8106</itunes:episode>
<itunes:subtitle>IcedID Malware; WebAssembly Miners; Subzero and Knotweed; @sucurisecurity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IcedID Malware; WebAssembly Miners; Subzero and Knotweed; @sucurisecurity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8106.mp3" length="5386180" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8106.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8106</link>
<pubDate>Thu, 28 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[IcedID (BokBot) with Dark VNC and Cobalt Strike<br/>
 <a href="https://isc.sans.edu/diary//28884">https://isc.sans.edu/diary//28884</a><br/>
Web Assembly Crypto Miners<br/>
 <a href="https://blog.sucuri.net/2022/07/cryptominers-webassembly-in-website-malware.html">https://blog.sucuri.net/2022/07/cryptominers-webassembly-in-website-malware.html</a><br/>
Subzero and Knotweed<br/>
 <a href="https://www.microsoft.com/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/">https://www.microsoft.com/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8106" type="text/plain" language="en" />
<itunes:keywords>subzero, knotweek, webassembly, wasm, cryptojacking, miners, icedid, bokbot, darkvnc, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 27th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8104</itunes:episode>
<itunes:subtitle>macOS Security; Executable Registry Files; Facebook Business Phishing; Proxy Headers; @xme @x86matthew @Synacktiv
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
macOS Security; Executable Registry Files; Facebook Business Phishing; Proxy Headers; @xme @x86matthew @Synacktiv
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8104.mp3" length="5472977" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8104.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8104</link>
<pubDate>Wed, 27 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[How is Your macOS Security Posture<br/>
 <a href="https://isc.sans.edu/diary/How+is+Your+macOS+Security+Posture%3F/28882">https://isc.sans.edu/diary/How+is+Your+macOS+Security+Posture%3F/28882</a><br/>
Registry file with Executable Payload<br/>
 <a href="https://www.x86matthew.com/view_post?id=embed_exe_reg">https://www.x86matthew.com/view_post?id=embed_exe_reg</a><br/>
Targeted Phishing of Facebook Business Users<br/>
 <a href="https://labs.withsecure.com/assets/BlogFiles/Publications/WithSecure_Research_DUCKTAIL.pdf">https://labs.withsecure.com/assets/BlogFiles/Publications/WithSecure_Research_DUCKTAIL.pdf</a><br/>
Forwarding Address is Hard<br/>
 <a href="https://www.synacktiv.com/publications/cve-2022-31813-forwarding-addresses-is-hard.html">https://www.synacktiv.com/publications/cve-2022-31813-forwarding-addresses-is-hard.html</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8104" type="text/plain" language="en" />
<itunes:keywords>Macos, apple, registry, phishing, facebook, Forwarding, proxies, headers, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 26th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8102</itunes:episode>
<itunes:subtitle>Fileless Powershell; MDM Vulnerablity; CosmicStrand UEFI Rootkit; @securelist @claroty @xme
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fileless Powershell; MDM Vulnerablity; CosmicStrand UEFI Rootkit; @securelist @claroty @xme
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8102.mp3" length="6233029" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8102.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8102</link>
<pubDate>Tue, 26 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[PowerShell Script with Fileless Capability<br/>
 <a href="https://isc.sans.edu/diary/PowerShell+Script+with+Fileless+Capability/28878">https://isc.sans.edu/diary/PowerShell+Script+with+Fileless+Capability/28878</a><br/>
With Management Comes Risk: Finding Flaws in Filewave MDM<br/>
 <a href="https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/">https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/</a><br/>
CosmicStrand: the discovery of a sophisticated UEFI firmware rootkit<br/>
 <a href="https://securelist.com/cosmicstrand-uefi-firmware-rootkit/106973/">https://securelist.com/cosmicstrand-uefi-firmware-rootkit/106973/</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8102" type="text/plain" language="en" />
<itunes:keywords>cosmicstrand, mdm, uefi, kaspersky, filewave, powershell, fileless, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8100</itunes:episode>
<itunes:subtitle>SMS and Phishing; Sonicwall SQLi; SHA Errors;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SMS and Phishing; Sonicwall SQLi; SHA Errors;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8100.mp3" length="5182189" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8100.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8100</link>
<pubDate>Mon, 25 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[An Analysis of a Discerning Phishing Website<br/>
 <a href="https://isc.sans.edu/diary/An+Analysis+of+a+Discerning+Phishing+Website+/28870">https://isc.sans.edu/diary/An+Analysis+of+a+Discerning+Phishing+Website+/28870</a><br/>
Sonicwall Vulnerability<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0007">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0007</a><br/>
Sh*load Exploids Episdoe V: Return of the Error<br/>
<a href="https://dellfer.com/shload-exploits-episode-v-return-of-the-error/">https://dellfer.com/shload-exploits-episode-v-return-of-the-error/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8100" type="text/plain" language="en" />
<itunes:keywords>sms, phishing, mobile, sonicwall, sql injection, sha2, error checking, tls, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8098</itunes:episode>
<itunes:subtitle>Non ASCII VBA; Cisco Update; Odd Outlook 365 Warnings; Windows RDP and Office Macro Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Non ASCII VBA; Cisco Update; Odd Outlook 365 Warnings; Windows RDP and Office Macro Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8098.mp3" length="5686648" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8098.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8098</link>
<pubDate>Fri, 22 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Maldoc with non-ASCII VBA Identifiers<br/>
 <a href="https://isc.sans.edu/diary/Maldoc%3A+non-ASCII+VBA+Identifiers/28866">https://isc.sans.edu/diary/Maldoc%3A+non-ASCII+VBA+Identifiers/28866</a><br/>
Cisco Security Updates<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x?">https://tools.cisco.com/security/center/publicationListing.x?</a><br/>
Outlook 365 Odd Supicious Login Attempt Warnings<br/>
 <a href="https://www.theregister.com/2022/07/21/outlook_sign_ins/">https://www.theregister.com/2022/07/21/outlook_sign_ins/</a><br/>
Windows RDP Brute Force Protection<br/>
 <a href="https://twitter.com/dwizzzleMSFT/status/1549870156771340288">https://twitter.com/dwizzzleMSFT/status/1549870156771340288</a><br/>
Microsoft resuming blocking macros<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805">https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8098" type="text/plain" language="en" />
<itunes:keywords>microsoft, windows, rdp, brute force, outlook, password, login attempts, cisco, maldoc, vba, ascii, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8096</itunes:episode>
<itunes:subtitle>Python Ducky; Apple Patches; Zyxel Vuln; DNS over HTTP/3; Atlasian Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Ducky; Apple Patches; Zyxel Vuln; DNS over HTTP/3; Atlasian Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8096.mp3" length="5480373" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8096.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8096</link>
<pubDate>Thu, 21 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Malicious Python Script Behaving Like a Rubber Ducky<br/>
 <a href="https://isc.sans.edu/diary/Malicious+Python+Script+Behaving+Like+a+Rubber+Ducky/28860">https://isc.sans.edu/diary/Malicious+Python+Script+Behaving+Like+a+Rubber+Ducky/28860</a><br/>
Apple Patches Everything<br/>
 <a href="https://isc.sans.edu/diary/Apple+Patches+Everything+Day/28862">https://isc.sans.edu/diary/Apple+Patches+Everything+Day/28862</a><br/>
Confluence Atlasian Hard Coded Password<br/>
 <a href="https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html">https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html</a><br/>
Zyxel Vulnerablity<br/>
 <a href="https://www.zyxel.com/support/Zyxel-security-advisory-authenticated-directory-traversal-vulnerabilities-of-firewalls.shtml">https://www.zyxel.com/support/Zyxel-security-advisory-authenticated-directory-traversal-vulnerabilities-of-firewalls.shtml</a><br/>
DNS over HTTP/3<br/>
 <a href="https://security.googleblog.com/2022/07/dns-over-http3-in-android.html">https://security.googleblog.com/2022/07/dns-over-http3-in-android.html</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8096" type="text/plain" language="en" />
<itunes:keywords>python, rubber ducky, apple, patches, ios, macos, watchos, tvos, zyxel, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8094</itunes:episode>
<itunes:subtitle>Beacon Request; Zyxel Vuln; Oracle CPU; MacOS Spyware; GPS Tracker Vulnerablity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Beacon Request; Zyxel Vuln; Oracle CPU; MacOS Spyware; GPS Tracker Vulnerablity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8094.mp3" length="6339576" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8094.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8094</link>
<pubDate>Wed, 20 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Beacon Request<br/>
 <a href="https://isc.sans.edu/diary/Requests+For+beacon.http-get.+Help+Us+Figure+Out+What+They+Are+Looking+For/28856">https://isc.sans.edu/diary/Requests+For+beacon.http-get.+Help+Us+Figure+Out+What+They+Are+Looking+For/28856</a><br/>
Oracle July 2022 CPU<br/>
 <a href="https://www.oracle.com/security-alerts/cpujul2022.html">https://www.oracle.com/security-alerts/cpujul2022.html</a><br/>
CloudMensis MacOS Spyware<br/>
 <a href="https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/">https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/</a><br/>
GPS Tracker Vulnerabilities<br/>
 <a href="https://www.bitsight.com/sites/default/files/2022-07/MiCODUS-GPS-Report-Final.pdf">https://www.bitsight.com/sites/default/files/2022-07/MiCODUS-GPS-Report-Final.pdf</a><br/>
]]></description>
<itunes:duration>7:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8094" type="text/plain" language="en" />
<itunes:keywords>beacon, oracle, cpu, cloudmensis, macos, spyware, gps, micodus, tracker, vulnerability, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8092</itunes:episode>
<itunes:subtitle>PDF Tools Keywords; Tor Improvements; Fake ICS Password Cracker; Apache Spark Vuln; Juniper Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF Tools Keywords; Tor Improvements; Fake ICS Password Cracker; Apache Spark Vuln; Juniper Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8092.mp3" length="5357444" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8092.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8092</link>
<pubDate>Tue, 19 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Adding Your Own Keywords to My PDF Tools<br/>
 <a href="https://isc.sans.edu/diary/Adding+Your+Own+Keywords+To+My+PDF+Tools/28852">https://isc.sans.edu/diary/Adding+Your+Own+Keywords+To+My+PDF+Tools/28852</a><br/>
Tor Improvements<br/>
 <a href="https://blog.torproject.org/new-release-tor-browser-115/">https://blog.torproject.org/new-release-tor-browser-115/</a><br/>
Trojan Horse Malware Password Cracker<br/>
 <a href="https://www.dragos.com/blog/the-trojan-horse-malware-password-cracking-ecosystem-targeting-industrial-operators/">https://www.dragos.com/blog/the-trojan-horse-malware-password-cracking-ecosystem-targeting-industrial-operators/</a><br/>
CVE-2022-33891 Apache Spark Shell Command Injection Vulnerability<br/>
 <a href="https://securityonline.info/cve-2022-33891-apache-spark-shell-command-injection-vulnerability/">https://securityonline.info/cve-2022-33891-apache-spark-shell-command-injection-vulnerability/</a><br/>
Juniper Junos Vulnerabilities<br/>
 <a href="https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=date%20descending&f:ctype=[Security%20Advisories]">https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=date%20descending&f:ctype=[Security%20Advisories]</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8092" type="text/plain" language="en" />
<itunes:keywords>pdf, didier, trojan, passwords, isc, apache, spark, juniper, junos, tor, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8090</itunes:episode>
<itunes:subtitle>Python File In Use; Google Data Safety; Google Play Malware @ingraomaxime; Faking Github Metadata;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python File In Use; Google Data Safety; Google Play Malware @ingraomaxime; Faking Github Metadata;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8090.mp3" length="4779101" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8090.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8090</link>
<pubDate>Mon, 18 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Python: Files in Use By Another Process<br/>
 <a href="https://isc.sans.edu/diary/Python%3A+Files+In+Use+By+Another+Process/28848">https://isc.sans.edu/diary/Python%3A+Files+In+Use+By+Another+Process/28848</a><br/>
Google Removing App Permissions List for Data Safety<br/>
 <a href="https://twitter.com/MishaalRahman/status/1547307555407421443">https://twitter.com/MishaalRahman/status/1547307555407421443</a><br/>
Google Play Malware<br/>
 <a href="https://twitter.com/IngraoMaxime/status/1547164768401858560">https://twitter.com/IngraoMaxime/status/1547164768401858560</a><br/>
Faking Github Metadata<br/>
 <a href="https://checkmarx.com/blog/unverified-commits-are-you-unknowingly-trusting-attackers-code/">https://checkmarx.com/blog/unverified-commits-are-you-unknowingly-trusting-attackers-code/</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8090" type="text/plain" language="en" />
<itunes:keywords>python, locked files, google, play store, app permissions, data safety, github, metadata, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8088</itunes:episode>
<itunes:subtitle>Debugging Broadcast Storms; Deanonymizing Browsers; MFA Phishing; VMWare Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Debugging Broadcast Storms; Deanonymizing Browsers; MFA Phishing; VMWare Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8088.mp3" length="5906158" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8088.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8088</link>
<pubDate>Fri, 15 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Debugging Broadcast Storms<br/>
 <a href="https://isc.sans.edu/diary/A+%22DHCP+is+Broken%22+story%2C+and+a+Blast+from+the+Past+%28or+should+I+say+%22Storm%22+from+the+past%29/28844">https://isc.sans.edu/diary/A+%22DHCP+is+Broken%22+story%2C+and+a+Blast+from+the+Past+%28or+should+I+say+%22Storm%22+from+the+past%29/28844</a><br/>
Targeted Deanonymization via Side Channel Attacks<br/>
 <a href="https://leakuidatorplusteam.github.io/preprint.pdf">https://leakuidatorplusteam.github.io/preprint.pdf</a><br/>
Cookie Theft to BEC<br/>
 <a href="https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/">https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/</a><br/>
VMWare Patch<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0025.html">https://www.vmware.com/security/advisories/VMSA-2021-0025.html</a><br/>
]]></description>
<itunes:duration>6:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8088" type="text/plain" language="en" />
<itunes:keywords>vmware, cookie, bec, anonymity, deanonymization, side channel, broadcast storm, networks, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8086</itunes:episode>
<itunes:subtitle>Phishing Referrers; Callback Phishing; Retbleed Spectre; MacOS Sandbox Escape; Lenovo UEFI
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing Referrers; Callback Phishing; Retbleed Spectre; MacOS Sandbox Escape; Lenovo UEFI
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8086.mp3" length="5184981" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8086.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8086</link>
<pubDate>Thu, 14 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Using Referrers to Detect Phishing Attacks<br/>
 <a href="https://isc.sans.edu/diary/Using+Referers+to+Detect+Phishing+Attacks/28836">https://isc.sans.edu/diary/Using+Referers+to+Detect+Phishing+Attacks/28836</a><br/>
Callback Phishing Campaigns Impersonating Security Companies<br/>
 <a href="https://www.crowdstrike.com/blog/callback-malware-campaigns-impersonate-crowdstrike-and-other-cybersecurity-companies/">https://www.crowdstrike.com/blog/callback-malware-campaigns-impersonate-crowdstrike-and-other-cybersecurity-companies/</a><br/>
Retbleed Spectre Attack<br/>
 <a href="https://comsec.ethz.ch/wp-content/files/retbleed_sec22.pdf">https://comsec.ethz.ch/wp-content/files/retbleed_sec22.pdf</a><br/>
Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706<br/>
 <a href="https://www.microsoft.com/security/blog/2022/07/13/uncovering-a-macos-app-sandbox-escape-vulnerability-a-deep-dive-into-cve-2022-26706/">https://www.microsoft.com/security/blog/2022/07/13/uncovering-a-macos-app-sandbox-escape-vulnerability-a-deep-dive-into-cve-2022-26706/</a><br/>
Buffer Overflow Vulnerabilities in UEFI firmware of several Lenovo Notebook <br/>
 <a href="https://twitter.com/ESETresearch/status/1547166334651334657">https://twitter.com/ESETresearch/status/1547166334651334657</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8086" type="text/plain" language="en" />
<itunes:keywords>uefi, lenovo, eset, macos, sandbox, microsoft, retbleed, spectre, intel, amd, phishing, referrer, callback, security companies, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8084</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; SAP Patches; IBM Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; SAP Patches; IBM Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8084.mp3" length="5178756" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8084.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8084</link>
<pubDate>Wed, 13 Jul 2022 02:25:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/diary/Microsoft+July+2022+Patch+Tuesday/28838">https://isc.sans.edu/diary/Microsoft+July+2022+Patch+Tuesday/28838</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
SAP Patches<br/>
 <a href="https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10">https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10</a><br/>
IBM Patches<br/>
 <a href="https://www.ibm.com/support/pages/node/6602255">https://www.ibm.com/support/pages/node/6602255</a><br/>
 <a href="https://www.ibm.com/support/pages/node/6602259">https://www.ibm.com/support/pages/node/6602259</a><br/>
 <a href="https://www.ibm.com/support/pages/node/6602251">https://www.ibm.com/support/pages/node/6602251</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8084" type="text/plain" language="en" />
<itunes:keywords>IBM, MQ, log4j, sap, adobe, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8082</itunes:episode>
<itunes:subtitle>Rogers Outage; Rolling Pwn / Hacking Honda; GitHub Runners Crypto Mining; #SANSFIRE Keynote Stream
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Rogers Outage; Rolling Pwn / Hacking Honda; GitHub Runners Crypto Mining; #SANSFIRE Keynote Stream
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8082.mp3" length="5574731" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8082.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8082</link>
<pubDate>Tue, 12 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Rogers Outage<br/>
 <a href="https://about.rogers.com/news-ideas/a-message-from-rogers-president-and-ceo/">https://about.rogers.com/news-ideas/a-message-from-rogers-president-and-ceo/</a><br/>
Rolling Pwn<br/>
<a href="https://rollingpwn.github.io/rolling-pwn/">https://rollingpwn.github.io/rolling-pwn/</a><br/>
GitHub Runners mine Cryptocoins<br/>
<a href="https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html">https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html</a><br/>
SANSFIRE Keynote Stream<br/>
 <a href="https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/">https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8082" type="text/plain" language="en" />
<itunes:keywords>github, rolling pwn, rogers, outage, cryptomining, runners, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8080</itunes:episode>
<itunes:subtitle>SANSFIRE; Emotet vs Cyberchef; Microsoft vs. Macros; Checkmate QNAP; PyPi 2FA;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANSFIRE; Emotet vs Cyberchef; Microsoft vs. Macros; Checkmate QNAP; PyPi 2FA;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8080.mp3" length="4891845" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8080.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8080</link>
<pubDate>Mon, 11 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[SANSFIRE Keynote Stream<br/>
 <a href="https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/">https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/</a><br/>
Extracting URLs from Emotet with Cyberchef<br/>
 <a href="https://isc.sans.edu/forums/diary/Excel%204%20Emotet%20Maldoc%20Analysis%20using%20CyberChef/28830/">https://isc.sans.edu/forums/diary/Excel%204%20Emotet%20Maldoc%20Analysis%20using%20CyberChef/28830/</a><br/>
Microsoft rolling Back Macro Policy Change<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805">https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805</a><br/>
Checkmate Ransomware Affected Poorly Configured QNAP NAS<br/>
 <a href="https://www.qnap.com/en/security-advisory/QSA-22-21">https://www.qnap.com/en/security-advisory/QSA-22-21</a><br/>
PyPi Requires 2FA for critical packages<br/>
 <a href="https://pypi.org/security-key-giveaway/">https://pypi.org/security-key-giveaway/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8080" type="text/plain" language="en" />
<itunes:keywords>pypi, 2fa, mfa, titan, google, checkmate, qnap, microsoft, office, macro, emotet, cyberchef, sansfire, keynote, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8078</itunes:episode>
<itunes:subtitle>Max SANs; Fortinet July Updates; Ouch Phishing; Quantum Safe Ciphers; Apple Lockdown
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Max SANs; Fortinet July Updates; Ouch Phishing; Quantum Safe Ciphers; Apple Lockdown
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8078.mp3" length="6477686" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8078.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8078</link>
<pubDate>Thu, 07 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[How Many SANs are Insane<br/>
 <a href="https://isc.sans.edu/forums/diary/How+Many+SANs+are+Insane/28820/">https://isc.sans.edu/forums/diary/How+Many+SANs+are+Insane/28820/</a><br/>
Fortinet July Updates<br/>
 <a href="https://fortiguard.fortinet.com/psirt?date=07-2022">https://fortiguard.fortinet.com/psirt?date=07-2022</a><br/>
Phishing Attacks Getting Trickier<br/>
 <a href="https://www.sans.org/newsletters/ouch/phishing-attacks-getting-trickier">https://www.sans.org/newsletters/ouch/phishing-attacks-getting-trickier</a><br/>
Quantum Safe Ciphers<br/>
 <a href="https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4">https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4</a><br/>
Apple Proposes Lockdown Mode<br/>
 <a href="https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/">https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/</a><br/>
]]></description>
<itunes:duration>7:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8078" type="text/plain" language="en" />
<itunes:keywords>apple, lockdown, ciphers, quantum safe, phsihing, ouch, fortinet, sans, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 6th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8076</itunes:episode>
<itunes:subtitle>EternalBlue Retrospective; OpenSSL Update; Keystroke Logging NPM Packages
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
EternalBlue Retrospective; OpenSSL Update; Keystroke Logging NPM Packages
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8076.mp3" length="5634082" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8076.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8076</link>
<pubDate>Wed, 06 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[EternalBlue 5 Years After WannaCry and NotPetya<br/>
 <a href="https://isc.sans.edu/forums/diary/EternalBlue+5+years+after+WannaCry+and+NotPetya/28816/">https://isc.sans.edu/forums/diary/EternalBlue+5+years+after+WannaCry+and+NotPetya/28816/</a><br/>
OpenSSL Patches Two Vulnerabilities<br/>
 <a href="https://www.openssl.org/news/secadv/20220705.txt">https://www.openssl.org/news/secadv/20220705.txt</a><br/>
Iconburst NPM Software Supply Chain Attack<br/>
 <a href="https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites">https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8076" type="text/plain" language="en" />
<itunes:keywords>iconburst, npm, openssl, eternalblue, wannacry, notpetya, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 5th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8074</itunes:episode>
<itunes:subtitle>7-Zip and MotW; Session Manager Backdoor; Chrome 0Day Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
7-Zip and MotW; Session Manager Backdoor; Chrome 0Day Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8074.mp3" length="4936076" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8074.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8074</link>
<pubDate>Tue, 05 Jul 2022 02:00:02 GMT</pubDate>
<description><![CDATA[7Zip Mark of the Web For Office Files<br/>
 <a href="https://isc.sans.edu/forums/diary/7Zip+MoW+For+Office+files/28812/">https://isc.sans.edu/forums/diary/7Zip+MoW+For+Office+files/28812/</a><br/>
SessionManager Backdoor Seen with IIS<br/>
 <a href="https://securelist.com/the-sessionmanager-iis-backdoor/106868/">https://securelist.com/the-sessionmanager-iis-backdoor/106868/</a><br/>
Googe Chrome Stable Channel Update<br/>
 <a href="https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html">https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8074" type="text/plain" language="en" />
<itunes:keywords>google, chrome, 0day, sessionmanager, iis, 7zip, motw, office, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8072</itunes:episode>
<itunes:subtitle>Cobalt Strike Domain Suspension; ManageEngine Vuln Details; CWE Top 25 Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobalt Strike Domain Suspension; ManageEngine Vuln Details; CWE Top 25 Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8072.mp3" length="5737768" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8072.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8072</link>
<pubDate>Fri, 01 Jul 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Case Study: Cobalt Strike Server Lives on After its Domain is Suspended<br/>
 <a href="https://isc.sans.edu/forums/diary/Case+Study+Cobalt+Strike+Server+Lives+on+After+Its+Domain+Is+Suspended/28804/">https://isc.sans.edu/forums/diary/Case+Study+Cobalt+Strike+Server+Lives+on+After+Its+Domain+Is+Suspended/28804/</a><br/>
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus<br/>
 <a href="https://www.horizon3.ai/red-team-blog-cve-2022-28219/">https://www.horizon3.ai/red-team-blog-cve-2022-28219/</a><br/>
CWE Top 25 Update<br/>
 <a href="https://cwe.mitre.org/top25/archive/2022/2022_cwe_top25.html#analysis">https://cwe.mitre.org/top25/archive/2022/2022_cwe_top25.html#analysis</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8072" type="text/plain" language="en" />
<itunes:keywords>cwe, cve, xxe, rce, cobalt strike, quakbot, manageengine, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 30th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8070</itunes:episode>
<itunes:subtitle>Moving MFA; Managing Human Risk Report; Service Fabric PoC; Zimbra RCE; Deepfake Interviews;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Moving MFA; Managing Human Risk Report; Service Fabric PoC; Zimbra RCE; Deepfake Interviews;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8070.mp3" length="5975998" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8070.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8070</link>
<pubDate>Thu, 30 Jun 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Its New Phone Day: Time to Migrate Your MFA<br/>
 <a href="https://isc.sans.edu/forums/diary/Its+New+Phone+Day+Time+to+migrate+your+MFA/28800/">https://isc.sans.edu/forums/diary/Its+New+Phone+Day+Time+to+migrate+your+MFA/28800/</a><br/>
Managing Human Risk Security Awareness Report<br/>
 <a href="https://go.sans.org/lp-wp-2022-sans-security-awareness-report">https://go.sans.org/lp-wp-2022-sans-security-awareness-report</a><br/>
Microsoft Azure Service Fabric Container Elevation of Privilege Vulnerability<br/>
 <a href="https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/#The-Vulnerability">https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/#The-Vulnerability</a><br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30137">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30137</a><br/>
Zimbra RCE Vulnerability<br/>
 <a href="https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/">https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/</a><br/>
FBI Warns of Deep Fakes Beeing Used in Job Interviews<br/>
 <a href="https://www.ic3.gov/Media/Y2022/PSA220628">https://www.ic3.gov/Media/Y2022/PSA220628</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8070" type="text/plain" language="en" />
<itunes:keywords>deepfake, fbi, job interview, zimbra, webmail, service fabric, container, escape, ssa, human risk, moving mfa, mfa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 29th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8068</itunes:episode>
<itunes:subtitle>HiByMusic Scans; OpenSSL Heap Overflow; ZuoRat; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HiByMusic Scans; OpenSSL Heap Overflow; ZuoRat; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8068.mp3" length="5187160" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8068.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8068</link>
<pubDate>Wed, 29 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Possible Scans for HiByMusic Devices<br/>
 <a href="https://isc.sans.edu/forums/diary/Possible+Scans+for+HiByMusic+Devices/28796/">https://isc.sans.edu/forums/diary/Possible+Scans+for+HiByMusic+Devices/28796/</a><br/>
OpenSSL Heap Overflow<br/>
 <a href="https://guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption/">https://guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption/</a><br/>
 <a href="https://github.com/openssl/openssl/issues/18625#issuecomment-1165012549">https://github.com/openssl/openssl/issues/18625#issuecomment-1165012549</a><br/>
ZuoRat MalwareHijacking Home Office Routers<br/>
 <a href="https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/">https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8068" type="text/plain" language="en" />
<itunes:keywords>zuorat, openssl, hibymusic, radio.txt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8066</itunes:episode>
<itunes:subtitle>Encrypted Client Hello; Jenkins Patches; Instagram Age Verification; CodeSys Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encrypted Client Hello; Jenkins Patches; Instagram Age Verification; CodeSys Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8066.mp3" length="5770080" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8066.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8066</link>
<pubDate>Tue, 28 Jun 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Encrypted Client Hello: Anybody Using it Yet?<br/>
 <a href="https://isc.sans.edu/forums/diary/Encrypted+Client+Hello+Anybody+Using+it+Yet/28792/">https://isc.sans.edu/forums/diary/Encrypted+Client+Hello+Anybody+Using+it+Yet/28792/</a><br/>
Jenkins Advisory<br/>
 <a href="https://www.jenkins.io/security/advisory/2022-06-22/">https://www.jenkins.io/security/advisory/2022-06-22/</a><br/>
Instagram Age Verification<br/>
 <a href="https://about.fb.com/news/2022/06/new-ways-to-verify-age-on-instagram/">https://about.fb.com/news/2022/06/new-ways-to-verify-age-on-instagram/</a><br/>
CodeSys V2 Vulnerability<br/>
 <a href="https://github.com/ic3sw0rd/Codesys_V2_Vulnerability">https://github.com/ic3sw0rd/Codesys_V2_Vulnerability</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8066" type="text/plain" language="en" />
<itunes:keywords>codesys, ics, ech, jenkins, tls, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 27th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8064</itunes:episode>
<itunes:subtitle>Python GUI Malware; Pasting Malcode; WebView2 Risks; Pretend Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python GUI Malware; Pasting Malcode; WebView2 Risks; Pretend Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8064.mp3" length="6897518" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8064.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8064</link>
<pubDate>Mon, 27 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Python Abusing the Windows GUI<br/>
 <a href="https://isc.sans.edu/forums/diary/Python+abusing+The+Windows+GUI/28780/">https://isc.sans.edu/forums/diary/Python+abusing+The+Windows+GUI/28780/</a><br/>
Malicious Code Passed to PowerShell via the Clipboard<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Code+Passed+to+PowerShell+via+the+Clipboard/28784/">https://isc.sans.edu/forums/diary/Malicious+Code+Passed+to+PowerShell+via+the+Clipboard/28784/</a><br/>
Attacking With WebView2 Applications<br/>
 <a href="https://mrd0x.com/attacking-with-webview2-applications/">https://mrd0x.com/attacking-with-webview2-applications/</a><br/>
Bronze Starlight Ransomware Operations Use Hui Loaders<br/>
 <a href="https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader">https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader</a><br/>
Novel Exploit Detected in Mitel VoIP Appliance<br/>
 <a href="https://www.crowdstrike.com/blog/novel-exploit-detected-in-mitel-voip-appliance/">https://www.crowdstrike.com/blog/novel-exploit-detected-in-mitel-voip-appliance/</a><br/>
 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29499">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29499</a><br/>
]]></description>
<itunes:duration>7:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8064" type="text/plain" language="en" />
<itunes:keywords>python, gui, powershell, clipboard, webview2, starlight, ransomware, hui loaders, mitel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 23rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8062</itunes:episode>
<itunes:subtitle>Coin Stealing Powershell; NSA PS Guidance; MageCart Update; Script Kiddies Hacked; Israeli Air Raid Sirens Hacked;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Coin Stealing Powershell; NSA PS Guidance; MageCart Update; Script Kiddies Hacked; Israeli Air Raid Sirens Hacked;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8062.mp3" length="4948512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8062.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8062</link>
<pubDate>Thu, 23 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious PowerShell Targeting Cryptocurrency Browser Extensions<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+PowerShell+Targeting+Cryptocurrency+Browser+Extensions/28772/">https://isc.sans.edu/forums/diary/Malicious+PowerShell+Targeting+Cryptocurrency+Browser+Extensions/28772/</a><br/>
Keeping PowerShell: Security Measures to Use and Embrace<br/>
 <a href="https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF">https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF</a><br/>
Client-Side Magecart Attacks Still Around, But More Covert<br/>
 <a href="https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert/">https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert/</a><br/>
Chinese actor takes aim, armed with Nim Language and Bizarro AES<br/>
 <a href="https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes/">https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes/</a><br/>
Israeli Air Raid Sirens Hacked<br/>
 <a href="https://twitter.com/Israel_Cyber/status/1538821467785265153">https://twitter.com/Israel_Cyber/status/1538821467785265153</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8062" type="text/plain" language="en" />
<itunes:keywords>israel, air raid, siren, hacked, chinese, nim, aes, magecart, powershell, crypto coin, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8060</itunes:episode>
<itunes:subtitle>Domain Age API; OT Vulnerablities; Cloudflare Outage; Acrobat Blocks AV; 7zip MOTW;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Domain Age API; OT Vulnerablities; Cloudflare Outage; Acrobat Blocks AV; 7zip MOTW;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8060.mp3" length="5571340" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8060.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8060</link>
<pubDate>Wed, 22 Jun 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Experimental New Domain / Domain Age API<br/>
 <a href="https://isc.sans.edu/forums/diary/Experimental+New+Domain+Domain+Age+API/28770/">https://isc.sans.edu/forums/diary/Experimental+New+Domain+Domain+Age+API/28770/</a><br/>
Forescout Vedere Labs Discovers 56 OT Vulnerabilities<br/>
 <a href="https://www.forescout.com/resources/ot-icefall-report/">https://www.forescout.com/resources/ot-icefall-report/</a><br/>
Cloudflare Outage<br/>
 <a href="https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/">https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/</a><br/>
Does Acrobat Reader Unload Injection of Security Products<br/>
 <a href="https://blog.minerva-labs.com/does-acrobat-reader-unload-injection-of-security-products">https://blog.minerva-labs.com/does-acrobat-reader-unload-injection-of-security-products</a><br/>
7-Zip Mark-of-the-Web Support<br/>
 <a href="https://www.7-zip.org/history.txt">https://www.7-zip.org/history.txt</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8060" type="text/plain" language="en" />
<itunes:keywords>7zip, motw, acrobat, pdf, anti-virus, cloudflare, outage, forescout, ot, vulnerabilities, new domain, domain age, api, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8058</itunes:episode>
<itunes:subtitle>TCP Fast Open Oddities; DFSCoerce NTLM Relay; Windows ARM Update; Safari Exploit; MSIE Remnants; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TCP Fast Open Oddities; DFSCoerce NTLM Relay; Windows ARM Update; Safari Exploit; MSIE Remnants; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8058.mp3" length="5116145" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8058.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8058</link>
<pubDate>Tue, 21 Jun 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Odd TCP Fast Open Packets<br/>
 <a href="https://isc.sans.edu/forums/diary/Odd+TCP+Fast+Open+Packets+Anybody+understands+why/28766/">https://isc.sans.edu/forums/diary/Odd+TCP+Fast+Open+Packets+Anybody+understands+why/28766/</a><br/>
DFSCoerce NTLM Relay Attack<br/>
 <a href="https://github.com/Wh04m1001/DFSCoerce">https://github.com/Wh04m1001/DFSCoerce</a><br/>
 <a href="https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429">https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429</a><br/>
Windows Emergency Update Fixes Microsoft 365 Issues on ARM Devices<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-emergency-update-fixes-microsoft-365-issues-on-arm-devices/">https://www.bleepingcomputer.com/news/microsoft/windows-emergency-update-fixes-microsoft-365-issues-on-arm-devices/</a><br/>
Safari Vulnerability Analysis<br/>
 <a href="https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html">https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html</a><br/>
Internet Explorer Remnants Still an Issue<br/>
 <a href="https://www.darkreading.com/vulnerabilities-threats/internet-explorer-will-likely-remain-an-attacker-target-for-some-time">https://www.darkreading.com/vulnerabilities-threats/internet-explorer-will-likely-remain-an-attacker-target-for-some-time</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8058" type="text/plain" language="en" />
<itunes:keywords>tcp, fast open, tfo, ntlm, relay, dfscoerce, ARM, windows, update, safari, vulnerablity, internet explorer, mshtml, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8056</itunes:episode>
<itunes:subtitle>Splunk Vulnerability; Matanbuchus Malware; Office 365 Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Splunk Vulnerability; Matanbuchus Malware; Office 365 Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8056.mp3" length="7510245" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8056.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8056</link>
<pubDate>Mon, 20 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Critical Vulnerability in Splunk Enterprise Deployment Server Functionality<br/>
 <a href="https://isc.sans.edu/forums/diary/Critical+vulnerability+in+Splunk+Enterprises+deployment+server+functionality/28760/">https://isc.sans.edu/forums/diary/Critical+vulnerability+in+Splunk+Enterprises+deployment+server+functionality/28760/</a><br/>
Malspam Pushes Matanbuchus Malware Leads to Cobalt Strike<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushes+Matanbuchus+malware+leads+to+Cobalt+Strike/28752/">https://isc.sans.edu/forums/diary/Malspam+pushes+Matanbuchus+malware+leads+to+Cobalt+Strike/28752/</a><br/>
Proofpoint Discovers Potentially Dangerous Office 365 Functionality<br/>
 <a href="https://www.proofpoint.com/us/blog/cloud-security/proofpoint-discovers-potentially-dangerous-microsoft-office-365-functionality">https://www.proofpoint.com/us/blog/cloud-security/proofpoint-discovers-potentially-dangerous-microsoft-office-365-functionality</a><br/>
]]></description>
<itunes:duration>8:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8056" type="text/plain" language="en" />
<itunes:keywords>malspam, malware, matanbuchus, cobalt strike, splunk, sharepoint, ransomware, office 365, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8054</itunes:episode>
<itunes:subtitle>Houdini is Back; Drifting Cloud; FreeBSD Wifi Xploit; Csico Email Insecurity; Fastjson RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Houdini is Back; Drifting Cloud; FreeBSD Wifi Xploit; Csico Email Insecurity; Fastjson RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8054.mp3" length="5298154" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8054.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8054</link>
<pubDate>Fri, 17 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Houdini is Back Delivered Through a JavaScript Dropper<br/>
 <a href="https://isc.sans.edu/forums/diary/Houdini+is+Back+Delivered+Through+a+JavaScript+Dropper/28746/">https://isc.sans.edu/forums/diary/Houdini+is+Back+Delivered+Through+a+JavaScript+Dropper/28746/</a><br/>
Drifting Cloud: Zero-Day Sophos Firewall Exploitation<br/>
 <a href="https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/">https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/</a><br/>
Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack<br/>
 <a href="https://www.zerodayinitiative.com/blog/2022/6/15/cve-2022-23088-exploiting-a-heap-overflow-in-the-freebsd-wi-fi-stack">https://www.zerodayinitiative.com/blog/2022/6/15/cve-2022-23088-exploiting-a-heap-overflow-in-the-freebsd-wi-fi-stack</a><br/>
Cisco Email Security Appliance and Cisco Secure Email and Web Manager<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-esa-auth-bypass-66kEcxQD">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-esa-auth-bypass-66kEcxQD</a><br/>
Analyzing the Fastjson "Auto Type Bypass" RCE vulnerability<br/>
 <a href="https://jfrog.com/blog/cve-2022-25845-analyzing-the-fastjson-auto-type-bypass-rce-vulnerability/">https://jfrog.com/blog/cve-2022-25845-analyzing-the-fastjson-auto-type-bypass-rce-vulnerability/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8054" type="text/plain" language="en" />
<itunes:keywords>houdini, cisco, email, freebsd, wifi, exploit, sophos, firewall, fastjson, rce, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8052</itunes:episode>
<itunes:subtitle>Terraforming Honeypots; Zimbra Vulnerability; Cloud Middleware; Windows NFS Details; Citrix ADC; Nexans Switches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Terraforming Honeypots; Zimbra Vulnerability; Cloud Middleware; Windows NFS Details; Citrix ADC; Nexans Switches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8052.mp3" length="5314848" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8052.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8052</link>
<pubDate>Thu, 16 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Terraforming Honeypots: Using IaaC & Cloud to Attract Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Terraforming+Honeypots+Installing+DShield+Sensors+in+the+Cloud/28748/">https://isc.sans.edu/forums/diary/Terraforming+Honeypots+Installing+DShield+Sensors+in+the+Cloud/28748/</a><br/>
Zimbra Email - Stealing Clear=Text Credenitals via Memcache Injection<br/>
 <a href="https://blog.sonarsource.com/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/">https://blog.sonarsource.com/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/</a><br/>
Cloud Middleware Dataset<br/>
 <a href="https://github.com/wiz-sec/cloud-middleware-dataset">https://github.com/wiz-sec/cloud-middleware-dataset</a><br/>
CVE-2022-26937 Windows Network File System NLM Portmap Stack Buffer Overflow<br/>
 <a href="https://www.zerodayinitiative.com/blog/2022/6/7/cve-2022-26937-microsoft-windows-network-file-system-nlm-portmap-stack-buffer-overflow">https://www.zerodayinitiative.com/blog/2022/6/7/cve-2022-26937-microsoft-windows-network-file-system-nlm-portmap-stack-buffer-overflow</a><br/>
Citrix Application Delivery Management Security Bulletin<br/>
 <a href="https://support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512">https://support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512</a><br/>
Hardcoded Backdoor User and Outdated Software Components in Nexans FTTO GigaSwitch<br/>
 <a href="https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/">https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8052" type="text/plain" language="en" />
<itunes:keywords>nexans, citrix, ftto, adm, nfs, windows, cloud, middleware, zimbra, terraform, honeypot, azure, aws, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8050</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; Synlaps Azure Vuln; Hetzbleed
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; Synlaps Azure Vuln; Hetzbleed
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8050.mp3" length="6260737" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8050.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8050</link>
<pubDate>Wed, 15 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+June+2022+Patch+Tuesday/28742/">https://isc.sans.edu/forums/diary/Microsoft+June+2022+Patch+Tuesday/28742/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
SynLapse Vulnerability<br/>
 <a href="https://orca.security/resources/blog/synlapse-critical-azure-synapse-analytics-service-vulnerability/">https://orca.security/resources/blog/synlapse-critical-azure-synapse-analytics-service-vulnerability/</a><br/>
Hertzbleed Attack<br/>
 <a href="https://www.hertzbleed.com">https://www.hertzbleed.com</a><br/>
]]></description>
<itunes:duration>7:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8050" type="text/plain" language="en" />
<itunes:keywords>adobe, microsoft, follina, synlapse, hertzbleed, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8048</itunes:episode>
<itunes:subtitle>Decoding Saitama; Travis CI Leaks; Syslogk Rootkit; Mitel Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Decoding Saitama; Travis CI Leaks; Syslogk Rootkit; Mitel Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8048.mp3" length="5180056" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8048.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8048</link>
<pubDate>Tue, 14 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Translating Saitama's DNS Tunneling<br/>
 <a href="https://isc.sans.edu/forums/diary/Translating+Saitamas+DNS+tunneling+messages/28738/">https://isc.sans.edu/forums/diary/Translating+Saitamas+DNS+tunneling+messages/28738/</a><br/>
Travis CI Logs Expose Users to Cyber Attacks<br/>
 <a href="https://blog.aquasec.com/travis-ci-security">https://blog.aquasec.com/travis-ci-security</a><br/>
Linux Threat Hunting: "Syslogk" a kernel rootkit found under development in the wild<br/>
 <a href="https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/">https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/</a><br/>
Mitel Desk Phone Backdoor<br/>
 <a href="https://blog.syss.com/posts/rooting-mitel-desk-phones-through-the-backdoor/">https://blog.syss.com/posts/rooting-mitel-desk-phones-through-the-backdoor/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8048" type="text/plain" language="en" />
<itunes:keywords>mitel, phone, linux, syslogk, rootkit, travis ci, saitama, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8046</itunes:episode>
<itunes:subtitle>Exploit Prediction; PACMAN Attack; Carrier Access Panels; Malicious PyPi;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exploit Prediction; PACMAN Attack; Carrier Access Panels; Malicious PyPi;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8046.mp3" length="5514636" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8046.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8046</link>
<pubDate>Mon, 13 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[EPSScall: An Exploit Prediction Scoring System App<br/>
 <a href="https://isc.sans.edu/forums/diary/EPSScall+An+Exploit+Prediction+Scoring+System+App/28732/">https://isc.sans.edu/forums/diary/EPSScall+An+Exploit+Prediction+Scoring+System+App/28732/</a><br/>
PACMan Attack<br/>
 <a href="https://pacmanattack.com">https://pacmanattack.com</a><br/>
 <a href="https://twitter.com/wdormann/status/1535245913857351680">https://twitter.com/wdormann/status/1535245913857351680</a><br/>
Carrier LenelS2 HID Mercury access panel vulnerability<br/>
 <a href="https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-01">https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-01</a><br/>
Malicious Python Modules<br/>
 <a href="https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer/">https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer/</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8046" type="text/plain" language="en" />
<itunes:keywords>python, keep, request, requests, carrier, mercury, lenels2, pacman, epsscall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8044</itunes:episode>
<itunes:subtitle>QBot/TA570 Follina Attempt; Facebook Phishing; Zyxel Adv; Fijuisu Centricstor Vuln; Meeting Owl Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
QBot/TA570 Follina Attempt; Facebook Phishing; Zyxel Adv; Fijuisu Centricstor Vuln; Meeting Owl Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8044.mp3" length="7509670" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8044.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8044</link>
<pubDate>Fri, 10 Jun 2022 02:00:02 GMT</pubDate>
<description><![CDATA[TA570 QBot attempts to exploit CVE-2022-30190 (Follina)<br/>
 <a href="https://isc.sans.edu/forums/diary/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt/28728/">https://isc.sans.edu/forums/diary/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt/28728/</a><br/>
Analysis of a Facebook Phishing Campaign<br/>
 <a href="https://pixmsecurity.com/blog/blog/phishing-tactics-how-a-threat-actor-stole-1m-credentials-in-4-months/">https://pixmsecurity.com/blog/blog/phishing-tactics-how-a-threat-actor-stole-1m-credentials-in-4-months/</a><br/>
Zyxel Security Advisory<br/>
 <a href="https://www.zyxel.com/support/Zyxel-security-advisory-for-CRLF-injection-vulnerability-in-some-legacy-firewalls.shtml">https://www.zyxel.com/support/Zyxel-security-advisory-for-CRLF-injection-vulnerability-in-some-legacy-firewalls.shtml</a><br/>
Fujitsu Centricstor Vulnerability<br/>
 <a href="https://research.nccgroup.com/2022/05/27/technical-advisory-fujitsu-centricstor-control-center-v8-1-unauthenticated-command-injection/">https://research.nccgroup.com/2022/05/27/technical-advisory-fujitsu-centricstor-control-center-v8-1-unauthenticated-command-injection/</a><br/>
Meeting Owl Vulnerablities<br/>
 <a href="https://www.modzero.com/static/meetingowl/Meeting_Owl_Pro_Security_Disclosure_Report_RELEASE.pdf">https://www.modzero.com/static/meetingowl/Meeting_Owl_Pro_Security_Disclosure_Report_RELEASE.pdf</a><br/>
]]></description>
<itunes:duration>8:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8044" type="text/plain" language="en" />
<itunes:keywords>meetig owl, fujisu, centricstor, zyxel, facebook, phishing, qbot, follina, ta570, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8042</itunes:episode>
<itunes:subtitle>SANS RSA Panel; More Confluence; Fake CCleaner; Vebatim USB Drive Weakness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS RSA Panel; More Confluence; Fake CCleaner; Vebatim USB Drive Weakness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8042.mp3" length="5279062" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8042.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8042</link>
<pubDate>Thu, 09 Jun 2022 02:00:01 GMT</pubDate>
<description><![CDATA[SANS RSA Panel<br/>
 (sorry, video no longer available)<br/>
Atlassian Confluence Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Atlassian+Confluence+Exploits+Seen+By+Our+Honeypots+CVE202226134/28722/">https://isc.sans.edu/forums/diary/Atlassian+Confluence+Exploits+Seen+By+Our+Honeypots+CVE202226134/28722/</a><br/>
Fake CClenaer Malvertisements<br/>
 <a href="https://blog.avast.com/fakecrack-campaign">https://blog.avast.com/fakecrack-campaign</a><br/>
Weakness in Verbatim Keypad Secure USB Drive<br/>
 <a href="https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/">https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8042" type="text/plain" language="en" />
<itunes:keywords>verbatim, keypad, secure, usb, drive, ccleaner, fake, rsa, panel, atlassian, confluence, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8040</itunes:episode>
<itunes:subtitle>DogWalk Windows 0-Day; QBot uses Follina; Deadbolt Update; Android Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DogWalk Windows 0-Day; QBot uses Follina; Deadbolt Update; Android Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8040.mp3" length="4984042" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8040.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8040</link>
<pubDate>Wed, 08 Jun 2022 11:45:02 GMT</pubDate>
<description><![CDATA[The Trouble With Microsoft's Troubleshooters<br/>
 <a href="https://irsl.medium.com/the-trouble-with-microsofts-troubleshooters-6e32fc80b8bd">https://irsl.medium.com/the-trouble-with-microsofts-troubleshooters-6e32fc80b8bd</a><br/>
QBot Uses Follina<br/>
 <a href="https://twitter.com/threatinsight/status/1534227444915482625">https://twitter.com/threatinsight/status/1534227444915482625</a><br/>
Deadbolt Ransomware<br/>
 <a href="https://www.trendmicro.com/en_us/research/22/f/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-mult.html">https://www.trendmicro.com/en_us/research/22/f/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-mult.html</a><br/>
Google Android Updates<br/>
 <a href="https://source.android.com/security/bulletin/2022-06-01?hl=en">https://source.android.com/security/bulletin/2022-06-01?hl=en</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8040" type="text/plain" language="en" />
<itunes:keywords>dogwalk, windows, qbot, follina, deadbolt, android, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8038</itunes:episode>
<itunes:subtitle>Follina Analysis Helper; Obscured Phishing; Unpatched Horde RCE; Passwordstate Looses Priv. Key
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Follina Analysis Helper; Obscured Phishing; Unpatched Horde RCE; Passwordstate Looses Priv. Key
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8038.mp3" length="5603236" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8038.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8038</link>
<pubDate>Tue, 07 Jun 2022 06:30:02 GMT</pubDate>
<description><![CDATA[MS-MSDT RTF Maldocs Analysis oledump Plugins<br/>
 <a href="https://isc.sans.edu/forums/diary/msmsdt+RTF+Maldoc+Analysis+oledump+Plugins/28718/">https://isc.sans.edu/forums/diary/msmsdt+RTF+Maldoc+Analysis+oledump+Plugins/28718/</a><br/>
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners<br/>
<a href="https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/">https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/</a><br/>
Unpatched Horde Webmail Bug<br/>
 <a href="https://blog.sonarsource.com/horde-webmail-rce-via-email/">https://blog.sonarsource.com/horde-webmail-rce-via-email/</a><br/>
Clickstudio (Passwordstate) Code Signing Cert Used by Follina Malware<br/>
 <a href="https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/">https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8038" type="text/plain" language="en" />
<itunes:keywords>clickstudio, passwordstate, horde, webmail, phishing, ms-msdt, rtf, maldocs, oledump, follina, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 6th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8036</itunes:episode>
<itunes:subtitle>Simple Analysis Evasion; Confluence Exploit; Gitlab Patch; u-boot Vuln; Unisoc Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Simple Analysis Evasion; Confluence Exploit; Gitlab Patch; u-boot Vuln; Unisoc Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8036.mp3" length="4896432" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8036.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8036</link>
<pubDate>Mon, 06 Jun 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Sandbox Evasion... With Just a Filename!<br/>
 <a href="https://isc.sans.edu/forums/diary/Sandbox+Evasion+With+Just+a+Filename/28708/">https://isc.sans.edu/forums/diary/Sandbox+Evasion+With+Just+a+Filename/28708/</a><br/>
Atlassian Exploit Released<br/>
 <a href="https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/">https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/</a><br/>
GitLab Critical Security Release<br/>
 <a href="https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/">https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/</a><br/>
U-Boot Vulnerablities<br/>
 <a href="https://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/">https://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/</a><br/>
Unisoc Baseband Chip Vulnerability<br/>
 <a href="https://research.checkpoint.com/2022/vulnerability-within-the-unisoc-baseband/">https://research.checkpoint.com/2022/vulnerability-within-the-unisoc-baseband/</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8036" type="text/plain" language="en" />
<itunes:keywords>sandbox, filename, gitlab, uboot, unisoc, atlasian, confluence, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8034</itunes:episode>
<itunes:subtitle>Intro to RECmd.exe; Confluence 0-Day; JetPort Backdoor; Elasticsearch Wiper;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Intro to RECmd.exe; Confluence 0-Day; JetPort Backdoor; Elasticsearch Wiper;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8034.mp3" length="5353522" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8034.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8034</link>
<pubDate>Fri, 03 Jun 2022 10:57:34 GMT</pubDate>
<description><![CDATA[Quick Answers in Incident Response RECmd.exe<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Answers+in+Incident+Response+RECmdexe/28706/">https://isc.sans.edu/forums/diary/Quick+Answers+in+Incident+Response+RECmdexe/28706/</a><br/>
Zero-Day Exploitation of Atlassian Confluence<br/>
 <a href="https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/">https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/</a><br/>
 <a href="https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html">https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html</a><br/>
Korenix Technology JetPort Backdoor<br/>
 <a href="https://sec-consult.com/vulnerability-lab/advisory/backdoor-account-in-korenix-technology-jetport-series/">https://sec-consult.com/vulnerability-lab/advisory/backdoor-account-in-korenix-technology-jetport-series/</a><br/>
Elasticsearch Data Wiped<br/>
 <a href="https://www.secureworks.com/blog/unsecured-elasticsearch-data-replaced-with-ransom-note">https://www.secureworks.com/blog/unsecured-elasticsearch-data-replaced-with-ransom-note</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8034" type="text/plain" language="en" />
<itunes:keywords>elasticsearch, korenix, jetport, zero-day, atlassian, confluence, redmd.exe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8032</itunes:episode>
<itunes:subtitle>Better HTML Phishing; Follina Update; Windows Search Vuln; WhatsApp Takeover; Weak RSA Keys
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Better HTML Phishing; Follina Update; Windows Search Vuln; WhatsApp Takeover; Weak RSA Keys
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8032.mp3" length="5277346" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8032.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8032</link>
<pubDate>Thu, 02 Jun 2022 11:38:50 GMT</pubDate>
<description><![CDATA[HTML Phishing Attachments - Now With Anti-Analysis Features<br/>
 <a href="https://isc.sans.edu/forums/diary/HTML+phishing+attachments+now+with+antianalysis+features/28702/">https://isc.sans.edu/forums/diary/HTML+phishing+attachments+now+with+antianalysis+features/28702/</a><br/>
Unofficial Patch for CVE-2022-30190 (Follina)<br/>
 <a href="https://blog.0patch.com/2022/06/free-micropatches-for-follina-microsoft.html">https://blog.0patch.com/2022/06/free-micropatches-for-follina-microsoft.html</a><br/>
Windows Search Vulnerability<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-windows-search-zero-day-added-to-microsoft-protocol-nightmare/">https://www.bleepingcomputer.com/news/security/new-windows-search-zero-day-added-to-microsoft-protocol-nightmare/</a><br/>
Call Forwarding Used to Compromise WhatsApp Accounts<br/>
 <a href="https://www.linkedin.com/posts/fb1h2s_beware-here-is-how-whatsapp-accounts-are-activity-6934386561048264704-NnFf/?utm_source=linkedin_share&utm_medium=member_desktop_web">https://www.linkedin.com/posts/fb1h2s_beware-here-is-how-whatsapp-accounts-are-activity-6934386561048264704-NnFf/?utm_source=linkedin_share&utm_medium=member_desktop_web</a><br/>
Badkeys in Fuji Xerox and Canon Printers<br/>
 <a href="https://fermatattack.secvuln.info">https://fermatattack.secvuln.info</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8032" type="text/plain" language="en" />
<itunes:keywords>badkeys, fuji, xeros, canon, rsa, fermat, whatsapp, windows, search, follina, phishing, html, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8030</itunes:episode>
<itunes:subtitle>Follina Update; OAS Platform Vuln; Exposed MySQL;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Follina Update; OAS Platform Vuln; Exposed MySQL;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8030.mp3" length="4757965" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8030.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8030</link>
<pubDate>Wed, 01 Jun 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Follina Update<br/>
 <a href="https://isc.sans.edu/forums/diary/First+Exploitation+of+Follina+Seen+in+the+Wild/28698/">https://isc.sans.edu/forums/diary/First+Exploitation+of+Follina+Seen+in+the+Wild/28698/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme+CVE202230190/28694/">https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme+CVE202230190/28694/</a><br/>
Open Automation Software Platform Vulnerability<br/>
 <a href="https://blog.talosintelligence.com/2022/05/vuln-spotlight-open-automation-platform.html">https://blog.talosintelligence.com/2022/05/vuln-spotlight-open-automation-platform.html</a><br/>
Over 3.6 million MySQL servers found exposed on the Internet<br/>
 <a href="https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/">https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8030" type="text/plain" language="en" />
<itunes:keywords>follina, ms-msdt, oas, open automation software, mysql, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 31st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8028</itunes:episode>
<itunes:subtitle>Microsoft Office MS-MSDT URL Scheme Exploit (0-Day) #follina
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Office MS-MSDT URL Scheme Exploit (0-Day) #follina
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8028.mp3" length="6849512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8028.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8028</link>
<pubDate>Mon, 30 May 2022 20:59:37 GMT</pubDate>
<description><![CDATA[New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme/28694/">https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme/28694/</a><br/>
]]></description>
<itunes:duration>7:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8028" type="text/plain" language="en" />
<itunes:keywords>microsoft, ms-msdt, debug tool, follina, office, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 27th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8026</itunes:episode>
<itunes:subtitle>Huge Signed PE Files; CVE-2022-22972 PoC; BMC Vuln.; Trend Micro vs. MSFT Patch; Nate Street @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Huge Signed PE Files; CVE-2022-22972 PoC; BMC Vuln.; Trend Micro vs. MSFT Patch; Nate Street @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8026.mp3" length="13464414" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8026.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8026</link>
<pubDate>Fri, 27 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Huge Signed PE Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Huge+Signed+PE+File/28686/">https://isc.sans.edu/forums/diary/Huge+Signed+PE+File/28686/</a><br/>
VMWare Authentication Bypass PoC<br/>
 <a href="https://www.horizon3.ai/vmware-authentication-bypass-vulnerability-cve-2022-22972-technical-deep-dive/">https://www.horizon3.ai/vmware-authentication-bypass-vulnerability-cve-2022-22972-technical-deep-dive/</a><br/>
Quanta Server BMC Vulnerability<br/>
 <a href="https://eclypsium.com/2022/05/26/quanta-servers-still-vulnerable-to-pantsdown/">https://eclypsium.com/2022/05/26/quanta-servers-still-vulnerable-to-pantsdown/</a><br/>
Windows 11 and Server 2022 Update Prevent Trend Micro Ransomware Protection<br/>
 <a href="https://success.trendmicro.com/dcx/s/solution/000291066?language=en_US">https://success.trendmicro.com/dcx/s/solution/000291066?language=en_US</a><br/>
Nate Street: Advancing SIEM Log Management Strategies through Vendor-Agnostic Measurement<br/>
 <a href="https://www.sans.edu/cyber-research/38685/">https://www.sans.edu/cyber-research/38685/</a><br/>
]]></description>
<itunes:duration>15:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8026" type="text/plain" language="en" />
<itunes:keywords>siem, sans_edu, windows 11, server 2022, quanta, bmc, huge file, vmware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 26th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8024</itunes:episode>
<itunes:subtitle>nmap resolve all; Unethical Research; Heroku GibHub Update; Tails Vuln; Chrome Bugs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
nmap resolve all; Unethical Research; Heroku GibHub Update; Tails Vuln; Chrome Bugs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8024.mp3" length="4638177" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8024.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8024</link>
<pubDate>Thu, 26 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Using NMAP to Assess Hosts in Load Balanced Clusters<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+NMAP+to+Assess+Hosts+in+Load+Balanced+Clusters/28682/">https://isc.sans.edu/forums/diary/Using+NMAP+to+Assess+Hosts+in+Load+Balanced+Clusters/28682/</a><br/>
Attacker Modifying Libraries Claims "Research"<br/>
 <a href="https://www.bleepingcomputer.com/news/security/hacker-says-hijacking-libraries-stealing-aws-keys-was-ethical-research/">https://www.bleepingcomputer.com/news/security/hacker-says-hijacking-libraries-stealing-aws-keys-was-ethical-research/</a><br/>
Heroku GitHub Integration Re-Enabled Again<br/>
 <a href="https://blog.heroku.com/github-integration-update">https://blog.heroku.com/github-integration-update</a><br/>
Serious security vulnerablity in Tails 5.0<br/>
 <a href="https://tails.boum.org/security/prototype_pollution/index.en.html">https://tails.boum.org/security/prototype_pollution/index.en.html</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html">https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8024" type="text/plain" language="en" />
<itunes:keywords>google, chrome, tail, firefox, github, heroku, nmap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8022</itunes:episode>
<itunes:subtitle>Python/PHP Library Backdoor; Zoom Patches; VMWare Exploit; Zyxel Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python/PHP Library Backdoor; Zoom Patches; VMWare Exploit; Zyxel Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8022.mp3" length="4755201" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8022.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8022</link>
<pubDate>Wed, 25 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[ctx Python Library Updated with "Extra" Features<br/>
 <a href="https://isc.sans.edu/forums/diary/ctx+Python+Library+Updated+with+Extra+Features/28678/">https://isc.sans.edu/forums/diary/ctx+Python+Library+Updated+with+Extra+Features/28678/</a><br/>
Zoom Updates<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
VMWare Exploit About to Be Released<br/>
 <a href="https://twitter.com/Horizon3Attack/status/1528935531333177344">https://twitter.com/Horizon3Attack/status/1528935531333177344</a><br/>
Zyxel Firewalls, AP Controllers, APs Patch<br/>
 <a href="https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml">https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8022" type="text/plain" language="en" />
<itunes:keywords>zyxel, vmware, horizon3, zoom, ctx, php, python, pypi, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 24th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8020</itunes:episode>
<itunes:subtitle>jQuery-File-Upload Scans; Oracle OOB Patch; NPM Hijack Detection; Account Pre-Hijacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
jQuery-File-Upload Scans; Oracle OOB Patch; NPM Hijack Detection; Account Pre-Hijacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8020.mp3" length="4875421" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8020.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8020</link>
<pubDate>Tue, 24 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Attacker Scanning for jQuery-File-Upload<br/>
 <a href="https://isc.sans.edu/forums/diary/Attacker+Scanning+for+jQueryFileUpload/28674/">https://isc.sans.edu/forums/diary/Attacker+Scanning+for+jQueryFileUpload/28674/</a><br/>
Oracle Security Alert Advisory - CVE-2022-21500<br/>
 <a href="https://www.oracle.com/security-alerts/alert-cve-2022-21500.html">https://www.oracle.com/security-alerts/alert-cve-2022-21500.html</a><br/>
How to find NPM dependencies vulnerable to account hijacking<br/>
 <a href="https://www.theregister.com/2022/05/23/npm_dependencies_vulnerable/">https://www.theregister.com/2022/05/23/npm_dependencies_vulnerable/</a><br/>
Pre-hijacked accounts<br/>
 <a href="https://arxiv.org/pdf/2205.10174.pdf">https://arxiv.org/pdf/2205.10174.pdf</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8020" type="text/plain" language="en" />
<itunes:keywords>jquery, hijacking, file upload, oracle, npm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 23rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8018</itunes:episode>
<itunes:subtitle>Zip bomb AV Evasion; Cisco Redis Patch; pwn2own Results; Cobalt Strike via PyPi; Netgear No Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zip bomb AV Evasion; Cisco Redis Patch; pwn2own Results; Cobalt Strike via PyPi; Netgear No Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8018.mp3" length="5491237" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8018.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8018</link>
<pubDate>Mon, 23 May 2022 02:00:01 GMT</pubDate>
<description><![CDATA[A "Zip Bomb" to Bypass Security Controls & Sandboxes<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Zip+Bomb+to+Bypass+Security+Controls+Sandboxes/28670/">https://isc.sans.edu/forums/diary/A+Zip+Bomb+to+Bypass+Security+Controls+Sandboxes/28670/</a><br/>
Cisco IOS XR Software Health Check Open Port Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-redis-ABJyE5xK">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-redis-ABJyE5xK</a><br/>
pwn2own Vancouver 2022 Results<br/>
 <a href="https://www.zerodayinitiative.com/blog/2022/5/18/pwn2own-vancouver-2022-the-results#three">https://www.zerodayinitiative.com/blog/2022/5/18/pwn2own-vancouver-2022-the-results#three</a><br/>
Malicious PyPi Packages Drop Cobalt Strike<br/>
 <a href="https://blog.sonatype.com/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux">https://blog.sonatype.com/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux</a><br/>
Security Advisory for BR200, BR500 and PSV-2021-0286<br/>
 <a href="https://kb.netgear.com/000064712/Security-Advisory-for-Multiple-Security-Vulnerabilities-on-BR200-and-BR500-PSV-2021-0286">https://kb.netgear.com/000064712/Security-Advisory-for-Multiple-Security-Vulnerabilities-on-BR200-and-BR500-PSV-2021-0286</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8018" type="text/plain" language="en" />
<itunes:keywords>netgear, br200, br500, pypi, cobalt strike, pwn2own, zipbomb, cisco, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8016</itunes:episode>
<itunes:subtitle>Bumblebee via TransferXL; MSFT OOB Update; SonicWall SMA1000; QNAP Deadbolt; DOJ Policy Update; Exposed Kubernetes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bumblebee via TransferXL; MSFT OOB Update; SonicWall SMA1000; QNAP Deadbolt; DOJ Policy Update; Exposed Kubernetes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8016.mp3" length="5361421" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8016.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8016</link>
<pubDate>Fri, 20 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Bumblebee Malware from TransferXL URLs<br/>
 <a href="https://isc.sans.edu/forums/diary/Bumblebee+Malware+from+TransferXL+URLs/28664/">https://isc.sans.edu/forums/diary/Bumblebee+Malware+from+TransferXL+URLs/28664/</a><br/>
Microsoft Out-of-Band Update fixes Authentication Issues<br/>
 <a href="https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#you-might-see-authentication-failures-on-the-server-or-client-for-services">https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#you-might-see-authentication-failures-on-the-server-or-client-for-services</a><br/>
Sonicwall Patch for SMA 1000<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0010">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0010</a><br/>
QNAP NAS Deadbolt Ransomware<br/>
 <a href="https://www.qnap.com/en/security-news/2022/take-immediate-actions-to-secure-qnap-nas-and-update-qts-to-the-latest-available-version">https://www.qnap.com/en/security-news/2022/take-immediate-actions-to-secure-qnap-nas-and-update-qts-to-the-latest-available-version</a><br/>
380,000 open Kubernetes API Servers<br/>
 <a href="https://www.shadowserver.org/news/over-380-000-open-kubernetes-api-servers/">https://www.shadowserver.org/news/over-380-000-open-kubernetes-api-servers/</a><br/>
Doj Annnounces New Polciy for Charging Cases under the Computer Fraud and Abuse Act<br/>
 <a href="https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act">https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8016" type="text/plain" language="en" />
<itunes:keywords>Bumblebee, sonicwall, windows, patch, AD, qnap, deadbolt, kubernetes, doj, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8014</itunes:episode>
<itunes:subtitle>VMWare Flaws; Tesla BLE Attacks; Credit Card Scraping; MSFT DAP to GDAP Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VMWare Flaws; Tesla BLE Attacks; Credit Card Scraping; MSFT DAP to GDAP Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8014.mp3" length="6019996" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8014.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8014</link>
<pubDate>Thu, 19 May 2022 02:00:01 GMT</pubDate>
<description><![CDATA[VMWare Flaws<br/>
 <a href="https://core.vmware.com/vmsa-2022-0014-questions-answers-faq">https://core.vmware.com/vmsa-2022-0014-questions-answers-faq</a><br/>
 <a href="https://blog.barracuda.com/2022/05/17/threat-spotlight-attempts-to-exploit-new-vmware-vulnerabilities/">https://blog.barracuda.com/2022/05/17/threat-spotlight-attempts-to-exploit-new-vmware-vulnerabilities/</a><br/>
Tesla BLE Proximity Authentication Vulnerable to Relay Attacks<br/>
 <a href="https://research.nccgroup.com/2022/05/15/technical-advisory-ble-proximity-authentication-vulnerable-to-relay-attacks/">https://research.nccgroup.com/2022/05/15/technical-advisory-ble-proximity-authentication-vulnerable-to-relay-attacks/</a><br/>
Credit Card Scraping via Malicious PHP Code<br/>
 <a href="https://www.ic3.gov/Media/News/2022/220516.pdf">https://www.ic3.gov/Media/News/2022/220516.pdf</a><br/>
Microsoft updating Delegated Admin Privileges<br/>
 <a href="https://docs.microsoft.com/en-gb/partner-center/announcements/2022-may#13">https://docs.microsoft.com/en-gb/partner-center/announcements/2022-may#13</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8014" type="text/plain" language="en" />
<itunes:keywords>microsoft, credit card, php, tesla, bluetooth, ble, vmware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8012</itunes:episode>
<itunes:subtitle>Chrome Browser Wallet; SQL Server Attacks; macOS Malware; Spring/Zyxel Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chrome Browser Wallet; SQL Server Attacks; macOS Malware; Spring/Zyxel Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8012.mp3" length="5478652" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8012.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8012</link>
<pubDate>Wed, 18 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Use Your Browser Internal Password Vault... or Not?<br/>
 <a href="https://isc.sans.edu/forums/diary/Use+Your+Browser+Internal+Password+Vault+or+Not/28658/">https://isc.sans.edu/forums/diary/Use+Your+Browser+Internal+Password+Vault+or+Not/28658/</a><br/>
SQL Server Brute Forcing<br/>
 <a href="https://twitter.com/MsftSecIntel/status/1526680337216114693">https://twitter.com/MsftSecIntel/status/1526680337216114693</a><br/>
UpdateAgent Adapts Again<br/>
 <a href="https://www.jamf.com/blog/updateagent-adapts-again/">https://www.jamf.com/blog/updateagent-adapts-again/</a><br/>
Updated Exploited Vulnerabilities<br/>
 <a href="https://www.cisa.gov/uscert/ncas/current-activity/2022/05/10/cisa-adds-one-known-exploited-vulnerability-catalog">https://www.cisa.gov/uscert/ncas/current-activity/2022/05/10/cisa-adds-one-known-exploited-vulnerability-catalog</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8012" type="text/plain" language="en" />
<itunes:keywords>spring, zyxel, updateagent, macos, sql server, browser, chrome, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8010</itunes:episode>
<itunes:subtitle>Apple Updates; Evil Never Sleeps; JS Tracker Keystroke Logging
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Evil Never Sleeps; JS Tracker Keystroke Logging
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8010.mp3" length="5598070" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8010.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8010</link>
<pubDate>Tue, 17 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Patches Everything<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28654/">https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28654/</a><br/>
Evil Never Sleeps: When Wireless Malware Stays on After Turning Off iPhones<br/>
 <a href="https://arxiv.org/pdf/2205.06114.pdf">https://arxiv.org/pdf/2205.06114.pdf</a><br/>
Third-Party Web Trackers Log What You Type Before Submitting<br/>
 <a href="https://homes.esat.kuleuven.be/~asenol/leaky-forms/">https://homes.esat.kuleuven.be/~asenol/leaky-forms/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8010" type="text/plain" language="en" />
<itunes:keywords>web trackers, javascript, keystroke logging, bluetooth, iphone, uwb, patches, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8008</itunes:episode>
<itunes:subtitle>BIG-IP Review; Sonicwall Patch; Zonealarm Priv Esc Vuln; Taking over npm account
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BIG-IP Review; Sonicwall Patch; Zonealarm Priv Esc Vuln; Taking over npm account
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8008.mp3" length="5715233" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8008.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8008</link>
<pubDate>Mon, 16 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[From 0-Day to Mirai: 7 days of BIG-IP Exploits<br/>
 <a href="https://isc.sans.edu/forums/diary/From+0Day+to+Mirai+7+days+of+BIGIP+Exploits/28644/">https://isc.sans.edu/forums/diary/From+0Day+to+Mirai+7+days+of+BIGIP+Exploits/28644/</a><br/>
Sonicwall Vulnerabilities Patched<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0009">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0009</a><br/>
Zonealarm Patch<br/>
 <a href="https://www.zonealarm.com/software/extreme-security/release-history">https://www.zonealarm.com/software/extreme-security/release-history</a><br/>
Taking over npm account<br/>
 <a href="https://thehackerblog.com/zero-days-without-incident-compromising-angular-via-expired-npm-publisher-email-domains-7kZplW4x/">https://thehackerblog.com/zero-days-without-incident-compromising-angular-via-expired-npm-publisher-email-domains-7kZplW4x/</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8008" type="text/plain" language="en" />
<itunes:keywords>npm, zonealarm, sonicwall, big-ip, f5, mirai, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8006</itunes:episode>
<itunes:subtitle>Get-WebRequest Fails; HP BIOS Patch; INTEL BIOS Patch; Zyxel RCE;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Get-WebRequest Fails; HP BIOS Patch; INTEL BIOS Patch; Zyxel RCE;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8006.mp3" length="4475032" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8006.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8006</link>
<pubDate>Fri, 13 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[When Get-WebRequest Fails You<br/>
 <a href="https://isc.sans.edu/forums/diary/When+GetWebRequest+Fails+You/28640/">https://isc.sans.edu/forums/diary/When+GetWebRequest+Fails+You/28640/</a><br/>
HP PC BIOS Security Updates<br/>
 <a href="https://support.hp.com/us-en/document/ish_6184733-6184761-16/hpsbhf03788">https://support.hp.com/us-en/document/ish_6184733-6184761-16/hpsbhf03788</a><br/>
INTEL BIOS Advisory<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.html</a><br/>
Zyxel RCE Vulnerability<br/>
 <a href="https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/">https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/</a><br/>
]]></description>
<itunes:duration>4:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8006" type="text/plain" language="en" />
<itunes:keywords>get-webrequest, bios, hp, intel, zyxel, firewall, rce, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8004</itunes:episode>
<itunes:subtitle>ISO Bumblebee Files; Google Drive Malware; Vanity URL Abuse; not so advanced npm attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ISO Bumblebee Files; Google Drive Malware; Vanity URL Abuse; not so advanced npm attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8004.mp3" length="4967342" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8004.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8004</link>
<pubDate>Thu, 12 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[TA578 Using Thread-Hijacked Emails to Push ISO Files for Bumblebee Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/TA578+using+threadhijacked+emails+to+push+ISO+files+for+Bumblebee+malware/28636/">https://isc.sans.edu/forums/diary/TA578+using+threadhijacked+emails+to+push+ISO+files+for+Bumblebee+malware/28636/</a><br/>
Google Drive Emerges as Top App for Malware Downloads<br/>
 <a href="https://www.helpnetsecurity.com/2022/05/11/malicious-pdf-search-engines/">https://www.helpnetsecurity.com/2022/05/11/malicious-pdf-search-engines/</a><br/>
Vanity URL Abuse<br/>
 <a href="https://www.varonis.com/blog/url-spoofing">https://www.varonis.com/blog/url-spoofing</a><br/>
npm Supply Chain Attack Turns Out to be Part of Penetration Test<br/>
 <a href="https://jfrog.com/blog/npm-supply-chain-attack-targets-german-based-companies/">https://jfrog.com/blog/npm-supply-chain-attack-targets-german-based-companies/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8004" type="text/plain" language="en" />
<itunes:keywords>npm, vanity, url, google drive, malware, pdf, ta578, iso, bumblebee, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8002</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates; npm foreach;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Updates; npm foreach;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8002.mp3" length="4959233" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8002.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8002</link>
<pubDate>Wed, 11 May 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft May 2022 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+May+2022+Patch+Tuesday/28632/">https://isc.sans.edu/forums/diary/Microsoft+May+2022+Patch+Tuesday/28632/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
npm "foreach" package domain takeover<br/>
 <a href="https://www.theregister.com/2022/05/10/security_npm_email/">https://www.theregister.com/2022/05/10/security_npm_email/</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8002" type="text/plain" language="en" />
<itunes:keywords>npm, foreach, domain, email, adobe, microsoft, may, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>8000</itunes:episode>
<itunes:subtitle>Octopus Backdoor is Back; CVE-2022-1388 (BIG-IP) Exploits; Trend Micro Fix; Azure RCE Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Octopus Backdoor is Back; CVE-2022-1388 (BIG-IP) Exploits; Trend Micro Fix; Azure RCE Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/8000.mp3" length="5224849" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/8000.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/8000</link>
<pubDate>Tue, 10 May 2022 02:10:01 GMT</pubDate>
<description><![CDATA[Octopus Backdoor is Back with a New Embedded Obfuscated Bat File<br/>
 <a href="https://isc.sans.edu/forums/diary/Octopus+Backdoor+is+Back+with+a+New+Embedded+Obfuscated+Bat+File/28628/#comments">https://isc.sans.edu/forums/diary/Octopus+Backdoor+is+Back+with+a+New+Embedded+Obfuscated+Bat+File/28628/#comments</a><br/>
CVE-2022-1388 (BIG-IP) Exploits<br/>
 <a href="https://twitter.com/sans_isc/status/1523741896707043328">https://twitter.com/sans_isc/status/1523741896707043328</a><br/>
 <a href="https://github.com/horizon3ai/CVE-2022-1388">https://github.com/horizon3ai/CVE-2022-1388</a><br/>
Trend Micro False Positive Aftermath<br/>
 <a href="https://success.trendmicro.com/dcx/s/solution/000290966?language=en_US">https://success.trendmicro.com/dcx/s/solution/000290966?language=en_US</a><br/>
Microsoft Azure<br/>
 <a href="https://orca.security/resources/blog/azure-synapse-analytics-security-advisory/">https://orca.security/resources/blog/azure-synapse-analytics-security-advisory/</a><br/>
 <a href="https://msrc-blog.microsoft.com/2022/05/09/vulnerability-mitigated-in-the-third-party-data-connector-used-in-azure-synapse-pipelines-and-azure-data-factory-cve-2022-29972/">https://msrc-blog.microsoft.com/2022/05/09/vulnerability-mitigated-in-the-third-party-data-connector-used-in-azure-synapse-pipelines-and-azure-data-factory-cve-2022-29972/</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=8000" type="text/plain" language="en" />
<itunes:keywords>orca, msrc, microsoft, azure, synapse, trend micro, big-ip, bigip, f5, octopus, backdoor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7998</itunes:episode>
<itunes:subtitle>BIG IP Vuln; QNAP Update; Raspberry Robin; rubygems flaw;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BIG IP Vuln; QNAP Update; Raspberry Robin; rubygems flaw;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7998.mp3" length="5248464" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7998.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7998</link>
<pubDate>Mon, 09 May 2022 02:00:01 GMT</pubDate>
<description><![CDATA[F5 BIG-IP Unauthenticated RCE Vulnerability (CVE-2022-1388)<br/>
 <a href="https://isc.sans.edu/forums/diary/F5+BIGIP+Unauthenticated+RCE+Vulnerability+CVE20221388/28624/">https://isc.sans.edu/forums/diary/F5+BIGIP+Unauthenticated+RCE+Vulnerability+CVE20221388/28624/</a><br/>
QNAP QVR Update<br/>
 <a href="https://www.qnap.com/de-de/security-advisory/qsa-22-07">https://www.qnap.com/de-de/security-advisory/qsa-22-07</a><br/>
Raspberry Robin Worm<br/>
 <a href="https://redcanary.com/blog/raspberry-robin/">https://redcanary.com/blog/raspberry-robin/</a><br/>
rubygems CVE-2022-29176 explained<br/>
 <a href="https://greg.molnar.io/blog/rubygems-cve-2022-29176/">https://greg.molnar.io/blog/rubygems-cve-2022-29176/</a><br/>
What is the simples malware in the world?<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+the+simplest+malware+in+the+world/28620/">https://isc.sans.edu/forums/diary/What+is+the+simplest+malware+in+the+world/28620/</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7998" type="text/plain" language="en" />
<itunes:keywords>fork bomb, malware, windows, ruby, gems, raspberry, robin, worm, usb, qnap, big-ip, f5, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 6th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7996</itunes:episode>
<itunes:subtitle>Excel to Remcos RAT; FIDO Support; Heroku Breach
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Excel to Remcos RAT; FIDO Support; Heroku Breach
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7996.mp3" length="5013977" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7996.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7996</link>
<pubDate>Fri, 06 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Password-protected Excel Spreadsheet Pushes Remcos RAT<br/>
 <a href="https://isc.sans.edu/forums/diary/Passwordprotected+Excel+spreadsheet+pushes+Remcos+RAT/28616/">https://isc.sans.edu/forums/diary/Passwordprotected+Excel+spreadsheet+pushes+Remcos+RAT/28616/</a><br/>
Microsoft, Apple, Google Accelated FIDO Standard Implementation<br/>
 <a href="https://www.theregister.com/2022/05/05/microsoft-apple-google-fido/">https://www.theregister.com/2022/05/05/microsoft-apple-google-fido/</a><br/>
Heroku Admits Breach<br/>
 <a href="https://status.heroku.com/incidents/2413">https://status.heroku.com/incidents/2413</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7996" type="text/plain" language="en" />
<itunes:keywords>heroku, microsoft, apple, google, heroku, excel, remcos rat, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 5th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7994</itunes:episode>
<itunes:subtitle>Windows Last Patched Day; Fake Updates; Malvuln; Cisco Patches; F5 Big IP iControl REST
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Last Patched Day; Fake Updates; Malvuln; Cisco Patches; F5 Big IP iControl REST
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7994.mp3" length="5266690" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7994.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7994</link>
<pubDate>Thu, 05 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Finding the Real "Last Patched" Day (Interim Version)<br/>
 <a href="https://isc.sans.edu/forums/diary/Finding+the+Real+Last+Patched+Day+Interim+Version/28610/">https://isc.sans.edu/forums/diary/Finding+the+Real+Last+Patched+Day+Interim+Version/28610/</a><br/>
Fake Windows Updates Install Ransomware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fake-windows-10-updates-infect-you-with-magniber-ransomware/">https://www.bleepingcomputer.com/news/security/fake-windows-10-updates-infect-you-with-magniber-ransomware/</a><br/>
Vulnerablities in Ransomware<br/>
 <a href="https://www.malvuln.com">https://www.malvuln.com</a><br/>
Heroku Forces Password Reset<br/>
 <a href="https://status.heroku.com/incidents/2413">https://status.heroku.com/incidents/2413</a><br/>
Cisco Patches Enterprise NFV Infrastructure Software<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9</a><br/>
Big-IP iControl REST Vulnerability<br/>
 <a href="https://support.f5.com/csp/article/K23605346">https://support.f5.com/csp/article/K23605346</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7994" type="text/plain" language="en" />
<itunes:keywords>f5, big-ip, cisco, heroku, malvuln, ransomware, patches, windows, fake updates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7992</itunes:episode>
<itunes:subtitle>Honeypot Updates; NanoSSL Vuln; uClibc DNS Bugs; AV Exploits; Trend Micro Flase Positive #GOSENTINELS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Honeypot Updates; NanoSSL Vuln; uClibc DNS Bugs; AV Exploits; Trend Micro Flase Positive #GOSENTINELS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7992.mp3" length="5481212" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7992.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7992</link>
<pubDate>Wed, 04 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Some Honeypot Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Some+Honeypot+Updates/28608/">https://isc.sans.edu/forums/diary/Some+Honeypot+Updates/28608/</a><br/>
TLStorm 2 - NanoSSL TLS Library Misuse<br/>
 <a href="https://www.armis.com/blog/tlstorm-2-nanossl-tls-library-misuse-leads-to-vulnerabilities-in-common-switches/">https://www.armis.com/blog/tlstorm-2-nanossl-tls-library-misuse-leads-to-vulnerabilities-in-common-switches/</a><br/>
Unpatched DNS Bug in uClibc and uClibc-ng Library<br/>
 <a href="https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-DNS-bug-in-popular-c-standard-library-putting-iot-at-risk/">https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-DNS-bug-in-popular-c-standard-library-putting-iot-at-risk/</a><br/>
Abusing Security Software to Sideload PlugX and ShadowPad<br/>
 <a href="https://www.sentinelone.com/labs/moshen-dragons-triad-and-error-approach-abusing-security-software-to-sideload-plugx-and-shadowpad/">https://www.sentinelone.com/labs/moshen-dragons-triad-and-error-approach-abusing-security-software-to-sideload-plugx-and-shadowpad/</a><br/>
Microsoft Edge Update Triggers Trend Micro AV<br/>
 <a href="https://success.trendmicro.com/forum/s/question/0D54T00001QDqzgSAD/we-are-getting-this-message-from-every-client-since-several-minutesis-it-a-false-positiv-error-or-do-we-have-a-real-trojaner-problem-">https://success.trendmicro.com/forum/s/question/0D54T00001QDqzgSAD/we-are-getting-this-message-from-every-client-since-several-minutesis-it-a-false-positiv-error-or-do-we-have-a-real-trojaner-problem-</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7992" type="text/plain" language="en" />
<itunes:keywords>edge, trend micro, microsoft, plugx, shadowpad, dns, queryid, uclibc, tlstorm, nanossl, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7990</itunes:episode>
<itunes:subtitle>VSTO Office Files; Gmail SMTP Relay; OpenSSF Package Analysis; M1 Prefetcher Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VSTO Office Files; Gmail SMTP Relay; OpenSSF Package Analysis; M1 Prefetcher Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7990.mp3" length="5138772" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7990.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7990</link>
<pubDate>Tue, 03 May 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Detecting VSTO Office Files with ExifTool<br/>
 <a href="https://isc.sans.edu/forums/diary/Detecting+VSTO+Office+Files+With+ExifTool/28604/">https://isc.sans.edu/forums/diary/Detecting+VSTO+Office+Files+With+ExifTool/28604/</a><br/>
The Gmail SMTP Relay Service Exploit<br/>
 <a href="https://www.avanan.com/blog/the-gmail-smtp-relay-service-exploit">https://www.avanan.com/blog/the-gmail-smtp-relay-service-exploit</a><br/>
OpenSSF Package Analysis<br/>
 <a href="https://openssf.org/blog/2022/04/28/introducing-package-analysis-scanning-open-source-packages-for-malicious-behavior/">https://openssf.org/blog/2022/04/28/introducing-package-analysis-scanning-open-source-packages-for-malicious-behavior/</a><br/>
M1 Prefetcher Data Leak<br/>
 <a href="https://www.prefetchers.info">https://www.prefetchers.info</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7990" type="text/plain" language="en" />
<itunes:keywords>M1, apple, prefetcher, openssf, gmail, smtp, vsto, office, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7988</itunes:episode>
<itunes:subtitle>Passive DNS; Microsoft Edge "VPN"; Weibo Making IPs Public; SonicWall Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Passive DNS; Microsoft Edge "VPN"; Weibo Making IPs Public; SonicWall Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7988.mp3" length="4335070" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7988.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7988</link>
<pubDate>Mon, 02 May 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Using Passive DNS Sources for Reconnaissance and Enumeration<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Passive+DNS+sources+for+Reconnaissance+and+Enumeration/28596/">https://isc.sans.edu/forums/diary/Using+Passive+DNS+sources+for+Reconnaissance+and+Enumeration/28596/</a><br/>
Microsoft Edge Secure Network<br/>
 <a href="https://support.microsoft.com/en-gb/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318">https://support.microsoft.com/en-gb/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318</a><br/>
Sina Weibo Making Users IPs and Location Public<br/>
 <a href="https://www.theregister.com/2022/04/29/weibo_location_services_default/">https://www.theregister.com/2022/04/29/weibo_location_services_default/</a><br/>
 <a href="https://weibo.com/u/1934183965?layerid=4763194269108760">https://weibo.com/u/1934183965?layerid=4763194269108760</a><br/>
SonicWall Global VPN Client DLL Search Order Hijacking<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0036">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0036</a><br/>
Zoom Updated<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
]]></description>
<itunes:duration>4:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7988" type="text/plain" language="en" />
<itunes:keywords>zoom, sonicwall, vpn, dll hijack, sina, weibo, edge secure network, microsoft, passive dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 29th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7986</itunes:episode>
<itunes:subtitle>SMB/RPC Honeypot Results; Azure PostgreSQL Priv Esc; GitHub Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SMB/RPC Honeypot Results; Azure PostgreSQL Priv Esc; GitHub Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7986.mp3" length="5604354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7986.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7986</link>
<pubDate>Fri, 29 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[A Day of SMB: What does our SMB/RPC Honeypot see? CVE-2022-26809<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Day+of+SMB+What+does+our+SMBRPC+Honeypot+see+CVE202226809/28594/">https://isc.sans.edu/forums/diary/A+Day+of+SMB+What+does+our+SMBRPC+Honeypot+see+CVE202226809/28594/</a><br/>
Azure PostgreSQL Privilege Escalation<br/>
 <a href="https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/">https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/</a><br/>
Security alert: Attack campaign involving stolen OAuth user tokens<br/>
 <a href="https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens">https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens</a><br/>
Netatalk Vulnerability Affecting Synology, QNAP, Others?<br/>
 <a href="https://www.synology.com/en-global/security/advisory/Synology_SA_22_06">https://www.synology.com/en-global/security/advisory/Synology_SA_22_06</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7986" type="text/plain" language="en" />
<itunes:keywords>netatalk, linux, qnap, synology, oauth, travis ci, postgrasql, heroku, azure, smb, rpc, honeypot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7984</itunes:episode>
<itunes:subtitle>MITRE ATT&amp;CK Update; MSFT Ukraine Report; Nimuspwn; npm Package Planting
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MITRE ATT&amp;CK Update; MSFT Ukraine Report; Nimuspwn; npm Package Planting
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7984.mp3" length="5448748" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7984.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7984</link>
<pubDate>Thu, 28 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[MITRE ATT&CK v11<br/>
 <a href="https://isc.sans.edu/forums/diary/MITRE+ATTCK+v11+a+small+update+that+can+help+not+just+with+detection+engineering/28590/">https://isc.sans.edu/forums/diary/MITRE+ATTCK+v11+a+small+update+that+can+help+not+just+with+detection+engineering/28590/</a><br/>
Microsoft Special Report: Ukraine<br/>
 <a href="https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Vwwd">https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Vwwd</a><br/>
Linux Privilege Escalation Nimbuspwn<br/>
 <a href="https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/">https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/</a><br/>
npm Package Planting<br/>
 <a href="https://blog.aquasec.com/npm-package-planting">https://blog.aquasec.com/npm-package-planting</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7984" type="text/plain" language="en" />
<itunes:keywords>npm, linux, nimbuspwn, privilege escalation, ukraine, microsoft, attck, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 27th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7982</itunes:episode>
<itunes:subtitle>WSO2 Vuln Exploited; Core Impact via VMware; VirusTotal Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WSO2 Vuln Exploited; Core Impact via VMware; VirusTotal Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7982.mp3" length="5652716" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7982.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7982</link>
<pubDate>Wed, 27 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[WSO2 Vuln Exploited to Install Crypto Coin Miners<br/>
 <a href="https://isc.sans.edu/forums/diary/WSO2+RCE+exploited+in+the+wild/28586/">https://isc.sans.edu/forums/diary/WSO2+RCE+exploited+in+the+wild/28586/</a><br/>
Core Impact Backdoor Delivered Via VMware Vulnerablity<br/>
 <a href="https://blog.morphisec.com/vmware-identity-manager-attack-backdoor">https://blog.morphisec.com/vmware-identity-manager-attack-backdoor</a><br/>
VirusTotal Exploit Update<br/>
 <a href="https://twitter.com/bquintero/status/1518738072820670464">https://twitter.com/bquintero/status/1518738072820670464</a><br/>
Emotet Experimenting With New Delivery Techniques<br/>
 <a href="https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques">https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7982" type="text/plain" language="en" />
<itunes:keywords>wso2, xmrig, vmware, iran, core impact, virustotal, emotet, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 26th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7980</itunes:episode>
<itunes:subtitle>PDF leads to PPT; VirusTotal Vuln; Apple Private Relay; Emotet fixes broken installer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF leads to PPT; VirusTotal Vuln; Apple Private Relay; Emotet fixes broken installer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7980.mp3" length="5338936" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7980.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7980</link>
<pubDate>Tue, 26 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Simple PDF Linking to Malicious Content<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+PDF+Linking+to+Malicious+Content/28582/">https://isc.sans.edu/forums/diary/Simple+PDF+Linking+to+Malicious+Content/28582/</a><br/>
VirusTotal Remote Code Execution<br/>
 <a href="https://www.cysrc.com/blog/virus-total-blog">https://www.cysrc.com/blog/virus-total-blog</a><br/>
Apple's Private Relay can Cause the System to Ignore Firewall Rules<br/>
 <a href="https://mullvad.net/en/blog/2022/4/25/apples-private-relay-can-cause-the-system-to-ignore-firewall-rules/">https://mullvad.net/en/blog/2022/4/25/apples-private-relay-can-cause-the-system-to-ignore-firewall-rules/</a><br/>
Emotet Breaks and Later Fixes Installer<br/>
 <a href="https://www.bleepingcomputer.com/news/security/emotet-malware-infects-users-again-after-fixing-broken-installer/">https://www.bleepingcomputer.com/news/security/emotet-malware-infects-users-again-after-fixing-broken-installer/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7980" type="text/plain" language="en" />
<itunes:keywords>emotet, apple, private relay, firewall, virustotal, pdf, link, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7978</itunes:episode>
<itunes:subtitle>Analyzing Word Phish; Targeting Roku; ECDSA JWT PoC; IBM DB2 Expat Vuln; Jira Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing Word Phish; Targeting Roku; ECDSA JWT PoC; IBM DB2 Expat Vuln; Jira Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7978.mp3" length="4507056" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7978.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7978</link>
<pubDate>Mon, 25 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Analyzing Word Phishing Document<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+a+Phishing+Word+Document/28562/">https://isc.sans.edu/forums/diary/Analyzing+a+Phishing+Word+Document/28562/</a><br/>
Targeting Roku Streaming Devices<br/>
 <a href="https://isc.sans.edu/forums/diary/Are+Roku+Streaming+Devices+Safe+from+Exploitation/28578/">https://isc.sans.edu/forums/diary/Are+Roku+Streaming+Devices+Safe+from+Exploitation/28578/</a><br/>
JWT Null Signature Vulnerability PoC<br/>
 <a href="https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/jwt-null-signature-vulnerable-app">https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/jwt-null-signature-vulnerable-app</a><br/>
Expat XML Vulnerabilities<br/>
 <a href="https://www.ibm.com/support/pages/node/6573293">https://www.ibm.com/support/pages/node/6573293</a><br/>
Jira Vulnerability<br/>
 <a href="https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html">https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html</a><br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7978" type="text/plain" language="en" />
<itunes:keywords>atlassian, jira, expat, xml, jwt, java, ecdsa, roku, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7976</itunes:episode>
<itunes:subtitle>Crypto Clipboard Swapper; AWS log4j Bug; Psychic Sig PoC; ALAC Audio Decoder Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Crypto Clipboard Swapper; AWS log4j Bug; Psychic Sig PoC; ALAC Audio Decoder Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7976.mp3" length="5708853" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7976.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7976</link>
<pubDate>Fri, 22 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Multi Cryptocurrency Clipboard Swapper<br/>
<a href="https://isc.sans.edu/forums/diary/MultiCryptocurrency+Clipboard+Swapper/28574/">https://isc.sans.edu/forums/diary/MultiCryptocurrency+Clipboard+Swapper/28574/</a><br/>
Amazong Fixes AWS log4j Fix<br/>
 <a href="https://aws.amazon.com/security/security-bulletins/AWS-2022-006/">https://aws.amazon.com/security/security-bulletins/AWS-2022-006/</a><br/>
Cisco Fixes<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Psychic Signature PoC<br/>
 <a href="https://github.com/khalednassar/CVE-2022-21449-TLS-PoC">https://github.com/khalednassar/CVE-2022-21449-TLS-PoC</a><br/>
ALAC Audio Decoder Bug<br/>
 <a href="https://blog.checkpoint.com/2022/04/21/largest-mobile-chipset-manufacturers-used-vulnerable-audio-decoder-2-3-of-android-users-privacy-around-the-world-were-at-risk/">https://blog.checkpoint.com/2022/04/21/largest-mobile-chipset-manufacturers-used-vulnerable-audio-decoder-2-3-of-android-users-privacy-around-the-world-were-at-risk/</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7976" type="text/plain" language="en" />
<itunes:keywords>python, windows, cryptocurrency, clipboard, aws, log4j, cisco, java, ecdsa, alac, audio decoder, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7974</itunes:episode>
<itunes:subtitle>Quakbot and DarkVNC; Java Psychic Signatures; Snort Modbus DoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Quakbot and DarkVNC; Java Psychic Signatures; Snort Modbus DoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7974.mp3" length="5134489" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7974.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7974</link>
<pubDate>Thu, 21 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[AA Distribution Quakbot (Qbot) infection siwth DarkVNC<br/>
 <a href="https://isc.sans.edu/forums/diary/aa+distribution+Qakbot+Qbot+infection+with+DarkVNC+traffic/28568/">https://isc.sans.edu/forums/diary/aa+distribution+Qakbot+Qbot+infection+with+DarkVNC+traffic/28568/</a><br/>
Java Psychic Signatures<br/>
 <a href="https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/">https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/</a><br/>
Snort DoS Vulnerability<br/>
 <a href="https://claroty.com/2022/04/14/blog-research-blinding-snort-breaking-the-modbus-ot-preprocessor/">https://claroty.com/2022/04/14/blog-research-blinding-snort-breaking-the-modbus-ot-preprocessor/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7974" type="text/plain" language="en" />
<itunes:keywords>snort, dos, java, ecdsa, psychic signatures, signatures, quakbot, qgot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7972</itunes:episode>
<itunes:subtitle>u-boot Password Reset; Oracle CPU; MetaMask iCloud Phishing; Less SMBv1; Lenovo removes accidental backdoors
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
u-boot Password Reset; Oracle CPU; MetaMask iCloud Phishing; Less SMBv1; Lenovo removes accidental backdoors
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7972.mp3" length="5562122" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7972.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7972</link>
<pubDate>Wed, 20 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[u-boot Password Reset<br/>
 <a href="https://isc.sans.edu/forums/diary/Resetting+Linux+Passwords+with+UBoot+Bootloaders/28564/">https://isc.sans.edu/forums/diary/Resetting+Linux+Passwords+with+UBoot+Bootloaders/28564/</a><br/>
Oracle CPU<br/>
 <a href="https://www.oracle.com/security-alerts/cpuapr2022.html">https://www.oracle.com/security-alerts/cpuapr2022.html</a><br/>
MetaMask iCloud Phishing<br/>
 <a href="https://www.bleepingcomputer.com/news/security/hackers-steal-655k-after-picking-metamask-seed-from-icloud-backup/">https://www.bleepingcomputer.com/news/security/hackers-steal-655k-after-picking-metamask-seed-from-icloud-backup/</a><br/>
SMB1 Gone From Windows 11 Home<br/>
 <a href="https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb1-now-disabled-by-default-for-windows-11-home-insiders-builds/ba-p/3289473">https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb1-now-disabled-by-default-for-windows-11-home-insiders-builds/ba-p/3289473</a><br/>
Lenovo UEFI/BIOS Vulnerability<br/>
 <a href="https://support.lenovo.com/us/en/product_security/ps500483-lenovo-system-update-privilege-escalation-vulnerability">https://support.lenovo.com/us/en/product_security/ps500483-lenovo-system-update-privilege-escalation-vulnerability</a><br/>
 <a href="https://support.lenovo.com/de/de/product_security/LEN-84943">https://support.lenovo.com/de/de/product_security/LEN-84943</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7972" type="text/plain" language="en" />
<itunes:keywords>uboot, oracle, metamask, icloud, cryptocoins, smbv1, windows 11, lenovo, backdoors, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7970</itunes:episode>
<itunes:subtitle>Sysmon BinaryData; Ukraine IcedID and Zimbra; NSO/Pegasus News; Fake Windows 11
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sysmon BinaryData; Ukraine IcedID and Zimbra; NSO/Pegasus News; Fake Windows 11
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7970.mp3" length="4447910" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7970.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7970</link>
<pubDate>Tue, 19 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Sysmon's ReigstryEvent (Value Set) and Binary Data<br/>
 <a href="https://isc.sans.edu/forums/diary/Sysmons+RegistryEvent+Value+Set/28558/">https://isc.sans.edu/forums/diary/Sysmons+RegistryEvent+Value+Set/28558/</a><br/>
Ukraine CERT Posts: IcedID and Zimbra Flaw<br/>
 <a href="https://cert.gov.ua/article/39606">https://cert.gov.ua/article/39606</a><br/>
 <a href="https://cert.gov.ua/article/39609">https://cert.gov.ua/article/39609</a><br/>
New NSO Pegasus Exploit Spotted in the Wild<br/>
 <a href="https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/">https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/</a><br/>
Unofficial Windows 11 Upgrade Delivers Spyware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/">https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/</a><br/>
]]></description>
<itunes:duration>4:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7970" type="text/plain" language="en" />
<itunes:keywords>Windows 11, Upgrade, microft, malware, pegasus, nso, ukraine, icedid, zimbra, sysmon, registryevent, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7968</itunes:episode>
<itunes:subtitle>Office and ISOs; Heroku/Travis CI GitHub OAuth Leak; Git Windows Bug; Cisco Wireless Controller Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Office and ISOs; Heroku/Travis CI GitHub OAuth Leak; Git Windows Bug; Cisco Wireless Controller Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7968.mp3" length="5018712" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7968.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7968</link>
<pubDate>Mon, 18 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Office Now Protects You From Malicious ISO Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Office+Protects+You+From+Malicious+ISO+Files/28554/">https://isc.sans.edu/forums/diary/Office+Protects+You+From+Malicious+ISO+Files/28554/</a><br/>
Github Stolen OAUTH User Tokens<br/>
 <a href="https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/">https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/</a><br/>
Git For Windows Vulnerability<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24765">https://nvd.nist.gov/vuln/detail/CVE-2022-24765</a><br/>
Cisco Wireless Controller Bug<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-auth-bypass-JRNhV4fF">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-auth-bypass-JRNhV4fF</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7968" type="text/plain" language="en" />
<itunes:keywords>Cisco, wireless controller, oauth, github, heroku, travis ci, office, iso, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7966</itunes:episode>
<itunes:subtitle>CVE-2022-26809 Update/Webcast; Google Chrome 0-day; Cisco WebEx No-Mute; Grafana Enterprise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2022-26809 Update/Webcast; Google Chrome 0-day; Cisco WebEx No-Mute; Grafana Enterprise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7966.mp3" length="4906772" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7966.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7966</link>
<pubDate>Fri, 15 Apr 2022 02:30:02 GMT</pubDate>
<description><![CDATA[An Update on CVE-2022-26809 MSRPC Vulnerability - PATCH NOW<br/>
 <a href="https://isc.sans.edu/forums/diary/An+Update+on+CVE202226809+MSRPC+Vulnerabliity+PATCH+NOW/28550/">https://isc.sans.edu/forums/diary/An+Update+on+CVE202226809+MSRPC+Vulnerabliity+PATCH+NOW/28550/</a><br/>
 Webcast: <a href="https://www.sans.org/webcasts/cve-2022-26809-ms-rpc-vulnerability-analysis/">https://www.sans.org/webcasts/cve-2022-26809-ms-rpc-vulnerability-analysis/</a><br/>
 <a href="https://twitter.com/splinter_code/status/1514653941304369153">https://twitter.com/splinter_code/status/1514653941304369153</a><br/>
Google Chrome 0-Day Patch<br/>
 <a href="https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html">https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html</a><br/>
Cisco Webex Phones Home Audio Telemetry<br/>
 <a href="https://wiscprivacy.com/papers/vca_mute.pdf">https://wiscprivacy.com/papers/vca_mute.pdf</a><br/>
Grafana Enterprise Vulnerabilty<br/>
 <a href="https://grafana.com/blog/2022/04/12/grafana-enterprise-8.4.6-released-with-high-severity-security-fix/">https://grafana.com/blog/2022/04/12/grafana-enterprise-8.4.6-released-with-high-severity-security-fix/</a><br/>
 <br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7966" type="text/plain" language="en" />
<itunes:keywords>grafana, cisco webex, mute, google chrome, 0 day, patch, cve-2022-26809, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7964</itunes:episode>
<itunes:subtitle>Ukraine/Russian Internet Stability; Windows Patches Followup; Adobe Updates; Struts 2 Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ukraine/Russian Internet Stability; Windows Patches Followup; Adobe Updates; Struts 2 Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7964.mp3" length="5240700" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7964.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7964</link>
<pubDate>Thu, 14 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[How is Ukrainian Internet Holding Up During Russian Invasion<br/>
 <a href="https://isc.sans.edu/forums/diary/How+is+Ukrainian+internet+holding+up+during+the+Russian+invasion/28546/">https://isc.sans.edu/forums/diary/How+is+Ukrainian+internet+holding+up+during+the+Russian+invasion/28546/</a><br/>
Update on Windows Patches and CVE-2022-26809<br/>
 <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26809">https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26809</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/products/photoshop/apsb22-20.html">https://helpx.adobe.com/security/products/photoshop/apsb22-20.html</a><br/>
Apache Struts 2 Update<br/>
 <a href="https://cwiki.apache.org/confluence/display/WW/S2-062">https://cwiki.apache.org/confluence/display/WW/S2-062</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7964" type="text/plain" language="en" />
<itunes:keywords>struts, struts 2, apache, adobe, pdf, reader, acrobat, windows, cve-2022-26809, ukrain, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7962</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; NGINX Statement; Industroyer2 Attack Against Ukraine Power Grid
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; NGINX Statement; Industroyer2 Attack Against Ukraine Power Grid
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7962.mp3" length="5974321" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7962.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7962</link>
<pubDate>Wed, 13 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft April 2022 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+April+2022+Patch+Tuesday/28542/">https://isc.sans.edu/forums/diary/Microsoft+April+2022+Patch+Tuesday/28542/</a><br/>
NGINX Statement To LDAP Weakness<br/>
 <a href="https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/">https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/</a><br/>
Attacks on Ukrainian Power Grid<br/>
 <a href="https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/">https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7962" type="text/plain" language="en" />
<itunes:keywords>ukraine, power grid, industroyer, reloaded, industroyer2, LDAP, nginx, microsoft, patch tuesday, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7960</itunes:episode>
<itunes:subtitle>Spring Cloud Functions Probed; MSFT Autopatch; npm protestware; Raspberry Pi Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Spring Cloud Functions Probed; MSFT Autopatch; npm protestware; Raspberry Pi Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7960.mp3" length="5341218" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7960.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7960</link>
<pubDate>Tue, 12 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Spring: It isn't just about Spring4Shell.<br/>
 <a href="https://isc.sans.edu/forums/diary/Spring+It+isnt+just+about+Spring4Shell+Spring+Cloud+Function+Vulnerabilities+are+being+probed+too/28538/">https://isc.sans.edu/forums/diary/Spring+It+isnt+just+about+Spring4Shell+Spring+Cloud+Function+Vulnerabilities+are+being+probed+too/28538/</a><br/>
Microsoft Windows Autopatch<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-current-and-stay-current-with-windows-autopatch/ba-p/3271839">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-current-and-stay-current-with-windows-autopatch/ba-p/3271839</a><br/>
More npm protestware<br/>
 <a href="https://github.com/Yaffle/EventSource/commit/de137927e13d8afac153d2485152ccec48948a7a">https://github.com/Yaffle/EventSource/commit/de137927e13d8afac153d2485152ccec48948a7a</a><br/>
Raspberry Pi Update<br/>
 <a href="https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/">https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7960" type="text/plain" language="en" />
<itunes:keywords>raspberry pi, bullseye, npm, protestware, auto patch, windows, sprint, cloud function, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7958</itunes:episode>
<itunes:subtitle>Misc Spring4Shell Items (Cisco, Mirai, Nginx); Russian CA Update; Conti Ransomware Copycats
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Misc Spring4Shell Items (Cisco, Mirai, Nginx); Russian CA Update; Conti Ransomware Copycats
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7958.mp3" length="5566018" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7958.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7958</link>
<pubDate>Mon, 11 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Misc Spring4Shell Items<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67</a><br/>
 <a href="https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html">https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html</a><br/>
 <a href="https://github.com/AgainstTheWest/NginxDay">https://github.com/AgainstTheWest/NginxDay</a><br/>
Russian Certificate Authority Update<br/>
 <a href="https://koen.engineer/russias-certificate-authority-for-sanctioned-organizations-645d61af8ac6">https://koen.engineer/russias-certificate-authority-for-sanctioned-organizations-645d61af8ac6</a><br/>
Conti Source Code Leak Leads to Copycats<br/>
 <a href="https://www.bleepingcomputer.com/news/security/hackers-use-contis-leaked-ransomware-to-attack-russian-companies/">https://www.bleepingcomputer.com/news/security/hackers-use-contis-leaked-ransomware-to-attack-russian-companies/</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7958" type="text/plain" language="en" />
<itunes:keywords>conti, coycat, russia, certifiates, CA, certificate authority, spring4shell, cisco, mirai, nginx, 0day, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7956</itunes:episode>
<itunes:subtitle>What is BIMI? Watchguard Vuln.; Malware in Lambdas; Job Scam @sans_edu @infosec_taylor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
What is BIMI? Watchguard Vuln.; Malware in Lambdas; Job Scam @sans_edu @infosec_taylor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7956.mp3" length="13412310" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7956.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7956</link>
<pubDate>Fri, 08 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[What is BIMI<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+BIMI+and+how+is+it+supposed+to+help+with+Phishing/28528/">https://isc.sans.edu/forums/diary/What+is+BIMI+and+how+is+it+supposed+to+help+with+Phishing/28528/</a><br/>
Watchguard Vulnerability behind Cyclops Blink<br/>
 <a href="https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA16S000000SOCGSA4&lang=en_US">https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA16S000000SOCGSA4&lang=en_US</a><br/>
Malware Targeting Amazon Lambdas<br/>
 <a href="https://www.cadosecurity.com/cado-discovers-denonia-the-first-malware-specifically-targeting-lambda/">https://www.cadosecurity.com/cado-discovers-denonia-the-first-malware-specifically-targeting-lambda/</a><br/>
Ashley Taylor: Doppelgaengers: Finding Job Scammers Who Steal Brand Identities<br/>
 <a href="https://www.sans.edu/cyber-research/doppelgangers-finding-job-scammers-who-steal-brand-identities/">https://www.sans.edu/cyber-research/doppelgangers-finding-job-scammers-who-steal-brand-identities/</a><br/>
]]></description>
<itunes:duration>15:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7956" type="text/plain" language="en" />
<itunes:keywords>lambdas, sans_edu, domains, brand, job ads, scams, amazon, bimi, email, watchguard, cyclops blink, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7954</itunes:episode>
<itunes:subtitle>MetaStealer Malware; Cyclops Blink Takedown; Palo Alto TLS Bug; VMWare Bugs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MetaStealer Malware; Cyclops Blink Takedown; Palo Alto TLS Bug; VMWare Bugs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7954.mp3" length="5595313" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7954.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7954</link>
<pubDate>Thu, 07 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Windows MetaStealer Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Windows+MetaStealer+Malware/28522/">https://isc.sans.edu/forums/diary/Windows+MetaStealer+Malware/28522/</a><br/>
US Justice Depatment Takes Down Cyclops Blink Botnet<br/>
 <a href="https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation">https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation</a><br/>
VMWare Bugs<br/>
 <a href="https://www.vmware.com/security/advisories.html">https://www.vmware.com/security/advisories.html</a><br/>
Palo Alto CVE-2022-0778<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2022-0778">https://security.paloaltonetworks.com/CVE-2022-0778</a><br/>
Unpatched Apple Bug<br/>
 <a href="https://www.intego.com/mac-security-blog/apple-neglects-to-patch-zero-day-wild-vulnerabilities-for-macos-big-sur-catalina/">https://www.intego.com/mac-security-blog/apple-neglects-to-patch-zero-day-wild-vulnerabilities-for-macos-big-sur-catalina/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7954" type="text/plain" language="en" />
<itunes:keywords>palo alot, vmware, cyclops blink, metastealer, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 6th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7952</itunes:episode>
<itunes:subtitle>CryptoMiner vs #Alibaba; #Cicada APT Techniques; Win11 Security; Fin7 Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CryptoMiner vs #Alibaba; #Cicada APT Techniques; Win11 Security; Fin7 Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7952.mp3" length="5774194" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7952.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7952</link>
<pubDate>Wed, 06 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[WebLogic Crypto Miner Malware Disabling Alibaba Cloud Monitoring Tools<br/>
 <a href="https://isc.sans.edu/forums/diary/WebLogic+Crypto+Miner+Malware+Disabling+Alibaba+Cloud+Monitoring+Tools/28520/">https://isc.sans.edu/forums/diary/WebLogic+Crypto+Miner+Malware+Disabling+Alibaba+Cloud+Monitoring+Tools/28520/</a><br/>
Cicada: Chinese APT Group Widens Targeting in Recent Espionage Activity<br/>
 <a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks">https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks</a><br/>
New Security Features for Windows 11<br/>
 <a href="https://www.microsoft.com/security/blog/2022/04/05/new-security-features-for-windows-11-will-help-protect-hybrid-work/">https://www.microsoft.com/security/blog/2022/04/05/new-security-features-for-windows-11-will-help-protect-hybrid-work/</a><br/>
Fin7 Power Hour: Adversary Archaeology and Evolution of FIN7<br/>
 <a href="https://www.mandiant.com/resources/evolution-of-fin7">https://www.mandiant.com/resources/evolution-of-fin7</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7952" type="text/plain" language="en" />
<itunes:keywords>fin7, windows 11, weblogic, cryptominer, alibaba, cloud, cicada, apt, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 5th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7950</itunes:episode>
<itunes:subtitle>WordPress/Google and Phishing; Mailchimp Breachs; GitHub Secret Leak Help; TruffleHog v3; Russian Certs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WordPress/Google and Phishing; Mailchimp Breachs; GitHub Secret Leak Help; TruffleHog v3; Russian Certs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7950.mp3" length="5525133" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7950.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7950</link>
<pubDate>Tue, 05 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Emptying the Phishtank: Are WordPress Sites the Mosquitoes of the Internet<br/>
 <a href="https://isc.sans.edu/forums/diary/Emptying+the+Phishtank+Are+WordPress+sites+the+Mosquitoes+of+the+Internet/28516/">https://isc.sans.edu/forums/diary/Emptying+the+Phishtank+Are+WordPress+sites+the+Mosquitoes+of+the+Internet/28516/</a><br/>
Mailchimp Breach Used to Target Trezor Users<br/>
 <a href="https://www.bleepingcomputer.com/news/security/hackers-breach-mailchimps-internal-tools-to-target-crypto-customers/">https://www.bleepingcomputer.com/news/security/hackers-breach-mailchimps-internal-tools-to-target-crypto-customers/</a><br/>
Proactively Prevent Secret Leaks With GitHub Advanced Security Secret Scanning<br/>
 <a href="https://github.blog/2022-04-04-push-protection-github-advanced-security/">https://github.blog/2022-04-04-push-protection-github-advanced-security/</a><br/>
TruffleHog v3<br/>
 <a href="https://trufflesecurity.com/blog/introducing-trufflehog-v3">https://trufflesecurity.com/blog/introducing-trufflehog-v3</a><br/>
Russian Certificates (chinese article)<br/>
 <a href="https://blog.netlab.360.com/review-revoke-russia-ssl-certificates/">https://blog.netlab.360.com/review-revoke-russia-ssl-certificates/</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7950" type="text/plain" language="en" />
<itunes:keywords>russia, certificates, trufflehog, github, secrets, api keys, trezor, mailchimp, phishing, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7948</itunes:episode>
<itunes:subtitle>GitLab Patch; ViaSat KA-SAT Details; MacOS Bug Enables Phishing; PEAR Bug Fixed
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GitLab Patch; ViaSat KA-SAT Details; MacOS Bug Enables Phishing; PEAR Bug Fixed
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7948.mp3" length="5618551" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7948.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7948</link>
<pubDate>Mon, 04 Apr 2022 02:00:02 GMT</pubDate>
<description><![CDATA[GitLab Critical Security Release<br/>
 <a href="https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/">https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/</a><br/>
ViaSat KA-SAT Network Cyber Attack<br/>
 <a href="https://www.viasat.com/about/newsroom/blog/ka-sat-network-cyber-attack-overview/">https://www.viasat.com/about/newsroom/blog/ka-sat-network-cyber-attack-overview/</a><br/>
MacOS Bug Enables Phishing<br/>
 <a href="https://rambo.codes/posts/2022-03-15-how-a-macos-bug-could-have-allowed-for-a-serious-phishing-attack-against-users">https://rambo.codes/posts/2022-03-15-how-a-macos-bug-could-have-allowed-for-a-serious-phishing-attack-against-users</a><br/>
PHP Supply Chain Attack on PEAR<br/>
 <a href="https://blog.sonarsource.com/php-supply-chain-attack-on-pear">https://blog.sonarsource.com/php-supply-chain-attack-on-pear</a><br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7948" type="text/plain" language="en" />
<itunes:keywords>php, pear, macos, phishing, viasat, ka-sat, wiper, gitlab, bug, vulnerability, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7946</itunes:episode>
<itunes:subtitle>Spring Clarifies Spring4Shell; Wyze Cam; Zyxel FW Patch; #Apple 0 Days #ipados #ios #0day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Spring Clarifies Spring4Shell; Wyze Cam; Zyxel FW Patch; #Apple 0 Days #ipados #ios #0day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7946.mp3" length="4999407" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7946.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7946</link>
<pubDate>Fri, 01 Apr 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Spring Vulnerability Update - Exploitation Attempts CVE-2022-22965<br/>
 <a href="https://isc.sans.edu/forums/diary/Spring+Vulnerability+Update+Exploitation+Attempts+CVE202222965/28504/">https://isc.sans.edu/forums/diary/Spring+Vulnerability+Update+Exploitation+Attempts+CVE202222965/28504/</a><br/>
Apple Patches 0 Day Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Patches+Actively+Exploited+Vulnerability+in+macOS+iOS+and+iPadOS/28506/">https://isc.sans.edu/forums/diary/Apple+Patches+Actively+Exploited+Vulnerability+in+macOS+iOS+and+iPadOS/28506/</a><br/>
Wyze Cam Vulnerabilities<br/>
 <a href="https://www.bitdefender.com/files/News/CaseStudies/study/413/Bitdefender-PR-Whitepaper-WCam-creat5991-en-EN.pdf">https://www.bitdefender.com/files/News/CaseStudies/study/413/Bitdefender-PR-Whitepaper-WCam-creat5991-en-EN.pdf</a><br/>
Zyxel Security Advisory<br/>
 <a href="https://www.zyxel.com/support/forgery-vulnerabilities-of-select-Armor-home-routers.shtml">https://www.zyxel.com/support/forgery-vulnerabilities-of-select-Armor-home-routers.shtml</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7946" type="text/plain" language="en" />
<itunes:keywords>zyxel, wyze, spring, camera, firewall, macos, vulnerabilities, ipados, ios, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 31st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7944</itunes:episode>
<itunes:subtitle>Spring4Shell/Java Confusion; XLSB Parsing; 3CX Phone Systems
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Spring4Shell/Java Confusion; XLSB Parsing; 3CX Phone Systems
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7944.mp3" length="5296017" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7944.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7944</link>
<pubDate>Thu, 31 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Java Springtime Confusion: What Vulnerabilty are We Talking About<br/>
 <a href="https://isc.sans.edu/forums/diary/Java+Springtime+Confusion+What+Vulnerability+are+We+Talking+About/28500/">https://isc.sans.edu/forums/diary/Java+Springtime+Confusion+What+Vulnerability+are+We+Talking+About/28500/</a><br/>
Quickie: Parsing XLSB Documents<br/>
 <a href="https://isc.sans.edu/forums/diary/Quickie+Parsing+XLSB+Documents/28496/">https://isc.sans.edu/forums/diary/Quickie+Parsing+XLSB+Documents/28496/</a><br/>
Pwning 3CX Phone Management Backends from the Internet<br/>
 <a href="https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88">https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7944" type="text/plain" language="en" />
<itunes:keywords>3cx, phone management, xlsb, java, spring4shell, spring, spring cloud, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 30th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7942</itunes:episode>
<itunes:subtitle>More Twitter Abuse; Firewall Vuln Correction; UPS Attacks; MFA Bypass Attacks; Mars Stealer; Hacker Subpoena
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Twitter Abuse; Firewall Vuln Correction; UPS Attacks; MFA Bypass Attacks; Mars Stealer; Hacker Subpoena
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7942.mp3" length="5966466" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7942.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7942</link>
<pubDate>Wed, 30 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[More Fake/Typosquatting Twitter Accounts Asking for Ukraine Cryptocurrency Donations<br/>
 <a href="https://isc.sans.edu/forums/diary/More+FakeTyposquatting+Twitter+Accounts+Asking+for+Ukraine+Crytocurrency+Donations/28492/">https://isc.sans.edu/forums/diary/More+FakeTyposquatting+Twitter+Accounts+Asking+for+Ukraine+Crytocurrency+Donations/28492/</a><br/>
Mitigating Attacks Against Uninterruptible Power Supply Devices<br/>
 <a href="https://www.cisa.gov/sites/default/files/publications/CISA-DOE_Insights-Mitigating_Vulnerabilities_Affecting_Uninterruptible_Power_Supply_Devices_Mar_29.pdf">https://www.cisa.gov/sites/default/files/publications/CISA-DOE_Insights-Mitigating_Vulnerabilities_Affecting_Uninterruptible_Power_Supply_Devices_Mar_29.pdf</a><br/>
MFA Bypass Attacks<br/>
 <a href="https://blog.talosintelligence.com/2022/03/transparent-tribe-new-campaign.html">https://blog.talosintelligence.com/2022/03/transparent-tribe-new-campaign.html</a><br/>
Google Advertises Mars Stealer<br/>
 <a href="https://blog.morphisec.com/threat-research-mars-stealer">https://blog.morphisec.com/threat-research-mars-stealer</a><br/>
Hackers Gaining Power of Subpoena Via Fake "Emergency Data Requests"<br/>
 <a href="https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/">https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7942" type="text/plain" language="en" />
<itunes:keywords>hackers, subpaena, data request, emergnecy, mfa, google, mars stealer, cisc, ups, sophos, sonicwall, ukraine, twitter, crypto, currencies, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 29th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7940</itunes:episode>
<itunes:subtitle>Twitter BGP Hijack; Ukraine DDoS; Sophos Patches; Sonicwall Update; opnsense CARP bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Twitter BGP Hijack; Ukraine DDoS; Sophos Patches; Sonicwall Update; opnsense CARP bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7940.mp3" length="5406733" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7940.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7940</link>
<pubDate>Tue, 29 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[BGP Hijacking of Twitter Prefix by RTComm.ru<br/>
 <a href="https://isc.sans.edu/forums/diary/BGP+Hijacking+of+Twitter+Prefix+by+RTCommru/28488/">https://isc.sans.edu/forums/diary/BGP+Hijacking+of+Twitter+Prefix+by+RTCommru/28488/</a><br/>
DDoS Against Sites in Ukraine<br/>
 <a href="https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/">https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/</a><br/>
Sophos Patches<br/>
 <a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce</a><br/>
Sonicwall Patches<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003">https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003</a><br/>
opnsense CARP protocol routing error<br/>
 <a href="https://medium.com/sensorfu/firewall-bypass-with-carp-in-packet-filter-c4ed70fb7dd7">https://medium.com/sensorfu/firewall-bypass-with-carp-in-packet-filter-c4ed70fb7dd7</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7940" type="text/plain" language="en" />
<itunes:keywords>opnsens, CARP, Sonicwall, Sophos, DDoS, Ukraine, BGP, Twitter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7938</itunes:episode>
<itunes:subtitle>XLSB File Analysis; Dirty Pipe Container Escape; PHP Filter Vuln; OpenBSD slaacd vuln; Google Chrome 0 Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XLSB File Analysis; Dirty Pipe Container Escape; PHP Filter Vuln; OpenBSD slaacd vuln; Google Chrome 0 Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7938.mp3" length="5580081" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7938.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7938</link>
<pubDate>Mon, 28 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[XLSB Files Because Binary is Stealthier Than XML<br/>
 <a href="https://isc.sans.edu/forums/diary/XLSB+Files+Because+Binary+is+Stealthier+Than+XML/28476/">https://isc.sans.edu/forums/diary/XLSB+Files+Because+Binary+is+Stealthier+Than+XML/28476/</a><br/>
Dirty Pipe Container Escape PoC<br/>
 <a href="https://www.datadoghq.com/blog/engineering/dirty-pipe-container-escape-poc/">https://www.datadoghq.com/blog/engineering/dirty-pipe-container-escape-poc/</a><br/>
PHP filter_var Shenanigans<br/>
 <a href="https://pwning.systems/posts/php_filter_var_shenanigans/">https://pwning.systems/posts/php_filter_var_shenanigans/</a><br/>
OpenBSD slaacd vuln<br/>
 <a href="https://blog.quarkslab.com/heap-overflow-in-openbsds-slaacd-via-router-advertisement.html">https://blog.quarkslab.com/heap-overflow-in-openbsds-slaacd-via-router-advertisement.html</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html">https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7938" type="text/plain" language="en" />
<itunes:keywords>google, chrome, openbsd, php, filter_var, xlsb, container, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7936</itunes:episode>
<itunes:subtitle>Malware via transfer.sh; WD PR4100 NAS Vuln; Crypto Malware; Lapsus$ Arrest; FBI Indictment
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware via transfer.sh; WD PR4100 NAS Vuln; Crypto Malware; Lapsus$ Arrest; FBI Indictment
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7936.mp3" length="5293105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7936.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7936</link>
<pubDate>Fri, 25 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Malware Delivered Through Free Sharing Tool<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Delivered+Through+Free+Sharing+Tool/28474/">https://isc.sans.edu/forums/diary/Malware+Delivered+Through+Free+Sharing+Tool/28474/</a><br/>
Western Digital PR4100 NAS Vulnerabilty<br/>
 <a href="https://research.nccgroup.com/2022/03/24/remote-code-execution-on-western-digital-pr4100-nas-cve-2022-23121/">https://research.nccgroup.com/2022/03/24/remote-code-execution-on-western-digital-pr4100-nas-cve-2022-23121/</a><br/>
Crypto malware in patched wallets targeting Android and iOS devices<br/>
 <a href="https://www.welivesecurity.com/2022/03/24/crypto-malware-patched-wallets-targeting-android-ios-devices/">https://www.welivesecurity.com/2022/03/24/crypto-malware-patched-wallets-targeting-android-ios-devices/</a><br/>
Lapsus$ Arrest<br/>
 <a href="https://www.bbc.com/news/technology-60864283">https://www.bbc.com/news/technology-60864283</a><br/>
 <a href="https://www.bloomberg.com/news/articles/2022-03-23/teen-suspected-by-cyber-researchers-of-being-lapsus-mastermind?sref=ylv224K8">https://www.bloomberg.com/news/articles/2022-03-23/teen-suspected-by-cyber-researchers-of-being-lapsus-mastermind?sref=ylv224K8</a><br/>
Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide<br/>
 <a href="https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical">https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7936" type="text/plain" language="en" />
<itunes:keywords>russian, ics, doj, lapsus$, lapsus, arrest, crypto, malware, android, ios, western digital, sharing, filesharing, afs, transfer.sh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 24th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7934</itunes:episode>
<itunes:subtitle>Mars Stealer; Okta/MSFT/Lapsus$ Update; Azure npm Attack; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mars Stealer; Okta/MSFT/Lapsus$ Update; Azure npm Attack; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7934.mp3" length="5600173" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7934.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7934</link>
<pubDate>Thu, 24 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Mars Stealer<br/>
 <a href="https://isc.sans.edu/forums/diary/Arkei+Variants+From+Vidar+to+Mars+Stealer/28468/">https://isc.sans.edu/forums/diary/Arkei+Variants+From+Vidar+to+Mars+Stealer/28468/</a><br/>
Okta Update<br/>
 <a href="https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/">https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/</a><br/>
Microsoft Lapsus$ Update<br/>
 <a href="https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/">https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/</a><br/>
npm Attack Targeting Azure Developers<br/>
 <a href="https://jfrog.com/blog/large-scale-npm-attack-targets-azure-developers-with-malicious-packages/">https://jfrog.com/blog/large-scale-npm-attack-targets-azure-developers-with-malicious-packages/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7934" type="text/plain" language="en" />
<itunes:keywords>mars, stealer, malware, microsoft, okta, lapsus$, lapsus, npm, azure, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 23rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7932</itunes:episode>
<itunes:subtitle>Whitehouse Statement; ASUS vs Cyclops; HP Vulnerabilities; Sophos UTM; MacOS GIMMICK; Possible Octa Breach
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Whitehouse Statement; ASUS vs Cyclops; HP Vulnerabilities; Sophos UTM; MacOS GIMMICK; Possible Octa Breach
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7932.mp3" length="6448276" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7932.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7932</link>
<pubDate>Wed, 23 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Statement by President Biden: What you need to do (or not do)<br/>
 <a href="https://isc.sans.edu/forums/diary/Statement+by+President+Biden+What+you+need+to+do+or+not+do/28466/">https://isc.sans.edu/forums/diary/Statement+by+President+Biden+What+you+need+to+do+or+not+do/28466/</a><br/>
ASUS Cyclops Blink Advisory<br/>
 <a href="https://www.asus.com/content/ASUS-Product-Security-Advisory/">https://www.asus.com/content/ASUS-Product-Security-Advisory/</a><br/>
HP Vulnerabilities<br/>
 <a href="https://support.hp.com/us-en/document/ish_5948778-5949142-16/hpsbpi03780">https://support.hp.com/us-en/document/ish_5948778-5949142-16/hpsbpi03780</a><br/>
Sophos UTM Updates<br/>
 <a href="https://www.sophos.com/en-us/security-advisories/sophos-sa-20220321-utm-9710">https://www.sophos.com/en-us/security-advisories/sophos-sa-20220321-utm-9710</a><br/>
MacOS GIMMICK Malware<br/>
 <a href="https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/">https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/</a><br/>
Octa Breached By Lapsus<br/>
 <a href="https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/">https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/</a><br/>
 <a href="https://twitter.com/BillDemirkapi/status/1506107157124722690">https://twitter.com/BillDemirkapi/status/1506107157124722690</a><br/>
]]></description>
<itunes:duration>7:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7932" type="text/plain" language="en" />
<itunes:keywords>octa, lapsus$, gimmick, macos, sophos, hp, printers, ASUS, HP, UTM, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7930</itunes:episode>
<itunes:subtitle>Analyzing Cleaned Maldoc; Serpent Backdoor; IBM Spectrum Protect; Lapsus$ vs Microsoft; Whitehouse Statement
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing Cleaned Maldoc; Serpent Backdoor; IBM Spectrum Protect; Lapsus$ vs Microsoft; Whitehouse Statement
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7930.mp3" length="6675436" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7930.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7930</link>
<pubDate>Tue, 22 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Maldoc Cleaned by Anti-Virus<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+Cleaned+by+AntiVirus/28460/">https://isc.sans.edu/forums/diary/Maldoc+Cleaned+by+AntiVirus/28460/</a><br/>
Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain<br/>
 <a href="https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain">https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain</a><br/>
IBM Spectrum Protect Update<br/>
 <a href="https://www.ibm.com/support/pages/node/6564745">https://www.ibm.com/support/pages/node/6564745</a><br/>
Lapsus$ May have Breached Microsoft<br/>
 <a href="https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/">https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/</a><br/>
Statement by President Biden on our Nation's Cybersecurity<br/>
 <a href="https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/statement-by-president-biden-on-our-nations-cybersecurity/">https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/statement-by-president-biden-on-our-nations-cybersecurity/</a><br/>
]]></description>
<itunes:duration>7:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7930" type="text/plain" language="en" />
<itunes:keywords>biden, whitehouse, russia, ukraine, lapsus, lapsus$, microsoft, ibm, spectrum protect, serpent, backdoor, french, maldoc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7928</itunes:episode>
<itunes:subtitle>Movable Type; SolarWinds Web Help Desk; MGLNDD Scans; CAPTCHA Phishing; Browser in Browser
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Movable Type; SolarWinds Web Help Desk; MGLNDD Scans; CAPTCHA Phishing; Browser in Browser
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7928.mp3" length="5437902" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7928.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7928</link>
<pubDate>Mon, 21 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Scans for Movable Type Vulnerability (CVE-2021-20837)<br/>
 <a href="https://isc.sans.edu/forums/diary/Scans+for+Movable+Type+Vulnerability+CVE202120837/28454/">https://isc.sans.edu/forums/diary/Scans+for+Movable+Type+Vulnerability+CVE202120837/28454/</a><br/>
SolarWinds Advisory: Unauahtneticated Access in Web Help Desk (12.7.5)<br/>
 <a href="https://isc.sans.edu/forums/diary/SolarWinds+Advisory+Unauthenticated+Access+in+Web+Help+Desk+1275/28456/">https://isc.sans.edu/forums/diary/SolarWinds+Advisory+Unauthenticated+Access+in+Web+Help+Desk+1275/28456/</a><br/>
MGLNDD_* Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/MGLNDD+Scans/28458/">https://isc.sans.edu/forums/diary/MGLNDD+Scans/28458/</a><br/>
CAPTCHA Phishing<br/>
 <a href="https://www.avanan.com/blog/using-captcha-forms-to-bypass-filters">https://www.avanan.com/blog/using-captcha-forms-to-bypass-filters</a><br/>
Browser in the Browser Templates<br/>
 <a href="https://mrd0x.com/browser-in-the-browser-phishing-attack/">https://mrd0x.com/browser-in-the-browser-phishing-attack/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7928" type="text/plain" language="en" />
<itunes:keywords>browser, phishing, captcha, mglndd, solarwinds, web help desk, whd, movable type, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7926</itunes:episode>
<itunes:subtitle>npm sabotage; Deepfakes; ATM Rootkit; Mikrotik Scanner; @sans_edu ICS NAC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
npm sabotage; Deepfakes; ATM Rootkit; Mikrotik Scanner; @sans_edu ICS NAC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7926.mp3" length="12530561" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7926.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7926</link>
<pubDate>Fri, 18 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[npm Package Sabotaged for Belarus/Russian Users<br/>
 <a href="https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/">https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/</a><br/>
President Zelensky Deepfakes<br/>
 <a href="https://twitter.com/ngleicher/status/1504186935291506693">https://twitter.com/ngleicher/status/1504186935291506693</a><br/>
ATM Rootkit<br/>
 <a href="https://www.mandiant.com/resources/unc2891-overview">https://www.mandiant.com/resources/unc2891-overview</a><br/>
Scanner for Backdoored Mikrotik Routers<br/>
 <a href="https://github.com/microsoft/routeros-scanner">https://github.com/microsoft/routeros-scanner</a><br/>
SANS.edu Student: Ron Grohman; Network Access Control and ICS: A Practical Guide<br/>
 <a href="https://www.sans.edu/cyber-research/network-access-control-and-ics-a-practical-guide/">https://www.sans.edu/cyber-research/network-access-control-and-ics-a-practical-guide/</a><br/>
]]></description>
<itunes:duration>14:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7926" type="text/plain" language="en" />
<itunes:keywords>sans.edu, ron grohman, ICS, network access control, nac, scanner, mikrotik, atm, deepfakes, zelensky, npm, belarus, russia, ukraine, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7924</itunes:episode>
<itunes:subtitle>Qakbot News; Gh0stCringe via MySQL/MSSQL; dompdf 0 day; openssl dos; pfsense update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Qakbot News; Gh0stCringe via MySQL/MSSQL; dompdf 0 day; openssl dos; pfsense update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7924.mp3" length="4951474" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7924.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7924</link>
<pubDate>Thu, 17 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Qakbot Infection With Cobalt Strike and VNC Activity<br/>
 <a href="https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448/">https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448/</a><br/>
Gh0stCringe RAT Being Distributed to Vulnerable Database Servers<br/>
 <a href="https://asec.ahnlab.com/en/32572/">https://asec.ahnlab.com/en/32572/</a><br/>
dompdf 0 day<br/>
 <a href="https://positive.security/blog/dompdf-rce">https://positive.security/blog/dompdf-rce</a><br/>
OpenSSL DoS Vulnerability<br/>
 <a href="https://www.openssl.org/news/secadv/20220315.txt">https://www.openssl.org/news/secadv/20220315.txt</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7924" type="text/plain" language="en" />
<itunes:keywords>openssl, dompdf, gh0stcringe, rat, database, mysql, mssql, quakbot, cobalt strike, vnc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7922</itunes:episode>
<itunes:subtitle>Odd Behaviours; MFA Bypass; Kaspersky Warning; CaddyWiper; Fake AV; DNS Tunnel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd Behaviours; MFA Bypass; Kaspersky Warning; CaddyWiper; Fake AV; DNS Tunnel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7922.mp3" length="4592755" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7922.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7922</link>
<pubDate>Wed, 16 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Clean Binaries with Suspicious Behaviour<br/>
 <a href="https://isc.sans.edu/forums/diary/Clean+Binaries+with+Suspicious+Behaviour/28444/">https://isc.sans.edu/forums/diary/Clean+Binaries+with+Suspicious+Behaviour/28444/</a><br/>
Misconfigured Multi-Factor Authentication Abused<br/>
 <a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-074a">https://www.cisa.gov/uscert/ncas/alerts/aa22-074a</a><br/>
German Office of Information Security Warns Kaspersky Users<br/>
 <a href="https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html">https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html</a><br/>
Caddy Wiper Targeting Ukraine<br/>
 <a href="https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/">https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/</a><br/>
Fake Antivirus Targeting Ukraine<br/>
 <a href="https://twitter.com/malwrhunterteam/status/1502302718140035080">https://twitter.com/malwrhunterteam/status/1502302718140035080</a><br/>
B1txor20 DNS Tunnel Backdoor<br/>
 <a href="https://blog.netlab.360.com/b1txor20-use-of-dns-tunneling_en/">https://blog.netlab.360.com/b1txor20-use-of-dns-tunneling_en/</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7922" type="text/plain" language="en" />
<itunes:keywords>dns tunnel, antivirus, log4j, caddywiper, kaspersky, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7920</itunes:episode>
<itunes:subtitle>Apple Updates Everything; More Ukraine Scams; Curl on Windows; Veeam Vuln; netfilter priv esc;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates Everything; More Ukraine Scams; Curl on Windows; Veeam Vuln; netfilter priv esc;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7920.mp3" length="5067884" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7920.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7920</link>
<pubDate>Tue, 15 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Apple Updates Everything<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Updates+Everything+MacOS+123+XCode+133+tvOS+154+watchOS+85+iPadOS+154+and+more/28438/">https://isc.sans.edu/forums/diary/Apple+Updates+Everything+MacOS+123+XCode+133+tvOS+154+watchOS+85+iPadOS+154+and+more/28438/</a><br/>
Look Alike Accounts Used in Ukraine Dontation Scam Impersonating Olena Zelenska<br/>
 <a href="https://isc.sans.edu/forums/diary/Look+Alike+Accounts+Used+in+Ukraine+Donation+Scam+impersonating+Olena+Zelenska/28440/">https://isc.sans.edu/forums/diary/Look+Alike+Accounts+Used+in+Ukraine+Donation+Scam+impersonating+Olena+Zelenska/28440/</a><br/>
Curl on Windows<br/>
 <a href="https://isc.sans.edu/forums/diary/Curl+on+Windows/28436/">https://isc.sans.edu/forums/diary/Curl+on+Windows/28436/</a><br/>
Veeam Vulnerabilities<br/>
 <a href="https://www.veeam.com/kb4288">https://www.veeam.com/kb4288</a><br/>
Linux Netfilter Privilege Escalation<br/>
 <a href="https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/">https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7920" type="text/plain" language="en" />
<itunes:keywords>linux, netfilter, veeam, curl, scam, crypto, bitcoin, ethereum, privilege escalation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7918</itunes:episode>
<itunes:subtitle>WebSocket Malware; Telegram C&amp;C Infostealer; USAHERDS Breach; YARA 4.2.0 Out
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebSocket Malware; Telegram C&amp;C Infostealer; USAHERDS Breach; YARA 4.2.0 Out
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7918.mp3" length="4889568" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7918.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7918</link>
<pubDate>Mon, 14 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Malware Using WebSockets For C&C<br/>
 <a href="https://isc.sans.edu/forums/diary/Keep+an+Eye+on+WebSockets/28430/">https://isc.sans.edu/forums/diary/Keep+an+Eye+on+WebSockets/28430/</a><br/>
Racoon Stealer leverages Telegram<br/>
 <a href="https://decoded.avast.io/vladimirmartyanov/raccoon-stealer-trash-panda-abuses-telegram/">https://decoded.avast.io/vladimirmartyanov/raccoon-stealer-trash-panda-abuses-telegram/</a><br/>
USAHERDS Hack<br/>
 <a href="https://www.wired.com/story/china-apt41-hacking-usaherds-log4j/">https://www.wired.com/story/china-apt41-hacking-usaherds-log4j/</a><br/>
YARA 4.2.0 Released<br/>
 <a href="https://isc.sans.edu/forums/diary/YARA+420+Released/28432/">https://isc.sans.edu/forums/diary/YARA+420+Released/28432/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7918" type="text/plain" language="en" />
<itunes:keywords>yara, usaherds, racoon, info stealer, stealer, telegram, websockets, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7916</itunes:episode>
<itunes:subtitle>Credentials on Virustotal; GPS Problems; Russian CA; New Spectre; Package Manager Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Credentials on Virustotal; GPS Problems; Russian CA; New Spectre; Package Manager Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7916.mp3" length="4963963" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7916.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7916</link>
<pubDate>Fri, 11 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Credential Leaks on Virustotal<br/>
 <a href="https://isc.sans.edu/forums/diary/Credentials+Leaks+on+VirusTotal/28426/">https://isc.sans.edu/forums/diary/Credentials+Leaks+on+VirusTotal/28426/</a><br/>
GPS Issues Around Finish Rusian Border<br/>
 <a href="https://www.straitstimes.com/world/europe/finland-detects-gps-disturbance-near-russias-kaliningrad">https://www.straitstimes.com/world/europe/finland-detects-gps-disturbance-near-russias-kaliningrad</a><br/>
Russia Considering Internal Certificate Authority<br/>
 <a href="https://www.gosuslugi.ru/tls">https://www.gosuslugi.ru/tls</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/">https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/</a><br/>
New Spectre Variant<br/>
 <a href="https://www.vusec.net/projects/bhi-spectre-bhb/">https://www.vusec.net/projects/bhi-spectre-bhb/</a><br/>
Package Manager Vulnerabilities (yarn, pip, composer...)<br/>
 <a href="https://blog.sonarsource.com/securing-developer-tools-package-managers">https://blog.sonarsource.com/securing-developer-tools-package-managers</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7916" type="text/plain" language="en" />
<itunes:keywords>yarn, pip, bower, composer, package manager, spectre, russia, certifiate authority, gps, credentials, virustotal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7914</itunes:episode>
<itunes:subtitle>batch infostealer; Mitel DDoS; Pro Ukrainian Hacking Tools Malware; Hack .ru Govt Sites
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
batch infostealer; Mitel DDoS; Pro Ukrainian Hacking Tools Malware; Hack .ru Govt Sites
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7914.mp3" length="5555483" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7914.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7914</link>
<pubDate>Thu, 10 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Infostealer in a Batch File<br/>
 <a href="https://isc.sans.edu/forums/diary/Infostealer+in+a+Batch+File/28422/">https://isc.sans.edu/forums/diary/Infostealer+in+a+Batch+File/28422/</a><br/>
TP240PhoneHome reflection/amplification DDoS Attack Vector<br/>
 <a href="https://blog.cloudflare.com/cve-2022-26143/">https://blog.cloudflare.com/cve-2022-26143/</a><br/>
Malware Disguises as Pro Ukrainian Cybertools<br/>
 <a href="https://blog.talosintelligence.com/2022/03/threat-advisory-cybercriminals.html#more">https://blog.talosintelligence.com/2022/03/threat-advisory-cybercriminals.html#more</a><br/>
Russian Government Sites Hacked in Supply Chain Attack<br/>
 <a href="https://www.bleepingcomputer.com/news/security/russian-government-sites-hacked-in-supply-chain-attack/">https://www.bleepingcomputer.com/news/security/russian-government-sites-hacked-in-supply-chain-attack/</a><br/>
Third Party Vulnerabilities in RUGGEDCOM ROS<br/>
 <a href="https://cert-portal.siemens.com/productcert/pdf/ssa-256353.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-256353.pdf</a><br/>
Adobe Bulletins<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7914" type="text/plain" language="en" />
<itunes:keywords>adobe, siemens, ruggedcom, russian, government, supply chain, ukraine, malware, tp240phonehome, mitel, infostealer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7912</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; @armissecurity APC UPS Vuln.; HP Firmware Bugs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; @armissecurity APC UPS Vuln.; HP Firmware Bugs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7912.mp3" length="4955960" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7912.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7912</link>
<pubDate>Wed, 09 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+March+2022+Patch+Tuesday/28418/">https://isc.sans.edu/forums/diary/Microsoft+March+2022+Patch+Tuesday/28418/</a><br/>
Critical APC UPS Vulnerability<br/>
 <a href="https://www.armis.com/research/tlstorm/">https://www.armis.com/research/tlstorm/</a><br/>
Vulnerabilities in Firmware Affecting HP Devices<br/>
 <a href="https://www.binarly.io/news/BinarlyDiscovers16NewHighImpactVulnerabilitiesinFirmwareAffectingHPEnterpriseDevices/index.html">https://www.binarly.io/news/BinarlyDiscovers16NewHighImpactVulnerabilitiesinFirmwareAffectingHPEnterpriseDevices/index.html</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7912" type="text/plain" language="en" />
<itunes:keywords>microsoft, patch tuesday, apc, ups, schneider, firmware, hp, uefi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7910</itunes:episode>
<itunes:subtitle>Ukraine Scam Followup; Dirty Pipe; Firefox Update; Azure AutoWarp; Terramaster Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ukraine Scam Followup; Dirty Pipe; Firefox Update; Azure AutoWarp; Terramaster Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7910.mp3" length="5154734" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7910.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7910</link>
<pubDate>Mon, 07 Mar 2022 22:06:25 GMT</pubDate>
<description><![CDATA[Ukraine Scam Followup<br/>
 <a href="https://isc.sans.edu/forums/diary/No+Bitcoin+No+Problem+Follow+Up+to+Last+Weeks+Donation+Scam/28412/">https://isc.sans.edu/forums/diary/No+Bitcoin+No+Problem+Follow+Up+to+Last+Weeks+Donation+Scam/28412/</a><br/>
Dirty Pipe Linux Vulnerability<br/>
 <a href="https://dirtypipe.cm4all.com">https://dirtypipe.cm4all.com</a><br/>
Mozilla Firefox and Thunderbird Vulnerability<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/">https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/</a><br/>
Azure AutoWarp<br/>
 <a href="https://orca.security/resources/blog/autowarp-microsoft-azure-automation-service-vulnerability/">https://orca.security/resources/blog/autowarp-microsoft-azure-automation-service-vulnerability/</a><br/>
Terramaster TOS Vulnerability<br/>
 <a href="https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/">https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/</a><br/>
 <a href="https://forum.terra-master.com/en/viewtopic.php?f=28&t=3030">https://forum.terra-master.com/en/viewtopic.php?f=28&t=3030</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7910" type="text/plain" language="en" />
<itunes:keywords>terramaster, azure, autowarp, mozilla, firefox, thunderbird, dirty pipe, ukraine, scam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7908</itunes:episode>
<itunes:subtitle>Ukraine Donation Scam; Cogent Disconnnects Russia; Russia DDoS Lists;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ukraine Donation Scam; Cogent Disconnnects Russia; Russia DDoS Lists;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7908.mp3" length="5971962" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7908.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7908</link>
<pubDate>Mon, 07 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Ukraine Dontation Scam<br/>
 <a href="https://isc.sans.edu/forums/diary/Scam+EMail+Impersonating+Red+Cross/28404/">https://isc.sans.edu/forums/diary/Scam+EMail+Impersonating+Red+Cross/28404/</a><br/>
Cogent Disconnects Russia<br/>
 <a href="https://www.washingtonpost.com/technology/2022/03/04/russia-ukraine-internet-cogent-cutoff/">https://www.washingtonpost.com/technology/2022/03/04/russia-ukraine-internet-cogent-cutoff/</a><br/>
Russia DDoS Lists<br/>
 <a href="https://safe-surf.ru/upload/ALRT/proxies.txt">https://safe-surf.ru/upload/ALRT/proxies.txt</a><br/>
 <a href="https://safe-surf.ru/upload/ALRT/referer_http_header.txt">https://safe-surf.ru/upload/ALRT/referer_http_header.txt</a><br/>
NVidia Stolen Certificates<br/>
 <a href="https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/">https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/</a><br/>
 <a href="https://twitter.com/cyb3rops/status/1499514240008437762">https://twitter.com/cyb3rops/status/1499514240008437762</a><br/>
GitLab Vulnerabilities<br/>
 <a href="https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/#unauthenticated-user-enumeration-on-graphql-api">https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/#unauthenticated-user-enumeration-on-graphql-api</a><br/>
Cisco Patches<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7908" type="text/plain" language="en" />
<itunes:keywords>cisco, expressway, gitlab, nvidia, certificates, russia, ukraine, ddos, certificates, red cross, scam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7906</itunes:episode>
<itunes:subtitle>Odd OpenWRT Scan; Alexa Hacks Alexa; Google Cloud Armor Update; Ukraine Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd OpenWRT Scan; Alexa Hacks Alexa; Google Cloud Armor Update; Ukraine Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7906.mp3" length="6281549" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7906.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7906</link>
<pubDate>Fri, 04 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Attackers Search For Exosed "LuCI" Folders<br/>
 <a href="https://isc.sans.edu/diary/28400">https://isc.sans.edu/diary/28400</a><br/>
Alexa Versus Alexa<br/>
 <a href="https://arxiv.org/abs/2202.08619">https://arxiv.org/abs/2202.08619</a><br/>
Bypassing Google Cloud Armor<br/>
 <a href="https://kloudle.com/blog/piercing-the-cloud-armor-the-8kb-bypass-in-google-cloud-platform-waf">https://kloudle.com/blog/piercing-the-cloud-armor-the-8kb-bypass-in-google-cloud-platform-waf</a><br/>
Ukraine Updates<br/>
 <a href="https://www.golem.de/news/ausfall-angriff-auf-ka-sat-satellit-ueber-gatewaystation-in-ukraine-2203-163614.html">https://www.golem.de/news/ausfall-angriff-auf-ka-sat-satellit-ueber-gatewaystation-in-ukraine-2203-163614.html</a><br/>
 <a href="https://www.crowdstrike.com/blog/how-to-decrypt-the-partyticket-ransomware-targeting-ukraine/">https://www.crowdstrike.com/blog/how-to-decrypt-the-partyticket-ransomware-targeting-ukraine/</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/ukraine-says-local-govt-sites-hacked-to-push-fake-capitulation-news/">https://www.bleepingcomputer.com/news/security/ukraine-says-local-govt-sites-hacked-to-push-fake-capitulation-news/</a><br/>
]]></description>
<itunes:duration>7:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7906" type="text/plain" language="en" />
<itunes:keywords>google, cloud armor, openwrt, satellite, ukraine, alexa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7904</itunes:episode>
<itunes:subtitle>Recognizing Biased/Fake News; FortiMail Bug; IBM; Google Chrome; Conti Leak; Middlebox DDoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Recognizing Biased/Fake News; FortiMail Bug; IBM; Google Chrome; Conti Leak; Middlebox DDoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7904.mp3" length="4895266" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7904.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7904</link>
<pubDate>Thu, 03 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[The More Often Something is Repeated, the More True it Becomes<br/>
 <a href="https://isc.sans.edu/forums/diary/The+More+Often+Something+is+Repeated+the+More+True+It+Becomes+Dealing+with+Social+Media/28396/">https://isc.sans.edu/forums/diary/The+More+Often+Something+is+Repeated+the+More+True+It+Becomes+Dealing+with+Social+Media/28396/</a><br/>
Fortinet Bug<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-21-028">https://www.fortiguard.com/psirt/FG-IR-21-028</a><br/>
IBM Updates<br/>
 <a href="https://www.ibm.com/blogs/psirt/">https://www.ibm.com/blogs/psirt/</a><br/>
Google Updates<br/>
 <a href="https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html</a><br/>
Conti Ransomware Leak<br/>
 <a href="https://threatpost.com/conti-ransomware-decryptor-trickbot-source-code-leaked/178727/">https://threatpost.com/conti-ransomware-decryptor-trickbot-source-code-leaked/178727/</a><br/>
Middle Box DDoS Attacks<br/>
 <a href="https://www.akamai.com/blog/security/tcp-middlebox-reflection">https://www.akamai.com/blog/security/tcp-middlebox-reflection</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7904" type="text/plain" language="en" />
<itunes:keywords>middle box, ddos, conti, ransomware, leak, google, chrome, ibm, fortinet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7902</itunes:episode>
<itunes:subtitle>Geoblocking; IsaacWiper; PJSIP Vulnerability; Octa Patch; ViaSat Outage
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Geoblocking; IsaacWiper; PJSIP Vulnerability; Octa Patch; ViaSat Outage
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7902.mp3" length="5384345" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7902.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7902</link>
<pubDate>Wed, 02 Mar 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Geoblocking when you can't Geoblock<br/>
 <a href="https://isc.sans.edu/forums/diary/Geoblocking+when+you+cant+Geoblock/28392/">https://isc.sans.edu/forums/diary/Geoblocking+when+you+cant+Geoblock/28392/</a><br/>
IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine<br/>
 <a href="https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/">https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/</a><br/>
Memory Corruption Vulnerabilities in PJSIP<br/>
 <a href="https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/">https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/</a><br/>
Octa Patch for Advanced Server Access Client<br/>
 <a href="https://trust.okta.com/security-advisories/okta-advanced-server-access-client-cve-2022-24295">https://trust.okta.com/security-advisories/okta-advanced-server-access-client-cve-2022-24295</a><br/>
ViaSat Outage<br/>
 <a href="https://www.reuters.com/business/aerospace-defense/satellite-firm-viasat-probes-suspected-cyberattack-ukraine-elsewhere-2022-02-28/">https://www.reuters.com/business/aerospace-defense/satellite-firm-viasat-probes-suspected-cyberattack-ukraine-elsewhere-2022-02-28/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7902" type="text/plain" language="en" />
<itunes:keywords>geoblocking, viasat, ukraine, octa, memory, pjsip, isaacwiper, hermetic wipter, isaac, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7900</itunes:episode>
<itunes:subtitle>PHP Update; Mozilla VPN Bug; Google Captcha Bypass; Samsung Encryption; Multiple IPs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PHP Update; Mozilla VPN Bug; Google Captcha Bypass; Samsung Encryption; Multiple IPs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7900.mp3" length="5998662" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7900.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7900</link>
<pubDate>Tue, 01 Mar 2022 02:00:01 GMT</pubDate>
<description><![CDATA[PHP Patches Code Injection Flaw<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21708">https://nvd.nist.gov/vuln/detail/CVE-2021-21708</a><br/>
 <a href="https://bugs.php.net/bug.php?id=81708">https://bugs.php.net/bug.php?id=81708</a><br/>
Mozilla VPN Local Privilege Escalation<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2022-08/">https://www.mozilla.org/en-US/security/advisories/mfsa2022-08/</a><br/>
Google Captcha Breaking<br/>
 <a href="https://east-ee.com/2022/02/28/1367/">https://east-ee.com/2022/02/28/1367/</a><br/>
Samsung Encryption Vulnerability<br/>
 <a href="https://eprint.iacr.org/2022/208.pdf">https://eprint.iacr.org/2022/208.pdf</a><br/>
tshark Multiple IPs<br/>
 <a href="https://isc.sans.edu/forums/diary/TShark+Multiple+IP+Addresses/28386/">https://isc.sans.edu/forums/diary/TShark+Multiple+IP+Addresses/28386/</a><br/>
]]></description>
<itunes:duration>6:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7900" type="text/plain" language="en" />
<itunes:keywords>tshark, samsung, google, captcha, recaptcha, php, filter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7898</itunes:episode>
<itunes:subtitle>Ukraine Update; Static Windows IPs; Snort and NetWitness; NVidia Breach; Incomplete Win11 Reset
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ukraine Update; Static Windows IPs; Snort and NetWitness; NVidia Breach; Incomplete Win11 Reset
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7898.mp3" length="4994226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7898.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7898</link>
<pubDate>Mon, 28 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Ukraine Update<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ransomware-gangs-hackers-pick-sides-over-russia-invading-ukraine/">https://www.bleepingcomputer.com/news/security/ransomware-gangs-hackers-pick-sides-over-russia-invading-ukraine/</a><br/>
 <a href="https://ddosecrets.com/wiki/Tetraedr">https://ddosecrets.com/wiki/Tetraedr</a><br/>
 <a href="https://twitter.com/YourAnonOne/status/1496965766435926039">https://twitter.com/YourAnonOne/status/1496965766435926039</a><br/>
 <a href="https://www.wired.com/story/ukraine-it-army-russia-war-cyberattacks-ddos/">https://www.wired.com/story/ukraine-it-army-russia-war-cyberattacks-ddos/</a><br/>
Odd Windows Behaviour with Fixed Addresses<br/>
 <a href="https://isc.sans.edu/forums/diary/Windows+Fixed+IPv4+Addresses+and+APIPA/28380/">https://isc.sans.edu/forums/diary/Windows+Fixed+IPv4+Addresses+and+APIPA/28380/</a><br/>
Using Snort IDS Rules in NetWitness Packet Decoder<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Snort+IDS+Rules+with+NetWitness+PacketDecoder/28382/">https://isc.sans.edu/forums/diary/Using+Snort+IDS+Rules+with+NetWitness+PacketDecoder/28382/</a><br/>
NVidia Breach<br/>
 <a href="https://www.bloomberg.com/news/articles/2022-02-25/nvidia-is-investigating-cyber-attack-but-business-uninterrupted">https://www.bloomberg.com/news/articles/2022-02-25/nvidia-is-investigating-cyber-attack-but-business-uninterrupted</a><br/>
Windows 11 Reset Not Removing All Data<br/>
 <a href="https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#2783msgdesc">https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#2783msgdesc</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7898" type="text/plain" language="en" />
<itunes:keywords>Windows 11, NVidia, snort, netwitness, fixed address, apipa, ukraine, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7896</itunes:episode>
<itunes:subtitle>Ukraine Update and Webcast; Zabbix Vulnerability; Asustore Deadbolt; MSFT App Store Electron Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ukraine Update and Webcast; Zabbix Vulnerability; Asustore Deadbolt; MSFT App Store Electron Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7896.mp3" length="5933730" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7896.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7896</link>
<pubDate>Fri, 25 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Ukraine Update: Webcast<br/>
 <a href="https://www.sans.org/webcasts/russian-cyber-attack-escalation-in-ukraine/">https://www.sans.org/webcasts/russian-cyber-attack-escalation-in-ukraine/</a><br/>
 <br/>
Other Ukraine Related Stories<br/>
 <a href="https://isc.sans.edu/forums/diary/Ukraine+Russia+Situation+From+a+Domain+Names+Perspective/28376/">https://isc.sans.edu/forums/diary/Ukraine+Russia+Situation+From+a+Domain+Names+Perspective/28376/</a><br/>
 <a href="https://detection.watchguard.com">https://detection.watchguard.com</a><br/>
Zabbix Vulnerablity Exploited<br/>
 <a href="https://www.cisa.gov/uscert/ncas/current-activity/2022/02/22/cisa-adds-two-known-exploited-vulnerabilities-catalog">https://www.cisa.gov/uscert/ncas/current-activity/2022/02/22/cisa-adds-two-known-exploited-vulnerabilities-catalog</a><br/>
 <a href="https://support.zabbix.com/browse/ZBX-20350">https://support.zabbix.com/browse/ZBX-20350</a><br/>
Asustore Victim of Deadbolt Ransomware<br/>
 <a href="https://forum.asustor.com/viewtopic.php?f=45&t=12630">https://forum.asustor.com/viewtopic.php?f=45&t=12630</a><br/>
Firepower Rule Update Failure After March 5th 2022<br/>
 <a href="https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html?emailclick=CNSemail">https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html?emailclick=CNSemail</a><br/>
Social Media Takeover Malware Distrubeted Via Microsoft App Store<br/>
 <a href="https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/">https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7896" type="text/plain" language="en" />
<itunes:keywords>social media takeover, electron, microsoft, asustor, firepower, certificate, deadbolt, ukraine, wiper, zabbix, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 24th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7894</itunes:episode>
<itunes:subtitle>New Sandworm; Ukraine Wiper; Log4Shell Wrapup; pfsense authenticated RCE; BVP47 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Sandworm; Ukraine Wiper; Log4Shell Wrapup; pfsense authenticated RCE; BVP47 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7894.mp3" length="6164109" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7894.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7894</link>
<pubDate>Thu, 24 Feb 2022 03:15:01 GMT</pubDate>
<description><![CDATA[New Sandworm Malware Cyclops Blink Replaces VPNFilter<br/>
 <a href="https://www.ncsc.gov.uk/news/joint-advisory-shows-new-sandworm-malware-cyclops-blink-replaces-vpnfilter">https://www.ncsc.gov.uk/news/joint-advisory-shows-new-sandworm-malware-cyclops-blink-replaces-vpnfilter</a><br/>
Wiper Malware Seen Deployed Against Targets in the Ukraine<br/>
 <a href="https://twitter.com/juanandres_gs/status/1496581710368358400">https://twitter.com/juanandres_gs/status/1496581710368358400</a><br/>
 <a href="https://twitter.com/ESETresearch/status/1496581903205511181">https://twitter.com/ESETresearch/status/1496581903205511181</a><br/>
The Rise and Fall of log4shell<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Rise+and+Fall+of+log4shell/28372/">https://isc.sans.edu/forums/diary/The+Rise+and+Fall+of+log4shell/28372/</a><br/>
pfsense authenticated RCE<br/>
 <a href="https://www.shielder.it/advisories/pfsense-remote-command-execution/">https://www.shielder.it/advisories/pfsense-remote-command-execution/</a><br/>
BVP47 Backdoor<br/>
 <a href="https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf">https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf</a><br/>
]]></description>
<itunes:duration>6:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7894" type="text/plain" language="en" />
<itunes:keywords>nsa, equation group, pfsense, log4shell, log4j, ukraine, wiper, backdoor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 23rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7892</itunes:episode>
<itunes:subtitle>Old Vuln Still Used; Horde XSS Exploit; NoVNC Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Old Vuln Still Used; Horde XSS Exploit; NoVNC Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7892.mp3" length="5766553" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7892.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7892</link>
<pubDate>Wed, 23 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[A Good Old Equation Editor Vulnerablity Deliverying Malware<br/>
 <a href="https://www.welivesecurity.com/2022/02/22/teenage-cybercrime-stop-kids-wrong-path/">https://www.welivesecurity.com/2022/02/22/teenage-cybercrime-stop-kids-wrong-path/</a><br/>
Horde Webmail 5.2.22 - Account Takeover via Email<br/>
 <a href="https://blog.sonarsource.com/horde-webmail-account-takeover-via-email">https://blog.sonarsource.com/horde-webmail-account-takeover-via-email</a><br/>
NoVNC Phishing<br/>
 <a href="https://mrd0x.com/bypass-2fa-using-novnc/">https://mrd0x.com/bypass-2fa-using-novnc/</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7892" type="text/plain" language="en" />
<itunes:keywords>novnc, phishing, horde, webmail, xss, equation editor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 22nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7890</itunes:episode>
<itunes:subtitle>Odd E-Mail Addresses; SMS Number Rental; Xenomorph Banking Trojan; Cryptbot; Magento Clarification
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd E-Mail Addresses; SMS Number Rental; Xenomorph Banking Trojan; Cryptbot; Magento Clarification
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7890.mp3" length="5284880" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7890.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7890</link>
<pubDate>Tue, 22 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Sending an Email to an IPv4 Address<br/>
 <a href="https://isc.sans.edu/forums/diary/Sending+an+Email+to+an+IPv4+Address/28362/">https://isc.sans.edu/forums/diary/Sending+an+Email+to+an+IPv4+Address/28362/</a><br/>
SMS Phone-Verified Account Services<br/>
 <a href="https://www.trendmicro.com/en_us/research/22/b/sms-pva-services-use-of-infected-android-phones-reveals-flaws-in-sms-verification.html">https://www.trendmicro.com/en_us/research/22/b/sms-pva-services-use-of-infected-android-phones-reveals-flaws-in-sms-verification.html</a><br/>
Xenomorph Android Banking Trojan<br/>
 <a href="https://www.threatfabric.com/blogs/xenomorph-a-newly-hatched-banking-trojan.html">https://www.threatfabric.com/blogs/xenomorph-a-newly-hatched-banking-trojan.html</a><br/>
Modified CryptBot Infostealer Going After Crypto Wallets<br/>
 <a href="https://asec.ahnlab.com/en/31802/">https://asec.ahnlab.com/en/31802/</a><br/>
Clarification for Adobe Magento Vulnerabilties<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb22-12.html">https://helpx.adobe.com/security/products/magento/apsb22-12.html</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7890" type="text/plain" language="en" />
<itunes:keywords>magento, adobe, infostealer, cryptbot, xenomorph, android, sms, pve, email, ip address, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7888</itunes:episode>
<itunes:subtitle>Double Compressed; Cassandra Vuln.; Apple T2 Weakness; Snap Priv Escalation Weakness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Double Compressed; Cassandra Vuln.; Apple T2 Weakness; Snap Priv Escalation Weakness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7888.mp3" length="4567149" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7888.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7888</link>
<pubDate>Mon, 21 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Remcos RAT Delivered Through Doube Compressed Archive<br/>
 <a href="https://isc.sans.edu/forums/diary/Remcos+RAT+Delivered+Through+Double+Compressed+Archive/28354/">https://isc.sans.edu/forums/diary/Remcos+RAT+Delivered+Through+Double+Compressed+Archive/28354/</a><br/>
Cassandra User-Defined Functions Remote Code Execution<br/>
 <a href="https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/">https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/</a><br/>
Apple T2 Weakness<br/>
 <a href="https://www.forensicfocus.com/news/passware-kit-forensic-t2-add-on-the-first-password-recovery-tool-for-macs-with-t2-chips/">https://www.forensicfocus.com/news/passware-kit-forensic-t2-add-on-the-first-password-recovery-tool-for-macs-with-t2-chips/</a><br/>
snap priviledge escalation<br/>
 <a href="https://www.qualys.com/2022/02/17/cve-2021-44731/oh-snap-more-lemmings.txt">https://www.qualys.com/2022/02/17/cve-2021-44731/oh-snap-more-lemmings.txt</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7888" type="text/plain" language="en" />
<itunes:keywords>snap, ubuntu, apple, t2, cassandra, file vault, disk encryption, compression, remcos rat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7886</itunes:episode>
<itunes:subtitle>MSFT Teams Malware; Thunderbird Patch; Cisco DANE Vuln; GitHub Code Scanning
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Teams Malware; Thunderbird Patch; Cisco DANE Vuln; GitHub Code Scanning
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7886.mp3" length="4743979" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7886.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7886</link>
<pubDate>Fri, 18 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Hackers Attach Malicious .exe Files to Teams Conversations<br/>
 <a href="https://www.avanan.com/blog/hackers-attach-malicious-.exe-files-to-teams-conversations">https://www.avanan.com/blog/hackers-attach-malicious-.exe-files-to-teams-conversations</a><br/>
Thunderbird Patches<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2022-07/">https://www.mozilla.org/en-US/security/advisories/mfsa2022-07/</a><br/>
Cisco Secure Email Gateway Update<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-MxZvGtgU">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-MxZvGtgU</a><br/>
GitHub Code Scanning Finds More Vulnerabilities Using Machine Learning<br/>
 <a href="https://github.blog/2022-02-17-code-scanning-finds-vulnerabilities-using-machine-learning/">https://github.blog/2022-02-17-code-scanning-finds-vulnerabilities-using-machine-learning/</a><br/>
Exploit for Magento Vulnerability (CVE-2022-24086) Available<br/>
 <a href="https://twitter.com/ptswarm/status/1494240197915123713">https://twitter.com/ptswarm/status/1494240197915123713</a><br/>
More Packet Fu With Zeek<br/>
 <a href="https://isc.sans.edu/forums/diary/More+packet+fu+with+zeek/28350/">https://isc.sans.edu/forums/diary/More+packet+fu+with+zeek/28350/</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7886" type="text/plain" language="en" />
<itunes:keywords>zeek, geolocation, github, cisco, email, thunderbird, magento, teams, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7884</itunes:episode>
<itunes:subtitle>Astaroth Infection; Atlassian Jira Updates; VMWare Updates; BEC via Virtual Meeting
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Astaroth Infection; Atlassian Jira Updates; VMWare Updates; BEC via Virtual Meeting
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7884.mp3" length="4938446" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7884.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7884</link>
<pubDate>Thu, 17 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Astaroth (Guildma) Infection<br/>
 <a href="https://isc.sans.edu/forums/diary/Astaroth+Guildma+infection/28346/">https://isc.sans.edu/forums/diary/Astaroth+Guildma+infection/28346/</a><br/>
Atlassian Jira Updates<br/>
 <a href="https://jira.atlassian.com/browse/CONFSERVER-66550">https://jira.atlassian.com/browse/CONFSERVER-66550</a><br/>
VMWare Updates<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0004.html">https://www.vmware.com/security/advisories/VMSA-2022-0004.html</a><br/>
FBI Warns of BEC Using Virtual Meeting Platforms<br/>
 <a href="https://www.ic3.gov/Media/Y2022/PSA220216">https://www.ic3.gov/Media/Y2022/PSA220216</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7884" type="text/plain" language="en" />
<itunes:keywords>fbi, vmware, atlassian, jira, astaroth, guildma, docusign, bec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 16th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7882</itunes:episode>
<itunes:subtitle>Bot Breakdown; SquirrelWaffle; WD MyCloud; Nooie Baby Monitor;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bot Breakdown; SquirrelWaffle; WD MyCloud; Nooie Baby Monitor;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7882.mp3" length="5092206" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7882.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7882</link>
<pubDate>Wed, 16 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Who Are Those Bots?<br/>
 <a href="https://isc.sans.edu/forums/diary/Who+Are+Those+Bots/28342/">https://isc.sans.edu/forums/diary/Who+Are+Those+Bots/28342/</a><br/>
SquirrelWaffle Adds a Twist of Fraud to Exchange Server Malspamming<br/>
 <a href="https://news.sophos.com/en-us/2022/02/15/vulnerable-exchange-server-hit-by-squirrelwaffle-and-financial-fraud/">https://news.sophos.com/en-us/2022/02/15/vulnerable-exchange-server-hit-by-squirrelwaffle-and-financial-fraud/</a><br/>
Details About Western Digital MyCloud Flaw<br/>
 <a href="https://www.iot-inspector.com/blog/advisory-western-digital-my-cloud-pro-series-pr4100-rce/">https://www.iot-inspector.com/blog/advisory-western-digital-my-cloud-pro-series-pr4100-rce/</a><br/>
Nooie Baby Monitor Vulnerabilities<br/>
 <a href="https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-nooie-baby-monitor/">https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-nooie-baby-monitor/</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7882" type="text/plain" language="en" />
<itunes:keywords>nooie, baby monitor, westerdan digital, mycloud, squirrelwaffle, exchange server, malspam, bec, bots, email, server, brute force, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 15th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7880</itunes:episode>
<itunes:subtitle>TLS Hello; Magento 0-Day; BigSur/Catalina Mystery Update; MSFT Defender and MacOS Issues; Google Chrome; Moxa MXView
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TLS Hello; Magento 0-Day; BigSur/Catalina Mystery Update; MSFT Defender and MacOS Issues; Google Chrome; Moxa MXView
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7880.mp3" length="5072730" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7880.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7880</link>
<pubDate>Tue, 15 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Reminder: Decoding TLS Client Hello to Non TLS Servers<br/>
 <a href="https://isc.sans.edu/forums/diary/Reminder+Decoding+TLS+Client+Hellos+to+non+TLS+servers/28338/">https://isc.sans.edu/forums/diary/Reminder+Decoding+TLS+Client+Hellos+to+non+TLS+servers/28338/</a><br/>
Magento 2 Critical Vulnerability<br/>
 <a href="https://sansec.io/research/magento-2-cve-2022-24086">https://sansec.io/research/magento-2-cve-2022-24086</a><br/>
BigSur/Catalina Mystery Update<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
MacOS Monterey Patch and Microsoft Defender<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mde-apparently-blocks-macos-monterey-12-1-12-2-upgrades/m-p/3078793">https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mde-apparently-blocks-macos-monterey-12-1-12-2-upgrades/m-p/3078793</a><br/>
Google Chrome 0-Day Fixed<br/>
 <a href="https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html">https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html</a><br/>
Moxa MXview Vulnerabilities and Patch<br/>
 <a href="https://www.claroty.com/2022/02/10/blog-research-securing-network-management-systems-moxa-mxview/">https://www.claroty.com/2022/02/10/blog-research-securing-network-management-systems-moxa-mxview/</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7880" type="text/plain" language="en" />
<itunes:keywords>moxa, mxview, google, chrome, apple, bigsur, catalina, monterey, msft defender, tls, hello, magento, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7878</itunes:episode>
<itunes:subtitle>CinaRAT via HTML IDs; Protecting LSASS; Blocking Facebook Credential Exposure
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CinaRAT via HTML IDs; Protecting LSASS; Blocking Facebook Credential Exposure
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7878.mp3" length="4552904" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7878.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7878</link>
<pubDate>Mon, 14 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[CinaRAT Delivered Through HTML ID Attributes<br/>
 <a href="https://isc.sans.edu/forums/diary/CinaRAT+Delivered+Through+HTML+ID+Attributes/28330/">https://isc.sans.edu/forums/diary/CinaRAT+Delivered+Through+HTML+ID+Attributes/28330/</a><br/>
Windows Defender ASR Blocks LSASS Credential Stealing<br/>
 <a href="https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-credential-stealing-from-the-windows-local-security-authority-subsystem">https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-credential-stealing-from-the-windows-local-security-authority-subsystem</a><br/>
Brave Blocking Credential Leaking Extension <br/>
 <a href="https://www.theregister.com/2022/02/12/facebook_god_mode/">https://www.theregister.com/2022/02/12/facebook_god_mode/</a><br/>
Project Zero Summary of Zero Day Bugs<br/>
 <a href="https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html">https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7878" type="text/plain" language="en" />
<itunes:keywords>google project zero, bugs, fixes, brave, chrome, extensions, facebook, windows, defender, ASR, LSASS, mimikatz, cinarat, html, id, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7876</itunes:episode>
<itunes:subtitle>WebKit 0-Day Patch; Zyxel NAS Exploit; WMIC Removal; Zoom Mac Microphone; Planted Evidence
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebKit 0-Day Patch; Zyxel NAS Exploit; WMIC Removal; Zoom Mac Microphone; Planted Evidence
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7876.mp3" length="5382356" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7876.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7876</link>
<pubDate>Fri, 11 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[iOS/iPadOS/macOS/Safari 0-Day Vulnerability in WebKit<br/>
 <a href="https://support.apple.com/en-us/HT213091">https://support.apple.com/en-us/HT213091</a><br/>
Zyxel Network Storage Devics Hunted By Mirai Variant<br/>
 <a href="https://isc.sans.edu/forums/diary/Zyxel+Network+Storage+Devices+Hunted+By+Mirai+Variant/28324/">https://isc.sans.edu/forums/diary/Zyxel+Network+Storage+Devices+Hunted+By+Mirai+Variant/28324/</a><br/>
WMIC Removal<br/>
 <a href="https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-deprecated-features">https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-deprecated-features</a><br/>
Zoom Uses Microphone after Meeting is Over<br/>
 <a href="https://community.zoom.com/t5/Meetings/Why-is-the-Zoom-app-listening-on-my-microphone-when-not-in-a/td-p/29019">https://community.zoom.com/t5/Meetings/Why-is-the-Zoom-app-listening-on-my-microphone-when-not-in-a/td-p/29019</a><br/>
Evidence Planted to Implicate Innocent Activists<br/>
 <a href="https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/">https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7876" type="text/plain" language="en" />
<itunes:keywords>planted evidence, zoom, microphone, wmic, zyxal, nas, apple, ios, macos, ipados, safari, webkit, 0day, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7874</itunes:episode>
<itunes:subtitle>Cobalt Strike via Emotet; Adobe Patches; Intel Updates; MageCart via Magento
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobalt Strike via Emotet; Adobe Patches; Intel Updates; MageCart via Magento
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7874.mp3" length="5669693" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7874.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7874</link>
<pubDate>Thu, 10 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Example of Cobalt Strike form Emotet Infection<br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+Cobalt+Strike+from+Emotet+infection/28318/">https://isc.sans.edu/forums/diary/Example+of+Cobalt+Strike+from+Emotet+infection/28318/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
Intel Updates<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/default.html">https://www.intel.com/content/www/us/en/security-center/default.html</a><br/>
NaturalFreshMall: A Mass Store Attack<br/>
 <a href="https://sansec.io/research/naturalfreshmall-mass-hack">https://sansec.io/research/naturalfreshmall-mass-hack</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7874" type="text/plain" language="en" />
<itunes:keywords>magecart, javascript, skimmer, intel, adobe, patches, cobalt strike, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 9th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7872</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; Google vs Cryptominers; Android Patches; SAP Patches; #Podcast Anniversary  #podcastaniversary</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; Google vs Cryptominers; Android Patches; SAP Patches; #Podcast Anniversary  #podcastaniversary</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7872.mp3" length="5150874" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7872.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7872</link>
<pubDate>Wed, 09 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+February+2022+Patch+Tuesday/28316/">https://isc.sans.edu/forums/diary/Microsoft+February+2022+Patch+Tuesday/28316/</a><br/>
Google Cloud Virtual Machine Threat Detection<br/>
 <a href="https://cloud.google.com/security-command-center/docs/concepts-vm-threat-detection-overview">https://cloud.google.com/security-command-center/docs/concepts-vm-threat-detection-overview</a><br/>
Android Patches<br/>
 <a href="https://source.android.com/security/bulletin/2022-02-01">https://source.android.com/security/bulletin/2022-02-01</a><br/>
SAP Patches<br/>
 <a href="https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022">https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022</a><br/>
Podcast 13 Year Anniversary<br/>
 <a href="https://isc.sans.edu/podcastdetail.html?id=25">https://isc.sans.edu/podcastdetail.html?id=25</a>]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7872" type="text/plain" language="en" />
<itunes:keywords>podcast, aniversary, sap, android, microsoft, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 8th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7870</itunes:episode>
<itunes:subtitle>Distributed Web Phish; MSFT vs. VBA; Acronis Update; Lockbit 2 IoCs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Distributed Web Phish; MSFT vs. VBA; Acronis Update; Lockbit 2 IoCs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7870.mp3" length="5084884" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7870.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7870</link>
<pubDate>Tue, 08 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[web3 phishing via self-customizign landing pages<br/>
 <a href="https://isc.sans.edu/forums/diary/web3+phishing+via+selfcustomizing+landing+pages/28312/">https://isc.sans.edu/forums/diary/web3+phishing+via+selfcustomizing+landing+pages/28312/</a><br/>
MSFT Blocking Office VBA Malcros<br/>
 <a href="https://www.theverge.com/2022/2/7/22922032/microsoft-block-office-vba-macros-default-change">https://www.theverge.com/2022/2/7/22922032/microsoft-block-office-vba-macros-default-change</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805">https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805</a><br/>
Acronis True Image Update<br/>
 <a href="https://security-advisory.acronis.com/updates/UPD-2201-f76f-838c">https://security-advisory.acronis.com/updates/UPD-2201-f76f-838c</a><br/>
Lockbit 2 IoCs<br/>
 <a href="https://www.ic3.gov/Media/News/2022/220204.pdf">https://www.ic3.gov/Media/News/2022/220204.pdf</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7870" type="text/plain" language="en" />
<itunes:keywords>lockbit, ransomware, acronic, msft, microsoft, vba, web3, distrubted web, skynet, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7868</itunes:episode>
<itunes:subtitle>Tax Phishing; IRS and ID.me; Argo CD Patch; PoE and Thermals
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tax Phishing; IRS and ID.me; Argo CD Patch; PoE and Thermals
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7868.mp3" length="5575525" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7868.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7868</link>
<pubDate>Mon, 07 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Intuit warns of new phishing scams<br/>
  <a href="https://security.intuit.com/security-notices">https://security.intuit.com/security-notices</a><br/>
IRS working with ID.me<br/>
  <a href="https://www.irs.gov/newsroom/new-identity-verification-process-to-access-certain-irs-online-tools-and-services">https://www.irs.gov/newsroom/new-identity-verification-process-to-access-certain-irs-online-tools-and-services</a><br/>
Argo CD Vulnerability<br/>
  <a href="https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments/">https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments/</a><br/>
  <a href="https://github.com/argoproj/argo-cd/security/advisories/GHSA-63qx-x74g-jcr7">https://github.com/argoproj/argo-cd/security/advisories/GHSA-63qx-x74g-jcr7</a><br/>
Thermal Imaging of PoE Devices<br/>
  <a href="https://isc.sans.edu/forums/diary/Power+over+Ethernet+and+Thermal+Imaging/28308/">https://isc.sans.edu/forums/diary/Power+over+Ethernet+and+Thermal+Imaging/28308/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7868" type="text/plain" language="en" />
<itunes:keywords>thermal, ir, poe, argo, cd, irs, id.me, intuit, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7866</itunes:episode>
<itunes:subtitle>Attack Surface Detection; MFA News; #Zimbra 0Day; #Cisco RV Series Routers;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Attack Surface Detection; MFA News; #Zimbra 0Day; #Cisco RV Series Routers;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7866.mp3" length="4784585" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7866.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7866</link>
<pubDate>Fri, 04 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Attack Surface Detection<br/>
 <a href="https://isc.sans.edu/forums/diary/Keeping+Track+of+Your+Attack+Surface+for+Cheap/28304/">https://isc.sans.edu/forums/diary/Keeping+Track+of+Your+Attack+Surface+for+Cheap/28304/</a><br/>
MFA News<br/>
 <a href="https://www.proofpoint.com/us/blog/threat-insight/mfa-psa-oh-my">https://www.proofpoint.com/us/blog/threat-insight/mfa-psa-oh-my</a><br/>
 <a href="https://news.microsoft.com/wp-content/uploads/prod/sites/626/2022/02/Cyber-Signals-E-1.pdf">https://news.microsoft.com/wp-content/uploads/prod/sites/626/2022/02/Cyber-Signals-E-1.pdf</a><br/>
Zimbra Webmail 0-Day Exploited<br/>
 <a href="https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/">https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/</a><br/>
Cisco RV Series Routers Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7866" type="text/plain" language="en" />
<itunes:keywords>cisco, zimbra, webmail, rv series, phishing, MFA, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7864</itunes:episode>
<itunes:subtitle>Finding elFinder;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding elFinder;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7864.mp3" length="4943370" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7864.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7864</link>
<pubDate>Thu, 03 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Finding elFinder: Who is looking for your files?<br/>
 <a href="https://isc.sans.edu/forums/diary/Finding+elFinder+Who+is+looking+for+your+files/28300/">https://isc.sans.edu/forums/diary/Finding+elFinder+Who+is+looking+for+your+files/28300/</a><br/>
IBM Spectrum Protect Plus Container Backup Vulnerabilities<br/>
 <a href="https://www.ibm.com/support/pages/node/6540860">https://www.ibm.com/support/pages/node/6540860</a><br/>
 <a href="https://www.ibm.com/support/pages/node/6552188">https://www.ibm.com/support/pages/node/6552188</a><br/>
Microsoft Update Connectivity<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/achieve-better-patch-compliance-with-update-connectivity-data/ba-p/3073356">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/achieve-better-patch-compliance-with-update-connectivity-data/ba-p/3073356</a><br/>
UEFI Bios Vulnerabilities<br/>
 <a href="https://www.insyde.com/security-pledge">https://www.insyde.com/security-pledge</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7864" type="text/plain" language="en" />
<itunes:keywords>uefi, microsoft, updates, elfinder, php, file upload, IBM, spectrum protect, backup, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 2nd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7862</itunes:episode>
<itunes:subtitle>Windows Priv Esc PoC; Web GPU Fingerprint; Automation Limits; Fake Job Ads;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Priv Esc PoC; Web GPU Fingerprint; Automation Limits; Fake Job Ads;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7862.mp3" length="5333614" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7862.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7862</link>
<pubDate>Wed, 02 Feb 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Windows Privilege Escalation Exploit CVE-2022-21882<br/>
 <a href="https://github.com/KaLendsi/CVE-2022-21882">https://github.com/KaLendsi/CVE-2022-21882</a><br/>
Fingerprinting Devices Via GPU<br/>
 <a href="https://arxiv.org/pdf/2201.09956.pdf">https://arxiv.org/pdf/2201.09956.pdf</a><br/>
SolarMarker Campaign used novel registry changes to establish persistence<br/>
 <a href="https://news.sophos.com/en-us/2022/02/01/solarmarker-campaign-used-novel-registry-changes-to-establish-persistence/">https://news.sophos.com/en-us/2022/02/01/solarmarker-campaign-used-novel-registry-changes-to-establish-persistence/</a><br/>
Fake Job Ads<br/>
 <a href="https://www.ic3.gov/Media/Y2022/PSA220201">https://www.ic3.gov/Media/Y2022/PSA220201</a><br/>
Automation is Nice But Don't Replace Your Knowledge<br/>
 <a href="https://isc.sans.edu/forums/diary/Automation+is+Nice+But+Dont+Replace+Your+Knowledge/28296/">https://isc.sans.edu/forums/diary/Automation+is+Nice+But+Dont+Replace+Your+Knowledge/28296/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7862" type="text/plain" language="en" />
<itunes:keywords>automation, ssh, fake job ads, solarmarker, registry, gpu, priv escalation, poc, windows, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 1st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7860</itunes:episode>
<itunes:subtitle>RPMSG Phishing; QNAP Auto Update; Samba Vuln; Datacenter Managment Exposed; XML Parser Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RPMSG Phishing; QNAP Auto Update; Samba Vuln; Datacenter Managment Exposed; XML Parser Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7860.mp3" length="4760701" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7860.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7860</link>
<pubDate>Tue, 01 Feb 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Be Careful with RPMSG Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Be+careful+with+RPMSG+files/28292/">https://isc.sans.edu/forums/diary/Be+careful+with+RPMSG+files/28292/</a><br/>
QNAP Auto Update Clarification<br/>
 <a href="https://www.qnap.com/en/security-news/2022/descriptions-and-explanations-of-the-qts-quts-hero-recommended-version-feature">https://www.qnap.com/en/security-news/2022/descriptions-and-explanations-of-the-qts-quts-hero-recommended-version-feature</a><br/>
Samba Vulnerability<br/>
 <a href="https://kb.cert.org/vuls/id/119678">https://kb.cert.org/vuls/id/119678</a><br/>
Exposed Datacenter Management<br/>
 <a href="https://www.bleepingcomputer.com/news/security/over-20-000-data-center-management-systems-exposed-to-hackers/">https://www.bleepingcomputer.com/news/security/over-20-000-data-center-management-systems-exposed-to-hackers/</a><br/>
Expat Vulnerability<br/>
 <a href="https://github.com/libexpat/libexpat/blob/master/expat/Changes">https://github.com/libexpat/libexpat/blob/master/expat/Changes</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7860" type="text/plain" language="en" />
<itunes:keywords>expat, datacenter, samba, rpmsg, phishing, qnap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 31st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7858</itunes:episode>
<itunes:subtitle>ISO inside HTML; YARA Console Module; Phishing Device Registration Trick; QNAP Forced Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ISO inside HTML; YARA Console Module; Phishing Device Registration Trick; QNAP Forced Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7858.mp3" length="5514121" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7858.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7858</link>
<pubDate>Mon, 31 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious ISO Embedded in an HTML Page<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+ISO+Embedded+in+an+HTML+Page/28282/">https://isc.sans.edu/forums/diary/Malicious+ISO+Embedded+in+an+HTML+Page/28282/</a><br/>
YARA Console Module<br/>
 <a href="https://isc.sans.edu/forums/diary/YARAs+Console+Module/28288/">https://isc.sans.edu/forums/diary/YARAs+Console+Module/28288/</a><br/>
Attackers Attaching Devices to Azure AD<br/>
 <a href="https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/">https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/</a><br/>
QNAP Forced Updates<br/>
 <a href="https://www.reddit.com/r/qnap/comments/sdsf02/i_just_suffered_what_i_believe_to_be_a_forced/huhfmjc/">https://www.reddit.com/r/qnap/comments/sdsf02/i_just_suffered_what_i_believe_to_be_a_forced/huhfmjc/</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7858" type="text/plain" language="en" />
<itunes:keywords>qnap, deadbolt, ransomware, azure, ad, devices, phishing, microsoft, yara, iso, html, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 28th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7856</itunes:episode>
<itunes:subtitle>Apple Bug Details; Little Snitch Bypass; DazzleSpy Malware; Intelligent Phishing Exercises; @sans_edu; @geoff_Dr
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Bug Details; Little Snitch Bypass; DazzleSpy Malware; Intelligent Phishing Exercises; @sans_edu; @geoff_Dr
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7856.mp3" length="13744807" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7856.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7856</link>
<pubDate>Fri, 28 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Technical Analysis of CVE-2022-22583<br/>
 <a href="https://perception-point.io/technical-analysis-of-cve-2022-22583-bypassing-macos-system-integrity-protection/">https://perception-point.io/technical-analysis-of-cve-2022-22583-bypassing-macos-system-integrity-protection/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28280/">https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28280/</a><br/>
Little Snitch Firewall Bypass<br/>
 <a href="https://rhinosecuritylabs.com/network-security/bypassing-little-snitch-firewall/">https://rhinosecuritylabs.com/network-security/bypassing-little-snitch-firewall/</a><br/>
DazzleSpy Malware<br/>
 <a href="https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/">https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/</a><br/>
Geoffrey Parker: Building an Intelligent, Automated Tiered Phishing System<br/>
 <a href="https://www.sans.edu/cyber-research/building-an-intelligent-automated-tiered-phishing-system-matching-the-message-level-to-user-ability/">https://www.sans.edu/cyber-research/building-an-intelligent-automated-tiered-phishing-system-matching-the-message-level-to-user-ability/</a><br/>
]]></description>
<itunes:duration>16:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7856" type="text/plain" language="en" />
<itunes:keywords>phishing, dazzlespy, sans.edu, little snitch, cve-2022-22583, apple, macos, sip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 27th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7854</itunes:episode>
<itunes:subtitle>Lights Out for iLO; Apple Updates Everything; Let's Encrypt Fixes;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Lights Out for iLO; Apple Updates Everything; Let's Encrypt Fixes;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7854.mp3" length="5655874" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7854.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7854</link>
<pubDate>Thu, 27 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Over 20 Thousand Servers Have Their iLO Interfaces exposed to the Internet<br/>
 <a href="https://isc.sans.edu/forums/diary/Over+20+thousand+servers+have+their+iLO+interfaces+exposed+to+the+internet+many+with+outdated+and+vulnerable+versions+of+FW/28276/">https://isc.sans.edu/forums/diary/Over+20+thousand+servers+have+their+iLO+interfaces+exposed+to+the+internet+many+with+outdated+and+vulnerable+versions+of+FW/28276/</a><br/>
Apple Patches and Exploits<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
 <a href="https://www.ryanpickren.com/safari-uxss">https://www.ryanpickren.com/safari-uxss</a><br/>
Let's Encrypt Fixes Problems and Revoces Certificates<br/>
 <a href="https://community.letsencrypt.org/t/changes-to-tls-alpn-01-challenge-validation/170427">https://community.letsencrypt.org/t/changes-to-tls-alpn-01-challenge-validation/170427</a><br/>
 <br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7854" type="text/plain" language="en" />
<itunes:keywords>lets encrypt, challenge, certificates, apple, patches, exploits, webcam, indexdb, ilo, hp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 26th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7852</itunes:episode>
<itunes:subtitle>Polkit Priv Esc. Vuln; Emotet Stops 0.0.0.0; log4j VMWare Exploits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Polkit Priv Esc. Vuln; Emotet Stops 0.0.0.0; log4j VMWare Exploits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7852.mp3" length="4744028" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7852.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7852</link>
<pubDate>Wed, 26 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Local Privilege Escalation Vulnerablity in Polkit's pkexec (CVE-2021-4034)<br/>
 <a href="https://isc.sans.edu/forums/diary/Local+privilege+escalation+vulnerability+in+polkits+pkexec+CVE20214034/28272/">https://isc.sans.edu/forums/diary/Local+privilege+escalation+vulnerability+in+polkits+pkexec+CVE20214034/28272/</a><br/>
Emotet Stops Using 0.0.0.0 in Spambot Traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+Stops+Using+0000+in+Spambot+Traffic/28270/">https://isc.sans.edu/forums/diary/Emotet+Stops+Using+0000+in+Spambot+Traffic/28270/</a><br/>
VMWare Warns of Log4j Exploitation<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0028.html">https://www.vmware.com/security/advisories/VMSA-2021-0028.html</a><br/>
 <a href="https://www.cynet.com/attack-techniques-hands-on/threats-looming-over-the-horizon/">https://www.cynet.com/attack-techniques-hands-on/threats-looming-over-the-horizon/</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7852" type="text/plain" language="en" />
<itunes:keywords>vmware, horizon, emotet, spambot, polkit, pkexec, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 25th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7850</itunes:episode>
<itunes:subtitle>UEFI Malware; Sonicwall Exploit; Dell EMC AppSync Vuln; Leaked Twitter Keys
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
UEFI Malware; Sonicwall Exploit; Dell EMC AppSync Vuln; Leaked Twitter Keys
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7850.mp3" length="5466060" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7850.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7850</link>
<pubDate>Tue, 25 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Moonbound UEFI Malware<br/>
 <a href="https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/">https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/</a><br/>
Exploit of Sonicwall CVE-2021-20038<br/>
 <a href="https://twitter.com/buffaloverflow/status/1485671824725786633">https://twitter.com/buffaloverflow/status/1485671824725786633</a><br/>
Dell EMC AppSync Vulnerability<br/>
 <a href="https://www.dell.com/support/kbdoc/de-de/000195377/dsa-2022-003-dell-emc-appsync-security-update-for-multiple-vulnerabilities">https://www.dell.com/support/kbdoc/de-de/000195377/dsa-2022-003-dell-emc-appsync-security-update-for-multiple-vulnerabilities</a><br/>
Twitter API Keys Leaked in GitHub<br/>
 <a href="https://incognitatech.medium.com/using-twitter-to-notify-careless-developers-the-unorthodox-way-d71478ad367a">https://incognitatech.medium.com/using-twitter-to-notify-careless-developers-the-unorthodox-way-d71478ad367a</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7850" type="text/plain" language="en" />
<itunes:keywords>twitter, api keys, github, dell, emc, appsync, uefi, moonbound, sonicwall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 24th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7848</itunes:episode>
<itunes:subtitle>Wininet.dll Feature; Excel "Real Estate" attack; F5 Patches; McAfee Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wininet.dll Feature; Excel "Real Estate" attack; F5 Patches; McAfee Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7848.mp3" length="5521279" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7848.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7848</link>
<pubDate>Mon, 24 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Obscure Wininet.dll Feature<br/>
 <a href="https://isc.sans.edu/forums/diary/Obscure+Wininetdll+Feature/28262/">https://isc.sans.edu/forums/diary/Obscure+Wininetdll+Feature/28262/</a><br/>
Mixed VBA and Excel 4 Macro in Targeted Excel Sheet<br/>
 <a href="https://isc.sans.edu/forums/diary/Mixed+VBA+Excel4+Macro+In+a+Targeted+Excel+Sheet/28264/">https://isc.sans.edu/forums/diary/Mixed+VBA+Excel4+Macro+In+a+Targeted+Excel+Sheet/28264/</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/excel-blog/excel-4-0-xlm-macros-now-restricted-by-default-for-customer/ba-p/3057905">https://techcommunity.microsoft.com/t5/excel-blog/excel-4-0-xlm-macros-now-restricted-by-default-for-customer/ba-p/3057905</a><br/>
F5 January 2022 Patches<br/>
 <a href="https://support.f5.com/csp/article/K40084114">https://support.f5.com/csp/article/K40084114</a><br/>
McAfee Privilege Escalation<br/>
 <a href="https://kc.mcafee.com/corporate/index?page=content&id=SB10378">https://kc.mcafee.com/corporate/index?page=content&id=SB10378</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7848" type="text/plain" language="en" />
<itunes:keywords>mcafee, f5, vba, excel, macro, wininet.dll, hsts, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 21st, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7846</itunes:episode>
<itunes:subtitle>RedLine Stealer; Google QR Code Bug; Linux Kernel Bug; Crypto.com 2FA Bypass; Windows GPOs to Avoid
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RedLine Stealer; Google QR Code Bug; Linux Kernel Bug; Crypto.com 2FA Bypass; Windows GPOs to Avoid
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7846.mp3" length="5539897" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7846.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7846</link>
<pubDate>Fri, 21 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[RedLine Stealer Delivered Through FTP<br/>
 <a href="https://isc.sans.edu/forums/diary/RedLine+Stealer+Delivered+Through+FTP/28258/">https://isc.sans.edu/forums/diary/RedLine+Stealer+Delivered+Through+FTP/28258/</a><br/>
Google Camera Alters QR Codes<br/>
 <a href="https://www.heise.de/hintergrund/Googles-Kamera-verfaelscht-Links-in-QR-Codes-6332669.html">https://www.heise.de/hintergrund/Googles-Kamera-verfaelscht-Links-in-QR-Codes-6332669.html</a><br/>
 <a href="https://www.androidpolice.com/google-camera-randomly-changes-some-qr-code-urls-on-android-12/">https://www.androidpolice.com/google-camera-randomly-changes-some-qr-code-urls-on-android-12/</a><br/>
Linux Kernel Privilege Escalation / Container Escape<br/>
 <a href="https://seclists.org/oss-sec/2022/q1/54">https://seclists.org/oss-sec/2022/q1/54</a><br/>
 <a href="https://access.redhat.com/security/cve/cve-2022-0185">https://access.redhat.com/security/cve/cve-2022-0185</a><br/>
Crypto.com 2FA Bypass<br/>
 <a href="https://threatpost.com/2fa-bypassed-crypto-com-heist/177846/">https://threatpost.com/2fa-bypassed-crypto-com-heist/177846/</a><br/>
Windows Policies to Avoid<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/why-you-shouldn-t-set-these-25-windows-policies/ba-p/3066178">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/why-you-shouldn-t-set-these-25-windows-policies/ba-p/3066178</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7846" type="text/plain" language="en" />
<itunes:keywords>windows, group policies, crypto.com, 2FA, MFA, Linux, kernel, camera, qr code, google ftp, redline, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 20th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7844</itunes:episode>
<itunes:subtitle>0.0.0.0 and Emotet; WebKit Patch; acer Care Center; Serv-U Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
0.0.0.0 and Emotet; WebKit Patch; acer Care Center; Serv-U Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7844.mp3" length="5536064" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7844.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7844</link>
<pubDate>Thu, 20 Jan 2022 02:25:02 GMT</pubDate>
<description><![CDATA[0.0.0.0 in Emotet Spambot Traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/0000+in+Emotet+Spambot+Traffic/28254/">https://isc.sans.edu/forums/diary/0000+in+Emotet+Spambot+Traffic/28254/</a><br/>
Linux Patch to Make 0.0.0.0/8 Routable<br/>
 <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=96125bf9985a">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=96125bf9985a</a><br/>
WebKit Patch for Cross Origin Database Name Leak<br/>
 <a href="https://trac.webkit.org/changeset/288078/webkit">https://trac.webkit.org/changeset/288078/webkit</a><br/>
ACER Care Center Privilege Escalation<br/>
 <a href="https://aptw.tf/2022/01/20/acer-care-center-privesc.html">https://aptw.tf/2022/01/20/acer-care-center-privesc.html</a><br/>
Imporper Input Validation Vulnerability in Serv-U<br/>
 <a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247">https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7844" type="text/plain" language="en" />
<itunes:keywords>serv-u, asus, webkit, acer, linux, emotet, spambot, 0.0.0.0, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 19th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7842</itunes:episode>
<itunes:subtitle>Phishing with Ads; Virustotal Hacking; Oracle Patches; Box MFA Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing with Ads; Virustotal Hacking; Oracle Patches; Box MFA Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7842.mp3" length="4932932" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7842.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7842</link>
<pubDate>Wed, 19 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Phishing E-Mail With an Advertisement<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+email+withan+advertisement/28250/">https://isc.sans.edu/forums/diary/Phishing+email+withan+advertisement/28250/</a><br/>
Virustotal Credential<br/>
 <a href="https://www.safebreach.com/blog/2022/the-perfect-cyber-crime/">https://www.safebreach.com/blog/2022/the-perfect-cyber-crime/</a><br/>
Oracle Quarterly Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpujan2022.html">https://www.oracle.com/security-alerts/cpujan2022.html</a><br/>
Box MFA Bypass<br/>
 <a href="https://www.varonis.com/blog/box-mfa-bypass-sms">https://www.varonis.com/blog/box-mfa-bypass-sms</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7842" type="text/plain" language="en" />
<itunes:keywords>box, mfa, oracle, virustotal, phishing, advertisement, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 18th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7840</itunes:episode>
<itunes:subtitle>Smarter Log4Shell; Special MSFT Update; Cisco CCMP Patch; Zoho Patch; Google Chrome Private Network Restriction
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Smarter Log4Shell; Special MSFT Update; Cisco CCMP Patch; Zoho Patch; Google Chrome Private Network Restriction
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7840.mp3" length="4880141" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7840.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7840</link>
<pubDate>Tue, 18 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Log4Shell Attacks Getting Smarter<br/>
 <a href="https://isc.sans.edu/forums/diary/Log4Shell+Attacks+Getting+Smarter/28246/">https://isc.sans.edu/forums/diary/Log4Shell+Attacks+Getting+Smarter/28246/</a><br/>
Microsoft Releases Special Update to Deal with January Update Fail<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-oob-updates-for-january-windows-update-issues/">https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-oob-updates-for-january-windows-update-issues/</a><br/>
Cisco Unified Contact Center Management Portal and Unifed Contact Center Domain Manager Privilege Escalation Vulnerablity<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ccmp-priv-esc-JzhTFLm4">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ccmp-priv-esc-JzhTFLm4</a><br/>
Zoho Critical Security Patch Released in Desktop Central and Desktop Central MSP<br/>
 <a href="https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022">https://pitstop.manageengine.com/portal/en/community/topic/a-critical-security-patch-released-in-desktop-central-and-desktop-central-msp-for-cve-2021-44757-17-1-2022</a><br/>
Google Chrome Restricting Private Network Access<br/>
 <a href="https://developer.chrome.com/blog/private-network-access-preflight/">https://developer.chrome.com/blog/private-network-access-preflight/</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7840" type="text/plain" language="en" />
<itunes:keywords>chrome, private networks, pna, preflight, zoho, desktop central, cisco, CCMP, microsoft, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 17th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7838</itunes:episode>
<itunes:subtitle>NTFS Alt. Data Streams; MSFT Resumes Windows Updates; Safari IndexDB Leak;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NTFS Alt. Data Streams; MSFT Resumes Windows Updates; Safari IndexDB Leak;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7838.mp3" length="4753662" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7838.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7838</link>
<pubDate>Mon, 17 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Use of Alternate Data Streams in Research Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Use+of+Alternate+Data+Streams+in+Research+Scans+for+indexjsp/28240/">https://isc.sans.edu/forums/diary/Use+of+Alternate+Data+Streams+in+Research+Scans+for+indexjsp/28240/</a><br/>
Microsoft Resumes Windows Server 2019 Cumulative Updates<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-resumes-rollout-of-january-windows-server-updates/">https://www.bleepingcomputer.com/news/microsoft/microsoft-resumes-rollout-of-january-windows-server-updates/</a><br/>
Safari Index DB Leak<br/>
 <a href="https://fingerprintjs.com/blog/indexeddb-api-browser-vulnerability-safari-15/">https://fingerprintjs.com/blog/indexeddb-api-browser-vulnerability-safari-15/</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7838" type="text/plain" language="en" />
<itunes:keywords>safari, indexdb, microsoft, windows server, 2019, updates, ads, ntfs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 14th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7836</itunes:episode>
<itunes:subtitle>MSFT Patch Issues; Jenkins Advisory; Qakbot Decryptor; Android 2G Disable; MSFT Defender Weakness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Issues; Jenkins Advisory; Qakbot Decryptor; Android 2G Disable; MSFT Defender Weakness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7836.mp3" length="4940744" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7836.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7836</link>
<pubDate>Fri, 14 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[MSFT Patch Issues<br/>
 <a href="https://borncity.com/win/2022/01/12/patchday-windows-8-1-server-2012-r2-updates-11-januar-2022-mgliche-boot-probleme/">https://borncity.com/win/2022/01/12/patchday-windows-8-1-server-2012-r2-updates-11-januar-2022-mgliche-boot-probleme/</a><br/>
 <a href="https://support.microsoft.com/en-us/topic/january-11-2022-kb5009624-monthly-rollup-23f4910b-6bdd-475c-bb4d-c0e961aff0bc">https://support.microsoft.com/en-us/topic/january-11-2022-kb5009624-monthly-rollup-23f4910b-6bdd-475c-bb4d-c0e961aff0bc</a><br/>
 <a href="https://support.microsoft.com/en-us/topic/january-11-2022-kb5009595-security-only-update-060870c2-ad08-40e5-b000-a9f6d40c0831">https://support.microsoft.com/en-us/topic/january-11-2022-kb5009595-security-only-update-060870c2-ad08-40e5-b000-a9f6d40c0831</a><br/>
Jenkins Security Advisory 2022-01-1<br/>
 <a href="https://www.jenkins.io/security/advisory/2022-01-12/">https://www.jenkins.io/security/advisory/2022-01-12/</a><br/>
Qakbot Configuration Decryptor<br/>
 <a href="https://github.com/drole/qakbot-registry-decrypt">https://github.com/drole/qakbot-registry-decrypt</a><br/>
Android allows Disabling 2G<br/>
 <a href="https://www.bleepingcomputer.com/news/security/android-users-can-now-disable-2g-to-block-stingray-attacks/">https://www.bleepingcomputer.com/news/security/android-users-can-now-disable-2g-to-block-stingray-attacks/</a><br/>
Weakness in Microsoft Defender<br/>
 <a href="https://twitter.com/splinter_code/status/1481073265380581381">https://twitter.com/splinter_code/status/1481073265380581381</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7836" type="text/plain" language="en" />
<itunes:keywords>microsoft defender, adnroid, 2g, quakbot, jenkins, microsoft, updates, reboot, hyper-v, uefi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 13th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7834</itunes:episode>
<itunes:subtitle>CVE-2020-21907 http.sys update; SonicWall Vuln Details; iOS/iPadOS Update; RDP Vuln Details; RATs vs Cloud
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2020-21907 http.sys update; SonicWall Vuln Details; iOS/iPadOS Update; RDP Vuln Details; RATs vs Cloud
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7834.mp3" length="4938068" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7834.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7834</link>
<pubDate>Thu, 13 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[A Quick CVE-2022-21907 FAQ<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Quick+CVE202221907+FAQ+work+in+progress/28234/">https://isc.sans.edu/forums/diary/A+Quick+CVE202221907+FAQ+work+in+progress/28234/</a><br/>
Details Released Regarding Patched Sonicwall Vulnerabilities<br/>
 <a href="https://www.rapid7.com/blog/post/2022/01/11/cve-2021-20038-42-sonicwall-sma-100-multiple-vulnerabilities-fixed-2/">https://www.rapid7.com/blog/post/2022/01/11/cve-2021-20038-42-sonicwall-sma-100-multiple-vulnerabilities-fixed-2/</a><br/>
iOS/iPad OS Fixing HomeKit Vulnerability / Private Relay issues<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
 <a href="https://www.macrumors.com/2022/01/12/apple-icloud-private-relay-ios-15-2/">https://www.macrumors.com/2022/01/12/apple-icloud-private-relay-ios-15-2/</a><br/>
Atticking RDP From Inside<br/>
 <a href="https://www.cyberark.com/resources/threat-research-blog/attacking-rdp-from-inside">https://www.cyberark.com/resources/threat-research-blog/attacking-rdp-from-inside</a><br/>
Nanocore, Netwire and AsyncRAT Spreading Campaign Uses Public Cloud Infrastructre<br/>
 <a href="https://blog.talosintelligence.com/2022/01/nanocore-netwire-and-asyncrat-spreading.html">https://blog.talosintelligence.com/2022/01/nanocore-netwire-and-asyncrat-spreading.html</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7834" type="text/plain" language="en" />
<itunes:keywords>nanocore, netwire, asyncrat, duckdns, rdp, ios, ipados, cve-2022-219-7, http.sys, homekit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 12th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7832</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday (#wormable #http.sys vuln); Adobe Updates 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday (#wormable #http.sys vuln); Adobe Updates 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7832.mp3" length="5797842" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7832.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7832</link>
<pubDate>Wed, 12 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday - January 2022<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+January+2022/28230/">https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+January+2022/28230/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7832" type="text/plain" language="en" />
<itunes:keywords>microsoft, patch tuesday, wormable, http.sys, adobe, reader, acrobat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 11th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7830</itunes:episode>
<itunes:subtitle>macOS "powerdir" vuln; URL Parser Vulns; npm libs sabotaged
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
macOS "powerdir" vuln; URL Parser Vulns; npm libs sabotaged
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7830.mp3" length="5053286" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7830.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7830</link>
<pubDate>Tue, 11 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[New MacOS Vulnerability Could Lead to Unauthorized User Data Access<br/>
 <a href="https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access">https://www.microsoft.com/security/blog/2022/01/10/new-macos-vulnerability-powerdir-could-lead-to-unauthorized-user-data-access</a><br/>
Exploiting URL Parsers<br/>
 <a href="https://claroty.com/wp-content/uploads/2022/01/Exploiting-URL-Parsing-Confusion.pdf">https://claroty.com/wp-content/uploads/2022/01/Exploiting-URL-Parsing-Confusion.pdf</a><br/>
NPM libs "colors" and "faker" sabotaged by developer<br/>
 <a href="https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/">https://www.bleepingcomputer.com/news/security/dev-corrupts-npm-libs-colors-and-faker-breaking-thousands-of-apps/</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7830" type="text/plain" language="en" />
<itunes:keywords>npm, colors, faker, url parsers, macos, powerdir, tcc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 10th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7828</itunes:episode>
<itunes:subtitle>Cobalt Strike via MSBuild; H2 JNDI Vuln; Trojanized dnSpy; Fin7 BadUSB
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobalt Strike via MSBuild; H2 JNDI Vuln; Trojanized dnSpy; Fin7 BadUSB
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7828.mp3" length="4936720" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7828.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7828</link>
<pubDate>Mon, 10 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Extracting Cobalt Strike Beacons from MSBuild Scripts<br/>
 <a href="https://isc.sans.edu/forums/diary/Extracting+Cobalt+Strike+Beacons+from+MSBuild+Scripts/28200/">https://isc.sans.edu/forums/diary/Extracting+Cobalt+Strike+Beacons+from+MSBuild+Scripts/28200/</a><br/>
The JNDI Strikes Back: Unauthenticated RCE in H2 Database Console<br/>
 <a href="https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/">https://jfrog.com/blog/the-jndi-strikes-back-unauthenticated-rce-in-h2-database-console/</a><br/>
Trojanized dnSpy app drops malware cocktail<br/>
 <a href="https://www.bleepingcomputer.com/news/security/trojanized-dnspy-app-drops-malware-cocktail-on-researchers-devs/">https://www.bleepingcomputer.com/news/security/trojanized-dnspy-app-drops-malware-cocktail-on-researchers-devs/</a><br/>
FIN7 Attackers Sending Malicious USB Sticks<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/">https://www.bleepingcomputer.com/news/security/fbi-hackers-use-badusb-to-target-defense-firms-with-ransomware/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7828" type="text/plain" language="en" />
<itunes:keywords>fin7, usb, badusb, rubberducky, dnspy, malware, cryptowallet, jndi, h2, database, cobalt stike, msbuild, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 7th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7826</itunes:episode>
<itunes:subtitle>Malware Targeting Chinese; Google Docs Comment Abuse; Google Voice Auth Scam
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Targeting Chinese; Google Docs Comment Abuse; Google Voice Auth Scam
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7826.mp3" length="4898512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7826.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7826</link>
<pubDate>Fri, 07 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious Python Script Targeting Chinese People<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Python+Script+Targeting+Chinese+People/28220/">https://isc.sans.edu/forums/diary/Malicious+Python+Script+Targeting+Chinese+People/28220/</a><br/>
Google Docs Comment Exploit Allows for Distribution of Phishing and Malware<br/>
 <a href="https://www.avanan.com/blog/google-docs-comment-exploit-allows-for-distribution-of-phishing-and-malware">https://www.avanan.com/blog/google-docs-comment-exploit-allows-for-distribution-of-phishing-and-malware</a><br/>
Google Voice Authentication Scams<br/>
 <a href="https://www.fbi.gov/contact-us/field-offices/portland/news/press-releases/oregon-fbi-tech-tuesday-building-a-digital-defense-against-google-voice-authentication-scams">https://www.fbi.gov/contact-us/field-offices/portland/news/press-releases/oregon-fbi-tech-tuesday-building-a-digital-defense-against-google-voice-authentication-scams</a><br/>
Norton Crypto Miner<br/>
 <a href="https://investor.nortonlifelock.com/About/Investors/press-releases/press-release-details/2021/NortonLifeLock-Unveils-Norton-Crypto/default.aspx">https://investor.nortonlifelock.com/About/Investors/press-releases/press-release-details/2021/NortonLifeLock-Unveils-Norton-Crypto/default.aspx</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7826" type="text/plain" language="en" />
<itunes:keywords>python, china, chinese, google, docs, comments, phshing, voice, norton, miner, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 6th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7824</itunes:episode>
<itunes:subtitle>Malware Code Reuse; ZLoader Exploiting Signature Bug; VMWare CD-Rom Vuln; Honda Y2K22 Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Code Reuse; ZLoader Exploiting Signature Bug; VMWare CD-Rom Vuln; Honda Y2K22 Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7824.mp3" length="4910125" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7824.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7824</link>
<pubDate>Thu, 06 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[Code Reuse in the Malware Landscape<br/>
 <a href="https://isc.sans.edu/forums/diary/Code+Reuse+In+the+Malware+Landscape/28216/">https://isc.sans.edu/forums/diary/Code+Reuse+In+the+Malware+Landscape/28216/</a><br/>
ZLoader Campaign Exploiting Signature Verification Bug<br/>
 <a href="https://research.checkpoint.com/2022/can-you-trust-a-files-digital-signature-new-zloader-campaign-exploits-microsofts-signature-verification-putting-users-at-risk/">https://research.checkpoint.com/2022/can-you-trust-a-files-digital-signature-new-zloader-campaign-exploits-microsofts-signature-verification-putting-users-at-risk/</a><br/>
VMWare Virtual CD-Rom Vulnerability<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2022-0001.html">https://www.vmware.com/security/advisories/VMSA-2022-0001.html</a><br/>
Honda Y2k22 Bug<br/>
 <a href="https://www.bleepingcomputer.com/news/technology/honda-acura-cars-hit-by-y2k22-bug-that-rolls-back-clocks-to-2002/">https://www.bleepingcomputer.com/news/technology/honda-acura-cars-hit-by-y2k22-bug-that-rolls-back-clocks-to-2002/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7824" type="text/plain" language="en" />
<itunes:keywords>honda, y2k22, malware, code reuse, zloader, signatures, vmware, cd-rom, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 5th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7822</itunes:episode>
<itunes:subtitle>BlockInput; Windows Server RDP Patch; Malicious Telegram Installer; Web Skimmer vs. Real Estate
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BlockInput; Windows Server RDP Patch; Malicious Telegram Installer; Web Skimmer vs. Real Estate
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7822.mp3" length="4789537" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7822.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7822</link>
<pubDate>Wed, 05 Jan 2022 02:05:01 GMT</pubDate>
<description><![CDATA[A Simple Batch File That Blocks People<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Simple+Batch+File+That+Blocks+People/28212/">https://isc.sans.edu/forums/diary/A+Simple+Batch+File+That+Blocks+People/28212/</a><br/>
Windows Server Remote Desktop Emergency Update<br/>
 <a href="https://docs.microsoft.com/en-us/windows/release-health/windows-message-center#2772">https://docs.microsoft.com/en-us/windows/release-health/windows-message-center#2772</a><br/>
Malicious Telegram Installer Includes Purple Fox Rootkit<br/>
 <a href="https://blog.minerva-labs.com/malicious-telegram-installer-drops-purple-fox-rootkit">https://blog.minerva-labs.com/malicious-telegram-installer-drops-purple-fox-rootkit</a><br/>
Web Skimmer Campaign Targets Real Estate Websites<br/>
 <a href="https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/">https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7822" type="text/plain" language="en" />
<itunes:keywords>web skimmer, telegram, windows server, blockinput, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 4th, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7820</itunes:episode>
<itunes:subtitle>Fake AV Phish; Trend Micro Bug; E-Commerce Bots; iOS Homekit DoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake AV Phish; Trend Micro Bug; E-Commerce Bots; iOS Homekit DoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7820.mp3" length="5036022" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7820.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7820</link>
<pubDate>Tue, 04 Jan 2022 02:00:02 GMT</pubDate>
<description><![CDATA[McAfee Phishing Campaign with a Nice Fake Scan<br/>
 <a href="https://isc.sans.edu/forums/diary/McAfee+Phishing+Campaign+with+a+Nice+Fake+Scan/28208/">https://isc.sans.edu/forums/diary/McAfee+Phishing+Campaign+with+a+Nice+Fake+Scan/28208/</a><br/>
Trend Micro Apex One Patch<br/>
 <a href="https://success.trendmicro.com/solution/000289996">https://success.trendmicro.com/solution/000289996</a><br/>
E-commerce Bots Using Cheap Domain Registration Services<br/>
 <a href="https://threatpost.com/ecommerce-bots-domain-registration-account-fraud/177305/">https://threatpost.com/ecommerce-bots-domain-registration-account-fraud/177305/</a><br/>
iOS Homekit DoS Vulnerability<br/>
 <a href="https://trevorspiniolas.com/doorlock/doorlock.html">https://trevorspiniolas.com/doorlock/doorlock.html</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7820" type="text/plain" language="en" />
<itunes:keywords>ios, homekit, dos, trend micro, apex, ecommerce, bots, mcafee, phish, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 3rd, 2022</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7818</itunes:episode>
<itunes:subtitle>Exchange Server Y2k+22; Agent Tesla Updates; SSD Firmware Tampering; iLO Bleed;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exchange Server Y2k+22; Agent Tesla Updates; SSD Firmware Tampering; iLO Bleed;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7818.mp3" length="6681337" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7818.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7818</link>
<pubDate>Mon, 03 Jan 2022 02:00:01 GMT</pubDate>
<description><![CDATA[Exchange Server Year 2022 Bug<br/>
 <a href="https://isc.sans.edu/forums/diary/Exchange+Server+Email+Trapped+in+Transport+Queues/28204/">https://isc.sans.edu/forums/diary/Exchange+Server+Email+Trapped+in+Transport+Queues/28204/</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/email-stuck-in-exchange-on-premises-transport-queues/ba-p/3049447">https://techcommunity.microsoft.com/t5/exchange-team-blog/email-stuck-in-exchange-on-premises-transport-queues/ba-p/3049447</a><br/>
Agent Tesla Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Agent+Tesla+Updates+SMTP+Data+Exfiltration+Technique/28190/">https://isc.sans.edu/forums/diary/Agent+Tesla+Updates+SMTP+Data+Exfiltration+Technique/28190/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Do+you+want+your+Agent+Tesla+in+the+300+MB+or+8+kB+package/28202/">https://isc.sans.edu/forums/diary/Do+you+want+your+Agent+Tesla+in+the+300+MB+or+8+kB+package/28202/</a><br/>
Forensics Issues and Techniques to Improve Security in SSD with Flex Capacity Feature<br/>
 <a href="https://arxiv.org/ftp/arxiv/papers/2112/2112.13923.pdf">https://arxiv.org/ftp/arxiv/papers/2112/2112.13923.pdf</a><br/>
iLO Bleed Attack<br/>
 <a href="https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/">https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/</a><br/>
]]></description>
<itunes:duration>7:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7818" type="text/plain" language="en" />
<itunes:keywords>exchange, agent tesla, forensics, ssd, flex capacity, ilo bleed, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 30th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7816</itunes:episode>
<itunes:subtitle>Log4j Summary; MSFT Defender Log4j False Pos; T-Mobile SIM Swapping; Fisher Price Phone Flaw
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Log4j Summary; MSFT Defender Log4j False Pos; T-Mobile SIM Swapping; Fisher Price Phone Flaw
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7816.mp3" length="3814529" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7816.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7816</link>
<pubDate>Thu, 30 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Log4j 2 Security Vulnerabilities Update Guide<br/>
 <a href="https://isc.sans.edu/forums/diary/Log4j+2+Security+Vulnerabilities+Update+Guide/28188/">https://isc.sans.edu/forums/diary/Log4j+2+Security+Vulnerabilities+Update+Guide/28188/</a><br/>
Microsoft Defender Log4j False Positives<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-log4j-scanner-triggers-false-positive-alerts/">https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-log4j-scanner-triggers-false-positive-alerts/</a><br/>
T-Mobile SIM Swapping Alerts<br/>
 <a href="https://www.bleepingcomputer.com/news/security/t-mobile-says-new-data-breach-caused-by-sim-swap-attacks/">https://www.bleepingcomputer.com/news/security/t-mobile-says-new-data-breach-caused-by-sim-swap-attacks/</a><br/>
Fisher Price Bluetooth Phone Privcy Flaw<br/>
 <a href="https://www.pentestpartners.com/security-blog/audio-bugging-with-the-fisher-price-chatter-bluetooth-telephone/">https://www.pentestpartners.com/security-blog/audio-bugging-with-the-fisher-price-chatter-bluetooth-telephone/</a><br/>
]]></description>
<itunes:duration>4:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7816" type="text/plain" language="en" />
<itunes:keywords>fisher price, bluetooth, t-mobile, sim swapping, log4j, microsoft, defender, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 29th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7814</itunes:episode>
<itunes:subtitle>One More #Log4j Vuln; LotL Classifiers; LastPass Credentials Stuffing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
One More #Log4j Vuln; LotL Classifiers; LastPass Credentials Stuffing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7814.mp3" length="4424927" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7814.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7814</link>
<pubDate>Wed, 29 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Log4j Vulnerablity CVE-2021-44832<br/>
 <a href="https://logging.apache.org/log4j/2.x/security.html#CVE-2021-44832">https://logging.apache.org/log4j/2.x/security.html#CVE-2021-44832</a><br/>
LotL Classifiers<br/>
 <a href="https://isc.sans.edu/forums/diary/LotL+Classifier+tests+for+shells+exfil+and+miners/28184/">https://isc.sans.edu/forums/diary/LotL+Classifier+tests+for+shells+exfil+and+miners/28184/</a><br/>
LastPass Credential Stuffing<br/>
 <a href="https://www.bleepingcomputer.com/news/security/lastpass-users-warned-their-master-passwords-are-compromised/">https://www.bleepingcomputer.com/news/security/lastpass-users-warned-their-master-passwords-are-compromised/</a><br/>
]]></description>
<itunes:duration>4:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7814" type="text/plain" language="en" />
<itunes:keywords>log4j, log4shell, lastpass, lotl, lolbins, cve-2021-44832, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 28th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7812</itunes:episode>
<itunes:subtitle>Cobaltstrike via MSBuild; Bypassing MacOS Gatekeeper; Spider-Miner
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobaltstrike via MSBuild; Bypassing MacOS Gatekeeper; Spider-Miner
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7812.mp3" length="4245977" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7812.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7812</link>
<pubDate>Tue, 28 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Attackers are Abusing MSBuild to Evade Defenses and Implant Cobalt Strike Beacons<br/>
 <a href="https://isc.sans.edu/forums/diary/Attackers+are+abusing+MSBuild+to+evade+defenses+and+implant+Cobalt+Strike+beacons/28180/">https://isc.sans.edu/forums/diary/Attackers+are+abusing+MSBuild+to+evade+defenses+and+implant+Cobalt+Strike+beacons/28180/</a><br/>
Bypassing File Quarantine, Gatekeeper and Notarization Requirements<br/>
 <a href="https://objective-see.com/blog/blog_0x6A.html">https://objective-see.com/blog/blog_0x6A.html</a><br/>
Spider-Miner: Trojanized Version of Spiderman No Way Home<br/>
 <a href="https://blog.reasonlabs.com/2021/12/23/spider-miner-with-great-power-comes-great-problems/">https://blog.reasonlabs.com/2021/12/23/spider-miner-with-great-power-comes-great-problems/</a><br/>
]]></description>
<itunes:duration>4:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7812" type="text/plain" language="en" />
<itunes:keywords>spider man, miner, monero, macos, notarization, gatekeeper, quarantine, MSBuild, Cobalt Strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 27th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7810</itunes:episode>
<itunes:subtitle>#log4j/#log4shell and IMDS + more Crypto Miners; MSFT Vuln/Malicious Driver Reporting; Azure Source Code Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#log4j/#log4shell and IMDS + more Crypto Miners; MSFT Vuln/Malicious Driver Reporting; Azure Source Code Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7810.mp3" length="5155448" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7810.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7810</link>
<pubDate>Mon, 27 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Log4j/Log4Shell and Cloud Internal Meta Data Services<br/>
 <a href="https://isc.sans.edu/forums/diary/log4shell+and+cloud+provider+internal+meta+data+services+IMDS/28168/">https://isc.sans.edu/forums/diary/log4shell+and+cloud+provider+internal+meta+data+services+IMDS/28168/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Defending+Cloud+IMDS+Against+log4shell+and+more/28170/">https://isc.sans.edu/forums/diary/Defending+Cloud+IMDS+Against+log4shell+and+more/28170/</a><br/>
Log4j/Log4Shell Pushing Crypto Miner<br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+how+attackers+are+trying+to+push+crypto+miners+via+Log4Shell/28172/">https://isc.sans.edu/forums/diary/Example+of+how+attackers+are+trying+to+push+crypto+miners+via+Log4Shell/28172/</a><br/>
Microsoft Vulnerable and Malicious Driver Reporting Center<br/>
 <a href="https://www.microsoft.com/security/blog/2021/12/08/improve-kernel-security-with-the-new-microsoft-vulnerable-and-malicious-driver-reporting-center/">https://www.microsoft.com/security/blog/2021/12/08/improve-kernel-security-with-the-new-microsoft-vulnerable-and-malicious-driver-reporting-center/</a><br/>
Azure Source Code Leak<br/>
 <a href="https://blog.wiz.io/azure-app-service-source-code-leak/">https://blog.wiz.io/azure-app-service-source-code-leak/</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7810" type="text/plain" language="en" />
<itunes:keywords>azure, app service, microsoft, drivers, log4j, log4shell, miner, imds, meta data services, aws, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 23rd, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7808</itunes:episode>
<itunes:subtitle>Forensics Challenge Solution; CAB-less 40444; COVID Home Test Weakness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Forensics Challenge Solution; CAB-less 40444; COVID Home Test Weakness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7808.mp3" length="3669289" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7808.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7808</link>
<pubDate>Thu, 23 Dec 2021 03:40:02 GMT</pubDate>
<description><![CDATA[Forensics Challenge Solution<br/>
 <a href="https://isc.sans.edu/forums/diary/December+2021+Forensic+Contest+Answers+and+Analysis/28160/">https://isc.sans.edu/forums/diary/December+2021+Forensic+Contest+Answers+and+Analysis/28160/</a><br/>
CAB-less 40444<br/>
 <a href="https://news.sophos.com/en-us/2021/12/21/attackers-test-cab-less-40444-exploit-in-a-dry-run/">https://news.sophos.com/en-us/2021/12/21/attackers-test-cab-less-40444-exploit-in-a-dry-run/</a><br/>
Ellume COVID Home Test Weakness<br/>
 <a href="https://github.com/FSecureLABS/Ellume-COVID-Test_Research-Files">https://github.com/FSecureLABS/Ellume-COVID-Test_Research-Files</a><br/>
]]></description>
<itunes:duration>4:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7808" type="text/plain" language="en" />
<itunes:keywords>covid, ellume, cab-less, cve-2021-40444, forensic challenge, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 22nd, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7806</itunes:episode>
<itunes:subtitle>More Undetectes PS Droppers; Apache Patches; Auerswald PBX Backdoor; Garrett Metal Detectors
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Undetectes PS Droppers; Apache Patches; Auerswald PBX Backdoor; Garrett Metal Detectors
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7806.mp3" length="4498682" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7806.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7806</link>
<pubDate>Wed, 22 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[More Undetected PowerShell Droppers<br/>
 <a href="https://isc.sans.edu/forums/diary/More+Undetected+PowerShell+Dropper/28158/">https://isc.sans.edu/forums/diary/More+Undetected+PowerShell+Dropper/28158/</a><br/>
Apache Patches<br/>
 <a href="https://httpd.apache.org/security/vulnerabilities_24.html">https://httpd.apache.org/security/vulnerabilities_24.html</a><br/>
Auerswald COMpact Multiple Backdoors<br/>
 <a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2021-007/-auerswald-compact-multiple-backdoors">https://www.redteam-pentesting.de/en/advisories/rt-sa-2021-007/-auerswald-compact-multiple-backdoors</a><br/>
Vulnerabilities in Garrett Metal Detectors<br/>
 <a href="https://blog.talosintelligence.com/2021/12/vuln-spotlight-garrett-metal-detector.html#more">https://blog.talosintelligence.com/2021/12/vuln-spotlight-garrett-metal-detector.html#more</a><br/>
]]></description>
<itunes:duration>4:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7806" type="text/plain" language="en" />
<itunes:keywords>garrett, metal detectors, auerswald, pbxs, dropper, powershell, antivirus, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 21st, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7804</itunes:episode>
<itunes:subtitle>Agent Tesla Code Reuse; VMWare Workspace ONE; KNXlock 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Agent Tesla Code Reuse; VMWare Workspace ONE; KNXlock 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7804.mp3" length="5274715" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7804.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7804</link>
<pubDate>Tue, 21 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[PowerPoint Atachments: Agent Tesla and Code Reuse in Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/PowerPoint+attachments+Agent+Tesla+and+code+reuse+in+malware/28154/">https://isc.sans.edu/forums/diary/PowerPoint+attachments+Agent+Tesla+and+code+reuse+in+malware/28154/</a><br/>
VMWare Workspace ONE Patch / log4j status<br/>
 <a href="https://www.vmware.com/security/advisories.html">https://www.vmware.com/security/advisories.html</a><br/>
Attacks Against Building Automation<br/>
 <a href="https://limessecurity.com/en/knxlock/">https://limessecurity.com/en/knxlock/</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7804" type="text/plain" language="en" />
<itunes:keywords>knxlock, building automation, knx, vmware, powerpoint, tesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 20th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7802</itunes:episode>
<itunes:subtitle>Automating Public DNS Changes; Office 2021 VPA Version; More #Log4j/Log4Shell fun
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Automating Public DNS Changes; Office 2021 VPA Version; More #Log4j/Log4Shell fun
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7802.mp3" length="5784427" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7802.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7802</link>
<pubDate>Mon, 20 Dec 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Disaster Recovery Automation Using Public DNS APIs<br/>
 <a href="https://isc.sans.edu/forums/diary/DR+Automation+Using+Public+DNS+APIs/28146/">https://isc.sans.edu/forums/diary/DR+Automation+Using+Public+DNS+APIs/28146/</a><br/>
Office 2021: VBA Project Version<br/>
 <a href="https://isc.sans.edu/forums/diary/Office+2021+VBA+Project+Version/28150/">https://isc.sans.edu/forums/diary/Office+2021+VBA+Project+Version/28150/</a><br/>
Log4j Updates<br/>
 <a href="https://www.blumira.com/analysis-log4shell-local-trigger/">https://www.blumira.com/analysis-log4shell-local-trigger/</a><br/>
 <a href="https://logging.apache.org/log4j/2.x/security.html">https://logging.apache.org/log4j/2.x/security.html</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7802" type="text/plain" language="en" />
<itunes:keywords>log4j, log4shell, office 2021, vba versions, disaster recovery, dns, dr, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 17th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7800</itunes:episode>
<itunes:subtitle>Contact Form Campaigns; BT vs. WiFi; Lenovo IMController; Log4j update #log4j #log4shell #lenovo 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Contact Form Campaigns; BT vs. WiFi; Lenovo IMController; Log4j update #log4j #log4shell #lenovo 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7800.mp3" length="6773835" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7800.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7800</link>
<pubDate>Fri, 17 Dec 2021 02:00:01 GMT</pubDate>
<description><![CDATA[How the "Contact Forms" Campaign Tricks People<br/>
 <a href="https://isc.sans.edu/forums/diary/How+the+Contact+Forms+campaign+tricks+people/28142/">https://isc.sans.edu/forums/diary/How+the+Contact+Forms+campaign+tricks+people/28142/</a><br/>
Bluetooth Used to Extract WiFi Secrets<br/>
 <a href="https://arxiv.org/pdf/2112.05719.pdf">https://arxiv.org/pdf/2112.05719.pdf</a><br/>
Lenovo Privilege Escalation Vulnerability<br/>
 <a href="https://support.lenovo.com/cy/en/product_security/len-75210">https://support.lenovo.com/cy/en/product_security/len-75210</a><br/>
 <a href="https://research.nccgroup.com/2021/12/15/technical-advisory-lenovo-imcontroller-local-privilege-escalation-cve-2021-3922-cve-2021-3969/">https://research.nccgroup.com/2021/12/15/technical-advisory-lenovo-imcontroller-local-privilege-escalation-cve-2021-3922-cve-2021-3969/</a><br/>
Log4j Updates<br/>
 <a href="https://github.com/cisagov/log4j-affected-db">https://github.com/cisagov/log4j-affected-db</a><br/>
 <a href="https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021">https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+December+2021</a><br/>
 <a href="https://twitter.com/sans_isc/status/1471611522694717445">https://twitter.com/sans_isc/status/1471611522694717445</a><br/>
 <br/>
]]></description>
<itunes:duration>7:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7800" type="text/plain" language="en" />
<itunes:keywords>log4j, lenovo, xml, imcontroller, bluetooth, wifi, coexistance, contact forms, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 16th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7798</itunes:episode>
<itunes:subtitle>Undetected Powershell Backdoor; Adobe Update; RDP Client Deserialization Vuln; webkit vs PS4
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Undetected Powershell Backdoor; Adobe Update; RDP Client Deserialization Vuln; webkit vs PS4
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7798.mp3" length="5146056" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7798.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7798</link>
<pubDate>Thu, 16 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Undetected Powershell Backdoor<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+but+Undetected+PowerShell+Backdoor/28138/">https://isc.sans.edu/forums/diary/Simple+but+Undetected+PowerShell+Backdoor/28138/</a><br/>
Adobe Security Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Remote Deserialization Bug in Microsoft RDP Client Through Smart Card Extension<br/>
 <a href="https://thalium.github.io/blog/posts/deserialization-bug-through-rdp-smart-card-extension/">https://thalium.github.io/blog/posts/deserialization-bug-through-rdp-smart-card-extension/</a><br/>
Webkit Bug Exploitable in PS4<br/>
 <a href="https://arstechnica.com/gaming/2021/12/new-ps4-homebrew-exploit-points-to-similar-ps5-hacks-to-come/">https://arstechnica.com/gaming/2021/12/new-ps4-homebrew-exploit-points-to-similar-ps5-hacks-to-come/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7798" type="text/plain" language="en" />
<itunes:keywords>ps4, webkit, rdp, client, adobe, deserialization, powershell, backdoor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 15th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7796</itunes:episode>
<itunes:subtitle>Microsoft Patches; Log4j Updates; Log4j Scanner/Patcher; Apple Updates #log4j $log4shell 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Log4j Updates; Log4j Scanner/Patcher; Apple Updates #log4j $log4shell 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7796.mp3" length="4784540" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7796.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7796</link>
<pubDate>Wed, 15 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+December+2021+Patch+Tuesday/28132/">https://isc.sans.edu/forums/diary/Microsoft+December+2021+Patch+Tuesday/28132/</a><br/>
Log4j Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Log4j+2150+and+previously+suggested+mitigations+may+not+be+enough/28134/">https://isc.sans.edu/forums/diary/Log4j+2150+and+previously+suggested+mitigations+may+not+be+enough/28134/</a><br/>
Log4j Scanner<br/>
 <a href="https://github.com/dtact/divd-2021-00038--log4j-scanner">https://github.com/dtact/divd-2021-00038--log4j-scanner</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7796" type="text/plain" language="en" />
<itunes:keywords>apple, log4j, ios, macos, ipados, watchos, tvos, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 14th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7794</itunes:episode>
<itunes:subtitle>Log4Shell "wrapup"; Google Chrome Update; Malicious PyPi Packages
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Log4Shell "wrapup"; Google Chrome Update; Malicious PyPi Packages
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7794.mp3" length="4602061" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7794.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7794</link>
<pubDate>Tue, 14 Dec 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Log4Shell Becoming Part of the Day to Day Grind<br/>
 <a href="https://isc.sans.edu/forums/diary/Log4Shell+exploited+to+implant+coin+miners/28124/">https://isc.sans.edu/forums/diary/Log4Shell+exploited+to+implant+coin+miners/28124/</a><br/>
 <a href="https://www.youtube.com/watch?v=oC2PZB5D3Ys">https://www.youtube.com/watch?v=oC2PZB5D3Ys</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html">https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html</a><br/>
Malicious PyPi Packages<br/>
 <a href="https://medium.com/ochrona/3-new-malicious-packages-found-on-pypi-a6bbb14b5e2">https://medium.com/ochrona/3-new-malicious-packages-found-on-pypi-a6bbb14b5e2</a><br/>
]]></description>
<itunes:duration>5:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7794" type="text/plain" language="en" />
<itunes:keywords>pypi, backdoor, google chrome, 0day, log4shell, log4j, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 13th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7792</itunes:episode>
<itunes:subtitle>Infocon Raised to Yellow for #Log4Shell / #Log4j2 Vulnerablity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Infocon Raised to Yellow for #Log4Shell / #Log4j2 Vulnerablity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7792.mp3" length="6805142" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7792.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7792</link>
<pubDate>Mon, 13 Dec 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Remote Code Execution in log4j2<br/>
 <a href="https://isc.sans.edu/forums/diary/RCE+in+log4j+Log4Shell+or+how+things+can+get+bad+quickly/28120/">https://isc.sans.edu/forums/diary/RCE+in+log4j+Log4Shell+or+how+things+can+get+bad+quickly/28120/</a><br/>
Log4j Zero Day<br/>
 <a href="https://www.lunasec.io/docs/blog/log4j-zero-day/">https://www.lunasec.io/docs/blog/log4j-zero-day/</a><br/>
Log4j2/Log4Shell Followup: What we see and how to defend and how to access our data<br/>
 <a href="https://isc.sans.edu/forums/diary/Log4j+Log4Shell+Followup+What+we+see+and+how+to+defend+and+how+to+access+our+data/28122/">https://isc.sans.edu/forums/diary/Log4j+Log4Shell+Followup+What+we+see+and+how+to+defend+and+how+to+access+our+data/28122/</a><br/>
Log4Shell Vendor Bulletins<br/>
 <a href="https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592">https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592</a><br/>
]]></description>
<itunes:duration>7:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7792" type="text/plain" language="en" />
<itunes:keywords>log4shell, log4j, log4j2, java, logs, api, rce, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 10th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7790</itunes:episode>
<itunes:subtitle>Discord Phishing; Microtik Issues; log4j RCE 0 Day; Sonicwall SMA 100 Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Discord Phishing; Microtik Issues; log4j RCE 0 Day; Sonicwall SMA 100 Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7790.mp3" length="5763492" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7790.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7790</link>
<pubDate>Fri, 10 Dec 2021 02:40:01 GMT</pubDate>
<description><![CDATA[Phishing Direct Messages via Discord<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+Direct+Messages+via+Discord/28114/">https://isc.sans.edu/forums/diary/Phishing+Direct+Messages+via+Discord/28114/</a><br/>
Vulnerable Microtik Routers<br/>
 <a href="https://eclypsium.com/2021/12/09/when-honey-bees-become-murder-hornets/">https://eclypsium.com/2021/12/09/when-honey-bees-become-murder-hornets/</a><br/>
log4j RCE 0-day<br/>
 <a href="https://www.lunasec.io/docs/blog/log4j-zero-day/">https://www.lunasec.io/docs/blog/log4j-zero-day/</a><br/>
Sonicwall SMA 100 Patch<br/>
 <a href="https://www.sonicwall.com/support/product-notification/product-security-notice-sma-100-series-vulnerability-patches-q4-2021/211201154715443/">https://www.sonicwall.com/support/product-notification/product-security-notice-sma-100-series-vulnerability-patches-q4-2021/211201154715443/</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7790" type="text/plain" language="en" />
<itunes:keywords>sonicwall, log4j, rce, 0-day, microtik, phishing, discord, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 9th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7788</itunes:episode>
<itunes:subtitle>Forensic Challenge; Phishing with MSFT OAuth; Android Patchday
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Forensic Challenge; Phishing with MSFT OAuth; Android Patchday
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7788.mp3" length="4922466" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7788.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7788</link>
<pubDate>Thu, 09 Dec 2021 02:30:01 GMT</pubDate>
<description><![CDATA[December 2021 Forensic Challenge<br/>
 <a href="https://isc.sans.edu/forums/diary/December+2021+Forensic+Challenge/28108/">https://isc.sans.edu/forums/diary/December+2021+Forensic+Challenge/28108/</a><br/>
Microsoft and GitHub OAuth Implementation Vulnerabilities Lead to Redirection Attacks<br/>
 <a href="https://www.proofpoint.com/us/blog/cloud-security/microsoft-and-github-oauth-implementation-vulnerabilities-lead-redirection">https://www.proofpoint.com/us/blog/cloud-security/microsoft-and-github-oauth-implementation-vulnerabilities-lead-redirection</a><br/>
Android Patch Day<br/>
 <a href="https://source.android.com/security/bulletin/2021-12-01?hl=en">https://source.android.com/security/bulletin/2021-12-01?hl=en</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7788" type="text/plain" language="en" />
<itunes:keywords>android, github, microsoft, forensic, challenge, contest, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 8th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7786</itunes:episode>
<itunes:subtitle>Webshells; AWS Outages; Kafka Exposed; Windows 10 RCE; Browser XS Bugs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Webshells; AWS Outages; Kafka Exposed; Windows 10 RCE; Browser XS Bugs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7786.mp3" length="5024565" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7786.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7786</link>
<pubDate>Wed, 08 Dec 2021 02:35:01 GMT</pubDate>
<description><![CDATA[Webshells, Webshells everywhere!<br/>
 <a href="https://isc.sans.edu/forums/diary/Webshells+Webshells+everywhere/28106/">https://isc.sans.edu/forums/diary/Webshells+Webshells+everywhere/28106/</a><br/>
AWS Outage<br/>
 <a href="https://status.aws.amazon.com">https://status.aws.amazon.com</a><br/>
Misconfigured Kafdrop Puts Companies' Apache Kafka Completely Exposed<br/>
 <a href="https://spectralops.io/blog/misconfigured-kafdrop-puts-companies-apache-kafka-completely-exposed/">https://spectralops.io/blog/misconfigured-kafdrop-puts-companies-apache-kafka-completely-exposed/</a><br/>
Windows 10 RCE: The exploit is in the link<br/>
 <a href="https://positive.security/blog/ms-officecmd-rce">https://positive.security/blog/ms-officecmd-rce</a><br/>
XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web Browsers<br/>
 <a href="https://xsinator.com/paper.pdf">https://xsinator.com/paper.pdf</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7786" type="text/plain" language="en" />
<itunes:keywords>xsinator, cross-site, xs leak, browser, windows 10, rce, link, ms-officemd, kafdrop, kafka, aws, webshells, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 7th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7784</itunes:episode>
<itunes:subtitle>OOB Networks for Incident Handling; Unitrends Backup Updates; Deanonymizing Tor;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OOB Networks for Incident Handling; Unitrends Backup Updates; Deanonymizing Tor;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7784.mp3" length="4922978" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7784.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7784</link>
<pubDate>Tue, 07 Dec 2021 02:25:01 GMT</pubDate>
<description><![CDATA[The Importance of Out of Band Networks<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Importance+of+OutofBand+Networks/28102/">https://isc.sans.edu/forums/diary/The+Importance+of+OutofBand+Networks/28102/</a><br/>
Kaseya Unitrends Backup Appliance Updates<br/>
 <a href="https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961">https://helpdesk.kaseya.com/hc/en-gb/articles/4412762258961</a><br/>
Is KAX17 Performing De-Anonymization Attacks Against Tor Users?<br/>
 <a href="https://nusenu.medium.com/is-kax17-performing-de-anonymization-attacks-against-tor-users-42e566defce8">https://nusenu.medium.com/is-kax17-performing-de-anonymization-attacks-against-tor-users-42e566defce8</a><br/>
Google Chrome Update No 0-Days<br/>
 <a href="https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7784" type="text/plain" language="en" />
<itunes:keywords>google chrome, kax17, nusenu, twitter, out of band, ransomware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 6th, 2021</title>
<itunes:author>Dr. Johannes B. Ullrich</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7782</itunes:episode>
<itunes:subtitle>UPX is forever; Airgap Attacks; Ubiquity Insider Extortion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
UPX is forever; Airgap Attacks; Ubiquity Insider Extortion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7782.mp3" length="4822414" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7782.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7782</link>
<pubDate>Mon, 06 Dec 2021 02:45:01 GMT</pubDate>
<description><![CDATA[The UPX Packer will never die<br/>
 <a href="https://isc.sans.edu/forums/diary/The+UPX+Packer+Will+Never+Die/28096/">https://isc.sans.edu/forums/diary/The+UPX+Packer+Will+Never+Die/28096/</a><br/>
Survey of Airgap Attacks<br/>
 <a href="https://www.welivesecurity.com/2021/12/01/jumping-air-gap-15-years-nation-state-effort/">https://www.welivesecurity.com/2021/12/01/jumping-air-gap-15-years-nation-state-effort/</a><br/>
Ubiquity Victim of Insider Extortion<br/>
 <a href="https://www.justice.gov/usao-sdny/pr/former-employee-technology-company-charged-stealing-confidential-data-and-extorting">https://www.justice.gov/usao-sdny/pr/former-employee-technology-company-charged-stealing-confidential-data-and-extorting</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7782" type="text/plain" language="en" />
<itunes:keywords>upx, airgap, usb, ubiquity, insider, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7780</itunes:episode>
<itunes:subtitle>TA551 Pushing IcedID; pip-audit; Wifi-Router Flaws; #HolidayHack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TA551 Pushing IcedID; pip-audit; Wifi-Router Flaws; #HolidayHack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7780.mp3" length="12388082" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7780.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7780</link>
<pubDate>Fri, 03 Dec 2021 02:00:01 GMT</pubDate>
<description><![CDATA[TA551 (Shathak) Pushes IcedID (Bokbot)<br/>
 <a href="https://isc.sans.edu/forums/diary/TA551+Shathak+pushes+IcedID+Bokbot/28092/">https://isc.sans.edu/forums/diary/TA551+Shathak+pushes+IcedID+Bokbot/28092/</a><br/>
pip-audit scanning Python packages for known vulnerabilities<br/>
 <a href="https://pypi.org/project/pip-audit/">https://pypi.org/project/pip-audit/</a><br/>
Wifi Router Flaws<br/>
 <a href="https://www.iot-inspector.com/blog/router-security-check-2021/">https://www.iot-inspector.com/blog/router-security-check-2021/</a><br/>
SANS Holiday Hack Challenge<br/>
 <a href="https://www.sans.org/mlp/holiday-hack-challenge/">https://www.sans.org/mlp/holiday-hack-challenge/</a><br/>
]]></description>
<itunes:duration>14:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7780" type="text/plain" language="en" />
<itunes:keywords>holiday, hack challenge, wifi, router, pip-audit, ta551, icedid, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7778</itunes:episode>
<itunes:subtitle>Webhook.site Exfiltration; NSS Library Vuln; EwDoor vs. AT&amp;T; JAMF Pro Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Webhook.site Exfiltration; NSS Library Vuln; EwDoor vs. AT&amp;T; JAMF Pro Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7778.mp3" length="5555432" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7778.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7778</link>
<pubDate>Thu, 02 Dec 2021 02:05:01 GMT</pubDate>
<description><![CDATA[Info-Stealer Using webhook.site to Exfiltrate Data<br/>
 <a href="https://isc.sans.edu/forums/diary/InfoStealer+Using+webhooksite+to+Exfiltrate+Data/28088/">https://isc.sans.edu/forums/diary/InfoStealer+Using+webhooksite+to+Exfiltrate+Data/28088/</a><br/>
Mozilla NSS Library Vulnerability<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2237">https://bugs.chromium.org/p/project-zero/issues/detail?id=2237</a><br/>
EwDoor Botnet is Attacking AT&T Customers<br/>
 <a href="https://blog.netlab.360.com/warning-ewdoor-botnet-is-attacking-att-customers/">https://blog.netlab.360.com/warning-ewdoor-botnet-is-attacking-att-customers/</a><br/>
JAMF Pro 10.32 Patch<br/>
 <a href="https://community.jamf.com/t5/jamf-pro/what-s-new-in-jamf-pro-10-32-release/m-p/246505">https://community.jamf.com/t5/jamf-pro/what-s-new-in-jamf-pro-10-32-release/m-p/246505</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7778" type="text/plain" language="en" />
<itunes:keywords>ewdoor, att, nss, mozillay, webhook, jamf, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7776</itunes:episode>
<itunes:subtitle>Composer vs PHPUnit; Microsoft Defender False Pos; HP Printer Vuln; Win10 Arbitrary File Read
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Composer vs PHPUnit; Microsoft Defender False Pos; HP Printer Vuln; Win10 Arbitrary File Read
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7776.mp3" length="5692322" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7776.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7776</link>
<pubDate>Wed, 01 Dec 2021 02:40:01 GMT</pubDate>
<description><![CDATA[Hunting for PHPUnit Installed via Composer<br/>
 <a href="https://isc.sans.edu/forums/diary/Hunting+for+PHPUnit+Installed+via+Composer/28084/">https://isc.sans.edu/forums/diary/Hunting+for+PHPUnit+Installed+via+Composer/28084/</a><br/>
Microsoft Defender Scares Admins with Emotet False Positivies<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-scares-admins-with-emotet-false-positives/">https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-scares-admins-with-emotet-false-positives/</a><br/>
Printing Shellz HP Printer Vulnerabilities<br/>
 <a href="https://blog.f-secure.com/hp-printer-vulnerabilities/?_ga=2.125707850.1160056027.1638325485-2056233716.1638325485">https://blog.f-secure.com/hp-printer-vulnerabilities/?_ga=2.125707850.1160056027.1638325485-2056233716.1638325485</a><br/>
Unpatched Local Privilege Escalation in Mobile Device Management Service<br/>
 <a href="https://blog.0patch.com/2021/11/micropatching-unpatched-local-privilege.html">https://blog.0patch.com/2021/11/micropatching-unpatched-local-privilege.html</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7776" type="text/plain" language="en" />
<itunes:keywords>mdm, windows, mobile device management, shellz, hp printer, defender, emotet, phpunit, composer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 30th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7774</itunes:episode>
<itunes:subtitle>Wireshark Update; Google Cloud Security; Zoom Patch; Slack vs DNSSEC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wireshark Update; Google Cloud Security; Zoom Patch; Slack vs DNSSEC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7774.mp3" length="4865295" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7774.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7774</link>
<pubDate>Tue, 30 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Wireshark 3.6.0 Released<br/>
 <a href="https://isc.sans.edu/forums/diary/Wireshark+360+Released/28076/">https://isc.sans.edu/forums/diary/Wireshark+360+Released/28076/</a><br/>
Google Cloud Security Report<br/>
 <a href="https://services.google.com/fh/files/misc/gcat_threathorizons_full_nov2021.pdf">https://services.google.com/fh/files/misc/gcat_threathorizons_full_nov2021.pdf</a><br/>
Zoom Patch<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
Slack DNSSEC Experience Reports<br/>
 <a href="https://slack.engineering/what-happened-during-slacks-dnssec-rollout/">https://slack.engineering/what-happened-during-slacks-dnssec-rollout/</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7774" type="text/plain" language="en" />
<itunes:keywords>dnssec, slack, zoom, google, cloud, wireshark, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 29th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7772</itunes:episode>
<itunes:subtitle>Disappearing Phish; Trickbot HTML Resolution Check; QNAP QVR Patch; CronRAT
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Disappearing Phish; Trickbot HTML Resolution Check; QNAP QVR Patch; CronRAT
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7772.mp3" length="5409948" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7772.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7772</link>
<pubDate>Mon, 29 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Phishing Pages Hiding Itself Using Dynamically Adjusted IP Based Allow List<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+page+hiding+itself+using+dynamically+adjusted+IPbased+allow+list/28070/">https://isc.sans.edu/forums/diary/Phishing+page+hiding+itself+using+dynamically+adjusted+IPbased+allow+list/28070/</a><br/>
Trickbot Phishing Checks Screen Resolution to Evade Researchers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/trickbot-phishing-checks-screen-resolution-to-evade-researchers/">https://www.bleepingcomputer.com/news/security/trickbot-phishing-checks-screen-resolution-to-evade-researchers/</a><br/>
QNAP QVR Patch<br/>
 <a href="https://www.qnap.com/de-de/security-advisory/qsa-21-51">https://www.qnap.com/de-de/security-advisory/qsa-21-51</a><br/>
CronRAT Malware Hiding in cron<br/>
 <a href="https://sansec.io/research/cronrat">https://sansec.io/research/cronrat</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7772" type="text/plain" language="en" />
<itunes:keywords>cronrat, malware, cron, crontab, qnap, qvr, trickbot, html, resolution, phishing, ip address, allow list, block list, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 24th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7770</itunes:episode>
<itunes:subtitle>Improved YARA Maldoc Signature; Windows Installer 0-Day; VMWare VCenter Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Improved YARA Maldoc Signature; Windows Installer 0-Day; VMWare VCenter Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7770.mp3" length="3004077" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7770.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7770</link>
<pubDate>Wed, 24 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[YARA Rule for OOXML Maldocs: Less False Positives<br/>
 <a href="https://isc.sans.edu/forums/diary/YARA+Rule+for+OOXML+Maldocs+Less+False+Positives/28066/">https://isc.sans.edu/forums/diary/YARA+Rule+for+OOXML+Maldocs+Less+False+Positives/28066/</a><br/>
Zero-Day Windows Installer Exploit<br/>
 <a href="https://www.bleepingcomputer.com/news/security/malware-now-trying-to-exploit-new-windows-installer-zero-day/">https://www.bleepingcomputer.com/news/security/malware-now-trying-to-exploit-new-windows-installer-zero-day/</a><br/>
VMWare VCenter Vulnerability and Patch<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0027.html">https://www.vmware.com/security/advisories/VMSA-2021-0027.html</a><br/>
]]></description>
<itunes:duration>3:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7770" type="text/plain" language="en" />
<itunes:keywords>vmware, vcenter, windows, installer, exploit, 0day, yara, ooxml, office, maldocs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 23rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7768</itunes:episode>
<itunes:subtitle>Office Macro YARA Rules; Magento Exploits; Exchange PoC (CVE-2021-42321); Windows PrivEsc 0-Day PoC; CloudLinux RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Office Macro YARA Rules; Magento Exploits; Exchange PoC (CVE-2021-42321); Windows PrivEsc 0-Day PoC; CloudLinux RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7768.mp3" length="4013944" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7768.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7768</link>
<pubDate>Tue, 23 Nov 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Simple YARA Rules for Office Maldocs<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+YARA+Rules+for+Office+Maldocs/28062/">https://isc.sans.edu/forums/diary/Simple+YARA+Rules+for+Office+Maldocs/28062/</a><br/>
Retailers Urged to Patch Magento<br/>
 <a href="https://www.theregister.com/2021/11/22/ncsc_magento_updates_black_friday_reminder/">https://www.theregister.com/2021/11/22/ncsc_magento_updates_black_friday_reminder/</a><br/>
PoC of CVE-2021-42321: pop mspaint.exe on the target<br/>
 <a href="https://gist.github.com/testanull/0188c1ae847f37a70fe536123d14f398">https://gist.github.com/testanull/0188c1ae847f37a70fe536123d14f398</a><br/>
BeC Via Exchange Flaws<br/>
 <a href="https://www.trendmicro.com/en_us/research/21/k/Squirrelwaffle-Exploits-ProxyShell-and-ProxyLogon-to-Hijack-Email-Chains.html">https://www.trendmicro.com/en_us/research/21/k/Squirrelwaffle-Exploits-ProxyShell-and-ProxyLogon-to-Hijack-Email-Chains.html</a><br/>
Windows Priv. Escalation PoC<br/>
 <a href="https://github.com/klinix5/InstallerFileTakeOver">https://github.com/klinix5/InstallerFileTakeOver</a><br/>
PHP deserialize vulnerablity in CloudLinux Imunity360<br/>
 <a href="https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html">https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html</a><br/>
]]></description>
<itunes:duration>4:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7768" type="text/plain" language="en" />
<itunes:keywords>php, deserialization, cloudlinux, imunify360, imunity360, bec, exchange, cve-2021-42321, magento, yara, maldocs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7766</itunes:episode>
<itunes:subtitle>Hikvision Exploited; Detecting PAM Backdoors
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hikvision Exploited; Detecting PAM Backdoors
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7766.mp3" length="4515969" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7766.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7766</link>
<pubDate>Mon, 22 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Hikvision Security Cameras Potentially Exposed to Remote Code Execution<br/>
 <a href="https://isc.sans.edu/forums/diary/Hikvision+Security+Cameras+Potentially+Exposed+to+Remote+Code+Execution/28056/">https://isc.sans.edu/forums/diary/Hikvision+Security+Cameras+Potentially+Exposed+to+Remote+Code+Execution/28056/</a><br/>
Detecting PAM Backdoors<br/>
 <a href="https://isc.sans.edu/forums/diary/Backdooring+PAM/28058/">https://isc.sans.edu/forums/diary/Backdooring+PAM/28058/</a><br/>
Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI Ecosystem<br/>
 <a href="https://dl.acm.org/doi/pdf/10.1145/3460120.3484768">https://dl.acm.org/doi/pdf/10.1145/3460120.3484768</a><br/>
CVE-2021-42306 CredManifest: App Registration Certificates Stored in Azure Active Directory<br/>
 <a href="https://www.netspi.com/blog/technical/cloud-penetration-testing/azure-cloud-vulnerability-credmanifest/">https://www.netspi.com/blog/technical/cloud-penetration-testing/azure-cloud-vulnerability-credmanifest/</a><br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7766" type="text/plain" language="en" />
<itunes:keywords>cve-2021-42306, credmanifest, azure, rusted anchors, ca, web, pki, tls, pam, backdoors, hikvision, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7764</itunes:episode>
<itunes:subtitle>JavaScript Delivers Agent Tesla; GitHub vs cookies.sqlite; Fatpipe VPN Exploited; Abusing ClouDNS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JavaScript Delivers Agent Tesla; GitHub vs cookies.sqlite; Fatpipe VPN Exploited; Abusing ClouDNS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7764.mp3" length="5941926" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7764.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7764</link>
<pubDate>Fri, 19 Nov 2021 03:00:02 GMT</pubDate>
<description><![CDATA[JavaScript Downloader Delivers Agent Tesla Trojan<br/>
 <a href="https://isc.sans.edu/forums/diary/JavaScript+Downloader+Delivers+Agent+Tesla+Trojan/28050/">https://isc.sans.edu/forums/diary/JavaScript+Downloader+Delivers+Agent+Tesla+Trojan/28050/</a><br/>
Exposed Firefox cookies.sqlite Databases<br/>
 <a href="https://www.theregister.com/2021/11/18/firefox_cookies_github/">https://www.theregister.com/2021/11/18/firefox_cookies_github/</a><br/>
FBI Warns of Fatpipe VPN Exploits<br/>
 <a href="https://www.ic3.gov/Media/News/2021/211117-2.pdf">https://www.ic3.gov/Media/News/2021/211117-2.pdf</a><br/>
Abusing ClouDNS<br/>
 <a href="https://blog.netlab.360.com/the-pitfall-of-threat-intelligence-whitelisting-specter-botnet-is-taking-over-top-legit-dns-domains-by-using-cloudns-service/">https://blog.netlab.360.com/the-pitfall-of-threat-intelligence-whitelisting-specter-botnet-is-taking-over-top-legit-dns-domains-by-using-cloudns-service/</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7764" type="text/plain" language="en" />
<itunes:keywords>cloudns, fbi, fatpipe, firefox, cookies.sqlite, javascript, tesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7762</itunes:episode>
<itunes:subtitle>DDS Implementation Vuln; Siemens Nucleus TCP/IP Flaws; Netgear UPNP;  
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DDS Implementation Vuln; Siemens Nucleus TCP/IP Flaws; Netgear UPNP;  
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7762.mp3" length="4151924" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7762.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7762</link>
<pubDate>Thu, 18 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[DDS Protocol Implementation Vulnerabilities<br/>
 <a href="https://us-cert.cisa.gov/ics/advisories/icsa-21-315-02">https://us-cert.cisa.gov/ics/advisories/icsa-21-315-02</a><br/>
Siemens TCP/IP Flaws<br/>
 <a href="https://www.forescout.com/blog/new-critical-vulnerabilities-found-on-nucleus-tcp-ip-stack/">https://www.forescout.com/blog/new-critical-vulnerabilities-found-on-nucleus-tcp-ip-stack/</a><br/>
Netgear UPNP Stack Based Buffer Overflow<br/>
 <a href="https://blog.grimm-co.com/2021/11/seamlessly-discovering-netgear.html">https://blog.grimm-co.com/2021/11/seamlessly-discovering-netgear.html</a><br/>
]]></description>
<itunes:duration>4:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7762" type="text/plain" language="en" />
<itunes:keywords>netgear, upnp, siemens, tcp/ip, dds, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 17th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7760</itunes:episode>
<itunes:subtitle>Emotet Returns; NPM Security; Intel CPU Debug Vulnerablity; Router Vulnerablity List
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Returns; NPM Security; Intel CPU Debug Vulnerablity; Router Vulnerablity List
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7760.mp3" length="5956523" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7760.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7760</link>
<pubDate>Wed, 17 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Emotet Returns<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+Returns/28044/">https://isc.sans.edu/forums/diary/Emotet+Returns/28044/</a><br/>
GitHub Improves npm Security<br/>
 <a href="https://github.blog/2021-11-15-githubs-commitment-to-npm-ecosystem-security/">https://github.blog/2021-11-15-githubs-commitment-to-npm-ecosystem-security/</a><br/>
Intel CPU Debug Vulnerability<br/>
 <a href="https://www.ptsecurity.com/ww-en/about/news/positive-technologies-discovers-vulnerability-in-intel-processors-used-in-laptops-cars-and-other-devices/">https://www.ptsecurity.com/ww-en/about/news/positive-technologies-discovers-vulnerability-in-intel-processors-used-in-laptops-cars-and-other-devices/</a><br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00528.html</a><br/>
Home Router Vulnerability Listing<br/>
 <a href="https://modemly.com/m1/pulse">https://modemly.com/m1/pulse</a><br/>
]]></description>
<itunes:duration>6:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7760" type="text/plain" language="en" />
<itunes:keywords>home router, vulnerability, intel, cpu, github, emotet, npm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7758</itunes:episode>
<itunes:subtitle>MSFT Update Fixes Auth Failures; Clipboard AD Passwd Change; Parking Pages Distribute Malware; Rowhamer 4 ever;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Update Fixes Auth Failures; Clipboard AD Passwd Change; Parking Pages Distribute Malware; Rowhamer 4 ever;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7758.mp3" length="5921741" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7758.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7758</link>
<pubDate>Tue, 16 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Emergency Update fixes AD Authentication Problems<br/>
 <a href="https://support.microsoft.com/en-us/topic/november-14-2021-kb5008601-os-build-14393-4771-out-of-band-c8cd33ce-3d40-4853-bee4-a7cc943582b9">https://support.microsoft.com/en-us/topic/november-14-2021-kb5008601-os-build-14393-4771-out-of-band-c8cd33ce-3d40-4853-bee4-a7cc943582b9</a><br/>
Using Copy Paste to Change Microsoft AD Password<br/>
 <a href="https://isc.sans.edu/forums/diary/Changing+your+AD+Password+Using+the+Clipboard+Not+as+Easy+as+Youd+Think/28036/">https://isc.sans.edu/forums/diary/Changing+your+AD+Password+Using+the+Clipboard+Not+as+Easy+as+Youd+Think/28036/</a><br/>
Parking Pages Used to Distrbute Malware<br/>
 <a href="https://blog.netlab.360.com/zhatuniubility-malware-uses-namesilo-parking-pages-and-googles-custom-pages-to-spread/">https://blog.netlab.360.com/zhatuniubility-malware-uses-namesilo-parking-pages-and-googles-custom-pages-to-spread/</a><br/>
Blacksmith Revives Rowhamer<br/>
 <a href="https://comsec.ethz.ch/research/dram/blacksmith/">https://comsec.ethz.ch/research/dram/blacksmith/</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7758" type="text/plain" language="en" />
<itunes:keywords>blacksmisth, rowhamer, parking pages, malware, namesilo, mirosoft, ad, password, copy, paste, clipboard, emergency update, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7756</itunes:episode>
<itunes:subtitle>Not So Fake FBI E-Mails; BASE64 Maldocd Reversing; zoom and vmware update; windows priv esc 0-day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Not So Fake FBI E-Mails; BASE64 Maldocd Reversing; zoom and vmware update; windows priv esc 0-day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7756.mp3" length="5142500" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7756.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7756</link>
<pubDate>Mon, 15 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Not So Fake FBI E-Mails<br/>
 <a href="https://www.fbi.gov/news/pressrel/press-releases/fbi-statement-on-incident-involving-fake-emails">https://www.fbi.gov/news/pressrel/press-releases/fbi-statement-on-incident-involving-fake-emails</a><br/>
 <a href="https://isc.sans.edu/forums/diary/External+Email+System+FBI+Compromised+Sending+Out+Fake+Warnings/28034/">https://isc.sans.edu/forums/diary/External+Email+System+FBI+Compromised+Sending+Out+Fake+Warnings/28034/</a><br/>
 <a href="https://twitter.com/spamhaus/status/1459450061696417792">https://twitter.com/spamhaus/status/1459450061696417792</a><br/>
Reversing Obfuscated Maldoc with BASE64<br/>
 <a href="https://isc.sans.edu/forums/diary/Obfuscated+Maldoc+Reversed+BASE64/28030/">https://isc.sans.edu/forums/diary/Obfuscated+Maldoc+Reversed+BASE64/28030/</a><br/>
Zoom Updates<br/>
 <a href="https://explore.zoom.us/en/trust/security/security-bulletin/">https://explore.zoom.us/en/trust/security/security-bulletin/</a><br/>
VMWare VCenter Update<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0025.html">https://www.vmware.com/security/advisories/VMSA-2021-0025.html</a><br/>
Windows User Profile 0-Day LPE<br/>
 <a href="https://halove23.blogspot.com/2021/10/windows-user-profile-service-0day.html">https://halove23.blogspot.com/2021/10/windows-user-profile-service-0day.html</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7756" type="text/plain" language="en" />
<itunes:keywords>lpe, windows, 0-day, vmware, user profile, vcenter, zoom, maldoc, base64, fbi, email, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7754</itunes:episode>
<itunes:subtitle>In Memory of Alan Paller. Cyber Security Industry Titan and SANS Institute Founder
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
In Memory of Alan Paller. Cyber Security Industry Titan and SANS Institute Founder
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7754.mp3" length="2828864" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7754.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7754</link>
<pubDate>Fri, 12 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[In Memory of Alan Paller. Cyber Security Industry Titan and SANS Institute Founder<br/>
 <a href="https://www.sans.org/press/announcements/alan-paller-cyber-security-industry-titan-and-sans-institute-founder-passes-away/">https://www.sans.org/press/announcements/alan-paller-cyber-security-industry-titan-and-sans-institute-founder-passes-away/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/In+Memory+of+Alan+Paller/28026/">https://isc.sans.edu/forums/diary/In+Memory+of+Alan+Paller/28026/</a><br/>
]]></description>
<itunes:duration>3:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7754" type="text/plain" language="en" />
<itunes:keywords>alan paller, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7752</itunes:episode>
<itunes:subtitle>Shadow IT and Phishing; PaloAlto GlobalProtect Vuln; Citrix DoS Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shadow IT and Phishing; PaloAlto GlobalProtect Vuln; Citrix DoS Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7752.mp3" length="5833649" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7752.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7752</link>
<pubDate>Thu, 11 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Shadow IT Makes People More Vulnerable to Phishing<br/>
 <a href="https://isc.sans.edu/forums/diary/Shadow+IT+Makes+People+More+Vulnerable+to+Phishing/28022/">https://isc.sans.edu/forums/diary/Shadow+IT+Makes+People+More+Vulnerable+to+Phishing/28022/</a><br/>
PaloAlto Networks GlobalProtect VPN CVE-2021-3064<br/>
 <a href="https://www.randori.com/blog/cve-2021-3064/?i=2">https://www.randori.com/blog/cve-2021-3064/?i=2</a><br/>
Citrix ADC/Gateway/SD-WAN WANOP Patch<br/>
 <a href="https://support.citrix.com/article/CTX330728">https://support.citrix.com/article/CTX330728</a><br/>
HPE Aruba Breach<br/>
 <a href="https://www.arubanetworks.com/support-services/security-bulletins/central-incident-faq/">https://www.arubanetworks.com/support-services/security-bulletins/central-incident-faq/</a><br/>
LiveStream: Application Security; Web Apps, APIs & Microservices<br/>
 youtu.be/6gGB7skXvpg<br/>
2pm ET Today (not 1pm as mentioned in the podcast]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7752" type="text/plain" language="en" />
<itunes:keywords>hpe, aruba, citrix, adc, sd-wan, paloalto, shadow it, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 10th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7750</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches; BusyBox Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches; BusyBox Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7750.mp3" length="5836184" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7750.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7750</link>
<pubDate>Wed, 10 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft November 2021 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+November+2021+Patch+Tuesday/28018/">https://isc.sans.edu/forums/diary/Microsoft+November+2021+Patch+Tuesday/28018/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
BusyBox Vulnerabilities<br/>
 <a href="https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/">https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7750" type="text/plain" language="en" />
<itunes:keywords>busybox, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7748</itunes:episode>
<itunes:subtitle>Abusing Security Tools; ManageEngine ADSelfService Attacks; Machine Learning Image Scaling Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Abusing Security Tools; ManageEngine ADSelfService Attacks; Machine Learning Image Scaling Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7748.mp3" length="6395648" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7748.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7748</link>
<pubDate>Tue, 09 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[(Ab)Using Security Tools & Controls for the Bad<br/>
 <a href="https://isc.sans.edu/forums/diary/AbUsing+Security+Tools+Controls+for+the+Bad/28014/">https://isc.sans.edu/forums/diary/AbUsing+Security+Tools+Controls+for+the+Bad/28014/</a><br/>
Targeted Attack Campaign Against ManageEngine ADSelfService Plus<br/>
 <a href="https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge/">https://unit42.paloaltonetworks.com/manageengine-godzilla-nglite-kdcsponge/</a><br/>
Image-Scaling Attacks in Machine Learning<br/>
 <a href="https://www.usenix.org/system/files/sec20fall_quiring_prepub.pdf">https://www.usenix.org/system/files/sec20fall_quiring_prepub.pdf</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7748" type="text/plain" language="en" />
<itunes:keywords>machine learning, manageengine, adselfservice, abusing, pam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7746</itunes:episode>
<itunes:subtitle>Extracting Cobalt Strike Keys from Memory; xmount; Proactive SIMs; Thunderbird Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Extracting Cobalt Strike Keys from Memory; xmount; Proactive SIMs; Thunderbird Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7746.mp3" length="4661189" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7746.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7746</link>
<pubDate>Mon, 08 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Decyprting Cobalt Strike Traffic With Keys Extracted From Process Memory<br/>
 <a href="https://isc.sans.edu/forums/diary/Decrypting+Cobalt+Strike+Traffic+With+Keys+Extracted+From+Process+Memory/28006/">https://isc.sans.edu/forums/diary/Decrypting+Cobalt+Strike+Traffic+With+Keys+Extracted+From+Process+Memory/28006/</a><br/>
XMount for Disk Images<br/>
 <a href="https://isc.sans.edu/forums/diary/Xmount+for+Disk+Images/28002/">https://isc.sans.edu/forums/diary/Xmount+for+Disk+Images/28002/</a><br/>
More Proactive SIMs<br/>
 <a href="https://medium.com/telecom-expert/more-proactive-sims-f8da2ef8b189">https://medium.com/telecom-expert/more-proactive-sims-f8da2ef8b189</a><br/>
Thunderbird Update<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2021-50/">https://www.mozilla.org/en-US/security/advisories/mfsa2021-50/</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7746" type="text/plain" language="en" />
<itunes:keywords>sim, xmount, cobalt strike, thunderbird, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7744</itunes:episode>
<itunes:subtitle>October Packets Challenge Solution; Linux Kernel RCE; Cisco Patches; WebAssembly Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
October Packets Challenge Solution; Linux Kernel RCE; Cisco Patches; WebAssembly Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7744.mp3" length="6225689" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7744.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7744</link>
<pubDate>Fri, 05 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[October 2021 Forensic Contest Answers and Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/October+2021+Forensic+Contest+Answers+and+Analysis/27998/">https://isc.sans.edu/forums/diary/October+2021+Forensic+Contest+Answers+and+Analysis/27998/</a><br/>
CVE-2021-43267: Remote Linux Kernel Heap Overflow in TIPC Module<br/>
 <a href="https://www.sentinelone.com/labs/tipc-remote-linux-kernel-heap-overflow-allows-arbitrary-code-execution/">https://www.sentinelone.com/labs/tipc-remote-linux-kernel-heap-overflow-allows-arbitrary-code-execution/</a><br/>
Cisco Patches<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
The Security Risk of Lacking Compiler Protection in WebAssembly<br/>
 <a href="https://arxiv.org/abs/2111.01421">https://arxiv.org/abs/2111.01421</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7744" type="text/plain" language="en" />
<itunes:keywords>webassembly, cisco, patches, tipc, linux, kernel, overflow, forensic, challenge, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 4th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7742</itunes:episode>
<itunes:subtitle>Patch Gitlab; More Exchange Action; Blackmatter Shutting Down Again; Android 0-Day Patched
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Patch Gitlab; More Exchange Action; Blackmatter Shutting Down Again; Android 0-Day Patched
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7742.mp3" length="4657630" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7742.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7742</link>
<pubDate>Thu, 04 Nov 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Gitlab CVE-2021-22205 Exploited (and often not patched)<br/>
 <a href="https://www.rapid7.com/blog/post/2021/11/01/gitlab-unauthenticated-remote-code-execution-cve-2021-22205-exploited-in-the-wild/">https://www.rapid7.com/blog/post/2021/11/01/gitlab-unauthenticated-remote-code-execution-cve-2021-22205-exploited-in-the-wild/</a><br/>
New Proxy Shell Exploits Seen Against Exchange<br/>
 <a href="https://blog.talosintelligence.com/2021/11/babuk-exploits-exchange.html">https://blog.talosintelligence.com/2021/11/babuk-exploits-exchange.html</a><br/>
Blackmatter Shutting Down Again<br/>
 <a href="https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-moves-victims-to-lockbit-after-shutdown/">https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-moves-victims-to-lockbit-after-shutdown/</a><br/>
Android 0-Day Patched<br/>
 <a href="https://source.android.com/security/bulletin/2021-11-01">https://source.android.com/security/bulletin/2021-11-01</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7742" type="text/plain" language="en" />
<itunes:keywords>Android, 0day, blackmatter, ransomware, proxy shell, exchange, gitlab, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7740</itunes:episode>
<itunes:subtitle>BrakTooth Update; XSS to Root; Pentaho Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BrakTooth Update; XSS to Root; Pentaho Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7740.mp3" length="5076590" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7740.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7740</link>
<pubDate>Wed, 03 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Revisiting BrakTooth: Two Months Later<br/>
 <a href="https://isc.sans.edu/forums/diary/Revisiting+BrakTooth+Two+Months+Later/27992/">https://isc.sans.edu/forums/diary/Revisiting+BrakTooth+Two+Months+Later/27992/</a><br/>
Escalating XSS to Sainthood with Nagios<br/>
 <a href="https://blog.grimm-co.com/2021/11/escalating-xss-to-sainthood-with-nagios.html">https://blog.grimm-co.com/2021/11/escalating-xss-to-sainthood-with-nagios.html</a><br/>
Pentaho Business Analytics Vulnerablity<br/>
 <a href="https://hawsec.com/publications/pentaho/HVPENT210401-Pentaho-BA-Security-Assessment-Report-v1_1.pdf">https://hawsec.com/publications/pentaho/HVPENT210401-Pentaho-BA-Security-Assessment-Report-v1_1.pdf</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7740" type="text/plain" language="en" />
<itunes:keywords>pentaho, xss, nagios, braktooth, bluetooth, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7738</itunes:episode>
<itunes:subtitle>Hiding Source Code; Detecting Header Smuggling; Kaspersky AWS SES Token Lost
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hiding Source Code; Detecting Header Smuggling; Kaspersky AWS SES Token Lost
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7738.mp3" length="6233462" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7738.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7738</link>
<pubDate>Tue, 02 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Trojan Source: Invisible Vulnerabilities<br/>
 <a href="https://www.trojansource.codes/trojan-source.pdf">https://www.trojansource.codes/trojan-source.pdf</a><br/>
Detecting HTTP Header Smuggling Vulnerabilities<br/>
 <a href="https://www.darkreading.com/application-security/free-tool-scans-web-servers-for-vulnerability-to-http-header-smuggling-attacks">https://www.darkreading.com/application-security/free-tool-scans-web-servers-for-vulnerability-to-http-header-smuggling-attacks</a><br/>
Kaspersky Lost Amazon Simple Email Service Token<br/>
 <a href="https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021_phishing">https://support.kaspersky.com/general/vulnerability.aspx?el=12430#01112021_phishing</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7738" type="text/plain" language="en" />
<itunes:keywords>kaspersky, amazon, simple email service, ses, http, header, smuggling, trojan source, compiler, editor, unicode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7736</itunes:episode>
<itunes:subtitle>RDP Scans; Sysmon Update; Chrome Updates; Android Rooting Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RDP Scans; Sysmon Update; Chrome Updates; Android Rooting Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7736.mp3" length="4818506" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7736.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7736</link>
<pubDate>Mon, 01 Nov 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Remote Desktop Protocol RDP Discovery<br/>
 <a href="https://isc.sans.edu/forums/diary/Remote+Desktop+Protocol+RDP+Discovery/27984/">https://isc.sans.edu/forums/diary/Remote+Desktop+Protocol+RDP+Discovery/27984/</a><br/>
Sysmon Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Sysinternals+Autoruns+and+Sysmon+updates/27986/">https://isc.sans.edu/forums/diary/Sysinternals+Autoruns+and+Sysmon+updates/27986/</a><br/>
Google Chrome Updates<br/>
 <a href="https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html">https://chromereleases.googleblog.com/2021/10/stable-channel-update-for-desktop_28.html</a><br/>
AbstractEmu Malware Roots Android<br/>
 <a href="https://blog.lookout.com/lookout-discovers-global-rooting-malware-campaign">https://blog.lookout.com/lookout-discovers-global-rooting-malware-campaign</a><br/>
Microsoft Defender For Endpoint Web Content Filtering<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/web-content-filtering-now-generally-available-on-windows/ba-p/2893357">https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/web-content-filtering-now-generally-available-on-windows/ba-p/2893357</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7736" type="text/plain" language="en" />
<itunes:keywords>rdp, sysmon, chrome, android, abstractemd, malware, microsoft, defender, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 29th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7734</itunes:episode>
<itunes:subtitle>Critical Hikvision Patch; MacOS SIP Vuln; NPM Typosquatting
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Critical Hikvision Patch; MacOS SIP Vuln; NPM Typosquatting
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7734.mp3" length="5006707" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7734.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7734</link>
<pubDate>Fri, 29 Oct 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Critical Hikvision Patch<br/>
 <a href="https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html">https://watchfulip.github.io/2021/09/18/Hikvision-IP-Camera-Unauthenticated-RCE.html</a><br/>
 <a href="https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/">https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-notification-command-injection-vulnerability-in-some-hikvision-products/</a><br/>
Shrootless Vulnerability in MacOS<br/>
 <a href="https://www.microsoft.com/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/">https://www.microsoft.com/security/blog/2021/10/28/microsoft-finds-new-macos-vulnerability-shrootless-that-could-bypass-system-integrity-protection/</a><br/>
More Malicious NPM Libraries<br/>
 <a href="https://www.theregister.com/2021/10/27/npm_roblox_ransomware/">https://www.theregister.com/2021/10/27/npm_roblox_ransomware/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7734" type="text/plain" language="en" />
<itunes:keywords>npm, noblox, shrootless, sip, macos, hikvision, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 28th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7732</itunes:episode>
<itunes:subtitle>OWA Phishing; Apple Fixes iOS 0-Day; Adobe Patches; DoH Pinkbot; Jira Insight Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OWA Phishing; Apple Fixes iOS 0-Day; Adobe Patches; DoH Pinkbot; Jira Insight Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7732.mp3" length="4637408" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7732.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7732</link>
<pubDate>Thu, 28 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Outlook Web Access Phishing<br/>
 <a href="https://isc.sans.edu/forums/diary/Hunting+for+Phishing+Sites+Masquerading+as+Outlook+Web+Access/27974/">https://isc.sans.edu/forums/diary/Hunting+for+Phishing+Sites+Masquerading+as+Outlook+Web+Access/27974/</a><br/>
Apple Security Updates Details Available<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
PinkBot Botnet Uses DoH<br/>
 <a href="https://blog.netlab.360.com/pinkbot/">https://blog.netlab.360.com/pinkbot/</a><br/>
Jira Insight Patch<br/>
 <a href="https://confluence.atlassian.com/adminjiraserver/jira-service-management-security-advisory-2021-10-20-1085186548.html">https://confluence.atlassian.com/adminjiraserver/jira-service-management-security-advisory-2021-10-20-1085186548.html</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7732" type="text/plain" language="en" />
<itunes:keywords>jira, insight, h2, pinkbot, dns over https, adobe, apple, udpates, outlook, owa, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 27th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7730</itunes:episode>
<itunes:subtitle>Apple Updates; Craigslist Hijack; UltimaSMS Malware; Firefox Proxy Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Craigslist Hijack; UltimaSMS Malware; Firefox Proxy Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7730.mp3" length="5004840" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7730.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7730</link>
<pubDate>Wed, 27 Oct 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Apple Updates Everything (but no details yet)<br/>
 <a href="https://support.apple.com/en-sa/HT201222">https://support.apple.com/en-sa/HT201222</a><br/>
Craigslist E-Mail Hijack<br/>
 <a href="https://www.inky.com/blog/urgency-mail-relay-serve-phishers-well-on-craigslist">https://www.inky.com/blog/urgency-mail-relay-serve-phishers-well-on-craigslist</a><br/>
UltimaSMS Android Malware<br/>
 <a href="https://blog.avast.com/premium-sms-scam-apps-on-play-store-avast">https://blog.avast.com/premium-sms-scam-apps-on-play-store-avast</a><br/>
Firefox Proxy Malware<br/>
 <a href="https://blog.mozilla.org/security/2021/10/25/securing-the-proxy-api-for-firefox-add-ons/">https://blog.mozilla.org/security/2021/10/25/securing-the-proxy-api-for-firefox-add-ons/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7730" type="text/plain" language="en" />
<itunes:keywords>firefox, update, proxy, ultimasms, android, craigslist, email, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 26th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7728</itunes:episode>
<itunes:subtitle>Decrypt Cobalt Strike; Critical Discourse Vuln; ua-parser-js malware; BillQuick Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Decrypt Cobalt Strike; Critical Discourse Vuln; ua-parser-js malware; BillQuick Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7728.mp3" length="4278988" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7728.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7728</link>
<pubDate>Tue, 26 Oct 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Decrypting Cobalt Strike Traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/Decrypting+Cobalt+Strike+Traffic+With+a+Leaked+Private+Key/27968/">https://isc.sans.edu/forums/diary/Decrypting+Cobalt+Strike+Traffic+With+a+Leaked+Private+Key/27968/</a><br/>
Critical Discourse Vulnerability<br/>
 <a href="https://us-cert.cisa.gov/ncas/current-activity/2021/10/24/critical-rce-vulnerability-discourse">https://us-cert.cisa.gov/ncas/current-activity/2021/10/24/critical-rce-vulnerability-discourse</a><br/>
Discourse Discussion Platform RCE<br/>
 <a href="https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq">https://github.com/discourse/discourse/security/advisories/GHSA-jcjx-pvpc-qgwq</a><br/>
 <a href="https://0day.click/recipe/discourse-sns-rce/">https://0day.click/recipe/discourse-sns-rce/</a><br/>
ua-parser-js malware<br/>
 <a href="https://github.com/advisories/GHSA-pjwm-rvh2-c87w">https://github.com/advisories/GHSA-pjwm-rvh2-c87w</a><br/>
Vulnerable Billing Software BillQuick Web Used to Deploy Ransomware<br/>
 <a href="https://www.huntress.com/blog/threat-advisory-hackers-are-exploiting-a-vulnerability-in-popular-billing-software-to-deploy-ransomware">https://www.huntress.com/blog/threat-advisory-hackers-are-exploiting-a-vulnerability-in-popular-billing-software-to-deploy-ransomware</a><br/>
]]></description>
<itunes:duration>4:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7728" type="text/plain" language="en" />
<itunes:keywords>billquick, cobalt strike, ua-parser-js, discourse, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 25th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7726</itunes:episode>
<itunes:subtitle>Malware Quiz; Odd ZIP Files; Decrypting Cobalt Strike
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Quiz; Odd ZIP Files; Decrypting Cobalt Strike
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7726.mp3" length="4996593" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7726.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7726</link>
<pubDate>Mon, 25 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Malware Quiz<br/>
<a href="https://isc.sans.edu/forums/diary/October+2021+Contest+Forensic+Challenge/27960/">https://isc.sans.edu/forums/diary/October+2021+Contest+Forensic+Challenge/27960/</a>                                                                                Odd Zip Files                                                                    <a href="https://isc.sans.edu/forums/diary/Phishing+ZIP+With+Malformed+Filename/27966/">https://isc.sans.edu/forums/diary/Phishing+ZIP+With+Malformed+Filename/27966/</a>                                                                                  Decrypting Cobalt Strike Configurations Using Known Secret Keys                  <a href="https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/">https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/</a>                                                                                                                                             Tracking BLE Fingerprints                                                        <a href="https://cseweb.ucsd.edu/~nibhaska/papers/sp22_paper.pdf">https://cseweb.ucsd.edu/~nibhaska/papers/sp22_paper.pdf</a>                                                                                                        GPS Software Bug                                                                 <a href="https://us-cert.cisa.gov/ncas/current-activity/2021/10/21/gps-daemon-gpsd-rollover-bug">https://us-cert.cisa.gov/ncas/current-activity/2021/10/21/gps-daemon-gpsd-rollover-bug</a>                                                                          <a href="https://isc.sans.edu/forums/diary/Keeping+Track+of+Time+Network+Time+Protocol+and+a+GPSD+Bug/27886/">https://isc.sans.edu/forums/diary/Keeping+Track+of+Time+Network+Time+Protocol+and+a+GPSD+Bug/27886/</a>]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7726" type="text/plain" language="en" />
<itunes:keywords>GPS, Tracking, ble, cobalt strike, zip, malware, packets, quiz, challenge, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7724</itunes:episode>
<itunes:subtitle>Stolen Images Malware; FiveSys Signed Rootkit; Oracle CPU; WinRAR Vuln; Bad NPM Packages
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Stolen Images Malware; FiveSys Signed Rootkit; Oracle CPU; WinRAR Vuln; Bad NPM Packages
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7724.mp3" length="5607938" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7724.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7724</link>
<pubDate>Fri, 22 Oct 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Stolen Images Evidence Campaign Pushes Sliver Based Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Stolen+Images+Evidence+campaign+pushes+Sliverbased+malware/27954/">https://isc.sans.edu/forums/diary/Stolen+Images+Evidence+campaign+pushes+Sliverbased+malware/27954/</a><br/>
FiveSys Rootkit Signed By Microsoft<br/>
 <a href="https://www.bitdefender.com/files/News/CaseStudies/study/405/Bitdefender-DT-Whitepaper-Fivesys-creat5699-en-EN.pdf">https://www.bitdefender.com/files/News/CaseStudies/study/405/Bitdefender-DT-Whitepaper-Fivesys-creat5699-en-EN.pdf</a><br/>
Oracle Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpuoct2021.html">https://www.oracle.com/security-alerts/cpuoct2021.html</a><br/>
WinRAR Vulnerability<br/>
 <a href="https://swarm.ptsecurity.com/winrars-vulnerable-trialware-when-free-software-isnt-free/">https://swarm.ptsecurity.com/winrars-vulnerable-trialware-when-free-software-isnt-free/</a><br/>
Crypto Mining npm Libraries<br/>
 <a href="https://blog.sonatype.com/newly-found-npm-malware-mines-cryptocurrency-on-windows-linux-macos-devices">https://blog.sonatype.com/newly-found-npm-malware-mines-cryptocurrency-on-windows-linux-macos-devices</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7724" type="text/plain" language="en" />
<itunes:keywords>cryptomining, npm, winrar, oracle, cpu, fivesys, windows, microsoft, certificate, sliver, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 21st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7722</itunes:episode>
<itunes:subtitle>Leaked Covid Certs; Chrome Removes FTP; Squirrel VM Bug; BlackByte Decryptor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Leaked Covid Certs; Chrome Removes FTP; Squirrel VM Bug; BlackByte Decryptor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7722.mp3" length="5042783" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7722.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7722</link>
<pubDate>Thu, 21 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Thanks to Covid 19: New Types of Documents are Lost in the Wild<br/>
 <a href="https://isc.sans.edu/forums/diary/Thanks+to+COVID19+New+Types+of+Documents+are+Lost+in+The+Wild/27952/">https://isc.sans.edu/forums/diary/Thanks+to+COVID19+New+Types+of+Documents+are+Lost+in+The+Wild/27952/</a><br/>
Google Chrome 95 Released<br/>
 <a href="https://chromestatus.com/roadmap">https://chromestatus.com/roadmap</a><br/>
Squirrel VM Bug<br/>
 <a href="https://thehackernews.com/2021/10/squirrel-engine-bug-could-let-attackers.html">https://thehackernews.com/2021/10/squirrel-engine-bug-could-let-attackers.html</a><br/>
BlackByte Decryptor Released<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/blackbyte-ransomware-pt-1-in-depth-analysis/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/blackbyte-ransomware-pt-1-in-depth-analysis/</a><br/>
 <a href="https://github.com/SpiderLabs/BlackByteDecryptor">https://github.com/SpiderLabs/BlackByteDecryptor</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7722" type="text/plain" language="en" />
<itunes:keywords>blackbyte, Decryptor, squirrel, vm, games, google, chrome, ftp, covid 19, certificates, vaccination, virustotal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 20th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7720</itunes:episode>
<itunes:subtitle>Great CN Firewall Experiment; Fake Gov Sites; TA505 Coming Back; Blackmatter Advise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Great CN Firewall Experiment; Fake Gov Sites; TA505 Coming Back; Blackmatter Advise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7720.mp3" length="4297773" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7720.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7720</link>
<pubDate>Wed, 20 Oct 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Can You Make the Great Chinese Firewall Work For You<br/>
 <a href="https://isc.sans.edu/forums/diary/Can+you+make+the+Great+Chinese+Firewall+work+for+you/27948/">https://isc.sans.edu/forums/diary/Can+you+make+the+Great+Chinese+Firewall+work+for+you/27948/</a><br/>
Fake Government Assistance Websites<br/>
 <a href="https://www.ic3.gov/Media/Y2021/PSA211015">https://www.ic3.gov/Media/Y2021/PSA211015</a><br/>
TA505 Coming Back<br/>
 <a href="https://www.proofpoint.com/us/blog/threat-insight/whatta-ta-ta505-ramps-activity-delivers-new-flawedgrace-variant">https://www.proofpoint.com/us/blog/threat-insight/whatta-ta-ta505-ramps-activity-delivers-new-flawedgrace-variant</a><br/>
BlackMatter Ransomware <br/>
 <a href="https://us-cert.cisa.gov/ncas/alerts/aa21-291a">https://us-cert.cisa.gov/ncas/alerts/aa21-291a</a><br/>
]]></description>
<itunes:duration>4:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7720" type="text/plain" language="en" />
<itunes:keywords>blackmatter, ransomware, ta505, government websites, phishing, chinese, firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7718</itunes:episode>
<itunes:subtitle>Certificated Auth for C2; PowerShell Patches; JunOS Patches; TianFu Cup
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Certificated Auth for C2; PowerShell Patches; JunOS Patches; TianFu Cup
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7718.mp3" length="4592568" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7718.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7718</link>
<pubDate>Tue, 19 Oct 2021 02:05:01 GMT</pubDate>
<description><![CDATA[Malcious PowerShell Script Using Client Certificate Authentication<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+PowerShell+Using+Client+Certificate+Authentication/27944/">https://isc.sans.edu/forums/diary/Malicious+PowerShell+Using+Client+Certificate+Authentication/27944/</a><br/>
PowerShell Updates<br/>
 <a href="https://github.com/PowerShell/Announcements/issues/27">https://github.com/PowerShell/Announcements/issues/27</a><br/>
Juniper JunOS Patches<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES">https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES</a><br/>
TianFu Cup<br/>
 <a href="https://tianfucup.com/en/#canjia">https://tianfucup.com/en/#canjia</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7718" type="text/plain" language="en" />
<itunes:keywords>junos, tianfu, junipter, powershell, certificates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7716</itunes:episode>
<itunes:subtitle>Apache 2.4.49/50 Exploited; Warranty Repairs; Malicious NFTs; Bitcoins for Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apache 2.4.49/50 Exploited; Warranty Repairs; Malicious NFTs; Bitcoins for Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7716.mp3" length="4991126" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7716.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7716</link>
<pubDate>Mon, 18 Oct 2021 02:05:01 GMT</pubDate>
<description><![CDATA[Active Scanning for Apache Vulnerabilities CVE-2021-41773 and 42013<br/>
 <a href="https://isc.sans.edu/forums/diary/Apache+is+Actively+Scan+for+CVE202141773+CVE202142013/27940/">https://isc.sans.edu/forums/diary/Apache+is+Actively+Scan+for+CVE202141773+CVE202142013/27940/</a><br/>
Warranty Repairs and Non Removable Storage Risks<br/>
 <a href="https://isc.sans.edu/forums/diary/Warranty+Repairs+and+NonRemovable+Storage+Risks/27938/">https://isc.sans.edu/forums/diary/Warranty+Repairs+and+NonRemovable+Storage+Risks/27938/</a><br/>
Crypto Wallet Compromised on OpenSea NFT Marketplace<br/>
 <a href="https://blog.checkpoint.com/2021/10/13/check-point-software-prevents-theft-of-crypto-wallets-on-opensea-the-worlds-largest-nft-marketplace/">https://blog.checkpoint.com/2021/10/13/check-point-software-prevents-theft-of-crypto-wallets-on-opensea-the-worlds-largest-nft-marketplace/</a><br/>
$5.2 Billion worth of Bitcoin Transactions Linked to Ransomware<br/>
 <a href="https://www.fincen.gov/sites/default/files/shared/Financial%20Trend%20Analysis_Ransomeware%20508%20FINAL.pdf">https://www.fincen.gov/sites/default/files/shared/Financial%20Trend%20Analysis_Ransomeware%20508%20FINAL.pdf</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7716" type="text/plain" language="en" />
<itunes:keywords>bitcoin, ransomware, nft, crypto wallet, opensea, warranty, removable storage, apache, directory traversal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7714</itunes:episode>
<itunes:subtitle>Windows Port Forward; SMTP Brute Forcing; Fake Ad Blocker; Romance Crypto Coin Scam; Sysmon4Linux; VMWare/Foxit Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Port Forward; SMTP Brute Forcing; Fake Ad Blocker; Romance Crypto Coin Scam; Sysmon4Linux; VMWare/Foxit Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7714.mp3" length="5797456" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7714.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7714</link>
<pubDate>Fri, 15 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Port Forwarding with Windows for the Win<br/>
 <a href="https://isc.sans.edu/forums/diary/PortForwarding+with+Windows+for+the+Win/27934/">https://isc.sans.edu/forums/diary/PortForwarding+with+Windows+for+the+Win/27934/</a><br/>
Please Fix Your E-Mail Brute Forcing Tool<br/>
 <a href="https://isc.sans.edu/forums/diary/Please+fix+your+EMail+Brute+forcing+tool/27930/">https://isc.sans.edu/forums/diary/Please+fix+your+EMail+Brute+forcing+tool/27930/</a><br/>
Ad Blocker Injects Ads<br/>
 <a href="https://www.imperva.com/blog/the-ad-blocker-that-injects-ads/">https://www.imperva.com/blog/the-ad-blocker-that-injects-ads/</a><br/>
Romance Scams Go After Crypto Currency<br/>
<a href="https://nakedsecurity.sophos.com/2021/10/13/romance-scams-with-a-cryptocurrency-twist-new-research-from-sophoslabs/">https://nakedsecurity.sophos.com/2021/10/13/romance-scams-with-a-cryptocurrency-twist-new-research-from-sophoslabs/</a><br/>
Sysmon For Linux<br/>
 <a href="https://github.com/Sysinternals/SysmonForLinux">https://github.com/Sysinternals/SysmonForLinux</a><br/>
Foxit Updates<br/>
 <a href="https://www.foxit.com/support/security-bulletins.html">https://www.foxit.com/support/security-bulletins.html</a><br/>
 <br/>
VMWare Updates<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0023.html">https://www.vmware.com/security/advisories/VMSA-2021-0023.html</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7714" type="text/plain" language="en" />
<itunes:keywords>vmware, foxit, sysmon, linux, romance, crypto, apple, ad blocker, email, brute forcing, netsh, port forwarding, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 13th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7712</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; PyPi Removes Malicious mitmproxy2 Module
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; PyPi Removes Malicious mitmproxy2 Module
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7712.mp3" length="5265101" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7712.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7712</link>
<pubDate>Wed, 13 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+October+2021+Patch+Tuesday/27928/">https://isc.sans.edu/forums/diary/Microsoft+October+2021+Patch+Tuesday/27928/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
PyPi Remove mitmproxy2 Module<br/>
 <a href="https://twitter.com/maximilianhils/status/1447525552370458625">https://twitter.com/maximilianhils/status/1447525552370458625</a><br/>
 <a href="https://web.archive.org/web/20211012105244/https://gist.github.com/mhils/7ff29d50b25a1c99e06834cf95684333">https://web.archive.org/web/20211012105244/https://gist.github.com/mhils/7ff29d50b25a1c99e06834cf95684333</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7712" type="text/plain" language="en" />
<itunes:keywords>pypi, mitmproxy, mitmproxy2, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7710</itunes:episode>
<itunes:subtitle>Odd Web Log Summary; iOS/iPadOS 15.0.2 (0-day); GitKraken weak keys; Lets Encrypt Outage
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd Web Log Summary; iOS/iPadOS 15.0.2 (0-day); GitKraken weak keys; Lets Encrypt Outage
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7710.mp3" length="4558561" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7710.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7710</link>
<pubDate>Tue, 12 Oct 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Non HTTP Requests Hitting Web Server<br/>
 <a href="https://isc.sans.edu/forums/diary/Things+that+go+Bump+in+the+Night+Non+HTTP+Requests+Hitting+Web+Servers/27924/">https://isc.sans.edu/forums/diary/Things+that+go+Bump+in+the+Night+Non+HTTP+Requests+Hitting+Web+Servers/27924/</a><br/>
Apple Updates iOS/iPadOS to 15.0.2<br/>
 <a href="https://saaramar.github.io/IOMFB_integer_overflow_poc/">https://saaramar.github.io/IOMFB_integer_overflow_poc/</a><br/>
 <a href="https://support.apple.com/en-us/HT212846">https://support.apple.com/en-us/HT212846</a><br/>
Weak SSH Keys Used with GitKraken<br/>
 <a href="https://github.blog/2021-10-11-github-security-update-revoking-weakly-generated-ssh-keys/">https://github.blog/2021-10-11-github-security-update-revoking-weakly-generated-ssh-keys/</a><br/>
Let's Encrypt Outage<br/>
 <a href="https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/6164b5af714e1f053880ba0c">https://letsencrypt.status.io/pages/incident/55957a99e800baa4470002da/6164b5af714e1f053880ba0c</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7710" type="text/plain" language="en" />
<itunes:keywords>letsencrypt, gitkraken, keypair, ssh keys, apple, ios, ipados, 15.0.2, http requests, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7708</itunes:episode>
<itunes:subtitle>WebLogic Xploits; Sorting Things; Telegram Auto-Delete; MSFT Disabling Excel 4.0 Macros;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebLogic Xploits; Sorting Things; Telegram Auto-Delete; MSFT Disabling Excel 4.0 Macros;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7708.mp3" length="4841502" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7708.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7708</link>
<pubDate>Mon, 11 Oct 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Scanning for Previous Oracle WebLogic Vulnerabilities<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+for+Previous+Oracle+WebLogic+Vulnerabilities/27918/">https://isc.sans.edu/forums/diary/Scanning+for+Previous+Oracle+WebLogic+Vulnerabilities/27918/</a><br/>
Sorting Things Out - Sorting Data by IP Address<br/>
 <a href="https://isc.sans.edu/forums/diary/Sorting+Things+Out+Sorting+Data+by+IP+Address/27916/">https://isc.sans.edu/forums/diary/Sorting+Things+Out+Sorting+Data+by+IP+Address/27916/</a><br/>
 <a href="https://gitlab.com/slackermedia/bashcrawl">https://gitlab.com/slackermedia/bashcrawl</a><br/>
Telegram Does Not Remove Auto-Deleted Messages from Cache<br/>
 <a href="https://habr.com/en/post/580582/">https://habr.com/en/post/580582/</a><br/>
Microsoft To Disable Excel 4.0 Macros By Default<br/>
 <a href="https://twitter.com/GelosSnake/status/1446192775087722497">https://twitter.com/GelosSnake/status/1446192775087722497</a><br/>
 <a href="https://m365admin.handsontek.net/macro-settings-update-to-disable-excel-4-0-macros-by-default/">https://m365admin.handsontek.net/macro-settings-update-to-disable-excel-4-0-macros-by-default/</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7708" type="text/plain" language="en" />
<itunes:keywords>weblogic, oracle, sort, bash, telegram, excel, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7706</itunes:episode>
<itunes:subtitle>Hunting IPTV Boxes; Apache 2.4.51 Released; FontOnLake Rootkit; osquery 5;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hunting IPTV Boxes; Apache 2.4.51 Released; FontOnLake Rootkit; osquery 5;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7706.mp3" length="5643453" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7706.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7706</link>
<pubDate>Fri, 08 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Who is Hunting For Your IPTV Set-Top Box?<br/>
 <a href="https://isc.sans.edu/forums/diary/Who+Is+Hunting+For+Your+IPTV+SetTop+Box/27912/">https://isc.sans.edu/forums/diary/Who+Is+Hunting+For+Your+IPTV+SetTop+Box/27912/</a><br/>
Another Update For Apache<br/>
 <a href="https://httpd.apache.org">https://httpd.apache.org</a><br/>
Font on Lake Rootkit<br/>
 <a href="https://www.welivesecurity.com/2021/10/07/fontonlake-previously-unknown-malware-family-targeting-linux/">https://www.welivesecurity.com/2021/10/07/fontonlake-previously-unknown-malware-family-targeting-linux/</a><br/>
osquery 5 with macOS Endpoint Security<br/>
 <a href="https://www.trailofbits.com/post/announcing-osquery-5-now-with-endpointsecurity-on-macos">https://www.trailofbits.com/post/announcing-osquery-5-now-with-endpointsecurity-on-macos</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7706" type="text/plain" language="en" />
<itunes:keywords>osquery, macos, fontonlake, rootkit, linux, apache, iptv, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 7th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7704</itunes:episode>
<itunes:subtitle>Apache Flaw Details; VMWare ESXi Ransomware; AT&amp;T SIM Forensics; Google Pushing 2SV
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apache Flaw Details; VMWare ESXi Ransomware; AT&amp;T SIM Forensics; Google Pushing 2SV
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7704.mp3" length="4771921" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7704.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7704</link>
<pubDate>Thu, 07 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Apache 2.4.49 Directory Traversal Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/Apache+2449+Directory+Traversal+Vulnerability+CVE202141773/27908/">https://isc.sans.edu/forums/diary/Apache+2449+Directory+Traversal+Vulnerability+CVE202141773/27908/</a><br/>
Python Ransomware Targeting ESXi Server<br/>
 <a href="https://www.sophos.com/en-us/press-office/press-releases/2021/10/sophos-researchers-uncover-new-python-ransomware-targeting-an-esxi-server-and-virtual-machines.aspx">https://www.sophos.com/en-us/press-office/press-releases/2021/10/sophos-researchers-uncover-new-python-ransomware-targeting-an-esxi-server-and-virtual-machines.aspx</a><br/>
AT&T SIM Forensics<br/>
 <a href="https://medium.com/telecom-expert/what-is-at-t-doing-at-1111340002-c418876c212c">https://medium.com/telecom-expert/what-is-at-t-doing-at-1111340002-c418876c212c</a><br/>
Google Making Additional 2FA Push<br/>
 <a href="https://blog.google/technology/safety-security/making-sign-safer-and-more-convenient/">https://blog.google/technology/safety-security/making-sign-safer-and-more-convenient/</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7704" type="text/plain" language="en" />
<itunes:keywords>Google, 2FA, ATT, SIM, Forensics, Python, ESXi, VMWare, Ransomware, Apache, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 6th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7702</itunes:episode>
<itunes:subtitle>Looking Glass; Facebook Postmortem; Apache 2.4.49 Vuln; Windows 11/2022 Released
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Looking Glass; Facebook Postmortem; Apache 2.4.49 Vuln; Windows 11/2022 Released
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7702.mp3" length="5068885" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7702.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7702</link>
<pubDate>Wed, 06 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Looking Glass Sites<br/>
 <a href="https://isc.sans.edu/forums/diary/Looking+Glasses+Debugging+Network+Connectivity+Issues/27904/">https://isc.sans.edu/forums/diary/Looking+Glasses+Debugging+Network+Connectivity+Issues/27904/</a><br/>
Facebook Postmortem<br/>
 <a href="https://engineering.fb.com/2021/10/05/networking-traffic/outage-details/">https://engineering.fb.com/2021/10/05/networking-traffic/outage-details/</a><br/>
Apache 2.4.49 Directory Traversal Vulnerability<br/>
 <a href="https://blog.sonatype.com/apache-servers-actively-exploited-in-wild-importance-of-prompt-patching">https://blog.sonatype.com/apache-servers-actively-exploited-in-wild-importance-of-prompt-patching</a><br/>
Windows 11 Released<br/>
 <a href="https://www.microsoft.com/security/blog/2021/10/04/windows-11-offers-chip-to-cloud-protection-to-meet-the-new-security-challenges-of-hybrid-work/">https://www.microsoft.com/security/blog/2021/10/04/windows-11-offers-chip-to-cloud-protection-to-meet-the-new-security-challenges-of-hybrid-work/</a><br/>
 <a href="https://www.microsoft.com/en-us/download/details.aspx?id=55319">https://www.microsoft.com/en-us/download/details.aspx?id=55319</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7702" type="text/plain" language="en" />
<itunes:keywords>windows 11, apache 2.4.49, path traversal, facebook, looking glass, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7700</itunes:episode>
<itunes:subtitle>Facebook Outage; Dark Botnet Update; Apache Airflow Credential Leakage #facebookout #airflow #bgp
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Facebook Outage; Dark Botnet Update; Apache Airflow Credential Leakage #facebookout #airflow #bgp
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7700.mp3" length="5166136" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7700.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7700</link>
<pubDate>Tue, 05 Oct 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Facebook Outage<br/>
 <a href="https://isc.sans.edu/forums/diary/Facebook+Outage+Yes+its+DNS+sort+of+A+super+quick+analysis+of+what+is+going+on/27900/">https://isc.sans.edu/forums/diary/Facebook+Outage+Yes+its+DNS+sort+of+A+super+quick+analysis+of+what+is+going+on/27900/</a><br/>
Boutique "Dark" Botnet Hunting for Crumbs<br/>
 <a href="https://isc.sans.edu/forums/diary/Boutique+Dark+Botnet+Hunting+for+Crumbs/27898/">https://isc.sans.edu/forums/diary/Boutique+Dark+Botnet+Hunting+for+Crumbs/27898/</a><br/>
Apache Airflow May Leak Credentials<br/>
 <a href="https://www.intezer.com/blog/cloud-security/misconfigured-airflows-leak-credentials/">https://www.intezer.com/blog/cloud-security/misconfigured-airflows-leak-credentials/</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7700" type="text/plain" language="en" />
<itunes:keywords>apache, airflow, dark.iot, dark, botnet, facebook, outage, bgp, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 4th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7698</itunes:episode>
<itunes:subtitle>cvtres.exe Malicious Use; More Chrome Patches; Security Awareness Month; Gatekeeper Bypass;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
cvtres.exe Malicious Use; More Chrome Patches; Security Awareness Month; Gatekeeper Bypass;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7698.mp3" length="5224389" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7698.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7698</link>
<pubDate>Mon, 04 Oct 2021 02:05:01 GMT</pubDate>
<description><![CDATA[A New Tool To Add to Your LOLBAS List: cvtres.exe<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Tool+to+Add+to+Your+LOLBAS+List+cvtresexe/27892/">https://isc.sans.edu/forums/diary/New+Tool+to+Add+to+Your+LOLBAS+List+cvtresexe/27892/</a><br/>
Google Chrome Continuing Updates<br/>
 <a href="https://support.google.com/chrome/answer/95414?hl=en&co=GENIE.Platform%3DDesktop">https://support.google.com/chrome/answer/95414?hl=en&co=GENIE.Platform%3DDesktop</a><br/>
Cyber Security Awareness Month<br/>
 <a href="https://www.sans.org/security-awareness-training/resources/">https://www.sans.org/security-awareness-training/resources/</a><br/>
 <a href="https://isc.sans.edu/tag.html?tag=csam">https://isc.sans.edu/tag.html?tag=csam</a><br/>
FCC Attempts to Fight SIM Swapping<br/>
 <a href="https://docs.fcc.gov/public/attachments/DOC-376199A1.pdf">https://docs.fcc.gov/public/attachments/DOC-376199A1.pdf</a><br/>
MacOS Gatekeeper Bypass<br/>
 <a href="https://labs.f-secure.com/blog/the-discovery-of-cve-2021-1810/">https://labs.f-secure.com/blog/the-discovery-of-cve-2021-1810/</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7698" type="text/plain" language="en" />
<itunes:keywords>macos, gatekeeper, fcc, sim swapping, security awareness month, google, chrome, lolbas, cvtres.exe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7696</itunes:episode>
<itunes:subtitle>Visa/Apple Express Transit Relay; FluBot Fake Updates; Azure Brute-Forceing; Domain Dumpster Diving @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Visa/Apple Express Transit Relay; FluBot Fake Updates; Azure Brute-Forceing; Domain Dumpster Diving @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7696.mp3" length="12897418" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7696.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7696</link>
<pubDate>Fri, 01 Oct 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Visa/Apple Express Transit Relay Attack<br/>
 <a href="https://www.bbc.com/news/technology-58719891">https://www.bbc.com/news/technology-58719891</a><br/>
FluBot Offering Fake FlutBot Protection<br/>
 <a href="https://twitter.com/CERTNZ/status/1443701853665980440">https://twitter.com/CERTNZ/status/1443701853665980440</a><br/>
Undetected Azure Active Directory Brute-Force Attacks<br/>
 <a href="https://www.secureworks.com/research/undetected-azure-active-directory-brute-force-attacks">https://www.secureworks.com/research/undetected-azure-active-directory-brute-force-attacks</a><br/>
SANS.edu Student Christopher DeWees: Expired Domain Dumpster Diving <a href="https://www.sans.edu/cyber-research/40505/">https://www.sans.edu/cyber-research/40505/</a><br/>
]]></description>
<itunes:duration>14:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7696" type="text/plain" language="en" />
<itunes:keywords>sans.edu, dewees, domains, expired, azure, active directory, brute forcing, flubot, visa, apple, express transit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 30th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7694</itunes:episode>
<itunes:subtitle>gpsd Bug; Airtag XSS; CISA/NSA VPN Guidance; Facebook Opensourcing Mariana Trench
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
gpsd Bug; Airtag XSS; CISA/NSA VPN Guidance; Facebook Opensourcing Mariana Trench
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7694.mp3" length="4902505" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7694.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7694</link>
<pubDate>Thu, 30 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Keeping Track of Time: Network Time Protocol and GPSD Bug<br/>
 <a href="https://isc.sans.edu/forums/diary/Keeping+Track+of+Time+Network+Time+Protocol+and+a+GPSD+Bug/27886/">https://isc.sans.edu/forums/diary/Keeping+Track+of+Time+Network+Time+Protocol+and+a+GPSD+Bug/27886/</a><br/>
Apple Airtags Stored XSS<br/>
 <a href="https://medium.com/@bobbyrsec/zero-day-hijacking-icloud-credentials-with-apple-airtags-stored-xss-6997da43a216">https://medium.com/@bobbyrsec/zero-day-hijacking-icloud-credentials-with-apple-airtags-stored-xss-6997da43a216</a><br/>
CISA/NSA Guidance To Configure VPNs<br/>
 <a href="https://media.defense.gov/2021/Sep/28/2002863184/-1/-1/0/CSI_SELECTING-HARDENING-REMOTE-ACCESS-VPNS-20210928.PDF">https://media.defense.gov/2021/Sep/28/2002863184/-1/-1/0/CSI_SELECTING-HARDENING-REMOTE-ACCESS-VPNS-20210928.PDF</a><br/>
Facebook Open Sourcing "Mariana Trench" Tool To Analyze Android and Java Apps<br/>
 <a href="https://engineering.fb.com/2021/09/29/security/mariana-trench/">https://engineering.fb.com/2021/09/29/security/mariana-trench/</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7694" type="text/plain" language="en" />
<itunes:keywords>facebook, mariana trench, android, vpn, apple, airtag, xss, ntp, gps, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 29th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7692</itunes:episode>
<itunes:subtitle>Current TLS/SSL Versions; Malicious Browser Crypto Wallets; Easier Exchange Emergency Mitigations
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Current TLS/SSL Versions; Malicious Browser Crypto Wallets; Easier Exchange Emergency Mitigations
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7692.mp3" length="5061009" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7692.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7692</link>
<pubDate>Wed, 29 Sep 2021 02:00:01 GMT</pubDate>
<description><![CDATA[TLS 1.3 and SSL: The Current State of Affairs<br/>
 <a href="https://isc.sans.edu/forums/diary/TLS+13+and+SSL+the+current+state+of+affairs/27882/">https://isc.sans.edu/forums/diary/TLS+13+and+SSL+the+current+state+of+affairs/27882/</a><br/>
EFF Discontinues HTTPS Everywhere Plugin<br/>
 <a href="https://www.eff.org/deeplinks/2021/09/https-actually-everywhere">https://www.eff.org/deeplinks/2021/09/https-actually-everywhere</a><br/>
Malicious CryptoCoin Wallet<br/>
 <a href="https://discourse.mozilla.org/t/got-hacked-by-the-add-on-called-safepal-wallet/85797">https://discourse.mozilla.org/t/got-hacked-by-the-add-on-called-safepal-wallet/85797</a><br/>
Microsoft Automates Exchange Mitigations<br/>
<a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/new-security-feature-in-september-2021-cumulative-update-for/ba-p/2783155">https://techcommunity.microsoft.com/t5/exchange-team-blog/new-security-feature-in-september-2021-cumulative-update-for/ba-p/2783155</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7692" type="text/plain" language="en" />
<itunes:keywords>exchange, mitigations, cryptocoin, safepol, eff, https, tls, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 28th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7690</itunes:episode>
<itunes:subtitle>Trend Micro ServerProtct Auth Bypass; Let's Encrypt Root Expiration; ERMAC Android Malware; QNAP Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Trend Micro ServerProtct Auth Bypass; Let's Encrypt Root Expiration; ERMAC Android Malware; QNAP Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7690.mp3" length="5160606" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7690.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7690</link>
<pubDate>Tue, 28 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Trend Micro ServerProtect Authentication Bypass Vulnerability<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-21-1115/">https://www.zerodayinitiative.com/advisories/ZDI-21-1115/</a><br/>
Let's Encrypt Root CA Expiration<br/>
 <a href="https://community.letsencrypt.org/t/production-chain-changes/150739">https://community.letsencrypt.org/t/production-chain-changes/150739</a><br/>
ERMAC Android Malware<br/>
 <a href="https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html">https://www.threatfabric.com/blogs/ermac-another-cerberus-reborn.html</a><br/>
QNAP Vulnerabilities<br/>
 <a href="https://www.qnap.com/en/security-advisory/QSA-21-35">https://www.qnap.com/en/security-advisory/QSA-21-35</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7690" type="text/plain" language="en" />
<itunes:keywords>trend micro, let's encrypt, ermac, qnap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 27th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7688</itunes:episode>
<itunes:subtitle>Mobile Device Inventory; Autodiscover Attacks; iOS 3x0Day; Cisco CAPWAP Vuln; Sonicall SMA 100 Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mobile Device Inventory; Autodiscover Attacks; iOS 3x0Day; Cisco CAPWAP Vuln; Sonicall SMA 100 Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7688.mp3" length="5529504" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7688.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7688</link>
<pubDate>Mon, 27 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Mobile Device Inventory via Active Sync<br/>
 <a href="https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Your+Users+Mobile+Devices+Simple+Inventory/27868/">https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Your+Users+Mobile+Devices+Simple+Inventory/27868/</a><br/>
Autodiscover Attacks<br/>
 <a href="https://autodiscover-vulnerable-tlds.com">https://autodiscover-vulnerable-tlds.com</a><br/>
 <a href="https://wiki.mozilla.org/Public_Suffix_List">https://wiki.mozilla.org/Public_Suffix_List</a><br/>
 <a href="https://www.guardicore.com/labs/autodiscovering-the-great-leak/">https://www.guardicore.com/labs/autodiscovering-the-great-leak/</a><br/>
Three More 0-Day Vulnerabilities in iOS<br/>
 <a href="https://habr.com/en/post/579714/">https://habr.com/en/post/579714/</a><br/>
 original russian version: <a href="https://habr.com/en/post/579716/">https://habr.com/en/post/579716/</a><br/>
Cisco CAPWAP Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-capwap-rce-LYgj8Kf">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewlc-capwap-rce-LYgj8Kf</a><br/>
Sonicwall SMA 100 Series Vulnerablity<br/>
 <a href="https://www.sonicwall.com/support/product-notification/security-notice-critical-arbitrary-file-delete-vulnerability-in-sonicwall-sma-100-series-appliances/210819124854603/">https://www.sonicwall.com/support/product-notification/security-notice-critical-arbitrary-file-delete-vulnerability-in-sonicwall-sma-100-series-appliances/210819124854603/</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7688" type="text/plain" language="en" />
<itunes:keywords>sonicwall, sma, cisco, capwap, ios, bug bounty, autodiscover, active sync, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 24th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7686</itunes:episode>
<itunes:subtitle>VBA Creates Excel4 Downloader; WPBT Unpatched Flaw; Patch for Older iOS/macOS; Broken Digital Signatures
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBA Creates Excel4 Downloader; WPBT Unpatched Flaw; Patch for Older iOS/macOS; Broken Digital Signatures
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7686.mp3" length="4936992" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7686.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7686</link>
<pubDate>Fri, 24 Sep 2021 02:05:01 GMT</pubDate>
<description><![CDATA[Excel Recipe: Some VBA Code with a Touch of Excel4 Macro<br/>
 <a href="https://isc.sans.edu/forums/diary/Excel+Recipe+Some+VBA+Code+with+a+Touch+of+Excel4+Macro/27864/">https://isc.sans.edu/forums/diary/Excel+Recipe+Some+VBA+Code+with+a+Touch+of+Excel4+Macro/27864/</a><br/>
Windows Platform Binary Table Weakness<br/>
 <a href="https://eclypsium.com/2021/09/20/everyone-gets-a-rootkit/">https://eclypsium.com/2021/09/20/everyone-gets-a-rootkit/</a><br/>
Apple Patches Older iOS/MacOS Versions<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Broken Digital Signatures Used to Foil Malware Detection<br/>
 <a href="https://blog.google/threat-analysis-group/financially-motivated-actor-breaks-certificate-parsing-avoid-detection/">https://blog.google/threat-analysis-group/financially-motivated-actor-breaks-certificate-parsing-avoid-detection/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7686" type="text/plain" language="en" />
<itunes:keywords>digital signatures, apple, ios, macos, WPBT, excel, macro, excel4, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 23rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7684</itunes:episode>
<itunes:subtitle>Obfuscated MSHTML Exploits; Exchange Autodiscovery Leak; Nagios Vuln; Apple SDK Removes TLS1.0/1.1
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated MSHTML Exploits; Exchange Autodiscovery Leak; Nagios Vuln; Apple SDK Removes TLS1.0/1.1
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7684.mp3" length="6090874" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7684.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7684</link>
<pubDate>Thu, 23 Sep 2021 11:35:01 GMT</pubDate>
<description><![CDATA[An XML-Obfustcated Office Document (CVE-2021-40444)<br/>
 <a href="https://isc.sans.edu/forums/diary/An+XMLObfuscated+Office+Document+CVE202140444/27860/">https://isc.sans.edu/forums/diary/An+XMLObfuscated+Office+Document+CVE202140444/27860/</a><br/>
Exchange Autodiscovering Leaks Credentials<br/>
 <a href="https://www.guardicore.com/labs/autodiscovering-the-great-leak/">https://www.guardicore.com/labs/autodiscovering-the-great-leak/</a><br/>
Nagios Vulnerabilities<br/>
 <a href="https://claroty.com/2021/09/21/blog-research-securing-network-management-systems-nagios-xi/">https://claroty.com/2021/09/21/blog-research-securing-network-management-systems-nagios-xi/</a><br/>
Apple Deprecating TLS 1.0/1.1<br/>
 <a href="https://developer.apple.com/news/?id=bv8ur34d">https://developer.apple.com/news/?id=bv8ur34d</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7684" type="text/plain" language="en" />
<itunes:keywords>nagios, exchange, autodiscovery, xml, office, mshtml, word, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7682</itunes:episode>
<itunes:subtitle>iOS 15 Private Relay; macOS Finder Vuln; vCenter Advisory; NetGear Circle Parental Control Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iOS 15 Private Relay; macOS Finder Vuln; vCenter Advisory; NetGear Circle Parental Control Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7682.mp3" length="5067500" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7682.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7682</link>
<pubDate>Wed, 22 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[A First Look at Apple's iOS 15 "Private Relay" feature<br/>
 <a href="https://isc.sans.edu/forums/diary/A+First+Look+at+Apples+iOS+15+Private+Relay+feature/27858/">https://isc.sans.edu/forums/diary/A+First+Look+at+Apples+iOS+15+Private+Relay+feature/27858/</a><br/>
macOS Finder Security Feature Bypass Leads to Possible RCE<br/>
 <a href="https://ssd-disclosure.com/ssd-advisory-macos-finder-rce/">https://ssd-disclosure.com/ssd-advisory-macos-finder-rce/</a><br/>
VMWare vCenter Advisory<br/>
 <a href="https://blogs.vmware.com/vsphere/2021/09/vmsa-2021-0020-what-you-need-to-know.html">https://blogs.vmware.com/vsphere/2021/09/vmsa-2021-0020-what-you-need-to-know.html</a><br/>
NetGear Circle Parental Control Vulnerablity<br/>
 <a href="https://blog.grimm-co.com/2021/09/mama-always-told-me-not-to-trust.html">https://blog.grimm-co.com/2021/09/mama-always-told-me-not-to-trust.html</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7682" type="text/plain" language="en" />
<itunes:keywords>netgear, circle, vmware, vCenter, macos, finder, private relay, ios 15, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 21st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7680</itunes:episode>
<itunes:subtitle>OMIGOD Scans; Apple Updates; ADSelfService Plus Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OMIGOD Scans; Apple Updates; ADSelfService Plus Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7680.mp3" length="5690073" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7680.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7680</link>
<pubDate>Tue, 21 Sep 2021 02:00:01 GMT</pubDate>
<description><![CDATA[OMIGOD Exploits Captured in the Wild.<br/>
 <a href="https://isc.sans.edu/forums/diary/OMIGOD+Exploits+Captured+in+the+Wild+Researchers+responsible+for+half+of+scans+for+related+ports/27852/">https://isc.sans.edu/forums/diary/OMIGOD+Exploits+Captured+in+the+Wild+Researchers+responsible+for+half+of+scans+for+related+ports/27852/</a><br/>
Apple iOS/iPadOS/tvOS 15 Updates (and WatchOS, Xcode, Safari)<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
ManageEngine ADSelfService Plus Exploited<br/>
 <a href="https://us-cert.cisa.gov/ncas/alerts/aa21-259a">https://us-cert.cisa.gov/ncas/alerts/aa21-259a</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7680" type="text/plain" language="en" />
<itunes:keywords>manageengine, adselfservice, apple, ios, ipados, tvos, watchos, xcode, safari, omigod, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 20th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7678</itunes:episode>
<itunes:subtitle>iOS Calendar Invites; MSHTML Exploit Docs; Mirai Hunting OMIGOD; Netgear Exploits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iOS Calendar Invites; MSHTML Exploit Docs; Mirai Hunting OMIGOD; Netgear Exploits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7678.mp3" length="5165637" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7678.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7678</link>
<pubDate>Mon, 20 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious Calendar Subscriptions Are Back<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Calendar+Subscriptions+Are+Back/27846/">https://isc.sans.edu/forums/diary/Malicious+Calendar+Subscriptions+Are+Back/27846/</a><br/>
Simple Analysis of a CVE-2021-40444 (MSHTML) Document<br/>
<a href="https://isc.sans.edu/forums/diary/Simple+Analysis+Of+A+CVE202140444+docx+Document/27848/">https://isc.sans.edu/forums/diary/Simple+Analysis+Of+A+CVE202140444+docx+Document/27848/</a><br/>
Mirai Botnet Hunting OMIGOD<br/>
 <a href="https://twitter.com/1ZRR4H/status/1438580885142507528">https://twitter.com/1ZRR4H/status/1438580885142507528</a><br/>
 <a href="https://isc.sans.edu/port.html?port=1270">https://isc.sans.edu/port.html?port=1270</a><br/>
Exploit for Netgear Flaws Available<br/>
 <a href="https://gynvael.coldwind.pl/?id=742">https://gynvael.coldwind.pl/?id=742</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7678" type="text/plain" language="en" />
<itunes:keywords>netgear, mirai, omigod, botnet, mshtml, calendar, ical, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 17th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7676</itunes:episode>
<itunes:subtitle>Brute Force Phishing; PrintNightmare Patch Stops Printing; Linux Malware on Windows ... and more
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Brute Force Phishing; PrintNightmare Patch Stops Printing; Linux Malware on Windows ... and more
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7676.mp3" length="5769472" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7676.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7676</link>
<pubDate>Fri, 17 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Phishing 101: why depend on one suspicious message subject when you can use many<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+101+why+depend+on+one+suspicious+message+subject+when+you+can+use+many/27842/">https://isc.sans.edu/forums/diary/Phishing+101+why+depend+on+one+suspicious+message+subject+when+you+can+use+many/27842/</a><br/>
PrintNightmare Fix Breaks Network Printing<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-windows-security-updates-break-network-printing/">https://www.bleepingcomputer.com/news/security/new-windows-security-updates-break-network-printing/</a><br/>
Malware Taking Advantage of Linux Subsystem for Windows<br/>
 <a href="https://blog.lumen.com/no-longer-just-theory-black-lotus-labs-uncovers-linux-executables-deployed-as-stealth-windows-loaders/">https://blog.lumen.com/no-longer-just-theory-black-lotus-labs-uncovers-linux-executables-deployed-as-stealth-windows-loaders/</a><br/>
Travis CI Patch<br/>
 <a href="https://travis-ci.community/t/security-bulletin/12081">https://travis-ci.community/t/security-bulletin/12081</a><br/>
IBM System x IMM Vulnerability<br/>
 <a href="https://support.lenovo.com/es/en/product_security/len-66347">https://support.lenovo.com/es/en/product_security/len-66347</a><br/>
Fake iTerm installing Malware on OS X<br/>
 <a href="https://objective-see.com/blog/blog_0x66.html">https://objective-see.com/blog/blog_0x66.html</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7676" type="text/plain" language="en" />
<itunes:keywords>iterm, ibm, system x, imm, travis ci, travis, linux, windows, subsystem, lsw, phishing, printnightmare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7674</itunes:episode>
<itunes:subtitle>Hancitor MSFT OneDrive; Azure Linux OMIGOD Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hancitor MSFT OneDrive; Azure Linux OMIGOD Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7674.mp3" length="4916625" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7674.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7674</link>
<pubDate>Thu, 16 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Hancitor Campaign Abusing Microsoft's OneDrive<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+campaign+abusing+Microsofts+OneDrive/27838/">https://isc.sans.edu/forums/diary/Hancitor+campaign+abusing+Microsofts+OneDrive/27838/</a><br/>
"Secret"Agent Exposes Azure Customers To Unauthorized Code Execution<br/>
 <a href="https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution">https://www.wiz.io/blog/secret-agent-exposes-azure-customers-to-unauthorized-code-execution</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7674" type="text/plain" language="en" />
<itunes:keywords>omigod, wiz, azure, linux, omi, vulnerability, hancitor, microsoft, onedrive, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7672</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7672.mp3" length="4816716" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7672.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7672</link>
<pubDate>Wed, 15 Sep 2021 02:05:01 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+September+2021+Patch+Tuesday/27834/">https://isc.sans.edu/forums/diary/Microsoft+September+2021+Patch+Tuesday/27834/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/security-bulletin.html">https://helpx.adobe.com/security/security-bulletin.html</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7672" type="text/plain" language="en" />
<itunes:keywords>adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 14th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7670</itunes:episode>
<itunes:subtitle>Apple Updates; Gooble Chrome Patches; WooCommerce Currency Conv. Flaw;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Gooble Chrome Patches; WooCommerce Currency Conv. Flaw;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7670.mp3" length="4616120" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7670.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7670</link>
<pubDate>Tue, 14 Sep 2021 02:05:01 GMT</pubDate>
<description><![CDATA[Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Citizenlab Discloses NSO Exploit Details<br/>
 <a href="https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/">https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild/</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop.html</a><br/>
WooCommerce Multi Currency Plugin Vulnerablity<br/>
 <a href="https://blog.nintechnet.com/vulnerability-fixed-in-wordpress-woocommerce-multi-currency-plugin/">https://blog.nintechnet.com/vulnerability-fixed-in-wordpress-woocommerce-multi-currency-plugin/</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7670" type="text/plain" language="en" />
<itunes:keywords>woocommerce, currency, plugin, google, chrome, citizenlab, nso, exploit, apple, ios, ipados, watchos, macos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 13th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7668</itunes:episode>
<itunes:subtitle>MSFT DNS Logs to Elastic; MSHTML Exploits; Lock Screen Bypass; Citrix Patches; nodejs tar vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT DNS Logs to Elastic; MSHTML Exploits; Lock Screen Bypass; Citrix Patches; nodejs tar vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7668.mp3" length="4965609" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7668.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7668</link>
<pubDate>Mon, 13 Sep 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Shipping Microsoft DNS Logs to Elasticsearch<br/>
 <a href="https://isc.sans.edu/forums/diary/Shipping+to+Elasticsearch+Microsoft+DNS+Logs/27828/">https://isc.sans.edu/forums/diary/Shipping+to+Elasticsearch+Microsoft+DNS+Logs/27828/</a><br/>
Exploit Generator for CVE-2021-40444<br/>
 <a href="https://github.com/lockedbyte/CVE-2021-40444">https://github.com/lockedbyte/CVE-2021-40444</a><br/>
Windows Lock Screen Bypass<br/>
 <a href="https://halove23.blogspot.com/2021/09/zdi-21-1053-bypassing-windows-lock.html">https://halove23.blogspot.com/2021/09/zdi-21-1053-bypassing-windows-lock.html</a><br/>
Citrix Hypervisor Update<br/>
 <a href="https://support.citrix.com/article/CTX325319">https://support.citrix.com/article/CTX325319</a><br/>
GitHub Identifies Vulnerable node.js Packages<br/>
 <a href="https://github.blog/2021-09-08-github-security-update-vulnerabilities-tar-npmcli-arborist/">https://github.blog/2021-09-08-github-security-update-vulnerabilities-tar-npmcli-arborist/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7668" type="text/plain" language="en" />
<itunes:keywords>github, node.js, citrix, windows, lock screen, mshtml, dns, elasticsearch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 10th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7666</itunes:episode>
<itunes:subtitle>ISC/DShield API Updates; MSHTML Vulnerablity Update; GitHub check-spelling Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ISC/DShield API Updates; MSHTML Vulnerablity Update; GitHub check-spelling Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7666.mp3" length="5768572" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7666.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7666</link>
<pubDate>Fri, 10 Sep 2021 02:00:01 GMT</pubDate>
<description><![CDATA[ISC/DShield API Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Updates+to+Our+DatafeedsAPI/27824/">https://isc.sans.edu/forums/diary/Updates+to+Our+DatafeedsAPI/27824/</a><br/>
Update on Windows MSHTML Vulnerability<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-mshtml-zero-day-defenses-bypassed-as-new-info-emerges/">https://www.bleepingcomputer.com/news/microsoft/windows-mshtml-zero-day-defenses-bypassed-as-new-info-emerges/</a><br/>
GitHub Actions check-spelling community workflow GITHUB_TOKEN leakage<br/>
 <a href="https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md">https://github.com/justinsteven/advisories/blob/master/2021_github_actions_checkspelling_token_leak_via_advice_symlink.md</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7666" type="text/plain" language="en" />
<itunes:keywords>mshtml, windows, api, threatfead, new domains, github, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7664</itunes:episode>
<itunes:subtitle>Protonmail Correction; BazarLoader "Stolen Images"; Thyotic SS; Zoho Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Protonmail Correction; BazarLoader "Stolen Images"; Thyotic SS; Zoho Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7664.mp3" length="5061394" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7664.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7664</link>
<pubDate>Thu, 09 Sep 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Protonmail Correction<br/>
 <a href="https://protonmail.com/blog/climate-activist-arrest/">https://protonmail.com/blog/climate-activist-arrest/</a><br/>
 <a href="https://protonmail.com/privacy-policy">https://protonmail.com/privacy-policy</a><br/>
"Stolen Images Evidence" Campaign Continues Pushing BazarLoader Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Stolen+Images+Evidence+Campaign+Continues+Pushing+BazarLoader+Malware/27816/">https://isc.sans.edu/forums/diary/Stolen+Images+Evidence+Campaign+Continues+Pushing+BazarLoader+Malware/27816/</a><br/>
Thyotic Secret Server Critical Update<br/>
 <a href="https://docs.thycotic.com/ss/11.0.0/release-notes/ss-rn-11-0-000007.md">https://docs.thycotic.com/ss/11.0.0/release-notes/ss-rn-11-0-000007.md</a><br/>
Zoho Vulnerablity Exploited <br/>
 <a href="https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html">https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7664" type="text/plain" language="en" />
<itunes:keywords>zoho, thyotic, bazarloader, protonmail, protonvpn, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7662</itunes:episode>
<itunes:subtitle>MSHTML 0-Day Exploited; ProtonVPN Privacy; What's App Moderation; Stashing Payload in Log Files (CLFS);
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSHTML 0-Day Exploited; ProtonVPN Privacy; What's App Moderation; Stashing Payload in Log Files (CLFS);
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7662.mp3" length="5112541" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7662.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7662</link>
<pubDate>Wed, 08 Sep 2021 02:05:01 GMT</pubDate>
<description><![CDATA[Microsoft MSHTML Remote Code Execution Vulnerability CVE-2021-40444<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444</a><br/>
ProntonMail/VPN Releasing User's IP Address<br/>
 <a href="https://protonmail.com/blog/climate-activist-arrest/">https://protonmail.com/blog/climate-activist-arrest/</a><br/>
What's App End To End Encryption Questioned (but upheld)<br/>
 <a href="https://twitter.com/evacide/status/1435288900587589632?s=20">https://twitter.com/evacide/status/1435288900587589632?s=20</a><br/>
PRIVATELOG and STASHLOG Malware Store Payload in Common Log File System (CLFS)<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2021/09/unknown-actor-using-clfs-log-files-for-stealth.html">https://www.fireeye.com/blog/threat-research/2021/09/unknown-actor-using-clfs-log-files-for-stealth.html</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7662" type="text/plain" language="en" />
<itunes:keywords>privatelog, stashlog, fireeye, clfs, log files, whats app, protonmail, protonvpn, mshtml, microsoft, cve-2021-40444, activex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 7th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7660</itunes:episode>
<itunes:subtitle>Confluence Update; ProxyShell Update; Ghostscript RCE;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Confluence Update; ProxyShell Update; Ghostscript RCE;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7660.mp3" length="4859436" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7660.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7660</link>
<pubDate>Tue, 07 Sep 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Confluence Update<br/>
 <a href="https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html">https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html</a><br/>
 <a href="https://www.jenkins.io/blog/2021/09/04/wiki-attacked/">https://www.jenkins.io/blog/2021/09/04/wiki-attacked/</a><br/>
ProxyShell Update<br/>
 <a href="https://news.sophos.com/en-us/2021/09/03/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks/">https://news.sophos.com/en-us/2021/09/03/conti-affiliates-use-proxyshell-exchange-exploit-in-ransomware-attacks/</a><br/>
RCE-0-Day for GhostScript 9.50<br/>
 <a href="https://github.com/duc-nt/RCE-0-day-for-GhostScript-9.50">https://github.com/duc-nt/RCE-0-day-for-GhostScript-9.50</a><br/>
Netgear Switch Auth Bypass<br/>
 <a href="https://kb.netgear.com/000063978/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Smart-Switches-PSV-2021-0140-PSV-2021-0144-PSV-2021-0145">https://kb.netgear.com/000063978/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Smart-Switches-PSV-2021-0140-PSV-2021-0144-PSV-2021-0145</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7660" type="text/plain" language="en" />
<itunes:keywords>netgear, ghostscript, proxyshell, confluence, exchange, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7658</itunes:episode>
<itunes:subtitle>Hurricane Scams; Confluence Attacked; Cisco Ent. NFVIS; GPU Malware; @sans_edu : Cloud Forensics Triage Framework
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hurricane Scams; Confluence Attacked; Cisco Ent. NFVIS; GPU Malware; @sans_edu : Cloud Forensics Triage Framework
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7658.mp3" length="12209101" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7658.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7658</link>
<pubDate>Fri, 03 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Attackers Will Always Abuse Major Events in our Lifes<br/>
 <a href="https://isc.sans.edu/forums/diary/Attackers+Will+Always+Abuse+Major+Events+in+our+Lifes/27808/">https://isc.sans.edu/forums/diary/Attackers+Will+Always+Abuse+Major+Events+in+our+Lifes/27808/</a><br/>
Active Exploitation of Confluence Server CVE-2021-26084<br/>
 <a href="https://www.rapid7.com/blog/post/2021/09/02/active-exploitation-of-confluence-server-cve-2021-26084/">https://www.rapid7.com/blog/post/2021/09/02/active-exploitation-of-confluence-server-cve-2021-26084/</a><br/>
GitHub Removing old Ciphers / Keys<br/>
 <a href="https://github.blog/2021-09-01-improving-git-protocol-security-github/">https://github.blog/2021-09-01-improving-git-protocol-security-github/</a><br/>
Cisco Enterprise NFV Infrastructure Software Authentication Bypass<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nfvis-g2DMVVh</a><br/>
Hackers are Selling Tool to Hide Malware in GPUs<br/>
 <a href="https://www.ehackingnews.com/2021/09/hackers-are-selling-tool-to-hide.html">https://www.ehackingnews.com/2021/09/hackers-are-selling-tool-to-hide.html</a><br/>
Michael Beck: Cloud Forensics Triage Framework (CFTF)<br/>
 <a href="https://www.sans.org/white-papers/40415/">https://www.sans.org/white-papers/40415/</a><br/>
]]></description>
<itunes:duration>14:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7658" type="text/plain" language="en" />
<itunes:keywords>sans_edu, forensics, cloud, cftf, gpu, malware, cisco, authentication, confluence, atlassian, github, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7656</itunes:episode>
<itunes:subtitle>Java Malware STRRAT; Baby Monitor Exposed; Annke NVR; ProxyWare Abuse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Java Malware STRRAT; Baby Monitor Exposed; Annke NVR; ProxyWare Abuse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7656.mp3" length="5342790" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7656.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7656</link>
<pubDate>Thu, 02 Sep 2021 02:00:01 GMT</pubDate>
<description><![CDATA[STRRAT: A Java Based RAT That Doesn't Care if You Have Java<br/>
 <a href="https://isc.sans.edu/forums/diary/STRRAT+a+Javabased+RAT+that+doesnt+care+if+you+have+Java/27798/">https://isc.sans.edu/forums/diary/STRRAT+a+Javabased+RAT+that+doesnt+care+if+you+have+Java/27798/</a><br/>
IPC360 Baby Monitor Vulnerability<br/>
<a href="https://www.bitdefender.com/files/News/CaseStudies/study/402/Bitdefender-PR-Whitepaper-VictureIPC-creat5590-en-EN.pdf">https://www.bitdefender.com/files/News/CaseStudies/study/402/Bitdefender-PR-Whitepaper-VictureIPC-creat5590-en-EN.pdf</a><br/>
Annke Network Video Recorder Vulnerability<br/>
 <a href="https://us-cert.cisa.gov/ics/advisories/icsa-21-238-02">https://us-cert.cisa.gov/ics/advisories/icsa-21-238-02</a><br/>
ProxyWare Abuse<br/>
 <a href="https://blog.talosintelligence.com/2021/08/proxyware-abuse.html">https://blog.talosintelligence.com/2021/08/proxyware-abuse.html</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7656" type="text/plain" language="en" />
<itunes:keywords>proxyware, annke, video recorder, nvr, baby monitor, ipc360, strrat, java, jre, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7654</itunes:episode>
<itunes:subtitle>More Bluetooth Vulns; Fortress Home Sec. Remote Disarm; PostgreSQL set_user
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Bluetooth Vulns; Fortress Home Sec. Remote Disarm; PostgreSQL set_user
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7654.mp3" length="4882066" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7654.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7654</link>
<pubDate>Wed, 01 Sep 2021 02:00:02 GMT</pubDate>
<description><![CDATA[BrakTooth: Impacts, Implications and Next Steps<br/>
 <a href="https://isc.sans.edu/forums/diary/BrakTooth+Impacts+Implications+and+Next+Steps/27802/">https://isc.sans.edu/forums/diary/BrakTooth+Impacts+Implications+and+Next+Steps/27802/</a><br/>
Fortress Home Security System Weakness<br/>
 <a href="https://threatpost.com/fortress-home-security-remote-disarmament/169069/">https://threatpost.com/fortress-home-security-remote-disarmament/169069/</a><br/>
PostgreSQL set_user Module Vulnerability<br/>
 <a href="https://www.postgresql.org/about/news/set_user-201-released-2279/">https://www.postgresql.org/about/news/set_user-201-released-2279/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7654" type="text/plain" language="en" />
<itunes:keywords>postgresql, set_user, fortress, braktooth, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 31st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7652</itunes:episode>
<itunes:subtitle>Crypto Clipboard Fun; Exchange ProxyToken; LockFile Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Crypto Clipboard Fun; Exchange ProxyToken; LockFile Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7652.mp3" length="5263782" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7652.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7652</link>
<pubDate>Tue, 31 Aug 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Cryptocurrency Clipboard Swapper Delivered With Love<br/>
 <a href="https://isc.sans.edu/forums/diary/Cryptocurrency+Clipboard+Swapper+Delivered+With+Love/27794/">https://isc.sans.edu/forums/diary/Cryptocurrency+Clipboard+Swapper+Delivered+With+Love/27794/</a><br/>
ProxyToken Vulnerability in Exchange<br/>
 <a href="https://www.zerodayinitiative.com/blog/2021/8/30/proxytoken-an-authentication-bypass-in-microsoft-exchange-server">https://www.zerodayinitiative.com/blog/2021/8/30/proxytoken-an-authentication-bypass-in-microsoft-exchange-server</a><br/>
LockFile Ransomware Evasion Tricks<br/>
 <a href="https://thehackernews.com/2021/08/lockfile-ransomware-bypasses-protection.html">https://thehackernews.com/2021/08/lockfile-ransomware-bypasses-protection.html</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7652" type="text/plain" language="en" />
<itunes:keywords>lockfile, ransomware, proxytoken, exchange, clipboard, crypto, bitcoin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 30th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7650</itunes:episode>
<itunes:subtitle>Cosmos DB Vulnerability; Open Redirect Phishing; Parallels Priv Escalation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cosmos DB Vulnerability; Open Redirect Phishing; Parallels Priv Escalation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7650.mp3" length="4566502" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7650.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7650</link>
<pubDate>Mon, 30 Aug 2021 10:15:02 GMT</pubDate>
<description><![CDATA[ChaosDB: Azure Cosmos Database Vulnerability<br/>
 <a href="https://chaosdb.wiz.io">https://chaosdb.wiz.io</a><br/>
Phishing via Open Redirects<br/>
 <a href="https://www.microsoft.com/security/blog/2021/08/26/widespread-credential-phishing-campaign-abuses-open-redirector-links/">https://www.microsoft.com/security/blog/2021/08/26/widespread-credential-phishing-campaign-abuses-open-redirector-links/</a><br/>
Parallels Vulnerability<br/>
 <a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/208188">https://exchange.xforce.ibmcloud.com/vulnerabilities/208188</a><br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-21-1000/">https://www.zerodayinitiative.com/advisories/ZDI-21-1000/</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7650" type="text/plain" language="en" />
<itunes:keywords>parallels, phishing, redirects, azure, chasodb, cosmos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 27th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7648</itunes:episode>
<itunes:subtitle>Cisco Advisories; Geth DoS Vuln; Confluence Patch; VMWare Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco Advisories; Geth DoS Vuln; Confluence Patch; VMWare Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7648.mp3" length="5125644" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7648.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7648</link>
<pubDate>Fri, 27 Aug 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Cisco Advisories<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
GETH DoS Vulnerability<br/>
 <a href="https://github.com/ethereum/go-ethereum/releases/tag/v1.10.8">https://github.com/ethereum/go-ethereum/releases/tag/v1.10.8</a><br/>
Confluence Security Advisory<br/>
 <a href="https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html">https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html</a><br/>
VMWare Updates<br/>
 <a href="https://www.vmware.com/security/advisories.html">https://www.vmware.com/security/advisories.html</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7648" type="text/plain" language="en" />
<itunes:keywords>vmware, updates, confluence, atlassian, geth, dos, cisco, nexus, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 26th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7646</itunes:episode>
<itunes:subtitle>SPF Survey for .CZ; OpenSSL Update; F5 BigIP Update; SideWalk Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SPF Survey for .CZ; OpenSSL Update; F5 BigIP Update; SideWalk Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7646.mp3" length="5124441" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7646.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7646</link>
<pubDate>Thu, 26 Aug 2021 02:05:01 GMT</pubDate>
<description><![CDATA[There May Be Many More SPF Records Than We Might Expect<br/>
 <a href="https://isc.sans.edu/forums/diary/There+may+be+many+more+SPF+records+than+we+might+expect/27786/">https://isc.sans.edu/forums/diary/There+may+be+many+more+SPF+records+than+we+might+expect/27786/</a><br/>
OpenSSL Update<br/>
 <a href="https://www.openssl.org/news/vulnerabilities.html">https://www.openssl.org/news/vulnerabilities.html</a><br/>
F5 Update<br/>
 <a href="https://support.f5.com/csp/article/K50974556">https://support.f5.com/csp/article/K50974556</a><br/>
 <a href="https://support.f5.com/csp/article/K41351250">https://support.f5.com/csp/article/K41351250</a><br/>
SideWalk Backdoor<br/>
 <a href="https://www.welivesecurity.com/2021/08/24/sidewalk-may-be-as-dangerous-as-crosswalk/">https://www.welivesecurity.com/2021/08/24/sidewalk-may-be-as-dangerous-as-crosswalk/</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7646" type="text/plain" language="en" />
<itunes:keywords>sidewalk, backdoor, f5, big-ip, openssl, spf, cz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 25th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7644</itunes:episode>
<itunes:subtitle>Searching for ENV; WhatsApp Malware; SteelSeries Keyboard Priv esc;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Searching for ENV; WhatsApp Malware; SteelSeries Keyboard Priv esc;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7644.mp3" length="4796685" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7644.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7644</link>
<pubDate>Wed, 25 Aug 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Attackers Hunting for Twilio Credentials<br/>
 <a href="https://isc.sans.edu/forums/diary/Attackers+Hunting+For+Twilio+Credentials/27782/">https://isc.sans.edu/forums/diary/Attackers+Hunting+For+Twilio+Credentials/27782/</a><br/>
Modified WhatsApp Spreading Malware<br/>
 <a href="https://securelist.com/triada-trojan-in-whatsapp-mod/103679/">https://securelist.com/triada-trojan-in-whatsapp-mod/103679/</a><br/>
Privilege Escalation without Pluggin in Device<br/>
<a href="http://0xsp.com/security%20research%20&%20development%20(SRD)/local-administrator-is-not-just-with-razer-it-is-possible-for-all">http://0xsp.com/security%20research%20&%20development%20(SRD)/local-administrator-is-not-just-with-razer-it-is-possible-for-all</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7644" type="text/plain" language="en" />
<itunes:keywords>steelseries, keyboard, privilege escalation, twilio, whatsapp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 24th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7642</itunes:episode>
<itunes:subtitle>OOB SMS Phish; Razer Mouse Priv Esc; Realtek Vuln Exploited; Exposed MSFT PowerApps
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OOB SMS Phish; Razer Mouse Priv Esc; Realtek Vuln Exploited; Exposed MSFT PowerApps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7642.mp3" length="5082226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7642.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7642</link>
<pubDate>Tue, 24 Aug 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Out of Band Phishing Using SMS Messages to Evade Network Detection<br/>
 <a href="https://isc.sans.edu/forums/diary/Out+of+Band+Phishing+Using+SMS+messages+to+Evade+Network+Detection/27768/">https://isc.sans.edu/forums/diary/Out+of+Band+Phishing+Using+SMS+messages+to+Evade+Network+Detection/27768/</a><br/>
Elevate Priviledges with Razer Mouse<br/>
 <a href="https://twitter.com/j0nh4t/status/1429049506021138437">https://twitter.com/j0nh4t/status/1429049506021138437</a><br/>
Realtek Vulnerabilites Exploited<br/>
 <a href="https://securingsam.com/realtek-vulnerabilities-weaponized/">https://securingsam.com/realtek-vulnerabilities-weaponized/</a><br/>
Exposed Microsoft Power Apps<br/>
 <a href="https://www.upguard.com/breaches/power-apps">https://www.upguard.com/breaches/power-apps</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7642" type="text/plain" language="en" />
<itunes:keywords>microsoft power apps, power apps, razer, mouse, realtek, sms, oob, out of band, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 23rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7640</itunes:episode>
<itunes:subtitle>Waiting for C2; DOCX with EXE; Securing Cloud PCs; Cloud PC Security; Pegasus Scam
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Waiting for C2; DOCX with EXE; Securing Cloud PCs; Cloud PC Security; Pegasus Scam
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7640.mp3" length="4645795" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7640.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7640</link>
<pubDate>Mon, 23 Aug 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Waiting for the C2 to Show Up<br/>
 <a href="https://isc.sans.edu/forums/diary/Waiting+for+the+C2+to+Show+Up/27772/">https://isc.sans.edu/forums/diary/Waiting+for+the+C2+to+Show+Up/27772/</a><br/>
DOCX with Embdedded EXE<br/>
 <a href="https://isc.sans.edu/forums/diary/docx+With+Embedded+EXE/27776/">https://isc.sans.edu/forums/diary/docx+With+Embedded+EXE/27776/</a><br/>
Securing Your Windows 365 Cloud PCs<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/securing-your-windows-365-cloud-pcs/ba-p/2663129">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/securing-your-windows-365-cloud-pcs/ba-p/2663129</a><br/>
Pegasus Fraud Scam<br/>
 <a href="https://www.ehackingnews.com/2021/08/pegasus-iphone-hacks-used-as-bait-in.html">https://www.ehackingnews.com/2021/08/pegasus-iphone-hacks-used-as-bait-in.html</a><br/>
Proper Audit Logging for Office 365<br/>
 <a href="https://zolder.io/office-365-audit-logging/">https://zolder.io/office-365-audit-logging/</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7640" type="text/plain" language="en" />
<itunes:keywords>zolder, office 365, pregasus, scam, windows 365, docx, c2, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 20th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7638</itunes:episode>
<itunes:subtitle>Lightning Strike; Cisco Won't fix EoL Router Bugs; Blackberry QNX bug; @sans_edu student @markmorow
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Lightning Strike; Cisco Won't fix EoL Router Bugs; Blackberry QNX bug; @sans_edu student @markmorow
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7638.mp3" length="13144388" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7638.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7638</link>
<pubDate>Fri, 20 Aug 2021 02:00:01 GMT</pubDate>
<description><![CDATA[When Lightning Strikes: What works and doesn't work<br/>
 <a href="https://isc.sans.edu/forums/diary/When+Lightning+Strikes+What+works+and+doesnt+work/27766/">https://isc.sans.edu/forums/diary/When+Lightning+Strikes+What+works+and+doesnt+work/27766/</a><br/>
Cisco Small Business Router Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-sb-rv-overflow-htpymMB5">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cisco-sb-rv-overflow-htpymMB5</a><br/>
Blackberry QNX Products Vulnerability<br/>
 <a href="https://support.blackberry.com/kb/articleDetail?articleNumber=000082334">https://support.blackberry.com/kb/articleDetail?articleNumber=000082334</a><br/>
SANS.edu Student: Mark Morowcynzski; Decreasing Attacker Dwell Time in Azure Active Directory<br/>
 <a href="https://www.sans.org/white-papers/40390/">https://www.sans.org/white-papers/40390/</a><br/>
]]></description>
<itunes:duration>15:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7638" type="text/plain" language="en" />
<itunes:keywords>sans.edu, blackberry, qnx, cisco, lightning, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7636</itunes:episode>
<itunes:subtitle>Moving Back to the Office; Adobe Updates; Tetris Spyware; HolesWarm Malware; Trickbot Tricks;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Moving Back to the Office; Adobe Updates; Tetris Spyware; HolesWarm Malware; Trickbot Tricks;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7636.mp3" length="4398590" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7636.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7636</link>
<pubDate>Thu, 19 Aug 2021 02:00:02 GMT</pubDate>
<description><![CDATA[5 Things to Consider Before Moving Back to the Office<br/>
 <a href="https://isc.sans.edu/forums/diary/5+Things+to+Consider+Before+Moving+Back+to+the+Office/27762/">https://isc.sans.edu/forums/diary/5+Things+to+Consider+Before+Moving+Back+to+the+Office/27762/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Several Web Sites Infected with Chinese Spyware<br/>
 <a href="https://imp0rtp3.wordpress.com/2021/08/12/tetris/">https://imp0rtp3.wordpress.com/2021/08/12/tetris/</a><br/>
Trickbot Tricks Users with 1Password<br/>
 <a href="https://www.ehackingnews.com/2021/08/trickbot-employs-bogus-1password.html">https://www.ehackingnews.com/2021/08/trickbot-employs-bogus-1password.html</a><br/>
 <br/>
]]></description>
<itunes:duration>4:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7636" type="text/plain" language="en" />
<itunes:keywords>trickbot, 1password, adobe, patches, office, chinese, jsonp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7634</itunes:episode>
<itunes:subtitle>Laravel Bug Exploited; ThroughTek Kaley Vuln; Fortinet FortiWeb; Google Chrome Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Laravel Bug Exploited; ThroughTek Kaley Vuln; Fortinet FortiWeb; Google Chrome Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7634.mp3" length="5543094" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7634.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7634</link>
<pubDate>Wed, 18 Aug 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Laravel Exploit Attempts Tageting Vulnerability in "Ignition"<br/>
 <a href="https://isc.sans.edu/forums/diary/Laravel+v842+exploit+attempts+for+CVE20213129+debug+mode+Remote+code+execution/27758/">https://isc.sans.edu/forums/diary/Laravel+v842+exploit+attempts+for+CVE20213129+debug+mode+Remote+code+execution/27758/</a><br/>
ThroughTek "Kaley" Protocol Vulnerability<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2021/08/mandiant-discloses-critical-vulnerability-affecting-iot-devices.html">https://www.fireeye.com/blog/threat-research/2021/08/mandiant-discloses-critical-vulnerability-affecting-iot-devices.html</a><br/>
Fortinet FortiWeb Vulnerability<br/>
 <a href="https://www.rapid7.com/blog/post/2021/08/17/fortinet-fortiweb-os-command-injection/">https://www.rapid7.com/blog/post/2021/08/17/fortinet-fortiweb-os-command-injection/</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7634" type="text/plain" language="en" />
<itunes:keywords>fortinet, fortiweb, throughtek, kaley, video, laravel, ignition, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 17th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7632</itunes:episode>
<itunes:subtitle>Malware Bazaar Tricks; Realtek Vuln; STARTTLS; NodeJS DNS Flaw; Racoon Infostealer Self-Infection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Bazaar Tricks; Realtek Vuln; STARTTLS; NodeJS DNS Flaw; Racoon Infostealer Self-Infection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7632.mp3" length="4778492" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7632.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7632</link>
<pubDate>Tue, 17 Aug 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Triage of Malware Bazaar's Daily Malware Batches<br/>
 <a href="https://isc.sans.edu/forums/diary/Extra+Tip+For+Triage+Of+MALWARE+Bazaars+Daily+Malware+Batches/27754/">https://isc.sans.edu/forums/diary/Extra+Tip+For+Triage+Of+MALWARE+Bazaars+Daily+Malware+Batches/27754/</a><br/>
Realtek SDK Vulnerability<br/>
 <a href="https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/">https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/</a><br/>
 <a href="https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf">https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf</a><br/>
STARTTLS Vulnerabilities<br/>
 <a href="https://www.usenix.org/conference/usenixsecurity21/presentation/poddebniak">https://www.usenix.org/conference/usenixsecurity21/presentation/poddebniak</a><br/>
Racoon Infostealer Self Infection<br/>
 <a href="https://mobile.twitter.com/HRock/status/1427259563363950596">https://mobile.twitter.com/HRock/status/1427259563363950596</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7632" type="text/plain" language="en" />
<itunes:keywords>racoon, infosteeler, self infection, starttls, realtek, malware bazaar, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7630</itunes:episode>
<itunes:subtitle>Exchange E-Discovery Scans; Danabot Malspam; Weaponizing Middleboxes; COTS Encryption in Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exchange E-Discovery Scans; Danabot Malspam; Weaponizing Middleboxes; COTS Encryption in Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7630.mp3" length="5195857" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7630.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7630</link>
<pubDate>Mon, 16 Aug 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Exchange E-Discovery Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+for+Microsoft+Exchange+eDiscovery/27748/">https://isc.sans.edu/forums/diary/Scanning+for+Microsoft+Exchange+eDiscovery/27748/</a><br/>
Danabot Distributed Through Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+Danabot+distributed+through+malspam/27744/">https://isc.sans.edu/forums/diary/Example+of+Danabot+distributed+through+malspam/27744/</a><br/>
Weaponizing Middleboxes<br/>
 <a href="https://geneva.cs.umd.edu/posts/usenix21-weaponizing-censors/">https://geneva.cs.umd.edu/posts/usenix21-weaponizing-censors/</a><br/>
 <a href="https://www.usenix.org/conference/usenixsecurity21/presentation/bock">https://www.usenix.org/conference/usenixsecurity21/presentation/bock</a><br/>
Deep Blue Magic Ransomware<br/>
 <a href="https://www.ehackingnews.com/2021/08/deepbluemagic-newly-discovered.html">https://www.ehackingnews.com/2021/08/deepbluemagic-newly-discovered.html</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7630" type="text/plain" language="en" />
<itunes:keywords>exchange, e-discovery, danabot, malspam, middleboxes, deep blue magic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 13th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7628</itunes:episode>
<itunes:subtitle>More Print Nightmare (and used in Ransomware Attacks); PolyNetwork Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Print Nightmare (and used in Ransomware Attacks); PolyNetwork Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7628.mp3" length="2979866" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7628.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7628</link>
<pubDate>Fri, 13 Aug 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Print Nightmare Continues: CVE-2021-36958<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36958">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-36958</a><br/>
Print Nightmare Abused by Ransomware Gangs<br/>
 <a href="https://www.crowdstrike.com/blog/magniber-ransomware-caught-using-printnightmare-vulnerability/">https://www.crowdstrike.com/blog/magniber-ransomware-caught-using-printnightmare-vulnerability/</a><br/>
PolyNetwork Attack<br/>
 <a href="https://www.theregister.com/2021/08/10/poly_networks_cryptocurrency_theft/">https://www.theregister.com/2021/08/10/poly_networks_cryptocurrency_theft/</a><br/>
]]></description>
<itunes:duration>3:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7628" type="text/plain" language="en" />
<itunes:keywords>polynetwork, print nightmare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7626</itunes:episode>
<itunes:subtitle>Encrypted ZIP to Cobalt Strike; MacOS AdLoad; 5G Issues; Cloud DNS;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encrypted ZIP to Cobalt Strike; MacOS AdLoad; 5G Issues; Cloud DNS;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7626.mp3" length="5284251" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7626.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7626</link>
<pubDate>Thu, 12 Aug 2021 02:00:02 GMT</pubDate>
<description><![CDATA[TA551 Shathak Continues Pushing BazarLoader Leading to Cobalt Strike<br/>
 <a href="https://isc.sans.edu/forums/diary/TA551+Shathak+continues+pushing+BazarLoader+infections+lead+to+Cobalt+Strike/27738/">https://isc.sans.edu/forums/diary/TA551+Shathak+continues+pushing+BazarLoader+infections+lead+to+Cobalt+Strike/27738/</a><br/>
New AdLoad Campaign Goes Undetected by XProtect<br/>
 <a href="https://labs.sentinelone.com/massive-new-adload-campaign-goes-entirely-undetected-by-apples-xprotect/">https://labs.sentinelone.com/massive-new-adload-campaign-goes-entirely-undetected-by-apples-xprotect/</a><br/>
Android FlyTrap Malware Hitting Facebook Users<br/>
 <a href="https://www.ehackingnews.com/2021/08/android-malware-flytrap-hacks-facebook.html">https://www.ehackingnews.com/2021/08/android-malware-flytrap-hacks-facebook.html</a><br/>
5G Shortcuts allow Evesdropping<br/>
 <a href="https://www.wired.com/story/5g-network-stingray-surveillance-non-standalone/">https://www.wired.com/story/5g-network-stingray-surveillance-non-standalone/</a><br/>
Cloud DNS Service Weeknesses<br/>
 <a href="https://www.wiz.io/blog/black-hat-2021-dns-loophole-makes-nation-state-level-spying-as-easy-as-registering-a-domain">https://www.wiz.io/blog/black-hat-2021-dns-loophole-makes-nation-state-level-spying-as-easy-as-registering-a-domain</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7626" type="text/plain" language="en" />
<itunes:keywords>cloud dns, 5g, lte, stringray, android, flytrap, malware, facebook, adload, macos, ta551, bazarloader, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7624</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches; cPanel Vulns; Firefox Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches; cPanel Vulns; Firefox Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7624.mp3" length="4838108" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7624.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7624</link>
<pubDate>Wed, 11 Aug 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+August+2021+Patch+Tuesday/27736/">https://isc.sans.edu/forums/diary/Microsoft+August+2021+Patch+Tuesday/27736/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
cPanel/WHM Vulnerabilities<br/>
 <a href="https://www.fortbridge.co.uk/research/multiple-vulnerabilities-in-cpanel-whm/">https://www.fortbridge.co.uk/research/multiple-vulnerabilities-in-cpanel-whm/</a><br/>
Firefox Update Released<br/>
 <a href="https://www.mozilla.org/en-US/firefox/91.0/releasenotes/">https://www.mozilla.org/en-US/firefox/91.0/releasenotes/</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7624" type="text/plain" language="en" />
<itunes:keywords>firefox, cpanel, adobe, microsoft, patches, xss, xee, csrf, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 10th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7622</itunes:episode>
<itunes:subtitle>Exchange ProxyShell; Synology and Router Attacks; Firefox Experiment; Messanging Bugs; HTTP2
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exchange ProxyShell; Synology and Router Attacks; Firefox Experiment; Messanging Bugs; HTTP2
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7622.mp3" length="5213472" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7622.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7622</link>
<pubDate>Tue, 10 Aug 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Exchange ProxyShell<br/>
<a href="https://isc.sans.edu/forums/diary/ProxyShell+how+many+Exchange+servers+are+affected+and+where+are+they/27732/">https://isc.sans.edu/forums/diary/ProxyShell+how+many+Exchange+servers+are+affected+and+where+are+they/27732/</a><br/>
Synology Warns of Brute Force Attacks<br/>
 <a href="https://www.synology.com/en-global/company/news/article/BruteForce/Synology">https://www.synology.com/en-global/company/news/article/BruteForce/Synology</a> %20Investigates%20Ongoing%20Brute-Force%20Attacks%20From%20Botnet<br/>
Router Auth Bypass<br/>
 <a href="https://threatpost.com/auth-bypass-bug-routers-exploited/168491/">https://threatpost.com/auth-bypass-bug-routers-exploited/168491/</a><br/>
Firefox Version 100 Experiment<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1719070">https://bugzilla.mozilla.org/show_bug.cgi?id=1719070</a><br/>
Interaction Less Vulnerabilities in Messaging Apps<br/>
 <a href="https://www.ehackingnews.com/2021/08/the-interaction-less-flaws-in-messaging.html">https://www.ehackingnews.com/2021/08/the-interaction-less-flaws-in-messaging.html</a><br/>
HTTP2 Vulnerabilities<br/>
 <a href="https://portswigger.net/research/http2#conclusion">https://portswigger.net/research/http2#conclusion</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7622" type="text/plain" language="en" />
<itunes:keywords>exchange, blackhat, router, synology, firefox, messaging apps, http2, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7620</itunes:episode>
<itunes:subtitle>Malicious Word Doc; Malware Bazaar Dailies; Go/Rust Octal IP Vuln; Master Faces; Pulse(In)Secure; Hadoop RCE Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Word Doc; Malware Bazaar Dailies; Go/Rust Octal IP Vuln; Master Faces; Pulse(In)Secure; Hadoop RCE Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7620.mp3" length="4827928" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7620.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7620</link>
<pubDate>Mon, 09 Aug 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Malicious Microsoft Word Remains A Key Infection Vector<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Microsoft+Word+Remains+A+Key+Infection+Vector/27716/">https://isc.sans.edu/forums/diary/Malicious+Microsoft+Word+Remains+A+Key+Infection+Vector/27716/</a><br/>
Malware Bazaar Daily Download<br/>
 <a href="https://isc.sans.edu/forums/diary/MALWARE+Bazaar+Download+daily+malware+batches/27728/">https://isc.sans.edu/forums/diary/MALWARE+Bazaar+Download+daily+malware+batches/27728/</a><br/>
Go/Rust IP Address Validation Vulnerability<br/>
 <a href="https://github.com/rust-lang/rust/pull/83652">https://github.com/rust-lang/rust/pull/83652</a><br/>
Facial Recognition "Master Keys"<br/>
 <a href="https://arxiv.org/pdf/2108.01077.pdf">https://arxiv.org/pdf/2108.01077.pdf</a><br/>
Pulse Secure Patch Bypass<br/>
 <a href="https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44858">https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44858</a><br/>
Hadoop ResourceManager Vulnerability Exploited<br/>
 <a href="https://blog.netlab.360.com/wei-xie-kuai-xun-teamtntxin-huo-dong-tong-guo-gan-ran-wang-ye-wen-jian-ti-gao-chuan-bo-neng-li/">https://blog.netlab.360.com/wei-xie-kuai-xun-teamtntxin-huo-dong-tong-guo-gan-ran-wang-ye-wen-jian-ti-gao-chuan-bo-neng-li/</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7620" type="text/plain" language="en" />
<itunes:keywords>hadoop, pulsesecure, facial recognition, go, rust, ip address, netmask, microsoft, word, malware, malwarebazaar, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 6th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7618</itunes:episode>
<itunes:subtitle>Cisco RV340/345; Telegram Self Destruct Bug; Bypassing MacOS TCC; Windows Hello Bypass Details; @sans_edu CSP Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco RV340/345; Telegram Self Destruct Bug; Bypassing MacOS TCC; Windows Hello Bypass Details; @sans_edu CSP Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7618.mp3" length="13276213" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7618.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7618</link>
<pubDate>Fri, 06 Aug 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Cisco Patches Unauthencticated RCE in RV340/345 devices<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv340-cmdinj-rcedos-pY8J3qfy">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv340-cmdinj-rcedos-pY8J3qfy</a><br/>
Telegram Flawed Self Destruct in MacOS<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/telegram-self-destruct-not-always/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/telegram-self-destruct-not-always/</a><br/>
Significant Vulnerabilities in MacOS Privacy Protections<br/>
 <a href="https://www.darkreading.com/application-security/researchers-find-significant-vulnerabilities-in-mac-os-privacy-protections">https://www.darkreading.com/application-security/researchers-find-significant-vulnerabilities-in-mac-os-privacy-protections</a><br/>
Windows Hello Bypass<br/>
 <a href="https://threatpost.com/microsofts-patch-windows-hello-faulty/168392/">https://threatpost.com/microsofts-patch-windows-hello-faulty/168392/</a><br/>
STI Student: James Casteel; Content Security Policy Bypass: Exploiting Misconfigurations <a href="https://www.sans.org/white-papers/40380">https://www.sans.org/white-papers/40380</a><br/>
]]></description>
<itunes:duration>15:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7618" type="text/plain" language="en" />
<itunes:keywords>sans.edu, csp, james casteel, windows hello, mac os, privacy, tcc, telegram, cisco patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7616</itunes:episode>
<itunes:subtitle>Possible UN Peacekeeping Phish; NichStack Vulns; Cloud Security; LockBit Recruiting Insiders; Office 365 Phish
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Possible UN Peacekeeping Phish; NichStack Vulns; Cloud Security; LockBit Recruiting Insiders; Office 365 Phish
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7616.mp3" length="5248457" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7616.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7616</link>
<pubDate>Thu, 05 Aug 2021 08:42:34 GMT</pubDate>
<description><![CDATA[Pivoting and Hunting for Shenanigans from a Reported Phishing Domain<br/>
 <a href="https://isc.sans.edu/forums/diary/Pivoting+and+Hunting+for+Shenanigans+from+a+Reported+Phishing+Domain/27710/">https://isc.sans.edu/forums/diary/Pivoting+and+Hunting+for+Shenanigans+from+a+Reported+Phishing+Domain/27710/</a><br/>
NichStack TCP/IP Vulnerabilities<br/>
 <a href="https://jfrog.com/blog/infrahalt-14-new-security-vulnerabilities-found-in-nichestack/">https://jfrog.com/blog/infrahalt-14-new-security-vulnerabilities-found-in-nichestack/</a><br/>
Securing the Cloud<br/>
 <a href="https://www.sans.org/newsletters/ouch/securely-using-the-cloud/">https://www.sans.org/newsletters/ouch/securely-using-the-cloud/</a><br/>
Lockbit Recruiting Insiders<br/>
 <a href="https://www.bleepingcomputer.com/news/security/lockbit-ransomware-recruiting-insiders-to-breach-corporate-networks/">https://www.bleepingcomputer.com/news/security/lockbit-ransomware-recruiting-insiders-to-breach-corporate-networks/</a><br/>
Sneaky Phishing Hittin Office 365 Users<br/>
 <a href="https://www.ehackingnews.com/2021/08/microsoft-warns-office-365-users-of.html">https://www.ehackingnews.com/2021/08/microsoft-warns-office-365-users-of.html</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7616" type="text/plain" language="en" />
<itunes:keywords>un phish, nichstack, tcp/ip, cloud, ouch, lockbit, insider, office 365, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 4th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7614</itunes:episode>
<itunes:subtitle>2FA Issues; Crazy Smishing; Google Chrome and Android Patch; NSA Kubernetes Hardening Guides
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
2FA Issues; Crazy Smishing; Google Chrome and Android Patch; NSA Kubernetes Hardening Guides
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7614.mp3" length="4648183" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7614.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7614</link>
<pubDate>Tue, 03 Aug 2021 21:42:29 GMT</pubDate>
<description><![CDATA[2FA Issues<br/>
 <a href="https://isc.sans.edu/forums/diary/Three+Problems+with+Two+Factor+Authentication/27704/">https://isc.sans.edu/forums/diary/Three+Problems+with+Two+Factor+Authentication/27704/</a><br/>
Crazy Smishing<br/>
 <a href="https://isc.sans.edu/forums/diary/Is+this+the+Weirdest+Phishing+SMishing+Attempt+Ever/27706/">https://isc.sans.edu/forums/diary/Is+this+the+Weirdest+Phishing+SMishing+Attempt+Ever/27706/</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2021/08/the-stable-channel-has-been-updated-to.html">https://chromereleases.googleblog.com/2021/08/the-stable-channel-has-been-updated-to.html</a><br/>
 <a href="https://www.bleepingcomputer.com/news/google/google-chrome-to-no-longer-show-secure-website-indicators/">https://www.bleepingcomputer.com/news/google/google-chrome-to-no-longer-show-secure-website-indicators/</a><br/>
Google Android Update<br/>
 <a href="https://source.android.com/security/bulletin/2021-08-01?hl=en">https://source.android.com/security/bulletin/2021-08-01?hl=en</a><br/>
DoD/NSA Publichses Kubernetes Hardening Guides<br/>
 <a href="https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF">https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7614" type="text/plain" language="en" />
<itunes:keywords>kubernetes, google, android, chrome, patches, phishing, smishing, 2fa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7612</itunes:episode>
<itunes:subtitle>DNS Queries Noise; BAT mods on the fly; "-" npm; RPC Filters vs PetitPotam; Pneumatic Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Queries Noise; BAT mods on the fly; "-" npm; RPC Filters vs PetitPotam; Pneumatic Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7612.mp3" length="5517097" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7612.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7612</link>
<pubDate>Tue, 03 Aug 2021 02:00:01 GMT</pubDate>
<description><![CDATA[Unsolicited DNS Queries<br/>
 <a href="https://isc.sans.edu/forums/diary/Unsolicited+DNS+Queries/27694/">https://isc.sans.edu/forums/diary/Unsolicited+DNS+Queries/27694/</a><br/>
Changing BAT Files on the Fly<br/>
 <a href="https://isc.sans.edu/forums/diary/Changing+BAT+Files+On+The+Fly/27700/">https://isc.sans.edu/forums/diary/Changing+BAT+Files+On+The+Fly/27700/</a><br/>
Empty NPM Package has Over 700,000 Downloads<br/>
 <a href="https://www.bleepingcomputer.com/news/software/empty-npm-package-has-over-700-000-downloads-heres-why/">https://www.bleepingcomputer.com/news/software/empty-npm-package-has-over-700-000-downloads-heres-why/</a><br/>
Blocking PetitPotam with netsh RPC Filters<br/>
 <a href="https://twitter.com/gentilkiwi/status/1421949715986403329">https://twitter.com/gentilkiwi/status/1421949715986403329</a><br/>
Pneumatic Tube Vulnerabilities<br/>
 <a href="https://www.blackhat.com/us-21/briefings/schedule/index.html#a-hole-in-the-tube-uncovering-vulnerabilities-in-critical-infrastructure-of-healthcare-facilities-23546">https://www.blackhat.com/us-21/briefings/schedule/index.html#a-hole-in-the-tube-uncovering-vulnerabilities-in-critical-infrastructure-of-healthcare-facilities-23546</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7612" type="text/plain" language="en" />
<itunes:keywords>petitpotam, tubes, pneumatic, rpc filters, netsh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, August 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7610</itunes:episode>
<itunes:subtitle>.reg Malware; Excessive Exchange Permissions (patched); Node.js Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
.reg Malware; Excessive Exchange Permissions (patched); Node.js Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7610.mp3" length="4869538" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7610.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7610</link>
<pubDate>Sun, 01 Aug 2021 18:39:40 GMT</pubDate>
<description><![CDATA[Infected With a .reg File<br/>
 <a href="https://isc.sans.edu/forums/diary/Infected+With+a+reg+File/27692/">https://isc.sans.edu/forums/diary/Infected+With+a+reg+File/27692/</a><br/>
Excessive Exchange Permissions (Patched)<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2186">https://bugs.chromium.org/p/project-zero/issues/detail?id=2186</a><br/>
Node.JS July 2021 Security Releases<br/>
 <a href="https://nodejs.org/en/blog/vulnerability/july-2021-security-releases-2/">https://nodejs.org/en/blog/vulnerability/july-2021-security-releases-2/</a><br/>
Malicious PyPi Packages<br/>
 <a href="https://jfrog.com/blog/malicious-pypi-packages-stealing-credit-cards-injecting-code/">https://jfrog.com/blog/malicious-pypi-packages-stealing-credit-cards-injecting-code/</a><br/>
REvil / Darkside May be Back as Blackmatter<br/>
 <a href="https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/">https://www.bleepingcomputer.com/news/security/darkside-ransomware-gang-returns-as-new-blackmatter-operation/</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7610" type="text/plain" language="en" />
<itunes:keywords>revil, darkside, blackmatter, pypi, node.js, exchange, permissions, registry, .reg file, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 30th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7608</itunes:episode>
<itunes:subtitle>Archive.org Malware; PyPI Security Analysis; Malware via Template Injection;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Archive.org Malware; PyPI Security Analysis; Malware via Template Injection;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7608.mp3" length="4947169" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7608.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7608</link>
<pubDate>Fri, 30 Jul 2021 01:09:26 GMT</pubDate>
<description><![CDATA[Malicious Content Delivered Trhough archive.org<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Content+Delivered+Through+archiveorg/27688/">https://isc.sans.edu/forums/diary/Malicious+Content+Delivered+Through+archiveorg/27688/</a><br/>
A Large-Scale Security-Oriented Static Analysis of Python Packages in PyPI<br/>
 <a href="https://arxiv.org/abs/2107.12699">https://arxiv.org/abs/2107.12699</a><br/>
Crimea "manifesto" deploys VBA Rat using double attack vectors<br/>
 <a href="https://blog.malwarebytes.com/threat-intelligence/2021/07/crimea-manifesto-deploys-vba-rat-using-double-attack-vectors/">https://blog.malwarebytes.com/threat-intelligence/2021/07/crimea-manifesto-deploys-vba-rat-using-double-attack-vectors/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7608" type="text/plain" language="en" />
<itunes:keywords>crimea, vba, rat, macro, template, pypi, archive.org, waybackmachine, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 29th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7606</itunes:episode>
<itunes:subtitle>IT Support Extortion; AV-Test Android; UBEL Android Malware; PunkSpider Reboot; AFRINIC IPv4 Heist
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IT Support Extortion; AV-Test Android; UBEL Android Malware; PunkSpider Reboot; AFRINIC IPv4 Heist
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7606.mp3" length="7472085" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7606.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7606</link>
<pubDate>Thu, 29 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[A Sextortion E-Mail From ... IT Support?!<br/>
 <a href="https://isc.sans.edu/forums/diary/A+sextortion+email+fromIT+support/27682/">https://isc.sans.edu/forums/diary/A+sextortion+email+fromIT+support/27682/</a><br/>
AV-Test Compares Android Anti-Virus Software<br/>
 <a href="https://www.av-test.org/en/news/15-security-apps-for-android-in-an-endurance-test/">https://www.av-test.org/en/news/15-security-apps-for-android-in-an-endurance-test/</a><br/>
Oscorp evolves into UBEL: Advanced Android Malware<br/>
 <a href="https://www.cleafy.com/cleafy-labs/ubel-oscorp-evolution">https://www.cleafy.com/cleafy-labs/ubel-oscorp-evolution</a><br/>
QOMPLX Reboots Punkspider<br/>
 <a href="https://www.globenewswire.com/da/news-release/2021/07/20/2265860/0/en/QOMPLX-Reboots-Punkspider.html">https://www.globenewswire.com/da/news-release/2021/07/20/2265860/0/en/QOMPLX-Reboots-Punkspider.html</a><br/>
AFRINIC IPv4 Address Heist<br/>
 <a href="https://lists.afrinic.net/pipermail/community-discuss/2021-July/004122.html">https://lists.afrinic.net/pipermail/community-discuss/2021-July/004122.html</a><br/>
]]></description>
<itunes:duration>8:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7606" type="text/plain" language="en" />
<itunes:keywords>afrinic, ipv4, qomplx, oscorp, ubel, av-test, google, android, sextortion, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 28th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7604</itunes:episode>
<itunes:subtitle>Details for CVE-2021-30807 (macOS/iOS); Zimbra XSS/SSRF; Ransomware via GPOs; Safe Links for MSFT Teams
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Details for CVE-2021-30807 (macOS/iOS); Zimbra XSS/SSRF; Ransomware via GPOs; Safe Links for MSFT Teams
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7604.mp3" length="5932464" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7604.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7604</link>
<pubDate>Wed, 28 Jul 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Details about CVE-2021-30807. (Patch released Monday for MacOS/iOS)<br/>
 <a href="https://saaramar.github.io/IOMobileFrameBuffer_LPE_POC/">https://saaramar.github.io/IOMobileFrameBuffer_LPE_POC/</a><br/>
Zimbra 8.8.15 XSS and SSRF Vulnerability<br/>
 <a href="https://blog.sonarsource.com/zimbra-webmail-compromise-via-email">https://blog.sonarsource.com/zimbra-webmail-compromise-via-email</a><br/>
LockBit Ransomware Uses Group Policies<br/>
 <a href="https://www.bleepingcomputer.com/news/security/lockbit-ransomware-automates-windows-domain-encryption-via-group-policies/">https://www.bleepingcomputer.com/news/security/lockbit-ransomware-automates-windows-domain-encryption-via-group-policies/</a><br/>
Microsoft Extending SafeLinks to Teams<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/microsoft-teams-gets-more-phishing-protection/ba-p/2585559">https://techcommunity.microsoft.com/t5/microsoft-defender-for-office/microsoft-teams-gets-more-phishing-protection/ba-p/2585559</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7604" type="text/plain" language="en" />
<itunes:keywords>microsoft, safelinks, teams, lockbit, ransomware, printer, zimbra, xss, ssrf, ios, macos, cvs-2021-30807, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 27th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7602</itunes:episode>
<itunes:subtitle>Recovering Malspam Password; Apple Patches 0-day; Multi OS Malware; GitHub Love for Go
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Recovering Malspam Password; Apple Patches 0-day; Multi OS Malware; GitHub Love for Go
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7602.mp3" length="5452827" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7602.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7602</link>
<pubDate>Tue, 27 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Recovering Malspam Password<br/>
 <a href="https://isc.sans.edu/forums/diary/Failed+Malspam+Recovering+The+Password/27674/">https://isc.sans.edu/forums/diary/Failed+Malspam+Recovering+The+Password/27674/</a><br/>
Apple Patches 0-Day<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Attackers Adopt Exotic Programming Languages<br/>
 <a href="https://blogs.blackberry.com/en/2021/07/old-dogs-new-tricks-attackers-adopt-exotic-programming-languages">https://blogs.blackberry.com/en/2021/07/old-dogs-new-tricks-attackers-adopt-exotic-programming-languages</a><br/>
LemonDuck/LemonCat Coinminers Going Multi-OS<br/>
 <a href="https://www.microsoft.com/security/blog/2021/07/22/when-coin-miners-evolve-part-1-exposing-lemonduck-and-lemoncat-modern-mining-malware-infrastructure/">https://www.microsoft.com/security/blog/2021/07/22/when-coin-miners-evolve-part-1-exposing-lemonduck-and-lemoncat-modern-mining-malware-infrastructure/</a><br/>
GitHub Expending Supply Chain Security Support to Go<br/>
 <a href="https://github.blog/2021-07-22-github-supply-chain-security-features-go-community/">https://github.blog/2021-07-22-github-supply-chain-security-features-go-community/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7602" type="text/plain" language="en" />
<itunes:keywords>apple, encryption, zip, john the ripper, lemonduck, lemoncat, github, go, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 26th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7600</itunes:episode>
<itunes:subtitle>PetitPotam ADCS Domain Admin Vulnerability; Mac Malware; VidMe Domain Owner Change
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PetitPotam ADCS Domain Admin Vulnerability; Mac Malware; VidMe Domain Owner Change
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7600.mp3" length="5707042" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7600.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7600</link>
<pubDate>Mon, 26 Jul 2021 02:10:03 GMT</pubDate>
<description><![CDATA[PetitPotam ADCS Domain Admin Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/Active+Directory+Certificate+Services+ADCS+PKI+domain+admin+vulnerability/27668/">https://isc.sans.edu/forums/diary/Active+Directory+Certificate+Services+ADCS+PKI+domain+admin+vulnerability/27668/</a><br/>
XCSSET Mac Malware Target Google Chrome / Telegram<br/>
 <a href="https://thehackernews.com/2021/07/nasty-macos-malware-xcsset-now-targets.html">https://thehackernews.com/2021/07/nasty-macos-malware-xcsset-now-targets.html</a><br/>
Defunct Video Hosting Site Flooding Normal Websites With Porn<br/>
 <a href="https://www.vice.com/en/article/qj8xz3/a-defunct-video-hosting-site-is-flooding-normal-websites-with-hardcore-porn">https://www.vice.com/en/article/qj8xz3/a-defunct-video-hosting-site-is-flooding-normal-websites-with-hardcore-porn</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7600" type="text/plain" language="en" />
<itunes:keywords>petitpotam, adcs, domain, certificate, ntlm, ntlm relay, xccset, xcode, vidme, adult, porn, video, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 23rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7598</itunes:episode>
<itunes:subtitle>Akamai Outage; "Summer of SAM" Continues; Oracle CPU; Jira Vulnerability; Kaminsky DNS Flaw Still a Problem
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Akamai Outage; "Summer of SAM" Continues; Oracle CPU; Jira Vulnerability; Kaminsky DNS Flaw Still a Problem
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7598.mp3" length="5741498" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7598.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7598</link>
<pubDate>Fri, 23 Jul 2021 02:10:02 GMT</pubDate>
<description><![CDATA[Akamai Outage<br/>
 <a href="https://isc.sans.edu/forums/diary/Lost+in+the+Cloud+Akamai+DNS+Outage/27660/">https://isc.sans.edu/forums/diary/Lost+in+the+Cloud+Akamai+DNS+Outage/27660/</a><br/>
"Summer of SAM" Continues<br/>
 <a href="https://isc.sans.edu/forums/diary/Summer+of+SAM+Microsoft+Releases+Guidance+for+CVE202136934/27656/">https://isc.sans.edu/forums/diary/Summer+of+SAM+Microsoft+Releases+Guidance+for+CVE202136934/27656/</a><br/>
Oracle Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpujul2021.html">https://www.oracle.com/security-alerts/cpujul2021.html</a><br/>
Kaseya Decryptor Available<br/>
 <a href="https://www.kaseya.com/potential-attack-on-kaseya-vsa/">https://www.kaseya.com/potential-attack-on-kaseya-vsa/</a><br/>
Jira Data Center and Jira Service Management Data Center Security Advisory<br/>
 <a href="https://confluence.atlassian.com/adminjiraserver/jira-data-center-and-jira-service-management-data-center-security-advisory-2021-07-21-1063571388.html">https://confluence.atlassian.com/adminjiraserver/jira-data-center-and-jira-service-management-data-center-security-advisory-2021-07-21-1063571388.html</a><br/>
Forgot password? Taking over user accounts Kaminsky style<br/>
 <a href="https://sec-consult.com/blog/detail/forgot-password-taking-over-user-accounts-kaminsky-style/">https://sec-consult.com/blog/detail/forgot-password-taking-over-user-accounts-kaminsky-style/</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7598" type="text/plain" language="en" />
<itunes:keywords>jira, kaseya, oracle, summer of sam, microsoft, windows, akamai, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7596</itunes:episode>
<itunes:subtitle>Summer of Sam Update; Apple Patches; XLoader for Mac; Pulse Secure Backdoors
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Summer of Sam Update; Apple Patches; XLoader for Mac; Pulse Secure Backdoors
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7596.mp3" length="5823633" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7596.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7596</link>
<pubDate>Thu, 22 Jul 2021 02:10:02 GMT</pubDate>
<description><![CDATA[Microsoft Published Summer of SAM Guidance<br/>
 <a href="https://isc.sans.edu/forums/diary/Summer+of+SAM+Microsoft+Releases+Guidance+for+CVE202136934/27656/">https://isc.sans.edu/forums/diary/Summer+of+SAM+Microsoft+Releases+Guidance+for+CVE202136934/27656/</a><br/>
Apple Patches Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Formbook/XLoader Malware Ported to Mac<br/>
 <a href="https://research.checkpoint.com/2021/top-prevalent-malware-with-a-thousand-campaigns-migrates-to-macos/">https://research.checkpoint.com/2021/top-prevalent-malware-with-a-thousand-campaigns-migrates-to-macos/</a><br/>
Pulse Secure Backdoors<br/>
 <a href="https://us-cert.cisa.gov/ncas/current-activity/2021/07/21/malware-targeting-pulse-secure-devices">https://us-cert.cisa.gov/ncas/current-activity/2021/07/21/malware-targeting-pulse-secure-devices</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7596" type="text/plain" language="en" />
<itunes:keywords>pulse secure, formbook, xloader, apple, microsoft, summer of sam, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 21st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7594</itunes:episode>
<itunes:subtitle>Windows #summerofsam Vuln; HP Driver Vuln; Linux Priv Escalation; Fortinet Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows #summerofsam Vuln; HP Driver Vuln; Linux Priv Escalation; Fortinet Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7594.mp3" length="6187603" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7594.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7594</link>
<pubDate>Wed, 21 Jul 2021 02:05:03 GMT</pubDate>
<description><![CDATA[Windows Registry Hives Permission Problem<br/>
 <a href="https://isc.sans.edu/forums/diary/Summer+of+SAM+incorrect+permissions+on+Windows+1011+hives/27652/">https://isc.sans.edu/forums/diary/Summer+of+SAM+incorrect+permissions+on+Windows+1011+hives/27652/</a><br/>
HP Printer Drivers Allows Privilege Escalation<br/>
 <a href="https://labs.sentinelone.com/cve-2021-3438-16-years-in-hiding-millions-of-printers-worldwide-vulnerable/">https://labs.sentinelone.com/cve-2021-3438-16-years-in-hiding-millions-of-printers-worldwide-vulnerable/</a><br/>
Linux Local Privilege Escalation in Filesystem Layer<br/>
 <a href="https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909">https://blog.qualys.com/vulnerabilities-threat-research/2021/07/20/sequoia-a-local-privilege-escalation-vulnerability-in-linuxs-filesystem-layer-cve-2021-33909</a><br/>
FortiManager and FortiAnalyzer Vulnerability<br/>
 <a href="https://www.fortiguard.com/psirt/FG-IR-21-067">https://www.fortiguard.com/psirt/FG-IR-21-067</a><br/>
]]></description>
<itunes:duration>7:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7594" type="text/plain" language="en" />
<itunes:keywords>fortimanager, fortianalyzer, linux, privilege escalation, filesystem, hp, printer, drivers, sam, summerofsam, registry, hives, permissions, windows, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 20th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7592</itunes:episode>
<itunes:subtitle>Print Nightmare Cont.; Apple Updates; iOS Format String RCE; Surfside Condo Scams
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Print Nightmare Cont.; Apple Updates; iOS Format String RCE; Surfside Condo Scams
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7592.mp3" length="5120081" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7592.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7592</link>
<pubDate>Tue, 20 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[New Windows Print Spooler Vulnerability - CVE-2021-34481<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Windows+Print+Spooler+Vulnerability+CVE202134481/27648/">https://isc.sans.edu/forums/diary/New+Windows+Print+Spooler+Vulnerability+CVE202134481/27648/</a><br/>
iOS/WatchOS/tvOS/Safari Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
iOS Format String Vulnerability Exploitable as RCE<br/>
 <a href="https://blog.zecops.com/research/meet-wifidemon-ios-wifi-rce-0-day-vulnerability-and-a-zero-click-vulnerability-that-was-silently-patched/">https://blog.zecops.com/research/meet-wifidemon-ios-wifi-rce-0-day-vulnerability-and-a-zero-click-vulnerability-that-was-silently-patched/</a><br/>
Surfside Condo Collapse Scams<br/>
 <a href="https://threatpost.com/attackers-target-florida-condo-collapse-victims/167917/">https://threatpost.com/attackers-target-florida-condo-collapse-victims/167917/</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7592" type="text/plain" language="en" />
<itunes:keywords>surfside, condo, collapse, scams, identity theft, ios, RCE, format string, apple, updates, windows, print spooler, print nightmare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7590</itunes:episode>
<itunes:subtitle>BaseXX Obfuscation; Juniper Radius Issue; NSO Group Leak; Password Autofill Dangers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BaseXX Obfuscation; Juniper Radius Issue; NSO Group Leak; Password Autofill Dangers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7590.mp3" length="5503301" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7590.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7590</link>
<pubDate>Mon, 19 Jul 2021 02:10:02 GMT</pubDate>
<description><![CDATA[Multiple BaseXX Obfuscations<br/>
 <a href="https://isc.sans.edu/forums/diary/Multiple+BaseXX+Obfuscations/27640/">https://isc.sans.edu/forums/diary/Multiple+BaseXX+Obfuscations/27640/</a><br/>
Juniper Patches: Radius Vulnerability<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11180&cat=SIRT_1&actp=LIST">https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11180&cat=SIRT_1&actp=LIST</a><br/>
fail2ban vulnerability<br/>
 <a href="https://github.com/fail2ban/fail2ban/security/advisories/GHSA-m985-3f3v-cwmm">https://github.com/fail2ban/fail2ban/security/advisories/GHSA-m985-3f3v-cwmm</a><br/>
NSO Group Victims Leaked<br/>
 <a href="https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/">https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/</a><br/>
Dangers of Autofilling Passwords<br/>
 <a href="https://marektoth.com/blog/password-managers-autofill/#analysis">https://marektoth.com/blog/password-managers-autofill/#analysis</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7590" type="text/plain" language="en" />
<itunes:keywords>autofilling, passwords, nso, nso group, pegasus, fail2ban, whois, juniper, basexx, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7588</itunes:episode>
<itunes:subtitle>USPS Phish; Sonicwall Ransomware; WooCommerce SQL Injection; KiwiSDR Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
USPS Phish; Sonicwall Ransomware; WooCommerce SQL Injection; KiwiSDR Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7588.mp3" length="5320556" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7588.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7588</link>
<pubDate>Fri, 16 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[USPS Phishing Kit Reporting Data Back Via Telegram<br/>
 <a href="https://isc.sans.edu/forums/diary/USPS+Phishing+Using+Telegram+to+Collect+Data/27630/">https://isc.sans.edu/forums/diary/USPS+Phishing+Using+Telegram+to+Collect+Data/27630/</a><br/>
Sonicwall Warns of Ransomware<br/>
 <a href="https://www.sonicwall.com/support/product-notification/urgent-security-notice-critical-risk-to-unpatched-end-of-life-sra-sma-8-x-remote-access-devices/210713105333210/">https://www.sonicwall.com/support/product-notification/urgent-security-notice-critical-risk-to-unpatched-end-of-life-sra-sma-8-x-remote-access-devices/210713105333210/</a><br/>
WooCommerce Flaw Exploited<br/>
 <a href="https://www.wordfence.com/blog/2021/07/critical-sql-injection-vulnerability-patched-in-woocommerce/">https://www.wordfence.com/blog/2021/07/critical-sql-injection-vulnerability-patched-in-woocommerce/</a><br/>
KiwiSDR Backdoor<br/>
 <a href="https://www.bleepingcomputer.com/news/security/software-maker-removes-backdoor-giving-root-access-to-radio-devices/">https://www.bleepingcomputer.com/news/security/software-maker-removes-backdoor-giving-root-access-to-radio-devices/</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7588" type="text/plain" language="en" />
<itunes:keywords>kiwisdr, backdoor, woocommercer, wordpress, sonicwall, usps, phishing, telegram, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7586</itunes:episode>
<itunes:subtitle>Malspam Fail; Firefox and SAP updates; Joker Android Malware; less.js vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malspam Fail; Firefox and SAP updates; Joker Android Malware; less.js vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7586.mp3" length="5042297" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7586.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7586</link>
<pubDate>Thu, 15 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[One way to fail at malspam - give reipients the wrong password<br/>
 <a href="https://isc.sans.edu/forums/diary/One+way+to+fail+at+malspam+give+recipients+the+wrong+password+for+an+encrypted+attachment/27634/">https://isc.sans.edu/forums/diary/One+way+to+fail+at+malspam+give+recipients+the+wrong+password+for+an+encrypted+attachment/27634/</a><br/>
Firefox Updates<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2021-28/">https://www.mozilla.org/en-US/security/advisories/mfsa2021-28/</a><br/>
SAP Netweaver Vulnerabilities<br/>
 <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506">https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=580617506</a><br/>
Joker Android Fleezware<br/>
 <a href="https://blog.zimperium.com/joker-is-still-no-laughing-matter/">https://blog.zimperium.com/joker-is-still-no-laughing-matter/</a><br/>
less.js RCE<br/>
 <a href="https://www.softwaresecured.com/exploiting-less-js">https://www.softwaresecured.com/exploiting-less-js</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7586" type="text/plain" language="en" />
<itunes:keywords>rce, less.js, joker, android, sap, netweaver, firefox, malspam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 14th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7584</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; ForgeRock OpenAM Exploited; GMAIL adds BIMI
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; ForgeRock OpenAM Exploited; GMAIL adds BIMI
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7584.mp3" length="5801736" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7584.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7584</link>
<pubDate>Wed, 14 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+July+2021+Patch+Tuesday/27628/">https://isc.sans.edu/forums/diary/Microsoft+July+2021+Patch+Tuesday/27628/</a><br/>
Adobe Patch Tuesday<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb21-51.html">https://helpx.adobe.com/security/products/acrobat/apsb21-51.html</a><br/>
ForgeRock OpenAM Vulnerability<br/>
 <a href="https://backstage.forgerock.com/knowledge/kb/article/a47894244">https://backstage.forgerock.com/knowledge/kb/article/a47894244</a><br/>
GMail Supporting BIMI<br/>
 <a href="https://cloud.google.com/blog/products/identity-security/bringing-bimi-to-gmail-in-google-workspace">https://cloud.google.com/blog/products/identity-security/bringing-bimi-to-gmail-in-google-workspace</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7584" type="text/plain" language="en" />
<itunes:keywords>bimi, gmail, forgerock, openam, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 13th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7582</itunes:episode>
<itunes:subtitle>Kaseya Patch; Solarwinds Advisory; Mint Mobile Breach; Twitter Verified Account Mistake
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kaseya Patch; Solarwinds Advisory; Mint Mobile Breach; Twitter Verified Account Mistake
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7582.mp3" length="5410605" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7582.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7582</link>
<pubDate>Tue, 13 Jul 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Kaseya Releases Patch and Hardening Guide<br/>
 <a href="https://helpdesk.kaseya.com/hc/en-gb/articles/4403760102417">https://helpdesk.kaseya.com/hc/en-gb/articles/4403760102417</a><br/>
Solarwinds Advisory CVE-2021-35211<br/>
 <a href="https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211">https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211</a><br/>
Mint Mobile Breach and Porting<br/>
 <a href="https://www.bleepingcomputer.com/news/security/mint-mobile-hit-by-a-data-breach-after-numbers-ported-data-accessed/">https://www.bleepingcomputer.com/news/security/mint-mobile-hit-by-a-data-breach-after-numbers-ported-data-accessed/</a><br/>
Twitter Verified Account Mistake<br/>
 <a href="https://twitter.com/conspirator0/status/1414475519609999366">https://twitter.com/conspirator0/status/1414475519609999366</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7582" type="text/plain" language="en" />
<itunes:keywords>kaseya, solarwindws, mint mobile, serv-u, twitter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7580</itunes:episode>
<itunes:subtitle>SSTP Scans; Hancitor XLL Files; Android Updates; Cisco Updates; Job Seekers Targeted
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SSTP Scans; Hancitor XLL Files; Android Updates; Cisco Updates; Job Seekers Targeted
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7580.mp3" length="5020289" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7580.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7580</link>
<pubDate>Mon, 12 Jul 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Scanning for Microsoft Secure Socket Tunneling Protocol<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+for+Microsoft+Secure+Socket+Tunneling+Protocol/27622/">https://isc.sans.edu/forums/diary/Scanning+for+Microsoft+Secure+Socket+Tunneling+Protocol/27622/</a><br/>
Hancitor tries XLL as Initial Malware File<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+tries+XLL+as+initial+malware+file/27618/">https://isc.sans.edu/forums/diary/Hancitor+tries+XLL+as+initial+malware+file/27618/</a><br/>
Android Updates<br/>
 <a href="https://source.android.com/security/bulletin/2021-07-01">https://source.android.com/security/bulletin/2021-07-01</a><br/>
Cisco Updates<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bpa-priv-esc-dgubwbH4">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bpa-priv-esc-dgubwbH4</a><br/>
Job Seekers Attacked with Malicious Documents<br/>
 <a href="https://www.ehackingnews.com/2021/07/job-seeking-engineers-have-become.html">https://www.ehackingnews.com/2021/07/job-seeking-engineers-have-become.html</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7580" type="text/plain" language="en" />
<itunes:keywords>microsoft, sstp, vpn, nacitor, xll, android, cisco, job seekers, lazarus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7578</itunes:episode>
<itunes:subtitle>sudo and Python; Fake Kaseya Patches; Sonicwall Exploit; WildPressure MacOS Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
sudo and Python; Fake Kaseya Patches; Sonicwall Exploit; WildPressure MacOS Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7578.mp3" length="4973635" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7578.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7578</link>
<pubDate>Fri, 09 Jul 2021 02:10:02 GMT</pubDate>
<description><![CDATA[Using Sudo With Python For More Security Controls<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Sudo+with+Python+For+More+Security+Controls/27614/">https://isc.sans.edu/forums/diary/Using+Sudo+with+Python+For+More+Security+Controls/27614/</a><br/>
Fake Kaseya Updates Include CobaltStrike Payload<br/>
 <a href="https://www.theregister.com/2021/07/07/kaseya_malware_patches_/">https://www.theregister.com/2021/07/07/kaseya_malware_patches_/</a><br/>
WildPressure macOS Trojan<br/>
 <a href="https://www.kaspersky.com/about/press-releases/2021_wildpressures-multi-platform-malware-hits-macos-in-the-middle-east">https://www.kaspersky.com/about/press-releases/2021_wildpressures-multi-platform-malware-hits-macos-in-the-middle-east</a><br/>
 <a href="https://www.patreon.com/posts/53462690">https://www.patreon.com/posts/53462690</a><br/>
iCloud Password Reset Weaknesss<br/>
 <a href="https://thezerohack.com/apple-vulnerability-bug-bounty">https://thezerohack.com/apple-vulnerability-bug-bounty</a><br/>
 <br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7578" type="text/plain" language="en" />
<itunes:keywords>icloud, password reset, wildpressure, macos, trojan, kaseya, fake, update, sudo, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7576</itunes:episode>
<itunes:subtitle>Printnightmare Update Update; GitLab Update; Vuln Nuget Packages
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Printnightmare Update Update; GitLab Update; Vuln Nuget Packages
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7576.mp3" length="5272469" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7576.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7576</link>
<pubDate>Thu, 08 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Releases Patches for CVE-2021-34527 UPDATED<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Releases+Patches+for+CVE202134527/27610/">https://isc.sans.edu/forums/diary/Microsoft+Releases+Patches+for+CVE202134527/27610/</a><br/>
GitLab Update<br/>
 <a href="https://www.ehackingnews.com/2021/07/gitlab-fixes-several-vulnerabilities.html">https://www.ehackingnews.com/2021/07/gitlab-fixes-several-vulnerabilities.html</a><br/>
Vulnerable NuGet Packages<br/>
 <a href="https://blog.secure.software/third-party-code-comes-with-some-baggage">https://blog.secure.software/third-party-code-comes-with-some-baggage</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7576" type="text/plain" language="en" />
<itunes:keywords>nuget, gitlab, microsoft, printnightmare, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 7th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7574</itunes:episode>
<itunes:subtitle>Printnightmare Patch; Kaseya; Kaspersky Password Manager; Amazon Echo Dot Forensics
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Printnightmare Patch; Kaseya; Kaspersky Password Manager; Amazon Echo Dot Forensics
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7574.mp3" length="7501174" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7574.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7574</link>
<pubDate>Wed, 07 Jul 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Releases Printnightmare Patch<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527</a><br/>
Kaseya Update<br/>
 <a href="https://www.kaseya.com/potential-attack-on-kaseya-vsa/">https://www.kaseya.com/potential-attack-on-kaseya-vsa/</a><br/>
Kaspersky Password Manager<br/>
 <a href="https://donjon.ledger.com/kaspersky-password-manager/">https://donjon.ledger.com/kaspersky-password-manager/</a><br/>
Amazon Echo Dot After Reset Artifacts<br/>
 <a href="https://dl.acm.org/doi/pdf/10.1145/3448300.3467820">https://dl.acm.org/doi/pdf/10.1145/3448300.3467820</a><br/>
]]></description>
<itunes:duration>8:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7574" type="text/plain" language="en" />
<itunes:keywords>kaspesky, password, manager, random numbers, amazone, echo, dot, forensics, microsoft, printnightmare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 6th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7572</itunes:episode>
<itunes:subtitle>Kaseya REvil Update; Printnightmare Update; RPM Key Issues; Node.JS Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kaseya REvil Update; Printnightmare Update; RPM Key Issues; Node.JS Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7572.mp3" length="5892560" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7572.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7572</link>
<pubDate>Tue, 06 Jul 2021 02:10:03 GMT</pubDate>
<description><![CDATA[Kaseya REvil Update<br/>
 <a href="https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689">https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689</a><br/>
<a href="https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident">https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident</a><br/>
<a href="https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b">https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b</a><br/>
<a href="https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/">https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/</a><br/>
Printnightmare Update<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527</a><br/>
<a href="https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c">https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c</a><br/>
<a href="https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/">https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/</a><br/>
<a href="https://github.com/LaresLLC/CVE-2021-1675">https://github.com/LaresLLC/CVE-2021-1675</a><br/>
Expired RPM Key Problem<br/>
 <a href="https://github.com/rpm-software-management/rpm/issues/1598">https://github.com/rpm-software-management/rpm/issues/1598</a><br/>
Node.JS Update<br/>
 <a href="https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/">https://nodejs.org/en/blog/vulnerability/july-2021-security-releases/</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7572" type="text/plain" language="en" />
<itunes:keywords>node.js, revil, rpm, pgp, keys, printnightmare, kasey, ransomware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7570</itunes:episode>
<itunes:subtitle>Special Podcast: Kaseya VSA REvil Ransomware Incident
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Special Podcast: Kaseya VSA REvil Ransomware Incident
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7570.mp3" length="4709594" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7570.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7570</link>
<pubDate>Sun, 04 Jul 2021 21:32:14 GMT</pubDate>
<description><![CDATA[Kaseya VSA REvil Ransomware Incident<br/>
 <a href="https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689">https://helpdesk.kaseya.com/hc/en-gb/articles/4403440684689</a><br/>
 <a href="https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident">https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident</a><br/>
 <a href="https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b">https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b</a><br/>
 <a href="https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/">https://csirt.divd.nl/2021/07/03/Kaseya-Case-Update/</a><br/>
 <br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7570" type="text/plain" language="en" />
<itunes:keywords>Kaseya, REVIL, Ransomware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7568</itunes:episode>
<itunes:subtitle>Special Podcast: Print Spooler Vulnerability (CVE-2021-34527, CVE-2021-1675) Update/Summary #printnightmare
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Special Podcast: Print Spooler Vulnerability (CVE-2021-34527, CVE-2021-1675) Update/Summary #printnightmare
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7568.mp3" length="6782336" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7568.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7568</link>
<pubDate>Fri, 02 Jul 2021 14:10:55 GMT</pubDate>
<description><![CDATA[Print Spooler printnightmare Update<br/>
 <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527</a><br/>
 <a href="https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c">https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c</a><br/>
 <a href="https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/">https://blog.truesec.com/2021/06/30/fix-for-printnightmare-cve-2021-1675-exploit-to-keep-your-print-servers-running-while-a-patch-is-not-available/</a><br/>
 <a href="https://github.com/LaresLLC/CVE-2021-1675">https://github.com/LaresLLC/CVE-2021-1675</a><br/>
]]></description>
<itunes:duration>7:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7568" type="text/plain" language="en" />
<itunes:keywords>cve-2021-34527, CVE-2021-1675, print spooler, printnightmare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7566</itunes:episode>
<itunes:subtitle>CVE-2021-1675 Printnightmare; IE11 PDF Patch; Netgear Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2021-1675 Printnightmare; IE11 PDF Patch; Netgear Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7566.mp3" length="6146890" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7566.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7566</link>
<pubDate>Thu, 01 Jul 2021 02:00:03 GMT</pubDate>
<description><![CDATA[CVE-2021-1675 Incomplete Patch - Printnightmware<br/>
 <a href="https://isc.sans.edu/forums/diary/CVE20211675+Incomplete+Patch+and+Leaked+RCE+Exploit/27588/">https://isc.sans.edu/forums/diary/CVE20211675+Incomplete+Patch+and+Leaked+RCE+Exploit/27588/</a><br/>
Internet Explorer PDF Update<br/>
 <a href="https://support.microsoft.com/en-us/topic/june-29-2021-kb5004760-os-builds-19041-1082-19042-1082-and-19043-1082-out-of-band-9508f7a2-0713-432f-b06c-1ae6d802a2f7">https://support.microsoft.com/en-us/topic/june-29-2021-kb5004760-os-builds-19041-1082-19042-1082-and-19043-1082-out-of-band-9508f7a2-0713-432f-b06c-1ae6d802a2f7</a><br/>
NETGEAR Router Vulnerabilities (DGN-2200v1)<br/>
 <a href="https://www.microsoft.com/security/blog/2021/06/30/microsoft-finds-new-netgear-firmware-vulnerabilities-that-could-lead-to-identity-theft-and-full-system-compromise/">https://www.microsoft.com/security/blog/2021/06/30/microsoft-finds-new-netgear-firmware-vulnerabilities-that-could-lead-to-identity-theft-and-full-system-compromise/</a><br/>
]]></description>
<itunes:duration>6:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7566" type="text/plain" language="en" />
<itunes:keywords>printnightmare, print spooler, windows, cve-2021-1675, internet explorer, pdf, netgear, router, dgb-2200v1, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 30th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7564</itunes:episode>
<itunes:subtitle>Phish Without Link; June Contest Solution; WD MyBook Details; Adobe Experience Manager PoC; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phish Without Link; June Contest Solution; WD MyBook Details; Adobe Experience Manager PoC; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7564.mp3" length="5253141" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7564.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7564</link>
<pubDate>Wed, 30 Jun 2021 02:05:03 GMT</pubDate>
<description><![CDATA[Google "Sweepstake" Phish Withouth Link<br/>
 <a href="https://isc.sans.edu/forums/diary/Diving+into+a+Google+Sweepstakes+Phishing+Email/27578/">https://isc.sans.edu/forums/diary/Diving+into+a+Google+Sweepstakes+Phishing+Email/27578/</a><br/>
Forensics Contest Solution / Winner<br/>
 <a href="https://isc.sans.edu/forums/diary/June+2021+Forensic+Contest+Answers+and+Analysis/27582/">https://isc.sans.edu/forums/diary/June+2021+Forensic+Contest+Answers+and+Analysis/27582/</a><br/>
WD MyBook Details<br/>
 <a href="https://arstechnica.com/gadgets/2021/06/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices/">https://arstechnica.com/gadgets/2021/06/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices/</a><br/>
Adobe Experience Manager PoC<br/>
 <a href="https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/">https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7564" type="text/plain" language="en" />
<itunes:keywords>phishing, google, sweepstakes, forensics, wd mybook, western digital, adobe, experience manager, poc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 28th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7560</itunes:episode>
<itunes:subtitle>LDAP Scans; CD/DVD Destruction; Zyxel Exploits; Cisco Vuln; Microsoft Signed Rootkit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LDAP Scans; CD/DVD Destruction; Zyxel Exploits; Cisco Vuln; Microsoft Signed Rootkit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7560.mp3" length="5530766" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7560.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7560</link>
<pubDate>Mon, 28 Jun 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Increase in UDP Port 389 Scans (LDAP/AD)<br/>
 <a href="https://isc.sans.edu/forums/diary/Is+this+traffic+bAD/27566/">https://isc.sans.edu/forums/diary/Is+this+traffic+bAD/27566/</a><br/>
CD/DVD Destruction<br/>
 <a href="https://isc.sans.edu/forums/diary/DIY+CDDVD+Destruction/27572/">https://isc.sans.edu/forums/diary/DIY+CDDVD+Destruction/27572/</a><br/>
Zyxel Exploits<br/>
 <a href="https://twitter.com/JAMESWT_MHT/status/1407987022170578946">https://twitter.com/JAMESWT_MHT/status/1407987022170578946</a><br/>
 <a href="https://kb.zyxel.com/KB/searchArticle!viewDetail.action?articleOid=018137&lang=EN">https://kb.zyxel.com/KB/searchArticle!viewDetail.action?articleOid=018137&lang=EN</a><br/>
Cisco Vulnerability Exploited<br/>
 <a href="https://threatpost.com/cisco-asa-bug-exploited-poc/167274/">https://threatpost.com/cisco-asa-bug-exploited-poc/167274/</a><br/>
Microsoft Signs Netfilter Rootkit<br/>
 <a href="https://www.gdatasoftware.com/blog/microsoft-signed-a-malicious-netfilter-rootkit">https://www.gdatasoftware.com/blog/microsoft-signed-a-malicious-netfilter-rootkit</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7560" type="text/plain" language="en" />
<itunes:keywords>cisco, microsoft, netfilter, rootkit, signature, zyxel, cd, dvd, destruction, drill, ldap, ad, scans, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 25th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7558</itunes:episode>
<itunes:subtitle>Cookie Trading; Atlassian Vulnerabilities; Dell BIOS Connect; ATM NFC Jackpotting
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cookie Trading; Atlassian Vulnerabilities; Dell BIOS Connect; ATM NFC Jackpotting
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7558.mp3" length="5634844" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7558.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7558</link>
<pubDate>Fri, 25 Jun 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Do You Like Cookies? Some are for sale!<br/>
 <a href="https://isc.sans.edu/forums/diary/Do+you+Like+Cookies+Some+are+for+sale/27558/">https://isc.sans.edu/forums/diary/Do+you+Like+Cookies+Some+are+for+sale/27558/</a><br/>
A supply-chain breach: Taking over an Atlassian account<br/>
 <a href="https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/23175805/Atlassian-ATO-CPR-blog-FINAL.pdf">https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/23175805/Atlassian-ATO-CPR-blog-FINAL.pdf</a><br/>
Dell Bios Connect Vulnerability<br/>
 <a href="https://eclypsium.com/2021/06/24/biosdisconnect/">https://eclypsium.com/2021/06/24/biosdisconnect/</a><br/>
ATM Jackpotting via NFC<br/>
 <a href="https://www.wired.com/story/atm-hack-nfc-bugs-point-of-sale/">https://www.wired.com/story/atm-hack-nfc-bugs-point-of-sale/</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7558" type="text/plain" language="en" />
<itunes:keywords>atm, jackpotting, nfc, dell, bios, bios connect, atlassian, jira, cookies, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 24th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7556</itunes:episode>
<itunes:subtitle>DNS SaaS Vulnerabilities; Cortex XSOAR Vuln; Carbon Black Patch; EFF DMCA Statement
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS SaaS Vulnerabilities; Cortex XSOAR Vuln; Carbon Black Patch; EFF DMCA Statement
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7556.mp3" length="5748130" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7556.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7556</link>
<pubDate>Thu, 24 Jun 2021 02:00:02 GMT</pubDate>
<description><![CDATA[DNS Name Server Hijack Attack<br/>
 <a href="https://www.darkreading.com/vulnerabilities---threats/new-dns-name-server-hijack-attack-exposes-businesses-government-agencies/d/d-id/1341377">https://www.darkreading.com/vulnerabilities---threats/new-dns-name-server-hijack-attack-exposes-businesses-government-agencies/d/d-id/1341377</a><br/>
Paloalto Cortex XSOAR Vulnerablity<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2021-3044">https://security.paloaltonetworks.com/CVE-2021-3044</a><br/>
VMWare Carbon Black App Control Authentication Bypass<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0012.html?">https://www.vmware.com/security/advisories/VMSA-2021-0012.html?</a><br/>
Standing With Security Researchers Against Misuse of the DMCA<br/>
 <a href="https://www.eff.org/deeplinks/2021/06/dmca-security-researcher-statement">https://www.eff.org/deeplinks/2021/06/dmca-security-researcher-statement</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7556" type="text/plain" language="en" />
<itunes:keywords>dmca, eff, vmware, carbon black, paloalto, cortex, xsoar, dns, aws, route 53, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 23rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7554</itunes:episode>
<itunes:subtitle>Phishing Avoiding Reports; PyPi Cryptominer; dovecot TLS Fix; Incomplete Sonicwall Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing Avoiding Reports; PyPi Cryptominer; dovecot TLS Fix; Incomplete Sonicwall Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7554.mp3" length="5486974" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7554.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7554</link>
<pubDate>Wed, 23 Jun 2021 02:10:03 GMT</pubDate>
<description><![CDATA[Phishing asking recipients not to report abuse<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+asking+recipients+not+to+report+abuse/27556/">https://isc.sans.edu/forums/diary/Phishing+asking+recipients+not+to+report+abuse/27556/</a><br/>
PyPi Cryptomining Malware<br/>
 <a href="https://blog.sonatype.com/sonatype-catches-new-pypi-cryptomining-malware-via-automated-detection">https://blog.sonatype.com/sonatype-catches-new-pypi-cryptomining-malware-via-automated-detection</a><br/>
Dovecot TLS Implementation Vulnerability<br/>
 <a href="https://hackerone.com/reports/1204962">https://hackerone.com/reports/1204962</a><br/>
 (see the link to the PDF for more details)<br/>
Sonicwall Patch Incomplete<br/>
 <a href="https://www.tripwire.com/state-of-security/featured/analyzing-sonicwalls-unsuccessful-fix-for-cve-2020-5135/">https://www.tripwire.com/state-of-security/featured/analyzing-sonicwalls-unsuccessful-fix-for-cve-2020-5135/</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7554" type="text/plain" language="en" />
<itunes:keywords>sonicwall, dovecot, tls, starttls, pypi, phishing, abuse, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7552</itunes:episode>
<itunes:subtitle>Darkside Imposture; Tesla RAT Update; Tpr Browser Update; Schneider PowerLogic; AutoCAD
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Darkside Imposture; Tesla RAT Update; Tpr Browser Update; Schneider PowerLogic; AutoCAD
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7552.mp3" length="4902105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7552.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7552</link>
<pubDate>Tue, 22 Jun 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Attack and Defend: Distributed Web Applications (free Webcast)<br/>
 <a href="https://www.sans.org/webcasts/attack-defend-modern-distributed-applications-119610">https://www.sans.org/webcasts/attack-defend-modern-distributed-applications-119610</a><br/>
Darkside Impersonators<br/>
 <a href="https://www.helpnetsecurity.com/2021/06/21/impersonating-darkside/">https://www.helpnetsecurity.com/2021/06/21/impersonating-darkside/</a><br/>
Tesla RAT COVID-19 Vaccination Phish<br/>
 <a href="https://threatpost.com/agent-tesla-covid-vax-phish/167082/">https://threatpost.com/agent-tesla-covid-vax-phish/167082/</a><br/>
Tor Browser Update<br/>
 <a href="https://www.bleepingcomputer.com/news/security/tor-browser-fixes-vulnerability-that-tracks-you-using-installed-apps/">https://www.bleepingcomputer.com/news/security/tor-browser-fixes-vulnerability-that-tracks-you-using-installed-apps/</a><br/>
Schneider PowerLogic Vulnerabilities<br/>
 <a href="https://www.ehackingnews.com/2021/06/six-major-flaws-identified-in-schneider.html">https://www.ehackingnews.com/2021/06/six-major-flaws-identified-in-schneider.html</a><br/>
AutoCAD Update<br/>
 <a href="https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004">https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7552" type="text/plain" language="en" />
<itunes:keywords>autocad, schneider, powerlogic, tor, browser, darkside, tesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 21st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7550</itunes:episode>
<itunes:subtitle>Azure Network Monitoring #2; Google Open Redirects; NIST RDS Hahes; iOS Wifi Bug; NSA VoIP Security Guide
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Azure Network Monitoring #2; Google Open Redirects; NIST RDS Hahes; iOS Wifi Bug; NSA VoIP Security Guide
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7550.mp3" length="5070356" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7550.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7550</link>
<pubDate>Mon, 21 Jun 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Network Forensics on Azure VMs (Part #2)<br/>
 <a href="https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+2/27538/">https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+2/27538/</a><br/>
Google Open Redirect Being Abused<br/>
 <a href="https://isc.sans.edu/forums/diary/Open+redirects+and+why+Phishers+love+them/27542/">https://isc.sans.edu/forums/diary/Open+redirects+and+why+Phishers+love+them/27542/</a><br/>
Easy Access to the NIST RDS Database<br/>
 <a href="https://isc.sans.edu/forums/diary/Easy+Access+to+the+NIST+RDS+Database/27544/">https://isc.sans.edu/forums/diary/Easy+Access+to+the+NIST+RDS+Database/27544/</a><br/>
iOS Wifi Bug<br/>
 <a href="https://blog.chichou.me/2021/06/20/quick-analysis-wifid/">https://blog.chichou.me/2021/06/20/quick-analysis-wifid/</a><br/>
NSA VoIP Security Guide<br/>
 <a href="https://media.defense.gov/2021/Jun/17/2002744054/-1/-1/1/CTR_DEPLOYING%20SECURE%20VVOIP%20SYSTEMS.PDF">https://media.defense.gov/2021/Jun/17/2002744054/-1/-1/1/CTR_DEPLOYING%20SECURE%20VVOIP%20SYSTEMS.PDF</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7550" type="text/plain" language="en" />
<itunes:keywords>nsa, voip, ios, wifi, ssid, format string, nist, rds, dns, google, redirects, azure, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7548</itunes:episode>
<itunes:subtitle>Azure Network Monitoring; Fake Ledger; Vulnerable Defibrilators; Prolexic Outage
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Azure Network Monitoring; Fake Ledger; Vulnerable Defibrilators; Prolexic Outage
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7548.mp3" length="5187354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7548.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7548</link>
<pubDate>Fri, 18 Jun 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Network Forensics on Azure VMs<br/>
 <a href="https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+1/27536/">https://isc.sans.edu/forums/diary/Network+Forensics+on+Azure+VMs+Part+1/27536/</a><br/>
Fake Ledger Hardware Wallets<br/>
 <a href="https://www.ledger.com/phishing-campaigns-status#phishing-campaigns">https://www.ledger.com/phishing-campaigns-status#phishing-campaigns</a><br/>
 <a href="https://www.reddit.com/r/ledgerwallet/comments/o154gz/package_from_ledger_is_this_legit/">https://www.reddit.com/r/ledgerwallet/comments/o154gz/package_from_ledger_is_this_legit/</a><br/>
Zoll Defibrilator Dashboard Vulnerability<br/>
 <a href="https://us-cert.cisa.gov/ics/advisories/icsma-21-161-01">https://us-cert.cisa.gov/ics/advisories/icsma-21-161-01</a><br/>
Akamai Prolexic Outage<br/>
 <a href="https://threatpost.com/hiccup-akamais-ddos-outages/167004/">https://threatpost.com/hiccup-akamais-ddos-outages/167004/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7548" type="text/plain" language="en" />
<itunes:keywords>akamai, prolexic, zoll, defibrilator, ledger, cryptocoin, azure, network forensics, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 17th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7546</itunes:episode>
<itunes:subtitle>June Forensic Quiz; ThroughTek IP Camera Vuln; Peleton Vuln; MSFT Defender Detecting Jailbreak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
June Forensic Quiz; ThroughTek IP Camera Vuln; Peleton Vuln; MSFT Defender Detecting Jailbreak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7546.mp3" length="4868593" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7546.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7546</link>
<pubDate>Thu, 17 Jun 2021 02:10:03 GMT</pubDate>
<description><![CDATA[June 2021 Forensic Quiz<br/>
 <a href="https://isc.sans.edu/forums/diary/June+2021+Forensic+Contest/27532/">https://isc.sans.edu/forums/diary/June+2021+Forensic+Contest/27532/</a><br/>
ThroughTek IP Camera SDK Vulnerability<br/>
 <a href="https://www.nozominetworks.com/blog/new-iot-security-risk-throughtek-p2p-supply-chain-vulnerability/">https://www.nozominetworks.com/blog/new-iot-security-risk-throughtek-p2p-supply-chain-vulnerability/</a><br/>
Peleoton Insecure Boot Vulnerability<br/>
 <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/a-new-program-for-your-peloton-whether-you-like-it-or-not/">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/a-new-program-for-your-peloton-whether-you-like-it-or-not/</a><br/>
Microsoft Defender for Endpoint Detecting Jailbroken Devices<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-new-capabilities-on-android-and-ios/ba-p/2442730">https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-new-capabilities-on-android-and-ios/ba-p/2442730</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7546" type="text/plain" language="en" />
<itunes:keywords>microsoft, defender, endpoint, ios, jailbreak, android, peleton, boot, forensic, quiz, throughtek, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7544</itunes:episode>
<itunes:subtitle>Newish Mirai going after Sonicall/DLink/Cisco; MSFT Teams Bug; Google Open Sources Homomorphic Encryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Newish Mirai going after Sonicall/DLink/Cisco; MSFT Teams Bug; Google Open Sources Homomorphic Encryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7544.mp3" length="5435410" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7544.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7544</link>
<pubDate>Wed, 16 Jun 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Multi Perimeter Device Exploit Mirai Version Hunting For Sonicwall, DLink, Cisco and more<br/>
 <a href="https://isc.sans.edu/forums/diary/Multi+Perimeter+Device+Exploit+Mirai+Version+Hunting+For+Sonicwall+DLink+Cisco+and+more/27528/">https://isc.sans.edu/forums/diary/Multi+Perimeter+Device+Exploit+Mirai+Version+Hunting+For+Sonicwall+DLink+Cisco+and+more/27528/</a><br/>
Google Open Sourcing Homomorphic Encrypion Libraries<br/>
 <a href="https://developers.googleblog.com/2021/06/our-latest-updates-on-fully-homomorphic-encryption.html">https://developers.googleblog.com/2021/06/our-latest-updates-on-fully-homomorphic-encryption.html</a><br/>
Stealing Tokens, emails, files and more in Microsoft Teams<br/>
 <a href="https://medium.com/tenable-techblog/stealing-tokens-emails-files-and-more-in-microsoft-teams-through-malicious-tabs-a7e5ff07b138">https://medium.com/tenable-techblog/stealing-tokens-emails-files-and-more-in-microsoft-teams-through-malicious-tabs-a7e5ff07b138</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7544" type="text/plain" language="en" />
<itunes:keywords>tokens, emails, files, teams, google, homomorphic encryption, mirai, sonicwall, dlink, cisco, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7542</itunes:episode>
<itunes:subtitle>Apple iOS 12.5.4; NIST.gov DNS issues; Akkadian Bugs; Exchange Online MFA Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple iOS 12.5.4; NIST.gov DNS issues; Akkadian Bugs; Exchange Online MFA Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7542.mp3" length="5047731" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7542.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7542</link>
<pubDate>Tue, 15 Jun 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Apple iOS 12.5.4 Security Update<br/>
 <a href="https://support.apple.com/en-us/HT212548">https://support.apple.com/en-us/HT212548</a><br/>
NIST.gov DNS Issues<br/>
 <a href="https://puck.nether.net/pipermail/outages/2021-June/013670.html">https://puck.nether.net/pipermail/outages/2021-June/013670.html</a><br/>
Akkadian Provisioning Manager Multiple Vulnerabilities<br/>
 <a href="https://www.rapid7.com/blog/post/2021/06/08/akkadian-provisioning-manager-multiple-vulnerabilities-disclosure/">https://www.rapid7.com/blog/post/2021/06/08/akkadian-provisioning-manager-multiple-vulnerabilities-disclosure/</a><br/>
Bypassing MFA in Exchange Online<br/>
 <a href="https://www.microsoft.com/security/blog/2021/06/14/behind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure/">https://www.microsoft.com/security/blog/2021/06/14/behind-the-scenes-of-business-email-compromise-using-cross-domain-threat-data-to-disrupt-a-large-bec-infrastructure/</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7542" type="text/plain" language="en" />
<itunes:keywords>nist, ntp, nist.gov, apple ios, mfa, exchange online, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 14th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7540</itunes:episode>
<itunes:subtitle>EoL SonicWall Exploited; Fortinet Still Targeted; PrivacyMic; Linux polkit Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
EoL SonicWall Exploited; Fortinet Still Targeted; PrivacyMic; Linux polkit Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7540.mp3" length="5790060" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7540.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7540</link>
<pubDate>Mon, 14 Jun 2021 02:05:02 GMT</pubDate>
<description><![CDATA[EoL SonicWall SRA 4600 VPN Gateways Exploited in Current Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Sonicwall+SRA+4600+Targeted+By+an+Old+Vulnerability/27518/">https://isc.sans.edu/forums/diary/Sonicwall+SRA+4600+Targeted+By+an+Old+Vulnerability/27518/</a><br/>
Older Fortinet Vulnerability Still Exploited<br/>
 <a href="https://isc.sans.edu/forums/diary/Fortinet+Targeted+for+Unpatched+SSL+VPN+Discovery+Activity/27520/">https://isc.sans.edu/forums/diary/Fortinet+Targeted+for+Unpatched+SSL+VPN+Discovery+Activity/27520/</a><br/>
PrivacyMic: Utlizing Inaudible Frequencies for Privacy Preserving Daily Activity Recognition<br/>
 <a href="http://alansonsample.com/publications/docs/2021%20-%20CHI%20-%20PrivacyMic-%20Utilizing%20Inaudible%20Frequencies%20for%20Privacy%20Preserving%20Daily%20Activity%20Recognition.pdf">http://alansonsample.com/publications/docs/2021%20-%20CHI%20-%20PrivacyMic-%20Utilizing%20Inaudible%20Frequencies%20for%20Privacy%20Preserving%20Daily%20Activity%20Recognition.pdf</a><br/>
Linux Vulnerability in polkit<br/>
 <a href="https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/">https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7540" type="text/plain" language="en" />
<itunes:keywords>linux, polkit, privacymic, fortinet, sonicwall, sra 4600, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7538</itunes:episode>
<itunes:subtitle>Cookie Banners Don't Work; Citrix Patch; XSS via VoIP; Message Broker DoS Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cookie Banners Don't Work; Citrix Patch; XSS via VoIP; Message Broker DoS Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7538.mp3" length="5892217" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7538.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7538</link>
<pubDate>Fri, 11 Jun 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Are Cookie Banners a Waste of Time or a Complete Waste of Time?<br/>
 <a href="https://isc.sans.edu/forums/diary/Are+Cookie+Banners+a+Waste+of+Time+or+a+Complete+Waste+of+Time/27436/">https://isc.sans.edu/forums/diary/Are+Cookie+Banners+a+Waste+of+Time+or+a+Complete+Waste+of+Time/27436/</a><br/>
Citrix Application Delivery Controller Vulnerability<br/>
 <a href="https://support.citrix.com/article/CTX297155">https://support.citrix.com/article/CTX297155</a><br/>
VoIP Monitor GUI XSS<br/>
 <a href="https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/">https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/</a><br/>
Denial of Service Vulnerabilitiesin RabbitMQ, EMQ X,and VeneMQ<br/>
 <a href="https://www.synopsys.com/blogs/software-security/cyrc-advisory-rabbitmq-emqx-vernemq/">https://www.synopsys.com/blogs/software-security/cyrc-advisory-rabbitmq-emqx-vernemq/</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7538" type="text/plain" language="en" />
<itunes:keywords>mq, mqtt, doc, rabbitmq, emq x, venemq, voip, xss, citrix, cookies, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 10th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7536</itunes:episode>
<itunes:subtitle>AV vs. Compilers; TLS App Layer Attack; Google Chrome Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AV vs. Compilers; TLS App Layer Attack; Google Chrome Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7536.mp3" length="5131841" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7536.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7536</link>
<pubDate>Thu, 10 Jun 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Architecture, Compilers and Black Magic<br/>
 <a href="https://isc.sans.edu/forums/diary/Architecture+compilers+and+black+magic+or+what+else+affects+the+ability+of+AVs+to+detect+malicious+files/27510/">https://isc.sans.edu/forums/diary/Architecture+compilers+and+black+magic+or+what+else+affects+the+ability+of+AVs+to+detect+malicious+files/27510/</a><br/>
ALPACA TLS Attack<br/>
 <a href="https://alpaca-attack.com/ALPACA.pdf">https://alpaca-attack.com/ALPACA.pdf</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop.html</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7536" type="text/plain" language="en" />
<itunes:keywords>google chorme, alpaca, anti virus, compilers, tls, application layer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7534</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; PuzzleMaker Chrome Exploit; Intel Patches; Adobe Updates; CentOS 7 and Letsencrypt
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; PuzzleMaker Chrome Exploit; Intel Patches; Adobe Updates; CentOS 7 and Letsencrypt
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7534.mp3" length="5940146" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7534.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7534</link>
<pubDate>Wed, 09 Jun 2021 02:10:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+June+2021+Patch+Tuesday/27506/">https://isc.sans.edu/forums/diary/Microsoft+June+2021+Patch+Tuesday/27506/</a><br/>
PuzzleMaker Attacks With Chrome Zero-Day Exploit Chain<br/>
 <a href="https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/">https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/</a><br/>
Intel Patches<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/default.html">https://www.intel.com/content/www/us/en/security-center/default.html</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Let's Encrypt and CentOS 7<br/>
 <a href="https://blog.devgenius.io/lets-encrypt-change-affects-openssl-1-0-x-and-centos-7-49bd66016af3">https://blog.devgenius.io/lets-encrypt-change-affects-openssl-1-0-x-and-centos-7-49bd66016af3</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7534" type="text/plain" language="en" />
<itunes:keywords>lets encrypt, centos 7, adobe, intel, patches, puzlemaker, microsoft, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7532</itunes:episode>
<itunes:subtitle>Amazon Sidewalk Going Live; Windows Container Malware; Colonial Pipeline Ransom Recovered
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Amazon Sidewalk Going Live; Windows Container Malware; Colonial Pipeline Ransom Recovered
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7532.mp3" length="5289812" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7532.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7532</link>
<pubDate>Tue, 08 Jun 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Amazon Sidewalk<br/>
 <a href="https://isc.sans.edu/forums/diary/Amazon+Sidewalk+Cutting+Through+the+Hype/27502/">https://isc.sans.edu/forums/diary/Amazon+Sidewalk+Cutting+Through+the+Hype/27502/</a><br/>
Windows Container Malware<br/>
 <a href="https://unit42.paloaltonetworks.com/siloscape/">https://unit42.paloaltonetworks.com/siloscape/</a><br/>
Darkside Ransom Confiscated<br/>
 <a href="https://www.documentcloud.org/documents/20799023-affidavit-1-in-application-by-the-united-states-for-a-seizure-warrant-for-one-account-for-investigation-of-18-usc-ss-981a1a-and-other-offenses-nd-cal-321-mj-70945">https://www.documentcloud.org/documents/20799023-affidavit-1-in-application-by-the-united-states-for-a-seizure-warrant-for-one-account-for-investigation-of-18-usc-ss-981a1a-and-other-offenses-nd-cal-321-mj-70945</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7532" type="text/plain" language="en" />
<itunes:keywords>darkside, windows, containers, malware, escape, amazon, sidewalk, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 7th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7530</itunes:episode>
<itunes:subtitle>Port 37; QNAP Patch; GitHub Patches Policy; WebEx Patch; VMWare Exploit Active
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Port 37; QNAP Patch; GitHub Patches Policy; WebEx Patch; VMWare Exploit Active
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7530.mp3" length="4472095" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7530.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7530</link>
<pubDate>Mon, 07 Jun 2021 02:05:03 GMT</pubDate>
<description><![CDATA[Strange Goings on With Port 37<br/>
 <a href="https://isc.sans.edu/forums/diary/Strange+goings+on+with+port+37/27496/">https://isc.sans.edu/forums/diary/Strange+goings+on+with+port+37/27496/</a><br/>
QNAP Video Station RCE Vulnerability<br/>
 <a href="https://www.qnap.com/de-de/security-advisory/qsa-21-21">https://www.qnap.com/de-de/security-advisory/qsa-21-21</a><br/>
Updated GitHub Policy<br/>
 <a href="https://github.blog/2021-06-04-updates-to-our-policies-regarding-exploits-malware-and-vulnerability-research/">https://github.blog/2021-06-04-updates-to-our-policies-regarding-exploits-malware-and-vulnerability-research/</a><br/>
Cisco WebEx Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-player-kOf8zVT">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-player-kOf8zVT</a><br/>
VMWare vCenter Server Vulnerability Actively Exploited<br/>
 <a href="https://thehackernews.com/2021/06/alert-critical-rce-bug-in-vmware.html">https://thehackernews.com/2021/06/alert-critical-rce-bug-in-vmware.html</a><br/>
]]></description>
<itunes:duration>4:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7530" type="text/plain" language="en" />
<itunes:keywords>vmware, vcenter, exploit, cisco, webex, github, qnap, rce, video station, port 37, ethereum, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 4th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7528</itunes:episode>
<itunes:subtitle>Zoom CIS Benchmark @boeke; BIG-IP Vuln; WE.LOCK Vuln; 2xWordpress Plugin Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zoom CIS Benchmark @boeke; BIG-IP Vuln; WE.LOCK Vuln; 2xWordpress Plugin Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7528.mp3" length="5364865" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7528.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7528</link>
<pubDate>Fri, 04 Jun 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Script to Test CIS Zoom Benchmark <br/>
 <a href="https://github.com/turbot/steampipe-mod-zoom-compliance">https://github.com/turbot/steampipe-mod-zoom-compliance</a><br/>
F5 BIG-IP Edge Client for Windows Vulnerability <br/>
 <a href="https://support.f5.com/csp/article/K20346072">https://support.f5.com/csp/article/K20346072</a><br/>
Fancy Product Designer Wordpress Plugin Vulnerability<br/>
 <a href="https://www.welivesecurity.com/2021/06/03/zero-day-popular-wordpress-plugin-exploited-take-over-websites/">https://www.welivesecurity.com/2021/06/03/zero-day-popular-wordpress-plugin-exploited-take-over-websites/</a><br/>
WordPress Pushes Jetpack Plugin Patch <br/>
 <a href="https://www.bleepingcomputer.com/news/security/wordpress-force-installs-jetpack-security-update-on-5-million-sites/">https://www.bleepingcomputer.com/news/security/wordpress-force-installs-jetpack-security-update-on-5-million-sites/</a><br/>
We.Lock Vulnerability<br/>
 <a href="https://github.com/CriticalSecurity/welock">https://github.com/CriticalSecurity/welock</a>]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7528" type="text/plain" language="en" />
<itunes:keywords>wordpress, jetpack, fancy product designer, plugin, f5, big-ip, edge client, cis, zoom, benchmark, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7526</itunes:episode>
<itunes:subtitle>Realtek WPA2 Vuln; Huawei LTE Vuln; NortonLifeLock Crypto; OpenPGP RNP Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Realtek WPA2 Vuln; Huawei LTE Vuln; NortonLifeLock Crypto; OpenPGP RNP Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7526.mp3" length="4903364" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7526.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7526</link>
<pubDate>Thu, 03 Jun 2021 02:10:02 GMT</pubDate>
<description><![CDATA[Realtek RTL8170C Vulnerabilities<br/>
 <a href="https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day">https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day</a><br/>
Huawei LTE USB Stick E3372 Vulnerablity<br/>
 <a href="https://www.theregister.com/2021/06/02/huawei_lte_usb_stick_vulnerability/">https://www.theregister.com/2021/06/02/huawei_lte_usb_stick_vulnerability/</a><br/>
NortonLifeLock Crypto<br/>
 <a href="https://investor.nortonlifelock.com/About/Investors/press-releases/press-release-details/2021/NortonLifeLock-Unveils-Norton-Crypto/default.aspx">https://investor.nortonlifelock.com/About/Investors/press-releases/press-release-details/2021/NortonLifeLock-Unveils-Norton-Crypto/default.aspx</a><br/>
OpenPGP RNP Patch<br/>
 <a href="https://www.rnpgp.org/advisories/ri-2021-001/">https://www.rnpgp.org/advisories/ri-2021-001/</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7526" type="text/plain" language="en" />
<itunes:keywords>openpgp, nortonlifelock, crypt miner, norton, symantec, huawei, realtek, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7524</itunes:episode>
<itunes:subtitle>LOLBAS with finger.exe; Bypassing Ransomware Protections; Firefox Patches; Edge https by default coming
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LOLBAS with finger.exe; Bypassing Ransomware Protections; Firefox Patches; Edge https by default coming
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7524.mp3" length="5512750" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7524.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7524</link>
<pubDate>Wed, 02 Jun 2021 02:10:02 GMT</pubDate>
<description><![CDATA[Guildma is now using Finger and Signed Binary Proxy Execution to Evade Defenses<br/>
 <a href="https://isc.sans.edu/forums/diary/Guildma+is+now+using+Finger+and+Signed+Binary+Proxy+Execution+to+evade+defenses/27482/">https://isc.sans.edu/forums/diary/Guildma+is+now+using+Finger+and+Signed+Binary+Proxy+Execution+to+evade+defenses/27482/</a><br/>
Bypassing Protected Folders Protections<br/>
 <a href="https://dl.acm.org/doi/10.1145/3431286">https://dl.acm.org/doi/10.1145/3431286</a><br/>
Firefox 89 Released<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/">https://www.mozilla.org/en-US/security/advisories/mfsa2021-23/</a><br/>
Microsoft Edge Will make https default<br/>
 <a href="https://blogs.windows.com/msedgedev/2021/06/01/available-for-preview-automatic-https-helps-keep-your-browsing-more-secure/">https://blogs.windows.com/msedgedev/2021/06/01/available-for-preview-automatic-https-helps-keep-your-browsing-more-secure/</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7524" type="text/plain" language="en" />
<itunes:keywords>microsoft edge, firefox, edge, protected folders, ransomware, guildma, finger, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7522</itunes:episode>
<itunes:subtitle>Malicious PS Hosted by Google; SonicWall Advisory; HPE Advisory; Siemens PLC memory protection bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious PS Hosted by Google; SonicWall Advisory; HPE Advisory; Siemens PLC memory protection bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7522.mp3" length="4491916" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7522.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7522</link>
<pubDate>Tue, 01 Jun 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious PowerShell Hosted on script.google.com<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+PowerShell+Hosted+on+scriptgooglecom/27468/">https://isc.sans.edu/forums/diary/Malicious+PowerShell+Hosted+on+scriptgooglecom/27468/</a><br/>
Sonicwall Advisory<br/>
 <a href="https://www.sonicwall.com/support/product-notification/security-advisory-on-prem-sonicwall-network-security-manager-nsm-command-injection-vulnerability/210525121534120/">https://www.sonicwall.com/support/product-notification/security-advisory-on-prem-sonicwall-network-security-manager-nsm-command-injection-vulnerability/210525121534120/</a><br/>
Hewlett Packard Enterprise Systems Insight Manger (SIM) Advisory<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us</a><br/>
Memory Protection Bypass in Siemens PLCs<br/>
 <a href="https://claroty.com/2021/05/28/blog-research-race-to-native-code-execution-in-plcs/">https://claroty.com/2021/05/28/blog-research-race-to-native-code-execution-in-plcs/</a><br/>
]]></description>
<itunes:duration>4:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7522" type="text/plain" language="en" />
<itunes:keywords>plc, siemens, hp, advisory, vulenrability, sonicwall, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 28th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7520</itunes:episode>
<itunes:subtitle>64 Bit AV Evasion; Unpatched MacOS/iOS Vuln; VSCode Extension Vuln; M1RACLES
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
64 Bit AV Evasion; Unpatched MacOS/iOS Vuln; VSCode Extension Vuln; M1RACLES
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7520.mp3" length="6162788" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7520.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7520</link>
<pubDate>Fri, 28 May 2021 02:00:03 GMT</pubDate>
<description><![CDATA[AV evasion with 64-bit Executables<br/>
 <a href="https://isc.sans.edu/forums/diary/All+your+Base+arenearly+equal+when+it+comes+to+AV+evasion+but+64bit+executables+are+not/27466/">https://isc.sans.edu/forums/diary/All+your+Base+arenearly+equal+when+it+comes+to+AV+evasion+but+64bit+executables+are+not/27466/</a><br/>
Unpatches WebKit Vulnerablity in iOS/macOS<br/>
 <a href="https://blog.theori.io/research/webkit-type-confusion/">https://blog.theori.io/research/webkit-type-confusion/</a><br/>
VSCode Extension Vulnerabilities <br/>
 <a href="https://snyk.io/blog/visual-studio-code-extension-security-vulnerabilities-deep-dive/">https://snyk.io/blog/visual-studio-code-extension-security-vulnerabilities-deep-dive/</a><br/>
M1RACLES<br/>
 <a href="https://m1racles.com">https://m1racles.com</a><br/>
]]></description>
<itunes:duration>6:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7520" type="text/plain" language="en" />
<itunes:keywords>m1, m1racles, miracles, vscode, extensions, webkit, ios, macos, evasion, 64-bit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 27th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7518</itunes:episode>
<itunes:subtitle>Bluetooth Vulnerabilities Trends; Google Chrom Update; PDF Certification Attacks; nginx Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bluetooth Vulnerabilities Trends; Google Chrom Update; PDF Certification Attacks; nginx Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7518.mp3" length="5303649" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7518.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7518</link>
<pubDate>Thu, 27 May 2021 02:00:02 GMT</pubDate>
<description><![CDATA[A Survey of Bluetooth Vulnerabilities<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Survey+of+Bluetooth+Vulnerabilities+Trends/27460/">https://isc.sans.edu/forums/diary/A+Survey+of+Bluetooth+Vulnerabilities+Trends/27460/</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2021/05/stable-channel-update-for-desktop_25.html">https://chromereleases.googleblog.com/2021/05/stable-channel-update-for-desktop_25.html</a><br/>
 <br/>
Attacks on PDF Certification<br/>
 <a href="https://www.pdf-insecurity.org">https://www.pdf-insecurity.org</a><br/>
nginx vulnerability<br/>
 <a href="https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/">https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7518" type="text/plain" language="en" />
<itunes:keywords>nginx, pdf, google chrome, vulnerabilities, updates, bluetooth, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 26th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7516</itunes:episode>
<itunes:subtitle>Finding Phishing; VMware Advisory; Trend Micro Bugs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding Phishing; VMware Advisory; Trend Micro Bugs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7516.mp3" length="4488605" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7516.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7516</link>
<pubDate>Wed, 26 May 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Uncovering Shenenigans in an IP Address Block via Hurricane Electic's BGP Toolkit<br/>
 <a href="https://isc.sans.edu/forums/diary/Uncovering+Shenanigans+in+an+IP+Address+Block+via+Hurricane+Electrics+BGP+Toolkit/27456/">https://isc.sans.edu/forums/diary/Uncovering+Shenanigans+in+an+IP+Address+Block+via+Hurricane+Electrics+BGP+Toolkit/27456/</a><br/>
VMware Advisory<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0010.html">https://www.vmware.com/security/advisories/VMSA-2021-0010.html</a><br/>
Trend Micro Bugs<br/>
 <a href="https://blog.talosintelligence.com/2021/05/vuln-spotlight-trend-i.html">https://blog.talosintelligence.com/2021/05/vuln-spotlight-trend-i.html</a><br/>
]]></description>
<itunes:duration>4:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7516" type="text/plain" language="en" />
<itunes:keywords>trend micro, bugs, vmware, advisory, hurricane electric, phishing, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 25th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7514</itunes:episode>
<itunes:subtitle>Apple Patches 0-Days; Bluetooth Vulnerabilities; NAGIOS Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patches 0-Days; Bluetooth Vulnerabilities; NAGIOS Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7514.mp3" length="4455116" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7514.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7514</link>
<pubDate>Tue, 25 May 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Apple Patches 0-Days<br/>
 <a href="https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/">https://www.jamf.com/blog/zero-day-tcc-bypass-discovered-in-xcsset-malware/</a><br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Bluetooth Vulnerabilities<br/>
 <a href="https://kb.cert.org/vuls/id/799380">https://kb.cert.org/vuls/id/799380</a><br/>
 <a href="https://francozappa.github.io/about-bias/publication/antonioli-20-bias/antonioli-20-bias.pdf">https://francozappa.github.io/about-bias/publication/antonioli-20-bias/antonioli-20-bias.pdf</a><br/>
NAGIOS Vulnerabilities<br/>
 <a href="https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/">https://skylightcyber.com/2021/05/20/13-nagios-vulnerabilities-7-will-shock-you/</a><br/>
]]></description>
<itunes:duration>4:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7514" type="text/plain" language="en" />
<itunes:keywords>nagios, bluetooth, ios, macos, apple, 0-day, bigsur, catalina, mojave, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 24th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7512</itunes:episode>
<itunes:subtitle>Phishing without Server; Anti-Debugging; WinRM exposes http.sys; Firefox Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing without Server; Anti-Debugging; WinRM exposes http.sys; Firefox Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7512.mp3" length="5693085" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7512.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7512</link>
<pubDate>Mon, 24 May 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Serverless Phishing Campaign<br/>
 <a href="https://isc.sans.edu/forums/diary/Serverless+Phishing+Campaign/27446/">https://isc.sans.edu/forums/diary/Serverless+Phishing+Campaign/27446/</a><br/>
Locking Kernel32.dll As Anti-Debugging Technique<br/>
 <a href="https://isc.sans.edu/forums/diary/Locking+Kernel32dll+As+AntiDebugging+Technique/27444/">https://isc.sans.edu/forums/diary/Locking+Kernel32dll+As+AntiDebugging+Technique/27444/</a><br/>
WinRM Vulnerable to http.sys Vulnerability<br/>
 <a href="https://twitter.com/JimDinMN/status/1395071966487269376">https://twitter.com/JimDinMN/status/1395071966487269376</a><br/>
Mozilla Firefox "Content-Type Confusion" Unsafe Code Execution<br/>
 <a href="https://besteffortteam.it/mozilla-firefox-content-type-confusion-unsafe-code-execution/">https://besteffortteam.it/mozilla-firefox-content-type-confusion-unsafe-code-execution/</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7512" type="text/plain" language="en" />
<itunes:keywords>mozilla, firefox, winrm, anti-debugging, serverless, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 21st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7510</itunes:episode>
<itunes:subtitle>DNS Videos; Ransomware Leak Abused; Exchange Patch Speed; GPS vs. IP Geolocation @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Videos; Ransomware Leak Abused; Exchange Patch Speed; GPS vs. IP Geolocation @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7510.mp3" length="16968944" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7510.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7510</link>
<pubDate>Fri, 21 May 2021 02:00:03 GMT</pubDate>
<description><![CDATA[New YouTube Video Series: Everything you ever wanted to know about DNS and more<br/>
 <a href="https://isc.sans.edu/forums/diary/New+YouTube+Video+Series+Everything+you+ever+wanted+to+know+about+DNS+and+more/27440/">https://isc.sans.edu/forums/diary/New+YouTube+Video+Series+Everything+you+ever+wanted+to+know+about+DNS+and+more/27440/</a><br/>
And Ransomware Just Got a Bit Meaner<br/>
 <a href="https://isc.sans.edu/forums/diary/And+Ransomware+Just+Got+a+Bit+Meaner+yes+it+is+possible/27438/">https://isc.sans.edu/forums/diary/And+Ransomware+Just+Got+a+Bit+Meaner+yes+it+is+possible/27438/</a><br/>
Attackers Scanned for Exchange Servers Five Minutes after Patch Release<br/>
 <a href="https://www.ehackingnews.com/2021/05/microsoft-exchange-bug-report-allowed.html">https://www.ehackingnews.com/2021/05/microsoft-exchange-bug-report-allowed.html</a><br/>
GPS For Authentication: Is the Juice Worth the Squeeze @sans_edu<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/authentication/gps-authentication-juice-worth-squeeze-40270">https://www.sans.org/reading-room/whitepapers/authentication/gps-authentication-juice-worth-squeeze-40270</a><br/>
]]></description>
<itunes:duration>19:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7510" type="text/plain" language="en" />
<itunes:keywords>gps, authentication, exchange, scanning, attackers, speed, patching, ransomware, ireland, youtube, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 20th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7508</itunes:episode>
<itunes:subtitle>May Forensic Quiz Solution; CIS Controls 8; iDRAC 9 Vuln; QNAP Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
May Forensic Quiz Solution; CIS Controls 8; iDRAC 9 Vuln; QNAP Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7508.mp3" length="5450978" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7508.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7508</link>
<pubDate>Thu, 20 May 2021 02:05:02 GMT</pubDate>
<description><![CDATA[May 2021 Forensic Contest: Answers and Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/May+2021+Forensic+Contest+Answers+and+Analysis/27430/">https://isc.sans.edu/forums/diary/May+2021+Forensic+Contest+Answers+and+Analysis/27430/</a><br/>
CIS Controls V8<br/>
 <a href="https://www.cisecurity.org/controls/v8/">https://www.cisecurity.org/controls/v8/</a><br/>
Dell iDRAC 9 Security Update<br/>
 <a href="https://www.dell.com/support/kbdoc/en-us/000186420/dsa-2021-082-dell-emc-idrac-9-security-update-for-improper-authentication-vulnerability">https://www.dell.com/support/kbdoc/en-us/000186420/dsa-2021-082-dell-emc-idrac-9-security-update-for-improper-authentication-vulnerability</a><br/>
QNAP Pre-Auth Remote Code Execution in MuscStation/MalwareRemover<br/>
 <a href="https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/">https://www.shielder.it/advisories/qnap-musicstation-malwareremover-pre-auth-remote-code-execution/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7508" type="text/plain" language="en" />
<itunes:keywords>qnap, dell, idrac, cis, contest, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7506</itunes:episode>
<itunes:subtitle>RunDLL to JS; Pulse Secure; Vulnerable Stalkerware; Double Encryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RunDLL to JS; Pulse Secure; Vulnerable Stalkerware; Double Encryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7506.mp3" length="4801184" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7506.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7506</link>
<pubDate>Wed, 19 May 2021 02:00:02 GMT</pubDate>
<description><![CDATA[From RunDLL32 to JavaScript then PowerShell<br/>
 <a href="https://isc.sans.edu/forums/diary/From+RunDLL32+to+JavaScript+then+PowerShell/27428/">https://isc.sans.edu/forums/diary/From+RunDLL32+to+JavaScript+then+PowerShell/27428/</a><br/>
New Pulse Secure VPN Advisory<br/>
 <a href="https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800/">https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44800/</a><br/>
Android Stalkerware Vulnerabilities<br/>
 <a href="https://www.welivesecurity.com/2021/05/17/android-stalkerware-threatens-victims-further-exposes-snoopers-themselves/">https://www.welivesecurity.com/2021/05/17/android-stalkerware-threatens-victims-further-exposes-snoopers-themselves/</a><br/>
Double Encrypting Ransomware<br/>
 <a href="https://www.wired.com/story/ransomware-double-encryption/">https://www.wired.com/story/ransomware-double-encryption/</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7506" type="text/plain" language="en" />
<itunes:keywords>ransomware, double encryption, android, stalkerware, pulse secure, vpn, rundll32, javascript, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7504</itunes:episode>
<itunes:subtitle>2FA vs Ransomware; Ransomware and Cyber Insurance; http.sys PoC; Browser HTML Sanitizer API; SANS.edu Research
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
2FA vs Ransomware; Ransomware and Cyber Insurance; http.sys PoC; Browser HTML Sanitizer API; SANS.edu Research
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7504.mp3" length="5457705" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7504.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7504</link>
<pubDate>Tue, 18 May 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Ransomware Defenses<br/>
 <a href="https://isc.sans.edu/forums/diary/Ransomware+Defenses/27420/">https://isc.sans.edu/forums/diary/Ransomware+Defenses/27420/</a><br/>
AXA Stops Ransomware Payments<br/>
 <a href="https://www.insurancejournal.com/news/international/2021/05/09/613255.htm">https://www.insurancejournal.com/news/international/2021/05/09/613255.htm</a><br/>
http.sys Proof of Concept<br/>
 <a href="https://github.com/0vercl0k/CVE-2021-31166">https://github.com/0vercl0k/CVE-2021-31166</a><br/>
Google/Mozilla colaborating on HTML Sanitizer API<br/>
 <a href="https://wicg.github.io/sanitizer-api/#sanitizer-api">https://wicg.github.io/sanitizer-api/#sanitizer-api</a><br/>
SANS Technology Institute Research Journal<br/>
 <a href="https://www.sans.edu/cyber-research">https://www.sans.edu/cyber-research</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7504" type="text/plain" language="en" />
<itunes:keywords>sans.edu, research, journal, google, mozilla, html, sanitizer, api, http.sys, poc, axa, insurance, ransomware, 2fa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 17th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7502</itunes:episode>
<itunes:subtitle>Exposed VNC; VSCode Rust Exploit; Exim PoC Code; Favicon Webshells
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exposed VNC; VSCode Rust Exploit; Exim PoC Code; Favicon Webshells
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7502.mp3" length="5077178" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7502.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7502</link>
<pubDate>Mon, 17 May 2021 02:05:03 GMT</pubDate>
<description><![CDATA["Open" Access to Industrial Systems Interfaces is Also Far From Zero<br/>
 <a href="https://isc.sans.edu/forums/diary/Open+Access+to+Industrial+Systems+Interface+is+Also+Far+From+Zero/27418/">https://isc.sans.edu/forums/diary/Open+Access+to+Industrial+Systems+Interface+is+Also+Far+From+Zero/27418/</a><br/>
Malicious Rust Macro for VSCode<br/>
 <a href="https://github.com/lucky/bad_actor_poc">https://github.com/lucky/bad_actor_poc</a><br/>
Exim PoC Released<br/>
 <a href="https://adepts.of0x.cc/exim-cve-2020-28018/">https://adepts.of0x.cc/exim-cve-2020-28018/</a><br/>
Newly Observed PHP-based skimmmer shows ongoing Magecart Group 12 activity<br/>
 <a href="https://blog.malwarebytes.com/cybercrime/2021/05/newly-observed-php-based-skimmer-shows-ongoing-magecart-group-12-activity/">https://blog.malwarebytes.com/cybercrime/2021/05/newly-observed-php-based-skimmer-shows-ongoing-magecart-group-12-activity/</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7502" type="text/plain" language="en" />
<itunes:keywords>favicon, webshell, exim, rust, vscode, vnc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 14th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7500</itunes:episode>
<itunes:subtitle>Cross Browser Tracking; Cisco AnyConnect Patch; MSBuild Abuse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cross Browser Tracking; Cisco AnyConnect Patch; MSBuild Abuse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7500.mp3" length="6027101" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7500.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7500</link>
<pubDate>Fri, 14 May 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Cross Browser Tracking with Schemeflood<br/>
 <a href="https://fingerprintjs.com/blog/external-protocol-flooding/">https://fingerprintjs.com/blog/external-protocol-flooding/</a><br/>
Cisco AnyConnect Secure Mobility Client Patch<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-ipc-KfQO9QhK">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-ipc-KfQO9QhK</a><br/>
MSBuild Abused By Attackers <br/>
 <a href="https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly">https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7500" type="text/plain" language="en" />
<itunes:keywords>fingerprint, browser, schems, cisco, anyconnect, msbuild, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 13th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7498</itunes:episode>
<itunes:subtitle>Exposed ICS Trending Lower; FragAttack Vendor Bulletins; Adobe Acrobat 0Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exposed ICS Trending Lower; FragAttack Vendor Bulletins; Adobe Acrobat 0Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7498.mp3" length="5226668" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7498.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7498</link>
<pubDate>Thu, 13 May 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Number of industrial control systems on the internet is lower then in 2020...but still far from zero<br/>
 <a href="https://isc.sans.edu/forums/diary/Number+of+industrial+control+systems+on+the+internet+is+lower+then+in+2020but+still+far+from+zero/27412/">https://isc.sans.edu/forums/diary/Number+of+industrial+control+systems+on+the+internet+is+lower+then+in+2020but+still+far+from+zero/27412/</a><br/>
Webcast: Ransoming Critical Infrastructure<br/>
 <a href="https://www.sans.org/webcasts/119775">https://www.sans.org/webcasts/119775</a><br/>
Links to FragAttacks Vendor Bulletins (in German)<br/>
 <a href="https://www.heise.de/news/WLAN-Sicherheitsluecken-FragAttacks-Erste-Updates-6045116.html">https://www.heise.de/news/WLAN-Sicherheitsluecken-FragAttacks-Erste-Updates-6045116.html</a><br/>
Adobe Acrobat Patches<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb21-29.html">https://helpx.adobe.com/security/products/acrobat/apsb21-29.html</a><br/>
Sending Arbitrary Messages via FindMy<br/>
 <a href="https://positive.security/blog/send-my">https://positive.security/blog/send-my</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7498" type="text/plain" language="en" />
<itunes:keywords>find my, apple, airtag, adobe, acrobat, patches, fragattacks, pipeline, ics, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7496</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday (http.sys!!); WiFi Fragmentation/Aggregation Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday (http.sys!!); WiFi Fragmentation/Aggregation Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7496.mp3" length="5763441" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7496.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7496</link>
<pubDate>Wed, 12 May 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+May+2021+Patch+Tuesday/27408">https://isc.sans.edu/forums/diary/Microsoft+May+2021+Patch+Tuesday/27408</a><br/>
WiFi Fragmentation Attacks<br/>
 <a href="https://www.fragattacks.com">https://www.fragattacks.com</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7496" type="text/plain" language="en" />
<itunes:keywords>wifi, aggregated frames, fragmentation, microsoft, patch tuesday, http.sys, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7494</itunes:episode>
<itunes:subtitle>Validating IP Addresses; Jailbreaking AirTags; Malicious Tor Exit Nodes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Validating IP Addresses; Jailbreaking AirTags; Malicious Tor Exit Nodes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7494.mp3" length="4889218" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7494.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7494</link>
<pubDate>Tue, 11 May 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Validating IP Addresses: Why Encoding Matters<br/>
 <a href="https://isc.sans.edu/forums/diary/Correctly+Validating+IP+Addresses+Why+encoding+matters+for+input+validation/27404/">https://isc.sans.edu/forums/diary/Correctly+Validating+IP+Addresses+Why+encoding+matters+for+input+validation/27404/</a><br/>
Jail Breaking AirTags<br/>
 <a href="https://twitter.com/ghidraninja/status/1391148503196438529">https://twitter.com/ghidraninja/status/1391148503196438529</a><br/>
Malicious Tor Exit Relay Activities<br/>
 <a href="https://nusenu.medium.com/tracking-one-year-of-malicious-tor-exit-relay-activities-part-ii-85c80875c5df">https://nusenu.medium.com/tracking-one-year-of-malicious-tor-exit-relay-activities-part-ii-85c80875c5df</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7494" type="text/plain" language="en" />
<itunes:keywords>tor, exit nodes, nusenu, airtags, jailbreak, ip addresses, input validation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 10th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7492</itunes:episode>
<itunes:subtitle>Research Scans; tsuNAME and Cyclehunter; Foxit Patches; Hypocrit Patch Research Investigation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Research Scans; tsuNAME and Cyclehunter; Foxit Patches; Hypocrit Patch Research Investigation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7492.mp3" length="4819869" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7492.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7492</link>
<pubDate>Mon, 10 May 2021 02:05:03 GMT</pubDate>
<description><![CDATA[Who is Probing the Internet for Research Purposes<br/>
 <a href="https://isc.sans.edu/forums/diary/Who+is+Probing+the+Internet+for+Research+Purposes/27400/">https://isc.sans.edu/forums/diary/Who+is+Probing+the+Internet+for+Research+Purposes/27400/</a><br/>
Cycle Hunter and tsuNAME DDoS Attack<br/>
 <a href="https://github.com/SIDN/CycleHunter">https://github.com/SIDN/CycleHunter</a><br/>
 <a href="https://tsuname.io/tech_report.pdf">https://tsuname.io/tech_report.pdf</a><br/>
Foxit Reader / Phantom PDF Vulnerabilities<br/>
 <a href="https://www.foxitsoftware.com/support/security-bulletins.html?Security+updates+available+in+Foxit+Reader+10.1.4+and+Foxit+PhantomPDF+10.1.42021-05-06">https://www.foxitsoftware.com/support/security-bulletins.html?Security+updates+available+in+Foxit+Reader+10.1.4+and+Foxit+PhantomPDF+10.1.42021-05-06</a><br/>
Hypocrit Patches Reviewed By Linux Foundation<br/>
 <a href="https://lore.kernel.org/lkml/202104221451.292A6ED4@keescook/">https://lore.kernel.org/lkml/202104221451.292A6ED4@keescook/</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7492" type="text/plain" language="en" />
<itunes:keywords>hypocrit patches, linux foundation, umn, foxit, reader, phantom pdf, cycle hunter, tsuname, researchers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 7th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7490</itunes:episode>
<itunes:subtitle>Azure Blob Scans; Qualcomm MSM Vuln.; Google 2SF Default; Celebrite UFED Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Azure Blob Scans; Qualcomm MSM Vuln.; Google 2SF Default; Celebrite UFED Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7490.mp3" length="5018989" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7490.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7490</link>
<pubDate>Fri, 07 May 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Scans for Exposed Azure Storage Containers<br/>
 <a href="https://isc.sans.edu/forums/diary/Exposed+Azure+Storage+Containers/27396/">https://isc.sans.edu/forums/diary/Exposed+Azure+Storage+Containers/27396/</a><br/>
Qualcomm MSM Vulnerability<br/>
 <a href="https://research.checkpoint.com/2021/security-probe-of-qualcomm-msm/">https://research.checkpoint.com/2021/security-probe-of-qualcomm-msm/</a><br/>
Google to Automatically enroll users in 2SF<br/>
 <a href="https://blog.google/technology/safety-security/a-simpler-and-safer-future-without-passwords/">https://blog.google/technology/safety-security/a-simpler-and-safer-future-without-passwords/</a><br/>
New Cellebrite Vulnerabilities Announced<br/>
 <a href="https://www.ehackingnews.com/2021/05/new-vulnerabilities-in-cellebrites.html">https://www.ehackingnews.com/2021/05/new-vulnerabilities-in-cellebrites.html</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7490" type="text/plain" language="en" />
<itunes:keywords>cellebrite, google, 2sf, 2fa, mfa, qualcomm, msm, azure, blog, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 6th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7488</itunes:episode>
<itunes:subtitle>PCAP Contest; Windows Defender Bug; VMWare Patch; Cisco Patches; Number Recycling Risks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PCAP Contest; Windows Defender Bug; VMWare Patch; Cisco Patches; Number Recycling Risks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7488.mp3" length="5583897" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7488.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7488</link>
<pubDate>Thu, 06 May 2021 02:15:02 GMT</pubDate>
<description><![CDATA[May 2021 Forensic Contest<br/>
 <a href="https://isc.sans.edu/forums/diary/May+2021+Forensic+Contest/27386/">https://isc.sans.edu/forums/diary/May+2021+Forensic+Contest/27386/</a><br/>
Windows Defender Bug Fills Windows 10 Boot Drive with thousands of files<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-defender-bug-fills-windows-10-boot-drive-with-thousands-of-files/">https://www.bleepingcomputer.com/news/microsoft/windows-defender-bug-fills-windows-10-boot-drive-with-thousands-of-files/</a><br/>
VMWare vRealize Business for Cloud Patch<br/>
 <a href="https://kb.vmware.com/s/article/83475">https://kb.vmware.com/s/article/83475</a><br/>
Cisco Updates SD-WAN vManager / HyperFlex HX<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities">https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities</a><br/>
Security and Privacy Risks of Number Recycling at Mobile Carriers in the US<br/>
 <a href="https://recyclednumbers.cs.princeton.edu">https://recyclednumbers.cs.princeton.edu</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7488" type="text/plain" language="en" />
<itunes:keywords>privacy, security, phone numbers, recycling, cisco, sd-wan, hyperflex, vmware, windows, defnder, forensic, contest, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7486</itunes:episode>
<itunes:subtitle>Android Update; All Dells Vulnerable; Exim Again; Fast Scanning; ICMP Tunnel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Android Update; All Dells Vulnerable; Exim Again; Fast Scanning; ICMP Tunnel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7486.mp3" length="4948453" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7486.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7486</link>
<pubDate>Wed, 05 May 2021 02:15:02 GMT</pubDate>
<description><![CDATA[Android Update<br/>
 <a href="https://source.android.com/security/bulletin/2021-05-01?hl=en">https://source.android.com/security/bulletin/2021-05-01?hl=en</a><br/>
Dell Privilege Escalation Vulnerability<br/>
 <a href="https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability">https://www.dell.com/support/kbdoc/en-us/000186019/dsa-2021-088-dell-client-platform-security-update-for-dell-driver-insufficient-access-control-vulnerability</a><br/>
 <a href="https://labs.sentinelone.com/cve-2021-21551-hundreds-of-millions-of-dell-computers-at-risk-due-to-multiple-bios-driver-privilege-escalation-flaws/">https://labs.sentinelone.com/cve-2021-21551-hundreds-of-millions-of-dell-computers-at-risk-due-to-multiple-bios-driver-privilege-escalation-flaws/</a><br/>
Exim Mail Server Vulnerabilities<br/>
 <a href="https://www.qualys.com/2021/05/04/21nails/21nails.txt">https://www.qualys.com/2021/05/04/21nails/21nails.txt</a><br/>
Quick and Dirty Python: masscan<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+and+dirty+Python+masscan/27384/">https://isc.sans.edu/forums/diary/Quick+and+dirty+Python+masscan/27384/</a><br/>
ICMP Tunnel Backdoor<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7486" type="text/plain" language="en" />
<itunes:keywords>icmp, python, masscan, exim, android, dell, firmware update, bios update, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 4th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7484</itunes:episode>
<itunes:subtitle>Apple WebKit 0-Day; MSFT Exchange PoC; Micro-Op Caches; Pulse Secure Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple WebKit 0-Day; MSFT Exchange PoC; Micro-Op Caches; Pulse Secure Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7484.mp3" length="4255352" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7484.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7484</link>
<pubDate>Tue, 04 May 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Apple Patches 2 0-Day Flaws in WebKit affecting iOS/MacOS/WatchOS<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
PoC Exploit for CVE-2021-28482 (Microsoft Exchange)<br/>
 <a href="https://gist.github.com/testanull/9ebbd6830f7a501e35e67f2fcaa57bda">https://gist.github.com/testanull/9ebbd6830f7a501e35e67f2fcaa57bda</a><br/>
 <a href="https://testbnull.medium.com/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482-e713001d915f">https://testbnull.medium.com/microsoft-exchange-from-deserialization-to-post-auth-rce-cve-2021-28482-e713001d915f</a><br/>
Yet Another Processor Side-Channel: Micro-Ops Caches<br/>
 <a href="http://www.cs.virginia.edu/venkat/papers/isca2021a.pdf">http://www.cs.virginia.edu/venkat/papers/isca2021a.pdf</a><br/>
Pulse Secure Update<br/>
 <a href="https://blog.pulsesecure.net/pulse-connect-secure-patch-availability-sa44784/">https://blog.pulsesecure.net/pulse-connect-secure-patch-availability-sa44784/</a><br/>
]]></description>
<itunes:duration>4:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7484" type="text/plain" language="en" />
<itunes:keywords>pulse secure, side-channel, micro-ops, poc, exchange, apple, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7482</itunes:episode>
<itunes:subtitle>Qiling Framework @qiling_io; Python ipaddress flaw; exiftool code exec; abus insecurity; sonicwall
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Qiling Framework @qiling_io; Python ipaddress flaw; exiftool code exec; abus insecurity; sonicwall
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7482.mp3" length="4945791" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7482.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7482</link>
<pubDate>Mon, 03 May 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Qiling: A true instrumentable binary emulation framework<br/>
 <a href="https://isc.sans.edu/forums/diary/Qiling+A+true+instrumentable+binary+emulation+framework/27372/">https://isc.sans.edu/forums/diary/Qiling+A+true+instrumentable+binary+emulation+framework/27372/</a><br/>
Python "ipaddress" improper input validation<br/>
 <a href="https://sick.codes/sick-2021-014/">https://sick.codes/sick-2021-014/</a><br/>
EXIF Tool Vulnerabilities<br/>
 <a href="https://twitter.com/wcbowling/status/1385803927321415687">https://twitter.com/wcbowling/status/1385803927321415687</a><br/>
ABUS Secvest Internet Connected Alarm Systems<br/>
 <a href="https://eye.security/nl/blog/breaking-abus-secvest-internet-connected-alarm-systems-cve-2020-28973">https://eye.security/nl/blog/breaking-abus-secvest-internet-connected-alarm-systems-cve-2020-28973</a><br/>
FiveHands Ransomware Installed via SonicWall Flaw<br/>
 <a href="https://thehackernews.com/2021/04/hackers-exploit-sonicwall-zero-day-bug.html">https://thehackernews.com/2021/04/hackers-exploit-sonicwall-zero-day-bug.html</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7482" type="text/plain" language="en" />
<itunes:keywords>fivehands, ransomware, sonicwall, abus, secvest, alarm, python, exif, ipaddress, qiling, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 30th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7480</itunes:episode>
<itunes:subtitle>From Python to .Net; PHP Composer; BadAlloc and RTOS;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
From Python to .Net; PHP Composer; BadAlloc and RTOS;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7480.mp3" length="4773165" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7480.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7480</link>
<pubDate>Fri, 30 Apr 2021 02:05:03 GMT</pubDate>
<description><![CDATA[From Python to .Net<br/>
 <a href="https://isc.sans.edu/forums/diary/From+Python+to+Net/27366/">https://isc.sans.edu/forums/diary/From+Python+to+Net/27366/</a><br/>
PHP Composer Vulnerability<br/>
 <a href="https://blog.sonarsource.com/php-supply-chain-attack-on-composer">https://blog.sonarsource.com/php-supply-chain-attack-on-composer</a><br/>
Microsoft Identifies Several Integer Overflow Vulnerablities<br/>
 <a href="https://us-cert.cisa.gov/ics/advisories/icsa-21-119-04">https://us-cert.cisa.gov/ics/advisories/icsa-21-119-04</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7480" type="text/plain" language="en" />
<itunes:keywords>python, .Net, php, composer, microsoft, malloc, rtos, heapoverflow, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 29th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7478</itunes:episode>
<itunes:subtitle>Stopping Google FLoC; RotaJakiro Backdoor; F5 Big IP Kerberos Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Stopping Google FLoC; RotaJakiro Backdoor; F5 Big IP Kerberos Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7478.mp3" length="4697734" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7478.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7478</link>
<pubDate>Thu, 29 Apr 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Stopping Google FLoC<br/>
 <a href="https://github.blog/changelog/2021-04-27-github-pages-permissions-policy-interest-cohort-header-added-to-all-pages-sites/">https://github.blog/changelog/2021-04-27-github-pages-permissions-policy-interest-cohort-header-added-to-all-pages-sites/</a><br/>
 <a href="https://amifloced.org">https://amifloced.org</a><br/>
RotaJakiro Backdoor<br/>
 <a href="https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/">https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/</a><br/>
F5 Big IP Kerberos Spoofing Vulnerablity<br/>
 <a href="https://support.f5.com/csp/article/K51213246">https://support.f5.com/csp/article/K51213246</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7478" type="text/plain" language="en" />
<itunes:keywords>f5, big-ip, kerberos, spoofing, rotajakrio, backdoor, linux, floc, google, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 28th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7476</itunes:episode>
<itunes:subtitle>Singapore Post Phish; Malicious Ads; MSFT Block Cryptojacking; Linux Priv Escalation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Singapore Post Phish; Malicious Ads; MSFT Block Cryptojacking; Linux Priv Escalation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7476.mp3" length="4024199" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7476.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7476</link>
<pubDate>Wed, 28 Apr 2021 02:05:03 GMT</pubDate>
<description><![CDATA[Diving into a Singapore Post Phihsing E-Mail<br/>
 <a href="https://isc.sans.edu/forums/diary/Diving+into+a+Singapore+Post+Phishing+Email/27356/">https://isc.sans.edu/forums/diary/Diving+into+a+Singapore+Post+Phishing+Email/27356/</a><br/>
Two in Five Victims of Online Scam Adverts Do Not Report to Host Platforms<br/>
 <a href="https://www.which.co.uk/news/2021/04/two-in-five-victims-of-online-scam-adverts-dont-report-to-host-platforms/">https://www.which.co.uk/news/2021/04/two-in-five-victims-of-online-scam-adverts-dont-report-to-host-platforms/</a><br/>
Microsoft Defender Blocks Cryptojacking Malware<br/>
 <a href="https://www.microsoft.com/security/blog/2021/04/26/defending-against-cryptojacking-with-microsoft-defender-for-endpoint-and-intel-tdt/">https://www.microsoft.com/security/blog/2021/04/26/defending-against-cryptojacking-with-microsoft-defender-for-endpoint-and-intel-tdt/</a><br/>
Linux Privilege Escalation Vulnerability<br/>
 <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211">https://talosintelligence.com/vulnerability_reports/TALOS-2020-1211</a><br/>
]]></description>
<itunes:duration>4:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7476" type="text/plain" language="en" />
<itunes:keywords>linux, syscall, microsoft, talos, cryptojacking, malicious ads, singapore, phish, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 27th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7474</itunes:episode>
<itunes:subtitle>Microstation CAD and VBA; Apple Patches Everything (and 0-Day); Hashicorp code signing key exposed;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microstation CAD and VBA; Apple Patches Everything (and 0-Day); Hashicorp code signing key exposed;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7474.mp3" length="6508414" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7474.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7474</link>
<pubDate>Tue, 27 Apr 2021 02:05:02 GMT</pubDate>
<description><![CDATA[CAD: .DGN and .MVBA Files analyzed with oledump<br/>
 <a href="https://isc.sans.edu/forums/diary/CAD+DGN+and+MVBA+Files/27354/">https://isc.sans.edu/forums/diary/CAD+DGN+and+MVBA+Files/27354/</a><br/>
MacOS 0-Day Bug Patched<br/>
 <a href="https://objective-see.com/blog/blog_0x64.html">https://objective-see.com/blog/blog_0x64.html</a><br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Emotet Uninstaller Triggered<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2021/01/cleaning-up-after-emotet-the-law-enforcement-file/">https://blog.malwarebytes.com/threat-analysis/2021/01/cleaning-up-after-emotet-the-law-enforcement-file/</a><br/>
HashiCorp Code Signing Key Exposed By Codecov Compromise<br/>
 <a href="https://www.theregister.com/2021/04/26/hashicorp_reveals_exposure_of_private/">https://www.theregister.com/2021/04/26/hashicorp_reveals_exposure_of_private/</a><br/>
]]></description>
<itunes:duration>7:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7474" type="text/plain" language="en" />
<itunes:keywords>apple, code signing, gatekeeper, hashicorp, emotet, cad, microstation, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 26th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7472</itunes:episode>
<itunes:subtitle>Compacts VBA Macro; Top Honeypot PW; Clickstudios compromise; homebrew vulnerability; Apple AirDrop Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Compacts VBA Macro; Top Honeypot PW; Clickstudios compromise; homebrew vulnerability; Apple AirDrop Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7472.mp3" length="5148201" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7472.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7472</link>
<pubDate>Mon, 26 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Compact VBA Macros<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+PowerPoint+AddOn+Small+Is+Beautiful/27342/">https://isc.sans.edu/forums/diary/Malicious+PowerPoint+AddOn+Small+Is+Beautiful/27342/</a><br/>
Base64 Strings Used in Web Scanning<br/>
 <a href="https://isc.sans.edu/forums/diary/Base64+Hashes+Used+in+Web+Scanning/27346/">https://isc.sans.edu/forums/diary/Base64+Hashes+Used+in+Web+Scanning/27346/</a><br/>
Clickstudios Password Manager Compromise<br/>
 <a href="https://www.csis.dk/newsroom-blog-overview/2021/moserpass-supply-chain/">https://www.csis.dk/newsroom-blog-overview/2021/moserpass-supply-chain/</a><br/>
Homebrew Code Execution Vulnerability<br/>
 <a href="https://brew.sh/2021/04/21/security-incident-disclosure/">https://brew.sh/2021/04/21/security-incident-disclosure/</a><br/>
Apple AirDrop Shares Personal Data<br/>
 <a href="https://www.informatik.tu-darmstadt.de/fb20/ueber_uns_details_231616.en.jsp">https://www.informatik.tu-darmstadt.de/fb20/ueber_uns_details_231616.en.jsp</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7472" type="text/plain" language="en" />
<itunes:keywords>airdrop, apple, privacy, homebrew, git, clickstudios, base64, vba, macros, ppt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 23rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7470</itunes:episode>
<itunes:subtitle>Docker and grype; SolarWinds Update; Cellebrite Exploit</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Docker and grype; SolarWinds Update; Cellebrite Exploit</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7470.mp3" length="5226970" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7470.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7470</link>
<pubDate>Fri, 23 Apr 2021 12:12:50 GMT</pubDate>
<description><![CDATA[How Safe are Your Docker Images<br/>
 <a href="https://isc.sans.edu/forums/diary/How+Safe+Are+Your+Docker+Images/27340/">https://isc.sans.edu/forums/diary/How+Safe+Are+Your+Docker+Images/27340/</a><br/>
Additional SolarWinds Infrastructure<br/>
 <a href="https://www.riskiq.com/blog/external-threat-management/solarwinds-c2-servers-new-tactics/">https://www.riskiq.com/blog/external-threat-management/solarwinds-c2-servers-new-tactics/</a><br/>
Cellebrite Exploit<br/>
 <a href="https://signal.org/blog/cellebrite-vulnerabilities/">https://signal.org/blog/cellebrite-vulnerabilities/</a><br/>
Duo 2FA Bypass<br/>
 <a href="https://sensepost.com/blog/2021/duo-two-factor-authentication-bypass/">https://sensepost.com/blog/2021/duo-two-factor-authentication-bypass/</a>]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7470" type="text/plain" language="en" />
<itunes:keywords>duo, 2fa, cellebrite, solarwinds, docker, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7468</itunes:episode>
<itunes:subtitle>Univ. of Minnesota and Linux Kernel; 7Zip Qlocker Ransomware; Chrome 0Day Fixed</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Univ. of Minnesota and Linux Kernel; 7Zip Qlocker Ransomware; Chrome 0Day Fixed</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7468.mp3" length="5701692" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7468.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7468</link>
<pubDate>Thu, 22 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Linux Kernel Maintainer Calls Out "hypocrite commits" by University of Minnesota<br/>
 <a href="https://lore.kernel.org/lkml/20210421130105.1226686-38-gregkh@linuxfoundation.org/">https://lore.kernel.org/lkml/20210421130105.1226686-38-gregkh@linuxfoundation.org/</a><br/>
 <a href="https://github.com/QiushiWu/QiushiWu.github.io/blob/main/papers/OpenSourceInsecurity.pdf">https://github.com/QiushiWu/QiushiWu.github.io/blob/main/papers/OpenSourceInsecurity.pdf</a><br/>
 <a href="https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.pdf">https://www-users.cs.umn.edu/~kjlu/papers/clarifications-hc.pdf</a><br/>
QNAP QLocker uses 7-Zip<br/>
 <a href="https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/">https://www.bleepingcomputer.com/news/security/massive-qlocker-ransomware-attack-uses-7zip-to-encrypt-qnap-devices/</a><br/>
Chrome O-Day Fixed<br/>
 <a href="https://thehackernews.com/2021/04/update-your-chrome-browser-immediately.html">https://thehackernews.com/2021/04/update-your-chrome-browser-immediately.html</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7468" type="text/plain" language="en" />
<itunes:keywords>chrome, 0-day, 7zip, qlocker, qnap, linux, kernel, umn, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 21st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7466</itunes:episode>
<itunes:subtitle>Pulse Secure VPN 0-Day; Sonic Wall 0=Day; Synology Vuln; Air Fryer Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Pulse Secure VPN 0-Day; Sonic Wall 0=Day; Synology Vuln; Air Fryer Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7466.mp3" length="5557793" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7466.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7466</link>
<pubDate>Wed, 21 Apr 2021 02:20:02 GMT</pubDate>
<description><![CDATA[Pulse Secure VPN 0-Day Exploited<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html">https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html</a><br/>
 <a href="https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/">https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44784/</a><br/>
SonicWall Vulnerabilities<br/>
 <a href="https://www.sonicwall.com/support/product-notification/security-notice-sonicwall-email-security-zero-day-vulnerabilities/210416112932360/">https://www.sonicwall.com/support/product-notification/security-notice-sonicwall-email-security-zero-day-vulnerabilities/210416112932360/</a><br/>
Synology Vulnerability<br/>
 <a href="https://blog.talosintelligence.com/2021/04/vuln-spotlight-synology-dsm.html#more">https://blog.talosintelligence.com/2021/04/vuln-spotlight-synology-dsm.html#more</a><br/>
Air Fryer Vulnerability<br/>
 <a href="https://blog.talosintelligence.com/2021/04/vuln-spotlight-co.html">https://blog.talosintelligence.com/2021/04/vuln-spotlight-co.html</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7466" type="text/plain" language="en" />
<itunes:keywords>air fryer, synology, sonicwall, pulse secure, vpn, 0-day, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 20th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7464</itunes:episode>
<itunes:subtitle>Finding Phishing Sites; Nagios XI Exploit; XCSSET Malware and M1; qnap/junos patches; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding Phishing Sites; Nagios XI Exploit; XCSSET Malware and M1; qnap/junos patches; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7464.mp3" length="4552958" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7464.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7464</link>
<pubDate>Tue, 20 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Hunting Phishing Websites with Favicon Hashes<br/>
 <a href="https://isc.sans.edu/forums/diary/Hunting+phishing+websites+with+favicon+hashes/27326/">https://isc.sans.edu/forums/diary/Hunting+phishing+websites+with+favicon+hashes/27326/</a><br/>
Nagios XI Vulnerability Exploited by Cryptominers<br/>
 <a href="https://unit42.paloaltonetworks.com/nagios-xi-vulnerability-cryptomining/">https://unit42.paloaltonetworks.com/nagios-xi-vulnerability-cryptomining/</a><br/>
XCSSET Malware Adapting to MacOS 11 and M1<br/>
 <a href="https://www.trendmicro.com/en_us/research/21/d/xcsset-quickly-adapts-to-macos-11-and-m1-based-macs.html">https://www.trendmicro.com/en_us/research/21/d/xcsset-quickly-adapts-to-macos-11-and-m1-based-macs.html</a><br/>
QNAP Patches<br/>
 <a href="https://www.qnap.com/de-de/security-advisories?ref=security_advisory_details">https://www.qnap.com/de-de/security-advisories?ref=security_advisory_details</a><br/>
Juniper Updates<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES">https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7464" type="text/plain" language="en" />
<itunes:keywords>juniper, qnap, bazar, xcsset, macos, m1, nagios, cryptointer, favicon, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7462</itunes:episode>
<itunes:subtitle>More Cobalt Stryike Decode; Codecov Breach; EIPStackGroup Vuln; MSFT Patch Problems
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Cobalt Stryike Decode; Codecov Breach; EIPStackGroup Vuln; MSFT Patch Problems
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7462.mp3" length="5009411" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7462.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7462</link>
<pubDate>Mon, 19 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Decoding Cobalt Strike Traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/Decoding+Cobalt+Strike+Traffic/27322/">https://isc.sans.edu/forums/diary/Decoding+Cobalt+Strike+Traffic/27322/</a><br/>
Codecov Breach<br/>
 <a href="https://about.codecov.io/security-update/">https://about.codecov.io/security-update/</a><br/>
Google Project Zero Tweaks Disclosure Rules<br/>
 <a href="https://googleprojectzero.blogspot.com">https://googleprojectzero.blogspot.com</a><br/>
EIPStackGroup OpENer Ethernet/IP<br/>
 <a href="https://us-cert.cisa.gov/ics/advisories/icsa-21-105-02">https://us-cert.cisa.gov/ics/advisories/icsa-21-105-02</a><br/>
DNS Problems with Windows 10 Security Update<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/mandatory-windows-10-update-causing-dns-and-shared-folder-issues/">https://www.bleepingcomputer.com/news/microsoft/mandatory-windows-10-update-causing-dns-and-shared-folder-issues/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7462" type="text/plain" language="en" />
<itunes:keywords>dns, windows 10, llmnr, eipstackgroup, pener, ethernet/ip, google, project zero, codecov, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7460</itunes:episode>
<itunes:subtitle>Internal CA; Top Vuln. Used By SVR; Insecure URL Handling; @sans_edu: Malware Deteciton in TLS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Internal CA; Top Vuln. Used By SVR; Insecure URL Handling; @sans_edu: Malware Deteciton in TLS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7460.mp3" length="12345318" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7460.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7460</link>
<pubDate>Fri, 16 Apr 2021 00:43:01 GMT</pubDate>
<description><![CDATA[Why and How You Should be Using an Internal Certificate Authority<br/>
 <a href="https://isc.sans.edu/forums/diary/Why+and+How+You+Should+be+Using+an+Internal+Certificate+Authority/27314/">https://isc.sans.edu/forums/diary/Why+and+How+You+Should+be+Using+an+Internal+Certificate+Authority/27314/</a><br/>
Vulnerabilities Used By Russian Foreign Intelligence Service<br/>
 <a href="https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2573391/russian-foreign-intelligence-service-exploiting-five-publicly-known-vulnerabili/">https://www.nsa.gov/News-Features/Feature-Stories/Article-View/Article/2573391/russian-foreign-intelligence-service-exploiting-five-publicly-known-vulnerabili/</a><br/>
Insecurity URL Handling<br/>
 <a href="https://positive.security/blog/url-open-rce">https://positive.security/blog/url-open-rce</a><br/>
SANS Research Paper: Bryan Scarbrough; Malware Detection in Encrypted TLS Traffic Through Machine Learning<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/artificialintelligence/malware-detection-encrypted-tls-traffic-machine-learning-40185">https://www.sans.org/reading-room/whitepapers/artificialintelligence/malware-detection-encrypted-tls-traffic-machine-learning-40185</a><br/>
]]></description>
<itunes:duration>14:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7460" type="text/plain" language="en" />
<itunes:keywords>sans.edu, research, tls, russian, vulnerabilities, insecure, url, internal CA, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7458</itunes:episode>
<itunes:subtitle>pcap challenge solution; Adobe, Chrome, SAP Patches; Linux/Mac npm Malware; @sans.edu NCL
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
pcap challenge solution; Adobe, Chrome, SAP Patches; Linux/Mac npm Malware; @sans.edu NCL
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7458.mp3" length="5476339" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7458.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7458</link>
<pubDate>Thu, 15 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[April 2021 Forensics Quiz Solution<br/>
 <a href="https://isc.sans.edu/forums/diary/April+2021+Forensic+Quiz+Answers+and+Analysis/27308/">https://isc.sans.edu/forums/diary/April+2021+Forensic+Quiz+Answers+and+Analysis/27308/</a><br/>
Adobe Patch Tuesday <br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Chrome 90 Released (and 0-Day Exploits)<br/>
 <a href="https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html">https://chromereleases.googleblog.com/2021/04/stable-channel-update-for-desktop_14.html</a><br/>
 <a href="https://github.com/avboy1337/1195777-chrome0day">https://github.com/avboy1337/1195777-chrome0day</a><br/>
 <a href="https://github.com/r4j0x00/exploits/tree/master/chrome-0day">https://github.com/r4j0x00/exploits/tree/master/chrome-0day</a><br/>
SAP Updates<br/>
 <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649">https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649</a><br/>
Linux/Mac Malware included in npm Module<br/>
 <a href="https://blog.sonatype.com/damaging-linux-mac-malware-bundled-within-browserify-npm-brandjack-attempt">https://blog.sonatype.com/damaging-linux-mac-malware-bundled-within-browserify-npm-brandjack-attempt</a><br/>
Congratulations to the SANS.edu National Cyber League Teams!<br/>
 <a href="https://twitter.com/SANS_EDU/status/1382453652602941440">https://twitter.com/SANS_EDU/status/1382453652602941440</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7458" type="text/plain" language="en" />
<itunes:keywords>sans.edu, ncl, linux, mac, npm, malware, sap, chrome, adobe, forensics, quiz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 14th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7456</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; Name:Wreck DNS Vulns; #PATCHEXCHANGEAGAIN
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; Name:Wreck DNS Vulns; #PATCHEXCHANGEAGAIN
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7456.mp3" length="5105858" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7456.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7456</link>
<pubDate>Wed, 14 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+April+2021+Patch+Tuesday/27306/">https://isc.sans.edu/forums/diary/Microsoft+April+2021+Patch+Tuesday/27306/</a><br/>
NAME:WRECK DNS Vulnerabilities<br/>
 <a href="https://www.forescout.com/research-labs/namewreck/">https://www.forescout.com/research-labs/namewreck/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7456" type="text/plain" language="en" />
<itunes:keywords>name:wreck, dns, microsoft, patches, exchange, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 13th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7454</itunes:episode>
<itunes:subtitle>Cleartext Cobalt Strike; ASA5506 SSD Failure; PulseSecure VPN Cert Expiration; Rwn2Own; Tesla Google Chrome exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cleartext Cobalt Strike; ASA5506 SSD Failure; PulseSecure VPN Cert Expiration; Rwn2Own; Tesla Google Chrome exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7454.mp3" length="5400434" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7454.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7454</link>
<pubDate>Tue, 13 Apr 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Example of Cleartext Cobalt Strike Traffic <br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+Cleartext+Cobalt+Strike+Traffic+Thanks+Brad/27300/">https://isc.sans.edu/forums/diary/Example+of+Cleartext+Cobalt+Strike+Traffic+Thanks+Brad/27300/</a><br/>
ASA 5506 Series Security Appliances Field Notice <br/>
 <a href="https://www.cisco.com/c/en/us/support/docs/field-notices/720/fn72019.html">https://www.cisco.com/c/en/us/support/docs/field-notices/720/fn72019.html</a><br/>
Expired Certificate for PulseSecure VPN Devices<br/>
 <a href="https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44781/?kA13Z000000fzbR">https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44781/?kA13Z000000fzbR</a><br/>
Pwn2Own Summary<br/>
 <a href="https://thehackernews.com/2021/04/windows-ubuntu-zoom-safari-ms-exchange.html">https://thehackernews.com/2021/04/windows-ubuntu-zoom-safari-ms-exchange.html</a><br/>
Tesla Exploited Via Google Chrome Vulnerability<br/>
 <a href="https://leethax0.rs/2021/04/ElectricChrome/">https://leethax0.rs/2021/04/ElectricChrome/</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7454" type="text/plain" language="en" />
<itunes:keywords>tesla, google chrome, pwn2own, certificate, pulsesecure, vpn, asa 5506, ssd, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7452</itunes:episode>
<itunes:subtitle>Bring Your Own Python; Facebook vs PSL; Malicious Ads Pushing Clubhouse Malware; Identifying Cobalt Strike DNS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bring Your Own Python; Facebook vs PSL; Malicious Ads Pushing Clubhouse Malware; Identifying Cobalt Strike DNS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7452.mp3" length="6020368" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7452.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7452</link>
<pubDate>Mon, 12 Apr 2021 02:00:03 GMT</pubDate>
<description><![CDATA[No Python Interpreter? This Simple RAT Installs Its Own Copy<br/>
 <a href="https://isc.sans.edu/forums/diary/No+Python+Interpreter+This+Simple+RAT+Installs+Its+Own+Copy/27292/">https://isc.sans.edu/forums/diary/No+Python+Interpreter+This+Simple+RAT+Installs+Its+Own+Copy/27292/</a><br/>
Facebook Mistakingly Suggests Adding Domains To Public Suffix List will Ease Tracking<br/>
 <a href="https://publicsuffix.org">https://publicsuffix.org</a><br/>
 <a href="https://www.facebook.com/business/help/331612538028890?id=428636648170202">https://www.facebook.com/business/help/331612538028890?id=428636648170202</a><br/>
Facebook Ads Used to Push Clubhouse Related Malware<br/>
 <a href="https://www.ehackingnews.com/2021/04/cybercriminals-used-facebook-ads-to.html">https://www.ehackingnews.com/2021/04/cybercriminals-used-facebook-ads-to.html</a><br/>
Identifying Cobalt Strike DNS Intrastructure<br/>
 <a href="https://labs.f-secure.com/blog/detecting-exposed-cobalt-strike-dns-redirectors">https://labs.f-secure.com/blog/detecting-exposed-cobalt-strike-dns-redirectors</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7452" type="text/plain" language="en" />
<itunes:keywords>cobalt strike, dns, facebook, clubhouse, malware, privacy, apple, psl, tld, python, rat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7450</itunes:episode>
<itunes:subtitle>Ransomware Prototype; HTML Lego; Azure Functions Vuln; Cisco SMB Router Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ransomware Prototype; HTML Lego; Azure Functions Vuln; Cisco SMB Router Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7450.mp3" length="5098704" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7450.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7450</link>
<pubDate>Fri, 09 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Simple Powershell Ransomware Creating a 7Z Archive of your Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+Powershell+Ransomware+Creating+a+7Z+Archive+of+your+Files/27286/">https://isc.sans.edu/forums/diary/Simple+Powershell+Ransomware+Creating+a+7Z+Archive+of+your+Files/27286/</a><br/>
HTML Lego: Hidden Phishing at Free JavaScript Site<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/html-lego-hidden-phishing-at-free-javascript-site/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/html-lego-hidden-phishing-at-free-javascript-site/</a><br/>
Royal FLush: Privilege Escalation Vulnerability in Azure Functions<br/>
 <a href="https://www.intezer.com/blog/cloud-security/royal-flush-privilege-escalation-vulnerability-in-azure-functions/">https://www.intezer.com/blog/cloud-security/royal-flush-privilege-escalation-vulnerability-in-azure-functions/</a><br/>
Cisco Small Business Router Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-rce-q3rxHnvm">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-rce-q3rxHnvm</a><br/>
Google Chrome Blocking Port 10080 <br/>
 <a href="https://github.com/whatwg/fetch/issues/1191#issuecomment-797659444">https://github.com/whatwg/fetch/issues/1191#issuecomment-797659444</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7450" type="text/plain" language="en" />
<itunes:keywords>google, chrome, 10080, cisco, smb, router, royal flush, azure, functions, html, phishing, javascript, powershell, ransomware, 7zip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7448</itunes:episode>
<itunes:subtitle>WiFi IDS; PHP Incident Update; Bleedingtooth; LinkedIn Leak; VMWare Patch; Cisco Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WiFi IDS; PHP Incident Update; Bleedingtooth; LinkedIn Leak; VMWare Patch; Cisco Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7448.mp3" length="5961848" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7448.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7448</link>
<pubDate>Thu, 08 Apr 2021 02:05:02 GMT</pubDate>
<description><![CDATA[WiFi IDS's and Private MAC Addresses<br/>
 <a href="https://isc.sans.edu/forums/diary/WiFi+IDS+and+Private+MAC+Addresses/27288/">https://isc.sans.edu/forums/diary/WiFi+IDS+and+Private+MAC+Addresses/27288/</a><br/>
Update on PHP Incident<br/>
 <a href="https://externals.io/message/113981">https://externals.io/message/113981</a><br/>
Details about Linux Kernel Bluetooth Vulnerabilities<br/>
 <a href="https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html">https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html</a><br/>
LinkedIn Leak<br/>
 <a href="https://www.ehackingnews.com/2021/04/data-stolen-from-500-million-linkedin.html">https://www.ehackingnews.com/2021/04/data-stolen-from-500-million-linkedin.html</a><br/>
VMWare Carbon Black Cloud Workload Applicatnce Authentication Bypass<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0005.html">https://www.vmware.com/security/advisories/VMSA-2021-0005.html</a><br/>
Cisco SD-WAN vManage Software Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-YuTVWqy">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-YuTVWqy</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7448" type="text/plain" language="en" />
<itunes:keywords>cisco, vmware, carbon black, vmanage, sd-wan, linkedin, leak, linux, bluetooth, bleeingtooth, php, wifi, ids, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 7th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7446</itunes:episode>
<itunes:subtitle>Malspam, Outlook and RFCs; QNAP Updates EOL Firmware; Gigaset Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malspam, Outlook and RFCs; QNAP Updates EOL Firmware; Gigaset Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7446.mp3" length="5184326" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7446.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7446</link>
<pubDate>Wed, 07 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Malspam with Lokibot vs. Outlook and RFCs<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+with+Lokibot+vs+Outlook+and+RFCs/27282/">https://isc.sans.edu/forums/diary/Malspam+with+Lokibot+vs+Outlook+and+RFCs/27282/</a><br/>
SAP Attacks<br/>
 <a href="https://us-cert.cisa.gov/ncas/current-activity/2021/04/06/malicious-cyber-activity-targeting-critical-sap-applications">https://us-cert.cisa.gov/ncas/current-activity/2021/04/06/malicious-cyber-activity-targeting-critical-sap-applications</a><br/>
QNAP Upates Older EOL Devices<br/>
 <a href="https://www.qnap.com/de-de/release-notes/qts/4.3.6.1620/20210322">https://www.qnap.com/de-de/release-notes/qts/4.3.6.1620/20210322</a><br/>
GIGASET Android Phones Infected by Compromised Update Server<br/>
 <a href="https://www.heise.de/news/Gigaset-Malware-Befall-von-Android-Geraeten-des-Herstellers-gibt-Raetsel-auf-6006464.html">https://www.heise.de/news/Gigaset-Malware-Befall-von-Android-Geraeten-des-Herstellers-gibt-Raetsel-auf-6006464.html</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7446" type="text/plain" language="en" />
<itunes:keywords>gigaset, android, malware, qnap, updates, patches, SAP, malspam, lokibot, rfs, outlook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 6th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7444</itunes:episode>
<itunes:subtitle>LinkedIn Phish; Malicious Text Files; Rust Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LinkedIn Phish; Malicious Text Files; Rust Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7444.mp3" length="5134485" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7444.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7444</link>
<pubDate>Tue, 06 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[LinkedIn Spear-Phishing Campaign Targets Job Hunters<br/>
 <a href="https://threatpost.com/linkedin-spear-phishing-job-hunters/165240/">https://threatpost.com/linkedin-spear-phishing-job-hunters/165240/</a><br/>
Malicious Text Files (CVE-2019-8761)<br/>
 <a href="https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html">https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html</a><br/>
Rust Privacy Concerns<br/>
 <a href="https://www.bleepingcomputer.com/news/security/most-loved-programming-language-rust-sparks-privacy-concerns/">https://www.bleepingcomputer.com/news/security/most-loved-programming-language-rust-sparks-privacy-concerns/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7444" type="text/plain" language="en" />
<itunes:keywords>rust, privacy, text, textedit, linkedin, job search, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7442</itunes:episode>
<itunes:subtitle>Sandbox vs. Real Screenshots; FortiOS Exploitation; GitHub Coin Mining; Facebook Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sandbox vs. Real Screenshots; FortiOS Exploitation; GitHub Coin Mining; Facebook Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7442.mp3" length="5308967" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7442.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7442</link>
<pubDate>Mon, 05 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[C2 Activity: Sandboxes or Real Victims<br/>
 <a href="https://isc.sans.edu/forums/diary/C2+Activity+Sandboxes+or+Real+Victims/27272/">https://isc.sans.edu/forums/diary/C2+Activity+Sandboxes+or+Real+Victims/27272/</a><br/>
Exploitation of Fortinet FortiOS Vulnerabilities<br/>
 <a href="https://us-cert.cisa.gov/ncas/current-activity/2021/04/02/fbi-cisa-joint-advisory-exploitation-fortinet-fortios">https://us-cert.cisa.gov/ncas/current-activity/2021/04/02/fbi-cisa-joint-advisory-exploitation-fortinet-fortios</a><br/>
 <a href="https://www.ic3.gov/Media/News/2021/210402.pdf">https://www.ic3.gov/Media/News/2021/210402.pdf</a><br/>
GitHub Actions Used to Mine Crypto<br/>
 <a href="https://therecord.media/github-investigating-crypto-mining-campaign-abusing-its-server-infrastructure/">https://therecord.media/github-investigating-crypto-mining-campaign-abusing-its-server-infrastructure/</a><br/>
Large Facebook Leak<br/>
 <a href="https://thehackernews.com/2021/04/533-million-facebook-users-phone.html">https://thehackernews.com/2021/04/533-million-facebook-users-phone.html</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7442" type="text/plain" language="en" />
<itunes:keywords>facebook, github, fortios, fortinet, sandboxes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7440</itunes:episode>
<itunes:subtitle>April PCAP Quiz; Coinhive Update; Forensicating BITS; More Water Trouble; QNAP Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
April PCAP Quiz; Coinhive Update; Forensicating BITS; More Water Trouble; QNAP Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7440.mp3" length="5571277" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7440.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7440</link>
<pubDate>Fri, 02 Apr 2021 02:10:02 GMT</pubDate>
<description><![CDATA[April 2021 Forensic Quiz<br/>
 <a href="https://isc.sans.edu/forums/diary/April+2021+Forensic+Quiz/27266/">https://isc.sans.edu/forums/diary/April+2021+Forensic+Quiz/27266/</a><br/>
Coinhive Domains Used to Warn Victims<br/>
 <a href="https://www.troyhunt.com/i-now-own-the-coinhive-domain-heres-how-im-fighting-cryptojacking-and-doing-good-things-with-content-security-policies/">https://www.troyhunt.com/i-now-own-the-coinhive-domain-heres-how-im-fighting-cryptojacking-and-doing-good-things-with-content-security-policies/</a><br/>
Detecting Attacker's BITS Utility Use<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2021/03/attacker-use-of-windows-background-intelligent-transfer-service.html">https://www.fireeye.com/blog/threat-research/2021/03/attacker-use-of-windows-background-intelligent-transfer-service.html</a><br/>
Kansas Man Indicted For Tampering With Public Water System<br/>
 <a href="https://www.justice.gov/usao-ks/pr/indictment-kansas-man-indicted-tampering-public-water-system">https://www.justice.gov/usao-ks/pr/indictment-kansas-man-indicted-tampering-public-water-system</a><br/>
Older QNAP Devices Vulnerable And No Longer Patched<br/>
 <a href="https://securingsam.com/new-vulnerabilities-allow-complete-takeover/">https://securingsam.com/new-vulnerabilities-allow-complete-takeover/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7440" type="text/plain" language="en" />
<itunes:keywords>qnap, kansas, water, bits, coinhive, troy hunt, april, quiz, packet, forensics, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7438</itunes:episode>
<itunes:subtitle>Modular InfoStealer; Google Chrome Update; DoH on Linux; Facial Recognition Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Modular InfoStealer; Google Chrome Update; DoH on Linux; Facial Recognition Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7438.mp3" length="4414338" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7438.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7438</link>
<pubDate>Thu, 01 Apr 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Quick Analysis of a Modular InfoStealer<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Analysis+of+a+Modular+InfoStealer/27264/">https://isc.sans.edu/forums/diary/Quick+Analysis+of+a+Modular+InfoStealer/27264/</a><br/>
Google Chrome Update / DoH on Linux<br/>
 <a href="https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop_30.html">https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop_30.html</a><br/>
 <a href="https://docs.google.com/document/d/1zAdSK393IznaLKQ0ItOmwLBy59fIq9ydxBRJQX-2ntQ/edit#">https://docs.google.com/document/d/1zAdSK393IznaLKQ0ItOmwLBy59fIq9ydxBRJQX-2ntQ/edit#</a><br/>
Chinese Tax Authority Facial Recognition System Fooled<br/>
 <a href="https://www.scmp.com/tech/tech-trends/article/3127645/chinese-government-run-facial-recognition-system-hacked-tax">https://www.scmp.com/tech/tech-trends/article/3127645/chinese-government-run-facial-recognition-system-hacked-tax</a><br/>
]]></description>
<itunes:duration>4:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7438" type="text/plain" language="en" />
<itunes:keywords>china, tax, facial recognition, biometrics, google chrome, doh, linux, infostealer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 31st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7436</itunes:episode>
<itunes:subtitle>TLS Survey; Perl Netmask Vulnerability; VMWare vRealize; pre-pw0ned docker images
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TLS Survey; Perl Netmask Vulnerability; VMWare vRealize; pre-pw0ned docker images
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7436.mp3" length="5031925" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7436.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7436</link>
<pubDate>Wed, 31 Mar 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Old TLS Versions: Gone but not Forgotten<br/>
 <a href="https://isc.sans.edu/forums/diary/Old+TLS+versions+gone+but+not+forgotten+well+not+really+gone+either/27260/">https://isc.sans.edu/forums/diary/Old+TLS+versions+gone+but+not+forgotten+well+not+really+gone+either/27260/</a><br/>
Perl Netmask Vulnerability<br/>
 <a href="https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/">https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/</a><br/>
VMWare vRealize Vulnerability<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0004.html">https://www.vmware.com/security/advisories/VMSA-2021-0004.html</a><br/>
Pre-P0wned Docker Containers<br/>
 <a href="https://unit42.paloaltonetworks.com/malicious-cryptojacking-images/">https://unit42.paloaltonetworks.com/malicious-cryptojacking-images/</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7436" type="text/plain" language="en" />
<itunes:keywords>pre-pwoned docker, docker, xmrig, miner, vmware, vrealie, ssrf, perl, netmask, tls, shodan, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 30th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7434</itunes:episode>
<itunes:subtitle>RTF Shellcode; PHP Git Repo Compromise; npm "netmask" package vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RTF Shellcode; PHP Git Repo Compromise; npm "netmask" package vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7434.mp3" length="6106192" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7434.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7434</link>
<pubDate>Tue, 30 Mar 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Jumping Into Shellcode<br/>
 <a href="https://isc.sans.edu/forums/diary/Jumping+into+Shellcode/27256/">https://isc.sans.edu/forums/diary/Jumping+into+Shellcode/27256/</a><br/>
PHP git repo compromised<br/>
 <a href="https://news-web.php.net/php.internals/113838">https://news-web.php.net/php.internals/113838</a><br/>
npm "netmask" package vulnerability<br/>
 <a href="https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/">https://sick.codes/universal-netmask-npm-package-used-by-270000-projects-vulnerable-to-octal-input-data-server-side-request-forgery-remote-file-inclusion-local-file-inclusion-and-more-cve-2021-28918/</a><br/>
]]></description>
<itunes:duration>6:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7434" type="text/plain" language="en" />
<itunes:keywords>npm, php, git, github, shellcode, rtf, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7420</itunes:episode>
<itunes:subtitle>Python Keylogger; XcodeSpy; Zoom Screen Sharing Leak; MyBB RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python Keylogger; XcodeSpy; Zoom Screen Sharing Leak; MyBB RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7420.mp3" length="5407204" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7420.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7420</link>
<pubDate>Fri, 19 Mar 2021 02:00:02 GMT</pubDate>
<description><![CDATA[A Simple Python Keylogger<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+Python+Keylogger/27216/">https://isc.sans.edu/forums/diary/Simple+Python+Keylogger/27216/</a><br/>
New macOS Malware XcodeSpy Targets Xcode Developers with EggShell Backdoor<br/>
 <a href="https://labs.sentinelone.com/new-macos-malware-xcodespy-targets-xcode-developers-with-eggshell-backdoor/">https://labs.sentinelone.com/new-macos-malware-xcodespy-targets-xcode-developers-with-eggshell-backdoor/</a><br/>
Zoom Screen Sharing Leak<br/>
 <a href="https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-044.txt">https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2020-044.txt</a><br/>
MyBB Remote Code Execution<br/>
 <a href="https://blog.mybb.com/2021/03/10/mybb-1-8-26-released-security-release/">https://blog.mybb.com/2021/03/10/mybb-1-8-26-released-security-release/</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7420" type="text/plain" language="en" />
<itunes:keywords>mybb, zoom, screen sharing, macos, xcodespy, xcode, python, keylogger, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7418</itunes:episode>
<itunes:subtitle>More Covid Phish; iOS Update Changes; Polyglot Twitter Images; Attaching CC to Images
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Covid Phish; iOS Update Changes; Polyglot Twitter Images; Attaching CC to Images
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7418.mp3" length="5232400" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7418.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7418</link>
<pubDate>Thu, 18 Mar 2021 02:00:02 GMT</pubDate>
<description><![CDATA["American Rescue Plan" Used as Theme in Phishing Lures Dropping Dridex<br/>
 <a href="https://cofense.com/blog/american-rescue-plan-phish/">https://cofense.com/blog/american-rescue-plan-phish/</a><br/>
Apple May Split Security Updates from Other Updates<br/>
 <a href="https://9to5mac.com/2021/03/15/ios-security-fixes-could-soon-be-delivered-separately-from-other-updates-beta-code-suggests/">https://9to5mac.com/2021/03/15/ios-security-fixes-could-soon-be-delivered-separately-from-other-updates-beta-code-suggests/</a><br/>
Polyglot Images on Twitter<br/>
 <a href="https://twitter.com/David3141593/status/1371978592679309315">https://twitter.com/David3141593/status/1371978592679309315</a><br/>
Magento 2 PHP Credit Card Skimmer Saves to JPG<br/>
 <a href="https://blog.sucuri.net/2021/03/magento-2-php-credit-card-skimmer-saves-to-jpg.html">https://blog.sucuri.net/2021/03/magento-2-php-credit-card-skimmer-saves-to-jpg.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7418" type="text/plain" language="en" />
<itunes:keywords>magento, credit card skimmer, jpg, polyglot, images, twitter, apple, updates, dridex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 17th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7416</itunes:episode>
<itunes:subtitle>One Click Exchange Fix; MSFT Azure AD Postmortem; Side Channel Exploits without JavaScript;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
One Click Exchange Fix; MSFT Azure AD Postmortem; Side Channel Exploits without JavaScript;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7416.mp3" length="5275558" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7416.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7416</link>
<pubDate>Wed, 17 Mar 2021 02:10:02 GMT</pubDate>
<description><![CDATA[One-Click Microsoft Exchange On-Premises Mitigation Tool<br/>
 <a href="https://msrc-blog.microsoft.com/2021/03/15/one-click-microsoft-exchange-on-premises-mitigation-tool-march-2021/">https://msrc-blog.microsoft.com/2021/03/15/one-click-microsoft-exchange-on-premises-mitigation-tool-march-2021/</a><br/>
Microsoft Explains Authentication Issues with Azure Active Directory<br/>
 <a href="https://www.documentcloud.org/documents/20515443-authentication-errors-across-multiple-microsoft-services-tracking-id-ln01-p8z">https://www.documentcloud.org/documents/20515443-authentication-errors-across-multiple-microsoft-services-tracking-id-ln01-p8z</a><br/>
JavaScript Less Side-Channel Exploits<br/>
 <a href="https://arxiv.org/abs/2103.04952">https://arxiv.org/abs/2103.04952</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7416" type="text/plain" language="en" />
<itunes:keywords>javascript, css, side-channel, spectre, microsoft, azure, active directory, exchange, mitigation tool, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7414</itunes:episode>
<itunes:subtitle>NimzaLoader; Win10 Crash Patches; Azure AD Outage; IBM DB2 Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NimzaLoader; Win10 Crash Patches; Azure AD Outage; IBM DB2 Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7414.mp3" length="4537173" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7414.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7414</link>
<pubDate>Tue, 16 Mar 2021 02:00:02 GMT</pubDate>
<description><![CDATA[NimzaLoader Malware Written in "nim"<br/>
  <a href="https://www.proofpoint.com/uk/blog/threat-insight/nimzaloader-ta800s-new-initial-access-malware">https://www.proofpoint.com/uk/blog/threat-insight/nimzaloader-ta800s-new-initial-access-malware</a><br/>
Windows 10 Emergency Update to Fix Printing Crashes<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-10-emergency-updates-released-to-fix-printing-crashes/">https://www.bleepingcomputer.com/news/microsoft/windows-10-emergency-updates-released-to-fix-printing-crashes/</a><br/>
Windows Azure AD Outage<br/>
 <a href="https://status.azure.com/status">https://status.azure.com/status</a><br/>
IBM DB2 Patch<br/>
 <a href="https://www.ibm.com/support/pages/node/6427855">https://www.ibm.com/support/pages/node/6427855</a><br/>
]]></description>
<itunes:duration>5:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7414" type="text/plain" language="en" />
<itunes:keywords>db2, ibm, windows, azure, ad, windows 10, nimzaloader, nim, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7412</itunes:episode>
<itunes:subtitle>Wireshark Exploit; Google Chrome; zhtrap @360netlab; twitter bug 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wireshark Exploit; Google Chrome; zhtrap @360netlab; twitter bug 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7412.mp3" length="4407341" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7412.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7412</link>
<pubDate>Mon, 15 Mar 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Wireshark Code Execution Exploit<br/>
 <a href="https://gitlab.com/wireshark/wireshark/-/issues/17232">https://gitlab.com/wireshark/wireshark/-/issues/17232</a><br/>
Google Chrome Vulnerability Exploited in the Wild<br/>
 <a href="https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-21193">https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-21193</a><br/>
Malware Installs Honeypot<br/>
 <a href="https://blog.netlab.360.com/new_threat_zhtrap_botnet_en/">https://blog.netlab.360.com/new_threat_zhtrap_botnet_en/</a><br/>
Twitter "Memphis" Bug<br/>
 <a href="https://www.bleepingcomputer.com/news/technology/twitter-bug-automatically-suspends-you-when-tweeting-memphis/">https://www.bleepingcomputer.com/news/technology/twitter-bug-automatically-suspends-you-when-tweeting-memphis/</a><br/>
]]></description>
<itunes:duration>4:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7412" type="text/plain" language="en" />
<itunes:keywords>twitter, memphis, honeypt, malware, google crhome, wireshark, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7410</itunes:episode>
<itunes:subtitle>Piktochart Phishing; ProxyLogon Public PoC; Win10 Crashes; Rob Upchurch: SMHNR DNS Leakage @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Piktochart Phishing; ProxyLogon Public PoC; Win10 Crashes; Rob Upchurch: SMHNR DNS Leakage @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7410.mp3" length="13525329" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7410.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7410</link>
<pubDate>Fri, 12 Mar 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Pichktochart - Phishing with Infographics<br/>
 <a href="https://isc.sans.edu/forums/diary/Piktochart+Phishing+with+Infographics/27194/">https://isc.sans.edu/forums/diary/Piktochart+Phishing+with+Infographics/27194/</a><br/>
ProxyLogon Public PoC<br/>
 <a href="https://www.praetorian.com/blog/reproducing-proxylogon-exploit/">https://www.praetorian.com/blog/reproducing-proxylogon-exploit/</a><br/>
Windows 10 Crashes After March 10th Updates<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-10-crashes-when-printing-due-to-microsoft-march-updates/">https://www.bleepingcomputer.com/news/microsoft/windows-10-crashes-when-printing-due-to-microsoft-march-updates/</a><br/>
DNS Vulnerability Updates<br/>
 <a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/seven-windows-wonders-critical-vulnerabilities-in-dns-dynamic-updates/">https://www.mcafee.com/blogs/other-blogs/mcafee-labs/seven-windows-wonders-critical-vulnerabilities-in-dns-dynamic-updates/</a><br/>
Rob Upchurch: Preventing Windows 10 SMHNR DNS Leakage<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/dns/preventing-windows-10-smhnr-dns-leakage-40165">https://www.sans.org/reading-room/whitepapers/dns/preventing-windows-10-smhnr-dns-leakage-40165</a><br/>
]]></description>
<itunes:duration>15:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7410" type="text/plain" language="en" />
<itunes:keywords>rob upchurch, smhnr, dns, windows, vulnerability, exchange, proxylogon, poc, phishing, piktochart, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7408</itunes:episode>
<itunes:subtitle>SharpRDP; F5 Vulnerabilities; Netgear Updates; sigstore
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SharpRDP; F5 Vulnerabilities; Netgear Updates; sigstore
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7408.mp3" length="4795737" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7408.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7408</link>
<pubDate>Thu, 11 Mar 2021 02:05:03 GMT</pubDate>
<description><![CDATA[SharpRDP - PSExec with PSExec, PSRemoting without PowerShell<br/>
 <a href="https://isc.sans.edu/forums/diary/SharpRDP+PSExec+without+PSExec+PSRemoting+without+PowerShell/27188/">https://isc.sans.edu/forums/diary/SharpRDP+PSExec+without+PSExec+PSRemoting+without+PowerShell/27188/</a><br/>
F5 Critical Vulnerabilities<br/>
 <a href="https://support.f5.com/csp/article/K02566623">https://support.f5.com/csp/article/K02566623</a><br/>
Netgear Updates<br/>
 <a href="https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/">https://research.nccgroup.com/2021/03/08/technical-advisory-multiple-vulnerabilities-in-netgear-prosafe-plus-jgs516pe-gs116ev2-switches/</a><br/>
Linux Foundation sigstore<br/>
 <a href="https://sigstore.dev">https://sigstore.dev</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7408" type="text/plain" language="en" />
<itunes:keywords>sigstore, google, linux foundation, code signing, f5, netgear, sharprdp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 10th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7406</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates; Verkada Breach; git vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Updates; Verkada Breach; git vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7406.mp3" length="6368313" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7406.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7406</link>
<pubDate>Wed, 10 Mar 2021 02:15:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+March+2021+Patch+Tuesday/27184/">https://isc.sans.edu/forums/diary/Microsoft+March+2021+Patch+Tuesday/27184/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Network Camera Breach<br/>
 <a href="https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams">https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/hackers-access-surveillance-cameras-at-tesla-cloudflare-banks-more/">https://www.bleepingcomputer.com/news/security/hackers-access-surveillance-cameras-at-tesla-cloudflare-banks-more/</a><br/>
git vulnerability<br/>
 <a href="https://www.openwall.com/lists/oss-security/2021/03/09/3">https://www.openwall.com/lists/oss-security/2021/03/09/3</a><br/>
]]></description>
<itunes:duration>7:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7406" type="text/plain" language="en" />
<itunes:keywords>git, verkata, cameras, adobe, microsoft, patches, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7404</itunes:episode>
<itunes:subtitle>YARA and CyberChef; Apple Patches; Chrome Blocks Port 554; Intel CPU Side Channel Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
YARA and CyberChef; Apple Patches; Chrome Blocks Port 554; Intel CPU Side Channel Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7404.mp3" length="4995044" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7404.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7404</link>
<pubDate>Tue, 09 Mar 2021 02:00:03 GMT</pubDate>
<description><![CDATA[YARA and CyberChef<br/>
 <a href="https://isc.sans.edu/forums/diary/YARA+and+CyberChef/27180/">https://isc.sans.edu/forums/diary/YARA+and+CyberChef/27180/</a><br/>
Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Google Adds Port 554 to "Restricted Ports"<br/>
 <a href="https://chromium.googlesource.com/chromium/src.git/+/refs/heads/master/net/base/port_util.cc">https://chromium.googlesource.com/chromium/src.git/+/refs/heads/master/net/base/port_util.cc</a><br/>
Yet Another Intel Side Channel Attack<br/>
 <a href="https://arxiv.org/pdf/2103.03443.pdf">https://arxiv.org/pdf/2103.03443.pdf</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7404" type="text/plain" language="en" />
<itunes:keywords>side channel, intel, ring, google, port 554, restricted ports, yara, cyberchef, apple, webkit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7402</itunes:episode>
<itunes:subtitle>MSFT Exchange; Excel 4 Macros (XLM) AMSI; Apple Find My Device Privacy Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Exchange; Excel 4 Macros (XLM) AMSI; Apple Find My Device Privacy Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7402.mp3" length="6600160" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7402.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7402</link>
<pubDate>Mon, 08 Mar 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Update on Microsoft Exchange Vulnerability<br/>
 <a href="https://github.com/microsoft/CSS-Exchange/tree/main/Security">https://github.com/microsoft/CSS-Exchange/tree/main/Security</a><br/>
 <a href="https://github.com/nccgroup/Cyber-Defence/tree/master/Intelligence/Exchange">https://github.com/nccgroup/Cyber-Defence/tree/master/Intelligence/Exchange</a><br/>
 <a href="https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b">https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b</a><br/>
Microsoft Adding Excel 4.0 Macro Hooks to AMSI<br/>
 <a href="https://www.microsoft.com/security/blog/2021/03/03/xlm-amsi-new-runtime-defense-against-excel-4-0-macro-malware/">https://www.microsoft.com/security/blog/2021/03/03/xlm-amsi-new-runtime-defense-against-excel-4-0-macro-malware/</a><br/>
Apple Find My Device Leak<br/>
 <a href="https://arxiv.org/pdf/2103.02282.pdf">https://arxiv.org/pdf/2103.02282.pdf</a><br/>
]]></description>
<itunes:duration>7:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7402" type="text/plain" language="en" />
<itunes:keywords>apple, find my device, microsoft, exchange, excel, xlm, amsi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7400</itunes:episode>
<itunes:subtitle>VBS to RAT; Cisco Snort DoS Patch; VMWare View Planer Update; Google FLoC; Supermicro Trickbot Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBS to RAT; Cisco Snort DoS Patch; VMWare View Planer Update; Google FLoC; Supermicro Trickbot Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7400.mp3" length="5367345" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7400.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7400</link>
<pubDate>Fri, 05 Mar 2021 12:05:03 GMT</pubDate>
<description><![CDATA[From VBS, PowerShell, C Sharp, Process Hollowing to RAT<br/>
 <a href="https://isc.sans.edu/forums/diary/From+VBS+PowerShell+C+Sharp+Process+Hollowing+to+RAT/27168/">https://isc.sans.edu/forums/diary/From+VBS+PowerShell+C+Sharp+Process+Hollowing+to+RAT/27168/</a><br/>
Cisco Patches Snort Related Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ethernet-dos-HGXgJH8n">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ethernet-dos-HGXgJH8n</a><br/>
VMWare View Planner Update<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0003.html">https://www.vmware.com/security/advisories/VMSA-2021-0003.html</a><br/>
Google's FLoC Algorithm<br/>
 <a href="https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-idea">https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-idea</a><br/>
Supermicro Trickbot Patch<br/>
 <a href="https://www.supermicro.com/en/support/security/trickbot">https://www.supermicro.com/en/support/security/trickbot</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7400" type="text/plain" language="en" />
<itunes:keywords>supermicro, trickbot, google, floc, vmware, view planner, cisco, patches, snort, vbs, powershell, c sharp, rat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 4th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7398</itunes:episode>
<itunes:subtitle>Microsoft Exchange Followup; Saltstack Vuln; Grub2 Patches; More Dependency Confusion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Exchange Followup; Saltstack Vuln; Grub2 Patches; More Dependency Confusion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7398.mp3" length="4412830" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7398.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7398</link>
<pubDate>Thu, 04 Mar 2021 02:25:02 GMT</pubDate>
<description><![CDATA[Microsoft Exchange Followup<br/>
 <a href="https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/">https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/</a><br/>
 <br/>
Saltstack Vulnerability<br/>
 <a href="https://www.immersivelabs.com/resources/blog/why-so-salty-local-privilege-escalation-on-saltstack-minions/">https://www.immersivelabs.com/resources/blog/why-so-salty-local-privilege-escalation-on-saltstack-minions/</a><br/>
GRUB2 Patches<br/>
 <a href="https://seclists.org/oss-sec/2021/q1/189">https://seclists.org/oss-sec/2021/q1/189</a><br/>
Dependency Confusion in the Wild<br/>
 <a href="https://threatpost.com/malicious-code-bombs-amazon-lyft-slack-zillow/164455/">https://threatpost.com/malicious-code-bombs-amazon-lyft-slack-zillow/164455/</a><br/>
]]></description>
<itunes:duration>4:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7398" type="text/plain" language="en" />
<itunes:keywords>dependency confusion, grub2, salt, saltstack, microsoft, exchange, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7396</itunes:episode>
<itunes:subtitle>Qakbot+Cobalt Strike; Exchange Server 0-Day; Google Chrome 0-Day; iOS Jailbreak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Qakbot+Cobalt Strike; Exchange Server 0-Day; Google Chrome 0-Day; iOS Jailbreak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7396.mp3" length="6398583" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7396.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7396</link>
<pubDate>Wed, 03 Mar 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Qakbot Infection with Cobalt Strike<br/>
 <a href="https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike/27158/">https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike/27158/</a><br/>
Exchange Server 0-Day Exploits<br/>
 <a href="https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/">https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/</a><br/>
Google Chrome 0-Day Exploits<br/>
 <a href="https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop.html</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7396" type="text/plain" language="en" />
<itunes:keywords>google, chrome, exchange, server, 0-day, exploit, qakbot, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7394</itunes:episode>
<itunes:subtitle>DNS over TLS; Gootloader; AOL Phishing; Spectre in the Wild;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS over TLS; Gootloader; AOL Phishing; Spectre in the Wild;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7394.mp3" length="5527078" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7394.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7394</link>
<pubDate>Tue, 02 Mar 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Fun with DNS over TLS and<br/>
 <a href="https://isc.sans.edu/forums/diary/Fun+with+DNS+over+TLS+DoT/27150/">https://isc.sans.edu/forums/diary/Fun+with+DNS+over+TLS+DoT/27150/</a><br/>
Gootloader Update<br/>
 <a href="https://news.sophos.com/en-us/2021/03/01/gootloader-expands-its-payload-delivery-options/">https://news.sophos.com/en-us/2021/03/01/gootloader-expands-its-payload-delivery-options/</a><br/>
AOL Phishing<br/>
 <a href="https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/">https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/</a><br/>
Spectre Exploit in the Wild<br/>
 <a href="https://dustri.org/b/spectre-exploits-in-the-wild.html">https://dustri.org/b/spectre-exploits-in-the-wild.html</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7394" type="text/plain" language="en" />
<itunes:keywords>spectre, aol, gootloader, dns, tls, dot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7392</itunes:episode>
<itunes:subtitle>Outlook Phish; Port 26 Followup; Alexa Skills; TMobile Breach
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Outlook Phish; Port 26 Followup; Alexa Skills; TMobile Breach
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7392.mp3" length="4532777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7392.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7392</link>
<pubDate>Mon, 01 Mar 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Pretending to be an Outlook Version Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Pretending+to+be+an+Outlook+Version+Update/27144/">https://isc.sans.edu/forums/diary/Pretending+to+be+an+Outlook+Version+Update/27144/</a><br/>
Geolocating Satori Botnet Scanning Port 26<br/>
 <a href="https://isc.sans.edu/forums/diary/So+where+did+those+Satori+attacks+come+from/27140/">https://isc.sans.edu/forums/diary/So+where+did+those+Satori+attacks+come+from/27140/</a><br/>
Alexa Skill Security<br/>
 <a href="https://www.ndss-symposium.org/wp-content/uploads/ndss2021_5A-1_23111_paper.pdf">https://www.ndss-symposium.org/wp-content/uploads/ndss2021_5A-1_23111_paper.pdf</a><br/>
TMobile Data Breach / SIM Swapping <br/>
 <a href="https://beta.documentcloud.org/documents/20492859-t-mobile-feb-2021-bc-data-breach">https://beta.documentcloud.org/documents/20492859-t-mobile-feb-2021-bc-data-breach</a><br/>
]]></description>
<itunes:duration>5:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7392" type="text/plain" language="en" />
<itunes:keywords>tmobile, sim swapping, breach, geolocation, satori, part 26, alexa, outlook, phish, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 26th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7390</itunes:episode>
<itunes:subtitle>Forensicating Azure VMs; FriarFoxi; JSON Parsers; MacOS 11.2.2
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Forensicating Azure VMs; FriarFoxi; JSON Parsers; MacOS 11.2.2
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7390.mp3" length="4526576" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7390.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7390</link>
<pubDate>Fri, 26 Feb 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Forensicating Azure VMs<br/>
 <a href="https://isc.sans.edu/forums/diary/Forensicating+Azure+VMs/27136/">https://isc.sans.edu/forums/diary/Forensicating+Azure+VMs/27136/</a><br/>
FriarFox Browser Extension Targeting GMail Accounts<br/>
 <a href="https://www.proofpoint.com/us/blog/threat-insight/ta413-leverages-new-friarfox-browser-extension-target-gmail-accounts-global">https://www.proofpoint.com/us/blog/threat-insight/ta413-leverages-new-friarfox-browser-extension-target-gmail-accounts-global</a><br/>
JSON Parser Inconsistencies<br/>
 <a href="https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities">https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities</a><br/>
Apple MacOS Update<br/>
 <a href="https://www.reddit.com/r/macbook/comments/kge24m/dead_m1_mac_with_usbc_multiport_adapters/">https://www.reddit.com/r/macbook/comments/kge24m/dead_m1_mac_with_usbc_multiport_adapters/</a><br/>
]]></description>
<itunes:duration>5:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7390" type="text/plain" language="en" />
<itunes:keywords>apple, macos, usbc, json, parsers, friarfox, extention, tibet, gmail, azure, vms, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 25th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7388</itunes:episode>
<itunes:subtitle>GuLoader/Remcos RAT; vCenter RCE PoC; CNAME Tracking; Cisco MSO Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GuLoader/Remcos RAT; vCenter RCE PoC; CNAME Tracking; Cisco MSO Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7388.mp3" length="4831589" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7388.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7388</link>
<pubDate>Thu, 25 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Malspam Pushes GuLoader for Remcos RAT<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushes+GuLoader+for+Remcos+RAT/27132/">https://isc.sans.edu/forums/diary/Malspam+pushes+GuLoader+for+Remcos+RAT/27132/</a><br/>
vCenter Exploit / Vulnerability Details<br/>
 <a href="https://swarm.ptsecurity.com/unauth-rce-vmware/#more-2477">https://swarm.ptsecurity.com/unauth-rce-vmware/#more-2477</a><br/>
DNS CNAME Tracking <br/>
 <a href="https://blog.lukaszolejnik.com/large-scale-analysis-of-dns-based-tracking-evasion-broad-data-leaks-included/">https://blog.lukaszolejnik.com/large-scale-analysis-of-dns-based-tracking-evasion-broad-data-leaks-included/</a><br/>
Cisco MSO Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7388" type="text/plain" language="en" />
<itunes:keywords>cisco, mso, dns, cname, vcenter, exploit, rce, poc, malspam, guloader, remcosrat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 24th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7386</itunes:episode>
<itunes:subtitle>Malicious FD Reply; Firefox Cookies Protection; VMWare Update; Signed PDFs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious FD Reply; Firefox Cookies Protection; VMWare Update; Signed PDFs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7386.mp3" length="5458062" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7386.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7386</link>
<pubDate>Wed, 24 Feb 2021 02:05:03 GMT</pubDate>
<description><![CDATA[Qakbot In a Response to Full Disclosure Post<br/>
 <a href="https://isc.sans.edu/forums/diary/Qakbot+in+a+response+to+Full+Disclosure+post/27130/">https://isc.sans.edu/forums/diary/Qakbot+in+a+response+to+Full+Disclosure+post/27130/</a><br/>
Firefox Total Cookie Protection<br/>
 <a href="https://blog.mozilla.org/security/2021/02/23/total-cookie-protection/">https://blog.mozilla.org/security/2021/02/23/total-cookie-protection/</a><br/>
VMWare ESXi / vCenter Server Update<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2021-0002.html">https://www.vmware.com/security/advisories/VMSA-2021-0002.html</a><br/>
Replacing Content in Signed PDFs<br/>
 <a href="https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1B-4_24117_paper.pdf">https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1B-4_24117_paper.pdf</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7386" type="text/plain" language="en" />
<itunes:keywords>signed pdfs, vmware, esxi, vcenter, firefox, qakbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 23rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7384</itunes:episode>
<itunes:subtitle>Unprotecting Excel; Brave DNS Leak; Telephony DoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Unprotecting Excel; Brave DNS Leak; Telephony DoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7384.mp3" length="5134397" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7384.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7384</link>
<pubDate>Tue, 23 Feb 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Unprotecting Malicious Documents For Inspection<br/>
 <a href="https://isc.sans.edu/forums/diary/Unprotecting+Malicious+Documents+For+Inspection/27126/">https://isc.sans.edu/forums/diary/Unprotecting+Malicious+Documents+For+Inspection/27126/</a><br/>
Brave Browser DNS Leak<br/>
 <a href="https://www.theregister.com/2021/02/22/in_brief_security/">https://www.theregister.com/2021/02/22/in_brief_security/</a><br/>
Telephony DoS<br/>
 <a href="https://www.ic3.gov/Media/Y2021/PSA210217">https://www.ic3.gov/Media/Y2021/PSA210217</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7384" type="text/plain" language="en" />
<itunes:keywords>tdos, telephony, voip, 911, ios, brave browser, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7382</itunes:episode>
<itunes:subtitle>DDE is Back; More M1 Malware; Malformed URL Prefixes; Sonicwall SMA 100
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DDE is Back; More M1 Malware; Malformed URL Prefixes; Sonicwall SMA 100
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7382.mp3" length="5177913" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7382.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7382</link>
<pubDate>Mon, 22 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Dynamic Data Exchange (DDE) is Back in the Wild<br/>
 <a href="https://isc.sans.edu/forums/diary/Dynamic+Data+Exchange+DDE+is+Back+in+the+Wild/27116/">https://isc.sans.edu/forums/diary/Dynamic+Data+Exchange+DDE+is+Back+in+the+Wild/27116/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/DDE+and+oledump/27122/">https://isc.sans.edu/forums/diary/DDE+and+oledump/27122/</a><br/>
macOS Malware "Prototype"<br/>
 <a href="https://redcanary.com/blog/clipping-silver-sparrows-wings/">https://redcanary.com/blog/clipping-silver-sparrows-wings/</a><br/>
New Phishing Attack Identifed: Malformed URL Prefixes<br/>
 <a href="https://www.greathorn.com/blog-new-phishing-attack-identified-malformed-url-prefixes/">https://www.greathorn.com/blog-new-phishing-attack-identified-malformed-url-prefixes/</a><br/>
Sonicwall SMA 100 Firmware Update<br/>
 <a href="https://www.sonicwall.com/support/product-notification/additional-sma-100-series-10-x-and-9-x-firmware-updates-required-updated-feb-19-2-p-m-cst/210122173415410/">https://www.sonicwall.com/support/product-notification/additional-sma-100-series-10-x-and-9-x-firmware-updates-required-updated-feb-19-2-p-m-cst/210122173415410/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7382" type="text/plain" language="en" />
<itunes:keywords>sonicwall, sma 100, url prefixes, macos, m1, malware, dde, dynamic data exchange, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7380</itunes:episode>
<itunes:subtitle>Trickbot; AppleJeus; Python 3 Buffer Overflow; Apple Security Guide
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Trickbot; AppleJeus; Python 3 Buffer Overflow; Apple Security Guide
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7380.mp3" length="5068564" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7380.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7380</link>
<pubDate>Fri, 19 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Malspam Pushes Trickbot gtag rob13<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Trickbot+gtag+rob13/27112/">https://isc.sans.edu/forums/diary/Malspam+pushing+Trickbot+gtag+rob13/27112/</a><br/>
AppleJeus <br/>
<a href="https://us-cert.cisa.gov/ncas/alerts/aa21-048a">https://us-cert.cisa.gov/ncas/alerts/aa21-048a</a><br/>
Python 3 Buffer Overflow<br/>
 <a href="https://bugs.python.org/issue42938">https://bugs.python.org/issue42938</a><br/>
Apple Platform Security Guide<br/>
 <a href="https://support.apple.com/guide/security/welcome/web">https://support.apple.com/guide/security/welcome/web</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7380" type="text/plain" language="en" />
<itunes:keywords>apple, python, applejeus, trickbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7378</itunes:episode>
<itunes:subtitle>LinkedInSecureMessage Phish; M1 Malware; Masslogger; QNAP Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LinkedInSecureMessage Phish; M1 Malware; Masslogger; QNAP Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7378.mp3" length="5253258" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7378.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7378</link>
<pubDate>Thu, 18 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[The new "LinkedInSecureMessage" Phish<br/>
 <a href="https://isc.sans.edu/forums/diary/The+new+LinkedInSecureMessage/27110/">https://isc.sans.edu/forums/diary/The+new+LinkedInSecureMessage/27110/</a><br/>
Apple M1 Optimized Malware<br/>
 <a href="https://objective-see.com/blog/blog_0x62.html">https://objective-see.com/blog/blog_0x62.html</a><br/>
QNAP Surveilance Station Vulnerability<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-21-07">https://www.qnap.com/en/security-advisory/qsa-21-07</a><br/>
Masslogger Exfiltrates User Credentials<br/>
 <a href="https://blog.talosintelligence.com/2021/02/masslogger-cred-exfil.html">https://blog.talosintelligence.com/2021/02/masslogger-cred-exfil.html</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7378" type="text/plain" language="en" />
<itunes:keywords>masslogger, qnap, apple, m1, linkedin, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 17th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7376</itunes:episode>
<itunes:subtitle>Port 26; MSFT Servicing Stack; Centreon; NPM VSCode RCE;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Port 26; MSFT Servicing Stack; Centreon; NPM VSCode RCE;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7376.mp3" length="4713102" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7376.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7376</link>
<pubDate>Wed, 17 Feb 2021 02:05:03 GMT</pubDate>
<description><![CDATA[More Weirdness on TCP Port 26<br/>
 <a href="https://isc.sans.edu/forums/diary/More+weirdness+on+TCP+port+26/27106/">https://isc.sans.edu/forums/diary/More+weirdness+on+TCP+port+26/27106/</a><br/>
Microsoft Pulls Servicing Stack Update<br/>
 <a href="https://threatpost.com/microsoft-windows-update-patch-tuesday/163981/">https://threatpost.com/microsoft-windows-update-patch-tuesday/163981/</a><br/>
Network Monitoring Company Centreon Compromised<br/>
 <a href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf">https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf</a><br/>
SHAREit Flaw Could Lead to Remote Code Execution<br/>
 <a href="https://www.trendmicro.com/en_us/research/21/b/shareit-flaw-could-lead-to-remote-code-execution.html">https://www.trendmicro.com/en_us/research/21/b/shareit-flaw-could-lead-to-remote-code-execution.html</a><br/>
VSCode NPM Extension RCE<br/>
 <a href="https://github.com/jackadamson/CVE-2021-26700">https://github.com/jackadamson/CVE-2021-26700</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7376" type="text/plain" language="en" />
<itunes:keywords>npm, vscode, shareit, centreon, microsoft, servicing stack, tcp, port 26, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 16th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7374</itunes:episode>
<itunes:subtitle>pfSense vs Bufferbloat; Safer Safebrowsing; Power/Internet Outages; Phone Scam Success Rates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
pfSense vs Bufferbloat; Safer Safebrowsing; Power/Internet Outages; Phone Scam Success Rates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7374.mp3" length="5887768" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7374.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7374</link>
<pubDate>Tue, 16 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Securing and Optimizing Networks Using pfSense Traffic Shaper to Combat Bufferbloat<br/>
 <a href="https://isc.sans.edu/forums/diary/Securing+and+Optimizing+Networks+Using+pfSense+Traffic+Shaper+Limiters+to+Combat+Bufferbloat/27102/">https://isc.sans.edu/forums/diary/Securing+and+Optimizing+Networks+Using+pfSense+Traffic+Shaper+Limiters+to+Combat+Bufferbloat/27102/</a><br/>
Apple to Proxy Safe Browsing Requests<br/>
 <a href="https://twitter.com/othermaciej/status/1359736220809531393">https://twitter.com/othermaciej/status/1359736220809531393</a><br/>
Power Outages and Some Network Outages as a Result <br/>
 <a href="https://downdetector.com">https://downdetector.com</a><br/>
Phone Scam Success Rates<br/>
 <a href="https://www.helpnetsecurity.com/2021/02/15/lost-money-to-phone-scams/">https://www.helpnetsecurity.com/2021/02/15/lost-money-to-phone-scams/</a><br/>
 <a href="https://nakedsecurity.sophos.com/2021/02/12/sms-tax-scam-unmasked-bogus-but-believable-dont-fall-for-it/">https://nakedsecurity.sophos.com/2021/02/12/sms-tax-scam-unmasked-bogus-but-believable-dont-fall-for-it/</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7374" type="text/plain" language="en" />
<itunes:keywords>phone scam, sms, taxes, power outage, network outage, apple, safe browsing, pfsense, bufferbloat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7372</itunes:episode>
<itunes:subtitle>AgentTesla in CHM; Telegram Delivery Fraud; Accellion FTA Exploit; mHealth APIs; Bloomberg
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AgentTesla in CHM; Telegram Delivery Fraud; Accellion FTA Exploit; mHealth APIs; Bloomberg
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7372.mp3" length="6870438" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7372.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7372</link>
<pubDate>Mon, 15 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[AgentTesla Dropped Through Automatic Click in Microsoft Help File<br/>
 <a href="https://isc.sans.edu/forums/diary/AgentTesla+Dropped+Through+Automatic+Click+in+Microsoft+Help+File/27092/">https://isc.sans.edu/forums/diary/AgentTesla+Dropped+Through+Automatic+Click+in+Microsoft+Help+File/27092/</a><br/>
Telegram used to Defraud Delivery Serivces<br/>
 <a href="https://thefintechtimes.com/sift-finds-new-telegram-fraud-exploiting-increasing-use-of-food-delivery-services/">https://thefintechtimes.com/sift-finds-new-telegram-fraud-exploiting-increasing-use-of-food-delivery-services/</a><br/>
Singtel Suffers Zero-DAy Cyberattack<br/>
 <a href="https://threatpost.com/singtel-zero-day-cyberattack/163938/">https://threatpost.com/singtel-zero-day-cyberattack/163938/</a><br/>
Vulnerabilities in Mobile Health Apps<br/>
 <a href="https://approov.io/download/all-that-we-let-in_hacking-mhealth-apps-and-apis.pdf">https://approov.io/download/all-that-we-let-in_hacking-mhealth-apps-and-apis.pdf</a><br/>
Bloomberg Supermicro Story <br/>
 <a href="https://www.bloomberg.com/features/2021-supermicro/">https://www.bloomberg.com/features/2021-supermicro/</a><br/>
 <a href="https://www.theregister.com/2021/02/12/supermicro_bloomberg_spying/">https://www.theregister.com/2021/02/12/supermicro_bloomberg_spying/</a><br/>
]]></description>
<itunes:duration>7:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7372" type="text/plain" language="en" />
<itunes:keywords>bloomberg, mobile health, api, singtel, telegram, agent tesla, accellion, fta, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7370</itunes:episode>
<itunes:subtitle>Hidden Agent Tesla; McAfee Update; Intel Patches; Discord Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hidden Agent Tesla; McAfee Update; Intel Patches; Discord Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7370.mp3" length="5084656" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7370.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7370</link>
<pubDate>Fri, 12 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Agent Tesla Hidden in Historical Anti-Malware Tool<br/>
 <a href="https://isc.sans.edu/forums/diary/Agent+Tesla+hidden+in+a+historical+antimalware+tool/27088/">https://isc.sans.edu/forums/diary/Agent+Tesla+hidden+in+a+historical+antimalware+tool/27088/</a><br/>
McAfee Total Protection Vulnerabilities<br/>
 <a href="https://service.mcafee.com/webcenter/portal/oracle/webcenter/page/scopedMD/s55728c97_466d_4ddb_952d_05484ea932c6/Page29.jspx">https://service.mcafee.com/webcenter/portal/oracle/webcenter/page/scopedMD/s55728c97_466d_4ddb_952d_05484ea932c6/Page29.jspx</a><br/>
Intel Patches<br/>
 <a href="https://blogs.intel.com/technology/2021/02/ipas-security-advisories-for-february-2021">https://blogs.intel.com/technology/2021/02/ipas-security-advisories-for-february-2021</a><br/>
Discord Used to Distribute Malware<br/>
 <a href="https://www.zscaler.com/blogs/security-research/discord-cdn-popular-choice-hosting-malicious-payloads">https://www.zscaler.com/blogs/security-research/discord-cdn-popular-choice-hosting-malicious-payloads</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7370" type="text/plain" language="en" />
<itunes:keywords>discord, malware, patches, intel, mcafee, agent tesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7368</itunes:episode>
<itunes:subtitle>Simple Phish; Phishing Stats; Adobe Patch; Apple Patch; Stupid ISNs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Simple Phish; Phishing Stats; Adobe Patch; Apple Patch; Stupid ISNs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7368.mp3" length="5159921" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7368.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7368</link>
<pubDate>Thu, 11 Feb 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Phishing Message to the ISC Handlers E-Mail Distro<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+message+to+the+ISC+handlers+email+distro/27082/">https://isc.sans.edu/forums/diary/Phishing+message+to+the+ISC+handlers+email+distro/27082/</a><br/>
Google Phishing Statistics<br/>
 <a href="https://cloud.google.com/blog/products/workspace/how-gmail-helps-users-avoid-email-scams">https://cloud.google.com/blog/products/workspace/how-gmail-helps-users-avoid-email-scams</a><br/>
Adobe Security Updates<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb21-09.html">https://helpx.adobe.com/security/products/acrobat/apsb21-09.html</a><br/>
Apple Sudo Patch<br/>
 <a href="https://support.apple.com/en-us/HT212177">https://support.apple.com/en-us/HT212177</a><br/>
Number:Jack ISN Generation Weaknesses<br/>
 <a href="https://www.forescout.com/company/resources/numberjack-weak-isn-generation-in-embedded-tcpip-stacks/">https://www.forescout.com/company/resources/numberjack-weak-isn-generation-in-embedded-tcpip-stacks/</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7368" type="text/plain" language="en" />
<itunes:keywords>tcp/ip, tcp, sequence number, isn, number:jack, apple, sudo, adobe, reader, google, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 10th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7366</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Dependency Confusion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Dependency Confusion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7366.mp3" length="5782450" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7366.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7366</link>
<pubDate>Wed, 10 Feb 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+February+2021+Patch+Tuesday/27080/">https://isc.sans.edu/forums/diary/Microsoft+February+2021+Patch+Tuesday/27080/</a><br/>
 <a href="https://www.theregister.com/2021/02/09/microsoft_patch_tuesday/">https://www.theregister.com/2021/02/09/microsoft_patch_tuesday/</a><br/>
Dependency Confusion<br/>
 <a href="https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610">https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610</a><br/>
 <a href="https://azure.microsoft.com/mediahandler/files/resourcefiles/3-ways-to-mitigate-risk-using-private-package-feeds/3%20Ways%20to%20Mitigate%20Risk%20When%20Using%20Private%20Package%20Feeds%20-%20v1.0.pdf">https://azure.microsoft.com/mediahandler/files/resourcefiles/3-ways-to-mitigate-risk-using-private-package-feeds/3%20Ways%20to%20Mitigate%20Risk%20When%20Using%20Private%20Package%20Feeds%20-%20v1.0.pdf</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7366" type="text/plain" language="en" />
<itunes:keywords>dependency, npm, pip, python, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 9th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7364</itunes:episode>
<itunes:subtitle>Tshark Malware Analysis; Bad Barcode Scanner; Morse Code Obfuscation; Water Supply Hacked
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tshark Malware Analysis; Bad Barcode Scanner; Morse Code Obfuscation; Water Supply Hacked
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7364.mp3" length="5194004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7364.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7364</link>
<pubDate>Tue, 09 Feb 2021 02:35:02 GMT</pubDate>
<description><![CDATA[Tshark and Malware Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/Quickie+tshark+Malware+Analysis/27076/">https://isc.sans.edu/forums/diary/Quickie+tshark+Malware+Analysis/27076/</a><br/>
Barcode Scanner Going Bad<br/>
 <a href="https://blog.malwarebytes.com/android/2021/02/barcode-scanner-app-on-google-play-infects-10-million-users-with-one-update/">https://blog.malwarebytes.com/android/2021/02/barcode-scanner-app-on-google-play-infects-10-million-users-with-one-update/</a><br/>
Morse Code Obfuscation<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-phishing-attack-uses-morse-code-to-hide-malicious-urls/">https://www.bleepingcomputer.com/news/security/new-phishing-attack-uses-morse-code-to-hide-malicious-urls/</a><br/>
Firefox Update<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2021-06/">https://www.mozilla.org/en-US/security/advisories/mfsa2021-06/</a><br/>
Water Treatment Facility Compromised<br/>
 <a href="https://www.reuters.com/article/us-usa-cyber-florida/hackers-broke-into-florida-towns-water-treatment-plant-attempted-to-poison-supply-sheriff-says-idUSKBN2A82FV">https://www.reuters.com/article/us-usa-cyber-florida/hackers-broke-into-florida-towns-water-treatment-plant-attempted-to-poison-supply-sheriff-says-idUSKBN2A82FV</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7364" type="text/plain" language="en" />
<itunes:keywords>water treatment, lye, firefox, morse code, teamviewer, barcode, tshark, python, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7362</itunes:episode>
<itunes:subtitle>VBA Macros vs. Application Menus; Great Suspender Malware; Chrome 0Day; Plex DDoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBA Macros vs. Application Menus; Great Suspender Malware; Chrome 0Day; Plex DDoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7362.mp3" length="5347600" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7362.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7362</link>
<pubDate>Mon, 08 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[VBA Macro Trying to Alter the Application Menus<br/>
 <a href="https://isc.sans.edu/forums/diary/VBA+Macro+Trying+to+Alter+the+Application+Menus/27068/">https://isc.sans.edu/forums/diary/VBA+Macro+Trying+to+Alter+the+Application+Menus/27068/</a><br/>
The Great Suspender Going Malicious<br/>
 <a href="https://www.zdnet.com/article/google-kills-the-great-suspender-heres-what-you-should-do-next/">https://www.zdnet.com/article/google-kills-the-great-suspender-heres-what-you-should-do-next/</a><br/>
 <a href="https://github.com/greatsuspender/thegreatsuspender/issues/1263">https://github.com/greatsuspender/thegreatsuspender/issues/1263</a><br/>
Google Chrome Zero Day<br/>
 <a href="https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html">https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html</a><br/>
Plex Media SSDP Amplication DDoS<br/>
 <a href="https://www.netscout.com/blog/asert/plex-media-ssdp-pmssdp-reflectionamplification-ddos-attack">https://www.netscout.com/blog/asert/plex-media-ssdp-pmssdp-reflectionamplification-ddos-attack</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7362" type="text/plain" language="en" />
<itunes:keywords>plex, ssdp, ddos, google chrome, 0day, great suspender, vpa macro, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7360</itunes:episode>
<itunes:subtitle>Data Exfill via Google Sync; MSFT Defender False Pos; MSIE 0Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Data Exfill via Google Sync; MSFT Defender False Pos; MSIE 0Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7360.mp3" length="5727497" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7360.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7360</link>
<pubDate>Fri, 05 Feb 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Abusing Google Chrome Extension Syncing For Data Exfiltration and C&C<br/>
 <a href="https://isc.sans.edu/forums/diary/Abusing+Google+Chrome+extension+syncing+for+data+exfiltration+and+CC/27066/">https://isc.sans.edu/forums/diary/Abusing+Google+Chrome+extension+syncing+for+data+exfiltration+and+CC/27066/</a><br/>
Microsoft Defender ATP Google Chrome False Positive<br/>
 <a href="https://twitter.com/itquartz/status/1356940218138509312">https://twitter.com/itquartz/status/1356940218138509312</a><br/>
Social Engineering Attacks against Security Researchers Used IE 0 day<br/>
 <a href="https://enki.co.kr/blog/2021/02/04/ie_0day.html#">https://enki.co.kr/blog/2021/02/04/ie_0day.html#</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/hacking-group-also-used-an-ie-zero-day-against-security-researchers/">https://www.bleepingcomputer.com/news/security/hacking-group-also-used-an-ie-zero-day-against-security-researchers/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7360" type="text/plain" language="en" />
<itunes:keywords>ie 0 day, msft defender atp, google chrome, false positive, extension, data sync, google, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 4th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7358</itunes:episode>
<itunes:subtitle>From Excel to Cobalt Strike;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
From Excel to Cobalt Strike;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7358.mp3" length="5394705" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7358.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7358</link>
<pubDate>Thu, 04 Feb 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Excel Spreadsheets Push SystemBC Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Excel+spreadsheets+push+SystemBC+malware/27060/">https://isc.sans.edu/forums/diary/Excel+spreadsheets+push+SystemBC+malware/27060/</a><br/>
SolarWinds Vulnerability<br/>
 <a href="https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=28389">https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=28389</a><br/>
SolarWinds SANS Lightning Summit<br/>
 <a href="https://www.sans.org/webcasts/solarwinds-lightning-summit-118550">https://www.sans.org/webcasts/solarwinds-lightning-summit-118550</a><br/>
SonicWall Patch<br/>
 <a href="https://www.sonicwall.com/support/product-notification/urgent-patch-available-for-sma-100-series-10-x-firmware-zero-day-vulnerability-updated-feb-3-2-p-m-cst/210122173415410/">https://www.sonicwall.com/support/product-notification/urgent-patch-available-for-sma-100-series-10-x-firmware-zero-day-vulnerability-updated-feb-3-2-p-m-cst/210122173415410/</a><br/>
Cisco Advisories<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Realtek RTL8195A Wi-Fi Module Vulnerability<br/>
 <a href="https://www.vdoo.com/blog/realtek-rtl8195a-vulnerabilities-discovered">https://www.vdoo.com/blog/realtek-rtl8195a-vulnerabilities-discovered</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7358" type="text/plain" language="en" />
<itunes:keywords>realtek, cisco, apple, macos, sudo, sonicwall, solarwinds, excel, systembc, cobalt strike, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 3rd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7356</itunes:episode>
<itunes:subtitle>XSL Script Malware; Camerafirma CA; Kobalos HPC Malware; Agent Tesla vs. AMSI
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XSL Script Malware; Camerafirma CA; Kobalos HPC Malware; Agent Tesla vs. AMSI
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7356.mp3" length="5441962" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7356.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7356</link>
<pubDate>Wed, 03 Feb 2021 11:25:02 GMT</pubDate>
<description><![CDATA[New Example of XSL Script Processing aka "Mitre T1220"<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Example+of+XSL+Script+Processing+aka+Mitre+T1220/27056/">https://isc.sans.edu/forums/diary/New+Example+of+XSL+Script+Processing+aka+Mitre+T1220/27056/</a><br/>
Camerfirma Certificate Authority Revocation<br/>
 <a href="https://groups.google.com/g/mozilla.dev.security.policy/c/jif4zWNgGPw">https://groups.google.com/g/mozilla.dev.security.policy/c/jif4zWNgGPw</a><br/>
Kobalos HPC Linux Malware<br/>
 <a href="https://www.welivesecurity.com/2021/02/02/kobalos-complex-linux-threat-high-performance-computing-infrastructure/">https://www.welivesecurity.com/2021/02/02/kobalos-complex-linux-threat-high-performance-computing-infrastructure/</a><br/>
Agent Tesla Overwries Windows AMSI<br/>
 <a href="https://threatpost.com/agent-tesla-microsoft-asmi/163581/">https://threatpost.com/agent-tesla-microsoft-asmi/163581/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7356" type="text/plain" language="en" />
<itunes:keywords>agent tesla, amsi, kobalos, hpc, comerfirma, xsl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 2nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7354</itunes:episode>
<itunes:subtitle>MacOS Update; Objective-See Open Source; iMessage Blastdoor; SonicWall Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS Update; Objective-See Open Source; iMessage Blastdoor; SonicWall Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7354.mp3" length="5442244" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7354.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7354</link>
<pubDate>Tue, 02 Feb 2021 02:00:02 GMT</pubDate>
<description><![CDATA[MacOS 11.2 Update<br/>
 <a href="https://support.apple.com/en-us/HT212147">https://support.apple.com/en-us/HT212147</a><br/>
Objective-See Tools Now Open Sources<br/>
 <a href="https://twitter.com/patrickwardle/status/1356149073045143553">https://twitter.com/patrickwardle/status/1356149073045143553</a><br/>
iMessage Blastdoor<br/>
 <a href="https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html">https://googleprojectzero.blogspot.com/2021/01/a-look-at-imessage-in-ios-14.html</a><br/>
SonicWall Update<br/>
 <a href="https://www.sonicwall.com/support/product-notification/urgent-security-notice-sonicwall-confirms-sma-100-series-10-x-zero-day-vulnerability-feb-1-2-p-m-cst/210122173415410/">https://www.sonicwall.com/support/product-notification/urgent-security-notice-sonicwall-confirms-sma-100-series-10-x-zero-day-vulnerability-feb-1-2-p-m-cst/210122173415410/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7354" type="text/plain" language="en" />
<itunes:keywords>sonicwall, imessage, blastdoor, objective-see, macos, 11.2, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 1st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7352</itunes:episode>
<itunes:subtitle>Perl.com / SpamCop Domain Issues; libgcrypt vulnerability; Fingerprinting QUIC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Perl.com / SpamCop Domain Issues; libgcrypt vulnerability; Fingerprinting QUIC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7352.mp3" length="4861566" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7352.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7352</link>
<pubDate>Mon, 01 Feb 2021 02:30:03 GMT</pubDate>
<description><![CDATA[Perl.com Domain Hijacked<br/>
 <a href="https://www.ehackingnews.com/2021/01/perlcom-official-site-for-perl.html">https://www.ehackingnews.com/2021/01/perlcom-official-site-for-perl.html</a><br/>
Spamcop Domain Expired<br/>
 <a href="https://www.bleepingcomputer.com/news/security/spamcop-anti-spam-service-suffers-an-outage-after-its-domain-expired/">https://www.bleepingcomputer.com/news/security/spamcop-anti-spam-service-suffers-an-outage-after-its-domain-expired/</a><br/>
libgcrypt vulnerability<br/>
 <a href="https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.html">https://lists.gnupg.org/pipermail/gnupg-announce/2021q1/000456.html</a><br/>
Fingerprinting QUIC<br/>
 <a href="https://arxiv.org/pdf/2101.11871.pdf">https://arxiv.org/pdf/2101.11871.pdf</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7352" type="text/plain" language="en" />
<itunes:keywords>quic, libgcrypt, spamcop, perl, domain, hijack, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 29th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7350</itunes:episode>
<itunes:subtitle>Cryptojacking Worm; Slip Streaming 2.0; Shadowsocks Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cryptojacking Worm; Slip Streaming 2.0; Shadowsocks Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7350.mp3" length="5366983" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7350.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7350</link>
<pubDate>Fri, 29 Jan 2021 02:00:02 GMT</pubDate>
<description><![CDATA[New Cryptojacking Malware<br/>
 <a href="https://unit42.paloaltonetworks.com/pro-ocean-rocke-groups-new-cryptojacking-malware/">https://unit42.paloaltonetworks.com/pro-ocean-rocke-groups-new-cryptojacking-malware/</a><br/>
SlipStreaming <br/>
 <a href="https://www.armis.com/resources/iot-security-blog/nat-slipstreaming-v2-0-new-attack-variant-can-expose-all-internal-network-devices-to-the-internet/">https://www.armis.com/resources/iot-security-blog/nat-slipstreaming-v2-0-new-attack-variant-can-expose-all-internal-network-devices-to-the-internet/</a><br/>
Shadowsocks<br/>
 <a href="https://shadowsocks.org/en/index.html">https://shadowsocks.org/en/index.html</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7350" type="text/plain" language="en" />
<itunes:keywords>shadowsocks, slip streaming, cryptojacking, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 28th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7348</itunes:episode>
<itunes:subtitle>Emotet Takedown and Attack Surface Reduction; Go Lang Vuln; Azure Docker Escape
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Takedown and Attack Surface Reduction; Go Lang Vuln; Azure Docker Escape
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7348.mp3" length="5579471" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7348.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7348</link>
<pubDate>Thu, 28 Jan 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Emotet vs. Windows Attack Surface Reduction<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+vs+Windows+Attack+Surface+Reduction/27036/">https://isc.sans.edu/forums/diary/Emotet+vs+Windows+Attack+Surface+Reduction/27036/</a><br/>
Go Lang Vulnerability<br/>
 <a href="https://blog.golang.org/path-security">https://blog.golang.org/path-security</a><br/>
Azure Docker Escape<br/>
 <a href="https://www.intezer.com/blog/research/how-we-hacked-azure-functions-and-escaped-docker/">https://www.intezer.com/blog/research/how-we-hacked-azure-functions-and-escaped-docker/</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7348" type="text/plain" language="en" />
<itunes:keywords>azure, functions, docker, escape, go, emotet, attack surface, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 27th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7346</itunes:episode>
<itunes:subtitle>sudo vulnerability; Quakbot Update; Targeting Security Researchers; Apple Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
sudo vulnerability; Quakbot Update; Targeting Security Researchers; Apple Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7346.mp3" length="5916584" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7346.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7346</link>
<pubDate>Wed, 27 Jan 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Critical sudo Vulnerability<br/>
 <a href="https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit">https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit</a><br/>
Quakbot (QBot) Update<br/>
 <a href="https://isc.sans.edu/forums/diary/TA551+Shathak+Word+docs+push+Qakbot+Qbot/27030/">https://isc.sans.edu/forums/diary/TA551+Shathak+Word+docs+push+Qakbot+Qbot/27030/</a><br/>
Targeting Security Researchers<br/>
 <a href="https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/">https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/</a><br/>
Apple Updates iOS, iPad, tvOS, watchOS, Xcode and iCloud for Windows<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7346" type="text/plain" language="en" />
<itunes:keywords>ios, ipados, tvos, watchos, xcode, icloude, apple, google, quakbot, qgot, sudo, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 26th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7344</itunes:episode>
<itunes:subtitle>Hunting DoH Endpoints; Malicious NPM; Mitigating $I30; Proton VPN BSOD
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hunting DoH Endpoints; Malicious NPM; Mitigating $I30; Proton VPN BSOD
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7344.mp3" length="4318484" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7344.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7344</link>
<pubDate>Tue, 26 Jan 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Fun With nmap nse Scripts and DoH (DNS over HTTPS)<br/>
 <a href="https://isc.sans.edu/forums/diary/Fun+with+NMAP+NSE+Scripts+and+DOH+DNS+over+HTTPS/27026/">https://isc.sans.edu/forums/diary/Fun+with+NMAP+NSE+Scripts+and+DOH+DNS+over+HTTPS/27026/</a><br/>
Malicious NPM Module Stealing Discord Passwords<br/>
 <a href="https://blog.sonatype.com/cursedgrabber-strikes-again-sonatype-spots-new-malware-campaign-against-software-supply-chains">https://blog.sonatype.com/cursedgrabber-strikes-again-sonatype-spots-new-malware-campaign-against-software-supply-chains</a><br/>
Mitigating the $I30 Bug<br/>
 <a href="https://www.osr.com/blog/2021/01/21/mitigating-the-i30bitmap-ntfs-bug/">https://www.osr.com/blog/2021/01/21/mitigating-the-i30bitmap-ntfs-bug/</a><br/>
 <a href="https://github.com/OSRDrivers/i30Flt">https://github.com/OSRDrivers/i30Flt</a><br/>
ProtonVPN BSOD<br/>
 <a href="https://protonstatus.com/incidents/124">https://protonstatus.com/incidents/124</a><br/>
]]></description>
<itunes:duration>4:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7344" type="text/plain" language="en" />
<itunes:keywords>protonvpn, bsod, $i30, ntfs, patch, npm, doh, nmap, nse, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 25th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7342</itunes:episode>
<itunes:subtitle>JNLP Malware; SonicWall Breach/Vuln; iObit Breach/Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JNLP Malware; SonicWall Breach/Vuln; iObit Breach/Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7342.mp3" length="5311760" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7342.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7342</link>
<pubDate>Mon, 25 Jan 2021 02:10:03 GMT</pubDate>
<description><![CDATA[Another File Extension to Block: JNLP<br/>
 <a href="https://isc.sans.edu/forums/diary/Another+File+Extension+to+Block+in+your+MTA+jnlp/27018/">https://isc.sans.edu/forums/diary/Another+File+Extension+to+Block+in+your+MTA+jnlp/27018/</a><br/>
SonicWall Vulnerability Used to Breach SonicWall<br/>
 <a href="https://www.sonicwall.com/support/product-notification/urgent-security-notice-netextender-vpn-client-10-x-sma-100-series-vulnerability-updated-jan-23-2021/210122173415410/">https://www.sonicwall.com/support/product-notification/urgent-security-notice-netextender-vpn-client-10-x-sma-100-series-vulnerability-updated-jan-23-2021/210122173415410/</a><br/>
iObit Forum Breached / Used for Ransomware Distribution<br/>
 <a href="https://www.bleepingcomputer.com/forums/t/741190/derohe-ransomware-distributed-through-fake-iobit-one-year-free-license-key-promo/">https://www.bleepingcomputer.com/forums/t/741190/derohe-ransomware-distributed-through-fake-iobit-one-year-free-license-key-promo/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7342" type="text/plain" language="en" />
<itunes:keywords>iobit, forum, ransomware, sonicwall, jnlp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 22nd, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7340</itunes:episode>
<itunes:subtitle>PS RunSpaces and REvil; SAP Exploit; Oracle Patches; RDP DDoS; High Performance Computing @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PS RunSpaces and REvil; SAP Exploit; Oracle Patches; RDP DDoS; High Performance Computing @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7340.mp3" length="11925623" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7340.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7340</link>
<pubDate>Fri, 22 Jan 2021 02:05:03 GMT</pubDate>
<description><![CDATA[Powershell Ropping REvil Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/Powershell+Dropping+a+REvil+Ransomware/27012/">https://isc.sans.edu/forums/diary/Powershell+Dropping+a+REvil+Ransomware/27012/</a><br/>
SAP Exploit Circulating<br/>
 <a href="https://onapsis.com/blog/new-sap-exploit-published-online-how-stay-secure">https://onapsis.com/blog/new-sap-exploit-published-online-how-stay-secure</a><br/>
Oracle Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpujan2021.html">https://www.oracle.com/security-alerts/cpujan2021.html</a><br/>
RDP Used for DDoS<br/>
 <a href="https://www.netscout.com/blog/asert/microsoft-remote-desktop-protocol-rdp-reflectionamplification">https://www.netscout.com/blog/asert/microsoft-remote-desktop-protocol-rdp-reflectionamplification</a><br/>
Billy Wilson: Mitigating Attacks Against Supercomputers with KRSI<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/linux/mitigating-attacks-supercomputer-krsi-40010">https://www.sans.org/reading-room/whitepapers/linux/mitigating-attacks-supercomputer-krsi-40010</a><br/>
]]></description>
<itunes:duration>13:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7340" type="text/plain" language="en" />
<itunes:keywords>krsi, sans_edu, billy milson, supwercomputers, hpsc, rdp, ddos, oracle, patches, SAP, Powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 21st, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7338</itunes:episode>
<itunes:subtitle>SolarWinds Updates; Cisco Advisories; WebRTC State Issues; Oracle BI XSS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SolarWinds Updates; Cisco Advisories; WebRTC State Issues; Oracle BI XSS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7338.mp3" length="6327722" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7338.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7338</link>
<pubDate>Thu, 21 Jan 2021 03:10:03 GMT</pubDate>
<description><![CDATA[SolarWinds Updates<br/>
 <a href="https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/">https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/</a><br/>
 <a href="https://blog.malwarebytes.com/malwarebytes-news/2021/01/malwarebytes-targeted-by-nation-state-actor-implicated-in-solarwinds-breach-evidence-suggests-abuse-of-privileged-access-to-microsoft-office-365-and-azure-environments/">https://blog.malwarebytes.com/malwarebytes-news/2021/01/malwarebytes-targeted-by-nation-state-actor-implicated-in-solarwinds-breach-evidence-suggests-abuse-of-privileged-access-to-microsoft-office-365-and-azure-environments/</a><br/>
Cisco Advisories<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-bufovulns-B5NrSHbj">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-bufovulns-B5NrSHbj</a><br/>
Evesdropping Vulnerabilities in Various WebRTC Based Video Conferencing Systems<br/>
 <a href="https://googleprojectzero.blogspot.com/2021/01/the-state-of-state-machines.html">https://googleprojectzero.blogspot.com/2021/01/the-state-of-state-machines.html</a><br/>
Oracle Business Intelligence Enterprise Edition XSS<br/>
 <a href="https://www.exploit-db.com/exploits/49444">https://www.exploit-db.com/exploits/49444</a><br/>
 <br/>
]]></description>
<itunes:duration>7:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7338" type="text/plain" language="en" />
<itunes:keywords>evesdropping, signal, webrtc, facetime, cisco, solarwinds, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 20th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7336</itunes:episode>
<itunes:subtitle>Qakbot Back From Holiday; dnsmasq vulnerabilities; Freakout Malware; Kids Break Screensaver
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Qakbot Back From Holiday; dnsmasq vulnerabilities; Freakout Malware; Kids Break Screensaver
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7336.mp3" length="5196206" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7336.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7336</link>
<pubDate>Wed, 20 Jan 2021 02:15:02 GMT</pubDate>
<description><![CDATA[Qakbot Activity Resumes After Holiday Break<br/>
 <a href="https://isc.sans.edu/forums/diary/Qakbot+activity+resumes+after+holiday+break/27008/">https://isc.sans.edu/forums/diary/Qakbot+activity+resumes+after+holiday+break/27008/</a><br/>
Multiple dnsmasq Vulnerabilities<br/>
 <a href="https://www.jsof-tech.com/wp-content/uploads/2021/01/DNSpooq_Technical-Whitepaper.pdf">https://www.jsof-tech.com/wp-content/uploads/2021/01/DNSpooq_Technical-Whitepaper.pdf</a><br/>
FreakOut Malware<br/>
 <a href="https://blog.checkpoint.com/2021/01/19/linux-users-should-patch-now-to-block-new-freakout-malware-which-exploits-new-vulnerabilities/">https://blog.checkpoint.com/2021/01/19/linux-users-should-patch-now-to-block-new-freakout-malware-which-exploits-new-vulnerabilities/</a><br/>
Kids Break Screensaver<br/>
 <a href="https://github.com/linuxmint/cinnamon-screensaver/issues/354">https://github.com/linuxmint/cinnamon-screensaver/issues/354</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7336" type="text/plain" language="en" />
<itunes:keywords>kids, linux, screensaver, freakout, dnsmasq, qakbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 19th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7334</itunes:episode>
<itunes:subtitle>Malicious Document; CIS Cisco NX-OS Benchmark; Shazam Geolocation; Social Engineering via VoIP/Messaging
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Document; CIS Cisco NX-OS Benchmark; Shazam Geolocation; Social Engineering via VoIP/Messaging
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7334.mp3" length="5133581" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7334.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7334</link>
<pubDate>Tue, 19 Jan 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Doc And RTF Malicious Document<br/>
 <a href="https://isc.sans.edu/forums/diary/Doc+RTF+Malicious+Document/26996/">https://isc.sans.edu/forums/diary/Doc+RTF+Malicious+Document/26996/</a><br/>
Center for Internet Security Cisco NX-OS Benchmark<br/>
 <a href="https://www.cisecurity.org/cis-benchmarks/">https://www.cisecurity.org/cis-benchmarks/</a><br/>
Exploit for Shazam Geolocation Vulnerablity<br/>
 <a href="https://ash-king.co.uk/blog/Shazlocate-abusing-CVE-2019-8791-CVE-2019-8792">https://ash-king.co.uk/blog/Shazlocate-abusing-CVE-2019-8791-CVE-2019-8792</a><br/>
Voice Phishing and Internal Messaging Systems Used to Escalate Privileges<br/>
 <a href="https://www.ic3.gov/Media/News/2021/210115.pdf">https://www.ic3.gov/Media/News/2021/210115.pdf</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7334" type="text/plain" language="en" />
<itunes:keywords>vishing, fbi, exploit, shazam, cid, cisco, nx-os, doc, rtf, maldoc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 18th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7332</itunes:episode>
<itunes:subtitle>DNS over HTTPs; Netlogon DC Encforcement Mode; Apple Removing Firewall Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS over HTTPs; Netlogon DC Encforcement Mode; Apple Removing Firewall Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7332.mp3" length="4662172" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7332.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7332</link>
<pubDate>Mon, 18 Jan 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Scans for DNS over HTTPs<br/>
 <a href="https://isc.sans.edu/forums/diary/Obfuscated+DNS+Queries/26992/">https://isc.sans.edu/forums/diary/Obfuscated+DNS+Queries/26992/</a><br/>
 <a href="https://us-cert.cisa.gov/ncas/current-activity/2021/01/15/nsa-releases-guidance-encrypted-dns-enterprise-environments">https://us-cert.cisa.gov/ncas/current-activity/2021/01/15/nsa-releases-guidance-encrypted-dns-enterprise-environments</a><br/>
Netlogon Domain Controller Enforcement Mode Starting February 9th<br/>
 <a href="https://msrc-blog.microsoft.com/2021/01/14/netlogon-domain-controller-enforcement-mode-is-enabled-by-default-beginning-with-the-february-9-2021-security-update-related-to-cve-2020-1472/">https://msrc-blog.microsoft.com/2021/01/14/netlogon-domain-controller-enforcement-mode-is-enabled-by-default-beginning-with-the-february-9-2021-security-update-related-to-cve-2020-1472/</a><br/>
Apple Removing ContentFilterExclusionList<br/>
 <a href="https://www.patreon.com/posts/46179028">https://www.patreon.com/posts/46179028</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7332" type="text/plain" language="en" />
<itunes:keywords>contentfilterexclusionlist, big sur, macos 11, firewall, apple, netlogon, zerologon, domain controller, dns, https, doh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 15th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7330</itunes:episode>
<itunes:subtitle>Dynamic Excel 4 Analysis; NTFS Corruption; Cisco Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dynamic Excel 4 Analysis; NTFS Corruption; Cisco Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7330.mp3" length="4399303" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7330.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7330</link>
<pubDate>Fri, 15 Jan 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Dynamically Analzying A Heavily Obfuscted Excel 4 Macro Malicious File<br/>
 <a href="https://isc.sans.edu/forums/diary/Dynamically+analyzing+a+heavily+obfuscated+Excel+4+macro+malicious+file/26986/">https://isc.sans.edu/forums/diary/Dynamically+analyzing+a+heavily+obfuscated+Excel+4+macro+malicious+file/26986/</a><br/>
Odd Filename Corrupts NTFS Disks<br/>
 <a href="https://twitter.com/jonasLyk/status/1347900440000811010">https://twitter.com/jonasLyk/status/1347900440000811010</a><br/>
Cisco Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
]]></description>
<itunes:duration>4:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7330" type="text/plain" language="en" />
<itunes:keywords>cisco, eol, ntfs, icon, filename, excel, spear phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 14th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7328</itunes:episode>
<itunes:subtitle>Hancitor is Back; Intel Anti Ransomware; Clouds Rain; SAP Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hancitor is Back; Intel Anti Ransomware; Clouds Rain; SAP Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7328.mp3" length="5379345" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7328.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7328</link>
<pubDate>Thu, 14 Jan 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Hancitor Activity Resumes After a Holiday Break<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+activity+resumes+after+a+hoilday+break/26980/">https://isc.sans.edu/forums/diary/Hancitor+activity+resumes+after+a+hoilday+break/26980/</a><br/>
Intel Hardware-Enabled Ransomware Protections<br/>
 <a href="https://www.cybereason.com/blog/cybereason-and-intel-introduce-hardware-enabled-ransomware-protections-for-businesses">https://www.cybereason.com/blog/cybereason-and-intel-introduce-hardware-enabled-ransomware-protections-for-businesses</a><br/>
Making Clouds Rain: RCE in Microsoft Office 365<br/>
 <a href="https://srcincite.io/blog/2021/01/12/making-clouds-rain-rce-in-office-365.html#fn:1">https://srcincite.io/blog/2021/01/12/making-clouds-rain-rce-in-office-365.html#fn:1</a><br/>
SAP Security Patch Day<br/>
 <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476">https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7328" type="text/plain" language="en" />
<itunes:keywords>sap, clouds, rce, office 365, interl, ransomware, hancitor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 13th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7326</itunes:episode>
<itunes:subtitle>MSFT Patches; Adobe Patches; Mimecast Cert Stolen; Leaking Silhouettes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patches; Adobe Patches; Mimecast Cert Stolen; Leaking Silhouettes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7326.mp3" length="5512549" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7326.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7326</link>
<pubDate>Wed, 13 Jan 2021 02:15:02 GMT</pubDate>
<description><![CDATA[MSFT January 2021 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+January+2021+Patch+Tuesday/26978/">https://isc.sans.edu/forums/diary/Microsoft+January+2021+Patch+Tuesday/26978/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
MimeCast Cert Stolen<br/>
 <a href="https://www.mimecast.com/blog/important-update-from-mimecast/">https://www.mimecast.com/blog/important-update-from-mimecast/</a><br/>
Leaking Silhouettes of Cross-Origin Images<br/>
 <a href="https://blog.mozilla.org/attack-and-defense/2021/01/11/leaking-silhouettes-of-cross-origin-images/">https://blog.mozilla.org/attack-and-defense/2021/01/11/leaking-silhouettes-of-cross-origin-images/</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7326" type="text/plain" language="en" />
<itunes:keywords>silhouettes, cross-origin, images, mimecast, adobe, msft, patches, updates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 12th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7324</itunes:episode>
<itunes:subtitle>NVD CVEScan; Sysinternals Update; Ubiquity Breach; Run-Only AppleScript Reversing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NVD CVEScan; Sysinternals Update; Ubiquity Breach; Run-Only AppleScript Reversing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7324.mp3" length="5303353" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7324.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7324</link>
<pubDate>Tue, 12 Jan 2021 02:00:02 GMT</pubDate>
<description><![CDATA[Using the NVD Database API Part 3/3<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+the+NVD+Database+and+API+to+Keep+Up+with+Vulnerabilities+and+Patches+Tool+Drop+CVEScan+Part+3+of+3/26974/">https://isc.sans.edu/forums/diary/Using+the+NVD+Database+and+API+to+Keep+Up+with+Vulnerabilities+and+Patches+Tool+Drop+CVEScan+Part+3+of+3/26974/</a><br/>
Sysinternals Update<br/>
 <a href="https://docs.microsoft.com/en-us/sysinternals/">https://docs.microsoft.com/en-us/sysinternals/</a><br/>
Ubiquiti Breach<br/>
 <a href="https://www.bleepingcomputer.com/news/security/networking-giant-ubiquiti-alerts-customers-of-potential-data-breach/">https://www.bleepingcomputer.com/news/security/networking-giant-ubiquiti-alerts-customers-of-potential-data-breach/</a><br/>
Run-Only AppleScript Reversing<br/>
 <a href="https://labs.sentinelone.com/fade-dead-adventures-in-reversing-malicious-run-only-applescripts/">https://labs.sentinelone.com/fade-dead-adventures-in-reversing-malicious-run-only-applescripts/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7324" type="text/plain" language="en" />
<itunes:keywords>run-only, apple script, macos, ubiquiti, unifi, breach, sysinternals, nvd, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 11th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7322</itunes:episode>
<itunes:subtitle>String Analysis; CVSS Reliability; Trump Video Malware; Covid Vacine Smishing; dnsrecon
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
String Analysis; CVSS Reliability; Trump Video Malware; Covid Vacine Smishing; dnsrecon
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7322.mp3" length="5170149" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7322.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7322</link>
<pubDate>Mon, 11 Jan 2021 02:05:02 GMT</pubDate>
<description><![CDATA[Maldoc Strings Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+Strings+Analysis/26966/">https://isc.sans.edu/forums/diary/Maldoc+Strings+Analysis/26966/</a><br/>
CVSS Reliablity Survey<br/>
 <a href="https://user-surveys.cs.fau.de/index.php?r=survey/index&sid=248857">https://user-surveys.cs.fau.de/index.php?r=survey/index&sid=248857</a><br/>
Fake Trump Video Malware<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/updated-qnode-rat-downloader-distributed-as-trump-video-scandal/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/updated-qnode-rat-downloader-distributed-as-trump-video-scandal/</a><br/>
SMS Phishing (Smishing)<br/>
 <a href="https://www.bbc.com/news/business-55563748">https://www.bbc.com/news/business-55563748</a><br/>
dnsren vulnerability<br/>
 <a href="https://www.exploit-db.com/exploits/49394">https://www.exploit-db.com/exploits/49394</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7322" type="text/plain" language="en" />
<itunes:keywords>dnsrecon, sms, phishing, smishing, trump video, malware, cvss, survey, maldoc, strings, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 8th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7320</itunes:episode>
<itunes:subtitle>NIST NVD API; Titan Security Key; Great Suspender Malware; Gnome Desktop Forensics @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NIST NVD API; Titan Security Key; Great Suspender Malware; Gnome Desktop Forensics @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7320.mp3" length="13610545" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7320.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7320</link>
<pubDate>Fri, 08 Jan 2021 02:30:02 GMT</pubDate>
<description><![CDATA[Using the NIST Database and API to Keep Up with Vulnerabilities<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+the+NIST+Database+and+API+to+Keep+Up+with+Vulnerabilities+and+Patches+Part+1+of+3/26958/">https://isc.sans.edu/forums/diary/Using+the+NIST+Database+and+API+to+Keep+Up+with+Vulnerabilities+and+Patches+Part+1+of+3/26958/</a><br/>
Titan Security Key<br/>
 <a href="https://ninjalab.io/wp-content/uploads/2021/01/a_side_journey_to_titan.pdf">https://ninjalab.io/wp-content/uploads/2021/01/a_side_journey_to_titan.pdf</a><br/>
The Great Suspender Google Chrome Extension<br/>
 <a href="https://www.theregister.com/2021/01/07/great_suspender_malware/">https://www.theregister.com/2021/01/07/great_suspender_malware/</a><br/>
Brian Nishida: Ubuntu Artifacts Generated by Gnome Desktop Environment<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/forensics/ubuntu-artifacts-generated-gnome-desktop-environment-40035">https://www.sans.org/reading-room/whitepapers/forensics/ubuntu-artifacts-generated-gnome-desktop-environment-40035</a><br/>
]]></description>
<itunes:duration>15:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7320" type="text/plain" language="en" />
<itunes:keywords>suspender, google, chrome, titan, u2f, fido2, nisc, nvd, api, sans_edu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 7th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7318</itunes:episode>
<itunes:subtitle>Zyxel Exploitation; Fortinet Patches; Foxit PhatomPDF; Firefox Android Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zyxel Exploitation; Fortinet Patches; Foxit PhatomPDF; Firefox Android Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7318.mp3" length="3987513" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7318.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7318</link>
<pubDate>Thu, 07 Jan 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Zyxel Exploitation Under Way<br/>
 <a href="https://isc.sans.edu/forums/diary/Scans+for+Zyxel+Backdoors+are+Commencing/26954/">https://isc.sans.edu/forums/diary/Scans+for+Zyxel+Backdoors+are+Commencing/26954/</a><br/>
Fortinet Patches<br/>
 <a href="https://www.fortiguard.com/psirt?date=01-2021">https://www.fortiguard.com/psirt?date=01-2021</a><br/>
Foxit PhantomPDF Patches<br/>
 <a href="https://www.foxitsoftware.com/support/security-bulletins.html">https://www.foxitsoftware.com/support/security-bulletins.html</a><br/>
Firefox Android Updates<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2021-01/">https://www.mozilla.org/en-US/security/advisories/mfsa2021-01/</a><br/>
]]></description>
<itunes:duration>4:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7318" type="text/plain" language="en" />
<itunes:keywords>foxit, fortinet, zyxel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 6th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7316</itunes:episode>
<itunes:subtitle>Netfox Detective; ElectroRAT; Chrome to Prefer https; Android Patches; Telegram Location bug/feature
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Netfox Detective; ElectroRAT; Chrome to Prefer https; Android Patches; Telegram Location bug/feature
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7316.mp3" length="5242282" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7316.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7316</link>
<pubDate>Wed, 06 Jan 2021 02:35:03 GMT</pubDate>
<description><![CDATA[Netfox Detective: An Alternative Open-Source Packet Analysis Tool<br/>
 <a href="https://isc.sans.edu/forums/diary/Netfox+Detective+An+Alternative+OpenSource+Packet+Analysis+Tool/26950/">https://isc.sans.edu/forums/diary/Netfox+Detective+An+Alternative+OpenSource+Packet+Analysis+Tool/26950/</a><br/>
ElectroRAT Drains Cryptocurrency Accounts<br/>
 <a href="https://www.intezer.com/blog/research/operation-ElectroRAT-attacker-creates-fake-companies-to-drain-your-crypto-wallets/">https://www.intezer.com/blog/research/operation-ElectroRAT-attacker-creates-fake-companies-to-drain-your-crypto-wallets/</a><br/>
Chrome Will Prefer HTTPS over HTTP By Default<br/>
 <a href="https://chromium-review.googlesource.com/c/chromium/src/+/2568448">https://chromium-review.googlesource.com/c/chromium/src/+/2568448</a><br/>
Android January Patch Day<br/>
 <a href="https://source.android.com/security/bulletin/2021-01-01">https://source.android.com/security/bulletin/2021-01-01</a><br/>
Telegram Publishes Users' Locations Online<br/>
 <a href="https://blog.ahmed.nyc/2021/01/if-you-use-this-feature-on-telegram.html">https://blog.ahmed.nyc/2021/01/if-you-use-this-feature-on-telegram.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7316" type="text/plain" language="en" />
<itunes:keywords>telegram, gps, location, android, chrome, google, tls, https, electrorat, cryptocurrencies, netfox, pcap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 5th, 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7314</itunes:episode>
<itunes:subtitle>From Small BAT to Infostealer; Citrix DTLS Flaw; Zend Deserialization
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
From Small BAT to Infostealer; Citrix DTLS Flaw; Zend Deserialization
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7314.mp3" length="4850221" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7314.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7314</link>
<pubDate>Tue, 05 Jan 2021 02:00:03 GMT</pubDate>
<description><![CDATA[From a Small BAT File to Mass Logger Infostealer<br/>
 <a href="https://isc.sans.edu/forums/diary/From+a+small+BAT+file+to+Mass+Logger+infostealer/26946/">https://isc.sans.edu/forums/diary/From+a+small+BAT+file+to+Mass+Logger+infostealer/26946/</a><br/>
Citrix Releases Updates Addressing DTLS Flaw<br/>
 <a href="https://support.citrix.com/article/CTX289674">https://support.citrix.com/article/CTX289674</a><br/>
Zend Framework Deserialization Flaw<br/>
 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3007">https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3007</a><br/>
 <a href="https://github.com/Ling-Yizhou/zendframework3-/blob/main/zend%20framework3%20">https://github.com/Ling-Yizhou/zendframework3-/blob/main/zend%20framework3%20</a> %20rce.md<br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7314" type="text/plain" language="en" />
<itunes:keywords>zend, laminas, deserialization, php, stream, citrix, dtls, ddos, bat, logger, infostealer, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 4th 2021</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7312</itunes:episode>
<itunes:subtitle>Traffic Analysis Quiz; Zyxel Backdoor; Microsoft Source Code Leak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Traffic Analysis Quiz; Zyxel Backdoor; Microsoft Source Code Leak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7312.mp3" length="3983028" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7312.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7312</link>
<pubDate>Mon, 04 Jan 2021 02:00:03 GMT</pubDate>
<description><![CDATA[Traffic Analysis Quiz<br/>
 <a href="https://isc.sans.edu/forums/diary/End+of+Year+Traffic+Analysis+Quiz/26940/">https://isc.sans.edu/forums/diary/End+of+Year+Traffic+Analysis+Quiz/26940/</a><br/>
Zyxel Backdoor<br/>
 <a href="https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html">https://www.eyecontrol.nl/blog/undocumented-user-account-in-zyxel-products.html</a><br/>
Microsoft Source Code Accessed As a Result of SolarWinds Backdoor<br/>
 <a href="https://msrc-blog.microsoft.com/2020/12/31/microsoft-internal-solorigate-investigation-update/">https://msrc-blog.microsoft.com/2020/12/31/microsoft-internal-solorigate-investigation-update/</a><br/>
]]></description>
<itunes:duration>4:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7312" type="text/plain" language="en" />
<itunes:keywords>microsoft, solarwinds, zyxel, wireshark, traffic analysis quiz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7310</itunes:episode>
<itunes:subtitle>Simple AV Priv Escalation; Go Miner Malware; AutoHotKey Credential Stealer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Simple AV Priv Escalation; Go Miner Malware; AutoHotKey Credential Stealer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7310.mp3" length="3890964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7310.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7310</link>
<pubDate>Wed, 30 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Accessing Restricted Directory Listings via Your AV Solution<br/>
 <a href="https://isc.sans.edu/forums/diary/Want+to+know+whats+in+a+folder+you+dont+have+a+permission+to+access+Try+asking+your+AV+solution/26932/">https://isc.sans.edu/forums/diary/Want+to+know+whats+in+a+folder+you+dont+have+a+permission+to+access+Try+asking+your+AV+solution/26932/</a><br/>
Coin Miner Malware Written in Go<br/>
 <a href="https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/?fbclid=IwAR3eFiHCNoqr5mc2UAOcm8nocjUOjZn0cpcAiSoYmn__JtJfBbjqUUT1OwQ">https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/?fbclid=IwAR3eFiHCNoqr5mc2UAOcm8nocjUOjZn0cpcAiSoYmn__JtJfBbjqUUT1OwQ</a><br/>
AutoHotKey Credential Stealer<br/>
 <a href="https://www.trendmicro.com/en_us/research/20/l/stealth-credential-stealer-targets-us-canadian-bank-customers.html">https://www.trendmicro.com/en_us/research/20/l/stealth-credential-stealer-targets-us-canadian-bank-customers.html</a><br/>
]]></description>
<itunes:duration>4:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7310" type="text/plain" language="en" />
<itunes:keywords>autohotkey, ahk, credential stealer, coinminer, miner, golang, go, av, priviledge escalation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7308</itunes:episode>
<itunes:subtitle>Android vs Let's Encrypt; Insufficient Windows Patch; Google Docs Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Android vs Let's Encrypt; Insufficient Windows Patch; Google Docs Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7308.mp3" length="4898785" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7308.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7308</link>
<pubDate>Tue, 29 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Extending Android Device Compatibility for Let's Encrypt Certificates<br/>
 <a href="https://letsencrypt.org/2020/12/21/extending-android-compatibility.html">https://letsencrypt.org/2020/12/21/extending-android-compatibility.html</a><br/>
Insufficient Patch for Windows 8.1/10 Print Spooler<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2096">https://bugs.chromium.org/p/project-zero/issues/detail?id=2096</a><br/>
Google Docs Vulnerability<br/>
 <a href="https://savebreach.com/stealing-private-documents-through-a-google-docs-bug/">https://savebreach.com/stealing-private-documents-through-a-google-docs-bug/</a><br/>
CCC Conferences Virtual <br/>
 <a href="https://streaming.media.ccc.de/rc3">https://streaming.media.ccc.de/rc3</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7308" type="text/plain" language="en" />
<itunes:keywords>ccc, google docs, windows, patch, print spooler, google, android, lets encrypt, acme, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7306</itunes:episode>
<itunes:subtitle>Quick Weekend Diaries; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Quick Weekend Diaries; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7306.mp3" length="4998335" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7306.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7306</link>
<pubDate>Mon, 28 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[base64dump.py Supported Encodings<br/>
 <a href="https://isc.sans.edu/forums/diary/base64dumppy+Supported+Encodings/26924/">https://isc.sans.edu/forums/diary/base64dumppy+Supported+Encodings/26924/</a><br/>
String Analysis and Maldocs<br/>
 <a href="https://isc.sans.edu/forums/diary/Quickie+String+Analysis+Maldocs/26922/">https://isc.sans.edu/forums/diary/Quickie+String+Analysis+Maldocs/26922/</a><br/>
Malicious Word Document Delivering an Octopus Backdoor<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Word+Document+Delivering+an+Octopus+Backdoor/26918/">https://isc.sans.edu/forums/diary/Malicious+Word+Document+Delivering+an+Octopus+Backdoor/26918/</a><br/>
Analysis Dridex Dropper, IoC extraction<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+Dridex+Dropper+IoC+extraction+guest+diary/26920/">https://isc.sans.edu/forums/diary/Analysis+Dridex+Dropper+IoC+extraction+guest+diary/26920/</a><br/>
AT&T Outage due to Nashville Explosion<br/>
 <a href="https://about.att.com/pages/disaster_relief/nashville.html">https://about.att.com/pages/disaster_relief/nashville.html</a><br/>
SolarWinds SUPERNOVA Malware / API Vulnerability<br/>
 <a href="https://www.solarwinds.com/securityadvisory">https://www.solarwinds.com/securityadvisory</a><br/>
Citrix ADC DDoS Attack<br/>
 <a href="https://support.citrix.com/article/CTX289674">https://support.citrix.com/article/CTX289674</a><br/>
Crowdstrike Reporting Tool for Azure<br/>
 <a href="https://github.com/CrowdStrike/CRT">https://github.com/CrowdStrike/CRT</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7306" type="text/plain" language="en" />
<itunes:keywords>crowdstrike, citric, dtls, ddos, solarwinds, supernova, atT, nashville, dridex, octopus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7304</itunes:episode>
<itunes:subtitle>Wifi Geolocation Malware; New Treck IP Stack Vulns; Detecting Treck IP Stack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Wifi Geolocation Malware; New Treck IP Stack Vulns; Detecting Treck IP Stack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7304.mp3" length="3532198" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7304.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7304</link>
<pubDate>Wed, 23 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Malware Victim Selection Through WiFi Identification<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Victim+Selection+Through+WiFi+Identification/26910/">https://isc.sans.edu/forums/diary/Malware+Victim+Selection+Through+WiFi+Identification/26910/</a><br/>
New Treck IP Stack Vulnerabilities<br/>
 <a href="https://treck.com/vulnerability-response-information/">https://treck.com/vulnerability-response-information/</a><br/>
Detecting Treck IP Stack<br/>
 <a href="https://github.com/Forescout/project-memoria-detector">https://github.com/Forescout/project-memoria-detector</a><br/>
]]></description>
<itunes:duration>3:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7304" type="text/plain" language="en" />
<itunes:keywords>treck, ip stack, wifi, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7302</itunes:episode>
<itunes:subtitle>OpenPortStats.com; Dell Wyse Vuln; More Solarwinds
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenPortStats.com; Dell Wyse Vuln; More Solarwinds
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7302.mp3" length="5546545" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7302.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7302</link>
<pubDate>Tue, 22 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[What's The Deal With Openportstats.com?<br/>
 <a href="https://isc.sans.edu/forums/diary/Whats+the+deal+with+openportstatscom/26912/">https://isc.sans.edu/forums/diary/Whats+the+deal+with+openportstatscom/26912/</a><br/>
Dell Wyse ThinOS 8.6 Security Update<br/>
 <a href="https://www.dell.com/support/kbdoc/en-hr/000180768/dsa-2020-281">https://www.dell.com/support/kbdoc/en-hr/000180768/dsa-2020-281</a><br/>
SolarWinds 2nd Backdoor<br/>
 <a href="https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/">https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/</a><br/>
SolarWinds Domains<br/>
 <a href="https://securelist.com/sunburst-connecting-the-dots-in-the-dns-requests/99862/">https://securelist.com/sunburst-connecting-the-dots-in-the-dns-requests/99862/</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7302" type="text/plain" language="en" />
<itunes:keywords>solarwinds, Backdoor, dns, passive dns, dell, wyse, thinsos, openportstats, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7300</itunes:episode>
<itunes:subtitle>Citrix ADC: One Year Later; VirusTotal vs. PE Explorer; Kasachstan TLS; 5G Vuln; Bouncy Castle
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix ADC: One Year Later; VirusTotal vs. PE Explorer; Kasachstan TLS; 5G Vuln; Bouncy Castle
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7300.mp3" length="4942015" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7300.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7300</link>
<pubDate>Mon, 21 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[A slightly optimistic tale of how patching went for CVE-2019-19781<br/>
 <a href="https://isc.sans.edu/forums/diary/A+slightly+optimistic+tale+of+how+patching+went+for+CVE201919781/26900/">https://isc.sans.edu/forums/diary/A+slightly+optimistic+tale+of+how+patching+went+for+CVE201919781/26900/</a><br/>
Heads-up: VirusTotal Functionality in Sysinternals Tools Not Working<br/>
 <a href="https://isc.sans.edu/forums/diary/Headsup+VirusTotal+Functionality+in+Sysinternals+Tools+Not+Working/26906/">https://isc.sans.edu/forums/diary/Headsup+VirusTotal+Functionality+in+Sysinternals+Tools+Not+Working/26906/</a><br/>
Kasachstan: Browsers Block Government Certificate Authority<br/>
 <a href="https://www.zdnet.com/article/apple-google-microsoft-and-mozilla-ban-kazakhstans-mitm-https-certificate/">https://www.zdnet.com/article/apple-google-microsoft-and-mozilla-ban-kazakhstans-mitm-https-certificate/</a><br/>
5G Vulnerabilities<br/>
 <a href="https://positive-tech.com/about/news/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication/">https://positive-tech.com/about/news/vulnerabilities-in-standalone-5g-networks-could-allow-attackers-to-steal-credentials-and-falsify-subscriber-authentication/</a><br/>
Bouncy Castle BCrypt Password Verification Error<br/>
 <a href="https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/">https://www.synopsys.com/blogs/software-security/cve-2020-28052-bouncy-castle/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7300" type="text/plain" language="en" />
<itunes:keywords>bouncey castle, bcrypt, 5g, kasachstan, tls, virustotal, sysinternals, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7298</itunes:episode>
<itunes:subtitle>No Password Github; Android Updates; Trend Micro InterScan Vuln; Malicious Browser Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
No Password Github; Android Updates; Trend Micro InterScan Vuln; Malicious Browser Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7298.mp3" length="5635409" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7298.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7298</link>
<pubDate>Fri, 18 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Token Authentication Requirements for Git Operations<br/>
 <a href="https://github.blog/2020-12-15-token-authentication-requirements-for-git-operations/">https://github.blog/2020-12-15-token-authentication-requirements-for-git-operations/</a><br/>
Google Attempting to Speed Up OS Update Adoption<br/>
 <a href="https://android-developers.googleblog.com/2020/12/treble-plus-one-equals-four.html">https://android-developers.googleblog.com/2020/12/treble-plus-one-equals-four.html</a><br/>
Trend Micro InterScan Web Security Virtual Appliance Vulnerability<br/>
 <a href="https://success.trendmicro.com/solution/000283077">https://success.trendmicro.com/solution/000283077</a><br/>
Malicios Browser Extensions<br/>
 <a href="https://blog.avast.com/malicious-browser-extensions-avast">https://blog.avast.com/malicious-browser-extensions-avast</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7298" type="text/plain" language="en" />
<itunes:keywords>avast, browser extensions, trend micro, interscan, google, android, qualcom, github, authentication, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7296</itunes:episode>
<itunes:subtitle>Cloud DNS Logs; Solarwinds Update; HPE SIM Vuln; SAP HANA SAML Weakness @martingalloar
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cloud DNS Logs; Solarwinds Update; HPE SIM Vuln; SAP HANA SAML Weakness @martingalloar
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7296.mp3" length="5436469" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7296.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7296</link>
<pubDate>Thu, 17 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Cloud DNS Logs<br/>
 <a href="https://isc.sans.edu/forums/diary/DNS+Logs+in+Public+Clouds/26892/">https://isc.sans.edu/forums/diary/DNS+Logs+in+Public+Clouds/26892/</a><br/>
Solarwinds Update<br/>
 <a href="https://www.heise.de/news/l-f-SolarWinds-Backdoor-Hersteller-sorgte-fuer-Ausnahmen-von-AV-Ueberwachung-4990910.html">https://www.heise.de/news/l-f-SolarWinds-Backdoor-Hersteller-sorgte-fuer-Ausnahmen-von-AV-Ueberwachung-4990910.html</a><br/>
 <a href="https://krebsonsecurity.com/2020/12/malicious-domain-in-solarwinds-hack-turned-into-killswitch/">https://krebsonsecurity.com/2020/12/malicious-domain-in-solarwinds-hack-turned-into-killswitch/</a><br/>
Hewlett Packard Enterprise Systems Insight Manager (SIM) Vulnerability<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04068en_us</a><br/>
SAP HANA SAML Validation Weakness<br/>
 <a href="https://www.secureauth.com/blog/secureauth-uncovers-saml-validation-weakness-in-sap-hana/">https://www.secureauth.com/blog/secureauth-uncovers-saml-validation-weakness-in-sap-hana/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7296" type="text/plain" language="en" />
<itunes:keywords>SAP, HANA, SAML, HP, SIM, Solarwinds, Cloud, DNS, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7294</itunes:episode>
<itunes:subtitle>FireEye Maldoc; Difference Maker; F5 Big-IP; Google Outage; GoLang XML 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
FireEye Maldoc; Difference Maker; F5 Big-IP; Google Outage; GoLang XML 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7294.mp3" length="5647124" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7294.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7294</link>
<pubDate>Wed, 16 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Analyzing A Fireeye Maldoc<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+FireEye+Maldocs/26882/">https://isc.sans.edu/forums/diary/Analyzing+FireEye+Maldocs/26882/</a><br/>
Didier Stevens: 2020 Difference Makers<br/>
 <a href="https://www.sans.org/webcasts/2020-difference-makers-awards-ceremony-117154">https://www.sans.org/webcasts/2020-difference-makers-awards-ceremony-117154</a><br/>
F5 Big IP Vulnerabilities<br/>
 <a href="https://support.f5.com/csp/article/K20984059">https://support.f5.com/csp/article/K20984059</a><br/>
 <a href="https://support.f5.com/csp/article/K42696541">https://support.f5.com/csp/article/K42696541</a><br/>
 <a href="https://support.f5.com/csp/article/K37960100">https://support.f5.com/csp/article/K37960100</a><br/>
Google Outage<br/>
 <a href="https://status.cloud.google.com/incident/zall/20013">https://status.cloud.google.com/incident/zall/20013</a><br/>
GoLang XML Parser Vulnerabilities <br/>
 <a href="https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/">https://mattermost.com/blog/coordinated-disclosure-go-xml-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7294" type="text/plain" language="en" />
<itunes:keywords>golang, xml, saml, google, outage, f5, big-ip, didier stevens, difference makers, fireeye, maldoc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7292</itunes:episode>
<itunes:subtitle>SolarWinds Followup; Apple Updates Everything; SOREL-20M
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SolarWinds Followup; Apple Updates Everything; SOREL-20M
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7292.mp3" length="6275779" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7292.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7292</link>
<pubDate>Tue, 15 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[SolarWinds Followup<br/>
 <a href="https://isc.sans.edu/forums/diary/SolarWinds+Breach+Used+to+Infiltrate+Customer+Networks+Solarigate/26884/">https://isc.sans.edu/forums/diary/SolarWinds+Breach+Used+to+Infiltrate+Customer+Networks+Solarigate/26884/</a><br/>
 <a href="https://sansurl.com/solarwinds">https://sansurl.com/solarwinds</a><br/>
Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Sophos and Reversing Labs Release 20 Million Malware Samples<br/>
 <a href="https://github.com/sophos-ai/SOREL-20M">https://github.com/sophos-ai/SOREL-20M</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7292" type="text/plain" language="en" />
<itunes:keywords>sophos, reversing labs, sorel-20m, apple, ios, macos, big sur, solarwinds, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7290</itunes:episode>
<itunes:subtitle>SolarWinds Compromise; Fireeye Yara Rules; Flash Player EOL; Subway UK Spreads Trickbot
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SolarWinds Compromise; Fireeye Yara Rules; Flash Player EOL; Subway UK Spreads Trickbot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7290.mp3" length="5130278" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7290.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7290</link>
<pubDate>Mon, 14 Dec 2020 03:15:02 GMT</pubDate>
<description><![CDATA[SolarWinds Compromise<br/>
 <a href="https://isc.sans.edu/forums/diary/SolarWinds+Breach+Used+to+Infiltrate+Customer+Networks+Solarigate/26884/">https://isc.sans.edu/forums/diary/SolarWinds+Breach+Used+to+Infiltrate+Customer+Networks+Solarigate/26884/</a><br/>
Writing Yara Rules for Fun and Profit: Notes form the FireEye Breach Countermeasures<br/>
 <a href="https://isc.sans.edu/forums/diary/Writing+Yara+Rules+for+Fun+and+Profit+Notes+from+the+FireEye+Breach+Countermeasures/26870/">https://isc.sans.edu/forums/diary/Writing+Yara+Rules+for+Fun+and+Profit+Notes+from+the+FireEye+Breach+Countermeasures/26870/</a><br/>
Flash Player EoL<br/>
 <a href="https://helpx.adobe.com/flash-player/release-note/fp_32_air_32_release_notes.html">https://helpx.adobe.com/flash-player/release-note/fp_32_air_32_release_notes.html</a><br/>
Subway Marketing System Hacked to Send TrickBot Malware Emails<br/>
 <a href="https://www.bleepingcomputer.com/news/security/subway-marketing-system-hacked-to-send-trickbot-malware-emails/">https://www.bleepingcomputer.com/news/security/subway-marketing-system-hacked-to-send-trickbot-malware-emails/</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7290" type="text/plain" language="en" />
<itunes:keywords>solarwinds, flash, yara, fireeye, subway, trickbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7288</itunes:episode>
<itunes:subtitle>ngrok Python Backdoor; Cisco Jabber Patches; SANS Holiday Hackchallenge; Desierailization; @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ngrok Python Backdoor; Cisco Jabber Patches; SANS Holiday Hackchallenge; Desierailization; @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7288.mp3" length="11524506" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7288.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7288</link>
<pubDate>Fri, 11 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Python Backdoor Talking to a C2 Through Ngrok<br/>
 <a href="https://isc.sans.edu/forums/diary/Python+Backdoor+Talking+to+a+C2+Through+Ngrok/26866/">https://isc.sans.edu/forums/diary/Python+Backdoor+Talking+to+a+C2+Through+Ngrok/26866/</a><br/>
Cisco Releases Improved Patch for Jabber Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-ZktzjpgO">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-ZktzjpgO</a><br/>
 <a href="https://watchcom.no/nyheter/nyhetsarkiv/uncovers-cisco-jabber-vulnerabilities/">https://watchcom.no/nyheter/nyhetsarkiv/uncovers-cisco-jabber-vulnerabilities/</a><br/>
 <br/>
SANS Holiday Hack Challenge<br/>
 <a href="https://holidayhackchallenge.com/2020/">https://holidayhackchallenge.com/2020/</a><br/>
Karim Lalji: Fear of the Unkown: A Metanalysis of Insecure Object Deserialization Vulnerabilities<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/testing/fear-unknown-metanalysis-insecure-object-deserialization-vulnerabilities-39920">https://www.sans.org/reading-room/whitepapers/testing/fear-unknown-metanalysis-insecure-object-deserialization-vulnerabilities-39920</a><br/>
]]></description>
<itunes:duration>13:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7288" type="text/plain" language="en" />
<itunes:keywords>sans_edu, karim lalji, deserialization, sans holiday hack, cisco, kringlecon, jabber, python, ngrok, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7286</itunes:episode>
<itunes:subtitle>Oblivious DNS over HTTPs; @httparchive almanach; IoT TCP/IP Stacks; Fireeye
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oblivious DNS over HTTPs; @httparchive almanach; IoT TCP/IP Stacks; Fireeye
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7286.mp3" length="5595189" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7286.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7286</link>
<pubDate>Thu, 10 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Oblivious DoH<br/>
 <a href="https://blog.cloudflare.com/oblivious-dns/">https://blog.cloudflare.com/oblivious-dns/</a><br/>
HTTP Archive Almanach<br/>
 <a href="https://almanac.httparchive.org/en/2020/security">https://almanac.httparchive.org/en/2020/security</a><br/>
Open Source IoT TCP/IP Stack Vulnerabilities<br/>
 <a href="https://www.forescout.com/company/resources/amnesia33-how-tcp-ip-stacks-breed-critical-vulnerabilities-in-iot-ot-and-it-devices/">https://www.forescout.com/company/resources/amnesia33-how-tcp-ip-stacks-breed-critical-vulnerabilities-in-iot-ot-and-it-devices/</a><br/>
Fireeye Red Team Tool Signatures<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html">https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7286" type="text/plain" language="en" />
<itunes:keywords>fireeye, forescout, tcp/ip, iot, httparchive, almanach, odoh, oblivious, apple, cloudflare, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7284</itunes:episode>
<itunes:subtitle>Microsoft Patches; Adobe Patches; OpenSSL Patches; and more Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patches; Adobe Patches; OpenSSL Patches; and more Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7284.mp3" length="5226553" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7284.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7284</link>
<pubDate>Wed, 09 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/December+2020+Microsoft+Patch+Tuesday+Exchange+Sharepoint+Dynamics+and+DNS+Spoofing/26860/">https://isc.sans.edu/forums/diary/December+2020+Microsoft+Patch+Tuesday+Exchange+Sharepoint+Dynamics+and+DNS+Spoofing/26860/</a><br/>
Adobe Patch Tuesday<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
OpenSSL Patch (Tuesday)<br/>
 <a href="https://www.openssl.org/news/secadv/20201208.txt">https://www.openssl.org/news/secadv/20201208.txt</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7284" type="text/plain" language="en" />
<itunes:keywords>openssl, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7282</itunes:episode>
<itunes:subtitle>BASE64 Tricks; MSFT Teamcs RCE; PlayStation Now RCE; Cisco Security Manager RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BASE64 Tricks; MSFT Teamcs RCE; PlayStation Now RCE; Cisco Security Manager RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7282.mp3" length="5127802" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7282.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7282</link>
<pubDate>Tue, 08 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Corrupt BASE64 Strings: Detection and Decoding<br/>
 <a href="https://isc.sans.edu/forums/diary/Corrupt+BASE64+Strings+Detection+and+Decoding/26616/">https://isc.sans.edu/forums/diary/Corrupt+BASE64+Strings+Detection+and+Decoding/26616/</a><br/>
Microsoft Teams Remote Code Execution Vulnerability (Patched)<br/>
 <a href="https://github.com/oskarsve/ms-teams-rce">https://github.com/oskarsve/ms-teams-rce</a><br/>
PlayStation Now RCE<br/>
 <a href="https://hackerone.com/reports/873614">https://hackerone.com/reports/873614</a><br/>
Cisco Security Manager Java Deserialization Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-java-rce-mWJEedcD">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csm-java-rce-mWJEedcD</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7282" type="text/plain" language="en" />
<itunes:keywords>base64, MSFT teams, electron, rce, playstation, psnow, cisco, security manager, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7280</itunes:episode>
<itunes:subtitle>Proxy Scanner; De-Pixalating Passwords; Tomcat Info Leak; Google Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Proxy Scanner; De-Pixalating Passwords; Tomcat Info Leak; Google Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7280.mp3" length="5231661" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7280.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7280</link>
<pubDate>Mon, 07 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Proxy Scanner Attempting to Connect to Specific Hostname<br/>
 <a href="https://isc.sans.edu/forums/diary/Is+IP+91199118137+testing+Access+to+aahwwx52hostxyz/26852/">https://isc.sans.edu/forums/diary/Is+IP+91199118137+testing+Access+to+aahwwx52hostxyz/26852/</a><br/>
Recovering Passwords From Pixelized Screenshots<br/>
 <a href="https://www.linkedin.com/pulse/recovering-passwords-from-pixelized-screenshots-sipke-mellema/">https://www.linkedin.com/pulse/recovering-passwords-from-pixelized-screenshots-sipke-mellema/</a><br/>
Tomcat Information Leak<br/>
 <a href="http://mail-archives.us.apache.org/mod_mbox/www-announce/202012.mbox/%3C52858194-2efd-6f17-1821-9036c8494df0%40apache.org%3E">http://mail-archives.us.apache.org/mod_mbox/www-announce/202012.mbox/%3C52858194-2efd-6f17-1821-9036c8494df0%40apache.org%3E</a><br/>
Google Updates<br/>
 <a href="https://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7280" type="text/plain" language="en" />
<itunes:keywords>proxy scanner, pixelated passwords, depixalating, tomcat, google, chrome, updates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7278</itunes:episode>
<itunes:subtitle>Packet Challenge; iOS Zero Click to Exploit; GitHub Report; Implementing CIS Benchmark @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Packet Challenge; iOS Zero Click to Exploit; GitHub Report; Implementing CIS Benchmark @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7278.mp3" length="14426449" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7278.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7278</link>
<pubDate>Fri, 04 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Traffic Analysis Quiz: Mr. Natural<br/>
 <a href="https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Mr+Natural/26844/">https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Mr+Natural/26844/</a><br/>
An iOS Zero-Click Radio Proximity Exploit Odyssey<br/>
 <a href="https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html">https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html</a><br/>
Github "State of the Octoverse" Report<br/>
 <a href="https://octoverse.github.com/static/2020-security-report.pdf">https://octoverse.github.com/static/2020-security-report.pdf</a><br/>
Christopher Hurless: Open-Source Endpoint Detection and Response with CIS Benchmarks, OSQuery, Elastic Stack and The Hive<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/incident/open-source-endpoint-detection-response-cis-benchmarks-osquery-elastic-stack-thehive-39900">https://www.sans.org/reading-room/whitepapers/incident/open-source-endpoint-detection-response-cis-benchmarks-osquery-elastic-stack-thehive-39900</a><br/>
]]></description>
<itunes:duration>16:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7278" type="text/plain" language="en" />
<itunes:keywords>christopher hurless, sans.edu, sti, @sans_edu, cis, benchmark, thehive, osquery, elastic stack, github, ios, radio, wdsl, traffic quiz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7276</itunes:episode>
<itunes:subtitle>DNS Spoofing; Bladabindi via npm; DarkIRC vs. WebLogic
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Spoofing; Bladabindi via npm; DarkIRC vs. WebLogic
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7276.mp3" length="6101703" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7276.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7276</link>
<pubDate>Thu, 03 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Prevelance of DNS Spoofing<br/>
 <a href="https://arxiv.org/abs/2011.12978">https://arxiv.org/abs/2011.12978</a><br/>
New npm Malware Includes Bladabindi Trojan<br/>
 <a href="https://blog.sonatype.com/bladabindi-njrat-rat-in-jdb.js-npm-malware">https://blog.sonatype.com/bladabindi-njrat-rat-in-jdb.js-npm-malware</a><br/>
DarkIRC Bot Exploits Recent Oracle WebLogic Vulnerablity<br/>
 <a href="https://blogs.juniper.net/en-us/threat-research/darkirc-bot-exploits-oracle-weblogic-vulnerability">https://blogs.juniper.net/en-us/threat-research/darkirc-bot-exploits-oracle-weblogic-vulnerability</a><br/>
]]></description>
<itunes:duration>6:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7276" type="text/plain" language="en" />
<itunes:keywords>Darkirc, weblogic, juniper, npm, bladabindi, dns, spoofing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7274</itunes:episode>
<itunes:subtitle>Xanthe Docker Aware Miner; Ocean Lotus Mac Backdoor;  OpenClinic vs OpenClinic GA; Cyberstart
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Xanthe Docker Aware Miner; Ocean Lotus Mac Backdoor;  OpenClinic vs OpenClinic GA; Cyberstart
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7274.mp3" length="7780701" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7274.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7274</link>
<pubDate>Wed, 02 Dec 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Xanthe Docker Aware Miner<br/>
 <a href="https://blog.talosintelligence.com/2020/12/xanthe-docker-aware-miner.html#more">https://blog.talosintelligence.com/2020/12/xanthe-docker-aware-miner.html#more</a><br/>
Ocean Lotus Mac Backdoor<br/>
 <a href="https://www.trendmicro.com/en_us/research/20/k/new-macos-backdoor-connected-to-oceanlotus-surfaces.html">https://www.trendmicro.com/en_us/research/20/k/new-macos-backdoor-connected-to-oceanlotus-surfaces.html</a><br/>
OpenClinic vs OpenClinic GA<br/>
 <a href="https://labs.bishopfox.com/advisories/openclinic-version-0.8.2">https://labs.bishopfox.com/advisories/openclinic-version-0.8.2</a><br/>
 <a href="https://us-cert.cisa.gov/ics/advisories/icsma-20-184-01">https://us-cert.cisa.gov/ics/advisories/icsma-20-184-01</a><br/>
 <a href="https://sourceforge.net/p/open-clinic/discussion/1231980/thread/a2e8909fc5/">https://sourceforge.net/p/open-clinic/discussion/1231980/thread/a2e8909fc5/</a><br/>
Register For Cyberstart<br/>
 <a href="https://www.cyberstartamerica.org">https://www.cyberstartamerica.org</a><br/>
]]></description>
<itunes:duration>8:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7274" type="text/plain" language="en" />
<itunes:keywords>cyberstart, openclinic, medical, ocean lotus, backdoor, mac, apple, xanthe, docker, miner, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 1st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7272</itunes:episode>
<itunes:subtitle>Decrypting PowerShell; TrendMicro Vuln; WebKit Update; New Skimmer JS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Decrypting PowerShell; TrendMicro Vuln; WebKit Update; New Skimmer JS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7272.mp3" length="5514728" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7272.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7272</link>
<pubDate>Tue, 01 Dec 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Decrypting PowerShell Payloads<br/>
 <a href="https://isc.sans.edu/forums/diary/Decrypting+PowerShell+Payloads+video/26838/">https://isc.sans.edu/forums/diary/Decrypting+PowerShell+Payloads+video/26838/</a><br/>
Trend Micro ServerProtect for Linux<br/>
 <a href="https://success.trendmicro.com/solution/000281950">https://success.trendmicro.com/solution/000281950</a><br/>
WebKit Vulnerabilities<br/>
 <a href="https://blog.talosintelligence.com/2020/11/vuln-spotlight-webkit-use-after-free-nov-2020.html">https://blog.talosintelligence.com/2020/11/vuln-spotlight-webkit-use-after-free-nov-2020.html</a><br/>
New Skimmer JS<br/>
 <a href="https://twitter.com/AffableKraut/status/1333258498910588928">https://twitter.com/AffableKraut/status/1333258498910588928</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7272" type="text/plain" language="en" />
<itunes:keywords>skimmer, javascript, webkit, trend micro, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7270</itunes:episode>
<itunes:subtitle>Powershell Patching Windows API; Dangers of IoT Gifts; MobileIron Vuln Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Powershell Patching Windows API; Dangers of IoT Gifts; MobileIron Vuln Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7270.mp3" length="5539634" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7270.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7270</link>
<pubDate>Mon, 30 Nov 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Live Patching Windows API Calls Using PowerShell<br/>
 <a href="https://isc.sans.edu/forums/diary/Live+Patching+Windows+API+Calls+Using+PowerShell/26826/">https://isc.sans.edu/forums/diary/Live+Patching+Windows+API+Calls+Using+PowerShell/26826/</a><br/>
Threat Hunting with JARM<br/>
 <a href="https://isc.sans.edu/forums/diary/Threat+Hunting+with+JARM/26832/">https://isc.sans.edu/forums/diary/Threat+Hunting+with+JARM/26832/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Tip+Using+JARM+With+a+SOCKS+Proxy/26834/">https://isc.sans.edu/forums/diary/Quick+Tip+Using+JARM+With+a+SOCKS+Proxy/26834/</a><br/>
Be Careful With IoT Gifts<br/>
 <a href="https://cybernews.com/security/walmart-exclusive-routers-others-made-in-china-contain-backdoors-to-control-devices/">https://cybernews.com/security/walmart-exclusive-routers-others-made-in-china-contain-backdoors-to-control-devices/</a><br/>
 <a href="https://www.cyberscoop.com/smart-doorbells-amazon-ebay-ncc-vulnerabilities/">https://www.cyberscoop.com/smart-doorbells-amazon-ebay-ncc-vulnerabilities/</a><br/>
Active Exploitation of Mobile Iron Vulnerabilities <br/>
 <a href="https://www.ncsc.gov.uk/news/alert-multiple-actors-attempt-exploit-mobileiron-vulnerability">https://www.ncsc.gov.uk/news/alert-multiple-actors-attempt-exploit-mobileiron-vulnerability</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7270" type="text/plain" language="en" />
<itunes:keywords>mobileiron, iot, gifts, door bells, doorbells, jarm, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 25th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7268</itunes:episode>
<itunes:subtitle>TCP RST; VMware Advisory; Holiday Hack Challenge; @KringleCon
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TCP RST; VMware Advisory; Holiday Hack Challenge; @KringleCon
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7268.mp3" length="9482773" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7268.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7268</link>
<pubDate>Wed, 25 Nov 2020 02:00:03 GMT</pubDate>
<description><![CDATA[The Special Case of TCP Resets <br/>
 <a href="https://isc.sans.edu/forums/diary/The+special+case+of+TCP+RST/26824/">https://isc.sans.edu/forums/diary/The+special+case+of+TCP+RST/26824/</a><br/>
VMWare Workspace Vulnerability<br/>
 <a href="https://www.theregister.com/2020/11/24/vmware_urges_sysadmins_to_implement/">https://www.theregister.com/2020/11/24/vmware_urges_sysadmins_to_implement/</a><br/>
Holiday Hack Challenge 2020<br/>
 <a href="https://holidayhackchallenge.com/2020/">https://holidayhackchallenge.com/2020/</a><br/>
]]></description>
<itunes:duration>11:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7268" type="text/plain" language="en" />
<itunes:keywords>holiday, hack challenge, vmware, tcp, resets rst, kringlecon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7266</itunes:episode>
<itunes:subtitle>Cobalt Strike Beacon; Godaddy Social Engineering; FBI Domain Spoofing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobalt Strike Beacon; Godaddy Social Engineering; FBI Domain Spoofing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7266.mp3" length="3116411" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7266.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7266</link>
<pubDate>Tue, 24 Nov 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Quick Tip: Cobalt Strike Beacon Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Tip+Cobalt+Strike+Beacon+Analysis/26818/">https://isc.sans.edu/forums/diary/Quick+Tip+Cobalt+Strike+Beacon+Analysis/26818/</a><br/>
Godaddy Social Engineering Used to Compromise Bitcoin Exchange Domains<br/>
 <a href="https://blog.liquid.com/security-incident-november-13-2020">https://blog.liquid.com/security-incident-november-13-2020</a><br/>
Spoofed FBI Domains <br/>
 <a href="https://www.ic3.gov/Media/Y2020/PSA201123">https://www.ic3.gov/Media/Y2020/PSA201123</a><br/>
]]></description>
<itunes:duration>3:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7266" type="text/plain" language="en" />
<itunes:keywords>fbi, domains, godaddy, bitcoin, cobalt strike, beacon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7264</itunes:episode>
<itunes:subtitle>VMWare Update; DB2 Vuln; Fortinet SSL VPN
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VMWare Update; DB2 Vuln; Fortinet SSL VPN
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7264.mp3" length="3266715" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7264.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7264</link>
<pubDate>Mon, 23 Nov 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Updates for VMWare ESXi; Fusion and Workstation<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0026.html">https://www.vmware.com/security/advisories/VMSA-2020-0026.html</a><br/>
IBM DB2 Vulnerability<br/>
 <a href="https://www.ibm.com/support/pages/node/6370025">https://www.ibm.com/support/pages/node/6370025</a><br/>
 <a href="https://www.ibm.com/support/pages/node/6370023">https://www.ibm.com/support/pages/node/6370023</a><br/>
Fortinet SSL VPN Exploit Used to Collect Credentials<br/>
 <a href="https://twitter.com/Bank_Security/status/1329426020647243778">https://twitter.com/Bank_Security/status/1329426020647243778</a><br/>
]]></description>
<itunes:duration>3:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7264" type="text/plain" language="en" />
<itunes:keywords>fortinet, vpn, epxloits, ibm db2, VMWare ESXi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7262</itunes:episode>
<itunes:subtitle>PowerShell Drops Formbook; Google Phish; JARM TLS Fingerprint; ICS and IDS @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PowerShell Drops Formbook; Google Phish; JARM TLS Fingerprint; ICS and IDS @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7262.mp3" length="13436864" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7262.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7262</link>
<pubDate>Fri, 20 Nov 2020 02:35:03 GMT</pubDate>
<description><![CDATA[PowerShell Dropper Delivering Formbook<br/>
 <a href="https://isc.sans.edu/forums/diary/PowerShell+Dropper+Delivering+Formbook/26806/">https://isc.sans.edu/forums/diary/PowerShell+Dropper+Delivering+Formbook/26806/</a><br/>
Google Leading the Way in Phishing<br/>
 <a href="https://www.armorblox.com/blog/ok-google-build-me-a-phishing-campaign">https://www.armorblox.com/blog/ok-google-build-me-a-phishing-campaign</a><br/>
Identifying Malicious Servers With JARM<br/>
 <a href="https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a">https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a</a><br/>
Daniel Behrens: Industrial Traffic Collection: Understanding the Implications of Deploying Visibility Without Impacting Production<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/ICS/industrial-traffic-collection-understanding-implications-deploying-visibility-impacting-production-39810">https://www.sans.org/reading-room/whitepapers/ICS/industrial-traffic-collection-understanding-implications-deploying-visibility-impacting-production-39810</a><br/>
]]></description>
<itunes:duration>15:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7262" type="text/plain" language="en" />
<itunes:keywords>sans_edu, ics, ids, jarm, salesforce, google, phishing, powershell, formbook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 19th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7260</itunes:episode>
<itunes:subtitle>More Controls Less Security; Google Chrome Update; Firefox HTTPS Only; Windows Kerberos
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Controls Less Security; Google Chrome Update; Firefox HTTPS Only; Windows Kerberos
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7260.mp3" length="4312666" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7260.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7260</link>
<pubDate>Thu, 19 Nov 2020 02:55:02 GMT</pubDate>
<description><![CDATA[When Security Controls Lead to Security Issues<br/>
 <a href="https://isc.sans.edu/forums/diary/When+Security+Controls+Lead+to+Security+Issues/26804/">https://isc.sans.edu/forums/diary/When+Security+Controls+Lead+to+Security+Issues/26804/</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_17.html">https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_17.html</a><br/>
Firefox 83 HTTPS Only Mode<br/>
 <a href="https://blog.mozilla.org/security/2020/11/17/firefox-83-introduces-https-only-mode/">https://blog.mozilla.org/security/2020/11/17/firefox-83-introduces-https-only-mode/</a><br/>
OOB Windows Kerberos Update<br/>
 <a href="https://docs.microsoft.com/en-us/windows/release-information/windows-message-center">https://docs.microsoft.com/en-us/windows/release-information/windows-message-center</a><br/>
Cisco WebEx Patch Fixes "Ghost Users"<br/>
 <a href="https://securityintelligence.com/posts/ibm-works-with-cisco-exorcise-ghosts-webex-meetings/">https://securityintelligence.com/posts/ibm-works-with-cisco-exorcise-ghosts-webex-meetings/</a><br/>
Ransomware Flooding Printers<br/>
 <a href="https://twitter.com/Irlenys/status/1327784305465188353">https://twitter.com/Irlenys/status/1327784305465188353</a><br/>
]]></description>
<itunes:duration>5:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7260" type="text/plain" language="en" />
<itunes:keywords>ransomware, egregor, webex, kerberos, firefox, https, chrome, google, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7258</itunes:episode>
<itunes:subtitle>MacOS 11 FW Bypass; Apple OCSP Changes; Cisco Security Manager @frycos
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS 11 FW Bypass; Apple OCSP Changes; Cisco Security Manager @frycos
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7258.mp3" length="4730681" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7258.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7258</link>
<pubDate>Wed, 18 Nov 2020 03:20:03 GMT</pubDate>
<description><![CDATA[Apple Binaries Used to Bypass 3rd Party Security Products on MacOS 11<br/>
 <a href="https://twitter.com/patrickwardle/status/1327726496203476992">https://twitter.com/patrickwardle/status/1327726496203476992</a><br/>
Apple Improving Privacy on App Certificate Checks<br/>
 <a href="https://support.apple.com/en-us/HT202491">https://support.apple.com/en-us/HT202491</a><br/>
Cisco Security Manager Vulnerabilities<br/>
 <a href="https://gist.github.com/Frycos/8bf5c125d720b3504b4f28a1126e509e">https://gist.github.com/Frycos/8bf5c125d720b3504b4f28a1126e509e</a><br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7258" type="text/plain" language="en" />
<itunes:keywords>macos, big sur, privacy, firewall, apple, ocsp, cisco, security manager, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7256</itunes:episode>
<itunes:subtitle>Old Vulnerabilities; XenApp/Desktop Update; Anti Zoombombing; Firefox Vuln Details
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Old Vulnerabilities; XenApp/Desktop Update; Anti Zoombombing; Firefox Vuln Details
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7256.mp3" length="5186353" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7256.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7256</link>
<pubDate>Tue, 17 Nov 2020 03:40:02 GMT</pubDate>
<description><![CDATA[Old Vulnerbilities Don't Die<br/>
 <a href="https://isc.sans.edu/forums/diary/Heartbleed+BlueKeep+and+other+vulnerabilities+that+didnt+disappear+just+because+we+dont+talk+about+them+anymore/26798/">https://isc.sans.edu/forums/diary/Heartbleed+BlueKeep+and+other+vulnerabilities+that+didnt+disappear+just+because+we+dont+talk+about+them+anymore/26798/</a><br/>
Citrix Virtual Apps and Desktops Security Update<br/>
 <a href="https://support.citrix.com/article/CTX285059">https://support.citrix.com/article/CTX285059</a><br/>
Zoom Security Improvements<br/>
 <a href="https://blog.zoom.us/new-ways-to-combat-zoom-meeting-disruptions/">https://blog.zoom.us/new-ways-to-combat-zoom-meeting-disruptions/</a><br/>
Firefox File Read Vulnerability Details<br/>
 <a href="https://medium.com/@kanytu/firefox-and-how-a-website-could-steal-all-of-your-cookies-581fe4648e8d">https://medium.com/@kanytu/firefox-and-how-a-website-could-steal-all-of-your-cookies-581fe4648e8d</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7256" type="text/plain" language="en" />
<itunes:keywords>firefox, zoom, citrix, xenapp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7254</itunes:episode>
<itunes:subtitle>Oledump Update; Old Malware New Clothes; MacOS OCSP Woes; VoltPillager SGX Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oledump Update; Old Malware New Clothes; MacOS OCSP Woes; VoltPillager SGX Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7254.mp3" length="5628132" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7254.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7254</link>
<pubDate>Mon, 16 Nov 2020 02:13:12 GMT</pubDate>
<description><![CDATA[Oledump Removed Macro Indicator<br/>
 <a href="https://isc.sans.edu/forums/diary/oledumps+Indicator/26794/">https://isc.sans.edu/forums/diary/oledumps+Indicator/26794/</a><br/>
Old Worm But New Obfuscation Technique<br/>
 <a href="https://isc.sans.edu/forums/diary/Old+Worm+But+New+Obfuscation+Technique/26792/">https://isc.sans.edu/forums/diary/Old+Worm+But+New+Obfuscation+Technique/26792/</a><br/>
MacOS OCSP Disaster<br/>
 <a href="https://blog.cryptohack.org/macos-ocsp-disaster">https://blog.cryptohack.org/macos-ocsp-disaster</a><br/>
VoltPillager: Hardware-base fault injection attacks against Instel SGX Enclaves using the SVID voltage scaling interface<br/>
 <a href="https://www.usenix.org/system/files/sec21summer_chen-zitai.pdf">https://www.usenix.org/system/files/sec21summer_chen-zitai.pdf</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7254" type="text/plain" language="en" />
<itunes:keywords>voltpillager, sgx, macos, ocsp, oledump, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7252</itunes:episode>
<itunes:subtitle>Exposed Azure Blobs; MacOS Security Updates; DNS Cache Poisoning Again; Poisoned Postman @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exposed Azure Blobs; MacOS Security Updates; DNS Cache Poisoning Again; Poisoned Postman @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7252.mp3" length="11806149" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7252.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7252</link>
<pubDate>Fri, 13 Nov 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Preventing Exposed Azure Blob Storage<br/>
 <a href="https://isc.sans.edu/forums/diary/Preventing+Exposed+Azure+Blob+Storage/26786/">https://isc.sans.edu/forums/diary/Preventing+Exposed+Azure+Blob+Storage/26786/</a><br/>
Apple Security Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
DNS Cache Poisoning Attack Reloaded<br/>
 <a href="https://dl.acm.org/doi/pdf/10.1145/3372297.3417280">https://dl.acm.org/doi/pdf/10.1145/3372297.3417280</a><br/>
Rebel Powell: Poisoned Postman; Detecting Manipulation of Compliance Features in a Microsoft Exchange Online Environment<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/cloud/poisoned-postman-detecting-manipulation-compliance-features-microsoft-exchange-online-environment-39850">https://www.sans.org/reading-room/whitepapers/cloud/poisoned-postman-detecting-manipulation-compliance-features-microsoft-exchange-online-environment-39850</a><br/>
]]></description>
<itunes:duration>14:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7252" type="text/plain" language="en" />
<itunes:keywords>rebel powell, sans.edu, dns, cache poisoning, apple, updates, big sur, azure blobs, macos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 12th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7250</itunes:episode>
<itunes:subtitle>Traffic Analysis Quiz; OSS Security Scorecards; Bitdefender UPX Issues;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Traffic Analysis Quiz; OSS Security Scorecards; Bitdefender UPX Issues;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7250.mp3" length="5072986" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7250.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7250</link>
<pubDate>Thu, 12 Nov 2020 02:15:03 GMT</pubDate>
<description><![CDATA[Traffic Analysis Quiz<br/>
 <a href="https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+DESKTOPFX23IK5/26780/">https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+DESKTOPFX23IK5/26780/</a><br/>
Open Source Security Scorecards<br/>
 <a href="https://github.com/ossf/scorecard">https://github.com/ossf/scorecard</a><br/>
Bitdefender: UPX Unpacking Featuring Ten Memory Corruptions<br/>
 <a href="https://landave.io/2020/11/bitdefender-upx-unpacking-featuring-ten-memory-corruptions/">https://landave.io/2020/11/bitdefender-upx-unpacking-featuring-ten-memory-corruptions/</a><br/>
Ubuntu 20.04 Privilege Escalation<br/>
 <a href="https://securitylab.github.com/research/Ubuntu-gdm3-accountsservice-LPE">https://securitylab.github.com/research/Ubuntu-gdm3-accountsservice-LPE</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7250" type="text/plain" language="en" />
<itunes:keywords>ubuntu, gdm, bitdefender, upx, packer, unpacker, compression, decompression, traffic analysis quiz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7248</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Platypus; Adobe/Firefox Updates; Fingerprinting ADS-B
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Platypus; Adobe/Firefox Updates; Fingerprinting ADS-B
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7248.mp3" length="5418586" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7248.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7248</link>
<pubDate>Wed, 11 Nov 2020 10:59:38 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+November+2020+Patch+Tuesday/26778/">https://isc.sans.edu/forums/diary/Microsoft+November+2020+Patch+Tuesday/26778/</a><br/>
"Platypus" Attack against Intel SGX<br/>
 <a href="https://platypusattack.com/">https://platypusattack.com/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Firefox Updates<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2020-49/#CVE-2020-26950">https://www.mozilla.org/en-US/security/advisories/mfsa2020-49/#CVE-2020-26950</a><br/>
Fingerprinting ADS-B Signals<br/>
 <a href="https://icnp20.cs.ucr.edu/proceedings/aimcom2/Real-World%20ADS-B%20signal%20recognition%20based%20on%20Radio%20Frequency%20Fingerprinting.pdf">https://icnp20.cs.ucr.edu/proceedings/aimcom2/Real-World%20ADS-B%20signal%20recognition%20based%20on%20Radio%20Frequency%20Fingerprinting.pdf</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7248" type="text/plain" language="en" />
<itunes:keywords>ads-b, firefox, adobe, platypus, intel, side-channel, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7246</itunes:episode>
<itunes:subtitle>How Attackers Improve; Linux Ransomware; Malicious MSFT Teams; NPM Malware; RPKI Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
How Attackers Improve; Linux Ransomware; Malicious MSFT Teams; NPM Malware; RPKI Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7246.mp3" length="5024342" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7246.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7246</link>
<pubDate>Tue, 10 Nov 2020 02:00:03 GMT</pubDate>
<description><![CDATA[How Attackers Brush Up Their Malicious Scripts<br/>
 <a href="https://isc.sans.edu/forums/diary/How+Attackers+Brush+Up+Their+Malicious+Scripts/26770/">https://isc.sans.edu/forums/diary/How+Attackers+Brush+Up+Their+Malicious+Scripts/26770/</a><br/>
RansomEXX Trojan Attacks Linux Systems<br/>
 <a href="https://securelist.com/ransomexx-trojan-attacks-linux-systems/99279/">https://securelist.com/ransomexx-trojan-attacks-linux-systems/99279/</a><br/>
Fake Microsoft Teams Updates Lead to Cobalt Strike Deployment<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/">https://www.bleepingcomputer.com/news/security/fake-microsoft-teams-updates-lead-to-cobalt-strike-deployment/</a><br/>
More NPM Malare Found<br/>
 <a href="https://blog.sonatype.com/discord.dll-successor-to-npm-fallguys-">https://blog.sonatype.com/discord.dll-successor-to-npm-fallguys-</a><br/>
The Internet is Getting Safer: Fall 2020 RPKI Update<br/>
 <a href="https://blog.cloudflare.com/rpki-2020-fall-update/">https://blog.cloudflare.com/rpki-2020-fall-update/</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7246" type="text/plain" language="en" />
<itunes:keywords>rpki, npm, microsoft, cobalt strike, teams, ransomexx, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7244</itunes:episode>
<itunes:subtitle>WebLogic Coin Mining; Extract VBA; Let's Encrypt Updates; set_fs(); BigIP
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebLogic Coin Mining; Extract VBA; Let's Encrypt Updates; set_fs(); BigIP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7244.mp3" length="4434075" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7244.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7244</link>
<pubDate>Mon, 09 Nov 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Cryptojacking Targeting WebLogic TCP/7001<br/>
Cryptojacking Targeting WebLogic TCP/7001<br/>
 <a href="https://isc.sans.edu/forums/diary/Cryptojacking+Targeting+WebLogic+TCP7001/26768/">https://isc.sans.edu/forums/diary/Cryptojacking+Targeting+WebLogic+TCP7001/26768/</a><br/>
Extracting VBA Code From Maldocs<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Tip+Extracting+all+VBA+Code+from+a+Maldoc/26772/">https://isc.sans.edu/forums/diary/Quick+Tip+Extracting+all+VBA+Code+from+a+Maldoc/26772/</a><br/>
Let's Encrypt May No Longer Be Recognized by Older Android Versions<br/>
 <a href="https://letsencrypt.org/2020/11/06/own-two-feet.html">https://letsencrypt.org/2020/11/06/own-two-feet.html</a><br/>
Linux Kernel to Remove set_fs()<br/>
 <a href="http://lkml.iu.edu/hypermail/linux/kernel/2010.3/00552.html">http://lkml.iu.edu/hypermail/linux/kernel/2010.3/00552.html</a><br/>
BigIP Vulnerability<br/>
 <a href="https://support.f5.com/csp/article/K43310520">https://support.f5.com/csp/article/K43310520</a>]]></description>
<itunes:duration>5:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7244" type="text/plain" language="en" />
<itunes:keywords>bigip, linux, set_fs, lets encrypt, android, vba, cryptojacking, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7242</itunes:episode>
<itunes:subtitle>Find "Invoke-Expression"; Apple Updates; VoIP Fraud; Replacing WINS @sans_edu 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Find "Invoke-Expression"; Apple Updates; VoIP Fraud; Replacing WINS @sans_edu 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7242.mp3" length="13322395" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7242.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7242</link>
<pubDate>Fri, 06 Nov 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Did You Spot "Invoke-Expression" ?<br/>
 <a href="https://isc.sans.edu/forums/diary/Did+You+Spot+InvokeExpression/26762/">https://isc.sans.edu/forums/diary/Did+You+Spot+InvokeExpression/26762/</a><br/>
Apple Security Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Corporte VoIP Phone System Attacks<br/>
 <a href="https://blog.checkpoint.com/2020/11/05/whos-calling-gaza-and-west-bank-hackers-exploit-and-monetize-corporate-voip-phone-system-vulnerability-internationally/">https://blog.checkpoint.com/2020/11/05/whos-calling-gaza-and-west-bank-hackers-exploit-and-monetize-corporate-voip-phone-system-vulnerability-internationally/</a><br/>
Mark Lucas: Replacing WINS in an Open Environment with Policy Managed DNS Servers<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/dns/replacing-wins-open-environment-policy-managed-dns-servers-39820">https://www.sans.org/reading-room/whitepapers/dns/replacing-wins-open-environment-policy-managed-dns-servers-39820</a><br/>
]]></description>
<itunes:duration>15:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7242" type="text/plain" language="en" />
<itunes:keywords>invoke-epxression, powershell, apple, macos, ios, ipados, patches, voip, asterisk, mark lucas, wins, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 5th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7240</itunes:episode>
<itunes:subtitle>Cisco AnyConnect Vuln; Chrome Root CA Policy; Android Security Bulletin
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco AnyConnect Vuln; Chrome Root CA Policy; Android Security Bulletin
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7240.mp3" length="4752255" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7240.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7240</link>
<pubDate>Thu, 05 Nov 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Cisco AnyConnect Security Mobility Client<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-ipc-KfQO9QhK">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-ipc-KfQO9QhK</a><br/>
Google Chrome Root CA Policy<br/>
 <a href="https://www.chromium.org/Home/chromium-security/root-ca-policy">https://www.chromium.org/Home/chromium-security/root-ca-policy</a><br/>
Android November 2020 Security Bulletin<br/>
 <a href="https://source.android.com/security/bulletin/2020-11-01">https://source.android.com/security/bulletin/2020-11-01</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7240" type="text/plain" language="en" />
<itunes:keywords>Cisco Anyconnect, google, chrome, CA, TLS, Android, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7238</itunes:episode>
<itunes:subtitle>Cobalt Strike and WebLogic; SaltSack; Adobe; Twilio NPM Brandjacking; GitHub Workflows
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cobalt Strike and WebLogic; SaltSack; Adobe; Twilio NPM Brandjacking; GitHub Workflows
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7238.mp3" length="4433361" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7238.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7238</link>
<pubDate>Wed, 04 Nov 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Attackers Exploiting WebLogic Servers to Install Cobalt Strike<br/>
 <a href="https://isc.sans.edu/forums/diary/Attackers+Exploiting+WebLogic+Servers+via+CVE202014882+to+install+Cobalt+Strike/26752">https://isc.sans.edu/forums/diary/Attackers+Exploiting+WebLogic+Servers+via+CVE202014882+to+install+Cobalt+Strike/26752</a><br/>
New SaltStack Vulnerabilities<br/>
 <a href="https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/">https://www.saltstack.com/blog/on-november-3-2020-saltstack-publicly-disclosed-three-new-cves/</a><br/>
Adobe Releases Acrobat/Reader Update<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb20-67.html">https://helpx.adobe.com/security/products/acrobat/apsb20-67.html</a><br/>
Malicious Twilio NPM Package<br/>
 <a href="https://www.npmjs.com/advisories/1574">https://www.npmjs.com/advisories/1574</a><br/>
GitHub Workflow Injection Vulnerabilities<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2070&can=2&q=&colspec=ID%20Type%20Status%20Priority%20Milestone%20Owner%20Summary&cells=ids">https://bugs.chromium.org/p/project-zero/issues/detail?id=2070&can=2&q=&colspec=ID%20Type%20Status%20Priority%20Milestone%20Owner%20Summary&cells=ids</a><br/>
]]></description>
<itunes:duration>5:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7238" type="text/plain" language="en" />
<itunes:keywords>github, twilio, npm, adobe, acrobat, reader, saltstack, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7236</itunes:episode>
<itunes:subtitle>Emotet :hearts: Qakbot; WebLogic Bad News; Google Chrome Udpate 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet :hearts: Qakbot; WebLogic Bad News; Google Chrome Udpate 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7236.mp3" length="5595953" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7236.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7236</link>
<pubDate>Tue, 03 Nov 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Emotet -> Qakbot -> More Emotet<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+Qakbot+more+Emotet/26750/">https://isc.sans.edu/forums/diary/Emotet+Qakbot+more+Emotet/26750/</a><br/>
WebLogic Bad News<br/>
 <a href="https://www.oracle.com/security-alerts/alert-cve-2020-14750.html">https://www.oracle.com/security-alerts/alert-cve-2020-14750.html</a><br/>
 <a href="https://twitter.com/80vul/status/1322078337137700865">https://twitter.com/80vul/status/1322078337137700865</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html</a><br/>
NAT Slipstreaming Re-Discovered<br/>
 <a href="https://thehackernews.com/2020/11/new-natfirewall-bypass-attack-lets.html">https://thehackernews.com/2020/11/new-natfirewall-bypass-attack-lets.html</a> <br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7236" type="text/plain" language="en" />
<itunes:keywords>NAT, slipstreaming, google, chrome, weblogic, emotet, qakbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7234</itunes:episode>
<itunes:subtitle>CAA Records; Unpatched Windows Bug Exploited; Operation Kitsone
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CAA Records; Unpatched Windows Bug Exploited; Operation Kitsone
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7234.mp3" length="4630464" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7234.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7234</link>
<pubDate>Mon, 02 Nov 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Quick Status of the CAA DNS Record Adoption <br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Status+of+the+CAA+DNS+Record+Adoption/26738/">https://isc.sans.edu/forums/diary/Quick+Status+of+the+CAA+DNS+Record+Adoption/26738/</a><br/>
Windows Kernel cng.sys pool-based buffer overflow CVE-2020-17087<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2104">https://bugs.chromium.org/p/project-zero/issues/detail?id=2104</a><br/>
Operation Earth Kitsune<br/>
 <a href="https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-earth-kitsune-tracking-slub-s-current-operations">https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-earth-kitsune-tracking-slub-s-current-operations</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7234" type="text/plain" language="en" />
<itunes:keywords>kistune, mattermost, slack, github, trendmicro, windows, kernel, privilege escalation, caa, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7232</itunes:episode>
<itunes:subtitle>WebLogic CVE-2020-14882 Exploit; ZoneAlarm Update; Ransomware and Healthcare; OpenEMR Vulns; @sans_edu: Serverless
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebLogic CVE-2020-14882 Exploit; ZoneAlarm Update; Ransomware and Healthcare; OpenEMR Vulns; @sans_edu: Serverless
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7232.mp3" length="12541957" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7232.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7232</link>
<pubDate>Fri, 30 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[PATCH NOW: CVE-2020-14882 WebLogic Actively Exploited<br/>
 <a href="https://isc.sans.edu/forums/diary/PATCH+NOW+CVE202014882+Weblogic+Actively+Exploited+Against+Honeypots/26734/">https://isc.sans.edu/forums/diary/PATCH+NOW+CVE202014882+Weblogic+Actively+Exploited+Against+Honeypots/26734/</a><br/>
Zonealarm Update<br/>
 <a href="https://www.zonealarm.com/software/extreme-security/release-history">https://www.zonealarm.com/software/extreme-security/release-history</a><br/>
Ransomware Targeting Healthcare<br/>
 <a href="https://us-cert.cisa.gov/ncas/alerts/aa20-302a">https://us-cert.cisa.gov/ncas/alerts/aa20-302a</a><br/>
OpenEMR Vulnerabilities <br/>
 <a href="https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerability">https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerability</a><br/>
Mishka McCowan: Mitigating Risk with the CSA 12 Critical Risks for Serverless Applications<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/cloud/mitigating-risk-csa-12-critical-risks-serverless-applications-39845">https://www.sans.org/reading-room/whitepapers/cloud/mitigating-risk-csa-12-critical-risks-serverless-applications-39845</a><br/>
]]></description>
<itunes:duration>14:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7232" type="text/plain" language="en" />
<itunes:keywords>openemr, ransomware, ryuk, zonealarm, cve-2020-14882, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7230</itunes:episode>
<itunes:subtitle>Reminder: SMBGhost; MSFT Defender ATP False Positives; QNAP; Linux Trickbot; Abuse.ch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reminder: SMBGhost; MSFT Defender ATP False Positives; QNAP; Linux Trickbot; Abuse.ch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7230.mp3" length="4920845" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7230.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7230</link>
<pubDate>Thu, 29 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[SMBGhost Remains Unpatched on 8% of Exposed SMB Servers<br/>
 <a href="https://isc.sans.edu/forums/diary/SMBGhost+the+critical+vulnerability+many+seem+to+have+forgotten+to+patch/26732/">https://isc.sans.edu/forums/diary/SMBGhost+the+critical+vulnerability+many+seem+to+have+forgotten+to+patch/26732/</a><br/>
Microsoft Defender ATP Cobalt Strike False Positive<br/>
 <a href="https://twitter.com/ffforward/status/1321375690084810753?s=20">https://twitter.com/ffforward/status/1321375690084810753?s=20</a><br/>
QNAP Security Advisory<br/>
 <a href="https://www.qnap.com/en/security-advisory/QSA-20-09">https://www.qnap.com/en/security-advisory/QSA-20-09</a><br/>
New Linux Trickbot Version Sighted<br/>
 <a href="https://www.netscout.com/blog/asert/dropping-anchor">https://www.netscout.com/blog/asert/dropping-anchor</a><br/>
Abuse.ch Needs Help <br/>
 <a href="https://abuse.ch/blog/moving-forward/">https://abuse.ch/blog/moving-forward/</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7230" type="text/plain" language="en" />
<itunes:keywords>abuse.ch, linux, trickbot, qnap, microsoft, atp, cobalt strike, smbghost, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7228</itunes:episode>
<itunes:subtitle>SonarQube Exploited; MSFT Edge/Chrome Updates; Flash Removal Tool; MSFT Teams
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SonarQube Exploited; MSFT Edge/Chrome Updates; Flash Removal Tool; MSFT Teams
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7228.mp3" length="4481992" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7228.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7228</link>
<pubDate>Wed, 28 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Vulnerable SonarQube Configurations Used to Steal Code<br/>
 <a href="https://beta.documentcloud.org/documents/20399900-fbi_flash_sonarqube_access_bc">https://beta.documentcloud.org/documents/20399900-fbi_flash_sonarqube_access_bc</a><br/>
Microsoft Edge Security Updates (Chromium-Based)<br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200002">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200002</a><br/>
Microsoft Releases Flash Removal Tool<br/>
 <a href="https://support.microsoft.com/en-us/help/4577586/update-for-removal-of-adobe-flash-player">https://support.microsoft.com/en-us/help/4577586/update-for-removal-of-adobe-flash-player</a><br/>
Bypassing MSFT Teams Policies<br/>
 <a href="https://o365blog.com/post/teams-policies/">https://o365blog.com/post/teams-policies/</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7228" type="text/plain" language="en" />
<itunes:keywords>microsoft teams, flash removal tool, flash player, microsoft, chrome, edge, chromium, sonarqube, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7226</itunes:episode>
<itunes:subtitle>Excel 4 Visibility; HP Revoked Cert; Link Preview Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Excel 4 Visibility; HP Revoked Cert; Link Preview Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7226.mp3" length="5173189" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7226.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7226</link>
<pubDate>Tue, 27 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Excel 4 Macros: "Abnormal Sheet Visibility"<br/>
 <a href="https://isc.sans.edu/forums/diary/Excel+4+Macros+Abnormal+Sheet+Visibility/26726/">https://isc.sans.edu/forums/diary/Excel+4+Macros+Abnormal+Sheet+Visibility/26726/</a><br/>
HP Printer Applications Certificate Revoked<br/>
 <a href="https://eclecticlight.co/2020/10/23/why-have-my-hp-printers-stopped-working-how-to-check-their-software-signature/">https://eclecticlight.co/2020/10/23/why-have-my-hp-printers-stopped-working-how-to-check-their-software-signature/</a><br/>
Link Previews and Privacy<br/>
 <a href="https://www.mysk.blog/2020/10/25/link-previews/">https://www.mysk.blog/2020/10/25/link-previews/</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7226" type="text/plain" language="en" />
<itunes:keywords>link previews, privacy, hp, certificates, macos, excel, visibility, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 26th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7224</itunes:episode>
<itunes:subtitle>Censys vs Shodan; Sooty; ML Attacks; #Samsung #S20 RCE; #VMWare Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Censys vs Shodan; Sooty; ML Attacks; #Samsung #S20 RCE; #VMWare Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7224.mp3" length="4759562" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7224.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7224</link>
<pubDate>Mon, 26 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[An Alternative to Shodan: Censys<br/>
 <a href="https://isc.sans.edu/forums/diary/An+Alternative+to+Shodan+Censys+with+UserAgent+CensysInspect11/26718/">https://isc.sans.edu/forums/diary/An+Alternative+to+Shodan+Censys+with+UserAgent+CensysInspect11/26718/</a><br/>
Sooty: SOC Analyst's All-in-One Tool<br/>
 <a href="https://isc.sans.edu/forums/diary/Sooty+SOC+Analysts+AllinOne+Tool/26714/">https://isc.sans.edu/forums/diary/Sooty+SOC+Analysts+AllinOne+Tool/26714/</a><br/>
Adversarial ML Threat Matrix<br/>
 <a href="https://github.com/mitre/advmlthreatmatrix">https://github.com/mitre/advmlthreatmatrix</a><br/>
Samsung S20 RCE<br/>
 <a href="https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/">https://labs.f-secure.com/blog/samsung-s20-rce-via-samsung-galaxy-store-app/</a><br/>
VMWare Advisory<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0023.html">https://www.vmware.com/security/advisories/VMSA-2020-0023.html</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7224" type="text/plain" language="en" />
<itunes:keywords>vmware, samson, s20, machine learning, sooty, censys, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7222</itunes:episode>
<itunes:subtitle>BazarLoader Samples; Secure Boot Reviews Stalled; Cisco Advisories
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BazarLoader Samples; Secure Boot Reviews Stalled; Cisco Advisories
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7222.mp3" length="4803813" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7222.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7222</link>
<pubDate>Fri, 23 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[BazarLoader Phishing Lures<br/>
 <a href="https://isc.sans.edu/forums/diary/BazarLoader+phishing+lures+plan+a+Halloween+party+get+a+bonus+and+be+fired+in+the+same+afternoon/26710/">https://isc.sans.edu/forums/diary/BazarLoader+phishing+lures+plan+a+Halloween+party+get+a+bonus+and+be+fired+in+the+same+afternoon/26710/</a><br/>
Stalled Reviews for Secure Boot Shim<br/>
 <a href="https://github.com/rhboot/shim-review/issues/120">https://github.com/rhboot/shim-review/issues/120</a><br/>
 <a href="https://github.com/rhboot/shim-review/issues/102#issuecomment-698963751">https://github.com/rhboot/shim-review/issues/102#issuecomment-698963751</a><br/>
Cisco Advisories<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7222" type="text/plain" language="en" />
<itunes:keywords>cisco, secure boot, uefi, shim, bazarloader, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7220</itunes:episode>
<itunes:subtitle>Agent Tesla Shipping Emails; CN Exploits Usual Vulns; URL Bar Spoofing; Oracle CPU
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Agent Tesla Shipping Emails; CN Exploits Usual Vulns; URL Bar Spoofing; Oracle CPU
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7220.mp3" length="4768713" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7220.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7220</link>
<pubDate>Thu, 22 Oct 2020 02:15:02 GMT</pubDate>
<description><![CDATA[Shipping Dangerous Goods<br/>
 <a href="https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/">https://isc.sans.edu/forums/diary/Shipping+dangerous+goods/26702/</a><br/>
Chinese State-Sponsored Actors Exploit Same Vulnerablities as Others<br/>
 <a href="https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF">https://media.defense.gov/2020/Oct/20/2002519884/-1/-1/0/CSA_CHINESE_EXPLOIT_VULNERABILITIES_UOO179811.PDF</a><br/>
URL Bar Spoofing Vulnerabilities<br/>
 <a href="https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html">https://thehackernews.com/2020/10/browser-address-spoofing-vulnerability.html</a><br/>
Oracle Quarterly Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpuoct2020.html">https://www.oracle.com/security-alerts/cpuoct2020.html</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7220" type="text/plain" language="en" />
<itunes:keywords>oracle, cpu, patch, url, url bar, chinese, nsa, tesla, agent tesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7218</itunes:episode>
<itunes:subtitle>Mirai in Python; Chrome Urgent Patch; QNAP ZeroLogon Patch; GravityRat; US Census Spoof
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mirai in Python; Chrome Urgent Patch; QNAP ZeroLogon Patch; GravityRat; US Census Spoof
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7218.mp3" length="4892694" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7218.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7218</link>
<pubDate>Wed, 21 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Mirai-alike Python Scanner<br/>
 <a href="https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/">https://isc.sans.edu/forums/diary/Miraialike+Python+Scanner/26698/</a><br/>
Google Chrome Update (actively exploited vulnerability fixed)<br/>
 <a href="https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html">https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html</a><br/>
QNAP Fixes ZeroLogon Vulnerability<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-20-07">https://www.qnap.com/en/security-advisory/qsa-20-07</a><br/>
GravityRat Going Multi Platform <br/>
 <a href="https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms">https://usa.kaspersky.com/about/press-releases/2020_infamous-gravity-rat-spyware-evolves-to-target-multiple-platforms</a><br/>
US Census Spoof<br/>
 <a href="https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020">https://beta.documentcloud.org/documents/20397864-fbi-flash-unattributed-entities-register-domains-10142020</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7218" type="text/plain" language="en" />
<itunes:keywords>us census, census, gravityrat, qnap, google, chrome, mirai, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7216</itunes:episode>
<itunes:subtitle>Out of Band #MSFT Patches; #SS7 Attacks; Adobe #Magento Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Out of Band #MSFT Patches; #SS7 Attacks; Adobe #Magento Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7216.mp3" length="4319241" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7216.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7216</link>
<pubDate>Tue, 20 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Out of Band MSFT Patches<br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17022</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-17023</a><br/>
Adobe Magento Patches<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb20-59.html">https://helpx.adobe.com/security/products/magento/apsb20-59.html</a><br/>
Attacks against SS7<br/>
 <a href="https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991">https://www.haaretz.com/israel-news/tech-news/.premium-exclusive-intricate-hack-against-israeli-crypto-execs-mossad-investigating-1.9211991</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/">https://www.bleepingcomputer.com/news/security/hackers-hijack-telegram-email-accounts-in-ss7-mobile-attack/</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7216" type="text/plain" language="en" />
<itunes:keywords>ss7, msft, patches, adobe, magento, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 19th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7214</itunes:episode>
<itunes:subtitle>CVE-2020-5135 #SonicWall RCE Vuln; Malspammer Mistakes; Traffic Analysis Quiz; Qualcom; Discord
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2020-5135 #SonicWall RCE Vuln; Malspammer Mistakes; Traffic Analysis Quiz; Qualcom; Discord
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7214.mp3" length="5792334" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7214.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7214</link>
<pubDate>Mon, 19 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[CVE-2020-5135 SonicWall Buffer Overflow<br/>
 <a href="https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/">https://isc.sans.edu/forums/diary/CVE20205135+Buffer+Overflow+in+SonicWall+VPNs+Patch+Now/26692/</a><br/>
Spammer Attached Mass Mailer Configuration Instead of Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/">https://isc.sans.edu/forums/diary/File+Selection+Gaffe/26694/</a><br/>
Traffic Analysis Quiz: Ugly-Wolf.net<br/>
 <a href="https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/">https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+UglyWolfnet/26688/</a><br/>
Qualcomm QCMAP Vulnerabilities<br/>
 <a href="https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities">https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities</a><br/>
Discord Desktop App RCE<br/>
 <a href="https://mksben.l0.cm/2020/10/discord-desktop-rce.html">https://mksben.l0.cm/2020/10/discord-desktop-rce.html</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7214" type="text/plain" language="en" />
<itunes:keywords>Discord, qualcomm, qcmap, android, traffic analysis, spammer, mistake, sonicwall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7212</itunes:episode>
<itunes:subtitle>Obfuscated #Python RAT; #BadNeighbor Update; BlueZ Vuln; Zoom E2EE 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated #Python RAT; #BadNeighbor Update; BlueZ Vuln; Zoom E2EE 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7212.mp3" length="4884631" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7212.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7212</link>
<pubDate>Fri, 16 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Obfuscated Python RAT<br/>
 <a href="https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/">https://isc.sans.edu/forums/diary/Nicely+Obfuscated+Python+RAT/26680/</a><br/>
BadNeighbor ICMPv6 Router Advertisement Update<br/>
 <a href="https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/">https://isc.sans.edu/forums/diary/CVE202016898+Windows+ICMPv6+Router+Advertisement+RRDNS+Option+Remote+Code+Execution+Vulnerability/26684/</a><br/>
BlueZ Vulnerability<br/>
 <a href="https://www.youtube.com/watch?v=qPYrLRausSw">https://www.youtube.com/watch?v=qPYrLRausSw</a><br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00435.html</a><br/>
 <a href="https://security.googleblog.com/">https://security.googleblog.com/</a> (available "soon")<br/>
Zoom Rolling Out End-to-End Encryption<br/>
 <a href="https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/">https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-offering/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7212" type="text/plain" language="en" />
<itunes:keywords>zoom, encryption, end-to-end, bluez, ibm, linux, bluetooth, badneighbor, icmpv6, ipv6, python, obfuscation, rat, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7210</itunes:episode>
<itunes:subtitle>TA511 Shathak Update; MSFT Patch Followup; Apple T2 Vuln Update; SAP Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TA511 Shathak Update; MSFT Patch Followup; Apple T2 Vuln Update; SAP Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7210.mp3" length="5042628" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7210.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7210</link>
<pubDate>Thu, 15 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[TA551/Shathak Word Docs Push IcedID and Bokbot<br/>
 <a href="https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/">https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/</a><br/>
MSFT Patch Tuesday Followup<br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16951</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16952</a><br/>
Apple T2 Chip Vulnerability Confirmed<br/>
 <a href="https://9to5mac.com/2020/10/13/t2-exploit-team/">https://9to5mac.com/2020/10/13/t2-exploit-team/</a><br/>
SAP Updates<br/>
 <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196">https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=558632196</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7210" type="text/plain" language="en" />
<itunes:keywords>SAP, Apple, T2, checkr8in, msft, shathak, ta551, icmpv6, icedid, bokbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7208</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7208.mp3" length="5571089" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7208.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7208</link>
<pubDate>Wed, 14 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/">https://isc.sans.edu/forums/diary/Microsoft+October+2020+Patch+Tuesday/26672/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/products/flash-player/apsb20-58.html">https://helpx.adobe.com/security/products/flash-player/apsb20-58.html</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7208" type="text/plain" language="en" />
<itunes:keywords>adobe, microsoft, icmpv6, router advertisements, ipv6, flash player, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7206</itunes:episode>
<itunes:subtitle>Nested MSG Files; Trickbot Takedown Attempt; Chrome Improving Cache Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Nested MSG Files; Trickbot Takedown Attempt; Chrome Improving Cache Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7206.mp3" length="4837092" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7206.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7206</link>
<pubDate>Tue, 13 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Nested .MSGs: Turtles All The Way Down<br/>
 <a href="https://isc.sans.edu/forums/diary/Nested+MSGs+Turtles+All+The+Way+Down/26668/">https://isc.sans.edu/forums/diary/Nested+MSGs+Turtles+All+The+Way+Down/26668/</a><br/>
Microsoft Attempting To Take Down Trickbot C2 Infrastructure<br/>
 <a href="https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/">https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/</a><br/>
Google Chrome Cache Partitioning<br/>
 <a href="https://developers.google.com/web/updates/2020/10/http-cache-partitioning">https://developers.google.com/web/updates/2020/10/http-cache-partitioning</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7206" type="text/plain" language="en" />
<itunes:keywords>msgs, nested, trickbot, takedown, microsoft, google, chrome, cache, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 12th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7204</itunes:episode>
<itunes:subtitle>Phishing Kits; Open Packaging; Analyzing MSGs; Cisco Flaws; Apple Flaws
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing Kits; Open Packaging; Analyzing MSGs; Cisco Flaws; Apple Flaws
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7204.mp3" length="4897065" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7204.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7204</link>
<pubDate>Mon, 12 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Phishing Kits As Far As The Eye Can See<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+kits+as+far+as+the+eye+can+see/26660/">https://isc.sans.edu/forums/diary/Phishing+kits+as+far+as+the+eye+can+see/26660/</a><br/>
Open Packaging Conventions<br/>
 <a href="https://isc.sans.edu/forums/diary/Open+Packaging+Conventions/26662/">https://isc.sans.edu/forums/diary/Open+Packaging+Conventions/26662/</a><br/>
Analyzing MSG Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+MSG+Files+With+pluginmsgsummary/26664/">https://isc.sans.edu/forums/diary/Analyzing+MSG+Files+With+pluginmsgsummary/26664/</a><br/>
Cisco Video Surveillance 8000 Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cdp-rcedos-mAHR8vNx">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cdp-rcedos-mAHR8vNx</a><br/>
55 New Apple Flaws<br/>
 <a href="https://samcurry.net/hacking-apple/">https://samcurry.net/hacking-apple/</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7204" type="text/plain" language="en" />
<itunes:keywords>phishing, youtube, oopc, packaging, opc, msg, outlook, cisco, video, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7202</itunes:episode>
<itunes:subtitle>Hashicorp Vault Vuln; Ryuk Writeup; Ricky Tan (@sans_edu) Zeek and Maltego Casefile
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hashicorp Vault Vuln; Ryuk Writeup; Ricky Tan (@sans_edu) Zeek and Maltego Casefile
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7202.mp3" length="16438277" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7202.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7202</link>
<pubDate>Fri, 09 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Hashicorp Vault Vulnerabilities<br/>
 <a href="https://googleprojectzero.blogspot.com/2020/10/enter-the-vault-auth-issues-hashicorp-vault.html">https://googleprojectzero.blogspot.com/2020/10/enter-the-vault-auth-issues-hashicorp-vault.html</a><br/>
Ryuk Ransomware Writeup<br/>
 <a href="https://thedfirreport.com/2020/10/08/ryuks-return/">https://thedfirreport.com/2020/10/08/ryuks-return/</a><br/>
Ricky Tan: Zeek Log Reconnaissance with Netowrk Graphs Using Maltego Casefile<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/securityanalytics/zeek-log-reconnaissance-network-graphs-maltego-casefile-39815">https://www.sans.org/reading-room/whitepapers/securityanalytics/zeek-log-reconnaissance-network-graphs-maltego-casefile-39815</a><br/>
]]></description>
<itunes:duration>19:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7202" type="text/plain" language="en" />
<itunes:keywords>sans edu, ricky tan, maltego, casefile, zeek, ryuk, hashicorp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7200</itunes:episode>
<itunes:subtitle>Nobody Attacking You Today; Google Chrome/Android Patches; QNAP Patches; Comcast Remote Vuln.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Nobody Attacking You Today; Google Chrome/Android Patches; QNAP Patches; Comcast Remote Vuln.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7200.mp3" length="5761988" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7200.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7200</link>
<pubDate>Thu, 08 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Today, Nobody is Going to Attack You<br/>
 <a href="https://isc.sans.edu/forums/diary/Today+Nobody+is+Going+to+Attack+You/26654/">https://isc.sans.edu/forums/diary/Today+Nobody+is+Going+to+Attack+You/26654/</a><br/>
Google Chrome Patches<br/>
 <a href="https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html</a><br/>
Android Security Update<br/>
 <a href="https://source.android.com/security/bulletin/2020-10-01">https://source.android.com/security/bulletin/2020-10-01</a><br/>
QNAP Patches Helpdesk Application<br/>
 <a href="https://www.qnap.com/en/security-advisory/QSA-20-08">https://www.qnap.com/en/security-advisory/QSA-20-08</a><br/>
Comcast Remote Control Evesdropping<br/>
 <a href="https://www.guardicore.com/2020/10/wareztheremote-turning-remotes-into-listening-devices/">https://www.guardicore.com/2020/10/wareztheremote-turning-remotes-into-listening-devices/</a><br/>
]]></description>
<itunes:duration>6:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7200" type="text/plain" language="en" />
<itunes:keywords>comcast, remote, evesdropping, microphone, qnap, android, google, chrome, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7198</itunes:episode>
<itunes:subtitle>Apple T2 Chip Vulnerability; NVIDIA; Cloudflare; Gavatar Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple T2 Chip Vulnerability; NVIDIA; Cloudflare; Gavatar Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7198.mp3" length="7159752" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7198.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7198</link>
<pubDate>Wed, 07 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Apple T2 Chip Vulnerability<br/>
 <a href="https://ironpeak.be/blog/crouching-t2-hidden-danger/">https://ironpeak.be/blog/crouching-t2-hidden-danger/</a><br/>
NVIDIA Patches<br/>
 <a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5075">https://nvidia.custhelp.com/app/answers/detail/a_id/5075</a><br/>
Cloudflare DDoS Alerts<br/>
 <a href="https://blog.cloudflare.com/announcing-ddos-alerts/">https://blog.cloudflare.com/announcing-ddos-alerts/</a><br/>
Gravatar Privacy Issue<br/>
 <a href="https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/">https://www.bleepingcomputer.com/news/security/online-avatar-service-gravatar-allows-mass-collection-of-user-info/</a><br/>
]]></description>
<itunes:duration>8:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7198" type="text/plain" language="en" />
<itunes:keywords>gravatar, cloudflare, nvidia, apple, t2, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7196</itunes:episode>
<itunes:subtitle>Repetition Obfuscation; UEFI Malware; AV Priv Escalation Flaw; Rapid7 SMTP Scan
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Repetition Obfuscation; UEFI Malware; AV Priv Escalation Flaw; Rapid7 SMTP Scan
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7196.mp3" length="4922304" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7196.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7196</link>
<pubDate>Tue, 06 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Obfuscation and Repetition<br/>
 <a href="https://isc.sans.edu/forums/diary/Obfuscation+and+Repetition/26648/">https://isc.sans.edu/forums/diary/Obfuscation+and+Repetition/26648/</a><br/>
Compromised UEFI Payload Found<br/>
 <a href="https://securelist.com/mosaicregressor/98849/">https://securelist.com/mosaicregressor/98849/</a><br/>
Privilege Escalation Flaw in All AntiVirus Products<br/>
 <a href="https://www.cyberark.com/resources/threat-research-blog/anti-virus-vulnerabilities-who-s-guarding-the-watch-tower">https://www.cyberark.com/resources/threat-research-blog/anti-virus-vulnerabilities-who-s-guarding-the-watch-tower</a><br/>
Rapid7 SMTP "NICER" Report<br/>
 <a href="https://blog.rapid7.com/2020/10/02/nicer-protocol-deep-dive-internet-exposure-of-smtp/">https://blog.rapid7.com/2020/10/02/nicer-protocol-deep-dive-internet-exposure-of-smtp/</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7196" type="text/plain" language="en" />
<itunes:keywords>smtp, nicer, rapid7, anitvirus, uefi, obfuscation, repetition, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 5th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7194</itunes:episode>
<itunes:subtitle>Phishing Kit; Huawei Botnet; SQL Server CU 8; Telstra BGP; Raccine @cyb3rops
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing Kit; Huawei Botnet; SQL Server CU 8; Telstra BGP; Raccine @cyb3rops
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7194.mp3" length="5381637" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7194.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7194</link>
<pubDate>Mon, 05 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Analysis of a Phishing Kit<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+Phishing+Kit/26634/">https://isc.sans.edu/forums/diary/Analysis+of+a+Phishing+Kit/26634/</a><br/>
Hoaxcalls Botnet Scanning for Huawei Home Gateway<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+for+SOHO+Routers/26638/">https://isc.sans.edu/forums/diary/Scanning+for+SOHO+Routers/26638/</a><br/>
SQL Server Cumulative Update 8 <br/>
 <a href="https://support.microsoft.com/en-us/help/4577194/cumulative-update-8-for-sql-server-2019">https://support.microsoft.com/en-us/help/4577194/cumulative-update-8-for-sql-server-2019</a><br/>
Telstra Accidentially Reroutes Proton Mail Traffic<br/>
 <a href="https://protonmail.com/blog/bgp-hijacking-september-2020/">https://protonmail.com/blog/bgp-hijacking-september-2020/</a><br/>
"Raccine" Ransomware Vaccine<br/>
 <a href="https://github.com/Neo23x0/Raccine">https://github.com/Neo23x0/Raccine</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7194" type="text/plain" language="en" />
<itunes:keywords>raccine, ransomware, vaccine, shadow volumes, vssadmin, telstra, sql server, moaxcalls, botnet, huawei, phishing, amex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7192</itunes:episode>
<itunes:subtitle>Azure AD Logs; Outdated Intel; Apple Pulls Patches; EMOTET Check Service
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Azure AD Logs; Outdated Intel; Apple Pulls Patches; EMOTET Check Service
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7192.mp3" length="4475397" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7192.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7192</link>
<pubDate>Fri, 02 Oct 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Making Sensor of Azure AD Activity Logs<br/>
<a href="https://isc.sans.edu/forums/diary/Making+sense+of+Azure+AD+AAD+activity+logs/26626/">https://isc.sans.edu/forums/diary/Making+sense+of+Azure+AD+AAD+activity+logs/26626/</a><br/>
IOCs Turning into IOOIs<br/>
 <a href="https://isc.sans.edu/forums/diary/IOCs+turning+into+IOOIs/26624/">https://isc.sans.edu/forums/diary/IOCs+turning+into+IOOIs/26624/</a><br/>
Apple Security Patch Pulled<br/>
 <a href="https://mrmacintosh.com/mojave-2020-005-security-update-causing-major-problems-updated">https://mrmacintosh.com/mojave-2020-005-security-update-causing-major-problems-updated</a><br/>
Have I Been EMOTET Service<br/>
 <a href="https://www.haveibeenemotet.com/">https://www.haveibeenemotet.com/</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7192" type="text/plain" language="en" />
<itunes:keywords>emotet, apple, safari, patch, pulled, ios, iooi, azuer ad, aad, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 1st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7190</itunes:episode>
<itunes:subtitle>FPURL.xml Scanning; HP Device Manager Backdoor; KensingtonWorks RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
FPURL.xml Scanning; HP Device Manager Backdoor; KensingtonWorks RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7190.mp3" length="5196598" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7190.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7190</link>
<pubDate>Thu, 01 Oct 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Scans for FPURL.xml: Reconnaissance or Not?<br/>
 <a href="https://isc.sans.edu/forums/diary/Scans+for+FPURLxml+Reconnaissance+or+Not/26622/">https://isc.sans.edu/forums/diary/Scans+for+FPURLxml+Reconnaissance+or+Not/26622/</a><br/>
HP Device Manager Backdoor<br/>
 <a href="https://support.hp.com/us-en/document/c06921908">https://support.hp.com/us-en/document/c06921908</a><br/>
 <a href="https://www.theregister.com/2020/09/30/hp_device_manager_backdoor_database_account/">https://www.theregister.com/2020/09/30/hp_device_manager_backdoor_database_account/</a><br/>
KensingtonWorks RCE<br/>
 <a href="https://robertheaton.com/another-rce-in-kensingtonworks/">https://robertheaton.com/another-rce-in-kensingtonworks/</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7190" type="text/plain" language="en" />
<itunes:keywords>kensington, kensingtonworks, mouse, hp, device manager, thin client, fpurl.xml, windows hello, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7188</itunes:episode>
<itunes:subtitle>Contractor/Partner Remote Access; Microsoft ZeroLogon Update; Cisco Patches; Foxit PDF Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Contractor/Partner Remote Access; Microsoft ZeroLogon Update; Cisco Patches; Foxit PDF Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7188.mp3" length="4182485" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7188.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7188</link>
<pubDate>Wed, 30 Sep 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Managing Remote Access for Contractors and Partners<br/>
 <a href="https://isc.sans.edu/forums/diary/Managing+Remote+Access+for+Partners+Contractors/26614/#comments">https://isc.sans.edu/forums/diary/Managing+Remote+Access+for+Partners+Contractors/26614/#comments</a><br/>
Updated Windows ZeroLogon Advisory<br/>
 <a href="https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc">https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc</a><br/>
Cisco Patching Exploited DoS Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz</a><br/>
FoxIT PDF Reader Update<br/>
 <a href="https://www.foxitsoftware.com/support/security-bulletins.html">https://www.foxitsoftware.com/support/security-bulletins.html</a><br/>
]]></description>
<itunes:duration>4:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7188" type="text/plain" language="en" />
<itunes:keywords>foxit, pdf, cisco, windows, zerologon, contractors, partners, remote access, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7186</itunes:episode>
<itunes:subtitle>Tyler Breach; Obfuscated PowerShell Backdoor; QNAP Patch; TrendMicro Apex One Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tyler Breach; Obfuscated PowerShell Backdoor; QNAP Patch; TrendMicro Apex One Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7186.mp3" length="4693375" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7186.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7186</link>
<pubDate>Tue, 29 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Some Tyler Technologies Customers Targeted after Breach<br/>
 <a href="https://isc.sans.edu/forums/diary/Some+Tyler+Technologies+Customers+Targeted+with+The+Installation+of+a+Bomgar+Client/26610/">https://isc.sans.edu/forums/diary/Some+Tyler+Technologies+Customers+Targeted+with+The+Installation+of+a+Bomgar+Client/26610/</a><br/>
Obfuscated PowerShell Backdoor<br/>
 <a href="https://isc.sans.edu/forums/diary/PowerShell+Backdoor+Launched+from+a+ShellCode/26602/">https://isc.sans.edu/forums/diary/PowerShell+Backdoor+Launched+from+a+ShellCode/26602/</a><br/>
QNAP Fixes AgeLocker Vulnerability in Photo Station<br/>
 <a href="https://www.qnap.com/de-de/security-advisory/qsa-20-06">https://www.qnap.com/de-de/security-advisory/qsa-20-06</a><br/>
TrendMicro Apex One Vulnerablity<br/>
 <a href="https://success.trendmicro.com/product-support/apex-one">https://success.trendmicro.com/product-support/apex-one</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7186" type="text/plain" language="en" />
<itunes:keywords>tyler, bomgard, beyond trust, trendmicro, qnap, agelocker, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7184</itunes:episode>
<itunes:subtitle>Exchange Online; Corrupt BASE64; Fortinet VPNs; Single Use CC Numbers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exchange Online; Corrupt BASE64; Fortinet VPNs; Single Use CC Numbers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7184.mp3" length="4748964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7184.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7184</link>
<pubDate>Mon, 28 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Securing Exchange Online<br/>
 <a href="https://isc.sans.edu/forums/diary/Securing+Exchange+Online+Guest+Diary/26600/">https://isc.sans.edu/forums/diary/Securing+Exchange+Online+Guest+Diary/26600/</a><br/>
Decoding Corrupt BASE64<br/>
 <a href="https://isc.sans.edu/forums/diary/Decoding+Corrupt+BASE64+Strings/26606/">https://isc.sans.edu/forums/diary/Decoding+Corrupt+BASE64+Strings/26606/</a><br/>
Fortinet VPN Default Setting Problem<br/>
 <a href="https://securingsam.com/breaching-the-fort/">https://securingsam.com/breaching-the-fort/</a><br/>
Single Use Credit Cards Numbers <br/>
 <a href="https://www.helpnetsecurity.com/2020/09/25/privacy-cards/">https://www.helpnetsecurity.com/2020/09/25/privacy-cards/</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7184" type="text/plain" language="en" />
<itunes:keywords>credit cards, fortinet, vpn, certificates, base64, exchange online, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 25th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7182</itunes:episode>
<itunes:subtitle>PowerShell Debugging; Zerologon Exploited; Instagram Vulnerability; Apple Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PowerShell Debugging; Zerologon Exploited; Instagram Vulnerability; Apple Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7182.mp3" length="5097856" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7182.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7182</link>
<pubDate>Fri, 25 Sep 2020 02:40:02 GMT</pubDate>
<description><![CDATA[Party in Ibiza with PowerShell<br/>
 <a href="https://isc.sans.edu/forums/diary/Party+in+Ibiza+with+PowerShell/26594/">https://isc.sans.edu/forums/diary/Party+in+Ibiza+with+PowerShell/26594/</a><br/>
Microsoft Tracking Zerologon Exploits<br/>
 <a href="https://twitter.com/MsftSecIntel/status/1308941504707063808">https://twitter.com/MsftSecIntel/status/1308941504707063808</a><br/>
Apple Patches<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Instagram for Android Vulnerability<br/>
 <a href="https://blog.checkpoint.com/2020/09/24/instahack-how-researchers-were-able-to-take-over-the-instagram-app-using-a-malicious-image/">https://blog.checkpoint.com/2020/09/24/instahack-how-researchers-were-able-to-take-over-the-instagram-app-using-a-malicious-image/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7182" type="text/plain" language="en" />
<itunes:keywords>instagram, android, microsoft, zerologon, powershell, debugger, obfuscation, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7180</itunes:episode>
<itunes:subtitle>Dynamic Maldocs; SAMBA and ZeroLogon; Google Chrome Update; QNAP Devices
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dynamic Maldocs; SAMBA and ZeroLogon; Google Chrome Update; QNAP Devices
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7180.mp3" length="4705081" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7180.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7180</link>
<pubDate>Thu, 24 Sep 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Dynamic Malicious Word Document<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Word+Document+with+Dynamic+Content/26590/">https://isc.sans.edu/forums/diary/Malicious+Word+Document+with+Dynamic+Content/26590/</a><br/>
Old Versions of SAMBA Affected by ZeroLogon Vulnerability<br/>
 <a href="https://www.samba.org/samba/security/CVE-2020-1472.html">https://www.samba.org/samba/security/CVE-2020-1472.html</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html">https://chromereleases.googleblog.com/2020/09/stable-channel-update-for-desktop_21.html</a><br/>
QNAP Devices hit by AgeLocker Ransomware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/agelocker-ransomware-targets-qnap-nas-devices-steals-data/">https://www.bleepingcomputer.com/news/security/agelocker-ransomware-targets-qnap-nas-devices-steals-data/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7180" type="text/plain" language="en" />
<itunes:keywords>qnap, agelocker, google, chrome, samba, zerologon, word, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7178</itunes:episode>
<itunes:subtitle>Citrix ADC Updates; Firefox Update; RDP vs. Ransomware; iOS 14 Jailbreak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix ADC Updates; Firefox Update; RDP vs. Ransomware; iOS 14 Jailbreak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7178.mp3" length="4673634" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7178.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7178</link>
<pubDate>Wed, 23 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Citrix ADC Udpates<br/>
 <a href="https://support.citrix.com/article/CTX281474">https://support.citrix.com/article/CTX281474</a><br/>
Firefox Version 81 Released<br/>
 <a href="https://www.mozilla.org/en-US/firefox/81.0/releasenotes/">https://www.mozilla.org/en-US/firefox/81.0/releasenotes/</a><br/>
Simple Scan Drops Ransomware Risk<br/>
 <a href="https://www.accesswire.com/607018/Corvus-Updates-Scan-Technology-with-RDP-Detection-Slashes-Ransomware-Claims-by-65">https://www.accesswire.com/607018/Corvus-Updates-Scan-Technology-with-RDP-Detection-Slashes-Ransomware-Claims-by-65</a><br/>
iOS 14 Jailbreak<br/>
 <a href="https://checkra.in/news/2020/09/iOS-14-announcement">https://checkra.in/news/2020/09/iOS-14-announcement</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7178" type="text/plain" language="en" />
<itunes:keywords>ios 14, jailbreak, checkra1n, ransomware, rdp, firefox, citrix, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7176</itunes:episode>
<itunes:subtitle>Overlay Phishing; MacOS Code Injection; Snort/ClamAV and Cobalt Strike
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Overlay Phishing; MacOS Code Injection; Snort/ClamAV and Cobalt Strike
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7176.mp3" length="5218906" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7176.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7176</link>
<pubDate>Tue, 22 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Slightly Broken Overlay Phishing<br/>
 <a href="https://isc.sans.edu/forums/diary/Slightly+broken+overlay+phishing/26586/">https://isc.sans.edu/forums/diary/Slightly+broken+overlay+phishing/26586/</a><br/>
MacOS Code Injection via Third Party Frameworks<br/>
 <a href="https://www.trustedsec.com/blog/macos-injection-via-third-party-frameworks">https://www.trustedsec.com/blog/macos-injection-via-third-party-frameworks</a><br/>
Snort/ClamAV Cobalt Strike Detection<br/>
 <a href="https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html#more">https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html#more</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7176" type="text/plain" language="en" />
<itunes:keywords>snort, clamav, coablt strike, macos, code injection, electron, .net, overlay, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7174</itunes:episode>
<itunes:subtitle>Python in Word Docs; Salesforce Phish; Google Appspot Phish; Sysmon Clipboard monitor 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Python in Word Docs; Salesforce Phish; Google Appspot Phish; Sysmon Clipboard monitor 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7174.mp3" length="4868918" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7174.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7174</link>
<pubDate>Mon, 21 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[A Mix of Python and VBA in a Malicious Word Document<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Mix+of+Python+VBA+in+a+Malicious+Word+Document/26578/">https://isc.sans.edu/forums/diary/A+Mix+of+Python+VBA+in+a+Malicious+Word+Document/26578/</a><br/>
Salesforce Phish<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+Salesforce+Phishing+Emails/26582/">https://isc.sans.edu/forums/diary/Analysis+of+a+Salesforce+Phishing+Emails/26582/</a><br/>
Google App Engine Used in Phishing Attacks<br/>
 <a href="https://medium.com/@marcelx/attackers-are-abusing-googles-app-engine-to-circumvent-enterprise-security-solutions-again-eda8345d531d">https://medium.com/@marcelx/attackers-are-abusing-googles-app-engine-to-circumvent-enterprise-security-solutions-again-eda8345d531d</a><br/>
Sysmon Adds Clipboard Monitoring<br/>
 <a href="https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon">https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon</a><br/>
Windows Defender No Longer Able to Download Files<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-windows-defender-ability-after-security-concerns/">https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-windows-defender-ability-after-security-concerns/</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7174" type="text/plain" language="en" />
<itunes:keywords>windows defender, lolbin, sysmon, clipboard, google, app engine, appspot, salesforce, phishing, python, vba, word, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7172</itunes:episode>
<itunes:subtitle>OSSEC Active Response; MSFT Mac Office Patch; VMWare Patch; Secure Boot; End of Flash
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OSSEC Active Response; MSFT Mac Office Patch; VMWare Patch; Secure Boot; End of Flash
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7172.mp3" length="4735062" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7172.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7172</link>
<pubDate>Fri, 18 Sep 2020 02:00:02 GMT</pubDate>
<description><![CDATA[OSSEC Active Response<br/>
 <a href="https://isc.sans.edu/forums/diary/Suspicious+Endpoint+Containment+with+OSSEC/26576/">https://isc.sans.edu/forums/diary/Suspicious+Endpoint+Containment+with+OSSEC/26576/</a><br/>
Microsoft Patch for Office for Mac<br/>
 <a href="https://docs.microsoft.com/en-us/officeupdates/release-notes-office-for-mac">https://docs.microsoft.com/en-us/officeupdates/release-notes-office-for-mac</a><br/>
VMWare Fusion Vulnerablity<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0020.html">https://www.vmware.com/security/advisories/VMSA-2020-0020.html</a><br/>
NSA Secure Boot Configuration Guide<br/>
 <a href="https://media.defense.gov/2020/Sep/15/2002497594/-1/-1/0/CTR-UEFI-SECURE-BOOT-CUSTOMIZATION-20200915.PDF/CTR-UEFI-SECURE-BOOT-CUSTOMIZATION-20200915.PDF">https://media.defense.gov/2020/Sep/15/2002497594/-1/-1/0/CTR-UEFI-SECURE-BOOT-CUSTOMIZATION-20200915.PDF/CTR-UEFI-SECURE-BOOT-CUSTOMIZATION-20200915.PDF</a><br/>
Microsoft Edge Warns Users of Adobe Flash End of Support<br/>
 <a href="https://blogs.windows.com/msedgedev/2020/09/04/update-adobe-flash-end-support/">https://blogs.windows.com/msedgedev/2020/09/04/update-adobe-flash-end-support/</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7172" type="text/plain" language="en" />
<itunes:keywords>microsft, edge, flash, nsa, vmwware, secure boot, uefi, office, mac, ossec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7170</itunes:episode>
<itunes:subtitle>Mirai vs Amanda; Apple Updates iOS/iPadOS/WatchOS and Safari
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mirai vs Amanda; Apple Updates iOS/iPadOS/WatchOS and Safari
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7170.mp3" length="4652424" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7170.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7170</link>
<pubDate>Thu, 17 Sep 2020 02:30:03 GMT</pubDate>
<description><![CDATA[Most Recent "Mirai" Bot Includes Code to Target Backups<br/>
 <a href="https://isc.sans.edu/forums/diary/Do+Vulnerabilities+Ever+Get+Old+Recent+Mirai+Variant+Scanning+for+20+Year+Old+Amanda+Version/26572/">https://isc.sans.edu/forums/diary/Do+Vulnerabilities+Ever+Get+Old+Recent+Mirai+Variant+Scanning+for+20+Year+Old+Amanda+Version/26572/</a><br/>
Apple Security Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7170" type="text/plain" language="en" />
<itunes:keywords>safari, apple, ios, ipados, watchos, amanda, backup, mirai, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7168</itunes:episode>
<itunes:subtitle>Malware Quiz; Magento 1 Attacks; Adobe Media Enc. Patch; Zerologin/Finger Reminders
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Quiz; Magento 1 Attacks; Adobe Media Enc. Patch; Zerologin/Finger Reminders
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7168.mp3" length="5325703" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7168.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7168</link>
<pubDate>Wed, 16 Sep 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Traffic Analysis Quiz: Oh No... Another Infection<br/>
 <a href="https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Oh+No+Another+Infection/26566/">https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Oh+No+Another+Infection/26566/</a><br/>
Magento 1 Stores Targeted By Recent Attack<br/>
 <a href="https://sansec.io/research/largest-magento-hack-to-date">https://sansec.io/research/largest-magento-hack-to-date</a><br/>
Adobe Media Encoder Patch<br/>
 <a href="https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html">https://helpx.adobe.com/security/products/media-encoder/apsb20-57.html</a><br/>
Zerologin Reminder<br/>
 <a href="https://www.secura.com/pathtoimg.php?id=2055">https://www.secura.com/pathtoimg.php?id=2055</a><br/>
Windows "Finger" Utility Abused<br/>
 <a href="http://hyp3rlinx.altervista.org/advisories/Windows_TCPIP_Finger_Command_C2_Channel_and_Bypassing_Security_Software.txt">http://hyp3rlinx.altervista.org/advisories/Windows_TCPIP_Finger_Command_C2_Channel_and_Bypassing_Security_Software.txt</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7168" type="text/plain" language="en" />
<itunes:keywords>finger, zerologin, adobe, magento, traffic analysis, quiz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7166</itunes:episode>
<itunes:subtitle>.well-known; BLE Lock Replay Vulnerability; Mobile Iron MDM Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
.well-known; BLE Lock Replay Vulnerability; Mobile Iron MDM Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7166.mp3" length="4332049" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7166.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7166</link>
<pubDate>Tue, 15 Sep 2020 03:25:02 GMT</pubDate>
<description><![CDATA[Not Everything About ".well-known" is Well Known<br/>
 <a href="https://isc.sans.edu/forums/diary/Not+Everything+About+wellknown+is+Well+Known/26564/">https://isc.sans.edu/forums/diary/Not+Everything+About+wellknown+is+Well+Known/26564/</a><br/>
BLE Lock Vulnerable to Replay Attack<br/>
 <a href="https://www.pentestpartners.com/security-blog/360lock-smart-lock-review/">https://www.pentestpartners.com/security-blog/360lock-smart-lock-review/</a><br/>
Mobile Iron Exploit Released<br/>
 <a href="https://blog.orange.tw/2020/09/how-i-hacked-facebook-again-mobileiron-mdm-rce.html">https://blog.orange.tw/2020/09/how-i-hacked-facebook-again-mobileiron-mdm-rce.html</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7166" type="text/plain" language="en" />
<itunes:keywords>mobile iron, mdm, orange, jndi, ble, lock, replay, well-known, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7164</itunes:episode>
<itunes:subtitle>Pillaging the Clipboard; PANOS Patch; Softswitch VoIP Malware; Zerologon
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Pillaging the Clipboard; PANOS Patch; Softswitch VoIP Malware; Zerologon
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7164.mp3" length="5350559" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7164.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7164</link>
<pubDate>Mon, 14 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Pillaging and Protecting the Clipboard<br/>
 <a href="https://isc.sans.edu/forums/diary/Whats+in+Your+Clipboard+Pillaging+and+Protecting+the+Clipboard/26556/">https://isc.sans.edu/forums/diary/Whats+in+Your+Clipboard+Pillaging+and+Protecting+the+Clipboard/26556/</a><br/>
Critical Vulnerability in PANOS<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2020-2040">https://security.paloaltonetworks.com/CVE-2020-2040</a><br/>
Linux VoIP Softswitch Malware<br/>
 <a href="https://www.welivesecurity.com/2020/09/10/who-callin-cdrthief-linux-voip-softswitches/">https://www.welivesecurity.com/2020/09/10/who-callin-cdrthief-linux-voip-softswitches/</a><br/>
CVE-2020-1472 Zerologon Privilege Escalation Vulnerability<br/>
 <a href="https://www.secura.com/blog/zero-logon">https://www.secura.com/blog/zero-logon</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7164" type="text/plain" language="en" />
<itunes:keywords>clipboard, panos, palo alto, voip, softwitch, linux, malware, zerologon, cve-2020-1472, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7162</itunes:episode>
<itunes:subtitle>Dridex Update; Zoom 2FA; AMD CPU Lock; BLURtooth
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dridex Update; Zoom 2FA; AMD CPU Lock; BLURtooth
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7162.mp3" length="6455016" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7162.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7162</link>
<pubDate>Fri, 11 Sep 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Recent Dridex Activity<br/>
 <a href="https://isc.sans.edu/forums/diary/Recent+Dridex+activity/26550/">https://isc.sans.edu/forums/diary/Recent+Dridex+activity/26550/</a><br/>
Zoom Bombings and Zoom 2FA<br/>
 <a href="https://arxiv.org/abs/2009.03822">https://arxiv.org/abs/2009.03822</a><br/>
 <a href="https://blog.zoom.us/secure-your-zoom-account-with-two-factor-authentication/">https://blog.zoom.us/secure-your-zoom-account-with-two-factor-authentication/</a><br/>
AMD Server CPUs May Be Locked to Particular Motherboard<br/>
 <a href="https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-for-enhanced-security-at-a-cost/">https://www.servethehome.com/amd-psb-vendor-locks-epyc-cpus-for-enhanced-security-at-a-cost/</a><br/>
BLURtooth Vulnerability<br/>
 <a href="https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/blurtooth/">https://www.bluetooth.com/learn-about-bluetooth/bluetooth-technology/bluetooth-security/blurtooth/</a><br/>
]]></description>
<itunes:duration>7:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7162" type="text/plain" language="en" />
<itunes:keywords>BLURtooth, bluetooth, amd, cpu, zoom, dridex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7160</itunes:episode>
<itunes:subtitle>MacOS 11 Network Traffic; Azure Auto Patching Windows; WeaveScope Used for Docker Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS 11 Network Traffic; Azure Auto Patching Windows; WeaveScope Used for Docker Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7160.mp3" length="4665589" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7160.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7160</link>
<pubDate>Thu, 10 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[MacOS 11 Network Traffic <br/>
 <a href="https://isc.sans.edu/forums/diary/A+First+Look+at+macOS+11+Big+Sur+Network+Traffic+New+Now+with+more+GREASE/26548/">https://isc.sans.edu/forums/diary/A+First+Look+at+macOS+11+Big+Sur+Network+Traffic+New+Now+with+more+GREASE/26548/</a><br/>
Azure Offers Automatic Windows VM Patching<br/>
 <a href="https://azure.microsoft.com/en-us/updates/automatic-vm-guest-patching-now-in-preview/">https://azure.microsoft.com/en-us/updates/automatic-vm-guest-patching-now-in-preview/</a><br/>
WeaveScope Used to Attack Docker Infrastructure<br/>
 <a href="https://www.intezer.com/blog/cloud-workload-protection/attackers-abusing-legitimate-cloud-monitoring-tools-to-conduct-cyber-attacks/">https://www.intezer.com/blog/cloud-workload-protection/attackers-abusing-legitimate-cloud-monitoring-tools-to-conduct-cyber-attacks/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7160" type="text/plain" language="en" />
<itunes:keywords>weavescope, docker, azure, windows, patching, macos, bigsur, tls, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7158</itunes:episode>
<itunes:subtitle>Patch Tuesday: Microsoft, Adobe, Intel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Patch Tuesday: Microsoft, Adobe, Intel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7158.mp3" length="5546594" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7158.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7158</link>
<pubDate>Wed, 09 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+September+2020+Patch+Tuesday/26544/">https://isc.sans.edu/forums/diary/Microsoft+September+2020+Patch+Tuesday/26544/</a><br/>
Adobe Security Bulletins<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Intel Patches<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/default.html">https://www.intel.com/content/www/us/en/security-center/default.html</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7158" type="text/plain" language="en" />
<itunes:keywords>Intel, Adobe, Microsoft, Patches, BIOS, exchange, sharepoint, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7156</itunes:episode>
<itunes:subtitle>XXE/VB 6.0 Malware; OLE and ZIP; Golang XSS; "Baka" Skimmer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XXE/VB 6.0 Malware; OLE and ZIP; Golang XSS; "Baka" Skimmer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7156.mp3" length="4642906" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7156.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7156</link>
<pubDate>Tue, 08 Sep 2020 02:00:02 GMT</pubDate>
<description><![CDATA[A Blast From The Past: XXEncoded VB 6.0 Trojan<br/>
 <a href="https://isc.sans.edu/forums/diary/A+blast+from+the+past+XXEncoded+VB60+Trojan/26538/">https://isc.sans.edu/forums/diary/A+blast+from+the+past+XXEncoded+VB60+Trojan/26538/</a><br/>
Office: About OLE and ZIP Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Office+About+OLE+and+ZIP+Files/26540/">https://isc.sans.edu/forums/diary/Office+About+OLE+and+ZIP+Files/26540/</a><br/>
Go XSS Vulnerability<br/>
 <a href="https://seclists.org/fulldisclosure/2020/Sep/5">https://seclists.org/fulldisclosure/2020/Sep/5</a><br/>
"Baka" JavaScript Skimmer<br/>
 <a href="https://usa.visa.com/content/dam/VCOM/global/support-legal/documents/visa-security-alert-baka-javascript-skimmer.pdf">https://usa.visa.com/content/dam/VCOM/global/support-legal/documents/visa-security-alert-baka-javascript-skimmer.pdf</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7156" type="text/plain" language="en" />
<itunes:keywords>baka, javascript, xss, golang, ole, office, zip, xxencode, visual basic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7154</itunes:episode>
<itunes:subtitle>Anti-Sandbox via NTP; Android DoH; DDoS Extortion; Cisco Jabber Followup
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Anti-Sandbox via NTP; Android DoH; DDoS Extortion; Cisco Jabber Followup
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7154.mp3" length="5222925" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7154.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7154</link>
<pubDate>Fri, 04 Sep 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Sandbox Evasion Using NTP<br/>
 <a href="https://isc.sans.edu/forums/diary/Sandbox+Evasion+Using+NTP/26534/">https://isc.sans.edu/forums/diary/Sandbox+Evasion+Using+NTP/26534/</a><br/>
Android DNS over HTTPS<br/>
 <a href="https://blog.chromium.org/2020/09/a-safer-and-more-private-browsing.html">https://blog.chromium.org/2020/09/a-safer-and-more-private-browsing.html</a><br/>
Cisco Jabber Vulnerability Fullowup<br/>
 <a href="https://watchcom.no/nyheter/nyhetsarkiv/uncovers-cisco-jabber-vulnerabilities/">https://watchcom.no/nyheter/nyhetsarkiv/uncovers-cisco-jabber-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7154" type="text/plain" language="en" />
<itunes:keywords>ddos, cisco, android, sandbox, ntp, doh, extortion, rddos, rdos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7152</itunes:episode>
<itunes:subtitle>Evil Windows Python; iOS 13.7; Cisco Jabber Patch; MoFi Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Evil Windows Python; iOS 13.7; Cisco Jabber Patch; MoFi Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7152.mp3" length="5304121" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7152.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7152</link>
<pubDate>Thu, 03 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Python and Risky Windows API Calls<br/>
 <a href="https://isc.sans.edu/forums/diary/Python+and+Risky+Windows+API+Calls/26530/">https://isc.sans.edu/forums/diary/Python+and+Risky+Windows+API+Calls/26530/</a><br/>
QNAP Updates<br/>
 <a href="https://www.qnap.com/en/release-notes/qts/4.3.6.1411/20200825">https://www.qnap.com/en/release-notes/qts/4.3.6.1411/20200825</a><br/>
 <a href="https://www.qnap.com/en/release-notes/qts/4.4.3.1400/20200817">https://www.qnap.com/en/release-notes/qts/4.4.3.1400/20200817</a><br/>
iOS 13.7 Update<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Cisco Jabber Update<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-jabber-UyTKCPGg</a><br/>
MoFi Router Vulnerabilities<br/>
 <a href="https://www.criticalstart.com/critical-vulnerabilities-discovered-in-mofi-routers/">https://www.criticalstart.com/critical-vulnerabilities-discovered-in-mofi-routers/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7152" type="text/plain" language="en" />
<itunes:keywords>mofi, router, cisco, jabber, ios, qnap, python, api, windows, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7150</itunes:episode>
<itunes:subtitle>Exposed DC Used for DDoS Attacks; Edge Reviving SHA1; Trend Micro Patch; Is isn't a Breach if the data is public
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exposed DC Used for DDoS Attacks; Edge Reviving SHA1; Trend Micro Patch; Is isn't a Breach if the data is public
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7150.mp3" length="5600354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7150.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7150</link>
<pubDate>Wed, 02 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Exposed Domain Controllers Used in DDoS Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Exposed+Windows+Domain+Controllers+Used+in+CLDAP+DDoS+Attacks/26526/">https://isc.sans.edu/forums/diary/Exposed+Windows+Domain+Controllers+Used+in+CLDAP+DDoS+Attacks/26526/</a><br/>
Microsoft Reviving SHA-1<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-for-microsoft-edge-version-85/ba-p/1618585">https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-for-microsoft-edge-version-85/ba-p/1618585</a><br/>
Trend Micro Updating Anti Malware Products<br/>
 <a href="https://success.trendmicro.com/solution/000263632">https://success.trendmicro.com/solution/000263632</a><br/>
Public Voter Data Sold as "Breach" <br/>
 <a href="https://www.cyberscoop.com/russia-hack-michigan-voter-data-kommersant/">https://www.cyberscoop.com/russia-hack-michigan-voter-data-kommersant/</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7150" type="text/plain" language="en" />
<itunes:keywords>michigan, voter, data, leak, breach, trend micro, malware, patch, microsoft, sha1, edge, ldap, ad, active directory, domain controler, dc, ddos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 1st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7148</itunes:episode>
<itunes:subtitle>Finding Original Maldocs; Slack Vuln; Apple Approved Malware; Cisco DoS Bug Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding Original Maldocs; Slack Vuln; Apple Approved Malware; Cisco DoS Bug Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7148.mp3" length="4415066" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7148.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7148</link>
<pubDate>Tue, 01 Sep 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Finding The Original Maldoc<br/>
 <a href="https://isc.sans.edu/forums/diary/Finding+The+Original+Maldoc/26520/">https://isc.sans.edu/forums/diary/Finding+The+Original+Maldoc/26520/</a><br/>
Slack Remote Code Execution<br/>
 <a href="https://hackerone.com/reports/783877">https://hackerone.com/reports/783877</a><br/>
Apple Approved Malware<br/>
 <a href="https://objective-see.com/blog/blog_0x4E.html">https://objective-see.com/blog/blog_0x4E.html</a><br/>
Cisco IOS XR Bug Exploited<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-dvmrp-memexh-dSmpdvfz</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7148" type="text/plain" language="en" />
<itunes:keywords>cisco, iso, xr, dos, apple, notorized, malware, slack, maldoc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 31st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7146</itunes:episode>
<itunes:subtitle>CenturyLink Outage; NZX DDoS; Pulse Connect Secure Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CenturyLink Outage; NZX DDoS; Pulse Connect Secure Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7146.mp3" length="6177061" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7146.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7146</link>
<pubDate>Mon, 31 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[CenturyLink Outage<br/>
 <a href="https://blog.cloudflare.com/analysis-of-todays-centurylink-level-3-outage/">https://blog.cloudflare.com/analysis-of-todays-centurylink-level-3-outage/</a><br/>
New Zealand Stock Market Denial of Service Attack<br/>
 <a href="https://www.theregister.com/2020/08/27/nzx_ddos_third_day/">https://www.theregister.com/2020/08/27/nzx_ddos_third_day/</a><br/>
Pulse Connect Secure RCE Patch<br/>
 <a href="https://www.gosecure.net/blog/2020/08/26/forget-your-perimeter-rce-in-pulse-connect-secure/">https://www.gosecure.net/blog/2020/08/26/forget-your-perimeter-rce-in-pulse-connect-secure/</a><br/>
]]></description>
<itunes:duration>7:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7146" type="text/plain" language="en" />
<itunes:keywords>pulse connect secure, pulse secure, vpn, new zealand, stock exchange, centurylink, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7144</itunes:episode>
<itunes:subtitle>security.txt; DNS Queries; MSFT Extends Win10 1803 Deadline; LemonDuck Tricks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
security.txt; DNS Queries; MSFT Extends Win10 1803 Deadline; LemonDuck Tricks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7144.mp3" length="6017244" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7144.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7144</link>
<pubDate>Fri, 28 Aug 2020 02:00:02 GMT</pubDate>
<description><![CDATA[A Reminder about Security.txt<br/>
 <a href="https://isc.sans.edu/forums/diary/Securitytxt+one+small+file+for+an+admin+one+giant+help+to+a+security+researcher/26510/">https://isc.sans.edu/forums/diary/Securitytxt+one+small+file+for+an+admin+one+giant+help+to+a+security+researcher/26510/</a><br/>
DNS Queries to Root Name Servers<br/>
 <a href="https://blog.apnic.net/2020/08/21/chromiums-impact-on-root-dns-traffic/">https://blog.apnic.net/2020/08/21/chromiums-impact-on-root-dns-traffic/</a><br/>
 <a href="https://www.zdnet.com/article/chromium-dns-hijacking-detection-accused-of-being-around-half-of-all-root-queries/">https://www.zdnet.com/article/chromium-dns-hijacking-detection-accused-of-being-around-half-of-all-root-queries/</a><br/>
Microsoft Extends Windows 10 1803 Deadline<br/>
 <a href="https://support.microsoft.com/en-us/help/13853/windows-lifecycle-fact-sheet">https://support.microsoft.com/en-us/help/13853/windows-lifecycle-fact-sheet</a><br/>
LemonDuck Adding New Tricks<br/>
 <a href="https://news.sophos.com/en-us/2020/08/25/lemon_duck-cryptominer-targets-cloud-apps-linux/">https://news.sophos.com/en-us/2020/08/25/lemon_duck-cryptominer-targets-cloud-apps-linux/</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7144" type="text/plain" language="en" />
<itunes:keywords>lemonduck, crypto miner, microsoft, windows, windows 10, 1803, dns, root, google, chrome, security.txt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7142</itunes:episode>
<itunes:subtitle>Twists and Turns of Excel; Autodesk Plugins; Firefox Update; Insider Bribe 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Twists and Turns of Excel; Autodesk Plugins; Firefox Update; Insider Bribe 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7142.mp3" length="4815515" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7142.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7142</link>
<pubDate>Thu, 27 Aug 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Malicious Excel Sheet with a NULL VT Score<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Excel+Sheet+with+a+NULL+VT+Score/26506/">https://isc.sans.edu/forums/diary/Malicious+Excel+Sheet+with+a+NULL+VT+Score/26506/</a><br/>
APT Attack Uses Autodesk Plugin<br/>
 <a href="https://www.bitdefender.com/files/News/CaseStudies/study/365/Bitdefender-PR-Whitepaper-APTHackers-creat4740-en-EN-GenericUse.pdf">https://www.bitdefender.com/files/News/CaseStudies/study/365/Bitdefender-PR-Whitepaper-APTHackers-creat4740-en-EN-GenericUse.pdf</a><br/>
Firefox Update<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2020-36/">https://www.mozilla.org/en-US/security/advisories/mfsa2020-36/</a><br/>
Arrest in Insider Attack<br/>
 <a href="https://www.justice.gov/opa/press-release/file/1308766/download">https://www.justice.gov/opa/press-release/file/1308766/download</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7142" type="text/plain" language="en" />
<itunes:keywords>fbi, insider, russian, firefox, apt, autodesk, plugin, excel, virustotal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 26th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7140</itunes:episode>
<itunes:subtitle>LOLBins; Malicous iOS Ads; Apache Update; Google Chrome Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LOLBins; Malicous iOS Ads; Apache Update; Google Chrome Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7140.mp3" length="4605965" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7140.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7140</link>
<pubDate>Wed, 26 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Keep an Eye on LOLBins<br/>
 <a href="https://isc.sans.edu/forums/diary/Keep+An+Eye+on+LOLBins/26502/">https://isc.sans.edu/forums/diary/Keep+An+Eye+on+LOLBins/26502/</a><br/>
Malicious iOS Adnetwork SDK<br/>
 <a href="https://snyk.io/research/sour-mint-malicious-sdk/">https://snyk.io/research/sour-mint-malicious-sdk/</a><br/>
Apache Update<br/>
 <a href="https://httpd.apache.org/security/vulnerabilities_24.html">https://httpd.apache.org/security/vulnerabilities_24.html</a><br/>
Google Chrome User-Agent Client Hints<br/>
 <a href="https://web.dev/user-agent-client-hints/">https://web.dev/user-agent-client-hints/</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7140" type="text/plain" language="en" />
<itunes:keywords>google, chrome, user-agent, client hints, apache, update, ios, sdk, ad network, lolbins, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 25th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7138</itunes:episode>
<itunes:subtitle>VT Threat Hunting; Secure RDP! Zoom Outage; MSFT Application Guard; Safari Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VT Threat Hunting; Secure RDP! Zoom Outage; MSFT Application Guard; Safari Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7138.mp3" length="4898894" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7138.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7138</link>
<pubDate>Tue, 25 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Tracking a Malware Campaign Through VT<br/>
 <a href="https://isc.sans.edu/forums/diary/Tracking+A+Malware+Campaign+Through+VT/26498/">https://isc.sans.edu/forums/diary/Tracking+A+Malware+Campaign+Through+VT/26498/</a><br/>
Zoom Outage<br/>
 <a href="https://www.cnn.com/2020/08/24/us/zoom-outage-worldwide-trnd/index.html">https://www.cnn.com/2020/08/24/us/zoom-outage-worldwide-trnd/index.html</a><br/>
RDP Remains a Top Target<br/>
 <a href="https://www.group-ib.com/media/iran-cybercriminals/?utm_source=bleeping_computer&utm_medium=article&utm_campaign=referral">https://www.group-ib.com/media/iran-cybercriminals/?utm_source=bleeping_computer&utm_medium=article&utm_campaign=referral</a><br/>
Microsoft Introduces Application Guard<br/>
 <a href="https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/install-app-guard?view=o365-worldwide">https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/install-app-guard?view=o365-worldwide</a><br/>
Safari File Sharing Bug<br/>
 <a href="https://blog.redteam.pl/2020/08/stealing-local-files-using-safari-web.html">https://blog.redteam.pl/2020/08/stealing-local-files-using-safari-web.html</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7138" type="text/plain" language="en" />
<itunes:keywords>microsoft, application guard, office, rdp, iran, zoom, outage, virus total, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7136</itunes:episode>
<itunes:subtitle>Helping Cyber Stalking Victims; RDP/Telnet Probes; Cinterion Java Vuln; Google Drive Extension Spoofing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Helping Cyber Stalking Victims; RDP/Telnet Probes; Cinterion Java Vuln; Google Drive Extension Spoofing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7136.mp3" length="5874616" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7136.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7136</link>
<pubDate>Mon, 24 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[A Word of Caution: Helping Cyber Stalking Victims<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Word+of+Caution+Helping+Out+People+Being+Stalked+Online/26422/">https://isc.sans.edu/forums/diary/A+Word+of+Caution+Helping+Out+People+Being+Stalked+Online/26422/</a><br/>
RDP and Telnet Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Remote+Desktop+TCP3389+and+Telnet+TCP23+What+might+they+have+in+Common/26492/">https://isc.sans.edu/forums/diary/Remote+Desktop+TCP3389+and+Telnet+TCP23+What+might+they+have+in+Common/26492/</a><br/>
Thales Cinterion Input Validation Vulnerability<br/>
 <a href="https://www.thalesgroup.com/en/markets/digital-identity-and-security/iot/resources/security-updates-cinterion-iot-modules">https://www.thalesgroup.com/en/markets/digital-identity-and-security/iot/resources/security-updates-cinterion-iot-modules</a><br/>
Google Drive File Extension Spoofing<br/>
 <a href="https://thehackernews.com/2020/08/google-drive-file-versions.html">https://thehackernews.com/2020/08/google-drive-file-versions.html</a><br/>
]]></description>
<itunes:duration>6:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7136" type="text/plain" language="en" />
<itunes:keywords>google, extension, spoofing, drive, thales, cinterion, java, input validation, hidden files, rdp, telnet, stalking, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7134</itunes:episode>
<itunes:subtitle>Enumerating O365 Rules; Gmail Spoofing; Disable DisableAntiSpyware; Acoustic Key Picking 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Enumerating O365 Rules; Gmail Spoofing; Disable DisableAntiSpyware; Acoustic Key Picking 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7134.mp3" length="5539987" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7134.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7134</link>
<pubDate>Fri, 21 Aug 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Office 365 Mail Forwarding Rules (and other Mail Rules too)<br/>
 <a href="https://isc.sans.edu/forums/diary/Office+365+Mail+Forwarding+Rules+and+other+Mail+Rules+too/26484/">https://isc.sans.edu/forums/diary/Office+365+Mail+Forwarding+Rules+and+other+Mail+Rules+too/26484/</a><br/>
Spoofing GMail/GSuite Customers<br/>
 <a href="https://ezh.es/blog/2020/08/the-confused-mailman-sending-spf-and-dmarc-passing-mail-as-any-gmail-or-g-suite-customer/">https://ezh.es/blog/2020/08/the-confused-mailman-sending-spf-and-dmarc-passing-mail-as-any-gmail-or-g-suite-customer/</a><br/>
Microsoft Updates DisableAntiSpyware Registry Key<br/>
 <a href="https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware">https://docs.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware</a><br/>
Acoustic Based Physical Key Inference<br/>
 <a href="https://www.comp.nus.edu.sg/~junhan/papers/SpiKey_HotMobile20_CamReady.pdf">https://www.comp.nus.edu.sg/~junhan/papers/SpiKey_HotMobile20_CamReady.pdf</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7134" type="text/plain" language="en" />
<itunes:keywords>acoustic, key, sound, picking, lock picking, lock, microsoft, disableantispyware, registry, defender, gmail, gsuite, dmarc, spf, office, mail, forwarding, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7132</itunes:episode>
<itunes:subtitle>Obfuscated Qakbot URLs; Encrypted Email Bugs; Win8.1/2012 Patch; Fileless Worm
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated Qakbot URLs; Encrypted Email Bugs; Win8.1/2012 Patch; Fileless Worm
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7132.mp3" length="5329344" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7132.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7132</link>
<pubDate>Thu, 20 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Example of a Word Document Delivering Qakbot<br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+Word+Document+Delivering+Qakbot/26482/">https://isc.sans.edu/forums/diary/Example+of+Word+Document+Delivering+Qakbot/26482/</a><br/>
PGP/SMime Implementation Weaknesses<br/>
 <a href="https://www.nds.ruhr-uni-bochum.de/media/nds/veroeffentlichungen/2020/08/15/mailto-paper.pdf">https://www.nds.ruhr-uni-bochum.de/media/nds/veroeffentlichungen/2020/08/15/mailto-paper.pdf</a><br/>
Windows 8.1 / 2012 Special Patch<br/>
 <a href="https://support.microsoft.com/en-us/help/4578013/security-update-for-windows-8-1-rt-8-1-and-server-2012-r2">https://support.microsoft.com/en-us/help/4578013/security-update-for-windows-8-1-rt-8-1-and-server-2012-r2</a><br/>
Fileless Cryptomining Worm<br/>
 <a href="https://www.helpnetsecurity.com/2020/08/19/fileless-worm-p2p-botnet/">https://www.helpnetsecurity.com/2020/08/19/fileless-worm-p2p-botnet/</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7132" type="text/plain" language="en" />
<itunes:keywords>cryptomining, worm, fileless, ssh, windows, patch, pgp, email, mailto, smime, qakbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 19th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7130</itunes:episode>
<itunes:subtitle>Dropbox Exfil; Jenkins Advisory; Chrome 86 Insecure Forms; Crypto Worm Hitting Docker/Kubernetes/Jenkins
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dropbox Exfil; Jenkins Advisory; Chrome 86 Insecure Forms; Crypto Worm Hitting Docker/Kubernetes/Jenkins
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7130.mp3" length="4680205" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7130.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7130</link>
<pubDate>Wed, 19 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Using APIs to Track Attackers<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+APIs+to+Track+Attackers/26472/">https://isc.sans.edu/forums/diary/Using+APIs+to+Track+Attackers/26472/</a><br/>
Jenkins Security Advisory<br/>
 <a href="https://www.jenkins.io/security/advisory/2020-08-17/">https://www.jenkins.io/security/advisory/2020-08-17/</a><br/>
Chrome Will Warn of Insecure Forms<br/>
 <a href="https://blog.chromium.org/2020/08/protecting-google-chrome-users-from.html">https://blog.chromium.org/2020/08/protecting-google-chrome-users-from.html</a><br/>
Reminder: September 1st Certificate Expiration Change<br/>
 <a href="https://www.ssl.com/blogs/398-day-browser-limit-for-ssl-tls-certificates-begins-september-1-2020/">https://www.ssl.com/blogs/398-day-browser-limit-for-ssl-tls-certificates-begins-september-1-2020/</a><br/>
Cryptojacking Worm Steals AWS Credentials<br/>
 <a href="https://www.helpnetsecurity.com/2020/08/18/worm-steals-aws-credentials/">https://www.helpnetsecurity.com/2020/08/18/worm-steals-aws-credentials/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7130" type="text/plain" language="en" />
<itunes:keywords>cryptojacking, worm, jenkins, kubernetes, dockder, aws, certificates, tls, ssl, chrome, dropbox, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7128</itunes:episode>
<itunes:subtitle>Apache Struts; Emotet Bug;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apache Struts; Emotet Bug;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7128.mp3" length="5035305" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7128.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7128</link>
<pubDate>Tue, 18 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Apache Struts Patch and PoC Exploit<br/>
 <a href="https://www.tenable.com/blog/cve-2019-0230-apache-struts-potential-remote-code-execution-vulnerability">https://www.tenable.com/blog/cve-2019-0230-apache-struts-potential-remote-code-execution-vulnerability</a><br/>
 <a href="https://cwiki.apache.org/confluence/display/WW/S2-059">https://cwiki.apache.org/confluence/display/WW/S2-059</a><br/>
Emotet Bug Used to Inoculate Systems<br/>
 <a href="https://www.binarydefense.com/emocrash-exploiting-a-vulnerability-in-emotet-malware-for-defense/">https://www.binarydefense.com/emocrash-exploiting-a-vulnerability-in-emotet-malware-for-defense/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7128" type="text/plain" language="en" />
<itunes:keywords>emotet, apache, struts, ogml, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7126</itunes:episode>
<itunes:subtitle>SANS Incident IOCs; Obfuscation by Size; Mac XCode Malware; Citrix Flase Positive
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SANS Incident IOCs; Obfuscation by Size; Mac XCode Malware; Citrix Flase Positive
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7126.mp3" length="3888787" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7126.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7126</link>
<pubDate>Mon, 17 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[SANS Data Incident 2020 - Indicators of Compromise<br/>
 <a href="https://www.sans.org/blog/sans-data-incident-2020-indicators-of-compromise/">https://www.sans.org/blog/sans-data-incident-2020-indicators-of-compromise/</a><br/>
Large File Used to Obfuscate Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Definition+of+overkill+using+130+MB+executable+to+hide+24+kB+malware/26464/">https://isc.sans.edu/forums/diary/Definition+of+overkill+using+130+MB+executable+to+hide+24+kB+malware/26464/</a><br/>
Mac Malware Spreading via XCode<br/>
 <a href="https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf">https://documents.trendmicro.com/assets/pdf/XCSSET_Technical_Brief.pdf</a><br/>
Citrix Broker Service Detected as Trojan by Windows Defender<br/>
 <a href="https://support.citrix.com/article/CTX279897">https://support.citrix.com/article/CTX279897</a><br/>
]]></description>
<itunes:duration>4:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7126" type="text/plain" language="en" />
<itunes:keywords>sans, data incident, ioc, malware, large file, gif, mac, macos, xcode, citrix, windows defender, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7124</itunes:episode>
<itunes:subtitle>ReVoLTE Attack; Alexa Patch; Drovorub Linux Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ReVoLTE Attack; Alexa Patch; Drovorub Linux Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7124.mp3" length="7110364" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7124.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7124</link>
<pubDate>Fri, 14 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Decrypting Voice over LTE Calls<br/>
 <a href="https://revolte-attack.net/">https://revolte-attack.net/</a><br/>
Vulnerabilities found on Amazon's Alexa<br/>
 <a href="https://research.checkpoint.com/2020/amazons-alexa-hacked/">https://research.checkpoint.com/2020/amazons-alexa-hacked/</a><br/>
DROVORUB Russian GRU Linux Malware<br/>
 <a href="https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF">https://media.defense.gov/2020/Aug/13/2002476465/-1/-1/0/CSA_DROVORUB_RUSSIAN_GRU_MALWARE_AUG_2020.PDF</a><br/>
]]></description>
<itunes:duration>8:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7124" type="text/plain" language="en" />
<itunes:keywords>russia, gru, drovorub, linux, malware, rootkit, alexa, lte, decryption, volte, revolte, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7122</itunes:episode>
<itunes:subtitle>Mordor &amp; Brim; Tor Exit Nodes Steal Bitcoin; SAP/Intel Patches; SANS Incident
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mordor &amp; Brim; Tor Exit Nodes Steal Bitcoin; SAP/Intel Patches; SANS Incident
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7122.mp3" length="6147081" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7122.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7122</link>
<pubDate>Thu, 13 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[To the Brim at the Gates of Mordor<br/>
 <a href="https://isc.sans.edu/forums/diary/To+the+Brim+at+the+Gates+of+Mordor+Pt+1/26456/">https://isc.sans.edu/forums/diary/To+the+Brim+at+the+Gates+of+Mordor+Pt+1/26456/</a><br/>
 <br/>
Large Group of Malicious Tor Exit Nodes<br/>
 <a href="https://medium.com/@nusenu/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac">https://medium.com/@nusenu/how-malicious-tor-relays-are-exploiting-users-in-2020-part-i-1097575c0cac</a><br/>
SAP Updates<br/>
 <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345">https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=552603345</a><br/>
Intel Updates<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/default.html">https://www.intel.com/content/www/us/en/security-center/default.html</a><br/>
SANS Data Incident<br/>
 <a href="https://www.sans.org/dataincident2020">https://www.sans.org/dataincident2020</a><br/>
]]></description>
<itunes:duration>7:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7122" type="text/plain" language="en" />
<itunes:keywords>sap, intel, sans, breack, data incident, tor, exit nodes, bitcoin, brim, mordor, pcaps, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 12th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7120</itunes:episode>
<itunes:subtitle>vBulletin 0 Day; MSFT Patches; Adobe Patches; Citrix Endpoint Mgmt Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
vBulletin 0 Day; MSFT Patches; Adobe Patches; Citrix Endpoint Mgmt Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7120.mp3" length="4609256" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7120.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7120</link>
<pubDate>Wed, 12 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[vBulletin 0-Day Exploit<br/>
 <a href="https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/">https://blog.exploitee.rs/2020/exploiting-vbulletin-a-tale-of-patch-fail/</a><br/>
Microsoft Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+August+2020+Patch+Tuesday/26452/">https://isc.sans.edu/forums/diary/Microsoft+August+2020+Patch+Tuesday/26452/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Citrix End Point Management Updates<br/>
 <a href="https://www.citrix.com/blogs/2020/08/11/citrix-provides-security-update-on-citrix-endpoint-management/">https://www.citrix.com/blogs/2020/08/11/citrix-provides-security-update-on-citrix-endpoint-management/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7120" type="text/plain" language="en" />
<itunes:keywords>citrix, adobe, microsoft, patches, critical, vbulletin, exploit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7118</itunes:episode>
<itunes:subtitle>Word Maldoc Solution; Pentest Scoping; Chrome Extensions; PDF Mayhem; Teamviewer update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Word Maldoc Solution; Pentest Scoping; Chrome Extensions; PDF Mayhem; Teamviewer update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7118.mp3" length="5969705" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7118.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7118</link>
<pubDate>Tue, 11 Aug 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Small Challenge: A Simple Word Maldoc (Solution)<br/>
 <a href="https://isc.sans.edu/forums/diary/Small+Challenge+A+Simple+Word+Maldoc+Part+2/26444/">https://isc.sans.edu/forums/diary/Small+Challenge+A+Simple+Word+Maldoc+Part+2/26444/</a><br/>
Scoping Web Application Pentests<br/>
 <a href="https://isc.sans.edu/forums/diary/Scoping+web+application+and+web+service+penetration+tests/26448/">https://isc.sans.edu/forums/diary/Scoping+web+application+and+web+service+penetration+tests/26448/</a><br/>
Problems With Chrome Extensions<br/>
 <a href="https://adguard.com/en/blog/fake-ad-blockers-part-3.html">https://adguard.com/en/blog/fake-ad-blockers-part-3.html</a><br/>
PDF Test Suite<br/>
 <a href="https://github.com/RUB-NDS/PDF101">https://github.com/RUB-NDS/PDF101</a><br/>
 <a href="https://raw.githubusercontent.com/RUB-NDS/PDF101/master/eval.png">https://raw.githubusercontent.com/RUB-NDS/PDF101/master/eval.png</a><br/>
Teamviewer Update<br/>
 <a href="https://community.teamviewer.com/t5/Announcements/Statement-on-CVE-2020-13699/m-p/99129">https://community.teamviewer.com/t5/Announcements/Statement-on-CVE-2020-13699/m-p/99129</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7118" type="text/plain" language="en" />
<itunes:keywords>teamviewer, pdf, chrome, google, extension, scoping, pentest, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7116</itunes:episode>
<itunes:subtitle>WIFICAM nc Exploits; Snapdragon Vulns; Chinese Firewall ESNI Blocking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WIFICAM nc Exploits; Snapdragon Vulns; Chinese Firewall ESNI Blocking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7116.mp3" length="6248376" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7116.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7116</link>
<pubDate>Mon, 10 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Scanning Activity Against WIFICAM Using Netcat<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+Activity+Include+Netcat+Listener/26442/">https://isc.sans.edu/forums/diary/Scanning+Activity+Include+Netcat+Listener/26442/</a><br/>
Qualcom Snapdragon Vulnerabilities<br/>
 <a href="https://blog.checkpoint.com/2020/08/06/achilles-small-chip-big-peril/">https://blog.checkpoint.com/2020/08/06/achilles-small-chip-big-peril/</a><br/>
China Blocking TLS 1.3 and ESNI<br/>
 <a href="https://gfw.report/blog/gfw_esni_blocking/en/">https://gfw.report/blog/gfw_esni_blocking/en/</a><br/>
]]></description>
<itunes:duration>7:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7116" type="text/plain" language="en" />
<itunes:keywords>china, esni, tls, blocking, qualcom, snapdragon, wificam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7114</itunes:episode>
<itunes:subtitle>FTCODE Ransomware Resurfaces; MSFT Defender vs hosts file; MSFT Print Spool Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
FTCODE Ransomware Resurfaces; MSFT Defender vs hosts file; MSFT Print Spool Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7114.mp3" length="4940581" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7114.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7114</link>
<pubDate>Fri, 07 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[FTCode Ransomware Resurfaces<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Fork+of+the+FTCode+Powershell+Ransomware/26434/">https://isc.sans.edu/forums/diary/A+Fork+of+the+FTCode+Powershell+Ransomware/26434/</a><br/>
Microsoft Anti-Malware Flaging Host File Manipulation<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-10-hosts-file-blocking-telemetry-is-now-flagged-as-a-risk/">https://www.bleepingcomputer.com/news/microsoft/windows-10-hosts-file-blocking-telemetry-is-now-flagged-as-a-risk/</a><br/>
Reviving older printer vulnerablity<br/>
 <a href="https://www.blackhat.com/us-20/briefings/schedule/#a-decade-after-stuxnets-printer-vulnerability-printing-is-still-the-stairway-to-heaven-19685">https://www.blackhat.com/us-20/briefings/schedule/#a-decade-after-stuxnets-printer-vulnerability-printing-is-still-the-stairway-to-heaven-19685</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7114" type="text/plain" language="en" />
<itunes:keywords>blackhat, print spooler, printer, microsoft, host file, host, defender, ftcode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7112</itunes:episode>
<itunes:subtitle>Malware Analysis Quiz; MacOS PoC Exploit; iOS OAuth2 Vuln; NSA Location Privacy Guide
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Analysis Quiz; MacOS PoC Exploit; iOS OAuth2 Vuln; NSA Location Privacy Guide
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7112.mp3" length="5437229" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7112.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7112</link>
<pubDate>Thu, 06 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Malware Analysis Quiz<br/>
 <a href="https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Whats+the+Malware+From+This+Infection/26430/">https://isc.sans.edu/forums/diary/Traffic+Analysis+Quiz+Whats+the+Malware+From+This+Infection/26430/</a><br/>
Exploiting CVE-2020-9854 on MacOS<br/>
 <a href="https://objective-see.com/blog/blog_0x4D.html">https://objective-see.com/blog/blog_0x4D.html</a><br/>
iOS OAuth2 Vulnerablity<br/>
 <a href="https://www.computest.nl/en/knowledge-platform/blog/vulnerability-new-touchid-feature-iCloud-accounts-at-risk-breached/">https://www.computest.nl/en/knowledge-platform/blog/vulnerability-new-touchid-feature-iCloud-accounts-at-risk-breached/</a><br/>
Limiting Location Data Exposure<br/>
 <a href="https://media.defense.gov/2020/Aug/04/2002469874/-1/-1/0/CSI_LIMITING_LOCATION_DATA_EXPOSURE_FINAL.PDF">https://media.defense.gov/2020/Aug/04/2002469874/-1/-1/0/CSI_LIMITING_LOCATION_DATA_EXPOSURE_FINAL.PDF</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7112" type="text/plain" language="en" />
<itunes:keywords>nsa, location, privacy, oauth2, ios, macos, cve-2020-9854, malware, quiz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 5th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7110</itunes:episode>
<itunes:subtitle>CVE-2020-3452 (Cisco ASA/FTD) Updates; DNS Concentration; Android Patches; iOS Jailbreak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2020-3452 (Cisco ASA/FTD) Updates; DNS Concentration; Android Patches; iOS Jailbreak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7110.mp3" length="5386033" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7110.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7110</link>
<pubDate>Wed, 05 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[A Reminder to Patch CVE-2020-3452. Active Exploitation Seen<br/>
 <a href="https://isc.sans.edu/forums/diary/Reminder+Patch+Cisco+ASA+FTD+Devices+CVE20203452+Exploitation+Continues/26426/">https://isc.sans.edu/forums/diary/Reminder+Patch+Cisco+ASA+FTD+Devices+CVE20203452+Exploitation+Continues/26426/</a><br/>
Internet Choke Points: Concentration of Authoritative Name Servers<br/>
 <a href="https://isc.sans.edu/forums/diary/Internet+Choke+Points+Concentration+of+Authoritative+Name+Servers/26428/">https://isc.sans.edu/forums/diary/Internet+Choke+Points+Concentration+of+Authoritative+Name+Servers/26428/</a><br/>
August Android Patches Released <br/>
 <a href="https://source.android.com/security/bulletin/2020-08-01">https://source.android.com/security/bulletin/2020-08-01</a><br/>
Possible New iOS Jailbreak Affecting Secure Enclave<br/>
 <a href="https://twitter.com/SparkZheng/status/1286599007834271744">https://twitter.com/SparkZheng/status/1286599007834271744</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7110" type="text/plain" language="en" />
<itunes:keywords>ios, jailbreak, pandu, android, patches, wifi, dns, choke points, cisco, cve-2020-3452, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7108</itunes:episode>
<itunes:subtitle>Multi C2 Macro; Boothole Patch Problem; Disable MacOS TCC; TAIDOOR Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Multi C2 Macro; Boothole Patch Problem; Disable MacOS TCC; TAIDOOR Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7108.mp3" length="4881340" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7108.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7108</link>
<pubDate>Tue, 04 Aug 2020 02:00:03 GMT</pubDate>
<description><![CDATA[VBA Macro With Multiple Command and Control Channels<br/>
 <a href="https://isc.sans.edu/forums/diary/Powershell+Bot+with+Multiple+C2+Protocols/26420/">https://isc.sans.edu/forums/diary/Powershell+Bot+with+Multiple+C2+Protocols/26420/</a><br/>
Boothole Patch Causes Unbootable Systems<br/>
 <a href="https://access.redhat.com/solutions/5272311">https://access.redhat.com/solutions/5272311</a><br/>
 <a href="https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass#Recovery">https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass#Recovery</a><br/>
Disabling MacOS TCC<br/>
 <a href="https://objective-see.com/blog/blog_0x4C.html">https://objective-see.com/blog/blog_0x4C.html</a><br/>
CISA Publishes Details about Chinese Malware<br/>
 <a href="https://us-cert.cisa.gov/ncas/current-activity/2020/08/03/chinese-malicious-cyber-activity">https://us-cert.cisa.gov/ncas/current-activity/2020/08/03/chinese-malicious-cyber-activity</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7108" type="text/plain" language="en" />
<itunes:keywords>cisa, taidoor, macos, tcc, boothole, vba, pentest, red team, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7106</itunes:episode>
<itunes:subtitle>Bad Bots; KeePassRCP Update; QNAP Malware Remover; Android Phone Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bad Bots; KeePassRCP Update; QNAP Malware Remover; Android Phone Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7106.mp3" length="4618021" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7106.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7106</link>
<pubDate>Mon, 03 Aug 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Pages Hit By Bad Bots<br/>
 <a href="https://isc.sans.edu/forums/diary/What+pages+do+bad+bots+look+for/26414/">https://isc.sans.edu/forums/diary/What+pages+do+bad+bots+look+for/26414/</a><br/>
KeePassRPC Vulnerablity<br/>
 <a href="https://forum.kee.pm/t/a-critical-security-update-for-keepassrpc-is-available/3040">https://forum.kee.pm/t/a-critical-security-update-for-keepassrpc-is-available/3040</a><br/>
QNAP Updates Malware Remover<br/>
 <a href="https://www.bleepingcomputer.com/news/security/qnap-urges-users-to-update-malware-remover-after-qsnatch-alert/">https://www.bleepingcomputer.com/news/security/qnap-urges-users-to-update-malware-remover-after-qsnatch-alert/</a><br/>
Android Phone Updates<br/>
 <a href="https://www.theregister.com/2020/07/31/nearly_a_third_of_secondhand/">https://www.theregister.com/2020/07/31/nearly_a_third_of_secondhand/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7106" type="text/plain" language="en" />
<itunes:keywords>android, qnap, keepass, bots, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 31st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7104</itunes:episode>
<itunes:subtitle>SQLi and Python; Google Allowing Office 365 Phishing; Netgear/Zoom Vulns; OPNsense Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SQLi and Python; Google Allowing Office 365 Phishing; Netgear/Zoom Vulns; OPNsense Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7104.mp3" length="4890471" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7104.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7104</link>
<pubDate>Fri, 31 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Python Developers: Prepare!<br/>
 <a href="https://isc.sans.edu/forums/diary/Python+Developers+Prepare/26408/">https://isc.sans.edu/forums/diary/Python+Developers+Prepare/26408/</a><br/>
Office 365 Phishing Hiding in Google Ads<br/>
 <a href="https://cofense.com/threat-actors-bypass-gateways-google-ad-redirects/">https://cofense.com/threat-actors-bypass-gateways-google-ad-redirects/</a><br/>
Zoom Brute Forcing Vulnerability<br/>
 <a href="https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/">https://www.tomanthony.co.uk/blog/zoom-security-exploit-crack-private-meeting-passwords/</a><br/>
Netgear Vulnerabilities<br/>
 <a href="https://www.kb.cert.org/vuls/id/576779">https://www.kb.cert.org/vuls/id/576779</a><br/>
 <a href="https://kb.netgear.com/000061982/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Routers-Mobile-Routers-Modems-Gateways-and-Extenders">https://kb.netgear.com/000061982/Security-Advisory-for-Multiple-Vulnerabilities-on-Some-Routers-Mobile-Routers-Modems-Gateways-and-Extenders</a><br/>
OPNSense Update<br/>
 <a href="https://opnsense.org/opnsense-20-7/">https://opnsense.org/opnsense-20-7/</a><br/>
Microsoft Retiring SHA1<br/>
 <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/sha-1-windows-content-to-be-retired-august-3-2020/ba-p/1544373">https://techcommunity.microsoft.com/t5/windows-it-pro-blog/sha-1-windows-content-to-be-retired-august-3-2020/ba-p/1544373</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7104" type="text/plain" language="en" />
<itunes:keywords>microsoft, sha1, opnsense, netgear, zoom, office365, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7102</itunes:episode>
<itunes:subtitle>Consumer VPNs; Tails 4.9; Browser Updates; GRUB2 Vuln; Facial Recognition and Masks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Consumer VPNs; Tails 4.9; Browser Updates; GRUB2 Vuln; Facial Recognition and Masks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7102.mp3" length="5168056" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7102.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7102</link>
<pubDate>Thu, 30 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Consumer VPNs: You May Be Fine Without It<br/>
 <a href="https://isc.sans.edu/forums/diary/Consumer+VPNs+You+May+Be+Fine+Without/26404/">https://isc.sans.edu/forums/diary/Consumer+VPNs+You+May+Be+Fine+Without/26404/</a><br/>
Tails Update<br/>
 <a href="https://tails.boum.org/news/version_4.9/index.en.html">https://tails.boum.org/news/version_4.9/index.en.html</a><br/>
Firefox Update<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2020-30/">https://www.mozilla.org/en-US/security/advisories/mfsa2020-30/</a><br/>
Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html">https://chromereleases.googleblog.com/2020/07/stable-channel-update-for-desktop_27.html</a><br/>
GRUB2 Vulnerability<br/>
 <a href="https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/">https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/</a><br/>
Facial Recognition With Masks<br/>
 <a href="https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8311.pdf">https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8311.pdf</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7102" type="text/plain" language="en" />
<itunes:keywords>facial recognition, masks, grub2, chrome, firefox, tails, vpns, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7100</itunes:episode>
<itunes:subtitle>New Datafeeds; Emotet Tricks; Magento Update; Docker Attacks;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Datafeeds; Emotet Tricks; Magento Update; Docker Attacks;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7100.mp3" length="5214505" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7100.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7100</link>
<pubDate>Wed, 29 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[New Datafeeds<br/>
 <a href="https://isc.sans.edu/forums/diary/All+I+want+this+Tuesday+More+Data/26400/">https://isc.sans.edu/forums/diary/All+I+want+this+Tuesday+More+Data/26400/</a><br/>
Emotet Stealing Email Attachments<br/>
 <a href="https://twitter.com/CofenseLabs/status/1288167724594671618">https://twitter.com/CofenseLabs/status/1288167724594671618</a><br/>
Magento Update<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb20-47.html">https://helpx.adobe.com/security/products/magento/apsb20-47.html</a><br/>
Explosed Docker Servers Infected with More Malware<br/>
 <a href="https://www.intezer.com/container-security/watch-your-containers-doki-infecting-docker-servers-in-the-cloud/">https://www.intezer.com/container-security/watch-your-containers-doki-infecting-docker-servers-in-the-cloud/</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7100" type="text/plain" language="en" />
<itunes:keywords>docker, dogecoin, doki, magento, emotet, datafeeds, cloudips, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7098</itunes:episode>
<itunes:subtitle>In Memory of Donald Smith; Decoding Metasploit Payloads; Emotet Vigilante; QNAP Advisory
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
In Memory of Donald Smith; Decoding Metasploit Payloads; Emotet Vigilante; QNAP Advisory
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7098.mp3" length="3903412" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7098.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7098</link>
<pubDate>Tue, 28 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[In Memory of Donald Smith<br/>
 <a href="https://isc.sans.edu/forums/diary/In+Memory+of+Donald+Smith/26396/">https://isc.sans.edu/forums/diary/In+Memory+of+Donald+Smith/26396/</a><br/>
Analyzing Metasploit ASP .Net Payloads<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+Metasploit+ASP+NET+Payloads/26392/">https://isc.sans.edu/forums/diary/Analyzing+Metasploit+ASP+NET+Payloads/26392/</a><br/>
Emotet Payloads Replaces with GIFs<br/>
 <a href="https://twitter.com/GossiTheDog/status/1286271503005290497">https://twitter.com/GossiTheDog/status/1286271503005290497</a><br/>
QNAP Devices Attacked<br/>
 <a href="https://us-cert.cisa.gov/ncas/alerts/aa20-209a">https://us-cert.cisa.gov/ncas/alerts/aa20-209a</a><br/>
]]></description>
<itunes:duration>4:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7098" type="text/plain" language="en" />
<itunes:keywords>qnap, emotet, gif, metasploit, asp, net, donald smith, don, rip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7096</itunes:episode>
<itunes:subtitle>Desktop Apps Using Web Tech; VBA Passwords; Cisco Treck IP Update; Ubiquity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Desktop Apps Using Web Tech; VBA Passwords; Cisco Treck IP Update; Ubiquity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7096.mp3" length="4668482" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7096.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7096</link>
<pubDate>Mon, 27 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Compromized Desktop Applications By Web Technologies<br/>
 <a href="https://isc.sans.edu/forums/diary/Compromized+Desktop+Applications+by+Web+Technologies/26384/">https://isc.sans.edu/forums/diary/Compromized+Desktop+Applications+by+Web+Technologies/26384/</a><br/>
Cracking Maldoc VBA Project Passwords<br/>
 <a href="https://isc.sans.edu/forums/diary/Cracking+Maldoc+VBA+Project+Passwords/26390/">https://isc.sans.edu/forums/diary/Cracking+Maldoc+VBA+Project+Passwords/26390/</a><br/>
Cisco Patching Treck IP Stack Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC</a><br/>
Ubiquity Devices Breack Due to Malformed Feed<br/>
 <a href="https://community.ui.com/questions/Threat-Management-rules-silently-disabled-for-users-as-of-July-17-2020/35221bd2-843d-41a3-a957-33f57d9a8468">https://community.ui.com/questions/Threat-Management-rules-silently-disabled-for-users-as-of-July-17-2020/35221bd2-843d-41a3-a957-33f57d9a8468</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7096" type="text/plain" language="en" />
<itunes:keywords>ubiquity, ugs, cisco, vba, discord, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7094</itunes:episode>
<itunes:subtitle>Blocking with MISP; ISC Intel Feed; ASUS Vuln; DLink Lost Key; Cisco Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Blocking with MISP; ISC Intel Feed; ASUS Vuln; DLink Lost Key; Cisco Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7094.mp3" length="5044436" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7094.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7094</link>
<pubDate>Fri, 24 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Simple Blocklisting with MISP and pfSense<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+Blocklisting+with+MISP+pfSense/26380/">https://isc.sans.edu/forums/diary/Simple+Blocklisting+with+MISP+pfSense/26380/</a><br/>
ISC Intel Feed (Beta. DO NOT USE AS BLOCKLIST)<br/>
 <a href="https://isc.sans.edu/api/intelfeed?json">https://isc.sans.edu/api/intelfeed?json</a><br/>
 (also see isc.sans.edu/api )<br/>
ASUS RT-AC1900P Router Vulnerability<br/>
 <a href="https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=27440">https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=27440</a><br/>
DLink Leaks Firmware Encryption Key<br/>
 <a href="https://nstarke.github.io/0036-decrypting-dlink-proprietary-firmware-images.html">https://nstarke.github.io/0036-decrypting-dlink-proprietary-firmware-images.html</a><br/>
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ro-path-KJuQhB86</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7094" type="text/plain" language="en" />
<itunes:keywords>cisco, asa, firepower, directory traversal, dlink, firmware, key, asus, intel feed, misp, pfsense, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7092</itunes:episode>
<itunes:subtitle>F5 IoCs; Insecure PDF Signatures; Sharepoint PoC; Twilio Compromise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
F5 IoCs; Insecure PDF Signatures; Sharepoint PoC; Twilio Compromise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7092.mp3" length="5439781" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7092.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7092</link>
<pubDate>Thu, 23 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[A Few IoCs Releated to the F5 Vulnerablity CVE-2020-5092<br/>
 <a href="https://isc.sans.edu/forums/diary/A+few+IoCs+related+to+CVE20205092/26378/">https://isc.sans.edu/forums/diary/A+few+IoCs+related+to+CVE20205092/26378/</a><br/>
PDF Signature Weaknesses<br/>
 <a href="https://pdf-insecurity.org/">https://pdf-insecurity.org/</a><br/>
Sharepoint Vulnerabliity PoC CVE-2020-1147<br/>
 <a href="https://srcincite.io/blog/2020/07/20/sharepoint-and-pwn-remote-code-execution-against-sharepoint-server-abusing-dataset.html">https://srcincite.io/blog/2020/07/20/sharepoint-and-pwn-remote-code-execution-against-sharepoint-server-abusing-dataset.html</a><br/>
Twilio Compromise<br/>
 <a href="https://www.theregister.com/2020/07/21/twilio_sdk_code_injection/">https://www.theregister.com/2020/07/21/twilio_sdk_code_injection/</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7092" type="text/plain" language="en" />
<itunes:keywords>twilio, javascript, supply chain, sharepoint, poc, pdf, signatures, f5, ios, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7090</itunes:episode>
<itunes:subtitle>Covid19 Network Exposures; Adobe Patch; Citrix Workspace Vuln; Procmon 4 Linux
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Covid19 Network Exposures; Adobe Patch; Citrix Workspace Vuln; Procmon 4 Linux
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7090.mp3" length="3856243" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7090.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7090</link>
<pubDate>Wed, 22 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Comparing Covid19 Remote Services in Different Countries<br/>
 <a href="https://isc.sans.edu/forums/diary/Couple+of+interesting+Covid19+related+stats/26374/">https://isc.sans.edu/forums/diary/Couple+of+interesting+Covid19+related+stats/26374/</a><br/>
Adobe Patches Photoshop<br/>
 <a href="https://helpx.adobe.com/security/products/bridge/apsb20-44.html">https://helpx.adobe.com/security/products/bridge/apsb20-44.html</a><br/>
 <a href="https://helpx.adobe.com/security/products/photoshop/apsb20-45.html">https://helpx.adobe.com/security/products/photoshop/apsb20-45.html</a><br/>
Citrix Workspace App Vulnerability<br/>
 <a href="https://www.pentestpartners.com/security-blog/raining-system-shells-with-citrix-workspace-app/">https://www.pentestpartners.com/security-blog/raining-system-shells-with-citrix-workspace-app/</a><br/>
Microsoft Publishes Sysinternals Procmon for Linux<br/>
 <a href="https://github.com/microsoft/ProcMon-for-Linux">https://github.com/microsoft/ProcMon-for-Linux</a><br/>
]]></description>
<itunes:duration>4:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7090" type="text/plain" language="en" />
<itunes:keywords>microsoft, sysinternals, procmon, linux, citrix, adopbe, photoshop, covid19, rdp, telnet, remote access, ssh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7088</itunes:episode>
<itunes:subtitle>Sextortion Wrapup; "BadPower" USB-C Firmware Weakness; Zoom Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sextortion Wrapup; "BadPower" USB-C Firmware Weakness; Zoom Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7088.mp3" length="5198406" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7088.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7088</link>
<pubDate>Tue, 21 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Sextortion Follow the Money Wrapup<br/>
 <a href="https://isc.sans.edu/forums/diary/Sextortion+Update+The+Final+Final+Chapter/26334/">https://isc.sans.edu/forums/diary/Sextortion+Update+The+Final+Final+Chapter/26334/</a><br/>
"BadPower" USB-C Charger Firmware Weakness (link in chinese)<br/>
 <a href="https://xlab.tencent.com/cn/2020/07/16/badpower/">https://xlab.tencent.com/cn/2020/07/16/badpower/</a><br/>
Zoom Phishing<br/>
 <a href="https://blog.checkpoint.com/2020/07/16/fixing-the-zoom-vanity-clause-check-point-and-zoom-collaborate-to-fix-vanity-url-issue/">https://blog.checkpoint.com/2020/07/16/fixing-the-zoom-vanity-clause-check-point-and-zoom-collaborate-to-fix-vanity-url-issue/</a><br/>
Microsoft Office TLS 1.x Phaseout<br/>
 <a href="https://docs.microsoft.com/en-us/microsoft-365/compliance/prepare-tls-1.2-in-office-365?view=o365-worldwide">https://docs.microsoft.com/en-us/microsoft-365/compliance/prepare-tls-1.2-in-office-365?view=o365-worldwide</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7088" type="text/plain" language="en" />
<itunes:keywords>microsoft, office, tls, office 365, zoom, phishing, badpower, usb, usb-c, bitcoin, sextortion, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7086</itunes:episode>
<itunes:subtitle>#SigRed Update; Cloutflare Outage; ZeroShell; Zone.Identifier; Forgotten tcpdump
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#SigRed Update; Cloutflare Outage; ZeroShell; Zone.Identifier; Forgotten tcpdump
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7086.mp3" length="4874379" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7086.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7086</link>
<pubDate>Mon, 20 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[#SigRed Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Hunting+for+SigRed+Exploitation/26362/">https://isc.sans.edu/forums/diary/Hunting+for+SigRed+Exploitation/26362/</a><br/>
Cloudflare Outage<br/>
 <a href="https://blog.cloudflare.com/cloudflare-outage-on-july-17-2020/">https://blog.cloudflare.com/cloudflare-outage-on-july-17-2020/</a><br/>
Exploitation of ZeroShell Routers<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+Activity+for+ZeroShell+Unauthenticated+Access/26368/">https://isc.sans.edu/forums/diary/Scanning+Activity+for+ZeroShell+Unauthenticated+Access/26368/</a><br/>
Zone.Identifier: A Coupe of Observations<br/>
 <a href="https://isc.sans.edu/forums/diary/ZoneIdentifier+A+Coupe+Of+Observations/26366/">https://isc.sans.edu/forums/diary/ZoneIdentifier+A+Coupe+Of+Observations/26366/</a><br/>
Forgotten tcpdump Options<br/>
 <a href="https://showmethepackets.com/index.php/2020/07/18/a-few-forgotten-tcpdump-options/">https://showmethepackets.com/index.php/2020/07/18/a-few-forgotten-tcpdump-options/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7086" type="text/plain" language="en" />
<itunes:keywords>tcpdump, zone.indentifier, ads, zeroshell, cloudflare, sigred, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7084</itunes:episode>
<itunes:subtitle>Twitter Compromise; SIGRed PoC; Apple Updates; SAP PoC; @sans_edu : Aaron Elyard
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Twitter Compromise; SIGRed PoC; Apple Updates; SAP PoC; @sans_edu : Aaron Elyard
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7084.mp3" length="11591453" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7084.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7084</link>
<pubDate>Fri, 17 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Twitter Compromise<br/>
 <a href="https://twitter.com/TwitterSupport/status/1283591846464233474?s=20">https://twitter.com/TwitterSupport/status/1283591846464233474?s=20</a><br/>
SIGRed PoC<br/>
 hxxps://github.com/maxpl0it/CVE-2020-1350-DoS<br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
SAP PoC Exploit Code Published<br/>
 <a href="https://github.com/chipik/SAP_RECON">https://github.com/chipik/SAP_RECON</a><br/>
 <a href="https://us-cert.cisa.gov/ncas/alerts/aa20-195a">https://us-cert.cisa.gov/ncas/alerts/aa20-195a</a><br/>
SANS.edu Student: Aaron Elyard: KITT<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/OpenSource/improving-analyst-efficiency-office365-business-email-compromise-investigation-scenarios-implementation-open-source-tools-39655">https://www.sans.org/reading-room/whitepapers/OpenSource/improving-analyst-efficiency-office365-business-email-compromise-investigation-scenarios-implementation-open-source-tools-39655</a><br/>
 KITT: <a href="https://github.com/intrepidtechie/KITT-O365-Tool">https://github.com/intrepidtechie/KITT-O365-Tool</a> <br/>
]]></description>
<itunes:duration>13:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7084" type="text/plain" language="en" />
<itunes:keywords>sans.edu, kitt, outlook 365, bec, sap, poc, exploit, apple, sigred, twitter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7082</itunes:episode>
<itunes:subtitle>MSFT DNS Server Vulnerability #sigred; Outlook Patch Crashes; Oracle CPU; Cisco Backdoors
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT DNS Server Vulnerability #sigred; Outlook Patch Crashes; Oracle CPU; Cisco Backdoors
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7082.mp3" length="4417976" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7082.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7082</link>
<pubDate>Thu, 16 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[MSFT DNS Server Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/PATCH+NOW+SIGRed+CVE20201350+Microsoft+DNS+Server+Vulnerability/26356/">https://isc.sans.edu/forums/diary/PATCH+NOW+SIGRed+CVE20201350+Microsoft+DNS+Server+Vulnerability/26356/</a><br/>
 <a href="https://www.sans.org/webcasts/about-windows-dns-vulnerability-cve-2020-1350-116120">https://www.sans.org/webcasts/about-windows-dns-vulnerability-cve-2020-1350-116120</a><br/>
Outlook Crashes After Patch Tuesday Updates<br/>
 <a href="https://www.reddit.com/r/sysadmin/comments/hrq0mn/outlook_immediately_crashing_on_open_after/fy5nnx2/">https://www.reddit.com/r/sysadmin/comments/hrq0mn/outlook_immediately_crashing_on_open_after/fy5nnx2/</a><br/>
Oracle Quarterly Critical Patch Update<br/>
 <a href="https://www.oracle.com/security-alerts/cpujul2020.html">https://www.oracle.com/security-alerts/cpujul2020.html</a><br/>
Cisco Backdoors<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities">https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=100#~Vulnerabilities</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7082" type="text/plain" language="en" />
<itunes:keywords>cisco, backdoors, default credentials, oracle, cpu, outlook, crashes, msft, dns server, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7080</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7080.mp3" length="4687145" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7080.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7080</link>
<pubDate>Wed, 15 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[MSFT Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+July+2020+Patch+Tuesday+Patch+Now/26350/">https://isc.sans.edu/forums/diary/Microsoft+July+2020+Patch+Tuesday+Patch+Now/26350/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7080" type="text/plain" language="en" />
<itunes:keywords>Adobe, Microsoft, dns, patch tuesday, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7078</itunes:episode>
<itunes:subtitle>VBA Details; Apple mount_apfs TCC Bypass 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBA Details; Apple mount_apfs TCC Bypass 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7078.mp3" length="5431732" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7078.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7078</link>
<pubDate>Tue, 14 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Purged VBA Code<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+VBA+Purging+Example/26342/">https://isc.sans.edu/forums/diary/Maldoc+VBA+Purging+Example/26342/</a><br/>
Password protected VBA Code<br/>
 <a href="https://isc.sans.edu/forums/diary/VBA+Project+Passwords/26346/">https://isc.sans.edu/forums/diary/VBA+Project+Passwords/26346/</a><br/>
MacOS mount_apfs TCC Bypass<br/>
 <a href="https://theevilbit.github.io/posts/cve_2020_9771/">https://theevilbit.github.io/posts/cve_2020_9771/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7078" type="text/plain" language="en" />
<itunes:keywords>macos, mount_apfs, apfs, password, vba, purged, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7076</itunes:episode>
<itunes:subtitle>Excel Starts Formbook; Zoom Update; Digicert Mass Revoke; OAUTH Consent Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Excel Starts Formbook; Zoom Update; Digicert Mass Revoke; OAUTH Consent Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7076.mp3" length="5753191" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7076.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7076</link>
<pubDate>Mon, 13 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Excel Spreadsheet Macro Kicks Off Formbook Infection<br/>
 <a href="https://isc.sans.edu/forums/diary/Excel+spreasheet+macro+kicks+off+Formbook+infection/26332/">https://isc.sans.edu/forums/diary/Excel+spreasheet+macro+kicks+off+Formbook+infection/26332/</a><br/>
Zoom Update Fixing Zoom on Windows 7 Vulnerability<br/>
 <a href="https://support.zoom.us/hc/en-us/articles/360046081271-New-updates-for-July-10-2020">https://support.zoom.us/hc/en-us/articles/360046081271-New-updates-for-July-10-2020</a><br/>
DigiCert Replaces 50,000 EV Certificates<br/>
 <a href="https://knowledge.digicert.com/alerts/DigiCert-ICA-Replacement">https://knowledge.digicert.com/alerts/DigiCert-ICA-Replacement</a><br/>
Microsoft Warns of OAUTH consent Phishing<br/>
 <a href="https://www.microsoft.com/security/blog/2020/07/08/protecting-remote-workforce-application-attacks-consent-phishing/">https://www.microsoft.com/security/blog/2020/07/08/protecting-remote-workforce-application-attacks-consent-phishing/</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7076" type="text/plain" language="en" />
<itunes:keywords>microsoft, oauth, phishing, digicert, ev certificates, ev, zoom, windows 7, formbook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7074</itunes:episode>
<itunes:subtitle>Citrix Scanning; Juniper Patches; Google Releases Tsunami Scanner; @sans_edu student Billy Wilson: Securing Super Computers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix Scanning; Juniper Patches; Google Releases Tsunami Scanner; @sans_edu student Billy Wilson: Securing Super Computers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7074.mp3" length="11997396" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7074.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7074</link>
<pubDate>Fri, 10 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Citrix Scanning<br/>
 <a href="https://isc.sans.edu/forums/diary/Active+Exploit+Attempts+Targeting+Recent+Citrix+ADC+Vulnerabilities+CTX276688/26330/">https://isc.sans.edu/forums/diary/Active+Exploit+Attempts+Targeting+Recent+Citrix+ADC+Vulnerabilities+CTX276688/26330/</a><br/>
 <a href="https://www.youtube.com/watch?time_continue=6&v=1_D4_9BKHSc&feature=emb_logo">https://www.youtube.com/watch?time_continue=6&v=1_D4_9BKHSc&feature=emb_logo</a><br/>
Juniper Patches<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES">https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES</a><br/>
Google Releases Tsunami Security Scanner<br/>
 <a href="https://github.com/google/tsunami-security-scanner">https://github.com/google/tsunami-security-scanner</a><br/>
SANS.edu Student Billy Wilson: Security Supercomputers with BPF Probes<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/detection/securing-soft-underbelly-supercomputer-bpf-probes-39635#__utma=56421037.1361558334.1422039453.1445264258.1445266863.510&__utmb=56421037.17.9.1445268558432&__utmc=56421037&__utmx=-&__utmz=56421037.1444729543.493.57.utmcsr=admin.sans.org|utmccn=%28referral%29|utmcmd=referral|utmcct=/account/madmin/account_manage">https://www.sans.org/reading-room/whitepapers/detection/securing-soft-underbelly-supercomputer-bpf-probes-39635#__utma=56421037.1361558334.1422039453.1445264258.1445266863.510&__utmb=56421037.17.9.1445268558432&__utmc=56421037&__utmx=-&__utmz=56421037.1444729543.493.57.utmcsr=admin.sans.org|utmccn=%28referral%29|utmcmd=referral|utmcct=/account/madmin/account_manage</a><br/>
]]></description>
<itunes:duration>14:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7074" type="text/plain" language="en" />
<itunes:keywords>sans.edu, billy wilson, supercomputers, bpf, juniper, google, tsunami, citrix, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7072</itunes:episode>
<itunes:subtitle>Obfuscated Malware; PAN-OS Vulnerability; Citrix Vuln Details; Mozilla Suspends Send
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated Malware; PAN-OS Vulnerability; Citrix Vuln Details; Mozilla Suspends Send
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7072.mp3" length="5483667" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7072.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7072</link>
<pubDate>Thu, 09 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Obfuscated Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/If+You+Want+Something+Done+Right+You+Have+To+Do+It+Yourself+Malware+Too/26320/">https://isc.sans.edu/forums/diary/If+You+Want+Something+Done+Right+You+Have+To+Do+It+Yourself+Malware+Too/26320/</a><br/>
PaloAlto Networks PAN-OS CVE-2020-2034<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2020-2034">https://security.paloaltonetworks.com/CVE-2020-2034</a><br/>
Citrix Vulnerability Details (CVE-2020-8194)<br/>
 <a href="https://dmaasland.github.io/posts/citrix.html">https://dmaasland.github.io/posts/citrix.html</a><br/>
Mozilla Suspending Send Service<br/>
 <a href="https://www.zdnet.com/article/mozilla-suspends-firefox-send-service-while-it-addresses-malware-abuse/">https://www.zdnet.com/article/mozilla-suspends-firefox-send-service-while-it-addresses-malware-abuse/</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7072" type="text/plain" language="en" />
<itunes:keywords>mozilla, send, citrix, paloalto, malware, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7070</itunes:episode>
<itunes:subtitle>F5 BigIP Wrapup / New Exploit Bypassing Workaround (HT @nccgroupinfosec); Citrix ADC Patches; Microsoft Freta;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
F5 BigIP Wrapup / New Exploit Bypassing Workaround (HT @nccgroupinfosec); Citrix ADC Patches; Microsoft Freta;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7070.mp3" length="4600471" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7070.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7070</link>
<pubDate>Wed, 08 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[F5 Big IP Wrapup<br/>
 <a href="https://twitter.com/NCCGroupInfosec/status/1280593966879125504">https://twitter.com/NCCGroupInfosec/status/1280593966879125504</a><br/>
 <a href="https://www.sans.org/webcasts/116065">https://www.sans.org/webcasts/116065</a><br/>
Citrix ADC / Citrix Gateway Patches<br/>
 <a href="https://www.citrix.com/blogs/2020/07/07/citrix-provides-context-on-security-bulletin-ctx276688/">https://www.citrix.com/blogs/2020/07/07/citrix-provides-context-on-security-bulletin-ctx276688/</a><br/>
Microsoft Releases Free Memory Analysis Service<br/>
 <a href="https://www.microsoft.com/en-us/research/blog/toward-trusted-sensing-for-the-cloud-introducing-project-freta/">https://www.microsoft.com/en-us/research/blog/toward-trusted-sensing-for-the-cloud-introducing-project-freta/</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7070" type="text/plain" language="en" />
<itunes:keywords>microsoft, freta, citrix, f5 bigip, workaround, nccgroup, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7068</itunes:episode>
<itunes:subtitle>More BigIP Exploits; MSFT ATP Web Content Filtering; Ransomware; More Research IPs; #DShield20Years 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More BigIP Exploits; MSFT ATP Web Content Filtering; Ransomware; More Research IPs; #DShield20Years 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7068.mp3" length="4484166" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7068.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7068</link>
<pubDate>Tue, 07 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[More BigIP Exploits<br/>
 <a href="https://isc.sans.edu/forums/diary/Summary+of+CVE20205902+F5+BIGIP+RCE+Vulnerability+Exploits/26316/">https://isc.sans.edu/forums/diary/Summary+of+CVE20205902+F5+BIGIP+RCE+Vulnerability+Exploits/26316/</a><br/>
Special F5 BigIP Webcast<br/>
 <a href="https://www.sans.org/webcasts/116065">https://www.sans.org/webcasts/116065</a><br/>
Microsoft ATP Web Content Filtering<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-atp/an-update-on-web-content-filtering/ba-p/1505445">https://techcommunity.microsoft.com/t5/microsoft-defender-atp/an-update-on-web-content-filtering/ba-p/1505445</a><br/>
Ouch Newsletter: Ransomware<br/>
 <a href="https://www.sans.org/security-awareness-training/resources/ransomware">https://www.sans.org/security-awareness-training/resources/ransomware</a><br/>
Extended Research Feed: Added Net Systems Research<br/>
 <a href="https://isc.sans.edu/api/threatcategory/research">https://isc.sans.edu/api/threatcategory/research</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7068" type="text/plain" language="en" />
<itunes:keywords>research feed, ouch, ransomware, awareness, atp, microsoft, f5, bigip, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7066</itunes:episode>
<itunes:subtitle>F5 BigIP Critical RCE; Guacamole RDP Gateway Vuln; Barclays vs Archive.org
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
F5 BigIP Critical RCE; Guacamole RDP Gateway Vuln; Barclays vs Archive.org
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7066.mp3" length="5252893" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7066.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7066</link>
<pubDate>Mon, 06 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[F5 BigIP Critical RCE<br/>
 <a href="https://support.f5.com/csp/article/K52145254">https://support.f5.com/csp/article/K52145254</a><br/>
 <a href="https://isc.sans.edu/forums/diary/CVE20205902+F5+BIGIP+Exploitation+Attempt/26310/">https://isc.sans.edu/forums/diary/CVE20205902+F5+BIGIP+Exploitation+Attempt/26310/</a><br/>
 <a href="https://github.com/rapid7/metasploit-framework/pull/13807/commits/0417e88ff24bf05b8874c953bd91600f10186ba4">https://github.com/rapid7/metasploit-framework/pull/13807/commits/0417e88ff24bf05b8874c953bd91600f10186ba4</a><br/>
 <a href="https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller">https://www.ptsecurity.com/ww-en/about/news/f5-fixes-critical-vulnerability-discovered-by-positive-technologies-in-big-ip-application-delivery-controller</a><br/>
Guacamole RDP Gateway Vulnerability<br/>
 <a href="https://blog.checkpoint.com/2020/07/02/hole-y-guacamole-fixing-critical-vulnerabilities-in-apaches-popular-remote-desktop-gateway/">https://blog.checkpoint.com/2020/07/02/hole-y-guacamole-fixing-critical-vulnerabilities-in-apaches-popular-remote-desktop-gateway/</a><br/>
Barclays Caught Serving Code from Wayback Machine<br/>
 <a href="https://www.theregister.com/2020/07/03/barclays_bank_javascript_wayback_machine/">https://www.theregister.com/2020/07/03/barclays_bank_javascript_wayback_machine/</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7066" type="text/plain" language="en" />
<itunes:keywords>Barkclays, wayback machine, archive.org, guacamole, rdp, f5, bigip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7064</itunes:episode>
<itunes:subtitle>DNS Exfil in PoS Malware; EvilQuest Update; More Tools - Less Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Exfil in PoS Malware; EvilQuest Update; More Tools - Less Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7064.mp3" length="3712879" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7064.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7064</link>
<pubDate>Thu, 02 Jul 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Alina PoS Malware Exfiltrating Data via DNS<br/>
 <a href="https://blog.centurylink.com/alina-point-of-sale-malware-still-lurking-in-dns/">https://blog.centurylink.com/alina-point-of-sale-malware-still-lurking-in-dns/</a><br/>
Evil Quest "Ransomware" Update<br/>
 <a href="https://objective-see.com/blog/blog_0x59.html">https://objective-see.com/blog/blog_0x59.html</a><br/>
IBM Cyber Resilient Organziation Report<br/>
 <a href="https://www.ibm.com/account/reg/us-en/signup?formid=urx-45839">https://www.ibm.com/account/reg/us-en/signup?formid=urx-45839</a><br/>
]]></description>
<itunes:duration>4:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7064" type="text/plain" language="en" />
<itunes:keywords>ibm, evilquest, macos, alina, pos, dns, data exfiltration, exfiltration, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 1st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7062</itunes:episode>
<itunes:subtitle>Special Windows Patch (Code Exec Vuln); MacOS Ransomware; VPN Priv Escalation; DNSSEC Phish
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Special Windows Patch (Code Exec Vuln); MacOS Ransomware; VPN Priv Escalation; DNSSEC Phish
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7062.mp3" length="4961431" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7062.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7062</link>
<pubDate>Wed, 01 Jul 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Window 10 / 2019 Server Out of Order Patch<br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1425">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1425</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1457">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1457</a><br/>
MacOS Ransomare Arrives as Fake Little Snitch Software<br/>
 <a href="https://blog.malwarebytes.com/mac/2020/06/new-mac-ransomware-spreading-through-piracy/">https://blog.malwarebytes.com/mac/2020/06/new-mac-ransomware-spreading-through-piracy/</a><br/>
VPN Privilege Escalation<br/>
 <a href="https://0xsha.io/posts/zombievpn-breaking-that-internet-security">https://0xsha.io/posts/zombievpn-breaking-that-internet-security</a><br/>
DNSSEC Phishing Scam<br/>
 <a href="https://nakedsecurity.sophos.com/2020/06/29/beware-secure-dns-scam-targeting-website-owners-and-bloggers/">https://nakedsecurity.sophos.com/2020/06/29/beware-secure-dns-scam-targeting-website-owners-and-bloggers/</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7062" type="text/plain" language="en" />
<itunes:keywords>DNSSEC, phishing, vpn, zombievpn, bitdefender, macos, ransomware, little snitch, windows 10, 2019, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7060</itunes:episode>
<itunes:subtitle>Sysmon and ADS; PAN-OS SAML Issues; Old Telnet Issue in Cisco IOS XE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sysmon and ADS; PAN-OS SAML Issues; Old Telnet Issue in Cisco IOS XE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7060.mp3" length="3863549" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7060.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7060</link>
<pubDate>Tue, 30 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Sysmon 11.10 and ADS Logging<br/>
 <a href="https://isc.sans.edu/forums/diary/Sysmon+and+Alternate+Data+Streams/26292/">https://isc.sans.edu/forums/diary/Sysmon+and+Alternate+Data+Streams/26292/</a><br/>
Paloalto PAN-OS SAML Vulnerability<br/>
 <a href="https://security.paloaltonetworks.com/CVE-2020-2021">https://security.paloaltonetworks.com/CVE-2020-2021</a><br/>
Cisco Telnet Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPx">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-telnetd-EFJrEzPx</a><br/>
 <a href="https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html">https://appgateresearch.blogspot.com/2020/02/bravestarr-fedora-31-netkit-telnetd_28.html</a><br/>
]]></description>
<itunes:duration>4:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7060" type="text/plain" language="en" />
<itunes:keywords>cisco, telnet, appgate, palo alto, pan, sysmon, saml, global protect, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7058</itunes:episode>
<itunes:subtitle>MacOS 11 Security Changes; Changes to Cert Expiration September 1st
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS 11 Security Changes; Changes to Cert Expiration September 1st
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7058.mp3" length="5981762" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7058.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7058</link>
<pubDate>Mon, 29 Jun 2020 01:12:18 GMT</pubDate>
<description><![CDATA[MacOS 11 Security Changes<br/>
 <a href="https://www.sentinelone.com/blog/macos-big-sur-9-big-surprises-for-enterprise-security/">https://www.sentinelone.com/blog/macos-big-sur-9-big-surprises-for-enterprise-security/</a><br/>
Certificate Lifetime Limited to 1 Year Starting September<br/>
 <a href="https://chromium.googlesource.com/chromium/src/+/ae4d6809912f8171b23f6aa43c6a4e8e627de784">https://chromium.googlesource.com/chromium/src/+/ae4d6809912f8171b23f6aa43c6a4e8e627de784</a><br/>
 <a href="https://support.apple.com/en-us/HT211025">https://support.apple.com/en-us/HT211025</a><br/>
 <a href="https://lists.cabforum.org/pipermail/servercert-wg/2020-June/002000.html">https://lists.cabforum.org/pipermail/servercert-wg/2020-June/002000.html</a><br/>
]]></description>
<itunes:duration>7:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7058" type="text/plain" language="en" />
<itunes:keywords>certificates, lifetime, expiration, macos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 26th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7056</itunes:episode>
<itunes:subtitle>Tech Tuesday Recording; Favicon Hides Code; GeoVision Vulns; Docker Vulns; Karim Lalji about #Cyberbunker; @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tech Tuesday Recording; Favicon Hides Code; GeoVision Vulns; Docker Vulns; Karim Lalji about #Cyberbunker; @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7056.mp3" length="14050151" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7056.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7056</link>
<pubDate>Fri, 26 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Recordings of the Tech Tuesday Workshop<br/>
 <a href="https://isc.sans.edu/forums/diary/Tech+Tuesday+Recap+Recordings+Part+2+Installing+the+Honeypot+release/26280/">https://isc.sans.edu/forums/diary/Tech+Tuesday+Recap+Recordings+Part+2+Installing+the+Honeypot+release/26280/</a><br/>
 <a href="https://www.youtube.com/channel/UCfbOsqPmWg1H_34hTjKEW2A">https://www.youtube.com/channel/UCfbOsqPmWg1H_34hTjKEW2A</a><br/>
Credit Card Skimmers Hide Code in Favicon EXIF Data<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2020/06/web-skimmer-hides-within-exif-metadata-exfiltrates-credit-cards-via-image-files/">https://blog.malwarebytes.com/threat-analysis/2020/06/web-skimmer-hides-within-exif-metadata-exfiltrates-credit-cards-via-image-files/</a><br/>
GeoVision Scanners Vulnerabilities<br/>
 <a href="https://thehackernews.com/2020/06/geovision-scanner-vulnerabilities.html">https://thehackernews.com/2020/06/geovision-scanner-vulnerabilities.html</a><br/>
Docker Images Containing Cryptojacking Malware<br/>
 <a href="https://unit42.paloaltonetworks.com/cryptojacking-docker-images-for-mining-monero/">https://unit42.paloaltonetworks.com/cryptojacking-docker-images-for-mining-monero/</a><br/>
SANS.edu Student Karim Lalji: <a href="https://www.sans.org/reading-room/whitepapers/threathunting/real-time-honeypot-forensic-investigation-german-organized-crime-network-39640">https://www.sans.org/reading-room/whitepapers/threathunting/real-time-honeypot-forensic-investigation-german-organized-crime-network-39640</a><br/>
]]></description>
<itunes:duration>16:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7056" type="text/plain" language="en" />
<itunes:keywords>docker, geovision, scanners, skimmers, favicon, exif, tech tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 25th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7054</itunes:episode>
<itunes:subtitle>Shell Link No-Touch Download; Updates: Chrome, QNAP, Magento; Exchange Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shell Link No-Touch Download; Updates: Chrome, QNAP, Magento; Exchange Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7054.mp3" length="4897061" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7054.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7054</link>
<pubDate>Thu, 25 Jun 2020 01:42:44 GMT</pubDate>
<description><![CDATA[Using Shell Links as zero-touch downloaders and to initiate network connections<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Shell+Links+as+zerotouch+downloaders+and+to+initiate+network+connections/26276/">https://isc.sans.edu/forums/diary/Using+Shell+Links+as+zerotouch+downloaders+and+to+initiate+network+connections/26276/</a><br/>
Chrome Updates Released<br/>
 <a href="https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_22.html">https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_22.html</a><br/>
QNAP Updates for Helpdesk<br/>
 <a href="https://www.qnap.com/de-de/security-advisory/qsa-20-03">https://www.qnap.com/de-de/security-advisory/qsa-20-03</a><br/>
Magento Update<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb20-41.html">https://helpx.adobe.com/security/products/magento/apsb20-41.html</a><br/>
Attacks Against Microsoft Exchange Servers<br/>
 <a href="https://www.microsoft.com/security/blog/2020/06/24/defending-exchange-servers-under-attack/">https://www.microsoft.com/security/blog/2020/06/24/defending-exchange-servers-under-attack/</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7054" type="text/plain" language="en" />
<itunes:keywords>microsoft, exchange, magento, qnap, chrome, shell, zero-touch, links, downloads, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7052</itunes:episode>
<itunes:subtitle>CyberBunker; Microsoft offering Linux/Android and Safe Documents
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CyberBunker; Microsoft offering Linux/Android and Safe Documents
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7052.mp3" length="5006414" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7052.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7052</link>
<pubDate>Wed, 24 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Analysis Of Traffic Targeting CyberBunker IP Space<br/>
 <a href="https://isc.sans.edu/forums/diary/Cyberbunker+20+Analysis+of+the+Remnants+of+a+Bullet+Proof+Hosting+Provider/26266/">https://isc.sans.edu/forums/diary/Cyberbunker+20+Analysis+of+the+Remnants+of+a+Bullet+Proof+Hosting+Provider/26266/</a><br/>
Microsoft Offering Enterprise Security Products for Linux/Android<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-atp/announcing-microsoft-defender-atp-for-android/ba-p/1480787">https://techcommunity.microsoft.com/t5/microsoft-defender-atp/announcing-microsoft-defender-atp-for-android/ba-p/1480787</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-defender-atp/microsoft-defender-atp-for-linux-is-now-generally-available/ba-p/1482344">https://techcommunity.microsoft.com/t5/microsoft-defender-atp/microsoft-defender-atp-for-linux-is-now-generally-available/ba-p/1482344</a><br/>
Microsoft Safe Documents<br/>
 <a href="https://techcommunity.microsoft.com/t5/microsoft-365-blog/safe-documents-is-generally-available/ba-p/1480401">https://techcommunity.microsoft.com/t5/microsoft-365-blog/safe-documents-is-generally-available/ba-p/1480401</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7052" type="text/plain" language="en" />
<itunes:keywords>cyberbunker, microsoft, enterprise, linux, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7050</itunes:episode>
<itunes:subtitle>WinMerge; VMWare/Office Patches for MacOS; RCE Bitdefender; Google Analytcs Data Exfil
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WinMerge; VMWare/Office Patches for MacOS; RCE Bitdefender; Google Analytcs Data Exfil
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7050.mp3" length="6067343" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7050.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7050</link>
<pubDate>Tue, 23 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Comparing Office Documents with WinMerge<br/>
 <a href="https://isc.sans.edu/forums/diary/Comparing+Office+Documents+with+WinMerge/26268/">https://isc.sans.edu/forums/diary/Comparing+Office+Documents+with+WinMerge/26268/</a><br/>
VMWare Tools and Microsoft Office Updates for macOS<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0014.html">https://www.vmware.com/security/advisories/VMSA-2020-0014.html</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1225">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1225</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1226">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1226</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1229">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1229</a><br/>
Remote Code Execution Vulnerability in Bitdefender<br/>
 <a href="https://palant.info/2020/06/22/exploiting-bitdefender-antivirus-rce-from-any-website/">https://palant.info/2020/06/22/exploiting-bitdefender-antivirus-rce-from-any-website/</a><br/>
Google Analytics Used to Exfiltrate Data<br/>
 <a href="https://www.perimeterx.com/tech-blog/2020/bypassing-csp-exflitrate-data/">https://www.perimeterx.com/tech-blog/2020/bypassing-csp-exflitrate-data/</a><br/>
]]></description>
<itunes:duration>7:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7050" type="text/plain" language="en" />
<itunes:keywords>vmware, google, analytics, bitdefender, csp, vmware, office, macos, microsoft, winmerge, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7048</itunes:episode>
<itunes:subtitle>Sigma Rules; Pi 0 Honeypot; Ransomware Post Infection; Discord Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sigma Rules; Pi 0 Honeypot; Ransomware Post Infection; Discord Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7048.mp3" length="4546333" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7048.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7048</link>
<pubDate>Mon, 22 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Sigma Rules! The Generic Signature Format for SIEM Systems<br/>
 <a href="https://isc.sans.edu/forums/diary/Sigma+rules+The+generic+signature+format+for+SIEM+systems/26258/">https://isc.sans.edu/forums/diary/Sigma+rules+The+generic+signature+format+for+SIEM+systems/26258/</a><br/>
Pi Zero Honeypot<br/>
 <a href="https://isc.sans.edu/forums/diary/Pi+Zero+HoneyPot/26260/">https://isc.sans.edu/forums/diary/Pi+Zero+HoneyPot/26260/</a><br/>
Ransomware Operators Lurk on Your Network<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ransomware-operators-lurk-on-your-network-after-their-attack/">https://www.bleepingcomputer.com/news/security/ransomware-operators-lurk-on-your-network-after-their-attack/</a><br/>
Discord Modified to Steal Accounts<br/>
 <a href="https://www.bleepingcomputer.com/news/security/discord-modified-to-steal-accounts-by-new-nitrohack-malware/">https://www.bleepingcomputer.com/news/security/discord-modified-to-steal-accounts-by-new-nitrohack-malware/</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7048" type="text/plain" language="en" />
<itunes:keywords>discord, nitrohack, ransomware, pi zero, honeypot, sigma, siem, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 19th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7046</itunes:episode>
<itunes:subtitle>Outlook Link Re-Write Bug; Cisco Updates; Netgear Bug; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Outlook Link Re-Write Bug; Cisco Updates; Netgear Bug; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7046.mp3" length="4994699" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7046.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7046</link>
<pubDate>Fri, 19 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Broken Phishing Accidentially Exploiting Outlook Zero-Day<br/>
 <a href="https://isc.sans.edu/forums/diary/Broken+phishing+accidentally+exploiting+Outlook+zeroday/26254/">https://isc.sans.edu/forums/diary/Broken+phishing+accidentally+exploiting+Outlook+zeroday/26254/</a><br/>
 Webcast: <a href="https://www.sans.org/webcasts/sansatmic-catch-release-phishing-techniques-good-guys-115430">https://www.sans.org/webcasts/sansatmic-catch-release-phishing-techniques-good-guys-115430</a><br/>
Cisco Updates<br/>
 Treck IP Stack: <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-treck-ip-stack-JyBQ5GyC</a><br/>
 All Advisories: <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Netgear httpd Firmware Upload Stack-based Buffer Overflow RCE Vulnerability<br/>
 <a href="https://blog.grimm-co.com/2020/06/soho-device-exploitation.html">https://blog.grimm-co.com/2020/06/soho-device-exploitation.html</a><br/>
Tech Tuesday Workshop: <a href="https://www.sans.org/webcasts/tech-tuesday-workshop-collaborating-scale-contribute-profit-internet-storm-center-115935">https://www.sans.org/webcasts/tech-tuesday-workshop-collaborating-scale-contribute-profit-internet-storm-center-115935</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7046" type="text/plain" language="en" />
<itunes:keywords>tech tuesday, netgear, workshop, firmware, cisco, outlook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7044</itunes:episode>
<itunes:subtitle>Odd Protest Spam; Zoom E2EE; Linux ACPI Bug; ISC Tech Tuesday Workshop
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd Protest Spam; Zoom E2EE; Linux ACPI Bug; ISC Tech Tuesday Workshop
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7044.mp3" length="5942639" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7044.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7044</link>
<pubDate>Thu, 18 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Odd Protest Spam (Scam?) Targeting Atlanta Police Foundation<br/>
 <a href="https://isc.sans.edu/forums/diary/Odd+Protest+Spam+Scam+Targeting+Atlanta+Police+Foundation/26248/">https://isc.sans.edu/forums/diary/Odd+Protest+Spam+Scam+Targeting+Atlanta+Police+Foundation/26248/</a><br/>
Zoom Publishes End-to-End Encryption Whitepaper<br/>
 <a href="https://github.com/zoom/zoom-e2e-whitepaper">https://github.com/zoom/zoom-e2e-whitepaper</a><br/>
Linux ACPI Bug Defeats UEFI Secure Boot<br/>
 <a href="https://git.zx2c4.com/american-unsigned-language/tree/american-unsigned-language-2.sh">https://git.zx2c4.com/american-unsigned-language/tree/american-unsigned-language-2.sh</a><br/>
Tech Tuesday Workshop: <a href="https://www.sans.org/webcasts/tech-tuesday-workshop-collaborating-scale-contribute-profit-internet-storm-center-115935">https://www.sans.org/webcasts/tech-tuesday-workshop-collaborating-scale-contribute-profit-internet-storm-center-115935</a><br/>
]]></description>
<itunes:duration>7:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7044" type="text/plain" language="en" />
<itunes:keywords>tech tuesday, zoom, linux, acpi, uefi, secure boot, atlanta, police, foundation, scam, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7042</itunes:episode>
<itunes:subtitle>Fake Dating Profile Extortion; TMobile Postmortem; Docker Image Vulns; IOT Ripple
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake Dating Profile Extortion; TMobile Postmortem; Docker Image Vulns; IOT Ripple
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7042.mp3" length="5594483" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7042.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7042</link>
<pubDate>Wed, 17 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Sextortion to the Next Level<br/>
 <a href="https://isc.sans.edu/forums/diary/Sextortion+to+The+Next+Level/26244/">https://isc.sans.edu/forums/diary/Sextortion+to+The+Next+Level/26244/</a><br/>
TMobile Outage Due to Configuration Error<br/>
 <a href="https://www.scmagazine.com/home/security-news/outages-draw-speculation-of-ddos-attack-on-u-s-but-reality-likely-more-boring/">https://www.scmagazine.com/home/security-news/outages-draw-speculation-of-ddos-attack-on-u-s-but-reality-likely-more-boring/</a><br/>
Vulnerability Analysis of 2500 Docker Hub Images<br/>
 <a href="https://arxiv.org/pdf/2006.02932.pdf">https://arxiv.org/pdf/2006.02932.pdf</a><br/>
Track IP Stack Contains Multiple Vulnerabilities<br/>
 <a href="https://www.kb.cert.org/vuls/id/257161">https://www.kb.cert.org/vuls/id/257161</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7042" type="text/plain" language="en" />
<itunes:keywords>track ip stack, docker, tmobile, sextortion, russian, ukrainian, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7040</itunes:episode>
<itunes:subtitle>HTML Phishing; TMobile Outage; LTE/5G GTP Issues; #SANSFIRE HAndler Talks 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HTML Phishing; TMobile Outage; LTE/5G GTP Issues; #SANSFIRE HAndler Talks 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7040.mp3" length="5769652" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7040.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7040</link>
<pubDate>Tue, 16 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[HTML Based Phishing Run<br/>
 <a href="https://isc.sans.edu/forums/diary/HTML+based+Phishing+Run/26242/">https://isc.sans.edu/forums/diary/HTML+based+Phishing+Run/26242/</a><br/>
Major T-Mobile Outage (may affect other carriers as well)<br/>
 <a href="https://twitter.com/NevilleRay/status/1272650750665953280">https://twitter.com/NevilleRay/status/1272650750665953280</a><br/>
 <a href="https://status.duo.com/incidents/txv7kq6tr0h8">https://status.duo.com/incidents/txv7kq6tr0h8</a><br/>
Vulnerabilities in LTE and 5G Networks<br/>
 <a href="https://positive-tech.com/storage/articles/gtp-2020/threat-vector-gtp-2020-eng.pdf">https://positive-tech.com/storage/articles/gtp-2020/threat-vector-gtp-2020-eng.pdf</a><br/>
SANSFIRE Handler Talks<br/>
 Xavier Mertens: <a href="https://www.sans.org/webcasts/sansatmic-walk-logs-hell-115420">https://www.sans.org/webcasts/sansatmic-walk-logs-hell-115420</a><br/>
 Bojan Zdrnja: <a href="https://www.sans.org/webcasts/sansatmic-arcane-web-mobile-application-vulnerHTML">https://www.sans.org/webcasts/sansatmic-arcane-web-mobile-application-vulnerHTML</a> Phishing<br/>
]]></description>
<itunes:duration>6:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7040" type="text/plain" language="en" />
<itunes:keywords>sansfire, siem, soc, webapp, pentest, mobile applications, lte, 5g, gtp, gprs, tmobile, outage, html, phish, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7038</itunes:episode>
<itunes:subtitle>Fileless Excel Malware; Win Update Issues; Privnote Phish; #SANSFIRE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fileless Excel Malware; Win Update Issues; Privnote Phish; #SANSFIRE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7038.mp3" length="5271545" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7038.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7038</link>
<pubDate>Mon, 15 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Fileless Excel Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Excel+Delivering+Fileless+Payload/26232/">https://isc.sans.edu/forums/diary/Malicious+Excel+Delivering+Fileless+Payload/26232/</a><br/>
Windows Update Issues<br/>
 <a href="https://support.microsoft.com/en-us/help/4566779/usb-printer-port-missing-after-disconnecting-printer-while-windows-10">https://support.microsoft.com/en-us/help/4566779/usb-printer-port-missing-after-disconnecting-printer-while-windows-10</a><br/>
 <a href="https://answers.microsoft.com/en-us/windows/forum/all/cumulative-updates-june-9th-2020/45a8a7f3-cb89-459e-acf1-32d9de15c099">https://answers.microsoft.com/en-us/windows/forum/all/cumulative-updates-june-9th-2020/45a8a7f3-cb89-459e-acf1-32d9de15c099</a><br/>
Privnote.com Phishing<br/>
 <a href="https://krebsonsecurity.com/2020/06/privnotes-com-is-phishing-bitcoin-from-users-of-private-messaging-service-privnote-com/">https://krebsonsecurity.com/2020/06/privnotes-com-is-phishing-bitcoin-from-users-of-private-messaging-service-privnote-com/</a><br/>
SANS @Mic Talk: ISC Handler Bojan Zdrnja<br/>
 <a href="https://www.sans.org/webcasts/sansatmic-arcane-web-mobile-application-vulnerabilities-115425">https://www.sans.org/webcasts/sansatmic-arcane-web-mobile-application-vulnerabilities-115425</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7038" type="text/plain" language="en" />
<itunes:keywords>sans@mic, bojan, web applications, mobile applications, privnote, phishing, privnotes, windows, update, excel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 12th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7036</itunes:episode>
<itunes:subtitle>JavaScript Anti-Debugging; Facebook Messanger Bug; Outlook Macros; Network Flows in AWS @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JavaScript Anti-Debugging; Facebook Messanger Bug; Outlook Macros; Network Flows in AWS @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7036.mp3" length="5897648" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7036.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7036</link>
<pubDate>Fri, 12 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Anti-Debugging JavaScript Techniques<br/>
 <a href="https://isc.sans.edu/forums/diary/AntiDebugging+JavaScript+Techniques/26228/">https://isc.sans.edu/forums/diary/AntiDebugging+JavaScript+Techniques/26228/</a><br/>
Facebook Messenger Desktop App Vulnerability<br/>
 <a href="https://blog.reasonsecurity.com/2020/06/11/persistence-method-using-facebook-messenger-desktop-app/">https://blog.reasonsecurity.com/2020/06/11/persistence-method-using-facebook-messenger-desktop-app/</a><br/>
Outlook Massmailing Macros<br/>
 <a href="https://www.welivesecurity.com/2020/06/11/gamaredon-group-grows-its-game/">https://www.welivesecurity.com/2020/06/11/gamaredon-group-grows-its-game/</a><br/>
STI Student Research: Dennis Taggard; Ebb and Flow: Network Flow Logging as a Staple of Public Cloud Visibility or a Waning Imperative?<br/>
 Paper: <a href="https://www.sans.org/reading-room/whitepapers/cloud/ebb-flow-network-flow-logging-staple-public-cloud-visibility-waning-imperative-39580">https://www.sans.org/reading-room/whitepapers/cloud/ebb-flow-network-flow-logging-staple-public-cloud-visibility-waning-imperative-39580</a><br/>
 Video: <a href="https://youtu.be/faoFx7Q3_aM">https://youtu.be/faoFx7Q3_aM</a><br/>
]]></description>
<itunes:duration>7:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7036" type="text/plain" language="en" />
<itunes:keywords>javascript, debugging, anti-debugging, Facebook, messenger, outlook, macro, network flows, aws, sti, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7034</itunes:episode>
<itunes:subtitle>ZLoader Update; More Expiring CAs; BLM Themed Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ZLoader Update; More Expiring CAs; BLM Themed Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7034.mp3" length="5304101" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7034.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7034</link>
<pubDate>Thu, 11 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Job Application Themed Malspam Pushes ZLoader<br/>
 <a href="https://isc.sans.edu/forums/diary/Job+applicationthemed+malspam+pushes+ZLoader/26222/">https://isc.sans.edu/forums/diary/Job+applicationthemed+malspam+pushes+ZLoader/26222/</a><br/>
More Expiring Root CAs<br/>
 <a href="https://scotthelme.co.uk/impending-doom-root-ca-expiring-legacy-clients/">https://scotthelme.co.uk/impending-doom-root-ca-expiring-legacy-clients/</a><br/>
Black Lives Matter Themed Malware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fake-black-lives-matter-voting-campaign-spreads-trickbot-malware/">https://www.bleepingcomputer.com/news/security/fake-black-lives-matter-voting-campaign-spreads-trickbot-malware/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7034" type="text/plain" language="en" />
<itunes:keywords>blm, black lives matter, trickbot, expiring ca, certificates, zloader, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7032</itunes:episode>
<itunes:subtitle>Microsoft Patch Day; SMBleed; Adobe Patches; Intel Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Day; SMBleed; Adobe Patches; Intel Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7032.mp3" length="5178665" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7032.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7032</link>
<pubDate>Wed, 10 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Day<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+June+2020+Patch+Tuesday/26220/">https://isc.sans.edu/forums/diary/Microsoft+June+2020+Patch+Tuesday/26220/</a><br/>
SMBleed<br/>
 <a href="https://github.com/ZecOps/CVE-2020-1206-POC">https://github.com/ZecOps/CVE-2020-1206-POC</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Intel Patch Day<br/>
 <a href="https://blogs.intel.com/technology/2020/06/ipas-security-advisories-for-june-2020/?linkId=100000012832617">https://blogs.intel.com/technology/2020/06/ipas-security-advisories-for-june-2020/?linkId=100000012832617</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7032" type="text/plain" language="en" />
<itunes:keywords>intel, adobe, microsoft, patches, smbleed, smbghost, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7030</itunes:episode>
<itunes:subtitle>Translating BASE64; Fake Ransomware Decrypt; GNUTLS Vuln; CallStranger
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Translating BASE64; Fake Ransomware Decrypt; GNUTLS Vuln; CallStranger
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7030.mp3" length="5767457" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7030.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7030</link>
<pubDate>Tue, 09 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Translating BASE64 Obfuscated Scripts<br/>
 <a href="https://isc.sans.edu/forums/diary/Translating+BASE64+Obfuscated+Scripts/26214/">https://isc.sans.edu/forums/diary/Translating+BASE64+Obfuscated+Scripts/26214/</a><br/>
Fake Ransomware Decryptor<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/">https://www.bleepingcomputer.com/news/security/fake-ransomware-decryptor-double-encrypts-desperate-victims-files/</a><br/>
GNUTLS TLS 1.3 Machine in the Middle<br/>
 <a href="https://gitlab.com/gnutls/gnutls/-/issues/1011">https://gitlab.com/gnutls/gnutls/-/issues/1011</a><br/>
CallStranger UPNP Vulnerability<br/>
 <a href="https://callstranger.com/">https://callstranger.com/</a><br/>
Shellcode Analysis 101<br/>
 <a href="https://www.sans.org/webcasts/sansatmic-shellcode-analysis-101-114160">https://www.sans.org/webcasts/sansatmic-shellcode-analysis-101-114160</a><br/>
]]></description>
<itunes:duration>6:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7030" type="text/plain" language="en" />
<itunes:keywords>shellcode, callstranger, upnp, gnutls, tls 1.3, fake ransomware decryptor, decryptor, ransomware, base64, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7028</itunes:episode>
<itunes:subtitle>PHP FastCGI Attacks; Protest Cybersecurity; QNAP Vuln; Blocking Loopback Portscans
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PHP FastCGI Attacks; Protest Cybersecurity; QNAP Vuln; Blocking Loopback Portscans
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7028.mp3" length="5376871" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7028.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7028</link>
<pubDate>Mon, 08 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[PHP FastCGI Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Not+so+FastCGI/26208/">https://isc.sans.edu/forums/diary/Not+so+FastCGI/26208/</a><br/>
Protest Cybersecurity<br/>
 <a href="https://isc.sans.edu/forums/diary/Cyber+Security+for+Protests/26210/">https://isc.sans.edu/forums/diary/Cyber+Security+for+Protests/26210/</a><br/>
uBlock Origin Blocks Portscans<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ublock-origin-ad-blocker-now-blocks-port-scans-on-most-sites/">https://www.bleepingcomputer.com/news/security/ublock-origin-ad-blocker-now-blocks-port-scans-on-most-sites/</a><br/>
QNAP Vulnerability<br/>
 <a href="https://www.qnap.com/en/security-advisory/qsa-20-01">https://www.qnap.com/en/security-advisory/qsa-20-01</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7028" type="text/plain" language="en" />
<itunes:keywords>qnap, ublock, ebay, portscan, javascript, xss, rce, protest, php, fastcgi, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 5th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7026</itunes:episode>
<itunes:subtitle>Anti-Debugging; Feed Update; Bank Transaction Spam;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Anti-Debugging; Feed Update; Bank Transaction Spam;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7026.mp3" length="11127728" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7026.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7026</link>
<pubDate>Fri, 05 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Anti-Debugging Technique Based on Memory Protection<br/>
 <a href="https://isc.sans.edu/forums/diary/AntiDebugging+Technique+based+on+Memory+Protection/26200/">https://isc.sans.edu/forums/diary/AntiDebugging+Technique+based+on+Memory+Protection/26200/</a><br/>
Suspending Suspicious Domain Feed/Update to Researcher IP Feed<br/>
 <a href="https://isc.sans.edu/forums/diary/Suspending+Suspicious+Domain+Feed+Update+to+Researcher+IP+Feed/26204/">https://isc.sans.edu/forums/diary/Suspending+Suspicious+Domain+Feed+Update+to+Researcher+IP+Feed/26204/</a> <br/>
Bank Transaction Comments Used for Abusive Messages<br/>
 <a href="https://www.theregister.com/2020/06/04/commonwealth_bank_bans_indecent_transaction_descriptions/">https://www.theregister.com/2020/06/04/commonwealth_bank_bans_indecent_transaction_descriptions/</a><br/>
Android Security Bulletin<br/>
 <a href="https://source.android.com/security/bulletin/2020-06-01">https://source.android.com/security/bulletin/2020-06-01</a><br/>
Android Wallpaper Crash<br/>
 <a href="https://www.androidauthority.com/android-wallpaper-crash-1124577/">https://www.androidauthority.com/android-wallpaper-crash-1124577/</a><br/>
STI Research Paper: Janusz Pazgier; Efficacy of UNIX HIDS<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/detection/efficacy-unix-hids-39565">https://www.sans.org/reading-room/whitepapers/detection/efficacy-unix-hids-39565</a><br/>
]]></description>
<itunes:duration>13:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7026" type="text/plain" language="en" />
<itunes:keywords>unix, hids, janusz pazgier, wallpaper, crash, android, bank, abusive messages, suspicious domains, ipip, anti-debugging, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7024</itunes:episode>
<itunes:subtitle>Polish ZLoader Malspam; Cisco IP-in-IP Flaw; Zoom Flaws; Firefox Disables DoH
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Polish ZLoader Malspam; Cisco IP-in-IP Flaw; Zoom Flaws; Firefox Disables DoH
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7024.mp3" length="5033473" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7024.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7024</link>
<pubDate>Thu, 04 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Polish Malspam Pushes ZLoader Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Polish+malspam+pushes+ZLoader+malware/26196/">https://isc.sans.edu/forums/diary/Polish+malspam+pushes+ZLoader+malware/26196/</a><br/>
Cisco Patches IP-in-IP Flaw<br/>
 <a href="https://securityaffairs.co/wordpress/104192/security/ip-in-ip-flaw-cisco.html">https://securityaffairs.co/wordpress/104192/security/ip-in-ip-flaw-cisco.html</a><br/>
Zoom Fixes Two Critical Flaws<br/>
 <a href="https://blog.talosintelligence.com/2020/06/vuln-spotlight-zoom-code-execution-june-2020.html">https://blog.talosintelligence.com/2020/06/vuln-spotlight-zoom-code-execution-june-2020.html</a><br/>
Firefox Disables Automatic DNS over HTTPS Selection to Prevent DDoS<br/>
 <a href="https://www.mozilla.org/en-US/firefox/77.0.1/releasenotes/">https://www.mozilla.org/en-US/firefox/77.0.1/releasenotes/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7024" type="text/plain" language="en" />
<itunes:keywords>firefox, doh, zoom, cisco, ip-in-ip, polish, malspam, zloader, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7022</itunes:episode>
<itunes:subtitle>Stackstrings; More AddTrust Woes; VMWare Cloud Director Exploit @__agwa
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Stackstrings; More AddTrust Woes; VMWare Cloud Director Exploit @__agwa
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7022.mp3" length="4680563" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7022.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7022</link>
<pubDate>Wed, 03 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Type 2 Strackstrings<br/>
 <a href="https://isc.sans.edu/forums/diary/Stackstrings+type+2/26192/">https://isc.sans.edu/forums/diary/Stackstrings+type+2/26192/</a><br/>
More Details About AddTrust External CA Root Expiration<br/>
 <a href="https://www.agwa.name/blog/post/fixing_the_addtrust_root_expiration">https://www.agwa.name/blog/post/fixing_the_addtrust_root_expiration</a><br/>
VMWare Cloud Director Vulnerability and Exploit <br/>
 <a href="https://citadelo.com/en/blog/full-infrastructure-takeover-of-vmware-cloud-director-CVE-2020-3956/">https://citadelo.com/en/blog/full-infrastructure-takeover-of-vmware-cloud-director-CVE-2020-3956/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7022" type="text/plain" language="en" />
<itunes:keywords>stackstring, vmware, addrust, ca, root, expiration, cloud director, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7020</itunes:episode>
<itunes:subtitle>Apple Patches Unc0ver; Office 365 Details; Security Researchers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patches Unc0ver; Office 365 Details; Security Researchers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7020.mp3" length="5971526" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7020.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7020</link>
<pubDate>Tue, 02 Jun 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Apple Patches Unc0ver<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Office 365 Adds Details About Malicious E-Mail Attachments<br/>
 <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=64570">https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=64570</a><br/>
Impact of Research on Our Data<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Impact+of+Researchers+on+Our+Data/26182/">https://isc.sans.edu/forums/diary/The+Impact+of+Researchers+on+Our+Data/26182/</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7020" type="text/plain" language="en" />
<itunes:keywords>researchers, office 365, attachments, apt, atp, unc0ver, apple, macos, ios, ipados, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 1st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7018</itunes:episode>
<itunes:subtitle>Sectigo CA; Sign in With Apple Flaw; DABANGG; FIDO @fidoalliance 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sectigo CA; Sign in With Apple Flaw; DABANGG; FIDO @fidoalliance 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7018.mp3" length="5266059" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7018.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7018</link>
<pubDate>Mon, 01 Jun 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Sectigo AddTrust CA Expired<br/>
 <a href="https://support.sectigo.com/articles/Knowledge/Sectigo-AddTrust-External-CA-Root-Expiring-May-30-2020">https://support.sectigo.com/articles/Knowledge/Sectigo-AddTrust-External-CA-Root-Expiring-May-30-2020</a><br/>
Critical Sign In With Apple Flaw<br/>
 <a href="https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/">https://bhavukjain.com/blog/2020/05/30/zeroday-signin-with-apple/</a><br/>
DABANGG: Refined Flush Based Cache Attacks<br/>
 <a href="https://www.cse.iitk.ac.in/users/biswap/DABANGG.pdf">https://www.cse.iitk.ac.in/users/biswap/DABANGG.pdf</a><br/>
New Website Explaining FIDO<br/>
 <a href="https://loginwithfido.com/">https://loginwithfido.com/</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7018" type="text/plain" language="en" />
<itunes:keywords>apple, sectigo, certificates, CA, fido, flush, cache, cpu, dabangg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7016</itunes:episode>
<itunes:subtitle>USBFuzz; Saltstack vs. Cisco; SHA1 Even Deader; @sans_edu : Threat Actor Assessments
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
USBFuzz; Saltstack vs. Cisco; SHA1 Even Deader; @sans_edu : Threat Actor Assessments
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7016.mp3" length="15734992" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7016.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7016</link>
<pubDate>Fri, 29 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[USBFuzz Finds Numerous USB Flaws<br/>
 <a href="https://www.nebelwelt.net/files/20SEC3.pdf">https://www.nebelwelt.net/files/20SEC3.pdf</a><br/>
Cisco Products Vulnerable to Saltstack Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-salt-2vx545AG</a><br/>
Another Nail in the Coffin for SHA-1<br/>
 <a href="https://eprint.iacr.org/2020/014.pdf">https://eprint.iacr.org/2020/014.pdf</a><br/>
STI Student: Andy Piazza; Qualifying Threat Actor Assessments<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/threatintelligence/paper/39585">https://www.sans.org/reading-room/whitepapers/threatintelligence/paper/39585</a><br/>
]]></description>
<itunes:duration>18:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7016" type="text/plain" language="en" />
<itunes:keywords>sti, sans_edu, interview, student, threat actor, assessments, cisco, sha1, hashes, usbfuzz, usb, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7014</itunes:episode>
<itunes:subtitle>Google Cloud Phish; Trend Micro Cheats; Netgear Nighthawk Evilgrade 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Cloud Phish; Trend Micro Cheats; Netgear Nighthawk Evilgrade 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7014.mp3" length="5736372" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7014.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7014</link>
<pubDate>Thu, 28 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Phishing With Google Cloud<br/>
 <a href="https://isc.sans.edu/forums/diary/Frankensteins+phishing+using+Google+Cloud+Storage/26174/">https://isc.sans.edu/forums/diary/Frankensteins+phishing+using+Google+Cloud+Storage/26174/</a><br/>
Trend Micro AntiVirus Blocked by Microsoft<br/>
 <a href="https://billdemirkapi.me/How-to-use-Trend-Micro-Rootkit-Remover-to-Install-a-Rootkit/">https://billdemirkapi.me/How-to-use-Trend-Micro-Rootkit-Remover-to-Install-a-Rootkit/</a><br/>
Netgear Nighthawk Firmware Update Vulnerability<br/>
 <a href="https://iot-lab-fh-ooe.github.io/netgear_update_vulnerability/">https://iot-lab-fh-ooe.github.io/netgear_update_vulnerability/</a><br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7014" type="text/plain" language="en" />
<itunes:keywords>netgear, nighthawk, firmware, evilgrade, trend, micro, antivirus, cheating, phishing, google, cloud, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7012</itunes:episode>
<itunes:subtitle>SHA3? MacOS Update; Windows 0Day Vuln; Phish Detection @CurtBraz
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SHA3? MacOS Update; Windows 0Day Vuln; Phish Detection @CurtBraz
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7012.mp3" length="5031279" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7012.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7012</link>
<pubDate>Wed, 27 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Where is SHA3<br/>
 <a href="https://isc.sans.edu/forums/diary/Seriously+SHA3+where+art+thou/26170/">https://isc.sans.edu/forums/diary/Seriously+SHA3+where+art+thou/26170/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Google ZDI Releases Details Regarding Unpatched Windows Vulnerabilities<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-20-666/">https://www.zerodayinitiative.com/advisories/ZDI-20-666/</a><br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-20-665/">https://www.zerodayinitiative.com/advisories/ZDI-20-665/</a><br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-20-663/">https://www.zerodayinitiative.com/advisories/ZDI-20-663/</a><br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-20-662/">https://www.zerodayinitiative.com/advisories/ZDI-20-662/</a><br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-20-664/">https://www.zerodayinitiative.com/advisories/ZDI-20-664/</a><br/>
Research into Phish Detection<br/>
 <a href="https://medium.com/@curtbraz/these-arent-the-phish-you-re-looking-for-7374c3986af5">https://medium.com/@curtbraz/these-arent-the-phish-you-re-looking-for-7374c3986af5</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7012" type="text/plain" language="en" />
<itunes:keywords>phishing, detection, google, zdi, windows, macos, ios, sha3, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 26th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7010</itunes:episode>
<itunes:subtitle>PowerPoint Add-Ins and VM Malware; iOS Patch Analysis; eBay Scanner; iPhone Jailbreak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PowerPoint Add-Ins and VM Malware; iOS Patch Analysis; eBay Scanner; iPhone Jailbreak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7010.mp3" length="5524985" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7010.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7010</link>
<pubDate>Tue, 26 May 2020 10:22:34 GMT</pubDate>
<description><![CDATA[Malicious PowerPoint Add-Ins Deliver Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/AgentTesla+Delivered+via+a+Malicious+PowerPoint+AddIn/26162/">https://isc.sans.edu/forums/diary/AgentTesla+Delivered+via+a+Malicious+PowerPoint+AddIn/26162/</a><br/>
Virtual Machine Delivers Malware<br/>
 <a href="https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/">https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/</a><br/>
iOS Patch Analysis<br/>
 <a href="https://blog.zecops.com/vulnerabilities/hidden-demons-maildemon-patch-analysis-ios-13-4-5-beta-vs-ios-13-5/">https://blog.zecops.com/vulnerabilities/hidden-demons-maildemon-patch-analysis-ios-13-4-5-beta-vs-ios-13-5/</a><br/>
eBay Port Scanning<br/>
 <a href="https://www.ghacks.net/2020/05/25/ebay-is-port-scanning-your-system-when-you-load-the-webpage/">https://www.ghacks.net/2020/05/25/ebay-is-port-scanning-your-system-when-you-load-the-webpage/</a><br/>
iPhone Jailbreak<br/>
 <a href="https://thehackernews.com/2020/05/iphone-ios-jailbreak-tools.html">https://thehackernews.com/2020/05/iphone-ios-jailbreak-tools.html</a><br/>
SANSFIRE<br/>
 <a href="https://isc.sans.edu/sansfire">https://isc.sans.edu/sansfire</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7010" type="text/plain" language="en" />
<itunes:keywords>sansfire, iphone, jailbreak, ebay, port scan, portscan, ios, vm, powerpoint, add-in, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7008</itunes:episode>
<itunes:subtitle>Malware Triage; Verizon DBIR; Apple Updates; Sophos XG Firewall
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Triage; Verizon DBIR; Apple Updates; Sophos XG Firewall
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7008.mp3" length="5075152" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7008.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7008</link>
<pubDate>Fri, 22 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Malware Triage with FLOSS: API Calls Based Behavior<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Triage+with+FLOSS+API+Calls+Based+Behavior/26156/">https://isc.sans.edu/forums/diary/Malware+Triage+with+FLOSS+API+Calls+Based+Behavior/26156/</a><br/>
Verizon Breach Report<br/>
 <a href="https://enterprise.verizon.com/resources/reports/dbir/">https://enterprise.verizon.com/resources/reports/dbir/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Sophos Firewall Vulnerability Exploit<br/>
 <a href="https://news.sophos.com/en-us/2020/05/21/asnarok2/">https://news.sophos.com/en-us/2020/05/21/asnarok2/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7008" type="text/plain" language="en" />
<itunes:keywords>sophos, apple, verizon, malware, triage, floss, fame, xg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7006</itunes:episode>
<itunes:subtitle>IceID Update; NXNSAttack; Adobe Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IceID Update; NXNSAttack; Adobe Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7006.mp3" length="4861583" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7006.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7006</link>
<pubDate>Thu, 21 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[IceID Malware Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Word+document+with+malicious+macro+pushes+IcedID+Bokbot/26146/">https://isc.sans.edu/forums/diary/Microsoft+Word+document+with+malicious+macro+pushes+IcedID+Bokbot/26146/</a><br/>
NXNSAttack DNS Amplification<br/>
 <a href="https://www.nxnsattack.com/">https://www.nxnsattack.com/</a><br/>
 <a href="https://en.blog.nic.cz/2020/05/19/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack/">https://en.blog.nic.cz/2020/05/19/nxnsattack-upgrade-resolvers-to-stop-new-kind-of-random-subdomain-attack/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7006" type="text/plain" language="en" />
<itunes:keywords>adobe, nxnsattack, dns, amplification, ddos, iceid, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7004</itunes:episode>
<itunes:subtitle>Port 62234; Cisco Patches; Google Chrome 83; QNAP @Happyholic1203
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Port 62234; Cisco Patches; Google Chrome 83; QNAP @Happyholic1203
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7004.mp3" length="5495004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7004.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7004</link>
<pubDate>Wed, 20 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Spike of Scans for Port 62234<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+up+on+Port+62234/26144/">https://isc.sans.edu/forums/diary/What+is+up+on+Port+62234/26144/</a><br/>
Cisco Patches<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-info-disclose-9eJtycMB">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-info-disclose-9eJtycMB</a><br/>
Google Chrome 83 Released<br/>
 <a href="https://chromereleases.googleblog.com/">https://chromereleases.googleblog.com/</a><br/>
QNAP Vulnerability Details Released<br/>
 <a href="https://medium.com/bugbountywriteup/qnap-pre-auth-root-rce-affecting-450k-devices-on-the-internet-d55488d28a05">https://medium.com/bugbountywriteup/qnap-pre-auth-root-rce-affecting-450k-devices-on-the-internet-d55488d28a05</a><br/>
ISC YouTube Channel<br/>
 <a href="https://www.youtube.com/channel/UCfbOsqPmWg1H_34hTjKEW2A">https://www.youtube.com/channel/UCfbOsqPmWg1H_34hTjKEW2A</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7004" type="text/plain" language="en" />
<itunes:keywords>port 62234, cisco, google, chrome, safebrowsing, youtube, qnap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 19th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7002</itunes:episode>
<itunes:subtitle>Multi Detection Confusion; O365 Mixes up Users; Apple BT Issues; #BIAS Bluetooth Vuln; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Multi Detection Confusion; O365 Mixes up Users; Apple BT Issues; #BIAS Bluetooth Vuln; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7002.mp3" length="5269716" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7002.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7002</link>
<pubDate>Tue, 19 May 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Antivirus & Multiple Detections<br/>
 <a href="https://isc.sans.edu/forums/diary/Antivirus+Multiple+Detections/26134/">https://isc.sans.edu/forums/diary/Antivirus+Multiple+Detections/26134/</a><br/>
Office 365 Returning Search Results from Other Organizations<br/>
 <a href="https://www.theregister.co.uk/2020/05/18/microsoft_office_365_internal_search_mixup/">https://www.theregister.co.uk/2020/05/18/microsoft_office_365_internal_search_mixup/</a><br/>
MagicPairing Vulnerabilities<br/>
 <a href="https://arxiv.org/pdf/2005.07255.pdf">https://arxiv.org/pdf/2005.07255.pdf</a><br/>
BIAS: Bluetooth Impersonation AttackS<br/>
 <a href="https://francozappa.github.io/about-bias/">https://francozappa.github.io/about-bias/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7002" type="text/plain" language="en" />
<itunes:keywords>bluetooth, magicpairing, apple, office 365, antivirus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>7000</itunes:episode>
<itunes:subtitle>OWA Scans; Edison Email Mixup; COMpfun Udpate; PAN OS Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OWA Scans; Edison Email Mixup; COMpfun Udpate; PAN OS Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/7000.mp3" length="5315061" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/7000.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/7000</link>
<pubDate>Mon, 18 May 2020 02:00:03 GMT</pubDate>
<description><![CDATA[OWA Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+for+Outlook+Web+Access+OWA+Microsoft+Exchange+Control+Panel+ECP/26132/">https://isc.sans.edu/forums/diary/Scanning+for+Outlook+Web+Access+OWA+Microsoft+Exchange+Control+Panel+ECP/26132/</a><br/>
Edison iOS E-Mail Client Leaks Data<br/>
 <a href="https://www.theverge.com/2020/5/16/21260967/edison-mail-update-ios-security-bug">https://www.theverge.com/2020/5/16/21260967/edison-mail-update-ios-security-bug</a><br/>
COMpfun Malware Uses Status Codes to Communicate<br/>
 <a href="https://securelist.com/compfun-http-status-based-trojan/96874/">https://securelist.com/compfun-http-status-based-trojan/96874/</a><br/>
PAN OS Patches<br/>
 <a href="https://securityaffairs.co/wordpress/103265/security/palo-alto-networks-pan-os-flaws.html">https://securityaffairs.co/wordpress/103265/security/palo-alto-networks-pan-os-flaws.html</a><br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=7000" type="text/plain" language="en" />
<itunes:keywords>panos, patches, compfun, edison, ios, email, owa, outlook, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6998</itunes:episode>
<itunes:subtitle>rethinking severity; top exploited vulns; iOS Vulnerability Glut; BigIP
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
rethinking severity; top exploited vulns; iOS Vulnerability Glut; BigIP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6998.mp3" length="5071495" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6998.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6998</link>
<pubDate>Fri, 15 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Rethinking Severity<br/>
 <a href="https://isc.sans.edu/forums/diary/Patch+Tuesday+Revisited+CVE20201048+isnt+as+Medium+as+MS+Would+Have+You+Believe/26124/">https://isc.sans.edu/forums/diary/Patch+Tuesday+Revisited+CVE20201048+isnt+as+Medium+as+MS+Would+Have+You+Believe/26124/</a><br/>
Top Exploited Vulnerabilities<br/>
 <a href="https://www.us-cert.gov/ncas/alerts/aa20-133a">https://www.us-cert.gov/ncas/alerts/aa20-133a</a><br/>
Zerodium Drops Payouts For iOS/Safari Exploits<br/>
 <a href="https://twitter.com/Zerodium/status/1260541578747064326?s=20">https://twitter.com/Zerodium/status/1260541578747064326?s=20</a><br/>
BigIP Edge Client Vulenrability<br/>
 <a href="https://support.f5.com/csp/article/K20346072">https://support.f5.com/csp/article/K20346072</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6998" type="text/plain" language="en" />
<itunes:keywords>bigip, zerodium, us-cert, severity, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6996</itunes:episode>
<itunes:subtitle>Dridex Update; Ramsay "Airgap" Malware; Windows 10 DoH Preview; #SANSFIRE Handler Series
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dridex Update; Ramsay "Airgap" Malware; Windows 10 DoH Preview; #SANSFIRE Handler Series
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6996.mp3" length="5017743" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6996.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6996</link>
<pubDate>Thu, 14 May 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Malspam with Links to ZIP Archives Pushes Dridex Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+with+links+to+zip+archives+pushes+Dridex+malware/26116/">https://isc.sans.edu/forums/diary/Malspam+with+links+to+zip+archives+pushes+Dridex+malware/26116/</a><br/>
Ramsay Cyber Espionage Toolkit<br/>
 <a href="https://www.welivesecurity.com/2020/05/13/ramsay-cyberespionage-toolkit-airgapped-networks/">https://www.welivesecurity.com/2020/05/13/ramsay-cyberespionage-toolkit-airgapped-networks/</a><br/>
Windows DNS over HTTPS Preview<br/>
 <a href="https://techcommunity.microsoft.com/t5/networking-blog/windows-insiders-can-now-test-dns-over-https/ba-p/1381282#">https://techcommunity.microsoft.com/t5/networking-blog/windows-insiders-can-now-test-dns-over-https/ba-p/1381282#</a><br/>
ISC Handler Series (SANSFIRE)<br/>
 <a href="https://www.sans.org/event/sansfire-2020/bonus-sessions/">https://www.sans.org/event/sansfire-2020/bonus-sessions/</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6996" type="text/plain" language="en" />
<itunes:keywords>handlers, sansifre, windows, dns, https, doh, ramsay, airgap, dridex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6994</itunes:episode>
<itunes:subtitle>MSFT / Adobe Patches; Exposed Firebase; Magecart Sightings; Glitter vs #thunderspy; @LibraAnalysis
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT / Adobe Patches; Exposed Firebase; Magecart Sightings; Glitter vs #thunderspy; @LibraAnalysis
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6994.mp3" length="5926913" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6994.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6994</link>
<pubDate>Wed, 13 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+May+2020+Patch+Tuesday/26114/">https://isc.sans.edu/forums/diary/Microsoft+May+2020+Patch+Tuesday/26114/</a><br/>
Adobe Security Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Android Applications Expose Firebase Databases<br/>
 <a href="https://www.comparitech.com/blog/information-security/firebase-misconfiguration-report/#What_data_is_exposed">https://www.comparitech.com/blog/information-security/firebase-misconfiguration-report/#What_data_is_exposed</a><br/>
More Magecart Sighted<br/>
 <a href="https://maxkersten.nl/2020/05/06/backtracking-magecart-infections/">https://maxkersten.nl/2020/05/06/backtracking-magecart-infections/</a><br/>
Glitter vs. Thunderspy<br/>
 <a href="https://www.youtube.com/watch?v=vlK5rrlc44g">https://www.youtube.com/watch?v=vlK5rrlc44g</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6994" type="text/plain" language="en" />
<itunes:keywords>glitter, thunderbolt, hunderspy, magecard, android, adobe, firebase, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 12th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6992</itunes:episode>
<itunes:subtitle>XLMMacroDeobfuscator; LinkedIn Phish; ThunderSpy; Patch vBulletin  @DissectMalware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XLMMacroDeobfuscator; LinkedIn Phish; ThunderSpy; Patch vBulletin  @DissectMalware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6992.mp3" length="4958493" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6992.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6992</link>
<pubDate>Tue, 12 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Excel 4 Macro Analysis: XLMMacroDeobfuscator<br/>
 <a href="https://isc.sans.edu/forums/diary/Excel+4+Macro+Analysis+XLMMacroDeobfuscator/26110/">https://isc.sans.edu/forums/diary/Excel+4+Macro+Analysis+XLMMacroDeobfuscator/26110/</a><br/>
LinkedIn Phish<br/>
 <a href="https://youtu.be/g0WHz6rikoc">https://youtu.be/g0WHz6rikoc</a><br/>
ThunderSpy Thunderbolt Attack<br/>
 <a href="https://thunderspy.io/">https://thunderspy.io/</a><br/>
vBulletin Vulnerability<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12720">https://nvd.nist.gov/vuln/detail/CVE-2020-12720</a><br/>
Mini-Netwars<br/>
 <a href="https://www.sans.org/mini-netwars">https://www.sans.org/mini-netwars</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6992" type="text/plain" language="en" />
<itunes:keywords>netwars, vbulletin, thunderspy, linkedin, excel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6990</itunes:episode>
<itunes:subtitle>YARA 4 Released; vRealize Salt; Samsung Android MMS RCE; MacOS 2FA Trojan
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
YARA 4 Released; vRealize Salt; Samsung Android MMS RCE; MacOS 2FA Trojan
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6990.mp3" length="4545964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6990.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6990</link>
<pubDate>Mon, 11 May 2020 02:00:03 GMT</pubDate>
<description><![CDATA[YARA 4.0.0 Released<br/>
 <a href="https://isc.sans.edu/forums/diary/YARA+v400+BASE64+Strings/26106/">https://isc.sans.edu/forums/diary/YARA+v400+BASE64+Strings/26106/</a><br/>
VMWare Patches vRealize to Address Saltstack Vulnerabilities<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0009.html">https://www.vmware.com/security/advisories/VMSA-2020-0009.html</a><br/>
Samsung Paches Android RCE Vulnerabilities <br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=2002">https://bugs.chromium.org/p/project-zero/issues/detail?id=2002</a><br/>
 <a href="https://security.samsungmobile.com/securityUpdate.smsb">https://security.samsungmobile.com/securityUpdate.smsb</a><br/>
MacOS 2FA Application Trojan<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2020/05/new-mac-variant-of-lazarus-dacls-rat-distributed-via-trojanized-2fa-app/">https://blog.malwarebytes.com/threat-analysis/2020/05/new-mac-variant-of-lazarus-dacls-rat-distributed-via-trojanized-2fa-app/</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6990" type="text/plain" language="en" />
<itunes:keywords>macos, 2fa, smasung, rce, images, vmware, yara, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6988</itunes:episode>
<itunes:subtitle>NMAP NSE Scripts; iOS Psychic Paper; #WorldPasswordDay; #Cisco Kerberos Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NMAP NSE Scripts; iOS Psychic Paper; #WorldPasswordDay; #Cisco Kerberos Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6988.mp3" length="4869987" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6988.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6988</link>
<pubDate>Fri, 08 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Scanning With NMAP NSE Scripts<br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+with+nmaps+NSE+scripts/26096/">https://isc.sans.edu/forums/diary/Scanning+with+nmaps+NSE+scripts/26096/</a><br/>
iOS Psychic Paper Vulerability<br/>
 <a href="https://siguza.github.io/psychicpaper/">https://siguza.github.io/psychicpaper/</a><br/>
World Password Day<br/>
 <a href="https://www.microsoft.com/security/blog/2020/05/07/protect-accounts-smarter-ways-sign-in-world-passwordless-day">https://www.microsoft.com/security/blog/2020/05/07/protect-accounts-smarter-ways-sign-in-world-passwordless-day</a><br/>
 <a href="https://tails.boum.org/news/version_4.6/index.en.html">https://tails.boum.org/news/version_4.6/index.en.html</a><br/>
Cisco Kerberos Bypass<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-asa-kerberos-bypass-96Gghe2sS">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-asa-kerberos-bypass-96Gghe2sS</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6988" type="text/plain" language="en" />
<itunes:keywords>nmap, ios, worldpasswordday, psychic paper, kerberos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6986</itunes:episode>
<itunes:subtitle>Malware Age; Fake Wallets; Favicon Hides JS; WebEx Phish @malwarebytes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Age; Fake Wallets; Favicon Hides JS; WebEx Phish @malwarebytes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6986.mp3" length="4997995" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6986.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6986</link>
<pubDate>Thu, 07 May 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Keeping an Eye on Malicious Files Life Time<br/>
 <a href="https://isc.sans.edu/forums/diary/Keeping+an+Eye+on+Malicious+Files+Life+Time/26092/">https://isc.sans.edu/forums/diary/Keeping+an+Eye+on+Malicious+Files+Life+Time/26092/</a><br/>
Fake Crypto Wallet Chrome Extensions<br/>
 <a href="https://www.theregister.co.uk/2020/05/06/chrome_malicious_extensions/">https://www.theregister.co.uk/2020/05/06/chrome_malicious_extensions/</a><br/>
Favicon Hides Credit Card Skimmer<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2020/05/credit-card-skimmer-masquerades-as-favicon/">https://blog.malwarebytes.com/threat-analysis/2020/05/credit-card-skimmer-masquerades-as-favicon/</a><br/>
WebEx Phishing<br/>
 <a href="https://abnormalsecurity.com/blog/abnormal-attack-stories-cisco-webex-phishing/">https://abnormalsecurity.com/blog/abnormal-attack-stories-cisco-webex-phishing/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6986" type="text/plain" language="en" />
<itunes:keywords>webex, favicon, crypto wallet, google chrome, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6984</itunes:episode>
<itunes:subtitle>Built in Cloud Security; Citrix Sharefile; Android/Fiefox/Dell/Wordpress Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Built in Cloud Security; Citrix Sharefile; Android/Fiefox/Dell/Wordpress Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6984.mp3" length="4402981" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6984.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6984</link>
<pubDate>Wed, 06 May 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Do Cloud Security Features Replace Pesonnel Security Capabilities?<br/>
 <a href="https://isc.sans.edu/forums/diary/Cloud+Security+Features+Dont+Replace+the+Need+for+Personnel+Security+Capabilities/26088/">https://isc.sans.edu/forums/diary/Cloud+Security+Features+Dont+Replace+the+Need+for+Personnel+Security+Capabilities/26088/</a><br/>
Citrix ShareFile Storage Zones Controller Update<br/>
 <a href="https://support.citrix.com/article/CTX269106">https://support.citrix.com/article/CTX269106</a><br/>
Android Update<br/>
 <a href="https://source.android.com/security/bulletin/2020-05-01">https://source.android.com/security/bulletin/2020-05-01</a><br/>
 <br/>
Firefox Update<br/>
 <a href="https://www.mozilla.org/en-US/firefox/76.0/releasenotes/">https://www.mozilla.org/en-US/firefox/76.0/releasenotes/</a><br/>
Dell OS Recovery Image Insecure Inherited Permissions<br/>
 <a href="https://www.dell.com/support/article/de-de/sln321036/dsa-2020-059-dell-os-recovery-image-insecure-inherited-permissions-vulnerability?lang=en">https://www.dell.com/support/article/de-de/sln321036/dsa-2020-059-dell-os-recovery-image-insecure-inherited-permissions-vulnerability?lang=en</a><br/>
WordPress Update<br/>
 <a href="https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updates">https://wordpress.org/support/wordpress-version/version-5-4-1/#security-updates</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6984" type="text/plain" language="en" />
<itunes:keywords>wordpress, dell, firefox, android, citrix, sharefile, cloud, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 5th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6982</itunes:episode>
<itunes:subtitle>Exploring Sysmon 11 Delete Protection; Digicert CT Compromise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exploring Sysmon 11 Delete Protection; Digicert CT Compromise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6982.mp3" length="4548528" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6982.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6982</link>
<pubDate>Tue, 05 May 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Exploring the Sysmon 11 File Deletion Protection<br/>
 <a href="https://isc.sans.edu/forums/diary/Sysmon+and+File+Deletion/26084/">https://isc.sans.edu/forums/diary/Sysmon+and+File+Deletion/26084/</a><br/>
Digicert CT Compromise<br/>
 <a href="https://groups.google.com/a/chromium.org/forum/#!topic/ct-policy/aKNbZuJzwfM">https://groups.google.com/a/chromium.org/forum/#!topic/ct-policy/aKNbZuJzwfM</a><br/>
WebLogic Flaw (new one..) Exploited in the Wild<br/>
 <a href="https://blogs.oracle.com/security/apply-april-2020-cpu">https://blogs.oracle.com/security/apply-april-2020-cpu</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6982" type="text/plain" language="en" />
<itunes:keywords>weblogic, oracle, digicert, ct, certificate transparency, sysmon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6980</itunes:episode>
<itunes:subtitle>ZIP and AES; Saltstack Exploited; MDM Compromise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ZIP and AES; Saltstack Exploited; MDM Compromise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6980.mp3" length="4552912" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6980.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6980</link>
<pubDate>Mon, 04 May 2020 02:00:03 GMT</pubDate>
<description><![CDATA[ZIP Files and AES<br/>
 <a href="https://isc.sans.edu/forums/diary/ZIP+AES/26080/">https://isc.sans.edu/forums/diary/ZIP+AES/26080/</a><br/>
Saltstack Vulnerability Exploited in the Wild<br/>
 <a href="https://status.ghost.org/">https://status.ghost.org/</a><br/>
Mobile Device Manager Compromise<br/>
 <a href="https://research.checkpoint.com/2020/first-seen-in-the-wild-mobile-as-attack-vector-using-mdm/">https://research.checkpoint.com/2020/first-seen-in-the-wild-mobile-as-attack-vector-using-mdm/</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6980" type="text/plain" language="en" />
<itunes:keywords>mdm, mobile devices, salt, saltstack, exploit, zip, aes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 1st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6978</itunes:episode>
<itunes:subtitle>IOCs from IMAP; Zyxel 0Day Bot; Salt Vuln; Mac Sandbox Escape
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IOCs from IMAP; Zyxel 0Day Bot; Salt Vuln; Mac Sandbox Escape
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6978.mp3" length="6092569" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6978.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6978</link>
<pubDate>Fri, 01 May 2020 02:05:03 GMT</pubDate>
<description><![CDATA[Collecting IOCs from IMAP Folder<br/>
 <a href="https://isc.sans.edu/forums/diary/Collecting+IOCs+from+IMAP+Folder/26070/">https://isc.sans.edu/forums/diary/Collecting+IOCs+from+IMAP+Folder/26070/</a><br/>
Attack Traffic on TCP Port 9673<br/>
 <a href="https://isc.sans.edu/forums/diary/Attack+traffic+on+TCP+port+9673/26074/">https://isc.sans.edu/forums/diary/Attack+traffic+on+TCP+port+9673/26074/</a><br/>
Saltstack Authorization Bypass<br/>
 <a href="https://labs.f-secure.com/advisories/saltstack-authorization-bypass">https://labs.f-secure.com/advisories/saltstack-authorization-bypass</a><br/>
Mac Sandbox Escape<br/>
 <a href="https://lapcatsoftware.com/articles/sandbox-escape.html">https://lapcatsoftware.com/articles/sandbox-escape.html</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6978" type="text/plain" language="en" />
<itunes:keywords>mac, sandbox, macos, saltstack, salt, 9673, 4005, 4006, ioc, imap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6976</itunes:episode>
<itunes:subtitle>Covid19 Tracing Protocols; Chrome Update; Sysmon Update; Shade; Honeysploit @CurtBraz
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Covid19 Tracing Protocols; Chrome Update; Sysmon Update; Shade; Honeysploit @CurtBraz
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6976.mp3" length="5266803" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6976.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6976</link>
<pubDate>Thu, 30 Apr 2020 02:00:02 GMT</pubDate>
<description><![CDATA[Privacy Preserving Protocols to Trace Covid19 Exposure<br/>
 <a href="https://isc.sans.edu/forums/diary/Privacy+Preserving+Protocols+to+Trace+Covid19+Exposure/26066/">https://isc.sans.edu/forums/diary/Privacy+Preserving+Protocols+to+Trace+Covid19+Exposure/26066/</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_27.html">https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_27.html</a><br/>
 <a href="https://docs.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security">https://docs.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security</a><br/>
Updated Version of Sysmon<br/>
 <a href="https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon">https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon</a><br/>
 <a href="https://techcommunity.microsoft.com/t5/sysinternals-blog/sysmon-v11-0-livekd-v5-63-process-explorer-v16-32-coreinfo-v3-5/ba-p/1345153">https://techcommunity.microsoft.com/t5/sysinternals-blog/sysmon-v11-0-livekd-v5-63-process-explorer-v16-32-coreinfo-v3-5/ba-p/1345153</a><br/>
Shade Ransomware Keys Released<br/>
 <a href="https://github.com/shade-team/keys/blob/master/README.md">https://github.com/shade-team/keys/blob/master/README.md</a><br/>
Exploiting the Exploiters<br/>
 <a href="https://medium.com/@curtbraz/exploiting-the-exploiters-46fd0d620fd8">https://medium.com/@curtbraz/exploiting-the-exploiters-46fd0d620fd8</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6976" type="text/plain" language="en" />
<itunes:keywords>covid19, google, chrome, patch, sysmon, shade, exploit, github, honeysploit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6974</itunes:episode>
<itunes:subtitle>Agent Tesla; VMWare ESXi Patch; Microsoft Ransomware Guidance; Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Agent Tesla; VMWare ESXi Patch; Microsoft Ransomware Guidance; Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6974.mp3" length="4069458" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6974.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6974</link>
<pubDate>Wed, 29 Apr 2020 02:00:03 GMT</pubDate>
<description><![CDATA[Agent Tesla Delivered by the Same Phishing Campagin for Over a Year<br/>
 <a href="https://isc.sans.edu/forums/diary/Agent+Tesla+delivered+by+the+same+phishing+campaign+for+over+a+year/26062/">https://isc.sans.edu/forums/diary/Agent+Tesla+delivered+by+the+same+phishing+campaign+for+over+a+year/26062/</a><br/>
VMWare ESXi Patch<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0008.html">https://www.vmware.com/security/advisories/VMSA-2020-0008.html</a><br/>
Microsoft Guidance For Ransomware Response<br/>
 <a href="https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/">https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/</a><br/>
Adobe Security Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
]]></description>
<itunes:duration>4:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6974" type="text/plain" language="en" />
<itunes:keywords>tesla, phishing, vmware, esxi, xss, microsoft, adobe, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6972</itunes:episode>
<itunes:subtitle>PS inside PSCredential; MSFT Teams GIF Vuln; USB Drives Spread Miner
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PS inside PSCredential; MSFT Teams GIF Vuln; USB Drives Spread Miner
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6972.mp3" length="5215599" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6972.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6972</link>
<pubDate>Tue, 28 Apr 2020 02:10:02 GMT</pubDate>
<description><![CDATA[Powershell Payload Stored in a PSCredential Object<br/>
 <a href="https://isc.sans.edu/forums/diary/Powershell+Payload+Stored+in+a+PSCredential+Object/26058/">https://isc.sans.edu/forums/diary/Powershell+Payload+Stored+in+a+PSCredential+Object/26058/</a><br/>
Microsoft Teams Account Takeover Bug<br/>
 <a href="https://www.cyberark.com/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams/">https://www.cyberark.com/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams/</a><br/>
USB Drives used to Spread Crypto Coin Mining Botnet<br/>
 <a href="https://www.welivesecurity.com/2020/04/23/eset-discovery-monero-mining-botnet-disrupted/">https://www.welivesecurity.com/2020/04/23/eset-discovery-monero-mining-botnet-disrupted/</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6972" type="text/plain" language="en" />
<itunes:keywords>usb, autoit, monery, microsoft teams, powershell, pscredential, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6970</itunes:episode>
<itunes:subtitle>Malware Bazaar; Canadian Shield; Covid 19 Tracing; Sophos XG Firewall
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Bazaar; Canadian Shield; Covid 19 Tracing; Sophos XG Firewall
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6970.mp3" length="6439275" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6970.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6970</link>
<pubDate>Mon, 27 Apr 2020 02:35:30 GMT</pubDate>
<description><![CDATA[Malware Bazaar<br/>
 <a href="https://isc.sans.edu/forums/diary/MALWARE+Bazaar/26052/">https://isc.sans.edu/forums/diary/MALWARE+Bazaar/26052/</a><br/>
CIRA Luanches Canadian Shield<br/>
 <a href="https://www.cira.ca/newsroom/canadian-shield/cira-launches-canadian-shield-provide-free-privacy-and-security-canadians">https://www.cira.ca/newsroom/canadian-shield/cira-launches-canadian-shield-provide-free-privacy-and-security-canadians</a><br/>
Covid19 Tracing Protocols<br/>
 <a href="https://github.com/DP-3T/documents">https://github.com/DP-3T/documents</a><br/>
 <a href="https://www.pepp-pt.org/content">https://www.pepp-pt.org/content</a><br/>
 <a href="https://www.apple.com/covid19/contacttracing/">https://www.apple.com/covid19/contacttracing/</a><br/>
Sophos XG Firewall SQL Injection Vulnerablity Exploited<br/>
 <a href="https://community.sophos.com/kb/en-us/135412">https://community.sophos.com/kb/en-us/135412</a><br/>
]]></description>
<itunes:duration>7:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6970" type="text/plain" language="en" />
<itunes:keywords>sophos, xg, firewall, sql injection, covid19, cira, malware, bazaar, canadian shield, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6968</itunes:episode>
<itunes:subtitle>GCC Adds Security Analyzer; IBM Spectrum Protect Flaw; GPU Radio; Red Team Platforms
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GCC Adds Security Analyzer; IBM Spectrum Protect Flaw; GPU Radio; Red Team Platforms
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6968.mp3" length="6181812" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6968.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6968</link>
<pubDate>Fri, 24 Apr 2020 03:00:03 GMT</pubDate>
<description><![CDATA[GCC's New Security Analyzer Finds Flaw in OpenSSL<br/>
 <a href="https://developers.redhat.com/blog/2020/03/26/static-analysis-in-gcc-10/">https://developers.redhat.com/blog/2020/03/26/static-analysis-in-gcc-10/</a><br/>
IBM Spectrum Protect Server Stack Based Buffer Overflow<br/>
 <a href="https://www.ibm.com/support/pages/node/6195706">https://www.ibm.com/support/pages/node/6195706</a><br/>
Possible Issues With Cummulative Windows Updates<br/>
 <a href="https://www.reddit.com/search/?q=KB4549951">https://www.reddit.com/search/?q=KB4549951</a><br/>
Using a GPU as a Radio<br/>
 <a href="https://duo.com/labs/research/finding-radio-sidechannels">https://duo.com/labs/research/finding-radio-sidechannels</a><br/>
Comparing Red Team Platforms<br/>
 <a href="https://redcanary.com/blog/comparing-red-team-platforms/">https://redcanary.com/blog/comparing-red-team-platforms/</a><br/>
]]></description>
<itunes:duration>7:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6968" type="text/plain" language="en" />
<itunes:keywords>red team, gpu, windows, updates, IBM, spectrum Protect, gcc, openssl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6966</itunes:episode>
<itunes:subtitle>iOS Mail 0Day; Zoom 5; OpenSSL Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iOS Mail 0Day; Zoom 5; OpenSSL Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6966.mp3" length="5098940" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6966.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6966</link>
<pubDate>Thu, 23 Apr 2020 03:00:03 GMT</pubDate>
<description><![CDATA[iOS Mail 0Day<br/>
 <a href="https://blog.zecops.com/vulnerabilities/unassisted-ios-attacks-via-mobilemail-maild-in-the-wild/">https://blog.zecops.com/vulnerabilities/unassisted-ios-attacks-via-mobilemail-maild-in-the-wild/</a><br/>
Zoom 5 To Be Released Shortly Addressing Encryption Issues<br/>
 <a href="https://blog.zoom.us/wordpress/2020/04/22/zoom-hits-milestone-on-90-day-security-plan-releases-zoom-5-0/">https://blog.zoom.us/wordpress/2020/04/22/zoom-hits-milestone-on-90-day-security-plan-releases-zoom-5-0/</a><br/>
OpenSSL Fixes DOS Flaw<br/>
 <a href="https://www.openssl.org/news/secadv/20200421.txt">https://www.openssl.org/news/secadv/20200421.txt</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6966" type="text/plain" language="en" />
<itunes:keywords>ios, mail, 0day, zoom, openssl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6964</itunes:episode>
<itunes:subtitle>SpectX; MSFT Office Patch; Stripe Data Collection; IBM Data Risk Manager Risk
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SpectX; MSFT Office Patch; Stripe Data Collection; IBM Data Risk Manager Risk
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6964.mp3" length="4996909" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6964.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6964</link>
<pubDate>Wed, 22 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[SpectX: Log Parser for DFIR<br/>
 <a href="https://isc.sans.edu/forums/diary/SpectX+Log+Parser+for+DFIR/26040/">https://isc.sans.edu/forums/diary/SpectX+Log+Parser+for+DFIR/26040/</a><br/>
Microsoft Patches Autodesk Library in Office<br/>
 <a href="https://www.autodesk.com/trust/security-advisories/adsk-sa-2020-0002">https://www.autodesk.com/trust/security-advisories/adsk-sa-2020-0002</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200004">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200004</a><br/>
Stripe Data Collection<br/>
 <a href="https://mtlynch.io/stripe-recording-its-customers/">https://mtlynch.io/stripe-recording-its-customers/</a><br/>
IBM Data Risk Manager Vulnerabilities<br/>
 <a href="https://github.com/pedrib/PoC/blob/master/advisories/IBM/ibm_drm/ibm_drm_rce.md">https://github.com/pedrib/PoC/blob/master/advisories/IBM/ibm_drm/ibm_drm_rce.md</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6964" type="text/plain" language="en" />
<itunes:keywords>ibm, data risk manager, stripe, microsoft, office, spectx, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6962</itunes:episode>
<itunes:subtitle>AutoIT Analysis; FPGA Vulnerability; Nagios Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AutoIT Analysis; FPGA Vulnerability; Nagios Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6962.mp3" length="4867439" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6962.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6962</link>
<pubDate>Tue, 21 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[KPOT AutoIt Script: Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/KPOT+AutoIt+Script+Analysis/26012/">https://isc.sans.edu/forums/diary/KPOT+AutoIt+Script+Analysis/26012/</a><br/>
FPGA Vulnerablity<br/>
 <a href="https://www.usenix.org/conference/usenixsecurity20/presentation/ender">https://www.usenix.org/conference/usenixsecurity20/presentation/ender</a><br/>
Nagios XI Vulnerability<br/>
 <a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/179406">https://exchange.xforce.ibmcloud.com/vulnerabilities/179406</a><br/>
 <br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6962" type="text/plain" language="en" />
<itunes:keywords>nagios, fpga, kpot, autoit, reverse analysis, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6960</itunes:episode>
<itunes:subtitle>Malicious RTF Generator; Sophos Pulls UTM Update; Pulse Secure VPN; Chrome Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious RTF Generator; Sophos Pulls UTM Update; Pulse Secure VPN; Chrome Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6960.mp3" length="4681652" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6960.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6960</link>
<pubDate>Mon, 20 Apr 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Weaponized RTF Document Generator Mailer in PowerShell<br/>
 <a href="https://isc.sans.edu/forums/diary/Weaponized+RTF+Document+Generator+Mailer+in+PowerShell/26030/">https://isc.sans.edu/forums/diary/Weaponized+RTF+Document+Generator+Mailer+in+PowerShell/26030/</a><br/>
Microsoft Fixes Bad Anti-Malware Signatures<br/>
 <a href="https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes">https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes</a><br/>
Sophos Pulls Bad Firmware Update<br/>
 <a href="https://community.sophos.com/kb/en-us/135383">https://community.sophos.com/kb/en-us/135383</a><br/>
Credentials Stolen from Pulse Secure VPN Abused <br/>
 <a href="https://www.us-cert.gov/ncas/alerts/aa20-107a">https://www.us-cert.gov/ncas/alerts/aa20-107a</a><br/>
Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html">https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_15.html</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6960" type="text/plain" language="en" />
<itunes:keywords>chrome, vpn, pulse secure, microsoft, security, anti-malware, rtf, template, generator, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6958</itunes:episode>
<itunes:subtitle>Applocker vs LOTL; Netlink GPON 0Day; Windows Security Crash; Bad Gems; vCenter Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Applocker vs LOTL; Netlink GPON 0Day; Windows Security Crash; Bad Gems; vCenter Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6958.mp3" length="4908760" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6958.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6958</link>
<pubDate>Fri, 17 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Applocker vs. Living off the Land Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+AppLocker+to+Prevent+Living+off+the+Land+Attacks/26032/">https://isc.sans.edu/forums/diary/Using+AppLocker+to+Prevent+Living+off+the+Land+Attacks/26032/</a><br/>
Netlink GPON 0-Day<br/>
 <a href="https://blog.netlab.360.com/multiple-fiber-routers-are-being-compromised-by-botnets-using-0-day-en/">https://blog.netlab.360.com/multiple-fiber-routers-are-being-compromised-by-botnets-using-0-day-en/</a><br/>
Windows Security Crashing After Definition Update<br/>
 <a href="https://www.askwoody.com/2020/reports-of-windows-security-nee-microsoft-security-essentials-crashing-after-installing-this-mornings-definition-updates/">https://www.askwoody.com/2020/reports-of-windows-security-nee-microsoft-security-essentials-crashing-after-installing-this-mornings-definition-updates/</a><br/>
700 Malicious Ruby Gems Found<br/>
 <a href="https://thehackernews.com/2020/04/rubygem-typosquatting-malware.html">https://thehackernews.com/2020/04/rubygem-typosquatting-malware.html</a><br/>
vCenter Exploit for CVE-2020-3952<br/>
 <a href="https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/">https://www.guardicore.com/2020/04/pwning-vmware-vcenter-cve-2020-3952/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6958" type="text/plain" language="en" />
<itunes:keywords>vmware, vcener, ruby, gems, windows security, netlink, gpon, applocker, lotd, living off the land, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6956</itunes:episode>
<itunes:subtitle>Hunting without IOCs; Cloudflare/Online Banking Outages; Crypto Stealing Chrome Ext.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hunting without IOCs; Cloudflare/Online Banking Outages; Crypto Stealing Chrome Ext.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6956.mp3" length="4587305" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6956.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6956</link>
<pubDate>Thu, 16 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Hunting Without IOCs<br/>
 <a href="https://isc.sans.edu/forums/diary/No+IOCs+No+Problem+Getting+a+Start+Hunting+for+Malicious+Office+Files/26026/">https://isc.sans.edu/forums/diary/No+IOCs+No+Problem+Getting+a+Start+Hunting+for+Malicious+Office+Files/26026/</a><br/>
Cloudflare/Online Banking Outages<br/>
 <a href="https://twitter.com/eastdakota/status/1250520852354854912">https://twitter.com/eastdakota/status/1250520852354854912</a><br/>
Crypto Currency Stealing Browser Extensions<br/>
 <a href="https://medium.com/mycrypto/discovering-fake-browser-extensions-that-target-users-of-ledger-trezor-mew-metamask-and-more-e281a2b80ff9">https://medium.com/mycrypto/discovering-fake-browser-extensions-that-target-users-of-ledger-trezor-mew-metamask-and-more-e281a2b80ff9</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6956" type="text/plain" language="en" />
<itunes:keywords>crypto, currency, chrome, browser extensions, cloudflare, hunting, macros, office, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6954</itunes:episode>
<itunes:subtitle>MSFT and Adobe Patches; Extended EOL for Win10 1809/1709; Dell SafeBIOS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT and Adobe Patches; Extended EOL for Win10 1809/1709; Dell SafeBIOS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6954.mp3" length="4208795" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6954.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6954</link>
<pubDate>Wed, 15 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+April+2020+Patch+Tuesday/26022/">https://isc.sans.edu/forums/diary/Microsoft+April+2020+Patch+Tuesday/26022/</a><br/>
Adobe Security Bulletins<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Microsoft Extending EOL For Windows 10 1709/1809<br/>
 <a href="https://support.microsoft.com/en-us/help/4557164/lifecycle-changes-to-end-of-support-and-servicing-dates">https://support.microsoft.com/en-us/help/4557164/lifecycle-changes-to-end-of-support-and-servicing-dates</a><br/>
Dell Safe BIOS<br/>
 <a href="https://blog.dellemc.com/en-us/dell-technologies-bolsters-pc-security-todays-remote-workers/">https://blog.dellemc.com/en-us/dell-technologies-bolsters-pc-security-todays-remote-workers/</a><br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6954" type="text/plain" language="en" />
<itunes:keywords>dell, safebios, microsoft, extnding eol, windows 10, patch tueday, adobe, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6952</itunes:episode>
<itunes:subtitle>Evolving Phishing Campaign; Flaming 3D Printers; Junos OS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Evolving Phishing Campaign; Flaming 3D Printers; Junos OS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6952.mp3" length="5325313" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6952.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6952</link>
<pubDate>Tue, 14 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Comparing the same Phishing Campaign 3 Months Appart<br/>
 <a href="https://isc.sans.edu/forums/diary/Look+at+the+same+phishing+campaign+3+months+apart/26018/">https://isc.sans.edu/forums/diary/Look+at+the+same+phishing+campaign+3+months+apart/26018/</a><br/>
Setting 3D Printers On Fire<br/>
 <a href="https://www.coalfire.com/The-Coalfire-Blog/April-2020/With-IoT-Common-Devices-Pose-New-Threats">https://www.coalfire.com/The-Coalfire-Blog/April-2020/With-IoT-Common-Devices-Pose-New-Threats</a><br/>
Junos OS: vMX Default Credentials<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10998">https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10998</a><br/>
DNS is Changing: So What? (@Mic Webinar)<br/>
 <a href="https://www.sans.org/webcasts/113635">https://www.sans.org/webcasts/113635</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6952" type="text/plain" language="en" />
<itunes:keywords>junos, vmx, 3d printers, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6950</itunes:episode>
<itunes:subtitle>Decrypted KPOT Malware; VCenter Patch; Ransomware Swith to Monero
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Decrypted KPOT Malware; VCenter Patch; Ransomware Swith to Monero
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6950.mp3" length="4460029" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6950.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6950</link>
<pubDate>Mon, 13 Apr 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Dynamic Analysis Technique to Get Decrypted KPOT Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Reader+Analysis+Dynamic+analysis+technique+to+get+decrypted+KPOT+Malware/26010/">https://isc.sans.edu/forums/diary/Reader+Analysis+Dynamic+analysis+technique+to+get+decrypted+KPOT+Malware/26010/</a><br/>
VMWare vCenter Server Vulnerability<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0006.html">https://www.vmware.com/security/advisories/VMSA-2020-0006.html</a><br/>
Sodinokibi Ransomware Switching to Monero<br/>
 <a href="https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-to-stop-taking-bitcoin-to-hide-money-trail/">https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-to-stop-taking-bitcoin-to-hide-money-trail/</a><br/>
Malware Impersonates Security Researchers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-wiper-malware-impersonates-security-researchers-as-prank/">https://www.bleepingcomputer.com/news/security/new-wiper-malware-impersonates-security-researchers-as-prank/</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6950" type="text/plain" language="en" />
<itunes:keywords>malware, wiper, impersonation, sodinokibi, monero, vmware, kpot, descryption, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6948</itunes:episode>
<itunes:subtitle>OS Spoofing; Dell iDRAC Patch; VISA ends Magento 1 support; TURN Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OS Spoofing; Dell iDRAC Patch; VISA ends Magento 1 support; TURN Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6948.mp3" length="4832692" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6948.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6948</link>
<pubDate>Fri, 10 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Spoofing OS Fingerprints<br/>
 <a href="https://isc.sans.edu/forums/diary/Performing+deception+to+OS+Fingerprint+Part+1+nmap/25960/">https://isc.sans.edu/forums/diary/Performing+deception+to+OS+Fingerprint+Part+1+nmap/25960/</a><br/>
Dell iDRAC Patch<br/>
 <a href="https://www.dell.com/support/article/de-de/sln320717/dsa-2020-063-idrac-buffer-overflow-vulnerability?lang=en">https://www.dell.com/support/article/de-de/sln320717/dsa-2020-063-idrac-buffer-overflow-vulnerability?lang=en</a><br/>
VISA Ends Magento 1 Support<br/>
 <a href="https://usa.visa.com/content/dam/VCOM/global/support-legal/documents/acquirer-advisory-magento-migration.pdf">https://usa.visa.com/content/dam/VCOM/global/support-legal/documents/acquirer-advisory-magento-migration.pdf</a><br/>
Slack WebRTC TURN Compromise<br/>
 <a href="https://www.rtcsec.com/2020/04/01-slack-webrtc-turn-compromise/">https://www.rtcsec.com/2020/04/01-slack-webrtc-turn-compromise/</a><br/>
COVID 19 Domain Classifier<br/>
 <a href="https://isc.sans.edu/covidclassifier.html">https://isc.sans.edu/covidclassifier.html</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6948" type="text/plain" language="en" />
<itunes:keywords>covid19, covid, domains, slack, webrtc, turn, visa, magento, adobe, dell, idrac, spoofing, os, fingerprints, nmap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6946</itunes:episode>
<itunes:subtitle>Encrypted Traffic Analysis; Corp.com; Exchange Authentication Update; Dark Nexus
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encrypted Traffic Analysis; Corp.com; Exchange Authentication Update; Dark Nexus
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6946.mp3" length="4970940" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6946.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6946</link>
<pubDate>Thu, 09 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[German Malspam Pushes ZLoader Malware; Decrypting HTTPs<br/>
 <a href="https://isc.sans.edu/forums/diary/German+malspam+pushes+ZLoader+malware/25996/">https://isc.sans.edu/forums/diary/German+malspam+pushes+ZLoader+malware/25996/</a><br/>
Microsoft Purchases Corp.com<br/>
 <a href="https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-so-bad-guys-cant/">https://krebsonsecurity.com/2020/04/microsoft-buys-corp-com-so-bad-guys-cant/</a><br/>
Microsoft Delaying Removal of Basic Authentiation from Exchange Online<br/>
 <a href="https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-and-exchange-online-april-2020-update/ba-p/1275508">https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-and-exchange-online-april-2020-update/ba-p/1275508</a><br/>
Dark Nexus Botnet<br/>
 <a href="https://www.bitdefender.com/files/News/CaseStudies/study/319/Bitdefender-PR-Whitepaper-DarkNexus-creat4349-en-EN-interactive.pdf">https://www.bitdefender.com/files/News/CaseStudies/study/319/Bitdefender-PR-Whitepaper-DarkNexus-creat4349-en-EN-interactive.pdf</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6946" type="text/plain" language="en" />
<itunes:keywords>dark nexus, botnet, iot, proxy, microsoft, exchange, authentication, oauth, corp.com, malspam, encryption, zloader, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6944</itunes:episode>
<itunes:subtitle>RDP Scanning Increase; Exposed Atlassian Tools; Android Pixel 4 Awake Detection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RDP Scanning Increase; Exposed Atlassian Tools; Android Pixel 4 Awake Detection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6944.mp3" length="4350692" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6944.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6944</link>
<pubDate>Wed, 08 Apr 2020 03:00:03 GMT</pubDate>
<description><![CDATA[RDP Scanning Increase<br/>
 <a href="https://isc.sans.edu/forums/diary/Increase+in+RDP+Scanning/25994/">https://isc.sans.edu/forums/diary/Increase+in+RDP+Scanning/25994/</a><br/>
Atlassian Advices Users To Secure Jira Service Desk<br/>
 <a href="https://community.atlassian.com/t5/Jira-Service-Desk-articles/Tips-for-setting-customer-permissions-in-Jira-Service-Desk/ba-p/1340617">https://community.atlassian.com/t5/Jira-Service-Desk-articles/Tips-for-setting-customer-permissions-in-Jira-Service-Desk/ba-p/1340617</a><br/>
Android Updates<br/>
 <a href="https://support.google.com/pixelphone/thread/38337876">https://support.google.com/pixelphone/thread/38337876</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6944" type="text/plain" language="en" />
<itunes:keywords>android, atlassian, jira, rdp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6942</itunes:episode>
<itunes:subtitle>BGP Hijack; Vuln Cost Plugin; Exchange Bug Patching; Fake Zoom Installer
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BGP Hijack; Vuln Cost Plugin; Exchange Bug Patching; Fake Zoom Installer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6942.mp3" length="5541084" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6942.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6942</link>
<pubDate>Tue, 07 Apr 2020 03:00:03 GMT</pubDate>
<description><![CDATA[ROSTELECOM Reroutes Traffic for Multiple Cloud Providers<br/>
 <a href="https://twitter.com/bgpmon/status/1246842916502302723">https://twitter.com/bgpmon/status/1246842916502302723</a><br/>
 <a href="https://bgpstream.com/event/230837">https://bgpstream.com/event/230837</a><br/>
Vuln Cost Security Scanner for VS Code<br/>
 <a href="https://snyk.io/security-scanner-vuln-cost/">https://snyk.io/security-scanner-vuln-cost/</a><br/>
Microsoft Exchange Server Vulnerability still not Patched<br/>
 <a href="https://blog.rapid7.com/2020/04/06/phishing-for-system-on-microsoft-exchange-cve-2020-0688/">https://blog.rapid7.com/2020/04/06/phishing-for-system-on-microsoft-exchange-cve-2020-0688/</a><br/>
Fake Zoom Installer<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/zoomed-in-a-look-into-a-coinminer-bundled-with-zoom-installer/">https://blog.trendmicro.com/trendlabs-security-intelligence/zoomed-in-a-look-into-a-coinminer-bundled-with-zoom-installer/</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6942" type="text/plain" language="en" />
<itunes:keywords>zoom, fake installer, microsoft, exchange, owa, patch, vuln cost, snyk, vs code, rostelecom, bpg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6940</itunes:episode>
<itunes:subtitle>Corrupt DOC; Zoom "Encryption"; Firefox Patch; Discord Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Corrupt DOC; Zoom "Encryption"; Firefox Patch; Discord Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6940.mp3" length="4823549" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6940.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6940</link>
<pubDate>Mon, 06 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[New Bypass Technique or Corrupt Word Document<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Bypass+Technique+or+Corrupt+Word+Document/25984/">https://isc.sans.edu/forums/diary/New+Bypass+Technique+or+Corrupt+Word+Document/25984/</a><br/>
CitizenLab Analyzes Zoom Encryption<br/>
 <a href="https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/">https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/</a><br/>
 <a href="https://www.sans.org/webcasts/zomg-its-zoom-114670">https://www.sans.org/webcasts/zomg-its-zoom-114670</a> <br/>
Mozilla Patches Critical Firefox Flaws<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/">https://www.mozilla.org/en-US/security/advisories/mfsa2020-11/</a><br/>
Malicious JavaScript injected into Discord<br/>
 <a href="https://www.bleepingcomputer.com/news/security/discord-turned-into-an-account-stealer-by-updated-malware/">https://www.bleepingcomputer.com/news/security/discord-turned-into-an-account-stealer-by-updated-malware/</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6940" type="text/plain" language="en" />
<itunes:keywords>discord, malware, anarchygrabber, firefox, mozilla, citizenlab, zoom, encryption, word, bypass, corrupt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6938</itunes:episode>
<itunes:subtitle>Twitter Cache Bug; MSSQL Server; Zoom Again; Covid19 Scams; Safari Camera Access Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Twitter Cache Bug; MSSQL Server; Zoom Again; Covid19 Scams; Safari Camera Access Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6938.mp3" length="5527183" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6938.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6938</link>
<pubDate>Fri, 03 Apr 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Twitter Cache Bug in Firefox <br/>
 <a href="https://privacy.twitter.com/en/blog/2020/data-cache-firefox">https://privacy.twitter.com/en/blog/2020/data-cache-firefox</a><br/>
MS-SQL Server Attack<br/>
 <a href="https://www.guardicore.com/2020/04/vollgar-ms-sql-servers-under-attack/">https://www.guardicore.com/2020/04/vollgar-ms-sql-servers-under-attack/</a><br/>
More Zoom Vulnerabilities <br/>
 <a href="https://objective-see.com/blog/blog_0x56.html">https://objective-see.com/blog/blog_0x56.html</a><br/>
Covid-19 Economic Impact Payments Scams<br/>
 <a href="https://www.justice.gov/usao-edky/press-release/file/1265371/download">https://www.justice.gov/usao-edky/press-release/file/1265371/download</a><br/>
Safari Camera Access Bug<br/>
 <a href="https://www.ryanpickren.com/webcam-hacking-overview">https://www.ryanpickren.com/webcam-hacking-overview</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6938" type="text/plain" language="en" />
<itunes:keywords>Safari, Covid19, zoom, mssql, ms-sql, twitter, firefox, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6936</itunes:episode>
<itunes:subtitle>Quakbot; TPOT and DShield; MacOS ssh; Cloudflare DNS; Zoom Leaks NTLM Hashes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Quakbot; TPOT and DShield; MacOS ssh; Cloudflare DNS; Zoom Leaks NTLM Hashes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6936.mp3" length="5428814" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6936.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6936</link>
<pubDate>Thu, 02 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Quakbot Malspam Sent From an Infected Windows Host<br/>
 <a href="https://isc.sans.edu/forums/diary/Qakbot+malspam+sent+from+an+infected+Windows+host/25972/">https://isc.sans.edu/forums/diary/Qakbot+malspam+sent+from+an+infected+Windows+host/25972/</a><br/>
TPOT Cowrie to ISC Logs<br/>
 <a href="https://isc.sans.edu/forums/diary/TPOTs+Cowrie+to+ISC+Logs/25976/">https://isc.sans.edu/forums/diary/TPOTs+Cowrie+to+ISC+Logs/25976/</a><br/>
SSH Issues After MacOS Update<br/>
 <a href="https://feed.tyler.io/so-uh-i-think-catalina-10154-broke-ssh/">https://feed.tyler.io/so-uh-i-think-catalina-10154-broke-ssh/</a><br/>
Cloudflare DNS For Families<br/>
 <a href="https://blog.cloudflare.com/introducing-1-1-1-1-for-families/">https://blog.cloudflare.com/introducing-1-1-1-1-for-families/</a><br/>
Zoom Leaks Windows Password Hashes via UNC Links<br/>
 <a href="https://twitter.com/hackerfantastic/status/1245133371262619654">https://twitter.com/hackerfantastic/status/1245133371262619654</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6936" type="text/plain" language="en" />
<itunes:keywords>zoom, ntlm, unc, cloudflare, dns, ssh, macos, tpot, quakbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 1st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6934</itunes:episode>
<itunes:subtitle>Kwampirs Update; Exposed RDP; D-Link Vulnerability; SMB CVE-2020-0796 Exploit 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kwampirs Update; Exposed RDP; D-Link Vulnerability; SMB CVE-2020-0796 Exploit 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6934.mp3" length="5841709" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6934.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6934</link>
<pubDate>Wed, 01 Apr 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Kwampirs Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Kwampirs+Targeted+Attacks+Involving+Healthcare+Sector/25968/">https://isc.sans.edu/forums/diary/Kwampirs+Targeted+Attacks+Involving+Healthcare+Sector/25968/</a><br/>
Exposed RDP<br/>
 <a href="https://blog.shodan.io/trends-in-internet-exposure/">https://blog.shodan.io/trends-in-internet-exposure/</a><br/>
D-Link DSL-2640B Vulnerability<br/>
 <a href="https://raelize.com/posts/d-link-dsl-2640b-security-advisories/">https://raelize.com/posts/d-link-dsl-2640b-security-advisories/</a><br/>
SMB 3.1.1 (CVE-2020-0796) Local Privilege Escalation Exploit<br/>
 <a href="https://github.com/danigargu/CVE-2020-0796">https://github.com/danigargu/CVE-2020-0796</a><br/>
]]></description>
<itunes:duration>6:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6934" type="text/plain" language="en" />
<itunes:keywords>smb, exploit, dlink, d-link, dsl, rdp, kwampirs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 31st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6932</itunes:episode>
<itunes:subtitle>Crashing Windows Explorer; Zoom Privacy; Zoom Bombing; Zoom Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Crashing Windows Explorer; Zoom Privacy; Zoom Bombing; Zoom Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6932.mp3" length="5747347" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6932.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6932</link>
<pubDate>Tue, 31 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Crashing Windows Explorer Without a Click<br/>
 <a href="https://isc.sans.edu/forums/diary/Crashing+explorerexe+without+a+click/25966/">https://isc.sans.edu/forums/diary/Crashing+explorerexe+without+a+click/25966/</a><br/>
Zoom Privacy Policy<br/>
 <a href="https://blogs.harvard.edu/doc/2020/03/27/zoom/">https://blogs.harvard.edu/doc/2020/03/27/zoom/</a><br/>
Zoom Bombing<br/>
 <a href="https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic">https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic</a><br/>
Zoom Related Domains Used for Phishing<br/>
 <a href="https://blog.checkpoint.com/2020/03/30/covid-19-impact-cyber-criminals-target-zoom-domains/">https://blog.checkpoint.com/2020/03/30/covid-19-impact-cyber-criminals-target-zoom-domains/</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6932" type="text/plain" language="en" />
<itunes:keywords>zoom, bombing, phishing, domains, privacy, facebook, crash, windows explorer, links, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6930</itunes:episode>
<itunes:subtitle>Domain Classifier; Malicious Teddy Bears; iOS Malware on HK News Sites
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Domain Classifier; Malicious Teddy Bears; iOS Malware on HK News Sites
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6930.mp3" length="4746749" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6930.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6930</link>
<pubDate>Mon, 30 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Covid19 Domain Classifier<br/>
 <a href="https://isc.sans.edu/covidclassifier.html">https://isc.sans.edu/covidclassifier.html</a><br/>
 <a href="https://www.youtube.com/watch?v=yNIlyJ3gI-4">https://www.youtube.com/watch?v=yNIlyJ3gI-4</a><br/>
Attackers Mail Malicious USB Drives and Teddy Bears<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/would-you-exchange-your-security-for-a-gift-card/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/would-you-exchange-your-security-for-a-gift-card/</a><br/>
HongKong News Sites Used to Install Malware on iOS Devices<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/">https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6930" type="text/plain" language="en" />
<itunes:keywords>hongkong, malware, ios, fin7, usb drives, teddy bears, covid19, domains, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6928</itunes:episode>
<itunes:subtitle>Obfuscation via Size; iOS VPN Bypass; Free Covid19 Domain List; Detecting Bad Keyboards
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscation via Size; iOS VPN Bypass; Free Covid19 Domain List; Detecting Bad Keyboards
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6928.mp3" length="4771252" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6928.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6928</link>
<pubDate>Fri, 27 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Very Large Sample as an Obfuscation Technique<br/>
 <a href="https://isc.sans.edu/forums/diary/Very+Large+Sample+as+Evasion+Technique/25948/">https://isc.sans.edu/forums/diary/Very+Large+Sample+as+Evasion+Technique/25948/</a><br/>
iOS VPN Bypass<br/>
 <a href="https://protonvpn.com/blog/apple-ios-vulnerability-disclosure/">https://protonvpn.com/blog/apple-ios-vulnerability-disclosure/</a><br/>
Free Covid19 Domain List<br/>
 <a href="https://www.domaintools.com/resources/blog/free-covid-19-threat-list-domain-risk-assessments-for-coronavirus-threats">https://www.domaintools.com/resources/blog/free-covid-19-threat-list-domain-risk-assessments-for-coronavirus-threats</a><br/>
Linux Rubber Ducky Protection<br/>
 <a href="https://opensource.googleblog.com/2020/03/usb-keystroke-injection-protection.html">https://opensource.googleblog.com/2020/03/usb-keystroke-injection-protection.html</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6928" type="text/plain" language="en" />
<itunes:keywords>rubber ducky, usb, keyboard, covid19, domains, domaintools, ios, vpn, protonvpn, obfuscation, size, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 26th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6926</itunes:episode>
<itunes:subtitle>Dridex Update; Covid-19 Ransom; HPE 40,000 hrs; Fake Google Updates; Trickbot
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dridex Update; Covid-19 Ransom; HPE 40,000 hrs; Fake Google Updates; Trickbot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6926.mp3" length="4533180" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6926.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6926</link>
<pubDate>Thu, 26 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Dridex Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Recent+Dridex+activity/25944/">https://isc.sans.edu/forums/diary/Recent+Dridex+activity/25944/</a><br/>
Covid-19 Ransom<br/>
 <a href="https://twitter.com/johullrich/status/1242983197555789824">https://twitter.com/johullrich/status/1242983197555789824</a><br/>
HP Enterprise SSD Firmware Bug<br/>
 <a href="https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00097382en_us">https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00097382en_us</a><br/>
Fake Google Chrome Update <br/>
 <a href="https://news.drweb.com/show/?i=13746&lng=en">https://news.drweb.com/show/?i=13746&lng=en</a><br/>
TrickBot Pushing a 2FA Bypass App in Germany<br/>
 <a href="https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/">https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6926" type="text/plain" language="en" />
<itunes:keywords>covid19, ransom, dridex, chrome, fake update, trickbot, trickmo, 2fa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 25th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6924</itunes:episode>
<itunes:subtitle>Type 1 Font Parsing Update; memcached dos; Adobe Patches; Apple Patches; OpenWRT
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Type 1 Font Parsing Update; memcached dos; Adobe Patches; Apple Patches; OpenWRT
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6924.mp3" length="4755172" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6924.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6924</link>
<pubDate>Wed, 25 Mar 2020 03:00:04 GMT</pubDate>
<description><![CDATA[Updated Microsoft Advisory 200006 <br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/adv200006">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/adv200006</a><br/>
Memcached Denial of Service Vulnerability<br/>
 <a href="https://github.com/memcached/memcached/issues/629">https://github.com/memcached/memcached/issues/629</a><br/>
Adobe Creative Cloud Desktop Application Patches<br/>
 <a href="https://helpx.adobe.com/security/products/creative-cloud/apsb20-11.html">https://helpx.adobe.com/security/products/creative-cloud/apsb20-11.html</a><br/>
Microsoft Pausing Cumulative Updates Starting May<br/>
 <a href="https://docs.microsoft.com/en-us/windows/release-information/windows-message-center#405">https://docs.microsoft.com/en-us/windows/release-information/windows-message-center#405</a><br/>
Apple Security Patches<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
OpenWRT Vulnerability Fixed<br/>
 <a href="https://thehackernews.com/2020/03/openwrt-rce-vulnerability.html">https://thehackernews.com/2020/03/openwrt-rce-vulnerability.html</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6924" type="text/plain" language="en" />
<itunes:keywords>openwrt, sha256, opkg, microsoft, adobe, cloud, memcached, apple, macos, ios, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6922</itunes:episode>
<itunes:subtitle>Windows Font Parsing 0-Day; Covid-19 Malware Summary; Firefox Turning TLS 1.0 Back on
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Font Parsing 0-Day; Covid-19 Malware Summary; Firefox Turning TLS 1.0 Back on
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6922.mp3" length="5057244" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6922.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6922</link>
<pubDate>Tue, 24 Mar 2020 03:00:04 GMT</pubDate>
<description><![CDATA[Windows Font Parsing 0-Day<br/>
 <a href="https://isc.sans.edu/forums/diary/Windows+Zeroday+Actively+Exploited+Type+1+Font+Parsing+Remote+Code+Execution+Vulnerability/25936/">https://isc.sans.edu/forums/diary/Windows+Zeroday+Actively+Exploited+Type+1+Font+Parsing+Remote+Code+Execution+Vulnerability/25936/</a><br/>
Covid-19 Malware Summary<br/>
 <a href="https://github.com/parthdmaniar/coronavirus-covid-19-SARS-CoV-2-IoCs">https://github.com/parthdmaniar/coronavirus-covid-19-SARS-CoV-2-IoCs</a><br/>
Firefox Turns TLS 1.0/1.1 Back on<br/>
 <a href="https://www.mozilla.org/en-US/firefox/74.0/releasenotes/">https://www.mozilla.org/en-US/firefox/74.0/releasenotes/</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6922" type="text/plain" language="en" />
<itunes:keywords>firefox, tls, covid-19, malware, windows, 0-day, font parsing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6920</itunes:episode>
<itunes:subtitle>More Covid19 Malware; Kr00k Exploit; Pwn2Own Results
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Covid19 Malware; Kr00k Exploit; Pwn2Own Results
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6920.mp3" length="5622635" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6920.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6920</link>
<pubDate>Mon, 23 Mar 2020 03:00:04 GMT</pubDate>
<description><![CDATA[More Covid19 Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/More+COVID19+Themed+Malware/25930/">https://isc.sans.edu/forums/diary/More+COVID19+Themed+Malware/25930/</a><br/>
Working Exploit for the Kr00k Wifi Exploit<br/>
 <a href="https://hexway.io/research/r00kie-kr00kie/">https://hexway.io/research/r00kie-kr00kie/</a><br/>
ZDI Pwn2Own Results<br/>
 <a href="https://www.zerodayinitiative.com/blog/2020/3/17/welcome-to-pwn2own-2020-the-schedule-and-live-results">https://www.zerodayinitiative.com/blog/2020/3/17/welcome-to-pwn2own-2020-the-schedule-and-live-results</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6920" type="text/plain" language="en" />
<itunes:keywords>macos, safari, windows, zdi, cansecwest, pwn2own, kr00k, exploit, covid19, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6918</itunes:episode>
<itunes:subtitle>More COVID-19 Malware; Cisco Patches; LDAPFragger
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More COVID-19 Malware; Cisco Patches; LDAPFragger
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6918.mp3" length="4339709" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6918.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6918</link>
<pubDate>Fri, 20 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[COVID-19 Themed Multistage Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/COVID19+Themed+Multistage+Malware/25922/">https://isc.sans.edu/forums/diary/COVID19+Themed+Multistage+Malware/25922/</a><br/>
Cisco SD-WAN Patches<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
oPatch Selling Patches for Windows 7<br/>
 <a href="https://twitter.com/0patch/status/1240602635205586945">https://twitter.com/0patch/status/1240602635205586945</a><br/>
LDAPFragger: Bypassing network restrictions using LDAP attributes<br/>
 <a href="https://research.nccgroup.com/2020/03/19/ldapfragger-bypassing-network-restrictions-using-ldap-attributes/">https://research.nccgroup.com/2020/03/19/ldapfragger-bypassing-network-restrictions-using-ldap-attributes/</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6918" type="text/plain" language="en" />
<itunes:keywords>covid19, malware, word, opatch, windows 7, cisco, sd-wan, ldapfragger, ldap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 19th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6916</itunes:episode>
<itunes:subtitle>TrendMicro Update; More VMWare Updates; Ransomware Trends; EnigmaSpark
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TrendMicro Update; More VMWare Updates; Ransomware Trends; EnigmaSpark
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6916.mp3" length="5146117" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6916.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6916</link>
<pubDate>Thu, 19 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[TrendMicro Update<br/>
 <a href="https://success.trendmicro.com/solution/000245571">https://success.trendmicro.com/solution/000245571</a><br/>
More VMWare Updates<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0005.html">https://www.vmware.com/security/advisories/VMSA-2020-0005.html</a><br/>
EnigmaSpark Malware<br/>
 <a href="https://securityintelligence.com/posts/EnigmaSpark-Politically-Themed-Cyber-Activity-Highlights-Regional-Opposition-to-Middle-East-Peace-Plan/">https://securityintelligence.com/posts/EnigmaSpark-Politically-Themed-Cyber-Activity-Highlights-Regional-Opposition-to-Middle-East-Peace-Plan/</a><br/>
Recent Ransomware Trends<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2020/03/they-come-in-the-night-ransomware-deployment-trends.html">https://www.fireeye.com/blog/threat-research/2020/03/they-come-in-the-night-ransomware-deployment-trends.html</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6916" type="text/plain" language="en" />
<itunes:keywords>ransomware, enigmaspark, vmware, trendmicro, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6914</itunes:episode>
<itunes:subtitle>DDoS Summary; Trickbot Update; Is Cryptojacking Dead? Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DDoS Summary; Trickbot Update; Is Cryptojacking Dead? Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6914.mp3" length="6516452" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6914.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6914</link>
<pubDate>Wed, 18 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[A Quick Summary of Current Reflective DNS DDoS Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Quick+Summary+of+Current+Reflective+DNS+DDoS+Attacks/25916/">https://isc.sans.edu/forums/diary/A+Quick+Summary+of+Current+Reflective+DNS+DDoS+Attacks/25916/</a><br/>
Trickbot gtag red5 distributed as DLL File<br/>
 <a href="https://isc.sans.edu/forums/diary/Trickbot+gtag+red5+distributed+as+a+DLL+file/25918/">https://isc.sans.edu/forums/diary/Trickbot+gtag+red5+distributed+as+a+DLL+file/25918/</a><br/>
Is Cryptojacking Dead after Coinhive Shutdown<br/>
 <a href="https://arxiv.org/pdf/2001.02975.pdf">https://arxiv.org/pdf/2001.02975.pdf</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb20-13.html">https://helpx.adobe.com/security/products/acrobat/apsb20-13.html</a><br/>
]]></description>
<itunes:duration>7:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6914" type="text/plain" language="en" />
<itunes:keywords>adobe, flash, acrobat, cryptojacking, coinhive, trickbot, dns, ddos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6912</itunes:episode>
<itunes:subtitle>Desktop.ini Tricks; VMWare Update; tcpdump bug PoC; Slack account takeover
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Desktop.ini Tricks; VMWare Update; tcpdump bug PoC; Slack account takeover
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6912.mp3" length="4938021" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6912.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6912</link>
<pubDate>Tue, 17 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Desktop.ini as a post-exploitation tool<br/>
 <a href="https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/">https://isc.sans.edu/forums/diary/Desktopini+as+a+postexploitation+tool/25912/</a><br/>
VMWAre Workstatation/Fusion Update<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2020-0004.html">https://www.vmware.com/security/advisories/VMSA-2020-0004.html</a><br/>
Blackwater Malware Abuses Cloudflare Workers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/blackwater-malware-abuses-cloudflare-workers-for-c2-communication/">https://www.bleepingcomputer.com/news/security/blackwater-malware-abuses-cloudflare-workers-for-c2-communication/</a><br/>
tcpdump Heap Based Buffer Over-Read<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19325">https://nvd.nist.gov/vuln/detail/CVE-2018-19325</a><br/>
Slack Account Takevoer Bug<br/>
 <a href="https://hackerone.com/reports/737140">https://hackerone.com/reports/737140</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6912" type="text/plain" language="en" />
<itunes:keywords>slack, tcpdump, blackwater, vmware, desktop.ini, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6910</itunes:episode>
<itunes:subtitle>Incremental Malicious PDFs; VPN Limits; Capturing Runts; Cooiethief; SANS Woring from Home Deployment Kit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Incremental Malicious PDFs; VPN Limits; Capturing Runts; Cooiethief; SANS Woring from Home Deployment Kit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6910.mp3" length="5785377" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6910.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6910</link>
<pubDate>Mon, 16 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Phishing PDFs With Incremental Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+PDF+With+Incremental+Updates/25904/">https://isc.sans.edu/forums/diary/Phishing+PDF+With+Incremental+Updates/25904/</a><br/>
VPN Access and Active Monitoring<br/>
 <a href="https://isc.sans.edu/forums/diary/VPN+Access+and+Activity+Monitoring/25906/">https://isc.sans.edu/forums/diary/VPN+Access+and+Activity+Monitoring/25906/</a><br/>
Capturing Invalid Ethernet Frames<br/>
 <a href="https://isc.sans.edu/forums/diary/Not+all+Ethernet+NICs+are+Created+Equal+Trying+to+Capture+Invalid+Ethernet+Frames/25896/">https://isc.sans.edu/forums/diary/Not+all+Ethernet+NICs+are+Created+Equal+Trying+to+Capture+Invalid+Ethernet+Frames/25896/</a><br/>
Cookiethief Android Cookie Stealing Malware<br/>
 <a href="https://securelist.com/cookiethief/96332/">https://securelist.com/cookiethief/96332/</a><br/>
SANS Security Awareness Deployment Kit for Securing Your Workforce at Home<br/>
 <a href="https://www.sans.org/webcasts/113875">https://www.sans.org/webcasts/113875</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6910" type="text/plain" language="en" />
<itunes:keywords>working from home, deploymnet kit, cookiethief, runts, invalid frames, vpn access, phishing, pdfs, incremental updates, pirates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6908</itunes:episode>
<itunes:subtitle>Windows SMBv3 Patch; Coronavirus Hancitor; Avast ditches JS; Checkra1n vs T2
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows SMBv3 Patch; Coronavirus Hancitor; Avast ditches JS; Checkra1n vs T2
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6908.mp3" length="5718086" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6908.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6908</link>
<pubDate>Fri, 13 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Releases Patch for Windows SMBv3 Compression Vulnerability CVE-2020-0796<br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796</a><br/>
Hancitor Distributed Through Coronavirus-Themed Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+distributed+through+coronavirusthemed+malspam/25892/">https://isc.sans.edu/forums/diary/Hancitor+distributed+through+coronavirusthemed+malspam/25892/</a><br/>
Avast Removes Vulnerable JavaScript Emulator From Products<br/>
 <a href="https://github.com/taviso/avscript">https://github.com/taviso/avscript</a><br/>
Checkra1n Exploit Works Against T2 Equipped Macs<br/>
 <a href="https://www.idownloadblog.com/2020/03/10/luca-todesco-teases-checkra1n-hacks-on-a-t2-equipped-macbook-pros-touch-bar/">https://www.idownloadblog.com/2020/03/10/luca-todesco-teases-checkra1n-hacks-on-a-t2-equipped-macbook-pros-touch-bar/</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6908" type="text/plain" language="en" />
<itunes:keywords>checkra1n, t2, macbook, apple, avast, javascript, taviso, hancitor, coronavirus, covid19, smbv3, cve-2020-0796, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 12th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6906</itunes:episode>
<itunes:subtitle>Mystery SMB3 Flaw Update; COVID19 Malware; Agent Tesla Canon EOS Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mystery SMB3 Flaw Update; COVID19 Malware; Agent Tesla Canon EOS Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6906.mp3" length="4844403" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6906.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6906</link>
<pubDate>Thu, 12 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Mystery SMB3 Flaw Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Critical+SMBv3+Vulnerability+Remote+Code+Execution/25890/">https://isc.sans.edu/forums/diary/Critical+SMBv3+Vulnerability+Remote+Code+Execution/25890/</a><br/>
COVID19 Malware<br/>
 <a href="https://blog.reasonsecurity.com/2020/03/09/covid-19-info-stealer-the-map-of-threats-threat-analysis-report/">https://blog.reasonsecurity.com/2020/03/09/covid-19-info-stealer-the-map-of-threats-threat-analysis-report/</a><br/>
Agent Tesla Spread by Fake Canon EOS Notification Email<br/>
 <a href="https://isc.sans.edu/forums/diary/Agent+Tesla+Delivered+via+Fake+Canon+EOS+Notification+on+Free+OwnCloud+Account/25884/">https://isc.sans.edu/forums/diary/Agent+Tesla+Delivered+via+Fake+Canon+EOS+Notification+on+Free+OwnCloud+Account/25884/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6906" type="text/plain" language="en" />
<itunes:keywords>agent tesla, corona, malware, smb3, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6904</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday and SMB3 Mystery Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday and SMB3 Mystery Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6904.mp3" length="4448338" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6904.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6904</link>
<pubDate>Wed, 11 Mar 2020 00:15:54 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200005">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200005</a><br/>
 <a href="https://isc.sans.edu/diary.html?storyid=25886">https://isc.sans.edu/diary.html?storyid=25886</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6904" type="text/plain" language="en" />
<itunes:keywords>microsoft, smb3, vulnerability, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6902</itunes:episode>
<itunes:subtitle>Self Modifying Excel 4 Macro; AMD Take a Way (or not); Google Play Protect Fail
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Self Modifying Excel 4 Macro; AMD Take a Way (or not); Google Play Protect Fail
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6902.mp3" length="5682981" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6902.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6902</link>
<pubDate>Tue, 10 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Malicious Spreadsheet With Data Connection and Excel 4 Macros<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Spreadsheet+With+Data+Connection+and+Excel+4+Macros/25880/">https://isc.sans.edu/forums/diary/Malicious+Spreadsheet+With+Data+Connection+and+Excel+4+Macros/25880/</a><br/>
Take a Way: Exploring the Security Implications of AMD's Cache Way Predictors<br/>
 <a href="https://mlq.me/download/takeaway.pdf">https://mlq.me/download/takeaway.pdf</a><br/>
 <a href="https://www.amd.com/en/corporate/product-security">https://www.amd.com/en/corporate/product-security</a><br/>
Google Play Store Protect Fails Security Test<br/>
 <a href="https://www.av-test.org/en/news/here-s-how-well-17-android-security-apps-provide-protection/">https://www.av-test.org/en/news/here-s-how-well-17-android-security-apps-provide-protection/</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6902" type="text/plain" language="en" />
<itunes:keywords>google play, protect, take a way, amd, cache, side channel, spreadsheet, excel, macros, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6900</itunes:episode>
<itunes:subtitle>Excel Very Hidden; Wireshark; Linux PPP; NordVPN; Android Unpatched
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Excel Very Hidden; Wireshark; Linux PPP; NordVPN; Android Unpatched
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6900.mp3" length="4628257" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6900.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6900</link>
<pubDate>Mon, 09 Mar 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Excel Maldocs: Hidden Sheets<br/>
 <a href="https://isc.sans.edu/forums/diary/Excel+Maldocs+Hidden+Sheets/25876/">https://isc.sans.edu/forums/diary/Excel+Maldocs+Hidden+Sheets/25876/</a><br/>
Wireshark 3.2.2. Released<br/>
 <a href="https://www.wireshark.org/docs/relnotes/wireshark-3.2.2.html">https://www.wireshark.org/docs/relnotes/wireshark-3.2.2.html</a><br/>
Linux PPP Vulnerability<br/>
 <a href="https://www.kb.cert.org/vuls/id/782301/">https://www.kb.cert.org/vuls/id/782301/</a><br/>
NordVPN Vulnerablity<br/>
 <a href="https://www.theregister.co.uk/2020/03/06/nordvpn_no_auth_needed_view_user_payments/">https://www.theregister.co.uk/2020/03/06/nordvpn_no_auth_needed_view_user_payments/</a><br/>
Unpatched Android Devices<br/>
 <a href="https://www.which.co.uk/news/2020/03/more-than-one-billion-android-devices-at-risk-of-malware-threats/">https://www.which.co.uk/news/2020/03/more-than-one-billion-android-devices-at-risk-of-malware-threats/</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6900" type="text/plain" language="en" />
<itunes:keywords>android, patches, nordvpn, ppp, linux, wireshark, excel, hidden, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6898</itunes:episode>
<itunes:subtitle>Survey Phish; Not a Corona Phish; Loss of Trust; Revocation Stop @certifygiac
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Survey Phish; Not a Corona Phish; Loss of Trust; Revocation Stop @certifygiac
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6898.mp3" length="5263869" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6898.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6898</link>
<pubDate>Fri, 06 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Survey Phish<br/>
 <a href="https://isc.sans.edu/forums/diary/Will+You+Put+Your+Password+in+a+Survey/25866/">https://isc.sans.edu/forums/diary/Will+You+Put+Your+Password+in+a+Survey/25866/</a><br/>
Healthcare.gov Sending E-Mail Looking Like Phishing<br/>
 <a href="https://twitter.com/johullrich/status/1235740586717720577">https://twitter.com/johullrich/status/1235740586717720577</a><br/>
Intel x86 Root of Trust: Loss of Trust<br/>
 <a href="https://blog.ptsecurity.com/2020/03/intelx86-root-of-trust-loss-of-trust.html">https://blog.ptsecurity.com/2020/03/intelx86-root-of-trust-loss-of-trust.html</a><br/>
Let's Encrypt Revises Revokation Plan<br/>
 <a href="https://community.letsencrypt.org/t/2020-02-29-caa-rechecking-bug/114591/2">https://community.letsencrypt.org/t/2020-02-29-caa-rechecking-bug/114591/2</a><br/>
Trust Me, I'm Certified Podcast<br/>
 <a href="https://www.giac.org/podcasts">https://www.giac.org/podcasts</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6898" type="text/plain" language="en" />
<itunes:keywords>giac, certified, revokation, letsencrypt, intel, healthcare, coronavirus, survey, phish, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 5th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6896</itunes:episode>
<itunes:subtitle>MSFT Subdomain Takeover; Not 0-Day Homoglyphs; Cornavirus Phish @JCyberSec
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Subdomain Takeover; Not 0-Day Homoglyphs; Cornavirus Phish @JCyberSec
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6896.mp3" length="5697980" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6896.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6896</link>
<pubDate>Thu, 05 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[MSFT Subdomain Takeover<br/>
 <a href="https://vullnerability.com/blog/microsoft-subdomain-account-takeover">https://vullnerability.com/blog/microsoft-subdomain-account-takeover</a><br/>
Homoglyph Attacks in the News Again<br/>
 <a href="https://www.soluble.ai/blog/public-disclosure-emoji-to-zero-day">https://www.soluble.ai/blog/public-disclosure-emoji-to-zero-day</a><br/>
Coronavirus Phish<br/>
 <a href="https://twitter.com/JCyberSec_/status/1234806881195044865">https://twitter.com/JCyberSec_/status/1234806881195044865</a><br/>
]]></description>
<itunes:duration>6:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6896" type="text/plain" language="en" />
<itunes:keywords>coronavirus, phish, homoglyphs, msft, subdomain, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6894</itunes:episode>
<itunes:subtitle>Event Explorer; Letsencrypt CAA Flaw; Smart Devices; Ransomware and Cloud
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Event Explorer; Letsencrypt CAA Flaw; Smart Devices; Ransomware and Cloud
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6894.mp3" length="5301184" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6894.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6894</link>
<pubDate>Wed, 04 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Introduction to EvtxEcmd (Evtx Explorer)<br/>
 <a href="https://isc.sans.edu/forums/diary/Introduction+to+EvtxEcmd+Evtx+Explorer/25858/">https://isc.sans.edu/forums/diary/Introduction+to+EvtxEcmd+Evtx+Explorer/25858/</a><br/>
Let's Encrypt Revoking Certificates<br/>
 <a href="https://community.letsencrypt.org/t/revoking-certain-certificates-on-march-4/114864">https://community.letsencrypt.org/t/revoking-certain-certificates-on-march-4/114864</a><br/>
Using Smart Devices in the Home Securely (NCSC Version)<br/>
 <a href="https://www.ncsc.gov.uk/guidance/smart-devices-in-the-home">https://www.ncsc.gov.uk/guidance/smart-devices-in-the-home</a><br/>
Ransomware and Cloud Backups<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ransomware-attackers-use-your-cloud-backups-against-you/">https://www.bleepingcomputer.com/news/security/ransomware-attackers-use-your-cloud-backups-against-you/</a><br/>
SANS Coronavirus Training Guarantee<br/>
 <a href="https://www.sans.org/training-guarantee">https://www.sans.org/training-guarantee</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6894" type="text/plain" language="en" />
<itunes:keywords>coronavirus, sans, ransomware, smart devices, ncsc, lets encrypt, caa, evtxecmd, event explorer, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6892</itunes:episode>
<itunes:subtitle>TLS vs Clear Distribution; Evasion Encyclopedia; Threat Dragon; Free SANS Stuff
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TLS vs Clear Distribution; Evasion Encyclopedia; Threat Dragon; Free SANS Stuff
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6892.mp3" length="4857930" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6892.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6892</link>
<pubDate>Tue, 03 Mar 2020 02:19:26 GMT</pubDate>
<description><![CDATA[SSL Distribution by Country<br/>
 <a href="https://isc.sans.edu/forums/diary/Secure+vs+cleartext+protocols+couple+of+interesting+stats/25854/">https://isc.sans.edu/forums/diary/Secure+vs+cleartext+protocols+couple+of+interesting+stats/25854/</a><br/>
Checkpoint Evasion Encyclopedia<br/>
 <a href="https://research.checkpoint.com/2020/cpr-evasion-encyclopedia-the-check-point-evasion-repository/">https://research.checkpoint.com/2020/cpr-evasion-encyclopedia-the-check-point-evasion-repository/</a><br/>
OWASP Threat Dragon<br/>
 <a href="https://github.com/mike-goodwin/owasp-threat-dragon-desktop">https://github.com/mike-goodwin/owasp-threat-dragon-desktop</a><br/>
SANS Free Things<br/>
 <a href="https://sans.org/free">https://sans.org/free</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6892" type="text/plain" language="en" />
<itunes:keywords>owasp, threat dragon, checkpoint, evasion, ssl, telnet, ssh, tls, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 2nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6890</itunes:episode>
<itunes:subtitle>Clipboard Leaks; Hazelcast; Microsoft Exchange; Tomcat
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Clipboard Leaks; Hazelcast; Microsoft Exchange; Tomcat
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6890.mp3" length="4289606" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6890.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6890</link>
<pubDate>Mon, 02 Mar 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Show me Your Clipboard Data!<br/>
 <a href="https://isc.sans.edu/forums/diary/Show+me+Your+Clipboard+Data/25846/">https://isc.sans.edu/forums/diary/Show+me+Your+Clipboard+Data/25846/</a><br/>
Hazelcast IMDB Discover Scan<br/>
 <a href="https://isc.sans.edu/forums/diary/Hazelcast+IMDG+Discover+Scan/25850/">https://isc.sans.edu/forums/diary/Hazelcast+IMDG+Discover+Scan/25850/</a><br/>
Microsoft Exchange Server Vulnerabilty Scans<br/>
 <a href="https://twitter.com/GossiTheDog/status/1232369036438233088">https://twitter.com/GossiTheDog/status/1232369036438233088</a><br/>
Tomcat Ghostcat Vulnerability<br/>
 <a href="https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E">https://lists.apache.org/thread.html/r7c6f492fbd39af34a68681dbbba0468490ff1a97a1bd79c6a53610ef%40%3Cannounce.tomcat.apache.org%3E</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6890" type="text/plain" language="en" />
<itunes:keywords>clipboard, vmware, ios, windows, powershell, imdb, hazelcast, exchange server, tomcat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6888</itunes:episode>
<itunes:subtitle>Ultrasonic Assistance; Browser Data Leakage; Cloud Snooper
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ultrasonic Assistance; Browser Data Leakage; Cloud Snooper
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6888.mp3" length="4672155" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6888.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6888</link>
<pubDate>Fri, 28 Feb 2020 04:50:02 GMT</pubDate>
<description><![CDATA[Ultrasonic Triggers for Cellphone Assistants.<br/>
 <a href="https://source.wustl.edu/2020/02/surfing-attack-hacks-siri-google-with-ultrasonic-waves/">https://source.wustl.edu/2020/02/surfing-attack-hacks-siri-google-with-ultrasonic-waves/</a><br/>
Comparing Information Leakage from Different Browsers<br/>
 <a href="https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf">https://www.scss.tcd.ie/Doug.Leith/pubs/browser_privacy.pdf</a><br/>
Cloud Snooper Attack<br/>
 <a href="https://news.sophos.com/en-us/2020/02/25/cloud-snooper-attack-bypasses-firewall-security-measures/">https://news.sophos.com/en-us/2020/02/25/cloud-snooper-attack-bypasses-firewall-security-measures/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6888" type="text/plain" language="en" />
<itunes:keywords>cloud snooper, firewall, browser, data leakage, yandex, brave, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6886</itunes:episode>
<itunes:subtitle>Kr00k WiFi Attack; Impersonating LTE USers; Zyxel RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kr00k WiFi Attack; Impersonating LTE USers; Zyxel RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6886.mp3" length="5718106" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6886.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6886</link>
<pubDate>Thu, 27 Feb 2020 04:55:03 GMT</pubDate>
<description><![CDATA[Kr00k WiFi Attack<br/>
 <a href="https://www.eset.com/int/kr00k/">https://www.eset.com/int/kr00k/</a><br/>
Impersonating LTE Users<br/>
 <a href="https://imp4gt-attacks.net/">https://imp4gt-attacks.net/</a><br/>
Zyxel RCE Vulnerablity<br/>
 <a href="https://www.kb.cert.org/vuls/id/498544/">https://www.kb.cert.org/vuls/id/498544/</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6886" type="text/plain" language="en" />
<itunes:keywords>zyxel, rce, lte, wifi, kr00k, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 26th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6884</itunes:episode>
<itunes:subtitle>Fraudulant Paypal Charges; New Chrome Release; FIDO2 for Hybrid Azure AD 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fraudulant Paypal Charges; New Chrome Release; FIDO2 for Hybrid Azure AD 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6884.mp3" length="4676556" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6884.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6884</link>
<pubDate>Wed, 26 Feb 2020 03:15:03 GMT</pubDate>
<description><![CDATA[Fraudulant Paypal Charges (links in German)<br/>
 <a href="https://twitter.com/iblueconnection/status/1232259071602044928">https://twitter.com/iblueconnection/status/1232259071602044928</a><br/>
 <a href="https://www.heise.de/security/meldung/Google-Pay-Luecke-in-virtuellen-Kreditkarten-erlaubt-unberechtigte-Abbuchungen-4667527.html">https://www.heise.de/security/meldung/Google-Pay-Luecke-in-virtuellen-Kreditkarten-erlaubt-unberechtigte-Abbuchungen-4667527.html</a><br/>
 <a href="https://stadt-bremerhaven.de/google-pay-virtuelle-paypal-kreditkarten-weisen-sicherheitsluecken-auf/">https://stadt-bremerhaven.de/google-pay-virtuelle-paypal-kreditkarten-weisen-sicherheitsluecken-auf/</a><br/>
Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html">https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html</a><br/>
Microsoft Public Preview For Azure AD Hybrid Environments<br/>
 <a href="https://techcommunity.microsoft.com/t5/azure-active-directory-identity/public-preview-of-azure-ad-support-for-fido2-security-keys-in/ba-p/1187929">https://techcommunity.microsoft.com/t5/azure-active-directory-identity/public-preview-of-azure-ad-support-for-fido2-security-keys-in/ba-p/1187929</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6884" type="text/plain" language="en" />
<itunes:keywords>azure, fido2, chrome, google, paypal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 25th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6882</itunes:episode>
<itunes:subtitle>ScrollToTextFragment Google Chrome; WhatsApp Invite Links @JordanWildon; OpenSMTPD again;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ScrollToTextFragment Google Chrome; WhatsApp Invite Links @JordanWildon; OpenSMTPD again;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6882.mp3" length="6117462" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6882.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6882</link>
<pubDate>Tue, 25 Feb 2020 03:00:02 GMT</pubDate>
<description><![CDATA[ScrollToTextFragment Privacy Concerns in Google Chrome 80<br/>
 <a href="https://github.com/WICG/ScrollToTextFragment/issues/76#issue-538137989">https://github.com/WICG/ScrollToTextFragment/issues/76#issue-538137989</a><br/>
 <a href="https://docs.google.com/document/d/1YHcl1-vE_ZnZ0kL2almeikAj2gkwCq8_5xwIae7PVik/edit#heading=h.uoiwg23pt0tx">https://docs.google.com/document/d/1YHcl1-vE_ZnZ0kL2almeikAj2gkwCq8_5xwIae7PVik/edit#heading=h.uoiwg23pt0tx</a><br/>
Another OpenSMTPD Vulnerability<br/>
 <a href="https://github.com/OpenSMTPD/OpenSMTPD/releases">https://github.com/OpenSMTPD/OpenSMTPD/releases</a><br/>
WhatsApp Group Invite Links in Search Engines<br/>
 <a href="https://twitter.com/JordanWildon/status/1230829082662842369">https://twitter.com/JordanWildon/status/1230829082662842369</a><br/>
]]></description>
<itunes:duration>7:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6882" type="text/plain" language="en" />
<itunes:keywords>whatsapp, invite links, search engines, opensmtpd, scrolltotextfragment, google, chrome, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6880</itunes:episode>
<itunes:subtitle>Excel Macros; VBScript Obfuscation; Letsencrypt; Google Play Malware; Google Warns of Edge
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Excel Macros; VBScript Obfuscation; Letsencrypt; Google Play Malware; Google Warns of Edge
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6880.mp3" length="5637275" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6880.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6880</link>
<pubDate>Mon, 24 Feb 2020 03:35:02 GMT</pubDate>
<description><![CDATA[Old Style Excel Macro Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+Excel+4+Macros+in+OOXML+Format/25830/">https://isc.sans.edu/forums/diary/Maldoc+Excel+4+Macros+in+OOXML+Format/25830/</a><br/>
Simple But Efficient VBScript Obfuscation<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+but+Efficient+VBScript+Obfuscation/25828/">https://isc.sans.edu/forums/diary/Simple+but+Efficient+VBScript+Obfuscation/25828/</a><br/>
Let's Encrypt Beefs Up Validation<br/>
 <a href="https://letsencrypt.org/2020/02/19/multi-perspective-validation.html">https://letsencrypt.org/2020/02/19/multi-perspective-validation.html</a><br/>
Google Play Store Joker / Clicken Malware<br/>
 <a href="https://research.checkpoint.com/2020/android-app-fraud-haken-clicker-and-joker-premium-dialer/">https://research.checkpoint.com/2020/android-app-fraud-haken-clicker-and-joker-premium-dialer/</a><br/>
Google Warns of Microsoft Edge<br/>
 <a href="https://www.heise.de/security/meldung/l-f-Google-findet-den-neuen-Edge-Browser-doof-und-unsicher-4665634.html">https://www.heise.de/security/meldung/l-f-Google-findet-den-neuen-Edge-Browser-doof-und-unsicher-4665634.html</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6880" type="text/plain" language="en" />
<itunes:keywords>google, microsoft, edge, play store, joker, clicken, letsencrypt, vbscript, excel, macro, obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6878</itunes:episode>
<itunes:subtitle>Whodat? Adobe/Cisco Patches; Apple Cert Validity; Finding Pythong re DoS @r2cdev 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Whodat? Adobe/Cisco Patches; Apple Cert Validity; Finding Pythong re DoS @r2cdev 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6878.mp3" length="5642395" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6878.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6878</link>
<pubDate>Fri, 21 Feb 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Enumerating Who "Owns" a Workstation for IR<br/>
 <a href="https://isc.sans.edu/forums/diary/Whodat+Enumerating+Who+owns+a+Workstation+for+IR/25822/">https://isc.sans.edu/forums/diary/Whodat+Enumerating+Who+owns+a+Workstation+for+IR/25822/</a><br/>
Special Update for Adobe After Effects and Media Encoder<br/>
 <a href="https://helpx.adobe.com/security/products/after_effects/apsb20-09.html">https://helpx.adobe.com/security/products/after_effects/apsb20-09.html</a><br/>
 <a href="https://helpx.adobe.com/security/products/media-encoder/apsb20-10.html">https://helpx.adobe.com/security/products/media-encoder/apsb20-10.html</a><br/>
Cisco Updates<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-on-prem-static-cred-sL8rDs8">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-on-prem-static-cred-sL8rDs8</a><br/>
Apple To No Longer Accept Certifcates as Valid that Exceed a Lifetime of 13 months<br/>
 <a href="https://www.theregister.co.uk/2020/02/20/apple_shorter_cert_lifetime/">https://www.theregister.co.uk/2020/02/20/apple_shorter_cert_lifetime/</a><br/>
Python ReDoS Bugs<br/>
 <a href="https://blog.r2c.dev/posts/finding-python-redos-bugs-at-scale-using-dlint-and-r2c/">https://blog.r2c.dev/posts/finding-python-redos-bugs-at-scale-using-dlint-and-r2c/</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6878" type="text/plain" language="en" />
<itunes:keywords>python, redos, dos, apple, certificates, cisco, patches, adobe, after effects, media encoder, ir, whodat, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6876</itunes:episode>
<itunes:subtitle>Sonicwall Vulns; SQL Server Exploit; Ransomware in CH; Unsigned Firmware @plopz0r
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sonicwall Vulns; SQL Server Exploit; Ransomware in CH; Unsigned Firmware @plopz0r
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6876.mp3" length="4857946" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6876.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6876</link>
<pubDate>Thu, 20 Feb 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Sonicwall Vulnerabilities<br/>
 <a href="https://psirt.global.sonicwall.com/vuln-list">https://psirt.global.sonicwall.com/vuln-list</a><br/>
 <a href="https://blog.scrt.ch/2020/02/11/sonicwall-sra-and-sma-vulnerabilties/">https://blog.scrt.ch/2020/02/11/sonicwall-sra-and-sma-vulnerabilties/</a><br/>
SQL Server RCE Exploit<br/>
 <a href="https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/">https://www.mdsec.co.uk/2020/02/cve-2020-0618-rce-in-sql-server-reporting-services-ssrs/</a><br/>
Ransomware in Switzerland<br/>
 <a href="https://www.melani.admin.ch/melani/en/home/dokumentation/newsletter/sicherheitsrisiko-durch-ransomware.html">https://www.melani.admin.ch/melani/en/home/dokumentation/newsletter/sicherheitsrisiko-durch-ransomware.html</a><br/>
Peripheral Vulnerabilities in Windows and Linux<br/>
 <a href="https://eclypsium.com/2020/2/18/unsigned-peripheral-firmware/">https://eclypsium.com/2020/2/18/unsigned-peripheral-firmware/</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6876" type="text/plain" language="en" />
<itunes:keywords>sonicwall, sql server, ransomware, switzerland, peripherals, firmware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 19th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6874</itunes:episode>
<itunes:subtitle>Discovering Files in Windows; Ring 2FA (and Nest); VPN Vulns; WordPress @hyp3rlinx 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Discovering Files in Windows; Ring 2FA (and Nest); VPN Vulns; WordPress @hyp3rlinx 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6874.mp3" length="61440" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6874.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6874</link>
<pubDate>Wed, 19 Feb 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Discovering Contents of Folders Without Permission<br/>
 <a href="https://isc.sans.edu/forums/diary/Discovering+contents+of+folders+in+Windows+without+permissions/25816/">https://isc.sans.edu/forums/diary/Discovering+contents+of+folders+in+Windows+without+permissions/25816/</a><br/>
Ring Enforces 2FA<br/>
 <a href="https://blog.ring.com/2020/02/18/extra-layers-of-security-and-control/">https://blog.ring.com/2020/02/18/extra-layers-of-security-and-control/</a><br/>
Iranian's finally discover VPN Vulnerabilities<br/>
 <a href="https://www.clearskysec.com/fox-kitten/">https://www.clearskysec.com/fox-kitten/</a><br/>
WordPress ThemeGrill Auth Bypass<br/>
 <a href="https://www.webarxsecurity.com/critical-issue-in-themegrill-demo-importer/">https://www.webarxsecurity.com/critical-issue-in-themegrill-demo-importer/</a><br/>
]]></description>
<itunes:duration>372</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6874" type="text/plain" language="en" />
<itunes:keywords>wordpress, themegrill, iran, vpn, citrix, ring, folders, permissions, windows, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 18th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6872</itunes:episode>
<itunes:subtitle>More Curl on Win; WHO Phishing; Malicious Chrome Extensions @bumblebreaches @crxpert
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Curl on Win; WHO Phishing; Malicious Chrome Extensions @bumblebreaches @crxpert
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6872.mp3" length="4784068" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6872.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6872</link>
<pubDate>Tue, 18 Feb 2020 03:00:02 GMT</pubDate>
<description><![CDATA[More about Curl on Windows<br/>
 <a href="https://isc.sans.edu/forums/diary/curl+and+SSPI/25812/">https://isc.sans.edu/forums/diary/curl+and+SSPI/25812/</a><br/>
WHO Warns of Coronavirus Phishing<br/>
 <a href="https://www.who.int/about/communications/cyber-security">https://www.who.int/about/communications/cyber-security</a><br/>
DUO Security / Google Identify Malicous Chrome Extensions<br/>
 <a href="https://duo.com/labs/research/crxcavator-malvertising-2020">https://duo.com/labs/research/crxcavator-malvertising-2020</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6872" type="text/plain" language="en" />
<itunes:keywords>duo, google, cisco, chrome extensions, who, phishing, coronavirus, curl, windows, sspi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6870</itunes:episode>
<itunes:subtitle>Windows Command Line Browsers; KBOT Old Virus Tricks; OpenSSH Now With FIDO/U2F
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Command Line Browsers; KBOT Old Virus Tricks; OpenSSH Now With FIDO/U2F
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6870.mp3" length="4607058" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6870.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6870</link>
<pubDate>Mon, 17 Feb 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Keep an Eye on Command-Line Browsers<br/>
 <a href="https://isc.sans.edu/forums/diary/Keep+an+Eye+on+CommandLine+Browsers/25804/">https://isc.sans.edu/forums/diary/Keep+an+Eye+on+CommandLine+Browsers/25804/</a><br/>
Old Tricks in New Bots: KBOT<br/>
 <a href="https://securelist.com/kbot-sometimes-they-come-back/96157/">https://securelist.com/kbot-sometimes-they-come-back/96157/</a><br/>
OpenSSH Now With Fido/U2F<br/>
 <a href="http://www.openssh.com/txt/release-8.2">http://www.openssh.com/txt/release-8.2</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6870" type="text/plain" language="en" />
<itunes:keywords>openssh, kbot, command line browsers, curl, wget, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6868</itunes:episode>
<itunes:subtitle>LDAP/AD Changes; SweynTooth BLE; Symantec EP Vuln; DNSSEC Key Signing Delay
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LDAP/AD Changes; SweynTooth BLE; Symantec EP Vuln; DNSSEC Key Signing Delay
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6868.mp3" length="5663607" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6868.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6868</link>
<pubDate>Fri, 14 Feb 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Changes to Microsoft LDAP/AD And How to Cope with them<br/>
 <a href="https://isc.sans.edu/forums/diary/Authmageddon+deferred+but+not+averted+Microsoft+LDAP+Changes+now+slated+for+Q3Q4+2020/25800/">https://isc.sans.edu/forums/diary/Authmageddon+deferred+but+not+averted+Microsoft+LDAP+Changes+now+slated+for+Q3Q4+2020/25800/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/March+Patch+Tuesday+is+Coming+the+LDAP+Changes+will+Change+Your+Life/25796/">https://isc.sans.edu/forums/diary/March+Patch+Tuesday+is+Coming+the+LDAP+Changes+will+Change+Your+Life/25796/</a><br/>
SweynTooth BLE Vulnerabilities<br/>
 <a href="https://asset-group.github.io/disclosures/sweyntooth/">https://asset-group.github.io/disclosures/sweyntooth/</a><br/>
Symantec Endpoint Protection Multiple Issues<br/>
 <a href="https://support.symantec.com/us/en/article.SYMSA1505.html">https://support.symantec.com/us/en/article.SYMSA1505.html</a><br/>
DNSSEC Root Key Signing Ceremony Delayed<br/>
 <a href="https://mm.icann.org/pipermail/root-dnssec-announce/2020/000121.html">https://mm.icann.org/pipermail/root-dnssec-announce/2020/000121.html</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6868" type="text/plain" language="en" />
<itunes:keywords>dnssec, symantec, sweyntooth, bluetoth, ble, ldap, ldaps, microsoft, ad, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6866</itunes:episode>
<itunes:subtitle>Latest ursniff sightings; Safe Documents; Wordpress GDPR Cookie Again; Apple Joins FIDO2 @fidoalliance
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Latest ursniff sightings; Safe Documents; Wordpress GDPR Cookie Again; Apple Joins FIDO2 @fidoalliance
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6866.mp3" length="5090906" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6866.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6866</link>
<pubDate>Thu, 13 Feb 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Malspam Pushes Ursnif<br/>
 <a href="https://isc.sans.edu/forums/diary/Malpsam+pushes+Ursnif+through+Italian+language+Word+docs/25792/">https://isc.sans.edu/forums/diary/Malpsam+pushes+Ursnif+through+Italian+language+Word+docs/25792/</a><br/>
Safe Documents in Office 365 Advanced Threat Protection<br/>
 <a href="https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/safe-docs">https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/safe-docs</a><br/>
Wordpress GDPR Cookie Consent Plugin Vulnerability<br/>
 <a href="https://blog.nintechnet.com/wordpress-gdpr-cookie-consent-plugin-fixed-vulnerability/">https://blog.nintechnet.com/wordpress-gdpr-cookie-consent-plugin-fixed-vulnerability/</a><br/>
Apple Joins Fido Alliance<br/>
 <a href="https://fidoalliance.org/members/">https://fidoalliance.org/members/</a><br/>
 <a href="https://research.kudelskisecurity.com/2020/02/12/fido2-deep-dive-attestations-trust-model-and-security/">https://research.kudelskisecurity.com/2020/02/12/fido2-deep-dive-attestations-trust-model-and-security/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6866" type="text/plain" language="en" />
<itunes:keywords>fido2, webauthn, wordpress, gdpr, office 365, safe documents, ursnif, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 12th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6864</itunes:episode>
<itunes:subtitle>Microsoft/Adobe Patches; Ransomware Abuses Vulnerable Driver
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft/Adobe Patches; Ransomware Abuses Vulnerable Driver
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6864.mp3" length="196255" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6864.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6864</link>
<pubDate>Wed, 12 Feb 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+for+February+2020/25790/">https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+for+February+2020/25790/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Ransomware Abuses Out of Date Driver<br/>
 <a href="https://news.sophos.com/en-us/2020/02/06/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software/">https://news.sophos.com/en-us/2020/02/06/living-off-another-land-ransomware-borrows-vulnerable-driver-to-remove-security-software/</a><br/>
]]></description>
<itunes:duration>1335</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6864" type="text/plain" language="en" />
<itunes:keywords>ransomware, adobe, gigabyte, drivers, robinhood, microsoft, patch Tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 11th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6862</itunes:episode>
<itunes:subtitle>Greedy Paypal Phish; SupportAssist Vuln; Lock My PC Scam; Docker Registries @unit42_intel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Greedy Paypal Phish; SupportAssist Vuln; Lock My PC Scam; Docker Registries @unit42_intel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6862.mp3" length="5376891" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6862.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6862</link>
<pubDate>Tue, 11 Feb 2020 03:05:03 GMT</pubDate>
<description><![CDATA[Paypal Phish is Asking for Everything<br/>
 <a href="https://isc.sans.edu/forums/diary/Current+PayPal+phishing+campaign+or+give+me+all+your+personal+information/25786/">https://isc.sans.edu/forums/diary/Current+PayPal+phishing+campaign+or+give+me+all+your+personal+information/25786/</a><br/>
Dell SupportAssist Client Uncontrolled Search Patch Vulnerability<br/>
 <a href="https://www.dell.com/support/article/ro/ro/robsdt1/sln320101/dsa-2020-005-dell-supportassist-client-uncontrolled-search-path-vulnerability?lang=en">https://www.dell.com/support/article/ro/ro/robsdt1/sln320101/dsa-2020-005-dell-supportassist-client-uncontrolled-search-path-vulnerability?lang=en</a><br/>
Lock My PC Used By Support Scammers<br/>
 <a href="https://fspro.net/lock-pc/">https://fspro.net/lock-pc/</a><br/>
 <a href="https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/">https://www.bleepingcomputer.com/news/security/lock-my-pc-used-by-tech-support-scammers-dev-offers-free-recovery/</a><br/>
Insecure Docker Registries<br/>
 <a href="https://unit42.paloaltonetworks.com/leaked-docker-code/">https://unit42.paloaltonetworks.com/leaked-docker-code/</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6862" type="text/plain" language="en" />
<itunes:keywords>docker, lock my pc, support scammers, paypal, dell, support assisst, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6860</itunes:episode>
<itunes:subtitle>Sandbox Detection; Emotet Wifi Spreader; Sudo Exploit; HiSilicon Vuln @censysio
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sandbox Detection; Emotet Wifi Spreader; Sudo Exploit; HiSilicon Vuln @censysio
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6860.mp3" length="5493184" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6860.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6860</link>
<pubDate>Mon, 10 Feb 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Sandbox Detection Tricks and Nice Obfuscation in a Single VBScript<br/>
 <a href="https://isc.sans.edu/forums/diary/Sandbox+Detection+Tricks+Nice+Obfuscation+in+a+Single+VBScript/25780/">https://isc.sans.edu/forums/diary/Sandbox+Detection+Tricks+Nice+Obfuscation+in+a+Single+VBScript/25780/</a><br/>
Emotet Spreads via Wifi<br/>
 <a href="https://www.binarydefense.com/emotet-evolves-with-new-wi-fi-spreader/">https://www.binarydefense.com/emotet-evolves-with-new-wi-fi-spreader/</a><br/>
Exploit Available for sudo pwfeedback bug<br/>
 <a href="https://dylankatz.com/Analysis-of-CVE-2019-18634/">https://dylankatz.com/Analysis-of-CVE-2019-18634/</a><br/>
xiongmail/hisilicon Vulnerability<br/>
 <a href="https://censys.io/blog/probing-the-xiongmai-hisilicon-soc-vulnerability">https://censys.io/blog/probing-the-xiongmai-hisilicon-soc-vulnerability</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6860" type="text/plain" language="en" />
<itunes:keywords>hisilicon, tcp 9350, pwfeedback, sudo, emotet, wifi, sandbox, vbscript, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6858</itunes:episode>
<itunes:subtitle>Android Bluetooth Vulnerability; Wacom Privacy Issues; Bitbucket Malware; Realtek Driver Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Android Bluetooth Vulnerability; Wacom Privacy Issues; Bitbucket Malware; Realtek Driver Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6858.mp3" length="4722624" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6858.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6858</link>
<pubDate>Fri, 07 Feb 2020 03:55:02 GMT</pubDate>
<description><![CDATA[Criticial Bluetooth Vulnerability in Android (CVE-2020-0022)<br/>
 <a href="https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022/">https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022/</a><br/>
Wacom Tablets Reports Application Details to Google<br/>
 <a href="https://robertheaton.com/2020/02/05/wacom-drawing-tablets-track-name-of-every-application-you-open/">https://robertheaton.com/2020/02/05/wacom-drawing-tablets-track-name-of-every-application-you-open/</a><br/>
Bitbucket Delivers Malware<br/>
 <a href="https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware">https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware</a><br/>
Realtek HD Audio Driver Package DLL Preloading<br/>
 <a href="https://safebreach.com/Post/Realtek-HD-Audio-Driver-Package-DLL-Preloading-and-Potential-Abuses-CVE-2019-19705">https://safebreach.com/Post/Realtek-HD-Audio-Driver-Package-DLL-Preloading-and-Potential-Abuses-CVE-2019-19705</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6858" type="text/plain" language="en" />
<itunes:keywords>realtek, dll preloading, bitbucket, wacom, bluetooth, android, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6856</itunes:episode>
<itunes:subtitle>Fake Browser Updates; Android Update; Cisco CDP Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake Browser Updates; Android Update; Cisco CDP Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6856.mp3" length="4909877" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6856.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6856</link>
<pubDate>Thu, 06 Feb 2020 03:45:03 GMT</pubDate>
<description><![CDATA[Fake Browser Updates installing NetSupport RAT<br/>
 <a href="https://isc.sans.edu/forums/diary/Fake+browser+update+pages+are+still+a+thing/25774/">https://isc.sans.edu/forums/diary/Fake+browser+update+pages+are+still+a+thing/25774/</a><br/>
Google Android Update<br/>
 <a href="https://source.android.com/security/bulletin/2020-02-01#Google-Play-system-updates">https://source.android.com/security/bulletin/2020-02-01#Google-Play-system-updates</a><br/>
5 Cisco Vulnerabilities<br/>
 <a href="https://www.armis.com/cdpwn/">https://www.armis.com/cdpwn/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6856" type="text/plain" language="en" />
<itunes:keywords>cisco, cdp, google, android, updates, patches, fake browser, netsupport, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 5th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6854</itunes:episode>
<itunes:subtitle>Google Chrome 80; Whats App File Read Vuln; HiSilicon DVR
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Chrome 80; Whats App File Read Vuln; HiSilicon DVR
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6854.mp3" length="5269013" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6854.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6854</link>
<pubDate>Wed, 05 Feb 2020 03:00:04 GMT</pubDate>
<description><![CDATA[Google Chrome 80 Released<br/>
 <a href="https://www.chromium.org/updates/same-site">https://www.chromium.org/updates/same-site</a><br/>
 <a href="https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html</a><br/>
File Read Vulnerablity in WhatsApp<br/>
 <a href="https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html</a><br/>
HiSilicon DVR Backdoor<br/>
 <a href="https://habr.com/en/post/486856/">https://habr.com/en/post/486856/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6854" type="text/plain" language="en" />
<itunes:keywords>hisilicon, whatsapp, google chrome, update, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 4th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6852</itunes:episode>
<itunes:subtitle>AZORult Triple Crypt; Sudo pwfeedback;  Teamviewer Password Storage
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AZORult Triple Crypt; Sudo pwfeedback;  Teamviewer Password Storage
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6852.mp3" length="5642033" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6852.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6852</link>
<pubDate>Tue, 04 Feb 2020 03:00:04 GMT</pubDate>
<description><![CDATA[Triple Encrypted AZORult Installer<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+tripleencrypted+AZORult+downloader/25768/">https://isc.sans.edu/forums/diary/Analysis+of+a+tripleencrypted+AZORult+downloader/25768/</a><br/>
New sudo Vulnerability (pwfeedback) <br/>
 <a href="https://www.sudo.ws/alerts/pwfeedback.html">https://www.sudo.ws/alerts/pwfeedback.html</a><br/>
Teamviewer Password Storage<br/>
 <a href="https://whynotsecurity.com/blog/teamviewer/">https://whynotsecurity.com/blog/teamviewer/</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6852" type="text/plain" language="en" />
<itunes:keywords>teamviewer, sudo, pwfeedback, azorult, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6850</itunes:episode>
<itunes:subtitle>Stego &amp; Cryptominers; Cornavirus Scams; Google OpenSK
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Stego &amp; Cryptominers; Cornavirus Scams; Google OpenSK
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6850.mp3" length="5124909" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6850.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6850</link>
<pubDate>Mon, 03 Feb 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Stego and Cryptominers (with video)<br/>
 <a href="https://isc.sans.edu/forums/diary/Video+Stego+Cryptominers/25764/">https://isc.sans.edu/forums/diary/Video+Stego+Cryptominers/25764/</a><br/>
Corona Virus Phishing / Scams<br/>
 <a href="https://blog.knowbe4.com/heads-up-scam-of-the-week-coronavirus-phishing-attacks-in-the-wild?nCOV-2019-bc-index">https://blog.knowbe4.com/heads-up-scam-of-the-week-coronavirus-phishing-attacks-in-the-wild?nCOV-2019-bc-index</a><br/>
 <a href="https://twitter.com/briankrebs/status/1223959185764896768">https://twitter.com/briankrebs/status/1223959185764896768</a><br/>
Google Open Sources Security Token Software<br/>
 <a href="https://security.googleblog.com/2020/01/say-hello-to-opensk-fully-open-source.html">https://security.googleblog.com/2020/01/say-hello-to-opensk-fully-open-source.html</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6850" type="text/plain" language="en" />
<itunes:keywords>google, opensk, token, corona virus, phishing, scam, vaccine, stego, cryptominer, wav, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 31st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6848</itunes:episode>
<itunes:subtitle>Chrome Same-Site Cookie Change; Avast Apology; Magento Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chrome Same-Site Cookie Change; Avast Apology; Magento Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6848.mp3" length="8732311" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6848.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6848</link>
<pubDate>Fri, 31 Jan 2020 03:35:47 GMT</pubDate>
<description><![CDATA[Chrome Same-Site Cookie Change<br/>
 <a href="https://www.chromestatus.com/feature/5088147346030592">https://www.chromestatus.com/feature/5088147346030592</a><br/>
 <a href="https://docs.microsoft.com/en-us/office365/troubleshoot/miscellaneous/chrome-behavior-affects-applications">https://docs.microsoft.com/en-us/office365/troubleshoot/miscellaneous/chrome-behavior-affects-applications</a><br/>
 <a href="https://caniuse.com/#feat=same-site-cookie-attribute">https://caniuse.com/#feat=same-site-cookie-attribute</a><br/>
 <br/>
Avast Apology<br/>
 <a href="https://blog.avast.com/a-message-from-ceo-ondrej-vlcek">https://blog.avast.com/a-message-from-ceo-ondrej-vlcek</a><br/>
Magento Update<br/>
 <a href="https://helpx.adobe.com/security/products/magento/apsb20-02.html">https://helpx.adobe.com/security/products/magento/apsb20-02.html</a><br/>
]]></description>
<itunes:duration>10:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6848" type="text/plain" language="en" />
<itunes:keywords>magento, avast, chrome, same-site, cookies, privacy, federated identity, saml, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 30th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6846</itunes:episode>
<itunes:subtitle>Impeachment Malware; Coronavirus Malware; I Got Phished; OpenSMTPD Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Impeachment Malware; Coronavirus Malware; I Got Phished; OpenSMTPD Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6846.mp3" length="5525736" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6846.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6846</link>
<pubDate>Thu, 30 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Malware Using Text from Impeachment News Coverage<br/>
 <a href="https://www.bleepingcomputer.com/news/security/malware-tries-to-trump-security-software-with-potus-impeachment/">https://www.bleepingcomputer.com/news/security/malware-tries-to-trump-security-software-with-potus-impeachment/</a><br/>
Coronavirus Themed Malware Targets Japan with Emotet<br/>
 <a href="https://twitter.com/Cryptolaemus1/status/1222388971428294656">https://twitter.com/Cryptolaemus1/status/1222388971428294656</a><br/>
 <a href="https://exchange.xforce.ibmcloud.com/collection/18f373debc38779065a26f1958dc260b">https://exchange.xforce.ibmcloud.com/collection/18f373debc38779065a26f1958dc260b</a><br/>
abuse.ch Offers new "I got phished" service<br/>
 <a href="https://igotphished.abuse.ch/">https://igotphished.abuse.ch/</a><br/>
OpenSMTPD RCE Vulnerability<br/>
 <a href="https://www.openwall.com/lists/oss-security/2020/01/28/3">https://www.openwall.com/lists/oss-security/2020/01/28/3</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6846" type="text/plain" language="en" />
<itunes:keywords>opensmtpd, abuse.ch, i got phished, coronavirus, emotet, trickbot, impeachment, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 29th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6844</itunes:episode>
<itunes:subtitle>Emotet Update; Apple Update; Zoom; Intel Cacheout; Avast Sells Data
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Update; Apple Update; Zoom; Intel Cacheout; Avast Sells Data
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6844.mp3" length="4592803" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6844.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6844</link>
<pubDate>Wed, 29 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Recent Emotet Infection installs Trickbot<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+epoch+1+infection+with+Trickbot+gtag+mor84/25752/">https://isc.sans.edu/forums/diary/Emotet+epoch+1+infection+with+Trickbot+gtag+mor84/25752/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Zoom Fixes Video Conferencing Brute Forcing Vulnerability<br/>
 <a href="https://www.theregister.co.uk/2020/01/28/zoom_eavesdrop_hack/">https://www.theregister.co.uk/2020/01/28/zoom_eavesdrop_hack/</a><br/>
Intel Fixes Yet Another Information Leakage Flaw<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00329.html</a><br/>
 <a href="https://cacheoutattack.com/">https://cacheoutattack.com/</a><br/>
Avast Anti Virus Selling User's Browsing Data<br/>
 <a href="https://www.vice.com/en_us/article/qjdkq7/avast-antivirus-sells-user-browsing-data-investigation">https://www.vice.com/en_us/article/qjdkq7/avast-antivirus-sells-user-browsing-data-investigation</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6844" type="text/plain" language="en" />
<itunes:keywords>avast, apple, intel, cacheout, zoom, Trickbot, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 28th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6842</itunes:episode>
<itunes:subtitle>Coronavirus Preparedness; RD Gateway; Mitsubishi Compromise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Coronavirus Preparedness; RD Gateway; Mitsubishi Compromise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6842.mp3" length="3814555" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6842.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6842</link>
<pubDate>Tue, 28 Jan 2020 03:05:03 GMT</pubDate>
<description><![CDATA[Coronavirus Preparedness and Associated Scams<br/>
 <a href="https://isc.sans.edu/forums/diary/Network+Security+Perspective+on+Coronavirus+Preparedness/25750/">https://isc.sans.edu/forums/diary/Network+Security+Perspective+on+Coronavirus+Preparedness/25750/</a><br/>
RD Gateway RCE Exploit Demoed<br/>
 <a href="https://twitter.com/layle_ctf/status/1221514332049113095?s=12">https://twitter.com/layle_ctf/status/1221514332049113095?s=12</a><br/>
Mitsubishi Electric Compromised via Trend Micro Vulnerability<br/>
 <a href="http://www.mitsubishielectric.co.jp/news/2020/0120-b.pdf">http://www.mitsubishielectric.co.jp/news/2020/0120-b.pdf</a><br/>
 <a href="https://www.zdnet.com/article/trend-micro-antivirus-zero-day-used-in-mitsubishi-electric-hack/">https://www.zdnet.com/article/trend-micro-antivirus-zero-day-used-in-mitsubishi-electric-hack/</a><br/>
]]></description>
<itunes:duration>4:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6842" type="text/plain" language="en" />
<itunes:keywords>mitsubishi, trend micro, office scan, rd gateway, exploit, coronavirus, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 27th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6840</itunes:episode>
<itunes:subtitle>Citrix ADC Updates; Windows Fix Breaks Printer; GE Medical Devices
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix ADC Updates; Windows Fix Breaks Printer; GE Medical Devices
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6840.mp3" length="4916083" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6840.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6840</link>
<pubDate>Mon, 27 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Citrix Releases ADC Updates For All Versions<br/>
 <a href="https://www.citrix.com/blogs/2020/01/24/citrix-releases-final-fixes-for-cve-2019-19781/">https://www.citrix.com/blogs/2020/01/24/citrix-releases-final-fixes-for-cve-2019-19781/</a><br/>
Temporary Windows 0-Day Fix Breaks Printers<br/>
 <a href="https://www.reddit.com/r/sysadmin/comments/etumy7/microsoft_ie_zeroday_fix_breaks_hp_printing/">https://www.reddit.com/r/sysadmin/comments/etumy7/microsoft_ie_zeroday_fix_breaks_hp_printing/</a><br/>
Critical Vulnerabilitiesin GE Medical Devices<br/>
 <a href="https://www.us-cert.gov/ics/advisories/icsma-20-023-01">https://www.us-cert.gov/ics/advisories/icsma-20-023-01</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6840" type="text/plain" language="en" />
<itunes:keywords>citrix adc, citrix, ge medical, windows, explorer, printers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 24th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6838</itunes:episode>
<itunes:subtitle>Simple vs Complex Obfuscation; RD Gateway PoC; Citrix Scanner; LastPass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Simple vs Complex Obfuscation; RD Gateway PoC; Citrix Scanner; LastPass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6838.mp3" length="5976654" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6838.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6838</link>
<pubDate>Fri, 24 Jan 2020 03:20:02 GMT</pubDate>
<description><![CDATA[Simple vs. Complex Obfuscation<br/>
 <a href="https://isc.sans.edu/forums/diary/Complex+Obfuscation+VS+Simple+Trick/25738/">https://isc.sans.edu/forums/diary/Complex+Obfuscation+VS+Simple+Trick/25738/</a><br/>
RD Gateway PoC Exploit Release<br/>
 <a href="https://github.com/ollypwn/BlueGate">https://github.com/ollypwn/BlueGate</a><br/>
Citrix ADC Compromise Scanner<br/>
 <a href="https://github.com/citrix/ioc-scanner-CVE-2019-19781/">https://github.com/citrix/ioc-scanner-CVE-2019-19781/</a><br/>
LastPass Accidentially Removes Extension from Chrome Web Store<br/>
 <a href="https://twitter.com/LastPassStatus/status/1220122561989640192">https://twitter.com/LastPassStatus/status/1220122561989640192</a><br/>
]]></description>
<itunes:duration>7:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6838" type="text/plain" language="en" />
<itunes:keywords>lastpass, dos, citrix, fireeye, scanner, rd gateway, rdp, bluegate, obfuscation, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 23rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6836</itunes:episode>
<itunes:subtitle>German Malspam; Safari Tracking; Muhstik vs. Tomato; Cisco Firepower
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
German Malspam; Safari Tracking; Muhstik vs. Tomato; Cisco Firepower
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6836.mp3" length="4974971" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6836.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6836</link>
<pubDate>Thu, 23 Jan 2020 03:00:03 GMT</pubDate>
<description><![CDATA[German Malspam Pushing Ursnif<br/>
 <a href="https://isc.sans.edu/forums/diary/German+language+malspam+pushes+Ursnif/25732/">https://isc.sans.edu/forums/diary/German+language+malspam+pushes+Ursnif/25732/</a><br/>
Tracking Users Using Safari's Intelligent Tracking Prevention<br/>
 <a href="https://arxiv.org/pdf/2001.07421.pdf">https://arxiv.org/pdf/2001.07421.pdf</a><br/>
Muhstik Botnet Targeting Tomato Routers<br/>
 <a href="https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/">https://unit42.paloaltonetworks.com/muhstik-botnet-attacks-tomato-routers-to-harvest-new-iot-devices/</a><br/>
Cisco Firepower Management Center LDAP Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-fmc-auth">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200122-fmc-auth</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6836" type="text/plain" language="en" />
<itunes:keywords>cisco, muhstik, tomato, rotuers, firepower, tracking, safari, ursnif, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 22nd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6834</itunes:episode>
<itunes:subtitle>Blue ; EFS Ransomware; Fake Data Leak Compensation; Fake Job Site Scam
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Blue ; EFS Ransomware; Fake Data Leak Compensation; Fake Job Site Scam
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6834.mp3" length="5132597" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6834.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6834</link>
<pubDate>Wed, 22 Jan 2020 03:00:03 GMT</pubDate>
<description><![CDATA[DeepBlueCLI<br/>
 <a href="https://isc.sans.edu/forums/diary/DeepBlueCLI+Powershell+Threat+Hunting/25730/">https://isc.sans.edu/forums/diary/DeepBlueCLI+Powershell+Threat+Hunting/25730/</a><br/>
 <a href="https://github.com/sans-blue-team/DeepBlueCLI">https://github.com/sans-blue-team/DeepBlueCLI</a><br/>
EFS Ransomware<br/>
 <a href="https://safebreach.com/Post/EFS-Ransomware">https://safebreach.com/Post/EFS-Ransomware</a><br/>
Fake Leak Compensation<br/>
 <a href="https://www.kaspersky.com/blog/data-leak-compensation-scam/32057/">https://www.kaspersky.com/blog/data-leak-compensation-scam/32057/</a><br/>
Criminals Use Fake Job Sites to Defraud Victims<br/>
 <a href="https://www.ic3.gov/media/2020/200121.aspx">https://www.ic3.gov/media/2020/200121.aspx</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6834" type="text/plain" language="en" />
<itunes:keywords>compensation, job sites, efs, ransomware, deepblueclie, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 21st 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6832</itunes:episode>
<itunes:subtitle>Twist on Sextortion; Emotet Extortion Ruse; Lastpass Outage; Netgear Leaks Priv Key
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Twist on Sextortion; Emotet Extortion Ruse; Lastpass Outage; Netgear Leaks Priv Key
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6832.mp3" length="4852452" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6832.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6832</link>
<pubDate>Tue, 21 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Twist on Sextortion<br/>
 <a href="https://www.dailymail.co.uk/sciencetech/article-7886055/Sextortion-campaign-targets-users-Google-Nest-smart-camera.html">https://www.dailymail.co.uk/sciencetech/article-7886055/Sextortion-campaign-targets-users-Google-Nest-smart-camera.html</a><br/>
Emotet Uses Extortion to Infect Systems<br/>
 <a href="https://www.bleepingcomputer.com/news/security/emotet-malware-dabbles-in-extortion-with-new-spam-template/">https://www.bleepingcomputer.com/news/security/emotet-malware-dabbles-in-extortion-with-new-spam-template/</a><br/>
Lastpass Outage<br/>
 <a href="https://www.theregister.co.uk/2020/01/20/lastpass_outage/">https://www.theregister.co.uk/2020/01/20/lastpass_outage/</a><br/>
Netgear Signed TLS Cert Private Key Disclosure<br/>
 <a href="https://gist.github.com/nstarke/a611a19aab433555e91c656fe1f030a9">https://gist.github.com/nstarke/a611a19aab433555e91c656fe1f030a9</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6832" type="text/plain" language="en" />
<itunes:keywords>netgear, lastpass, emotet, sextortion, nest, camera, private key, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 20th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6830</itunes:episode>
<itunes:subtitle>MSFT Browser 0Day; Curveball and Citrix ADC Update #CitrixADC #Curveball
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Browser 0Day; Curveball and Citrix ADC Update #CitrixADC #Curveball
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6830.mp3" length="4629363" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6830.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6830</link>
<pubDate>Mon, 20 Jan 2020 04:40:02 GMT</pubDate>
<description><![CDATA[Microsoft Scripting Engine Memory Corruption Vulnerability<br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200001">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV200001</a><br/>
CVE-2020-0601 Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Summing+up+CVE20200601+or+the+Lets+Decrypt+vulnerability/25720/">https://isc.sans.edu/forums/diary/Summing+up+CVE20200601+or+the+Lets+Decrypt+vulnerability/25720/</a><br/>
Curveball Update<br/>
 <a href="https://www.citrix.com/blogs/2020/01/19/vulnerability-update-first-permanent-fixes-available-timeline-accelerated/">https://www.citrix.com/blogs/2020/01/19/vulnerability-update-first-permanent-fixes-available-timeline-accelerated/</a><br/>
 <a href="https://isc.sans.edu/diary//25724">https://isc.sans.edu/diary//25724</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6830" type="text/plain" language="en" />
<itunes:keywords>cve-2020-0601, shitrix, curveball, windows, internet explorer, jscript, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 17th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6828</itunes:episode>
<itunes:subtitle>CVE-2020-0601 Update; Citrix ADC Update; Cablehaunt; SecDevOps
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2020-0601 Update; Citrix ADC Update; Cablehaunt; SecDevOps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6828.mp3" length="12096151" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6828.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6828</link>
<pubDate>Fri, 17 Jan 2020 03:00:03 GMT</pubDate>
<description><![CDATA[CVE-2020-0601 Update ("Curveball" , "Letsdecrypt")<br/>
 <a href="https://isc.sans.edu/forums/diary/Summing+up+CVE20200601+or+the+Lets+Decrypt+vulnerability/25720/">https://isc.sans.edu/forums/diary/Summing+up+CVE20200601+or+the+Lets+Decrypt+vulnerability/25720/</a><br/>
 <a href="https://curveballtest.com">https://curveballtest.com</a><br/>
Certain Netscaler Devices Do Not Support Mitigation (article in dutch)<br/>
 <a href="https://www.ncsc.nl/actueel/nieuws/2020/januari/16/door-citrix-geadviseerde-mitigerende-maatregelen-niet-altijd-effectief">https://www.ncsc.nl/actueel/nieuws/2020/januari/16/door-citrix-geadviseerde-mitigerende-maatregelen-niet-altijd-effectief</a><br/>
Cable Haunt Vulnerability<br/>
 <a href="https://cablehaunt.com/">https://cablehaunt.com/</a><br/>
STI Student Interview: Jon Michael Lacek <br/>
 <a href="https://www.sans.org/reading-room/whitepapers/securecode/changing-devops-culture-security-scan-time-39125">https://www.sans.org/reading-room/whitepapers/securecode/changing-devops-culture-security-scan-time-39125</a><br/>
]]></description>
<itunes:duration>14:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6828" type="text/plain" language="en" />
<itunes:keywords>sti, sans.edu, devops, cable, modem, cablemhaunt, netscaler, citrix, curveball, letsdecrypt, cve-2020-0601, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 16th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6826</itunes:episode>
<itunes:subtitle>CVE-2020-0601 Exploit Released; Oracle Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2020-0601 Exploit Released; Oracle Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6826.mp3" length="5441256" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6826.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6826</link>
<pubDate>Thu, 16 Jan 2020 03:20:26 GMT</pubDate>
<description><![CDATA[CVE-2020-0601 Followup<br/>
 <a href="https://isc.sans.edu/forums/diary/CVE20200601+Followup/25714/">https://isc.sans.edu/forums/diary/CVE20200601+Followup/25714/</a><br/>
Oracle Patches<br/>
 <a href="https://www.oracle.com/security-alerts/cpujan2020.html">https://www.oracle.com/security-alerts/cpujan2020.html</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6826" type="text/plain" language="en" />
<itunes:keywords>oracle, cve-2020-0601, cryptoapi, crypt32.dll, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 15th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6824</itunes:episode>
<itunes:subtitle>Microsoft January 2020 Patch Tuesday and #CryptoAPI Flaw
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft January 2020 Patch Tuesday and #CryptoAPI Flaw
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6824.mp3" length="8436460" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6824.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6824</link>
<pubDate>Wed, 15 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Microsoft January 2020 Patch Tuesday and #CryptoAPI Flaw<br/>
 Webcast: <a href="https://sans.org/cryptoapi-isc">https://sans.org/cryptoapi-isc</a><br/>
 Diary: <a href="https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+for+January+2020/25710/">https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+for+January+2020/25710/</a><br/>
 NSA Release: <a href="https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF">https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF</a><br/>
]]></description>
<itunes:duration>10:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6824" type="text/plain" language="en" />
<itunes:keywords>microsoft, cryptoapi, crypt32.dll, ecc, eliptic curve, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 14th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6822</itunes:episode>
<itunes:subtitle>Upcoming Critical MSFT Patch; SIM Swaping is Easy; wombat dressing room
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Upcoming Critical MSFT Patch; SIM Swaping is Easy; wombat dressing room
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6822.mp3" length="6192429" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6822.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6822</link>
<pubDate>Tue, 14 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Upcoming Critical MSFT Patch<br/>
 <a href="https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-of-first-2020-patch-tuesday/">https://krebsonsecurity.com/2020/01/cryptic-rumblings-ahead-of-first-2020-patch-tuesday/</a><br/>
SIM Swapping is Easy<br/>
 <a href="https://www.issms2fasecure.com/assets/sim_swaps-01-10-2020.pdf">https://www.issms2fasecure.com/assets/sim_swaps-01-10-2020.pdf</a><br/>
Google Open Sources wombat dressing room npm publication proxy<br/>
 <a href="https://opensource.googleblog.com/2020/01/wombat-dressing-room-npm-publication_10.html">https://opensource.googleblog.com/2020/01/wombat-dressing-room-npm-publication_10.html</a><br/>
]]></description>
<itunes:duration>7:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6822" type="text/plain" language="en" />
<itunes:keywords>wombat dressing room, npm, proxy, sim swapping, msft patch, cryptoapi, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 13th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6820</itunes:episode>
<itunes:subtitle>Citrix ADC Vulnerability Actively Exploited #CitrixADC #Netscaler #cve201919781 #citrix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix ADC Vulnerability Actively Exploited #CitrixADC #Netscaler #cve201919781 #citrix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6820.mp3" length="6386620" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6820.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6820</link>
<pubDate>Mon, 13 Jan 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Citrix ADC Vulnerability Actively Exploited. Assume vulnerable systems are compromised.<br/>
 Updated Citrix Advisory: <a href="https://support.citrix.com/article/CTX267027">https://support.citrix.com/article/CTX267027</a><br/>
 Exploit Activity Summary: <a href="https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/">https://isc.sans.edu/forums/diary/Citrix+ADC+Exploits+are+Public+and+Heavily+Used+Attempts+to+Install+Backdoor/25700/</a><br/>
 Vulnerablity Scanner: <a href="https://github.com/trustedsec/cve-2019-19781/">https://github.com/trustedsec/cve-2019-19781/</a><br/>
 Special Webcast: <a href="https://i5c.us/citrix">https://i5c.us/citrix</a><br/>
 YouTube Walk Through of the vulnerability: <a href="https://youtu.be/msslpqyf98c">https://youtu.be/msslpqyf98c</a><br/>
]]></description>
<itunes:duration>7:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6820" type="text/plain" language="en" />
<itunes:keywords>citrix, citrixadc, cve-2019-19781, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 10th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6818</itunes:episode>
<itunes:subtitle>Another Word Maldoc; SHA1 Update; Cisco Update; Girls Go Cyberstart @GGCyberStart
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Another Word Maldoc; SHA1 Update; Cisco Update; Girls Go Cyberstart @GGCyberStart
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6818.mp3" length="8938574" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6818.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6818</link>
<pubDate>Fri, 10 Jan 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Another Malicious Word Document<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Analyzis+of+another+Maldoc/25694/">https://isc.sans.edu/forums/diary/Quick+Analyzis+of+another+Maldoc/25694/</a><br/>
SHA1 Update<br/>
 <a href="https://sha-mbles.github.io/">https://sha-mbles.github.io/</a><br/>
Cisco Updates<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Mandy Galante: Girls Go Cyberstart (register now. Play Jan 13th-31st)<br/>
 <a href="https://www.girlsgocyberstart.org/">https://www.girlsgocyberstart.org/</a><br/>
]]></description>
<itunes:duration>10:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6818" type="text/plain" language="en" />
<itunes:keywords>girls go cyberstart, ggcyberstart, cisco, sha1, word, maldoc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 9th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6816</itunes:episode>
<itunes:subtitle>Firefox Bug; Zero-Day in Play Store; Tails 4.2; TikTok Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Firefox Bug; Zero-Day in Play Store; Tails 4.2; TikTok Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6816.mp3" length="4787725" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6816.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6816</link>
<pubDate>Thu, 09 Jan 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Critical Firefox Update Fixing Exploited Bug<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/">https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/</a><br/>
3 Google Play Store Apps Exploit Android Zero-Day<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/">https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/</a><br/>
Tails 4.2 <br/>
 <a href="https://tails.boum.org/news/version_4.2/index.en.html">https://tails.boum.org/news/version_4.2/index.en.html</a><br/>
TikTok Vulnerablities<br/>
 <a href="https://research.checkpoint.com/2020/tik-or-tok-is-tiktok-secure-enough/">https://research.checkpoint.com/2020/tik-or-tok-is-tiktok-secure-enough/</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6816" type="text/plain" language="en" />
<itunes:keywords>tiktok, tails, linux, secure, anonymous, nso group, firefox, sidewinder, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 8th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6814</itunes:episode>
<itunes:subtitle>Citrix ADC Update; Pulse Secure SSLVPN Exploited; Project Zero Disclosure Policy; Android Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix ADC Update; Pulse Secure SSLVPN Exploited; Project Zero Disclosure Policy; Android Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6814.mp3" length="4616209" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6814.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6814</link>
<pubDate>Wed, 08 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Citrix ADC Update<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Quick+Update+on+Scanning+for+CVE201919781+Citrix+ADC+Gateway+Vulnerability/25686/">https://isc.sans.edu/forums/diary/A+Quick+Update+on+Scanning+for+CVE201919781+Citrix+ADC+Gateway+Vulnerability/25686/</a><br/>
Pulse Secure SSLVPN Exploited<br/>
 <a href="https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/">https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/</a><br/>
 <a href="https://www.darkreading.com/attacks-breaches/widely-known-flaw-in-pulse-secure-vpn-being-used-in-ransomware-attacks/d/d-id/1336729">https://www.darkreading.com/attacks-breaches/widely-known-flaw-in-pulse-secure-vpn-being-used-in-ransomware-attacks/d/d-id/1336729</a><br/>
Google Project Zero Changing Disclosure Policy <br/>
 <a href="https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html">https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html</a><br/>
Google Updates Android <br/>
 <a href="https://source.android.com/security/bulletin/2020-01-01">https://source.android.com/security/bulletin/2020-01-01</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6814" type="text/plain" language="en" />
<itunes:keywords>google, android, project zero, pulse secure sslvpn, sslvpn, travelex, citrix, netscaler, adc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 7th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6812</itunes:episode>
<itunes:subtitle>Spoofed Scans from 103/8; Iran Terror Threat; BusKill
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Spoofed Scans from 103/8; Iran Terror Threat; BusKill
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6812.mp3" length="4356178" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6812.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6812</link>
<pubDate>Tue, 07 Jan 2020 03:00:03 GMT</pubDate>
<description><![CDATA[Spoofed Scans from 103/8<br/>
 <a href="https://isc.sans.edu/forums/diary/Increase+in+Number+of+Sources+January+3rd+and+4th+spoofed/25678/">https://isc.sans.edu/forums/diary/Increase+in+Number+of+Sources+January+3rd+and+4th+spoofed/25678/</a><br/>
Iran Terror Threat<br/>
 <a href="https://www.dhs.gov/sites/default/files/ntas/alerts/20_0104_ntas_bulletin.pdf">https://www.dhs.gov/sites/default/files/ntas/alerts/20_0104_ntas_bulletin.pdf</a><br/>
BusKill Laptop Kill Cord<br/>
 <a href="https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-man-switch/">https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-man-switch/</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6812" type="text/plain" language="en" />
<itunes:keywords>buskill, iran, spoofed, scans, 103, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 6th 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6810</itunes:episode>
<itunes:subtitle>CCPA Intro; Cisco Patches; XiaoMi Camera Bug;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CCPA Intro; Cisco Patches; XiaoMi Camera Bug;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6810.mp3" length="3798460" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6810.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6810</link>
<pubDate>Mon, 06 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Quick Summary of the California Conumser Privacy Act<br/>
 <a href="https://isc.sans.edu/forums/diary/CCPA+Quick+Overview/25668/">https://isc.sans.edu/forums/diary/CCPA+Quick+Overview/25668/</a><br/>
Cisco Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
XiaoMi Camera Cache Bug<br/>
 <a href="https://www.reddit.com/r/googlehome/comments/eine1m/when_i_load_the_xiaomi_camera_in_my_google_home/">https://www.reddit.com/r/googlehome/comments/eine1m/when_i_load_the_xiaomi_camera_in_my_google_home/</a><br/>
]]></description>
<itunes:duration>4:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6810" type="text/plain" language="en" />
<itunes:keywords>xiaomi, camera, cache, cisco, ccpa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 3rd 2020</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6808</itunes:episode>
<itunes:subtitle>Ransomware written in JavaScript/Node.js; Landry Breach; Holiday Hack Challenge</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ransomware written in JavaScript/Node.js; Landry Breach; Holiday Hack Challenge</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6808.mp3" length="7071237" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6808.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6808</link>
<pubDate>Fri, 03 Jan 2020 03:00:02 GMT</pubDate>
<description><![CDATA[Ransomware written in JavaScript using Node.js<br/>
 <a href="https://isc.sans.edu/forums/diary/Ransomware+in+Nodejs/25664/">https://isc.sans.edu/forums/diary/Ransomware+in+Nodejs/25664/</a><br/>
Landry Restaurant PoS Breach<br/>
 <a href="https://www.landrysinc.com/CreditNotice/CANotice.asp">https://www.landrysinc.com/CreditNotice/CANotice.asp</a><br/>
Holiday Hack Challenge<br/>
 <a href="https://www.holidayhackchallenge.com">https://www.holidayhackchallenge.com</a><br/>
Citrix/NetScaler Vulnerability Special Webcast Recording<br/>
 <a href="https://i5c.us/citrix">https://i5c.us/citrix</a><br/>
]]></description>
<itunes:duration>8:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6808" type="text/plain" language="en" />
<itunes:keywords>citrix, netscaler, webcast, recording, holiday hack challenge, kinklecon, landry, pos, credit cards, ransomware, nodejs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 31st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6806</itunes:episode>
<itunes:subtitle>ISC API Update; 36C3 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ISC API Update; 36C3 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6806.mp3" length="5562095" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6806.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6806</link>
<pubDate>Tue, 31 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[ISC API Update<br/>
 <a href="https://isc.sans.edu/api">https://isc.sans.edu/api</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Miscellaneous+Updates+to+our+Threatfeed+API/25654/">https://isc.sans.edu/forums/diary/Miscellaneous+Updates+to+our+Threatfeed+API/25654/</a><br/>
CCC Conference<br/>
 <a href="https://fahrplan.events.ccc.de/congress/2019/Fahrplan/">https://fahrplan.events.ccc.de/congress/2019/Fahrplan/</a><br/>
 <a href="https://events.ccc.de/congress/2019/wiki/index.php/Main_Page">https://events.ccc.de/congress/2019/wiki/index.php/Main_Page</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6806" type="text/plain" language="en" />
<itunes:keywords>ccc, bluetooth, lte, isc api, api, onyphe, shodan, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6804</itunes:episode>
<itunes:subtitle>Breaking 2FA Soft Tokens; Pihole Dashbaord; Corrupt Office Docs; Enumerating O365 Users;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Breaking 2FA Soft Tokens; Pihole Dashbaord; Corrupt Office Docs; Enumerating O365 Users;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6804.mp3" length="4987556" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6804.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6804</link>
<pubDate>Mon, 30 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Breaking 2FA Soft Tokens<br/>
 <a href="https://resources.fox-it.com/rs/170-CAK-271/images/201912_Report_Operation_Wocao.pdf">https://resources.fox-it.com/rs/170-CAK-271/images/201912_Report_Operation_Wocao.pdf</a><br/>
PiHole Dashboard<br/>
 <a href="https://isc.sans.edu/forums/diary/ELK+Dashboard+for+Pihole+Logs/25652/">https://isc.sans.edu/forums/diary/ELK+Dashboard+for+Pihole+Logs/25652/</a><br/>
Corrupt Office Documents<br/>
 <a href="https://isc.sans.edu/forums/diary/Corrupt+Office+Documents/25650/">https://isc.sans.edu/forums/diary/Corrupt+Office+Documents/25650/</a><br/>
Enumerating Office 365 Users<br/>
 <a href="https://isc.sans.edu/forums/diary/Enumerating+office365+users/25648/">https://isc.sans.edu/forums/diary/Enumerating+office365+users/25648/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6804" type="text/plain" language="en" />
<itunes:keywords>o365, office 365, microsoft, enumeration, PiHole, oledump, elk, 2fa, rsa, apt, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 27th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6802</itunes:episode>
<itunes:subtitle>Citrix Application Delivery Controller (Netscaler ADC) Critical Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citrix Application Delivery Controller (Netscaler ADC) Critical Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6802.mp3" length="3144722" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6802.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6802</link>
<pubDate>Fri, 27 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Citrix Application Delivery Controller (Netscaler ADC) Critical Vulnerability<br/>
 <a href="https://www.ptsecurity.com/ww-en/about/news/citrix-vulnerability-allows-criminals-to-hack-networks-of-80000-companies/">https://www.ptsecurity.com/ww-en/about/news/citrix-vulnerability-allows-criminals-to-hack-networks-of-80000-companies/</a><br/>
 <a href="https://support.citrix.com/article/CTX267027">https://support.citrix.com/article/CTX267027</a><br/>
]]></description>
<itunes:duration>3:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6802" type="text/plain" language="en" />
<itunes:keywords>Citrix, Netscaler, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6800</itunes:episode>
<itunes:subtitle>Extracting Macros from AutoCAD Files; Cisco PKI Expiration; AFRINIC IP Heist
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Extracting Macros from AutoCAD Files; Cisco PKI Expiration; AFRINIC IP Heist
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6800.mp3" length="3841042" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6800.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6800</link>
<pubDate>Mon, 23 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Extracting VBA Macros From .DWG Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Extracting+VBA+Macros+From+DWG+Files/25634/">https://isc.sans.edu/forums/diary/Extracting+VBA+Macros+From+DWG+Files/25634/</a><br/>
Cisco PKI Self-Signed Certificate Expiration<br/>
 <a href="https://www.cisco.com/c/en/us/support/docs/field-notices/704/fn70489.html">https://www.cisco.com/c/en/us/support/docs/field-notices/704/fn70489.html</a><br/>
AFRINIC IP Address Space Misappropriated By Insider<br/>
 <a href="https://mybroadband.co.za/news/internet/330379-how-internet-resources-worth-r800-million-were-stolen-and-sold-on-the-black-market.html">https://mybroadband.co.za/news/internet/330379-how-internet-resources-worth-r800-million-were-stolen-and-sold-on-the-black-market.html</a><br/>
]]></description>
<itunes:duration>4:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6800" type="text/plain" language="en" />
<itunes:keywords>AFRINIC, IPv4 Heist, Cisco, PKI, VBA, DWG, AutoCAD, oledump, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6798</itunes:episode>
<itunes:subtitle>More DNS over HTTPS Details; Ransomware Going Public; Google Chrome Update 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More DNS over HTTPS Details; Ransomware Going Public; Google Chrome Update 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6798.mp3" length="4372790" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6798.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6798</link>
<pubDate>Fri, 20 Dec 2019 03:00:03 GMT</pubDate>
<description><![CDATA[More DNS over HTTPS Details<br/>
 <a href="https://isc.sans.edu/forums/diary/More+DNS+over+HTTPS+Become+One+With+the+Packet+Be+the+Query+See+the+Query/25628/">https://isc.sans.edu/forums/diary/More+DNS+over+HTTPS+Become+One+With+the+Packet+Be+the+Query+See+the+Query/25628/</a><br/>
Ransomware Outing Victims<br/>
 <a href="https://krebsonsecurity.com/2019/12/ransomware-gangs-now-outing-victim-businesses-that-dont-pay-up/">https://krebsonsecurity.com/2019/12/ransomware-gangs-now-outing-victim-businesses-that-dont-pay-up/</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop_17.html">https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop_17.html</a><br/>
]]></description>
<itunes:duration>5:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6798" type="text/plain" language="en" />
<itunes:keywords>google, chrome, ransomware, doh, dns, https, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6796</itunes:episode>
<itunes:subtitle>Emotet update; Joomla Patches; Unicode Problems
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet update; Joomla Patches; Unicode Problems
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6796.mp3" length="3167034" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6796.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6796</link>
<pubDate>Thu, 19 Dec 2019 03:00:03 GMT</pubDate>
<description><![CDATA[An Emotet Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+infection+with+spambot+activity/25622/">https://isc.sans.edu/forums/diary/Emotet+infection+with+spambot+activity/25622/</a><br/>
Emotet Used to Spread Malware From German Federal Agency Accounts (german)<br/>
 <a href="https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2019/Spam-Bundesbehoerden_181219.html">https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2019/Spam-Bundesbehoerden_181219.html</a><br/>
Joomla Patches SQL Injection<br/>
 <a href="https://developer.joomla.org/security-centre.html">https://developer.joomla.org/security-centre.html</a><br/>
Unicode Mapping Problems<br/>
 <a href="https://eng.getwisdom.io/hacking-github-with-unicode-dotless-i/">https://eng.getwisdom.io/hacking-github-with-unicode-dotless-i/</a><br/>
]]></description>
<itunes:duration>3:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6796" type="text/plain" language="en" />
<itunes:keywords>emotet, joomla, unicode, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6794</itunes:episode>
<itunes:subtitle>Discovering DNS over HTTPS; Ring Camera Weaknesses; WhatsApp Bug;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Discovering DNS over HTTPS; Ring Camera Weaknesses; WhatsApp Bug;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6794.mp3" length="5055219" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6794.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6794</link>
<pubDate>Wed, 18 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Discovering DNS over HTTPS<br/>
 <a href="https://isc.sans.edu/forums/diary/Is+it+Possible+to+Identify+DNS+over+HTTPs+Without+Decrypting+TLS/25616/">https://isc.sans.edu/forums/diary/Is+it+Possible+to+Identify+DNS+over+HTTPs+Without+Decrypting+TLS/25616/</a><br/>
Ring Camera Weaknesses<br/>
 <a href="https://www.vice.com/en_us/article/epg4xm/amazon-ring-camera-security">https://www.vice.com/en_us/article/epg4xm/amazon-ring-camera-security</a><br/>
WhatsApp DoS Bug<br/>
 <a href="https://research.checkpoint.com/2019/breakingapp-whatsapp-crash-data-loss-bug/">https://research.checkpoint.com/2019/breakingapp-whatsapp-crash-data-loss-bug/</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6794" type="text/plain" language="en" />
<itunes:keywords>whatsapp, dos, ring, dns, https, doh, dns over https, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6792</itunes:episode>
<itunes:subtitle>Slack "Unshare" Vuln; Google Enforces OAUTH; TPLink Auth Bypass; Factoring IoT RSA Keys
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Slack "Unshare" Vuln; Google Enforces OAUTH; TPLink Auth Bypass; Factoring IoT RSA Keys
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6792.mp3" length="5287078" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6792.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6792</link>
<pubDate>Tue, 17 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Slack "Unshare" Not Working As Expected<br/>
 <a href="https://www.theregister.co.uk/2019/12/16/slack_filesharing_vulnerability_post_sharing/">https://www.theregister.co.uk/2019/12/16/slack_filesharing_vulnerability_post_sharing/</a><br/>
Google Making OAUTH Mandatory for GSuite<br/>
 <a href="https://gsuiteupdates.googleblog.com/2019/12/less-secure-apps-oauth-google-username-password-incorrect.html">https://gsuiteupdates.googleblog.com/2019/12/less-secure-apps-oauth-google-username-password-incorrect.html</a><br/>
TPLink Authentication Bypass<br/>
 <a href="https://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/">https://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/</a><br/>
Factoring IoT RSA Keys<br/>
 <a href="https://info.keyfactor.com/factoring-rsa-keys-in-the-iot-era">https://info.keyfactor.com/factoring-rsa-keys-in-the-iot-era</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6792" type="text/plain" language="en" />
<itunes:keywords>rsa, tplink, google, oauth, slack, factoring, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6790</itunes:episode>
<itunes:subtitle>Malicious Autocad Files; OpenBSD Priv. Escalation; NPM Path Traversal
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Autocad Files; OpenBSD Priv. Escalation; NPM Path Traversal
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6790.mp3" length="4764105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6790.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6790</link>
<pubDate>Mon, 16 Dec 2019 03:00:04 GMT</pubDate>
<description><![CDATA[VBA Macros in Autocad<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+DWG+Files/25612/">https://isc.sans.edu/forums/diary/Malicious+DWG+Files/25612/</a><br/>
OpenBSD Privilege Escalation Vulnerability<br/>
 <a href="https://www.qualys.com/2019/12/11/cve-2019-19726/local-privilege-escalation-openbsd-dynamic-loader.txt">https://www.qualys.com/2019/12/11/cve-2019-19726/local-privilege-escalation-openbsd-dynamic-loader.txt</a><br/>
NPM Fixes Critical Security Vulnerability<br/>
 <a href="https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli">https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6790" type="text/plain" language="en" />
<itunes:keywords>npm, yarn, path traversal, openbsd, privileges escalation, VBA, Autocad, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 13th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6788</itunes:episode>
<itunes:subtitle>Shared Data in Malware; WebKit Tracking Protection; SMS Verification; @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shared Data in Malware; WebKit Tracking Protection; SMS Verification; @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6788.mp3" length="12158482" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6788.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6788</link>
<pubDate>Fri, 13 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Malware Information Sharing<br/>
 <a href="https://isc.sans.edu/forums/diary/Code+Data+Reuse+in+the+Malware+Ecosystem/25598/">https://isc.sans.edu/forums/diary/Code+Data+Reuse+in+the+Malware+Ecosystem/25598/</a><br/>
Apple Improves Tracking Prevention Tracking in WebKit<br/>
 <a href="https://webkit.org/blog/9661/preventing-tracking-prevention-tracking/">https://webkit.org/blog/9661/preventing-tracking-prevention-tracking/</a><br/>
Google Verified SMS Messages<br/>
 <a href="https://www.blog.google/products/messages/safer-conversations-messages-verified-sms-and-spam-protection/">https://www.blog.google/products/messages/safer-conversations-messages-verified-sms-and-spam-protection/</a><br/>
Echobot Keeps Adding More Exploits<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-echobot-variant-exploits-77-remote-code-execution-flaws/">https://www.bleepingcomputer.com/news/security/new-echobot-variant-exploits-77-remote-code-execution-flaws/</a><br/>
STI Research Paper: Caleb Baker DNS Monitoring<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/dns/challenges-effective-dns-query-monitoring-39215">https://www.sans.org/reading-room/whitepapers/dns/challenges-effective-dns-query-monitoring-39215</a><br/>
]]></description>
<itunes:duration>14:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6788" type="text/plain" language="en" />
<itunes:keywords>dns, blacklists, monitoring, google, echobot, sms, apple, webkit, tracking, malware, information sharing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6786</itunes:episode>
<itunes:subtitle>German Malspam / Trickbot; KeyWe Locks; Chrome Update; iOS Spam Filter
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
German Malspam / Trickbot; KeyWe Locks; Chrome Update; iOS Spam Filter
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6786.mp3" length="4448132" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6786.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6786</link>
<pubDate>Thu, 12 Dec 2019 03:00:03 GMT</pubDate>
<description><![CDATA[German Malspam Installs Trickbot<br/>
 <a href="https://isc.sans.edu/forums/diary/German+language+malspam+pushes+yet+another+wave+of+Trickbot/25594/">https://isc.sans.edu/forums/diary/German+language+malspam+pushes+yet+another+wave+of+Trickbot/25594/</a><br/>
Vulnerable KeyWe Smart Lock<br/>
 <a href="https://labs.f-secure.com/advisories/keywe-smart-lock-unauthorized-access-traffic-interception">https://labs.f-secure.com/advisories/keywe-smart-lock-unauthorized-access-traffic-interception</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html</a><br/>
iOS Spam Feature<br/>
 <a href="https://support.apple.com/en-us/HT210756">https://support.apple.com/en-us/HT210756</a><br/>
 <a href="https://kishanbagaria.com/airdos/">https://kishanbagaria.com/airdos/</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6786" type="text/plain" language="en" />
<itunes:keywords>ios, anti-spam, airdos, google, chrome, keywe, smart lock, trickbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6784</itunes:episode>
<itunes:subtitle>Microsoft, Adobe, Intel and Apple Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft, Adobe, Intel and Apple Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6784.mp3" length="5725574" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6784.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6784</link>
<pubDate>Wed, 11 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+December+2019+Patch+Tuesday/25592/">https://isc.sans.edu/forums/diary/Microsoft+December+2019+Patch+Tuesday/25592/</a><br/>
 <a href="https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/">https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/</a><br/>
Adobe Patch Tuesday<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Apple Security Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Intel Plundervolt Update<br/>
 <a href="https://blogs.intel.com/technology/2019/12/ipas-security-advisories-for-december-2019/">https://blogs.intel.com/technology/2019/12/ipas-security-advisories-for-december-2019/</a><br/>
]]></description>
<itunes:duration>6:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6784" type="text/plain" language="en" />
<itunes:keywords>intel, plundervolt, apple, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6782</itunes:episode>
<itunes:subtitle>Another Word Maldoc; Snatch Ransomware; Ryuk Decryptor Fail; Sysmon DNS Rules @swiftonsecurity 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Another Word Maldoc; Snatch Ransomware; Ryuk Decryptor Fail; Sysmon DNS Rules @swiftonsecurity 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6782.mp3" length="6659238" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6782.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6782</link>
<pubDate>Tue, 10 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Another Word Maldoc<br/>
 <a href="https://isc.sans.edu/forums/diary/Lazy+Sunday+Maldoc+Analysis/25586/">https://isc.sans.edu/forums/diary/Lazy+Sunday+Maldoc+Analysis/25586/</a><br/>
Snatch Ransomware Reboots System Into Safe Mode To Disable Anti Virus<br/>
 <a href="https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/">https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/</a><br/>
Ryuk Ransomware Decryptor May No Longer Work / Corrupt Documents<br/>
 <a href="https://blog.emsisoft.com/en/35023/bug-in-latest-ryuk-decryptor-may-cause-data-loss/">https://blog.emsisoft.com/en/35023/bug-in-latest-ryuk-decryptor-may-cause-data-loss/</a><br/>
Extending Windows 7 Security Updates<br/>
 <a href="https://www.ghacks.net/2019/12/07/someone-found-a-way-to-bypass-windows-7-extended-security-updates-checks/">https://www.ghacks.net/2019/12/07/someone-found-a-way-to-bypass-windows-7-extended-security-updates-checks/</a><br/>
Swift on Security Updates Sysmon Rules<br/>
 <a href="https://github.com/SwiftOnSecurity/sysmon-config">https://github.com/SwiftOnSecurity/sysmon-config</a><br/>
RSA Webcast<br/>
 <a href="https://www.rsaconference.com/industry-topics/webcast/36-five-most-dangerous-attacks-evolving">https://www.rsaconference.com/industry-topics/webcast/36-five-most-dangerous-attacks-evolving</a><br/>
]]></description>
<itunes:duration>7:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6782" type="text/plain" language="en" />
<itunes:keywords>Word, maldoc, oledump, snatch, ransomware, safe mode, ryuk, decryptor, windows 7, esu, swift on security, sysmon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6780</itunes:episode>
<itunes:subtitle>HTML Phishing Email; Great (Red) Canon Activated Against HK
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HTML Phishing Email; Great (Red) Canon Activated Against HK
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6780.mp3" length="5171510" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6780.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6780</link>
<pubDate>Mon, 09 Dec 2019 03:00:02 GMT</pubDate>
<description><![CDATA[E-Mail Includes Entire HTML/Javascript Phishing Kit<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+with+a+selfcontained+credentialsstealing+webpage/25580/">https://isc.sans.edu/forums/diary/Phishing+with+a+selfcontained+credentialsstealing+webpage/25580/</a><br/>
Great Canon / Red Canon Activated to Silence Pro  Hongkong Forum<br/>
 <a href="https://cybersecurity.att.com/blogs/labs-research/the-great-cannon-has-been-deployed-again">https://cybersecurity.att.com/blogs/labs-research/the-great-cannon-has-been-deployed-again</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6780" type="text/plain" language="en" />
<itunes:keywords>hongkong, red canon, great canon, javascript, phishing, html email, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 6th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6778</itunes:episode>
<itunes:subtitle>OpenBSD Vuln; Linux/BSD VPN Connection Hijack; STI Paper: RASP vs. WAF
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenBSD Vuln; Linux/BSD VPN Connection Hijack; STI Paper: RASP vs. WAF
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6778.mp3" length="11783990" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6778.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6778</link>
<pubDate>Fri, 06 Dec 2019 04:30:02 GMT</pubDate>
<description><![CDATA[OpenBSD Authentication Bypass and Privilege Escalation Vulnerability<br/>
 <a href="https://www.qualys.com/2019/12/04/cve-2019-19521/authentication-vulnerabilities-openbsd.txt?_ga=2.58244398.587934852.1575530822-682141427.1570559125">https://www.qualys.com/2019/12/04/cve-2019-19521/authentication-vulnerabilities-openbsd.txt?_ga=2.58244398.587934852.1575530822-682141427.1570559125</a><br/>
Hijacking Linux (and BSD) VPN Connections<br/>
 <a href="https://seclists.org/oss-sec/2019/q4/122">https://seclists.org/oss-sec/2019/q4/122</a><br/>
RASP vs. WAF: Alexander Fry Research Paper<br/>
<a href="https://www.sans.org/reading-room/whitepapers/application/runtime-application-self-protection-rasp-investigation-effectiveness-rasp-solution-protecting-vulnerable-target-applications-38950">https://www.sans.org/reading-room/whitepapers/application/runtime-application-self-protection-rasp-investigation-effectiveness-rasp-solution-protecting-vulnerable-target-applications-38950</a><br/>
]]></description>
<itunes:duration>14:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6778" type="text/plain" language="en" />
<itunes:keywords>rasp, waf, vpn, linux, bsd, openbsd, authentication, login, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 5th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6776</itunes:episode>
<itunes:subtitle>Atlasian Companion App IBM Aspera Cloud; Python Libraries; GoAhead
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Atlasian Companion App IBM Aspera Cloud; Python Libraries; GoAhead
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6776.mp3" length="5069480" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6776.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6776</link>
<pubDate>Thu, 05 Dec 2019 05:05:02 GMT</pubDate>
<description><![CDATA[Atlasian Companion App / IBM Aspera Cloud <br/>
 <a href="https://www.theregister.co.uk/2019/12/05/atlassian_zero_day_bug/">https://www.theregister.co.uk/2019/12/05/atlassian_zero_day_bug/</a><br/>
 <a href="https://confluence.atlassian.com/doc/administering-the-atlassian-companion-app-958456281.html">https://confluence.atlassian.com/doc/administering-the-atlassian-companion-app-958456281.html</a><br/>
 <a href="https://twitter.com/tmslft/status/1202056063878606848?s=20">https://twitter.com/tmslft/status/1202056063878606848?s=20</a><br/>
Fake Python Library in PyPi<br/>
 <a href="https://github.com/dateutil/dateutil/issues/984">https://github.com/dateutil/dateutil/issues/984</a><br/>
GoAhead Web Server Vulnerability<br/>
 <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2019-0888">https://talosintelligence.com/vulnerability_reports/TALOS-2019-0888</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6776" type="text/plain" language="en" />
<itunes:keywords>goahead, web server, python, dateutil, jellyfish, je1lyfish, atlasian, aspera, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6774</itunes:episode>
<itunes:subtitle>Avast Blocked from Firefox; Android Patches; Strandhogg; Firefox 71
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Avast Blocked from Firefox; Android Patches; Strandhogg; Firefox 71
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6774.mp3" length="5206625" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6774.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6774</link>
<pubDate>Wed, 04 Dec 2019 04:40:02 GMT</pubDate>
<description><![CDATA[Avast Online Security and Avast Secure Browser Blocked for Spying on Users<br/>
 <a href="https://palant.de/2019/10/28/avast-online-security-and-avast-secure-browser-are-spying-on-you/">https://palant.de/2019/10/28/avast-online-security-and-avast-secure-browser-are-spying-on-you/</a><br/>
Google Android Updates<br/>
 <a href="https://source.android.com/security/bulletin/2019-12-01">https://source.android.com/security/bulletin/2019-12-01</a><br/>
Strandhogg Vulnerability<br/>
 <a href="https://promon.co/security-news/strandhogg/">https://promon.co/security-news/strandhogg/</a><br/>
Firefox 71 Released<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2019-34/">https://www.mozilla.org/en-US/security/advisories/mfsa2019-34/</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6774" type="text/plain" language="en" />
<itunes:keywords>firefox, strandhogg, android, updates, patches, banking trojan, avast, privacy, anti malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6772</itunes:episode>
<itunes:subtitle>Port 26 Scans; Ursnif/Dridex; Windows 7 ESU; QNAP Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Port 26 Scans; Ursnif/Dridex; Windows 7 ESU; QNAP Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6772.mp3" length="4954644" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6772.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6772</link>
<pubDate>Tue, 03 Dec 2019 04:30:03 GMT</pubDate>
<description><![CDATA[Increased Scans on Port 26<br/>
 <a href="https://isc.sans.edu/forums/diary/Next+up+whats+up+with+TCP+port+26/25564/">https://isc.sans.edu/forums/diary/Next+up+whats+up+with+TCP+port+26/25564/</a><br/>
Recent Ursnif Malspam <br/>
 <a href="https://isc.sans.edu/forums/diary/Ursnif+infection+with+Dridex/25566/">https://isc.sans.edu/forums/diary/Ursnif+infection+with+Dridex/25566/</a><br/>
Windows 7 Extended Security Updates<br/>
 <a href="https://www.microsoft.com/microsoft-365/partners/news/article/announcing-paid-windows-7-extended-security-updates">https://www.microsoft.com/microsoft-365/partners/news/article/announcing-paid-windows-7-extended-security-updates</a><br/>
QNAP Patches Photo Station<br/>
 <a href="https://www.qnap.com/en/security-advisory/nas-201911-25">https://www.qnap.com/en/security-advisory/nas-201911-25</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6772" type="text/plain" language="en" />
<itunes:keywords>qnap, windows 7, ESU, microsoft, ursnif, dridex, exim, telnet, port 26, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6770</itunes:episode>
<itunes:subtitle>Agent Tesla; SauronEye; Splunk Y2k20 Bug; Google Threat Analysis Group Summary
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Agent Tesla; SauronEye; Splunk Y2k20 Bug; Google Threat Analysis Group Summary
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6770.mp3" length="5654255" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6770.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6770</link>
<pubDate>Mon, 02 Dec 2019 08:55:02 GMT</pubDate>
<description><![CDATA[Agent Tesla Malware Sample Analysis<br/>
<a href="https://isc.sans.edu/forums/diary/Finding+an+Agent+Tesla+malware+sample/25554/">https://isc.sans.edu/forums/diary/Finding+an+Agent+Tesla+malware+sample/25554/</a><br/>
Search With SauronEye<br/>
 <a href="https://isc.sans.edu/forums/diary/ISC+Snapshot+Search+with+SauronEye/25558/">https://isc.sans.edu/forums/diary/ISC+Snapshot+Search+with+SauronEye/25558/</a><br/>
Splunk Y2K20 Patch<br/>
 <a href="https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020">https://docs.splunk.com/Documentation/Splunk/8.0.0/ReleaseNotes/FixDatetimexml2020</a><br/>
Google TAG Quarterly Summary<br/>
 <a href="https://blog.google/technology/safety-security/threat-analysis-group/protecting-users-government-backed-hacking-and-disinformation/">https://blog.google/technology/safety-security/threat-analysis-group/protecting-users-government-backed-hacking-and-disinformation/</a><br/>
]]></description>
<itunes:duration>6:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6770" type="text/plain" language="en" />
<itunes:keywords>google, tag, state sponsored, splunk, y2k, sauroneye, agent tesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 27th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6768</itunes:episode>
<itunes:subtitle>Playing With Phishing; HPE SSD Update; Malicious Android SDK; Kaspersky Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Playing With Phishing; HPE SSD Update; Malicious Android SDK; Kaspersky Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6768.mp3" length="4872728" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6768.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6768</link>
<pubDate>Wed, 27 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Playing With Phishing<br/>
 <a href="https://isc.sans.edu/forums/diary/Lessons+learned+from+playing+a+willing+phish/25552/">https://isc.sans.edu/forums/diary/Lessons+learned+from+playing+a+willing+phish/25552/</a><br/>
HPE SSD Drives will Stop Working in 3 years<br/>
 <a href="https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00092491en_us">https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00092491en_us</a><br/>
Malicious Android SDK Captures Social Media Data<br/>
 <a href="https://help.twitter.com/en/sdk-issue">https://help.twitter.com/en/sdk-issue</a><br/>
Kasperski API Exposed to Websites<br/>
 <a href="https://palant.de/2019/11/26/internal-kaspersky-api-exposed-to-websites/">https://palant.de/2019/11/26/internal-kaspersky-api-exposed-to-websites/</a><br/>
Malicious Ad Statistics<br/>
 <a href="https://www.confiant.com/Demand-Quality-Report-Q3-2019">https://www.confiant.com/Demand-Quality-Report-Q3-2019</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6768" type="text/plain" language="en" />
<itunes:keywords>kasperski, ads, sdk, twitter, ssd, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6766</itunes:episode>
<itunes:subtitle>DoH In SOHO Networks; Fortinet Weak Crypto; Tracking via DNS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DoH In SOHO Networks; Fortinet Weak Crypto; Tracking via DNS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6766.mp3" length="3907604" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6766.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6766</link>
<pubDate>Tue, 26 Nov 2019 03:00:02 GMT</pubDate>
<description><![CDATA[DNS over HTTPS (DoH) in SOHO Networks<br/>
 <a href="https://isc.sans.edu/forums/diary/My+Little+DoH+Setup/25548/">https://isc.sans.edu/forums/diary/My+Little+DoH+Setup/25548/</a><br/>
Fortinet Weak Crypto <br/>
 <a href="https://sec-consult.com/en/blog/advisories/weak-encryption-cipher-and-hardcoded-cryptographic-keys-in-fortinet-products/">https://sec-consult.com/en/blog/advisories/weak-encryption-cipher-and-hardcoded-cryptographic-keys-in-fortinet-products/</a><br/>
Tracking Web Users via DNS<br/>
 <a href="https://github.com/uBlockOrigin/uBlock-issues/issues/780">https://github.com/uBlockOrigin/uBlock-issues/issues/780</a><br/>
]]></description>
<itunes:duration>4:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6766" type="text/plain" language="en" />
<itunes:keywords>tracking, dns, fortinet, https, doh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6764</itunes:episode>
<itunes:subtitle>Web Filter Recon; Malice for Local Malware Analysis; VNC Flaws
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Web Filter Recon; Malice for Local Malware Analysis; VNC Flaws
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6764.mp3" length="4505181" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6764.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6764</link>
<pubDate>Mon, 25 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Web Filter Misconfiguration Abused for Recognisance<br/>
 <a href="https://isc.sans.edu/forums/diary/Abusing+Web+Filters+Misconfiguration+for+Reconnaissance/25538/">https://isc.sans.edu/forums/diary/Abusing+Web+Filters+Misconfiguration+for+Reconnaissance/25538/</a><br/>
Local Malware Analysis with Malice<br/>
 <a href="https://isc.sans.edu/forums/diary/Local+Malware+Analysis+with+Malice/25544/">https://isc.sans.edu/forums/diary/Local+Malware+Analysis+with+Malice/25544/</a><br/>
Multiple Vulnerabilities in VNC<br/>
 <a href="https://www.kaspersky.com/blog/vnc-vulnerabilities/31462/">https://www.kaspersky.com/blog/vnc-vulnerabilities/31462/</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6764" type="text/plain" language="en" />
<itunes:keywords>vnc, malice, web filter, recognisance, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6762</itunes:episode>
<itunes:subtitle>Memory Encryption Issues; Memory Encryption Issues; RIPlace; OFfcie Preview Issue
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Memory Encryption Issues; Memory Encryption Issues; RIPlace; OFfcie Preview Issue
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6762.mp3" length="5273179" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6762.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6762</link>
<pubDate>Fri, 22 Nov 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Weaknesses in Memory Encryption Solutions<br/>
 <a href="https://arxiv.org/abs/1908.11680">https://arxiv.org/abs/1908.11680</a><br/>
GetMonero Wallet Compromised<br/>
 <a href="https://web.getmonero.org/2019/11/19/warning-compromised-binaries.html">https://web.getmonero.org/2019/11/19/warning-compromised-binaries.html</a><br/>
RIPlace Ransomware Detection Bypass<br/>
 <a href="https://www.nyotron.com/blog/nyotron-discovers-potentially-unstoppable-ransomware-evasion-technique-riplace/">https://www.nyotron.com/blog/nyotron-discovers-potentially-unstoppable-ransomware-evasion-technique-riplace/</a><br/>
Microsoft Office Remote Content Triggers in Preview Pane<br/>
 <a href="https://medium.com/@curtbraz/getting-malicious-office-documents-to-fire-with-protected-view-4de18668c386">https://medium.com/@curtbraz/getting-malicious-office-documents-to-fire-with-protected-view-4de18668c386</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6762" type="text/plain" language="en" />
<itunes:keywords>office, preview, phishing, riplace, ransomware, getmonero, wallet, memory encryption, amd, intel, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6760</itunes:episode>
<itunes:subtitle>Latest Hancitor Update; Oracle Payday Vuln; Chrome Update; Unbound Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Latest Hancitor Update; Oracle Payday Vuln; Chrome Update; Unbound Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6760.mp3" length="5143720" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6760.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6760</link>
<pubDate>Thu, 21 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Latest Hancitor Malspam Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+infection+with+Pony+Evil+Pony+Ursnif+and+Cobalt+Strike/25532/">https://isc.sans.edu/forums/diary/Hancitor+infection+with+Pony+Evil+Pony+Ursnif+and+Cobalt+Strike/25532/</a><br/>
Oracle Payday Vulnerabilities Exploited<br/>
 <a href="https://www.onapsis.com/blog/oracle-payday-vulnerabilities">https://www.onapsis.com/blog/oracle-payday-vulnerabilities</a><br/>
Google Chrome Update<br/>
 <a href="https://chromereleases.googleblog.com/2019/11/stable-channel-update-for-desktop_18.html">https://chromereleases.googleblog.com/2019/11/stable-channel-update-for-desktop_18.html</a><br/>
NSA Publishes Guide About the Risks of Inspecting TLS<br/>
 <a href="https://media.defense.gov/2019/Nov/18/2002212783/-1/-1/0/MANAGING%20RISK%20FROM%20TLS%20INSPECTION_20191106.PDF">https://media.defense.gov/2019/Nov/18/2002212783/-1/-1/0/MANAGING%20RISK%20FROM%20TLS%20INSPECTION_20191106.PDF</a><br/>
Unbound Command Execution Vulnerability<br/>
 <a href="https://nlnetlabs.nl/projects/unbound/security-advisories/#vulnerability-in-ipsec-module">https://nlnetlabs.nl/projects/unbound/security-advisories/#vulnerability-in-ipsec-module</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6760" type="text/plain" language="en" />
<itunes:keywords>unbound, NSA, TLS interception, google chrome, oracle, payday, hancitor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6758</itunes:episode>
<itunes:subtitle>JAWS DVR Bot; Tianfu Cup; Access Hotfix; Win10 DoH; Android Camera Permission Mixup
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JAWS DVR Bot; Tianfu Cup; Access Hotfix; Win10 DoH; Android Camera Permission Mixup
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6758.mp3" length="5371928" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6758.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6758</link>
<pubDate>Wed, 20 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[JAWS DVR Bot<br/>
 <a href="https://isc.sans.edu/forums/diary/Cheap+Chinese+JAWS+of+DVR+Exploitability+on+Port+60001/25530/">https://isc.sans.edu/forums/diary/Cheap+Chinese+JAWS+of+DVR+Exploitability+on+Port+60001/25530/</a><br/>
TianFu Cup<br/>
 <a href="https://twitter.com/TianfuCup">https://twitter.com/TianfuCup</a><br/>
Microsoft Access Hotfix<br/>
 <a href="https://support.microsoft.com/en-us/help/4484198/november-18-2019-update-for-office-2016-kb4484198">https://support.microsoft.com/en-us/help/4484198/november-18-2019-update-for-office-2016-kb4484198</a><br/>
Windows 10 DNS over HTTPS<br/>
 <a href="https://techcommunity.microsoft.com/t5/Networking-Blog/Windows-will-improve-user-privacy-with-DNS-over-HTTPS/ba-p/1014229">https://techcommunity.microsoft.com/t5/Networking-Blog/Windows-will-improve-user-privacy-with-DNS-over-HTTPS/ba-p/1014229</a><br/>
Android Camera Permission Mixup<br/>
 <a href="https://www.checkmarx.com/blog/how-attackers-could-hijack-your-android-camera">https://www.checkmarx.com/blog/how-attackers-could-hijack-your-android-camera</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6758" type="text/plain" language="en" />
<itunes:keywords>jaws, dvr, mirai, tianfu, access, win10, dns over https, doh, android, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6756</itunes:episode>
<itunes:subtitle>SMS Woes; Intel Removing EOL BIOS Downloads; Agressive Outlook 365 Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SMS Woes; Intel Removing EOL BIOS Downloads; Agressive Outlook 365 Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6756.mp3" length="4745455" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6756.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6756</link>
<pubDate>Tue, 19 Nov 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Carriers Filter SMS Messages Sent By Applications<br/>
 <a href="https://isc.sans.edu/forums/diary/SMS+and+2FA+Another+Reason+to+Move+away+from+It/25526/">https://isc.sans.edu/forums/diary/SMS+and+2FA+Another+Reason+to+Move+away+from+It/25526/</a><br/>
Intel Removing BIOS Downloads for EOL Hardware<br/>
 <a href="https://www.vogons.org/viewtopic.php?f=46&t=69184">https://www.vogons.org/viewtopic.php?f=46&t=69184</a><br/>
 <a href="https://news.ycombinator.com/item?id=21563309">https://news.ycombinator.com/item?id=21563309</a><br/>
Outlook 365 Remains Top Phishing Target<br/>
 <a href="https://info.phishlabs.com/blog/active-office-365-phishing-campaign-targeting-admin-credentials">https://info.phishlabs.com/blog/active-office-365-phishing-campaign-targeting-admin-credentials</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6756" type="text/plain" language="en" />
<itunes:keywords>outlook 365, phishing, intel, firmware, updates, sms messages, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6754</itunes:episode>
<itunes:subtitle>TPM-Fail Update; Office Update Breaks Access; WhatsApp Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TPM-Fail Update; Office Update Breaks Access; WhatsApp Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6754.mp3" length="4983899" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6754.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6754</link>
<pubDate>Mon, 18 Nov 2019 03:00:04 GMT</pubDate>
<description><![CDATA[TPM Fail Update<br/>
 <a href="https://downloadcenter.intel.com/download/28632">https://downloadcenter.intel.com/download/28632</a><br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html</a><br/>
Office November Update Issues<br/>
 <a href="https://borncity.com/win/2019/11/13/office-november-2019-updates-are-causing-access-error-3340/">https://borncity.com/win/2019/11/13/office-november-2019-updates-are-causing-access-error-3340/</a><br/>
WhatsApp Stack Based Buffer Overflow<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11931">https://nvd.nist.gov/vuln/detail/CVE-2019-11931</a><br/>
Android Qualcom Data Exfiltration Bug<br/>
 <a href="https://research.checkpoint.com/the-road-to-qualcomm-trustzone-apps-fuzzing/">https://research.checkpoint.com/the-road-to-qualcomm-trustzone-apps-fuzzing/</a><br/>
Nextcloud Ransomware NextCry<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-nextcry-ransomware-encrypts-data-on-nextcloud-linux-servers/">https://www.bleepingcomputer.com/news/security/new-nextcry-ransomware-encrypts-data-on-nextcloud-linux-servers/</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6754" type="text/plain" language="en" />
<itunes:keywords>android, qualcom, nextcloud, nextcry, whatsapp, access, office, tpmfail, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6752</itunes:episode>
<itunes:subtitle>LokiBot Update; Zeek Packet-Fu; TPM Leaks; Zombieload 2.0
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LokiBot Update; Zeek Packet-Fu; TPM Leaks; Zombieload 2.0
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6752.mp3" length="6100425" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6752.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6752</link>
<pubDate>Fri, 15 Nov 2019 03:00:02 GMT</pubDate>
<description><![CDATA[LokiBot Update (November 2019)<br/>
 <a href="https://isc.sans.edu/forums/diary/An+example+of+malspam+pushing+Lokibot+malware+November+2019/25518/">https://isc.sans.edu/forums/diary/An+example+of+malspam+pushing+Lokibot+malware+November+2019/25518/</a><br/>
Some Packet-Fu with Zeek<br/>
 <a href="https://isc.sans.edu/forums/diary/Some+packetfu+with+Zeek+previously+known+as+bro/25510/">https://isc.sans.edu/forums/diary/Some+packetfu+with+Zeek+previously+known+as+bro/25510/</a><br/>
TPM Leaks<br/>
 <a href="http://tpm.fail/">http://tpm.fail/</a><br/>
Zombieload 2.0 Vulnerability<br/>
 <a href="https://zombieloadattack.com/">https://zombieloadattack.com/</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6752" type="text/plain" language="en" />
<itunes:keywords>zombieload, tpm, leak, zeek, lokibot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 13th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6750</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates; Facebook Camera "Bug"; McAfee Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Updates; Facebook Camera "Bug"; McAfee Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6750.mp3" length="5663036" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6750.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6750</link>
<pubDate>Wed, 13 Nov 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/November+2019+Microsoft+Patch+Tuesday/25516/">https://isc.sans.edu/forums/diary/November+2019+Microsoft+Patch+Tuesday/25516/</a><br/>
Adobe Update<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Facebook Camera Bug<br/>
 <a href="https://www.cnet.com/news/facebook-bug-has-camera-activated-while-people-are-using-the-app">https://www.cnet.com/news/facebook-bug-has-camera-activated-while-people-are-using-the-app</a><br/>
McAfee Anti Virus Bypass and Persistance<br/>
 <a href="https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648">https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648</a><br/>
]]></description>
<itunes:duration>6:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6750" type="text/plain" language="en" />
<itunes:keywords>mcafee, facebook, camera, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6748</itunes:episode>
<itunes:subtitle>TheMoon Still Here; Apply Magento Update; CSS Injection in Slack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TheMoon Still Here; Apply Magento Update; CSS Injection in Slack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6748.mp3" length="4838347" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6748.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6748</link>
<pubDate>Tue, 12 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Are We Going Back to TheMoon And How is Liquor Involved<br/>
 <a href="https://isc.sans.edu/forums/diary/Are+We+Going+Back+to+TheMoon+and+How+is+Liquor+Involved/25512/">https://isc.sans.edu/forums/diary/Are+We+Going+Back+to+TheMoon+and+How+is+Liquor+Involved/25512/</a><br/>
New Update for Magento Shopping Cart<br/>
 <a href="https://magento.com/security/patches/latest-magento-security-update-helps-protect-recently-reported-rce-vulnerability">https://magento.com/security/patches/latest-magento-security-update-helps-protect-recently-reported-rce-vulnerability</a><br/>
 <a href="https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update">https://magento.com/security/patches/magento-2.3.3-and-2.2.10-security-update</a><br/>
ZoneAlarm vBulletin Forum Breached<br/>
 <a href="https://thehackernews.com/2019/11/zonealarm-forum-data-breach.html">https://thehackernews.com/2019/11/zonealarm-forum-data-breach.html</a><br/>
CSS Injection in Slack to Log Keystrokes<br/>
 <a href="https://fletchto99.dev/2019/november/slack-vulnerability/">https://fletchto99.dev/2019/november/slack-vulnerability/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6748" type="text/plain" language="en" />
<itunes:keywords>slack, css, keystroke logger, vbulletin, zonealarm, magento, themoon, liquor 1.0, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6746</itunes:episode>
<itunes:subtitle>Misused MSFT Apps; Pwn2Own Summary; State of Javascript Security; Honeypot Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Misused MSFT Apps; Pwn2Own Summary; State of Javascript Security; Honeypot Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6746.mp3" length="5689362" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6746.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6746</link>
<pubDate>Mon, 11 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Applications Diverted from Their Main Use<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Apps+Diverted+from+Their+Main+Use/25502/">https://isc.sans.edu/forums/diary/Microsoft+Apps+Diverted+from+Their+Main+Use/25502/</a><br/>
Did Bluekeep Malware Afect Patching<br/>
 <a href="https://isc.sans.edu/forums/diary/Did+the+recent+malicious+BlueKeep+campaign+have+any+positive+impact+when+it+comes+to+patching/25506/">https://isc.sans.edu/forums/diary/Did+the+recent+malicious+BlueKeep+campaign+have+any+positive+impact+when+it+comes+to+patching/25506/</a><br/>
Pwn2Own Summary<br/>
 <a href="https://www.zerodayinitiative.com/blog/2019/11/7/pwn2own-tokyo-2019-day-two-final-results">https://www.zerodayinitiative.com/blog/2019/11/7/pwn2own-tokyo-2019-day-two-final-results</a><br/>
State of Javascript Framework Security<br/>
 <a href="https://snyk.io/wp-content/uploads/snyk-javascript_report_2019.pdf">https://snyk.io/wp-content/uploads/snyk-javascript_report_2019.pdf</a><br/>
DShield/ISC Honeypot Update<br/>
 <a href="https://isc.sans.edu/honeypot.html">https://isc.sans.edu/honeypot.html</a><br/>
]]></description>
<itunes:duration>6:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6746" type="text/plain" language="en" />
<itunes:keywords>snyk, javascript, jquery, pwn2own, bluekeep, microsoft, word, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6744</itunes:episode>
<itunes:subtitle>Adobe Mobile SDK; QNAP Advice; Double ZIP Files; Ring Video Doorbell
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe Mobile SDK; QNAP Advice; Double ZIP Files; Ring Video Doorbell
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6744.mp3" length="5508699" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6744.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6744</link>
<pubDate>Fri, 08 Nov 2019 03:00:05 GMT</pubDate>
<description><![CDATA[Adobe Mobile SDK Update Fixes TLS Defaults<br/>
 <a href="https://wwws.nightwatchcybersecurity.com/2019/11/06/insecure-defaults-in-adobes-mobile-sdks/">https://wwws.nightwatchcybersecurity.com/2019/11/06/insecure-defaults-in-adobes-mobile-sdks/</a><br/>
QNAP Updates QSnatch Advisory<br/>
 <a href="https://www.qnap.com/en/security-advisory/nas-201911-01">https://www.qnap.com/en/security-advisory/nas-201911-01</a><br/>
Double Loaded ZIP Files Delivery Malware<br/>
 <a href="https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/double-loaded-zip-file-delivers-nanocore/">https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/double-loaded-zip-file-delivers-nanocore/</a><br/>
Ring Video Doorbell Leaks Wifi Password<br/>
 <a href="https://labs.bitdefender.com/2019/11/ring-video-doorbell-pro-under-the-scope/">https://labs.bitdefender.com/2019/11/ring-video-doorbell-pro-under-the-scope/</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6744" type="text/plain" language="en" />
<itunes:keywords>ring, video doorbell, wifi, zip, malware, qnap, qsnatch, adobe, mobile sdk, tls, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6742</itunes:episode>
<itunes:subtitle>Google PlayStore Security; Xen and npcap Patches; TrendMicro Insider Issue; SANS Ouch Newsletter
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google PlayStore Security; Xen and npcap Patches; TrendMicro Insider Issue; SANS Ouch Newsletter
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6742.mp3" length="4474829" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6742.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6742</link>
<pubDate>Thu, 07 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Google Improving PlayStore Security With Partners<br/>
 <a href="https://security.googleblog.com/2019/11/the-app-defense-alliance-bringing.html">https://security.googleblog.com/2019/11/the-app-defense-alliance-bringing.html</a><br/>
Xen Security Advisories<br/>
 <a href="https://xenbits.xen.org/xsa/">https://xenbits.xen.org/xsa/</a><br/>
npcap pool corruption vulnerability<br/>
 <a href="https://github.com/nmap/nmap/issues/1568">https://github.com/nmap/nmap/issues/1568</a><br/>
TrendMicro Employee Selling Customer Data to Tech Support Scammers<br/>
 <a href="https://blog.trendmicro.com/trend-micro-discloses-insider-threat-impacting-some-of-its-consumer-customers/">https://blog.trendmicro.com/trend-micro-discloses-insider-threat-impacting-some-of-its-consumer-customers/</a><br/>
SANS Security Awareness Newsletter<br/>
 <a href="https://www.sans.org/security-awareness-training/resources/shopping-online-securely-1">https://www.sans.org/security-awareness-training/resources/shopping-online-securely-1</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6742" type="text/plain" language="en" />
<itunes:keywords>google, playstore, xen, npcap, trendmicro, insider, tech support scam, ouch, awareness, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 6th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6740</itunes:episode>
<itunes:subtitle>Formbook Malspam; Honeypot Update; Office on Mac Macros; libarchive bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Formbook Malspam; Honeypot Update; Office on Mac Macros; libarchive bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6740.mp3" length="5355836" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6740.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6740</link>
<pubDate>Wed, 06 Nov 2019 03:00:05 GMT</pubDate>
<description><![CDATA[Formbook Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/23387/">https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/23387/</a><br/>
Honeypot Update<br/>
 <a href="https://github.com/DShield-ISC/dshield">https://github.com/DShield-ISC/dshield</a><br/>
Office on Mac XLM Macros<br/>
 <a href="https://kb.cert.org/vuls/id/125336/">https://kb.cert.org/vuls/id/125336/</a><br/>
Firefox Browser Lock Bug Exploited<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1593795">https://bugzilla.mozilla.org/show_bug.cgi?id=1593795</a><br/>
libarchive use after free vulnerability<br/>
 <a href="https://medium.com/@social_62682/new-libarchive-use-after-free-vulnerability-36c4b141fe89">https://medium.com/@social_62682/new-libarchive-use-after-free-vulnerability-36c4b141fe89</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6740" type="text/plain" language="en" />
<itunes:keywords>libarchive, Firefox, office on mac, excel, xlm, macros, honeypot, formbook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 5th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6738</itunes:episode>
<itunes:subtitle>Bluekeep Exploit Update; ClamAV Vuln; XCode Patch; MikroTik DNS Cache Poison
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bluekeep Exploit Update; ClamAV Vuln; XCode Patch; MikroTik DNS Cache Poison
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6738.mp3" length="5304267" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6738.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6738</link>
<pubDate>Tue, 05 Nov 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Clam AV Vulnerability<br/>
 <a href="https://twitter.com/hackerfantastic/status/1190685521153937408">https://twitter.com/hackerfantastic/status/1190685521153937408</a><br/>
 <a href="https://pastebin.com/cfP7X89m">https://pastebin.com/cfP7X89m</a><br/>
XCode Vulnerability<br/>
 <a href="https://support.apple.com/en-is/HT210729">https://support.apple.com/en-is/HT210729</a><br/>
MikroTik DNS Cache Poisoning<br/>
 <a href="https://blog.mikrotik.com/security/dns-cache-poisoning-vulnerability.html">https://blog.mikrotik.com/security/dns-cache-poisoning-vulnerability.html</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6738" type="text/plain" language="en" />
<itunes:keywords>xcode, microtik, dns cache poisoning, dns, clamav, clambc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6736</itunes:episode>
<itunes:subtitle>Chrome Update; BlueKeep Mass Exploit; Unpached rConfig RCE (exploited, but maybe not a big deal)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chrome Update; BlueKeep Mass Exploit; Unpached rConfig RCE (exploited, but maybe not a big deal)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6736.mp3" length="5032539" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6736.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6736</link>
<pubDate>Mon, 04 Nov 2019 03:44:56 GMT</pubDate>
<description><![CDATA[Critical Google Chrome Update Fixes Exploited Vulnerability<br/>
 <a href="https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html">https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html</a><br/>
Blue Keep Vulnerability Mass Exploited to Install Crypto Coin Miner<br/>
 <a href="https://www.kryptoslogic.com/blog/2019/11/bluekeep-cve-2019-0708-exploitation-spotted-in-the-wild/">https://www.kryptoslogic.com/blog/2019/11/bluekeep-cve-2019-0708-exploitation-spotted-in-the-wild/</a><br/>
rConfig Vulnerabilities<br/>
 <a href="https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/">https://shells.systems/rconfig-v3-9-2-authenticated-and-unauthenticated-rce-cve-2019-16663-and-cve-2019-16662/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6736" type="text/plain" language="en" />
<itunes:keywords>rconfig, blue keep, google chrome update, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 1st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6734</itunes:episode>
<itunes:subtitle>EML O365 Phishing; MSFT TLS Timeouts; MESSAGETAP; Amazon 3rd Party Device Auth Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
EML O365 Phishing; MSFT TLS Timeouts; MESSAGETAP; Amazon 3rd Party Device Auth Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6734.mp3" length="4935259" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6734.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6734</link>
<pubDate>Fri, 01 Nov 2019 03:00:04 GMT</pubDate>
<description><![CDATA[Phishing Made Easy With EML Files and Outlook 365<br/>
 <a href="https://isc.sans.edu/forums/diary/EML+attachments+in+O365+a+recipe+for+phishing/25474/">https://isc.sans.edu/forums/diary/EML+attachments+in+O365+a+recipe+for+phishing/25474/</a><br/>
Microsoft TLS Security Enhancements Lead to Timeouts<br/>
 <a href="https://support.microsoft.com/en-us/help/4528489/transport-layer-security-tls-connections-might-intermittently-fail-or">https://support.microsoft.com/en-us/help/4528489/transport-layer-security-tls-connections-might-intermittently-fail-or</a><br/>
 <br/>
MESSAGETAP: Who's Reading Your Text Messages<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2019/10/messagetap-who-is-reading-your-text-messages.html">https://www.fireeye.com/blog/threat-research/2019/10/messagetap-who-is-reading-your-text-messages.html</a><br/>
Amazon Authentication Failure for 3rd Party Devices<br/>
 <a href="https://old.reddit.com/r/sysadmin/comments/dpbt3t/the_perils_of_security_and_how_i_finally_resolved/">https://old.reddit.com/r/sysadmin/comments/dpbt3t/the_perils_of_security_and_how_i_finally_resolved/</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6734" type="text/plain" language="en" />
<itunes:keywords>amazon, oauth2, messagetap, microsoft, tls, phishing, outlook 365, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 31st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6732</itunes:episode>
<itunes:subtitle>Apple Updates; Untitled Goose; Pagers in Medicine; Kibana Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Untitled Goose; Pagers in Medicine; Kibana Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6732.mp3" length="5520054" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6732.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6732</link>
<pubDate>Thu, 31 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Apple Security Updates Details Released<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Untitled Goose Deserialization<br/>
 <a href="https://pulsesecurity.co.nz/advisories/untitled-goose-game-deserialization">https://pulsesecurity.co.nz/advisories/untitled-goose-game-deserialization</a><br/>
Insecure Pagers Leak Medical Data<br/>
 <a href="https://techcrunch.com/2019/10/30/nhs-pagers-medical-health-data/">https://techcrunch.com/2019/10/30/nhs-pagers-medical-health-data/</a><br/>
Kibana Vulnerablity <br/>
 <a href="https://research.securitum.com/prototype-pollution-rce-kibana-cve-2019-7609/">https://research.securitum.com/prototype-pollution-rce-kibana-cve-2019-7609/</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6732" type="text/plain" language="en" />
<itunes:keywords>kibana, pagers, medical data, untitled goose, deserialization, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6730</itunes:episode>
<itunes:subtitle>xHelper Update; Counterstrike Money Laundry; PCAPs from YAML
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
xHelper Update; Counterstrike Money Laundry; PCAPs from YAML
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6730.mp3" length="4713290" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6730.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6730</link>
<pubDate>Wed, 30 Oct 2019 03:00:04 GMT</pubDate>
<description><![CDATA[xHelper Android Malware<br/>
 <a href="https://www.symantec.com/blogs/threat-intelligence/xhelper-android-malware">https://www.symantec.com/blogs/threat-intelligence/xhelper-android-malware</a><br/>
Counterstrike Game Keys Used for Money Laundry<br/>
 <a href="https://blog.counter-strike.net/index.php/2019/10/26113/">https://blog.counter-strike.net/index.php/2019/10/26113/</a><br/>
Greating PCAP Files From YAML<br/>
 <a href="https://isc.sans.edu/forums/diary/Generating+PCAP+Files+from+YAML/25464/">https://isc.sans.edu/forums/diary/Generating+PCAP+Files+from+YAML/25464/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6730" type="text/plain" language="en" />
<itunes:keywords>pcap, yaml, pcraft, counterstrike, game keys, xhelper, android, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 29th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6728</itunes:episode>
<itunes:subtitle>PHP 7 RCE Exploited; Finding Shellcode; iOS/tvOS/Safari Updates; Sextortion Blogs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PHP 7 RCE Exploited; Finding Shellcode; iOS/tvOS/Safari Updates; Sextortion Blogs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6728.mp3" length="4052806" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6728.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6728</link>
<pubDate>Tue, 29 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[PHP 7 Remote Code Execution Vulnerability Exploited<br/>
 <a href="https://lab.wallarm.com/php-remote-code-execution-0-day-discovered-in-real-world-ctf-exercise/">https://lab.wallarm.com/php-remote-code-execution-0-day-discovered-in-real-world-ctf-exercise/</a><br/>
 <a href="https://github.com/neex/phuip-fpizdam">https://github.com/neex/phuip-fpizdam</a><br/>
Finding Shellcode with scdbg<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+scdbg+to+Find+Shellcode/25460/">https://isc.sans.edu/forums/diary/Using+scdbg+to+Find+Shellcode/25460/</a><br/>
Apple iOS / tvOS / Safari Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Sextortion Attempts Are Targeting Blogs<br/>
 <a href="https://www.bleepingcomputer.com/news/security/blogger-and-wordpress-sites-hacked-to-show-sextortion-scams/">https://www.bleepingcomputer.com/news/security/blogger-and-wordpress-sites-hacked-to-show-sextortion-scams/</a><br/>
]]></description>
<itunes:duration>4:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6728" type="text/plain" language="en" />
<itunes:keywords>sextortion, wordpress, blogger, php7, nginx, fpm, scdbg, apple, ios, tvos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 28th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6726</itunes:episode>
<itunes:subtitle>Odd Double Base64 Header; Parsing DNS Logs in PS; iOS Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd Double Base64 Header; Parsing DNS Logs in PS; iOS Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6726.mp3" length="4893931" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6726.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6726</link>
<pubDate>Mon, 28 Oct 2019 03:45:03 GMT</pubDate>
<description><![CDATA[Odd Double Base64 Endoded "BS_REAL_IP" Header<br/>
 <a href="https://isc.sans.edu/forums/diary/Unusual+Activity+with+Double+Base64+Encoding/25458/">https://isc.sans.edu/forums/diary/Unusual+Activity+with+Double+Base64+Encoding/25458/</a><br/>
DNS Archeology With PowerShell<br/>
 <a href="https://isc.sans.edu/forums/diary/More+on+DNS+Archeology+with+PowerShell/25452/">https://isc.sans.edu/forums/diary/More+on+DNS+Archeology+with+PowerShell/25452/</a><br/>
iOS Appstore Malware<br/>
 <a href="https://www.wandera.com/mobile-security/ios-trojan-malware/">https://www.wandera.com/mobile-security/ios-trojan-malware/</a><br/>
British Law Enforcement Misses Malware Reports Due to Anti-Malware<br/>
 <a href="https://www.theregister.co.uk/2019/10/24/hmicfrs_report_cyber_crime/">https://www.theregister.co.uk/2019/10/24/hmicfrs_report_cyber_crime/</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6726" type="text/plain" language="en" />
<itunes:keywords>malware, law enforcement, england, dns, ios, powershell, windows, bs_real_ip, base64, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6724</itunes:episode>
<itunes:subtitle>XXE Vuln in LSP4XML (VS Code); Google Chrome SameSite Changes; Gigamon Leftovers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XXE Vuln in LSP4XML (VS Code); Google Chrome SameSite Changes; Gigamon Leftovers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6724.mp3" length="5823211" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6724.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6724</link>
<pubDate>Fri, 25 Oct 2019 04:45:03 GMT</pubDate>
<description><![CDATA[XML External Entity Vuln in LSP4XML Affects Various Developer Tools<br/>
 <a href="https://www.shielder.it/blog/dont-open-that-xml-xxe-to-rce-in-xml-plugins-for-vs-code-eclipse-theia/?preview=true">https://www.shielder.it/blog/dont-open-that-xml-xxe-to-rce-in-xml-plugins-for-vs-code-eclipse-theia/?preview=true</a><br/>
Google Chrome Will Make "SameSite" Default<br/>
 <a href="https://blog.chromium.org/2019/10/developers-get-ready-for-new.html">https://blog.chromium.org/2019/10/developers-get-ready-for-new.html</a><br/>
Leftover Gigamon Configurations<br/>
 <a href="https://isc.sans.edu/forums/diary/Your+Supply+Chain+Doesnt+End+At+Receiving+How+Do+You+Decommission+Network+Equipment/25448/">https://isc.sans.edu/forums/diary/Your+Supply+Chain+Doesnt+End+At+Receiving+How+Do+You+Decommission+Network+Equipment/25448/</a><br/>
]]></description>
<itunes:duration>6:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6724" type="text/plain" language="en" />
<itunes:keywords>gigamon, google, chrome, samesite, xml, xxe, lsp4xml, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 24th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6722</itunes:episode>
<itunes:subtitle>SIM Swapping; Discord Infostealer; Cisco Exploit Code; Tails 4.0 Released
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SIM Swapping; Discord Infostealer; Cisco Exploit Code; Tails 4.0 Released
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6722.mp3" length="4256861" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6722.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6722</link>
<pubDate>Thu, 24 Oct 2019 03:45:02 GMT</pubDate>
<description><![CDATA[FTC Issues SIM Swapping Guidance<br/>
 <a href="https://www.consumer.ftc.gov/blog/2019/10/sim-swap-scams-how-protect-yourself">https://www.consumer.ftc.gov/blog/2019/10/sim-swap-scams-how-protect-yourself</a><br/>
Discord Used as Info Stealer Backdoor<br/>
 <a href="https://www.bleepingcomputer.com/news/security/discord-turned-into-an-info-stealing-backdoor-by-new-malware/">https://www.bleepingcomputer.com/news/security/discord-turned-into-an-info-stealing-backdoor-by-new-malware/</a><br/>
Cisco Exploit Code<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass</a><br/>
Tails 4.0 Released <br/>
 <a href="https://tails.boum.org/news/version_4.0/index.en.html">https://tails.boum.org/news/version_4.0/index.en.html</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6722" type="text/plain" language="en" />
<itunes:keywords>tails 4.0, privacy, cisco, discord, electron, javascript, SIM swapping, ftc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6720</itunes:episode>
<itunes:subtitle>Testing TLS 1.3; Firefox/Chrome Updates; Cache Poisoning DoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Testing TLS 1.3; Firefox/Chrome Updates; Cache Poisoning DoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6720.mp3" length="6023263" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6720.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6720</link>
<pubDate>Wed, 23 Oct 2019 03:45:02 GMT</pubDate>
<description><![CDATA[Testing TLS 1.3 And Supported Ciphers<br/>
 <a href="https://isc.sans.edu/forums/diary/Testing+TLSv13+and+supported+ciphers/25442/">https://isc.sans.edu/forums/diary/Testing+TLSv13+and+supported+ciphers/25442/</a><br/>
Google Chrome 78 Released <br/>
 <a href="https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.html">https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.html</a><br/>
Firefox 70 Released<br/>
 <a href="https://www.mozilla.org/en-US/firefox/70.0/releasenotes/">https://www.mozilla.org/en-US/firefox/70.0/releasenotes/</a><br/>
Cache Poisoning DoS<br/>
 <a href="https://cpdos.org/">https://cpdos.org/</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6720" type="text/plain" language="en" />
<itunes:keywords>cache poisoning, cpdos, dos, proxy, firefox, google, chrome, mozilla, tls 1.3, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6718</itunes:episode>
<itunes:subtitle>DNS over TLS Scans; North/Thor/Viking/VPN Compromises; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS over TLS Scans; North/Thor/Viking/VPN Compromises; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6718.mp3" length="4796288" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6718.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6718</link>
<pubDate>Tue, 22 Oct 2019 04:35:02 GMT</pubDate>
<description><![CDATA[DNS over TLS Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Whats+up+with+TCP+853+DNS+over+TLS/25438/">https://isc.sans.edu/forums/diary/Whats+up+with+TCP+853+DNS+over+TLS/25438/</a><br/>
NordVPN and Others Compromised<br/>
 <a href="https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-hacked/">https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-hacked/</a><br/>
 <a href="https://twitter.com/hexdefined/status/1186106695073726466">https://twitter.com/hexdefined/status/1186106695073726466</a><br/>
Trend Micro Bypass<br/>
 <a href="http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-ANTI-THREAT-TOOLKIT-(ATTK)-REMOTE-CODE-EXECUTION.txt">http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-ANTI-THREAT-TOOLKIT-(ATTK)-REMOTE-CODE-EXECUTION.txt</a><br/>
Realtek Linux Wifi Driver Buffer Overflow<br/>
 <a href="https://twitter.com/nicowaisman/status/1184864519316758535">https://twitter.com/nicowaisman/status/1184864519316758535</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6718" type="text/plain" language="en" />
<itunes:keywords>realtek, wifi, trend micro, attk, vpn, nordvpn, vikingvpn, dns over tls, dot, scans, 853, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6716</itunes:episode>
<itunes:subtitle>Attacks Against NVMS-9000 DVR; Pixel 4 / Galaxy S10 Biometrics; Home Speaker Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Attacks Against NVMS-9000 DVR; Pixel 4 / Galaxy S10 Biometrics; Home Speaker Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6716.mp3" length="5789200" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6716.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6716</link>
<pubDate>Mon, 21 Oct 2019 03:36:42 GMT</pubDate>
<description><![CDATA[Attacks Against NVMS-9000 DVR Web Vulnerability <br/>
 <a href="https://isc.sans.edu/forums/diary/Scanning+Activity+for+NVMS9000+Digital+Video+Recorder/25434/">https://isc.sans.edu/forums/diary/Scanning+Activity+for+NVMS9000+Digital+Video+Recorder/25434/</a><br/>
Pixel 4 Face Unlock Works with Eyes Shut<br/>
 <a href="https://www.bbc.com/news/technology-50085630">https://www.bbc.com/news/technology-50085630</a><br/>
Samsung Galaxy S10 Fingerprint Unlock Bug<br/>
 <a href="https://www.bbc.com/news/technology-50080586">https://www.bbc.com/news/technology-50080586</a><br/>
Alexa/Google Home Phishing<br/>
 <a href="https://srlabs.de/bites/smart-spies/">https://srlabs.de/bites/smart-spies/</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6716" type="text/plain" language="en" />
<itunes:keywords>Alexa, Google Home, Phishing, Samsung, galaxy, s10, fingerprint, biometrics, pixel 4, sleeping, face recognition, nvms-9000, dvr, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6714</itunes:episode>
<itunes:subtitle>Bypassing SPF Records; Old Domain Paypal Accounts; Typosquatting 2020 Election; @sans_edu interview
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bypassing SPF Records; Old Domain Paypal Accounts; Typosquatting 2020 Election; @sans_edu interview
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6714.mp3" length="14030206" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6714.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6714</link>
<pubDate>Fri, 18 Oct 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Phishing E-Mail Spoofing SPF Protected Domain<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+email+spoofing+SPFenabled+domain/25426/">https://isc.sans.edu/forums/diary/Phishing+email+spoofing+SPFenabled+domain/25426/</a><br/>
Purchased Domain Arrives with Paypal Accounts Linked to it<br/>
 <a href="https://www.theregister.co.uk/2019/10/17/paypal_account_domain/">https://www.theregister.co.uk/2019/10/17/paypal_account_domain/</a><br/>
Typosquatting Attacks Affect 2020 Presidential Election<br/>
 <a href="https://www.digitalshadows.com/blog-and-research/typosquatting-and-the-2020-u-s-presidential-election/">https://www.digitalshadows.com/blog-and-research/typosquatting-and-the-2020-u-s-presidential-election/</a><br/>
STI Student: Christopher Hurless Exploring Osquery, Fleet, and Elastic Stack as an Open-source solution to Endpoint Detection and Response<br/>
<a href="https://www.sans.org/reading-room/whitepapers/detection/paper/39165">https://www.sans.org/reading-room/whitepapers/detection/paper/39165</a><br/>
]]></description>
<itunes:duration>16:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6714" type="text/plain" language="en" />
<itunes:keywords>sans_edu, interview, student, osquery, fleet, elastic, typosquatting, 2020 election, paypal, domain, phishing, spf, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6712</itunes:episode>
<itunes:subtitle>Oracle CPU; jackson-databind vulnerability; VMWare; Wordpress
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oracle CPU; jackson-databind vulnerability; VMWare; Wordpress
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6712.mp3" length="4649638" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6712.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6712</link>
<pubDate>Thu, 17 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Oracle CPU<br/>
 <a href="https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html">https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html</a><br/>
Jackson-Databind Vulnerablity<br/>
 <a href="https://github.com/FasterXML/jackson-databind/issues/2387">https://github.com/FasterXML/jackson-databind/issues/2387</a><br/>
VMWare Cloud Foundation and VMware Harbor Container Registry Patch<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2019-0016.html">https://www.vmware.com/security/advisories/VMSA-2019-0016.html</a><br/>
Wordpress Update<br/>
 <a href="https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/">https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/</a><br/>
Cryptominers Hiding in WAV Files<br/>
 <a href="https://threatvector.cylance.com/en_us/home/malicious-payloads-hiding-beneath-the-wav.html">https://threatvector.cylance.com/en_us/home/malicious-payloads-hiding-beneath-the-wav.html</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6712" type="text/plain" language="en" />
<itunes:keywords>oracle, cpu, jackson-databind, vmware, wordpress, wav files, cryptominers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6710</itunes:episode>
<itunes:subtitle>Adobe Updates; Symantec BSDO; OSX Shlayer/Tarmac; Fake iOS Jailbreak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe Updates; Symantec BSDO; OSX Shlayer/Tarmac; Fake iOS Jailbreak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6710.mp3" length="4617457" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6710.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6710</link>
<pubDate>Wed, 16 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Symantec BSOD<br/>
 <a href="https://support.symantec.com/us/en/article.TECH256643.html">https://support.symantec.com/us/en/article.TECH256643.html</a><br/>
OSX/Shlayer Bypasses Gatekeeper/XProtect<br/>
 <a href="https://blog.confiant.com/osx-shlayer-new-shurprise-unveiling-osx-tarmac-f965a32de887">https://blog.confiant.com/osx-shlayer-new-shurprise-unveiling-osx-tarmac-f965a32de887</a><br/>
Fake iOS Jailbreak Leads to Clickfraud<br/>
 <a href="https://blog.talosintelligence.com/2019/10/checkrain-click-fraud.html">https://blog.talosintelligence.com/2019/10/checkrain-click-fraud.html</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6710" type="text/plain" language="en" />
<itunes:keywords>ios, jailbreak, clickfraud, checkrain, shlayer, gatekeeper, xprotect, adobe, symantec, bsod, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6708</itunes:episode>
<itunes:subtitle>Sudo Vulnerablity; Apple Safebrowsing; Streaming Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sudo Vulnerablity; Apple Safebrowsing; Streaming Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6708.mp3" length="5096539" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6708.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6708</link>
<pubDate>Tue, 15 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[sudo vulnerability<br/>
 <a href="https://www.sudo.ws/alerts/minus_1_uid.html">https://www.sudo.ws/alerts/minus_1_uid.html</a><br/>
Apple Safebrowsing Controversy<br/>
 <a href="https://blog.cryptographyengineering.com/2019/10/13/dear-apple-safe-browsing-might-not-be-that-safe/">https://blog.cryptographyengineering.com/2019/10/13/dear-apple-safe-browsing-might-not-be-that-safe/</a><br/>
Streaming Service Tracking Behaviour<br/>
 <a href="https://www.princeton.edu/~pmittal/publications/tv-tracking-ccs19.pdf">https://www.princeton.edu/~pmittal/publications/tv-tracking-ccs19.pdf</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6708" type="text/plain" language="en" />
<itunes:keywords>roku, amazon fire, tracking, streaming, safebrowsing, apple, sudo, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 14th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6706</itunes:episode>
<itunes:subtitle>YARA Update; Hacking Back Against Ransomware; Fake Crypto Trading Software
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
YARA Update; Hacking Back Against Ransomware; Fake Crypto Trading Software
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6706.mp3" length="3048903" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6706.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6706</link>
<pubDate>Mon, 14 Oct 2019 03:00:02 GMT</pubDate>
<description><![CDATA[YARA Update<br/>
 <a href="https://isc.sans.edu/forums/diary/YARA+v3110+released/25408/">https://isc.sans.edu/forums/diary/YARA+v3110+released/25408/</a><br/>
Hacking Back Against Ransomware<br/>
 <a href="https://www.zdnet.com/article/white-hat-hacks-muhstik-ransomware-gang-and-releases-decryption-keys/">https://www.zdnet.com/article/white-hat-hacks-muhstik-ransomware-gang-and-releases-decryption-keys/</a><br/>
Fake Crypto Trading Software<br/>
 <a href="https://www.bleepingcomputer.com/news/security/attackers-create-elaborate-crypto-trading-scheme-to-install-malware/">https://www.bleepingcomputer.com/news/security/attackers-create-elaborate-crypto-trading-scheme-to-install-malware/</a><br/>
]]></description>
<itunes:duration>3:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6706" type="text/plain" language="en" />
<itunes:keywords>crypto trading, hacking back, ransomware, muhstik, yara, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6704</itunes:episode>
<itunes:subtitle>OUI Mining; iTerm2 Vuln; Apple Updater Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OUI Mining; iTerm2 Vuln; Apple Updater Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6704.mp3" length="5254891" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6704.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6704</link>
<pubDate>Fri, 11 Oct 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Mining Live Networks for OUI Data Oddness<br/>
 <a href="https://isc.sans.edu/forums/diary/Mining+Live+Networks+for+OUI+Data+Oddness/25404/">https://isc.sans.edu/forums/diary/Mining+Live+Networks+for+OUI+Data+Oddness/25404/</a><br/>
iTerm2 Vulnerability<br/>
 <a href="https://groups.google.com/forum/#!topic/iterm2-discuss/57k_AuLdQa4">https://groups.google.com/forum/#!topic/iterm2-discuss/57k_AuLdQa4</a><br/>
Apple Updater Exploited in Bitpaymer Campaign<br/>
<a href="https://blog.morphisec.com/apple-zero-day-exploited-in-bitpaymer-campaign">https://blog.morphisec.com/apple-zero-day-exploited-in-bitpaymer-campaign</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6704" type="text/plain" language="en" />
<itunes:keywords>oui, ethernet, mac, iterm2, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6702</itunes:episode>
<itunes:subtitle>Vidar Malware Analysis; NTLM MIC Bypass; Threats on Google Play Store
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Vidar Malware Analysis; NTLM MIC Bypass; Threats on Google Play Store
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6702.mp3" length="4701570" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6702.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6702</link>
<pubDate>Thu, 10 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[What Data Does Vidar Malware Steal<br/>
 <a href="https://isc.sans.edu/forums/diary/What+data+does+Vidar+malware+steal+from+an+infected+host/25398/">https://isc.sans.edu/forums/diary/What+data+does+Vidar+malware+steal+from+an+infected+host/25398/</a><br/>
NTLM MIC Bypass<br/>
 <a href="https://www.preempt.com/blog/drop-the-mic-2-active-directory-open-to-more-ntlm-attacks/">https://www.preempt.com/blog/drop-the-mic-2-active-directory-open-to-more-ntlm-attacks/</a><br/>
Threats on Google Play<br/>
 <a href="https://news.drweb.com/show/review/?i=13446#google">https://news.drweb.com/show/review/?i=13446#google</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6702" type="text/plain" language="en" />
<itunes:keywords>google play, mic, ntlm, relay attack, vidar, infostealer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6700</itunes:episode>
<itunes:subtitle>MSFT Patches; Android Patches; vBulletin Patches 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patches; Android Patches; vBulletin Patches 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6700.mp3" length="4522006" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6700.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6700</link>
<pubDate>Wed, 09 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+October+2019+Patch+Tuesday/25396/">https://isc.sans.edu/forums/diary/Microsoft+October+2019+Patch+Tuesday/25396/</a><br/>
Android Update<br/>
 <a href="https://source.android.com/security/bulletin/2019-10-01">https://source.android.com/security/bulletin/2019-10-01</a><br/>
vBulletin Update<br/>
 <a href="https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2">https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4423646-vbulletin-5-5-x-5-5-2-5-5-3-and-5-5-4-security-patch-level-2</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6700" type="text/plain" language="en" />
<itunes:keywords>vbulletin, android, update, patches, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6698</itunes:episode>
<itunes:subtitle>2xVPN=0VPN; WhatsApp GIF Bug; MacOS Catalina; Magecart Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
2xVPN=0VPN; WhatsApp GIF Bug; MacOS Catalina; Magecart Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6698.mp3" length="5053750" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6698.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6698</link>
<pubDate>Tue, 08 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Cloudflare Warp + NordVPN on iOS Leads to Traffic in the Clear<br/>
 <a href="https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/">https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/</a><br/>
WhatsApp Bug<br/>
 <a href="https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/">https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/</a><br/>
MacOS Catalina and Safari Update Released<br/>
 <a href="https://www.macrumors.com/2019/10/07/apple-releases-macos-catalina/">https://www.macrumors.com/2019/10/07/apple-releases-macos-catalina/</a><br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a> (nothing new yet)<br/>
Magecart Still Going Strong<br/>
 <a href="https://www.theregister.co.uk/2019/10/04/magecart/">https://www.theregister.co.uk/2019/10/04/magecart/</a><br/>
 (original RiskIQ report requires Registration)<br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6698" type="text/plain" language="en" />
<itunes:keywords>magecart, macos, catalina, whatsapp, cloudflare, nordvpn, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6696</itunes:episode>
<itunes:subtitle>R and visNetwork; Android Priv. Escalation Exploited; Signal Evesdropping
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
R and visNetwork; Android Priv. Escalation Exploited; Signal Evesdropping
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6696.mp3" length="4471166" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6696.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6696</link>
<pubDate>Mon, 07 Oct 2019 03:00:02 GMT</pubDate>
<description><![CDATA[visNetwork for Network Data<br/>
 <a href="https://isc.sans.edu/forums/diary/visNetwork+for+Network+Data/25390/">https://isc.sans.edu/forums/diary/visNetwork+for+Network+Data/25390/</a><br/>
Android Priv. Escalation Vulnerability Exploited in the Wild<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1942">https://bugs.chromium.org/p/project-zero/issues/detail?id=1942</a><br/>
Signal Evesdropping Vulnerability<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1943">https://bugs.chromium.org/p/project-zero/issues/detail?id=1943</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6696" type="text/plain" language="en" />
<itunes:keywords>signal, android, evesdropping, priviledge escalation, nso group, R, visnetwork, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6694</itunes:episode>
<itunes:subtitle>Lost Files Ransomware; tcpdump vulnerabilities; Reductor Malware; Pass The Hash @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Lost Files Ransomware; tcpdump vulnerabilities; Reductor Malware; Pass The Hash @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6694.mp3" length="12761543" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6694.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6694</link>
<pubDate>Fri, 04 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Last Files Ransomware is Back With New Ruse<br/>
 <a href="https://isc.sans.edu/forums/diary/LostFiles+Ransomware/25382/">https://isc.sans.edu/forums/diary/LostFiles+Ransomware/25382/</a><br/>
tcpdump vulnerabilities<br/>
 <a href="https://www.tcpdump.org/tcpdump-changes.txt">https://www.tcpdump.org/tcpdump-changes.txt</a><br/>
TLS Manipulating Malware<br/>
 <a href="https://securelist.com/compfun-successor-reductor/93633/">https://securelist.com/compfun-successor-reductor/93633/</a><br/>
Luasz Cyra: Pass the Hash in Windows 10<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/testing/paper/39170">https://www.sans.org/reading-room/whitepapers/testing/paper/39170</a><br/>
]]></description>
<itunes:duration>15:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6694" type="text/plain" language="en" />
<itunes:keywords>pass the hash, windows 10, tls, reductor, tcpdump, ransomware, last files, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6692</itunes:episode>
<itunes:subtitle>Latest Emotet News; Ouch! Newsletter; XPdf/Foxit Updates; eFax Malspam
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Latest Emotet News; Ouch! Newsletter; XPdf/Foxit Updates; eFax Malspam
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6692.mp3" length="4462758" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6692.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6692</link>
<pubDate>Thu, 03 Oct 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Latest Emotet News<br/>
 <a href="https://isc.sans.edu/forums/diary/A+recent+example+of+Emotet+malspam/25378/">https://isc.sans.edu/forums/diary/A+recent+example+of+Emotet+malspam/25378/</a><br/>
SANS Ouch! Newsletter<br/>
 <a href="https://www.sans.org/security-awareness-training/resources/four-simple-steps-staying-secure">https://www.sans.org/security-awareness-training/resources/four-simple-steps-staying-secure</a><br/>
XPdf and Foxit Updates<br/>
 <a href="https://www.foxitsoftware.com/support/security-bulletins.php">https://www.foxitsoftware.com/support/security-bulletins.php</a><br/>
 <a href="https://forum.xpdfreader.com/viewtopic.php?f=3&t=41885">https://forum.xpdfreader.com/viewtopic.php?f=3&t=41885</a><br/>
eFax Malspam<br/>
 <a href="https://www.heise.de/security/meldung/Achtung-Angebliches-eFax-birgt-Trojaner-4544386.html">https://www.heise.de/security/meldung/Achtung-Angebliches-eFax-birgt-Trojaner-4544386.html</a><br/>
Office 365 Idle Timeout<br/>
 <a href="https://docs.microsoft.com/en-us/sharepoint/sign-out-inactive-users">https://docs.microsoft.com/en-us/sharepoint/sign-out-inactive-users</a><br/>
 <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=55183">https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=55183</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6692" type="text/plain" language="en" />
<itunes:keywords>office 365, timeout, efax, spam, malspam, xpdf, foxit, ouch, awareness, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6690</itunes:episode>
<itunes:subtitle>PDF Encryption Flaw; Windows 7 Security Extended Updates; ODT Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF Encryption Flaw; Windows 7 Security Extended Updates; ODT Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6690.mp3" length="5106417" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6690.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6690</link>
<pubDate>Wed, 02 Oct 2019 03:00:03 GMT</pubDate>
<description><![CDATA[PDF Encryption Flaw<br/>
 <a href="https://web-in-security.blogspot.com/2019/09/pdfex-major-security-flaws-in-pdf.html">https://web-in-security.blogspot.com/2019/09/pdfex-major-security-flaws-in-pdf.html</a><br/>
Windows 7 Security Updates Beyond 2020<br/>
 <a href="https://www.microsoft.com/en-us/microsoft-365/blog/2019/10/01/windows-small-midsize-businesses-stay-secure-current/">https://www.microsoft.com/en-us/microsoft-365/blog/2019/10/01/windows-small-midsize-businesses-stay-secure-current/</a><br/>
ODT Documents Used to Distribute Malware<br/>
 <a href="https://blog.talosintelligence.com/2019/09/odt-malware-twist.html">https://blog.talosintelligence.com/2019/09/odt-malware-twist.html</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6690" type="text/plain" language="en" />
<itunes:keywords>ODT, Documents, Malware, Talos, Windows 7, PDF, encryption, PDFex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 1st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6688</itunes:episode>
<itunes:subtitle>Maldoc, Powershell and BITS; Cisco Patch Cycle; Exim Flaw
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Maldoc, Powershell and BITS; Cisco Patch Cycle; Exim Flaw
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6688.mp3" length="4097773" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6688.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6688</link>
<pubDate>Tue, 01 Oct 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Maldoc, PowerShell and BITS<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+PowerShell+BITS/25372/">https://isc.sans.edu/forums/diary/Maldoc+PowerShell+BITS/25372/</a><br/>
Yet Another Critical Exim Flaw<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16928">https://nvd.nist.gov/vuln/detail/CVE-2019-16928</a><br/>
CISCO Introduces Semianual Patch Day<br/>
 <a href="https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-72547">https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-72547</a><br/>
Windows 2019 to make it easier to disable legacy TLS Versions<br/>
 <a href="https://www.microsoft.com/security/blog/2019/09/30/tls-version-enforcement-capabilities-now-available-certificate-binding-windows-server-2019">https://www.microsoft.com/security/blog/2019/09/30/tls-version-enforcement-capabilities-now-available-certificate-binding-windows-server-2019</a><br/>
]]></description>
<itunes:duration>4:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6688" type="text/plain" language="en" />
<itunes:keywords>Windows Server 2019, TLS, Cisco, Exim, Maldoc, powershell, bits, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6686</itunes:episode>
<itunes:subtitle>Polycom Scans; Apple Security Details; iOS Jail Break
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Polycom Scans; Apple Security Details; iOS Jail Break
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6686.mp3" length="4941112" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6686.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6686</link>
<pubDate>Mon, 30 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Polycom Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Scans+for+Polycom+Autoconfiguration+Files/25366/">https://isc.sans.edu/forums/diary/New+Scans+for+Polycom+Autoconfiguration+Files/25366/</a><br/>
Apple Security Details<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
iOS Jailbreak<br/>
 <a href="https://github.com/axi0mX/ipwndfu">https://github.com/axi0mX/ipwndfu</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6686" type="text/plain" language="en" />
<itunes:keywords>ios, apple, macos, jailbreak, patches, polycom, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 27th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6684</itunes:episode>
<itunes:subtitle>vBulletin Botnet; Cisco Patches; Sniffle BT Sniffer; OWA Blocking Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
vBulletin Botnet; Cisco Patches; Sniffle BT Sniffer; OWA Blocking Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6684.mp3" length="4761181" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6684.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6684</link>
<pubDate>Fri, 27 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[vBulletin Botnet<br/>
 <a href="https://twitter.com/bad_packets/status/1177256656322695168">https://twitter.com/bad_packets/status/1177256656322695168</a><br/>
Cisco Industrial Router Security Bulletin<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ios-gos-auth</a><br/>
Sniffle Bluetooth Sniffer<br/>
 <a href="https://github.com/nccgroup/sniffle">https://github.com/nccgroup/sniffle</a><br/>
Outlook on the web blocking more extensions<br/>
 <a href="https://techcommunity.microsoft.com/t5/Exchange-Team-Blog/Changes-to-File-Types-Blocked-in-Outlook-on-the-web/ba-p/874451">https://techcommunity.microsoft.com/t5/Exchange-Team-Blog/Changes-to-File-Types-Blocked-in-Outlook-on-the-web/ba-p/874451</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6684" type="text/plain" language="en" />
<itunes:keywords>outlook, extensions, owa, sniffle, cisco, router, security, vbulletin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6682</itunes:episode>
<itunes:subtitle>Malspam Pushing Quasar; vBulletin Patch; Fake Veteran Employment Site
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malspam Pushing Quasar; vBulletin Patch; Fake Veteran Employment Site
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6682.mp3" length="3862259" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6682.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6682</link>
<pubDate>Thu, 26 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Malspam Pushing Quasar RAT<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Quasar+RAT/25354/">https://isc.sans.edu/forums/diary/Malspam+pushing+Quasar+RAT/25354/</a><br/>
vBulletin 0-Day Exploit Update<br/>
 <a href="https://www.bleepingcomputer.com/news/security/vbulletin-zero-day-exploited-for-years-gets-unofficial-patch/">https://www.bleepingcomputer.com/news/security/vbulletin-zero-day-exploited-for-years-gets-unofficial-patch/</a><br/>
Fake Veteran Employment Site<br/>
 <a href="https://blog.talosintelligence.com/2019/09/tortoiseshell-fake-veterans.html">https://blog.talosintelligence.com/2019/09/tortoiseshell-fake-veterans.html</a><br/>
]]></description>
<itunes:duration>4:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6682" type="text/plain" language="en" />
<itunes:keywords>cisco, talos, veteran, malware, vbulletin, exploit, patch, quasar, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6680</itunes:episode>
<itunes:subtitle>Remotewebaccess CT Logs; Coldfusion Patch; Apple Updates; vBulletin 0Day RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Remotewebaccess CT Logs; Coldfusion Patch; Apple Updates; vBulletin 0Day RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6680.mp3" length="4543953" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6680.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6680</link>
<pubDate>Wed, 25 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Remotewebaccess.com Domain in Certificate Transparency Logs<br/>
 <a href="https://isc.sans.edu/forums/diary/Huge+Amount+of+remotewebaccesscom+Sites+Found+in+Certificate+Transparency+Logs/25352/">https://isc.sans.edu/forums/diary/Huge+Amount+of+remotewebaccesscom+Sites+Found+in+Certificate+Transparency+Logs/25352/</a><br/>
Adobe Releases Emergency ColdFusion Patch<br/>
 <a href="https://blogs.adobe.com/psirt/?p=1789">https://blogs.adobe.com/psirt/?p=1789</a><br/>
Apple Releases Additional Updates for iOS/iPadOS<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
vBulletin Vulnerability 0-Day Exploit Released<br/>
 <a href="https://seclists.org/fulldisclosure/2019/Sep/31">https://seclists.org/fulldisclosure/2019/Sep/31</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6680" type="text/plain" language="en" />
<itunes:keywords>vbulletin, 0day, rce, apple, ios, ipados, adobe, coldfusion, patch, remotewebaccess, certificate transparency, ct, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 24th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6678</itunes:episode>
<itunes:subtitle>MSFT releases IE Patch; Cloudflare Blocking Bots; iOS Bluetooth Restriction; Forcepoint VPN
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT releases IE Patch; Cloudflare Blocking Bots; iOS Bluetooth Restriction; Forcepoint VPN
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6678.mp3" length="4642326" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6678.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6678</link>
<pubDate>Tue, 24 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Releases Special Patch for Exploited Vulnerability in Internet Explorer<br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1367">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1367</a><br/>
Cloudflare Adding "Bot Fight" option<br/>
 <a href="https://blog.cloudflare.com/cleaning-up-bad-bots/">https://blog.cloudflare.com/cleaning-up-bad-bots/</a><br/>
iOS Bluetooth Access Feature<br/>
 <a href="https://www.theverge.com/2019/9/19/20867286/ios-13-bluetooth-permission-privacy-feature-apps">https://www.theverge.com/2019/9/19/20867286/ios-13-bluetooth-permission-privacy-feature-apps</a><br/>
Forcepoint VPN Update<br/>
 <a href="https://support.forcepoint.com/KBArticle?id=000017525">https://support.forcepoint.com/KBArticle?id=000017525</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6678" type="text/plain" language="en" />
<itunes:keywords>forcepoint, unquoted path, ios, bluetooth, permissions, privacy, location, cloudflare, bot fight, microsoftl, internet explorer, patch, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6676</itunes:episode>
<itunes:subtitle>Android Adware; Wireshark Update; Harbor Priv. Escalation Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Android Adware; Wireshark Update; Harbor Priv. Escalation Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6676.mp3" length="4620381" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6676.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6676</link>
<pubDate>Mon, 23 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Popular Android Selfie Apps Act as Adware<br/>
 <a href="https://www.wandera.com/mobile-security/google-play-adware/">https://www.wandera.com/mobile-security/google-play-adware/</a><br/>
Wireshark Update<br/>
 <a href="https://www.wireshark.org/docs/relnotes/wireshark-3.0.5.html">https://www.wireshark.org/docs/relnotes/wireshark-3.0.5.html</a><br/>
Harbor Privilege Escalation<br/>
 <a href="https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/">https://unit42.paloaltonetworks.com/critical-vulnerability-in-harbor-enables-privilege-escalation-from-zero-to-admin-cve-2019-16097/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6676" type="text/plain" language="en" />
<itunes:keywords>harbor, docker, wireshark, android, selfie, adware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6674</itunes:episode>
<itunes:subtitle>Agent Tesla; Apple Updates; SAMBA disables SMB1; GitHub Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Agent Tesla; Apple Updates; SAMBA disables SMB1; GitHub Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6674.mp3" length="4330004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6674.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6674</link>
<pubDate>Fri, 20 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Agent Tesla<br/>
 <a href="https://isc.sans.edu/forums/diary/Agent+Tesla+Trojan+Abusing+Corporate+Email+Accounts/25336/">https://isc.sans.edu/forums/diary/Agent+Tesla+Trojan+Abusing+Corporate+Email+Accounts/25336/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
 <a href="https://developer.apple.com/documentation/safari_release_notes/safari_13_release_notes">https://developer.apple.com/documentation/safari_release_notes/safari_13_release_notes</a><br/>
SAMBA 4.11 Released<br/>
 <a href="https://www.samba.org/samba/history/samba-4.11.0.html">https://www.samba.org/samba/history/samba-4.11.0.html</a><br/>
GitHub Security Updates<br/>
 <a href="https://github.blog/2019-09-18-securing-software-together/">https://github.blog/2019-09-18-securing-software-together/</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6674" type="text/plain" language="en" />
<itunes:keywords>github, samba, apple, ios, watchos, safari, agent tesla, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6672</itunes:episode>
<itunes:subtitle>Emotet Sample; Windows Defender Bug; QEMU/VMWare VM Escape; CWE Top 25
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Sample; Windows Defender Bug; QEMU/VMWare VM Escape; CWE Top 25
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6672.mp3" length="5277208" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6672.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6672</link>
<pubDate>Thu, 19 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Analyzing a Current Emotet Sample<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+malspam+is+back/25330/">https://isc.sans.edu/forums/diary/Emotet+malspam+is+back/25330/</a><br/>
Windows Defender "Scan Now" Failed Bug Fix<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/windows-defender-antivirus-scans-broken-after-new-update/">https://www.bleepingcomputer.com/news/microsoft/windows-defender-antivirus-scans-broken-after-new-update/</a><br/>
 <a href="https://borncity.com/win/2019/09/18/defender-antimalware-version-4-18-1908-7-released/">https://borncity.com/win/2019/09/18/defender-antimalware-version-4-18-1908-7-released/</a><br/>
QEMU Vulnerablity<br/>
 <a href="https://www.openwall.com/lists/oss-security/2019/09/17/1">https://www.openwall.com/lists/oss-security/2019/09/17/1</a><br/>
VMWare Vulnerabilty<br/>
 <a href="https://blogs.vmware.com/security/2019/09/amd-display-driver-security-updates-address-cve-2019-5685.html">https://blogs.vmware.com/security/2019/09/amd-display-driver-security-updates-address-cve-2019-5685.html</a><br/>
New CWE Top 25 Released<br/>
 <a href="https://cwe.mitre.org/top25/archive/2019/2019_cwe_top25.html">https://cwe.mitre.org/top25/archive/2019/2019_cwe_top25.html</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6672" type="text/plain" language="en" />
<itunes:keywords>cwe, vmware, qemu, vm escape, windows defender, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6670</itunes:episode>
<itunes:subtitle>Find Windows Log Gaps; SOHOpelesly Broken; HP Printer Privacy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Find Windows Log Gaps; SOHOpelesly Broken; HP Printer Privacy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6670.mp3" length="4946238" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6670.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6670</link>
<pubDate>Wed, 18 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Investigating Gaps in Windows Event Logs<br/>
 <a href="https://isc.sans.edu/forums/diary/Investigating+Gaps+in+your+Windows+Event+Logs/25328/">https://isc.sans.edu/forums/diary/Investigating+Gaps+in+your+Windows+Event+Logs/25328/</a><br/>
SOHOpelesly Broken 2<br/>
<a href="https://www.securityevaluators.com/whitepaper/sohopelessly-broken-2/">https://www.securityevaluators.com/whitepaper/sohopelessly-broken-2/</a><br/>
HP Printer Privacy <br/>
 <a href="https://robertheaton.com/2019/09/15/hp-printers-send-data-on-what-you-print-back-to-hp/">https://robertheaton.com/2019/09/15/hp-printers-send-data-on-what-you-print-back-to-hp/</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6670" type="text/plain" language="en" />
<itunes:keywords>hp, privacy, printer, soho, router, nas, sohoplesly, windows, event logs, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6668</itunes:episode>
<itunes:subtitle>Encrypted Sextortion; Simjacker; LassPass Fix
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encrypted Sextortion; Simjacker; LassPass Fix
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6668.mp3" length="5561732" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6668.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6668</link>
<pubDate>Tue, 17 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Encrypted Sextortion<br/>
 <a href="https://isc.sans.edu/forums/diary/Encrypted+Sextortion+PDFs/25324/">https://isc.sans.edu/forums/diary/Encrypted+Sextortion+PDFs/25324/</a><br/>
SimJacker<br/>
 <a href="https://www.adaptivemobile.com/blog/simjacker-next-generation-spying-over-mobile">https://www.adaptivemobile.com/blog/simjacker-next-generation-spying-over-mobile</a><br/>
LastPass Password Leak<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1930">https://bugs.chromium.org/p/project-zero/issues/detail?id=1930</a><br/>
Microsoft Extends EoL For Exchange Server 2010<br/>
 <a href="https://techcommunity.microsoft.com/t5/Exchange-Team-Blog/Microsoft-Extending-End-of-Support-for-Exchange-Server-2010-to/ba-p/753591">https://techcommunity.microsoft.com/t5/Exchange-Team-Blog/Microsoft-Extending-End-of-Support-for-Exchange-Server-2010-to/ba-p/753591</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6668" type="text/plain" language="en" />
<itunes:keywords>exchange server, eol, lastpass, simjacker, sextortion, encrypted, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6666</itunes:episode>
<itunes:subtitle>#RigEK -> VBScript; Pentesters Arrested; iOS 13 Unlock Trick
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#RigEK -> VBScript; Pentesters Arrested; iOS 13 Unlock Trick
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6666.mp3" length="5199672" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6666.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6666</link>
<pubDate>Mon, 16 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Rig Exploit Kit Delivering VBScript<br/>
 <a href="https://isc.sans.edu/forums/diary/Rig+Exploit+Kit+Delivering+VBScript/25318/">https://isc.sans.edu/forums/diary/Rig+Exploit+Kit+Delivering+VBScript/25318/</a><br/>
Pentesters Arrested During Physical Access Pentest<br/>
 <a href="https://arstechnica.com/information-technology/2019/09/check-the-scope-pen-testers-nabbed-jailed-in-iowa-courthouse-break-in-attempt/">https://arstechnica.com/information-technology/2019/09/check-the-scope-pen-testers-nabbed-jailed-in-iowa-courthouse-break-in-attempt/</a><br/>
iOS Lock Screen Unlock Vulnerability<br/>
 <a href="https://www.theregister.co.uk/2019/09/12/apples_ios_lock_workaround/">https://www.theregister.co.uk/2019/09/12/apples_ios_lock_workaround/</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6666" type="text/plain" language="en" />
<itunes:keywords>ios, lock screen, unlock, pentest, arrested, iowa, vbscript, rigek, rig, exploit kit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6660</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; SSH Side Channel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; SSH Side Channel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6660.mp3" length="4626238" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6660.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6660</link>
<pubDate>Wed, 11 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+September+2019+Patch+Tuesday/25310/">https://isc.sans.edu/forums/diary/Microsoft+September+2019+Patch+Tuesday/25310/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Intel SSH Side Channel Vulnerability<br/>
 <a href="https://www.vusec.net/projects/netcat/">https://www.vusec.net/projects/netcat/</a><br/>
 <a href="https://www.cs.vu.nl/~herbertb/download/papers/netcat_sp20.pdf">https://www.cs.vu.nl/~herbertb/download/papers/netcat_sp20.pdf</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6660" type="text/plain" language="en" />
<itunes:keywords>intel, ssh, side channel, netcat, adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6658</itunes:episode>
<itunes:subtitle>Firefox Making DoH Default; Telegram Fixes Privacy Bug; PsiXBot uses DoH
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Firefox Making DoH Default; Telegram Fixes Privacy Bug; PsiXBot uses DoH
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6658.mp3" length="5425686" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6658.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6658</link>
<pubDate>Tue, 10 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Firefox to Enable DNS over HTTPs by Default in September<br/>
 <a href="https://blog.mozilla.org/futurereleases/2019/09/06/whats-next-in-making-dns-over-https-the-default/">https://blog.mozilla.org/futurereleases/2019/09/06/whats-next-in-making-dns-over-https-the-default/</a><br/>
Telegram Fixes Privacy Bug<br/>
 <a href="https://www.inputzero.io/2019/09/telegram-privacy-fails-again.html">https://www.inputzero.io/2019/09/telegram-privacy-fails-again.html</a><br/>
PsiXBot Uses DoH<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/psixbot-now-using-google-dns-over-https-and-possible-new-sexploitation-module">https://www.proofpoint.com/us/threat-insight/post/psixbot-now-using-google-dns-over-https-and-possible-new-sexploitation-module</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6658" type="text/plain" language="en" />
<itunes:keywords>psixbot, doh, telegram, firefox, https, dns, privacy, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6656</itunes:episode>
<itunes:subtitle>Mirai Updates; Bluekeep in Metasploit; Gmail Spam Response; Exim TLS SNI Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mirai Updates; Bluekeep in Metasploit; Gmail Spam Response; Exim TLS SNI Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6656.mp3" length="4057181" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6656.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6656</link>
<pubDate>Mon, 09 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Unidentified Scanning Activity Likely Associated with Mirai/Successors<br/>
 <a href="https://isc.sans.edu/forums/diary/Unidentified+Scanning+Activity/25304/">https://isc.sans.edu/forums/diary/Unidentified+Scanning+Activity/25304/</a><br/>
Bluekeep Exploit Now in Metasploit<br/>
 <a href="https://blog.rapid7.com/2019/09/06/initial-metasploit-exploit-module-for-bluekeep-cve-2019-0708/">https://blog.rapid7.com/2019/09/06/initial-metasploit-exploit-module-for-bluekeep-cve-2019-0708/</a><br/>
How to Remove GMail Calendar Spam<br/>
 <a href="https://support.google.com/calendar/answer/6084018?co=GENIE.Platform%3DDesktop&hl=en">https://support.google.com/calendar/answer/6084018?co=GENIE.Platform%3DDesktop&hl=en</a><br/>
Exim SNI TLS Vulnerability<br/>
 <a href="https://exim.org/static/doc/security/CVE-2019-15846.txt">https://exim.org/static/doc/security/CVE-2019-15846.txt</a><br/>
]]></description>
<itunes:duration>4:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6656" type="text/plain" language="en" />
<itunes:keywords>gmail spam, bluekeep, metasploit, mirai, exim, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6650</itunes:episode>
<itunes:subtitle>LNK File Trickbot; Supermicro Vritual USB BMC Vuln; Facebook Free Basics Key
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LNK File Trickbot; Supermicro Vritual USB BMC Vuln; Facebook Free Basics Key
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6650.mp3" length="5049004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6650.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6650</link>
<pubDate>Wed, 04 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Tricky Link Retrieves Trick Bot <br/>
 <a href="https://isc.sans.edu/forums/diary/Guest+Diary+Tricky+LNK+points+to+TrickBot/25290/">https://isc.sans.edu/forums/diary/Guest+Diary+Tricky+LNK+points+to+TrickBot/25290/</a><br/>
Supermicro Virtual USB Vulnerability <br/>
 <a href="https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/">https://eclypsium.com/2019/09/03/usbanywhere-bmc-vulnerability-opens-servers-to-remote-attack/</a><br/>
Facebook Free Basics Key Used to Sign Unrelated Android Apps<br/>
 <a href="https://www.androidpolice.com/2019/08/29/cryptographic-key-used-to-sign-one-of-facebooks-android-apps-compromised/">https://www.androidpolice.com/2019/08/29/cryptographic-key-used-to-sign-one-of-facebooks-android-apps-compromised/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6650" type="text/plain" language="en" />
<itunes:keywords>facebook, free basics, private key, supermicro, bmc, usb, trickbot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6648</itunes:episode>
<itunes:subtitle>Malware Installs Node.js; Dovecot Vulnerability; Cloudflare Workers Spreading Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Installs Node.js; Dovecot Vulnerability; Cloudflare Workers Spreading Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6648.mp3" length="3970143" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6648.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6648</link>
<pubDate>Tue, 03 Sep 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Malware Installs Node.js<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Dropping+a+Local+Nodejs+Instance/25284/">https://isc.sans.edu/forums/diary/Malware+Dropping+a+Local+Nodejs+Instance/25284/</a><br/>
Dovecot and PigeonHole Vulnerability<br/>
 <a href="https://www.openwall.com/lists/oss-security/2019/08/28/3">https://www.openwall.com/lists/oss-security/2019/08/28/3</a><br/>
Cloudflare Workers Spreading Malware<br/>
 <a href="https://medium.com/@marcelx/threat-actor-behind-astaroth-is-now-using-cloudflare-workers-to-bypass-your-security-solutions-2c658d08f4c">https://medium.com/@marcelx/threat-actor-behind-astaroth-is-now-using-cloudflare-workers-to-bypass-your-security-solutions-2c658d08f4c</a><br/>
]]></description>
<itunes:duration>4:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6648" type="text/plain" language="en" />
<itunes:keywords>cloudflare, workers, astaroth, dovecot, nodejs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6646</itunes:episode>
<itunes:subtitle>iOS Exploits in the Wild; Twitter CEO Account Hijack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iOS Exploits in the Wild; Twitter CEO Account Hijack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6646.mp3" length="4467147" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6646.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6646</link>
<pubDate>Mon, 02 Sep 2019 03:00:02 GMT</pubDate>
<description><![CDATA[iOS Exploits in the Wild<br/>
 <a href="https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html">https://googleprojectzero.blogspot.com/2019/08/a-very-deep-dive-into-ios-exploit.html</a><br/>
Twitter CEO's Twitter Account Hijacked<br/>
 <a href="https://twitter.com/TwitterComms/status/1167528672523210752">https://twitter.com/TwitterComms/status/1167528672523210752</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6646" type="text/plain" language="en" />
<itunes:keywords>twitter, ios, google, sim swapping, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6644</itunes:episode>
<itunes:subtitle>Malware Compiling Itself; Notifying Vulnerable Home Automation Owners; Botnet Takedown
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Compiling Itself; Notifying Vulnerable Home Automation Owners; Botnet Takedown
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6644.mp3" length="5390569" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6644.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6644</link>
<pubDate>Fri, 30 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Malware Samples Compiling Their Next Stage On PremiseMalware Compiling Itself;<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Samples+Compiling+Their+Next+Stage+on+Premise/25278/">https://isc.sans.edu/forums/diary/Malware+Samples+Compiling+Their+Next+Stage+on+Premise/25278/</a><br/>
CERT-Bund Attempts to Notify Users of Vulnerable Home Automation Systems<br/>
 <a href="https://www.heise.de/security/meldung/CERT-Bund-warnt-vor-offenen-Smarthome-Systemen-4509977.html">https://www.heise.de/security/meldung/CERT-Bund-warnt-vor-offenen-Smarthome-Systemen-4509977.html</a><br/>
French Authorities Shut Down Coinminer Botnet<br/>
 <a href="https://decoded.avast.io/janvojtesek/putting-an-end-to-retadup-a-malicious-worm-that-infected-hundreds-of-thousands/">https://decoded.avast.io/janvojtesek/putting-an-end-to-retadup-a-malicious-worm-that-infected-hundreds-of-thousands/</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6644" type="text/plain" language="en" />
<itunes:keywords>france, retadup, coinminer, takedown, shutdown, cert-bund, home automation, jsc.exe, msbuild.exe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 29th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6642</itunes:episode>
<itunes:subtitle>Open Redirects; ADB Botnet; Android CamScanner Malware; Cisco REST API Auth Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Open Redirects; ADB Botnet; Android CamScanner Malware; Cisco REST API Auth Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6642.mp3" length="4986093" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6642.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6642</link>
<pubDate>Thu, 29 Aug 2019 03:25:02 GMT</pubDate>
<description><![CDATA[Open Redirects: A Small But Very Common Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/Guest+Diary+Open+Redirect+A+Small+But+Very+Common+Vulnerability/25276/">https://isc.sans.edu/forums/diary/Guest+Diary+Open+Redirect+A+Small+But+Very+Common+Vulnerability/25276/</a><br/>
CamScanner Malicious Download Component<br/>
 <a href="https://securelist.com/dropper-in-google-play/92496/">https://securelist.com/dropper-in-google-play/92496/</a><br/>
Ares ADB Botnet<br/>
 <a href="https://www.wootcloud.com/blogs/ars_botnet.html">https://www.wootcloud.com/blogs/ars_botnet.html</a><br/>
Cisco REST API Container for IOS XE Authentication Bypass<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6642" type="text/plain" language="en" />
<itunes:keywords>Cisco, Ares, ADB, rest api, container, redirects, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 28th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6640</itunes:episode>
<itunes:subtitle>TLS 1.2 For Email; xHelper Android Trojan; LYCEUM Threat Group
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TLS 1.2 For Email; xHelper Android Trojan; LYCEUM Threat Group
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6640.mp3" length="5610370" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6640.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6640</link>
<pubDate>Wed, 28 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Is it "Safe" To Require TLS 1.2 for Email<br/>
 <a href="https://isc.sans.edu/forums/diary/Is+it+Safe+to+Require+TLS+12+for+EMail/25270/">https://isc.sans.edu/forums/diary/Is+it+Safe+to+Require+TLS+12+for+EMail/25270/</a><br/>
Android Trojan Infects Tens of Thousands of Devices in 4 Months<br/>
 <a href="https://www.bleepingcomputer.com/news/security/android-trojan-infects-tens-of-thousands-of-devices-in-4-months/">https://www.bleepingcomputer.com/news/security/android-trojan-infects-tens-of-thousands-of-devices-in-4-months/</a><br/>
LYCEUM Threat Group Targeting Middle East<br/>
 <a href="https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign">https://www.secureworks.com/blog/lyceum-takes-center-stage-in-middle-east-campaign</a><br/>
]]></description>
<itunes:duration>6:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6640" type="text/plain" language="en" />
<itunes:keywords>lyceum, middle east, android, xhelper, tls, email, starttls, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 27th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6638</itunes:episode>
<itunes:subtitle>iOS/macOS Patch; Pulse Secure VPN Scans; Emotet
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iOS/macOS Patch; Pulse Secure VPN Scans; Emotet
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6638.mp3" length="4152263" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6638.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6638</link>
<pubDate>Tue, 27 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Apple Patches Jailbreak Vulnerability<br/>
 <a href="https://support.apple.com/en-us/HT210549">https://support.apple.com/en-us/HT210549</a><br/>
Scanning for Pulse Secure VPN Endpoints<br/>
 <a href="https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2019-11510/">https://badpackets.net/over-14500-pulse-secure-vpn-endpoints-vulnerable-to-cve-2019-11510/</a><br/>
Emotet is Back<br/>
 <a href="https://www.bleepingcomputer.com/news/security/emotet-botnet-is-back-servers-active-across-the-world/">https://www.bleepingcomputer.com/news/security/emotet-botnet-is-back-servers-active-across-the-world/</a><br/>
]]></description>
<itunes:duration>4:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6638" type="text/plain" language="en" />
<itunes:keywords>emotet, pulse secure vpn, vpn, pulse, apple, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6636</itunes:episode>
<itunes:subtitle>Mimikatz/RDPWrapper Dropper; IRS Impersonation; Instagraph Phish; GitHub WebAuthn
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mimikatz/RDPWrapper Dropper; IRS Impersonation; Instagraph Phish; GitHub WebAuthn
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6636.mp3" length="4525289" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6636.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6636</link>
<pubDate>Mon, 26 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Simple Mimikatz And RDPWrapper Dropper<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+Mimikatz+RDPWrapper+Dropper/25262/">https://isc.sans.edu/forums/diary/Simple+Mimikatz+RDPWrapper+Dropper/25262/</a><br/>
Malware Impersonating IRS<br/>
 <a href="https://www.irs.gov/newsroom/security-summit-warns-of-new-irs-impersonation-email-scam-reminds-taxpayers-the-irs-does-not-send-unsolicited-emails">https://www.irs.gov/newsroom/security-summit-warns-of-new-irs-impersonation-email-scam-reminds-taxpayers-the-irs-does-not-send-unsolicited-emails</a><br/>
Instagram Phishing with 2FA Codes<br/>
 <a href="https://nakedsecurity.sophos.com/2019/08/23/instagram-phishing-uses-2fa-as-a-lure/">https://nakedsecurity.sophos.com/2019/08/23/instagram-phishing-uses-2fa-as-a-lure/</a><br/>
GitHub Adding WebAuthn Support<br/>
 <a href="https://www.theregister.co.uk/2019/08/23/github_upgrades_its_twofactor_authentication_with_webauthn_support/">https://www.theregister.co.uk/2019/08/23/github_upgrades_its_twofactor_authentication_with_webauthn_support/</a><br/>
Lenovo Solution Center Privilege Escalation<br/>
 <a href="https://www.pentestpartners.com/security-blog/privesc-in-lenovo-solution-centre-10-minutes-later/">https://www.pentestpartners.com/security-blog/privesc-in-lenovo-solution-centre-10-minutes-later/</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6636" type="text/plain" language="en" />
<itunes:keywords>lenovo, github, webauthn, instagram, phishing, 2fa, malware, irs, mimikatz, rdpwrapper, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6634</itunes:episode>
<itunes:subtitle>Steam Double 0; Malicious npm Packages; Branded Outlook 365 Phishing Pages
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Steam Double 0; Malicious npm Packages; Branded Outlook 365 Phishing Pages
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6634.mp3" length="4897952" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6634.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6634</link>
<pubDate>Fri, 23 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Steam Zero Days and Bug Bounty Controversy<br/>
 <a href="https://www.theregister.co.uk/2019/08/22/valve_bug_bounty_steam_u_turn/">https://www.theregister.co.uk/2019/08/22/valve_bug_bounty_steam_u_turn/</a><br/>
bb-builder malicious npm Package<br/>
 <a href="https://blog.reversinglabs.com/blog/the-npm-package-that-walked-away-with-all-your-passwords">https://blog.reversinglabs.com/blog/the-npm-package-that-walked-away-with-all-your-passwords</a><br/>
Phishers Customize Branded Outlook 365 Login Pages<br/>
 <a href="https://www.bleepingcomputer.com/news/security/phishing-attacks-scrape-branded-microsoft-365-login-pages/">https://www.bleepingcomputer.com/news/security/phishing-attacks-scrape-branded-microsoft-365-login-pages/</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6634" type="text/plain" language="en" />
<itunes:keywords>phishing, outlook, msft, bb-builder, bb-build, npm, steam, valve, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6632</itunes:episode>
<itunes:subtitle>KAPE vs. Commando; Sphinx Servers; Cisco Patches; Newly Registered Domains
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
KAPE vs. Commando; Sphinx Servers; Cisco Patches; Newly Registered Domains
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6632.mp3" length="4753133" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6632.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6632</link>
<pubDate>Thu, 22 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[KAPE vs. Commando VM: Red vs. Blue<br/>
 <a href="https://isc.sans.edu/forums/diary/KAPE+Kroll+Artifact+Parser+and+Extractor/25258/">https://isc.sans.edu/forums/diary/KAPE+Kroll+Artifact+Parser+and+Extractor/25258/</a><br/>
Attacks against Exposed Sphinx Servers<br/>
 <a href="https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/CERT-Bund/CERT-Reports/HOWTOs/Open-Sphinx-Server/open-Sphinx-server_node.html">https://www.bsi.bund.de/EN/Topics/IT-Crisis-Management/CERT-Bund/CERT-Reports/HOWTOs/Open-Sphinx-Server/open-Sphinx-server_node.html</a><br/>
Cisco Patches<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=50#~Vulnerabilities">https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=50#~Vulnerabilities</a><br/>
Newly Registered Domains Most Dangerous<br/>
 <a href="https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/">https://unit42.paloaltonetworks.com/newly-registered-domains-malicious-abuse-by-bad-actors/</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6632" type="text/plain" language="en" />
<itunes:keywords>NRD, newly registerd domains, cisco, patches, sphinx, kape, commando, red vs. blue, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6630</itunes:episode>
<itunes:subtitle>Guildma Malware using Facebook/YouTube C&amp;C; rest-client ruby gem backdoored
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Guildma Malware using Facebook/YouTube C&amp;C; rest-client ruby gem backdoored
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6630.mp3" length="4768495" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6630.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6630</link>
<pubDate>Wed, 21 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Guildma Malware is Now Using Facebook and YouTube as Update Channel<br/>
 <a href="https://isc.sans.edu/forums/diary/Guildma+malware+is+now+accessing+Facebook+andYouTube+to+keep+uptodate/25222/">https://isc.sans.edu/forums/diary/Guildma+malware+is+now+accessing+Facebook+andYouTube+to+keep+uptodate/25222/</a><br/>
Supply Chain Issues: rest-client ruby gem backdoored<br/>
 <a href="https://www.theregister.co.uk/2019/08/20/ruby_gem_hacked/">https://www.theregister.co.uk/2019/08/20/ruby_gem_hacked/</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6630" type="text/plain" language="en" />
<itunes:keywords>suppy chain, rest-client, ruby, gem, guildma, malware, facebook, youtube, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6628</itunes:episode>
<itunes:subtitle>iOS 12.4 Jailbreak; SHA2-Signed Updates vs. Symantec AV; Attacking Bluetooth
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iOS 12.4 Jailbreak; SHA2-Signed Updates vs. Symantec AV; Attacking Bluetooth
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6628.mp3" length="4670114" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6628.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6628</link>
<pubDate>Tue, 20 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[iOS 12.4 Jailbreak Released after Reindruced Vulnerability form 12.2<br/>
 <a href="https://github.com/pwn20wndstuff/Undecimus/releases">https://github.com/pwn20wndstuff/Undecimus/releases</a><br/>
SHA2-Signed Updates for Windows Not Available with Symantec Endpoint Protection<br/>
 <a href="https://support.symantec.com/us/en/article.tech255857.html">https://support.symantec.com/us/en/article.tech255857.html</a><br/>
Attacking and Downgrading Bluetooth Key Negotiation<br/>
 <a href="https://knobattack.com">https://knobattack.com</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6628" type="text/plain" language="en" />
<itunes:keywords>bluetooth, sha2, windows, symantec, windows 7, windows 2008, ios, jailbreak, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6626</itunes:episode>
<itunes:subtitle>VoIP Vulnerabilities; AV Sandbox Leaks; Trend Micro Password Manager; Firefox Password Manager;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VoIP Vulnerabilities; AV Sandbox Leaks; Trend Micro Password Manager; Firefox Password Manager;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6626.mp3" length="4279529" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6626.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6626</link>
<pubDate>Mon, 19 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Large Number of VoIP System Vulnerabilities Released<br/>
 <a href="https://www.sit.fraunhofer.de/en/cve/">https://www.sit.fraunhofer.de/en/cve/</a><br/>
Confidential Company Documents Leaked in Public Sandboxes<br/>
 <a href="https://blog.cylab.co/2019/08/16/confidential-company-documents-exposed-in-public-sandboxes/">https://blog.cylab.co/2019/08/16/confidential-company-documents-exposed-in-public-sandboxes/</a><br/>
 <a href="https://www.sit.fraunhofer.de/en/news-events/latest/press-releases/details/news-article/show/gefahr-uebers-telefon/">https://www.sit.fraunhofer.de/en/news-events/latest/press-releases/details/news-article/show/gefahr-uebers-telefon/</a><br/>
Trend Micro Password Manager DLL Hijacking<br/>
 <a href="https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123396.aspx">https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123396.aspx</a><br/>
Firefox Password Manager May Leak Passwords<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2019-24/#CVE-2019-11733">https://www.mozilla.org/en-US/security/advisories/mfsa2019-24/#CVE-2019-11733</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6626" type="text/plain" language="en" />
<itunes:keywords>firefox, mozilla, password manager, trend micro, sandbox leaks, virustotal, voip, vulnerabilities, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6624</itunes:episode>
<itunes:subtitle>Spearphishing Maldoc Analysis; No News IoT Security; Kaspersky Insecurity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Spearphishing Maldoc Analysis; No News IoT Security; Kaspersky Insecurity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6624.mp3" length="5352169" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6624.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6624</link>
<pubDate>Fri, 16 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Analysis of a Spearphishing Maldoc<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+Spearphishing+Maldoc/25242/">https://isc.sans.edu/forums/diary/Analysis+of+a+Spearphishing+Maldoc/25242/</a><br/>
IoT Security Stagnation<br/>
 <a href="https://securityledger.com/2019/08/huge-survey-of-firmware-finds-no-security-gains-in-15-years/">https://securityledger.com/2019/08/huge-survey-of-firmware-finds-no-security-gains-in-15-years/</a><br/>
Kaspersky Insecurity<br/>
 <a href="https://www.heise.de/ct/artikel/Kasper-Spy-Kaspersky-Anti-Virus-puts-users-at-risk-4496138.html">https://www.heise.de/ct/artikel/Kasper-Spy-Kaspersky-Anti-Virus-puts-users-at-risk-4496138.html</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6624" type="text/plain" language="en" />
<itunes:keywords>kaspesky, privacy, iot, security, spearphishing, maldoc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6622</itunes:episode>
<itunes:subtitle>MedusaHTTP Malware; DuckDNS C&amp;C; HTTP/2 Vulnerabilities; Intel NUC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MedusaHTTP Malware; DuckDNS C&amp;C; HTTP/2 Vulnerabilities; Intel NUC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6622.mp3" length="5107145" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6622.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6622</link>
<pubDate>Thu, 15 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[MedusaHTTP Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Recent+example+of+MedusaHTTP+malware/25234/">https://isc.sans.edu/forums/diary/Recent+example+of+MedusaHTTP+malware/25234/</a><br/>
Cryptominer uses DuckDNS for C&C<br/>
 <a href="https://www.varonis.com/blog/monero-cryptominer/">https://www.varonis.com/blog/monero-cryptominer/</a><br/>
Intel NUC Vulnerabilities<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/default.html">https://www.intel.com/content/www/us/en/security-center/default.html</a><br/>
HTTP/2 Vulnerabilities<br/>
 <a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md">https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6622" type="text/plain" language="en" />
<itunes:keywords>http/2, intel, nuc, cryptominer, duckdns, medusahttp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 14th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6620</itunes:episode>
<itunes:subtitle>MSFT/Adobe Patch Tuesday; Windwos Text Services (CTF) Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT/Adobe Patch Tuesday; Windwos Text Services (CTF) Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6620.mp3" length="4543947" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6620.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6620</link>
<pubDate>Wed, 14 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/August+2019+Microsoft+Patch+Tuesday/25236/">https://isc.sans.edu/forums/diary/August+2019+Microsoft+Patch+Tuesday/25236/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Windows Text Services Vulnerabilities<br/>
 <a href="https://googleprojectzero.blogspot.com/2019/08/down-rabbit-hole.html#ftnt2">https://googleprojectzero.blogspot.com/2019/08/down-rabbit-hole.html#ftnt2</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6620" type="text/plain" language="en" />
<itunes:keywords>ctf, windows text services, project zero, google, adobe, microsoft, patches, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 13th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6618</itunes:episode>
<itunes:subtitle>DAA Files; Exploiting SQLLite; Printer Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DAA Files; Exploiting SQLLite; Printer Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6618.mp3" length="4807988" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6618.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6618</link>
<pubDate>Tue, 13 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Malicious DAA Attachments<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+DAA+Attachments/25230/">https://isc.sans.edu/forums/diary/Malicious+DAA+Attachments/25230/</a><br/>
SQLLite Exploits<br/>
 <a href="https://research.checkpoint.com/select-code_execution-from-using-sqlite/">https://research.checkpoint.com/select-code_execution-from-using-sqlite/</a><br/>
Printer Vulnerabilities<br/>
 <a href="https://www.defcon.org/html/defcon-27/dc-27-speakers.html#Romero">https://www.defcon.org/html/defcon-27/dc-27-speakers.html#Romero</a><br/>
 <a href="https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-xerox-printers/?research=Technical+advisories">https://www.nccgroup.trust/us/our-research/technical-advisory-multiple-vulnerabilities-in-xerox-printers/?research=Technical+advisories</a><br/>
 <br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6618" type="text/plain" language="en" />
<itunes:keywords>printers, kyocera, hp, xerox, sqllite, daa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6616</itunes:episode>
<itunes:subtitle>Phishing With JavaScript; Camera Vulnerabilities; Tesla Surveilance; Electron Weaknesses
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing With JavaScript; Camera Vulnerabilities; Tesla Surveilance; Electron Weaknesses
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6616.mp3" length="4611964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6616.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6616</link>
<pubDate>Mon, 12 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[100% JavaScript Phishing Page<br/>
 <a href="https://isc.sans.edu/forums/diary/100+JavaScript+Phishing+Page/25220/">https://isc.sans.edu/forums/diary/100+JavaScript+Phishing+Page/25220/</a><br/>
Vulnerabilities in DSLR Cameras<br/>
 <a href="https://research.checkpoint.com/say-cheese-ransomware-ing-a-dslr-camera/">https://research.checkpoint.com/say-cheese-ransomware-ing-a-dslr-camera/</a><br/>
 <a href="https://global.canon/en/support/security/d-camera.html">https://global.canon/en/support/security/d-camera.html</a><br/>
Turning Tesla into Surveilance Platform<br/>
 <a href="https://github.com/tevora-threat/scout">https://github.com/tevora-threat/scout</a><br/>
Basic Electron Framework Exploitation<br/>
 <a href="https://www.contextis.com/en/blog/basic-electron-framework-exploitation">https://www.contextis.com/en/blog/basic-electron-framework-exploitation</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6616" type="text/plain" language="en" />
<itunes:keywords>electron, Tesla, surveilance, dslr, checkpoint, cameras, javascript, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6614</itunes:episode>
<itunes:subtitle>Kubernetes Security Audit; Apple Bug Bounty; Steam Vuln; Actual Sextortion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kubernetes Security Audit; Apple Bug Bounty; Steam Vuln; Actual Sextortion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6614.mp3" length="5436649" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6614.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6614</link>
<pubDate>Fri, 09 Aug 2019 03:55:13 GMT</pubDate>
<description><![CDATA[Kubernetes Security Audit Published<br/>
 <a href="https://github.com/kubernetes/community/blob/master/wg-security-audit/findings/Kubernetes%20Final%20Report.pdf">https://github.com/kubernetes/community/blob/master/wg-security-audit/findings/Kubernetes%20Final%20Report.pdf</a><br/>
 <a href="https://www.cncf.io/blog/2019/08/06/open-sourcing-the-kubernetes-security-audit/">https://www.cncf.io/blog/2019/08/06/open-sourcing-the-kubernetes-security-audit/</a><br/>
Apple Expands Bug Bounty<br/>
 <a href="https://www.blackhat.com/us-19/briefings/schedule/index.html#behind-the-scenes-of-ios-and-mac-security-17220">https://www.blackhat.com/us-19/briefings/schedule/index.html#behind-the-scenes-of-ios-and-mac-security-17220</a><br/>
 <a href="https://www.forbes.com/sites/thomasbrewster/2019/08/08/apple-confirms-1-million-reward-for-hackers-who-find-serious-iphone-vulnerabilities/">https://www.forbes.com/sites/thomasbrewster/2019/08/08/apple-confirms-1-million-reward-for-hackers-who-find-serious-iphone-vulnerabilities/</a><br/>
0-Day Privilege Escalation in Steam Client<br/>
 <a href="https://amonitoring.ru/article/steamclient-0day/">https://amonitoring.ru/article/steamclient-0day/</a><br/>
Actual Sextortion Trojan<br/>
 <a href="https://www.welivesecurity.com/2019/08/08/varenyky-spambot-campaigns-france/">https://www.welivesecurity.com/2019/08/08/varenyky-spambot-campaigns-france/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6614" type="text/plain" language="en" />
<itunes:keywords>sextortion, 0day, steam, priviledge escalation, apple, bug bounty, kubernetes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6612</itunes:episode>
<itunes:subtitle>AT&amp;T Insider Attack; RDP/HyperV Vulnerability; Cisco Patches; Firefox Android WebAuthn
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AT&amp;T Insider Attack; RDP/HyperV Vulnerability; Cisco Patches; Firefox Android WebAuthn
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6612.mp3" length="5485293" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6612.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6612</link>
<pubDate>Thu, 08 Aug 2019 04:20:02 GMT</pubDate>
<description><![CDATA[AT&T Insiders Bribed to Obtain Unlock Codes<br/>
 <a href="https://www.justice.gov/usao-wdwa/press-release/file/1191031/download">https://www.justice.gov/usao-wdwa/press-release/file/1191031/download</a><br/>
Older RDP Vulnerability Can be Used for HyperV VM Escape<br/>
 <a href="https://www.microsoft.com/security/blog/2019/08/07/a-case-study-in-industry-collaboration-poisoned-rdp-vulnerability-disclosure-and-response/">https://www.microsoft.com/security/blog/2019/08/07/a-case-study-in-industry-collaboration-poisoned-rdp-vulnerability-disclosure-and-response/</a><br/>
Cisco Patches Smart Switch 220 Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Firefox for Android Supporting WebAuthn<br/>
 <a href="https://blog.mozilla.org/security/2019/08/05/web-authentication-in-firefox-for-android/">https://blog.mozilla.org/security/2019/08/05/web-authentication-in-firefox-for-android/</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6612" type="text/plain" language="en" />
<itunes:keywords>firefox, android, webauthn, cisco, smart switch, rdp, hyperv, at and amp, t, insider, bribe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6610</itunes:episode>
<itunes:subtitle>Corporate IoT Attack; SWAPGS Spectre Attacks; WPA-3 Weaknesses
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Corporate IoT Attack; SWAPGS Spectre Attacks; WPA-3 Weaknesses
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6610.mp3" length="5261112" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6610.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6610</link>
<pubDate>Wed, 07 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Corporate IoT Used in Intrusion<br/>
 <a href="https://msrc-blog.microsoft.com/2019/08/05/corporate-iot-a-path-to-intrusion/">https://msrc-blog.microsoft.com/2019/08/05/corporate-iot-a-path-to-intrusion/</a><br/>
New Spectre Variant: SWAPGS<br/>
 <a href="https://www.bitdefender.com/business/swapgs-attack.html">https://www.bitdefender.com/business/swapgs-attack.html</a><br/>
New WPA3 Weaknesses<br/>
 <a href="https://wpa3.mathyvanhoef.com/#new">https://wpa3.mathyvanhoef.com/#new</a><br/>
]]></description>
<itunes:duration>6:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6610" type="text/plain" language="en" />
<itunes:keywords>wpa3, spectre, wifi, swpags, iot, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 6th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6608</itunes:episode>
<itunes:subtitle>Sexploitation Money Summary; VMWare Update; Android Qualcom Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sexploitation Money Summary; VMWare Update; Android Qualcom Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6608.mp3" length="4758617" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6608.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6608</link>
<pubDate>Tue, 06 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Sexploitation E-Mail: Where did the winnings go <br/>
 <a href="https://isc.sans.edu/forums/diary/Sextortion+Follow+the+Money+The+Final+Chapter/25204/">https://isc.sans.edu/forums/diary/Sextortion+Follow+the+Money+The+Final+Chapter/25204/</a><br/>
VMWare Update<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2019-0012.html">https://www.vmware.com/security/advisories/VMSA-2019-0012.html</a><br/>
Android Update Fixes Qualcom Bug<br/>
 <a href="https://source.android.com/security/bulletin/2019-08-01.html">https://source.android.com/security/bulletin/2019-08-01.html</a><br/>
 <a href="https://blade.tencent.com/en/advisories/qualpwn/">https://blade.tencent.com/en/advisories/qualpwn/</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6608" type="text/plain" language="en" />
<itunes:keywords>android, vmware, qualcom, qualpwn, exploitation, btc, bitcoin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 5th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6606</itunes:episode>
<itunes:subtitle>Misconfigured JIRA; Voice Assistant Listening Policies Change; NVidia Updates; Detecting Chrome 76 Incognito Mode
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Misconfigured JIRA; Voice Assistant Listening Policies Change; NVidia Updates; Detecting Chrome 76 Incognito Mode
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6606.mp3" length="4938912" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6606.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6606</link>
<pubDate>Mon, 05 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Misconfigured JIRA Leaks User Details<br/>
 <a href="https://medium.com/@logicbomb_1/one-misconfig-jira-to-leak-them-all-including-nasa-and-hundreds-of-fortune-500-companies-a70957ef03c7">https://medium.com/@logicbomb_1/one-misconfig-jira-to-leak-them-all-including-nasa-and-hundreds-of-fortune-500-companies-a70957ef03c7</a><br/>
Google, Amazon, Apple modify policy on listening in on Assistant Recordings<br/>
 <a href="https://datenschutz-hamburg.de/assets/pdf/2019-08-01_press-release-Google_Assistant.pdf">https://datenschutz-hamburg.de/assets/pdf/2019-08-01_press-release-Google_Assistant.pdf</a><br/>
 <a href="https://www.bloomberg.com/news/articles/2019-08-02/amazon-gives-option-to-disable-human-review-of-alexa-recordings">https://www.bloomberg.com/news/articles/2019-08-02/amazon-gives-option-to-disable-human-review-of-alexa-recordings</a><br/>
 <a href="https://www.theverge.com/2019/8/2/20751270/apple-stops-contractors-siri-voice-recordings-privacy-opt-out">https://www.theverge.com/2019/8/2/20751270/apple-stops-contractors-siri-voice-recordings-privacy-opt-out</a><br/>
 <a href="https://www.blog.google/products/assistant/more-information-about-our-processes-safeguard-speech-data/">https://www.blog.google/products/assistant/more-information-about-our-processes-safeguard-speech-data/</a><br/>
NVidia Updates<br/>
 <a href="https://nvidia.custhelp.com/app/answers/detail/a_id/4841/kw/Security%20Bulletin">https://nvidia.custhelp.com/app/answers/detail/a_id/4841/kw/Security%20Bulletin</a><br/>
Detecting Incognito Mode in Google Chrome 76 <br/>
 <a href="https://blog.jse.li/posts/chrome-76-incognito-filesystem-timing/">https://blog.jse.li/posts/chrome-76-incognito-filesystem-timing/</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6606" type="text/plain" language="en" />
<itunes:keywords>google chrome, incognito, nvidia, google, amazon, apple, siri, alexa, jira, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6604</itunes:episode>
<itunes:subtitle>Investigating Port 9527; Rocke Cryptojacking; PowerShel Empire EOL 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Investigating Port 9527; Rocke Cryptojacking; PowerShel Empire EOL 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6604.mp3" length="4646341" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6604.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6604</link>
<pubDate>Fri, 02 Aug 2019 03:00:02 GMT</pubDate>
<description><![CDATA[What Is Listening On Port 9527/TCP<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+Listening+On+Port+9527TCP/25194/">https://isc.sans.edu/forums/diary/What+is+Listening+On+Port+9527TCP/25194/</a><br/>
PowerShell Empire Abandonded<br/>
 <a href="https://github.com/EmpireProject/Empire">https://github.com/EmpireProject/Empire</a><br/>
 <a href="https://twitter.com/xorrior/status/1156626182978383874">https://twitter.com/xorrior/status/1156626182978383874</a><br/>
Cryptomining via GitHub/PasteBin C&C<br/>
 <a href="https://unit42.paloaltonetworks.com/rockein-the-netflow/">https://unit42.paloaltonetworks.com/rockein-the-netflow/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6604" type="text/plain" language="en" />
<itunes:keywords>rocke, cryptomining, cryptojacking, 9527, webcam, powershell, empire, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 1st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6602</itunes:episode>
<itunes:subtitle>Targeted Phish; Enterprise Software Phoning Home; Bypassing Contactless Limits
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Targeted Phish; Enterprise Software Phoning Home; Bypassing Contactless Limits
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6602.mp3" length="5440310" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6602.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6602</link>
<pubDate>Thu, 01 Aug 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Phishing Attack Targeting Financial Sector<br/>
 <a href="https://isc.sans.edu/forums/diary/Targeted+Phishing+Attacks+in+the+Financial+Industry+Fire3+Phishing+Kit/25188/">https://isc.sans.edu/forums/diary/Targeted+Phishing+Attacks+in+the+Financial+Industry+Fire3+Phishing+Kit/25188/</a> <br/>
Enterprise Software Phoneing Home<br/>
 <a href="https://www.extrahop.com/company/press-releases/2019/extrahop-issues-warning-about-phoning-home/">https://www.extrahop.com/company/press-releases/2019/extrahop-issues-warning-about-phoning-home/</a><br/>
Google Stripping www and https again<br/>
 <a href="https://bugs.chromium.org/p/chromium/issues/detail?id=883038#c114">https://bugs.chromium.org/p/chromium/issues/detail?id=883038#c114</a><br/>
Bypassing VISA Contactless Limits<br/>
 <a href="https://www.ptsecurity.com/ww-en/about/news/visa-card-vulnerability-can-bypass-contactless-limits/">https://www.ptsecurity.com/ww-en/about/news/visa-card-vulnerability-can-bypass-contactless-limits/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6602" type="text/plain" language="en" />
<itunes:keywords>visa, contactless, google, chrome, enterprise software, exfil, phoning home, phishing, financial, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 31st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6600</itunes:episode>
<itunes:subtitle>Luno Phish and Pseudo 2FA; Chrome Update; Disabling Siri Server Side Logging; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Luno Phish and Pseudo 2FA; Chrome Update; Disabling Siri Server Side Logging; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6600.mp3" length="4908560" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6600.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6600</link>
<pubDate>Wed, 31 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Luno Phishing E-Mail and Badly Implemented 2FA<br/>
 <a href="https://isc.sans.edu/forums/diary/Can+You+Spell+2FA+A+Luno+Phish+Example/25186/">https://isc.sans.edu/forums/diary/Can+You+Spell+2FA+A+Luno+Phish+Example/25186/</a><br/>
Google Chrome Update<br/>
 <a href="https://w3c.github.io/webappsec-fetch-metadata/">https://w3c.github.io/webappsec-fetch-metadata/</a><br/>
 <a href="https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html">https://chromereleases.googleblog.com/2019/07/stable-channel-update-for-desktop_30.html</a><br/>
Apple Re-Releases 2019-004 Security Update for Sierra/High Sierra<br/>
 <a href="https://support.apple.com/en-us/HT210348">https://support.apple.com/en-us/HT210348</a><br/>
Disabling Server Side Recording of Apple Siri Commands<br/>
 <a href="https://github.com/jankais3r/Siri-NoLoggingPLS">https://github.com/jankais3r/Siri-NoLoggingPLS</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6600" type="text/plain" language="en" />
<itunes:keywords>siri, apple, sierra, google, chrome, luno, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6598</itunes:episode>
<itunes:subtitle>VxWorks TCP/IP Flaws; iOS iMessage File Disclosure (patched)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VxWorks TCP/IP Flaws; iOS iMessage File Disclosure (patched)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6598.mp3" length="5539779" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6598.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6598</link>
<pubDate>Tue, 30 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[11 Flaws in VxWorks IPNet TCP/IP Stack<br/>
 <a href="https://go.armis.com/urgent11">https://go.armis.com/urgent11</a><br/>
iOS iMessage File Disclosure Vulnerability<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1858">https://bugs.chromium.org/p/project-zero/issues/detail?id=1858</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6598" type="text/plain" language="en" />
<itunes:keywords>ios, imessage, vxworks, ipnet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 29th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6596</itunes:episode>
<itunes:subtitle>Port 34567 Uptick; LibreOffice Macro Code Exec; Extracting Private Keys from Amazon Music
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Port 34567 Uptick; LibreOffice Macro Code Exec; Extracting Private Keys from Amazon Music
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6596.mp3" length="6079571" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6596.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6596</link>
<pubDate>Mon, 29 Jul 2019 03:00:02 GMT</pubDate>
<description><![CDATA[DVRIP Port 34567 Uptick<br/>
 <a href="https://isc.sans.edu/forums/diary/DVRIP+Port+34567+Uptick/25174/">https://isc.sans.edu/forums/diary/DVRIP+Port+34567+Uptick/25174/</a><br/>
LibreOffice LibreLogo Macro Python Code Injection<br/>
 <a href="https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/">https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/</a><br/>
Extracting Private Key From Amazon Music Application<br/>
 <a href="https://koen.io/2019/07/26/underscoring-the-private-in-private-key/">https://koen.io/2019/07/26/underscoring-the-private-in-private-key/</a><br/>
]]></description>
<itunes:duration>7:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6596" type="text/plain" language="en" />
<itunes:keywords>amazon, music, private key, librelogo, libreoffice, dvrip, port 34567, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6594</itunes:episode>
<itunes:subtitle>When Users Attack; BlueKeep in Canvas; Darkmatter Cert Nixed; Johannesburg Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
When Users Attack; BlueKeep in Canvas; Darkmatter Cert Nixed; Johannesburg Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6594.mp3" length="5361308" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6594.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6594</link>
<pubDate>Fri, 26 Jul 2019 03:00:02 GMT</pubDate>
<description><![CDATA[When Users Attack: Users and Admins Thwarting Security Controls<br/>
<a href="https://isc.sans.edu/forums/diary/When+Users+Attack+Users+and+Admins+Thwarting+Security+Controls/25170/">https://isc.sans.edu/forums/diary/When+Users+Attack+Users+and+Admins+Thwarting+Security+Controls/25170/</a><br/>
Immunity's Canvas Now Includes BlueKeep Exploit<br/>
 <a href="https://twitter.com/Immunityinc/status/1153752470130221057">https://twitter.com/Immunityinc/status/1153752470130221057</a><br/>
Johannesburg Power Outages Due To Ransomware<br/>
 <a href="https://twitter.com/CityofJoburgZA">https://twitter.com/CityofJoburgZA</a><br/>
 <a href="https://www.theregister.co.uk/2019/07/25/johannesburg_ransomware_infection/">https://www.theregister.co.uk/2019/07/25/johannesburg_ransomware_infection/</a><br/>
Darkmatter Intermediate Certificate Trust Removed From Google Chrome<br/>
 <a href="https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/7-oKhDBLetQ">https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/7-oKhDBLetQ</a><br/>
]]></description>
<itunes:duration>6:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6594" type="text/plain" language="en" />
<itunes:keywords>dakrmatter, certificates, johannesburg, ransomware, immunity, canvas, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6592</itunes:episode>
<itunes:subtitle>VLC Non-Vulnerabilty; Crytominer with BlueKeep Scanner; Elastic; People as IOCs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VLC Non-Vulnerabilty; Crytominer with BlueKeep Scanner; Elastic; People as IOCs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6592.mp3" length="4893564" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6592.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6592</link>
<pubDate>Thu, 25 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[VLC not Vulnerable to libebml Vulnerablity<br/>
 <a href="https://threader.app/thread/1153963312981389312">https://threader.app/thread/1153963312981389312</a><br/>
Cryptominer With BlueKeep Scanner<br/>
 <a href="https://www.intezer.com/blog-watching-the-watchbog-new-bluekeep-scanner-and-linux-exploits/">https://www.intezer.com/blog-watching-the-watchbog-new-bluekeep-scanner-and-linux-exploits/</a><br/>
Elasticsearch Vulnerabilities used to install DDoS Bot<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/multistage-attack-delivers-billgates-setag-backdoor-can-turn-elasticsearch-databases-into-ddos-botnet-zombies/">https://blog.trendmicro.com/trendlabs-security-intelligence/multistage-attack-delivers-billgates-setag-backdoor-can-turn-elasticsearch-databases-into-ddos-botnet-zombies/</a><br/>
May People Be Considered As IOC?<br/>
 <a href="https://isc.sans.edu/forums/diary/May+People+Be+Considered+as+IOC/25166/">https://isc.sans.edu/forums/diary/May+People+Be+Considered+as+IOC/25166/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6592" type="text/plain" language="en" />
<itunes:keywords>elastic, ddos, linux, cryptominer, bluekeep, watchbog, vlc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 24th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6590</itunes:episode>
<itunes:subtitle>TLS Configuration; #Apple Updates; #QNAP/#Synology Advice; New #Bluekeep Writeup @0xeb-bp 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TLS Configuration; #Apple Updates; #QNAP/#Synology Advice; New #Bluekeep Writeup @0xeb-bp 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6590.mp3" length="5074594" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6590.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6590</link>
<pubDate>Wed, 24 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[TLS Configuration<br/>
 <a href="https://isc.sans.edu/forums/diary/Verifying+SSLTLS+configuration+part+1/25162/">https://isc.sans.edu/forums/diary/Verifying+SSLTLS+configuration+part+1/25162/</a><br/>
 <a href="https://www.sans.org/webcasts/beast-poodle-celebrating-sweet32-111400">https://www.sans.org/webcasts/beast-poodle-celebrating-sweet32-111400</a><br/>
Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
QNAP/Synology Update Security Advise<br/>
 <a href="https://www.qnap.com/en-us/security-advisory/nas-201907-11">https://www.qnap.com/en-us/security-advisory/nas-201907-11</a><br/>
 <a href="https://www.facebook.com/synologydeutschland/photos/a.1594837477441905/2417134061878905/">https://www.facebook.com/synologydeutschland/photos/a.1594837477441905/2417134061878905/</a><br/>
New Bluekeep Writeup<br/>
 <a href="https://github.com/0xeb-bp/bluekeep">https://github.com/0xeb-bp/bluekeep</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6590" type="text/plain" language="en" />
<itunes:keywords>bluekeep, apple, qnap, synology, tls, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6588</itunes:episode>
<itunes:subtitle>Compressed PowerShell; GlobalProtect RCE; FortiOS RCE; ProFTPD Permission Issue
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Compressed PowerShell; GlobalProtect RCE; FortiOS RCE; ProFTPD Permission Issue
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6588.mp3" length="4530042" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6588.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6588</link>
<pubDate>Tue, 23 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Analyzing Compressed PowerShell Scripts<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+Compressed+PowerShell+Scripts/25158/">https://isc.sans.edu/forums/diary/Analyzing+Compressed+PowerShell+Scripts/25158/</a><br/>
PaloAlto GlobalProtect PreAuth RCE<br/>
 <a href="http://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html">http://blog.orange.tw/2019/07/attacking-ssl-vpn-part-1-preauth-rce-on-palo-alto.html</a><br/>
Fortinet Vulnerability<br/>
 <a href="https://fortiguard.com/psirt/FG-IR-19-144">https://fortiguard.com/psirt/FG-IR-19-144</a><br/>
ProFTPd Permission Bypass Vulnerability<br/>
 <a href="https://tbspace.de/cve201912815proftpd.html">https://tbspace.de/cve201912815proftpd.html</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6588" type="text/plain" language="en" />
<itunes:keywords>proftpd, cpto, cpfr, fortinet, paloalto, globalprotect, powershell, zlib, compression, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6586</itunes:episode>
<itunes:subtitle>php malware; iNSYNC breached by Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
php malware; iNSYNC breached by Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6586.mp3" length="5190522" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6586.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6586</link>
<pubDate>Mon, 22 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[PHP Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+PHP+Script+Back+on+Stage/25148/">https://isc.sans.edu/forums/diary/Malicious+PHP+Script+Back+on+Stage/25148/</a><br/>
Drupal Vulnerabilities<br/>
 <a href="https://www.drupal.org/sa-core-2019-008">https://www.drupal.org/sa-core-2019-008</a><br/>
iNSYNQ Breach<br/>
 <a href="https://www.insynq.com/support/#status">https://www.insynq.com/support/#status</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6586" type="text/plain" language="en" />
<itunes:keywords>php, malware, drupal, insynq, quickbooks, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6584</itunes:episode>
<itunes:subtitle>802.1x Tips; Kazachstan TLS Interception; Cylance Weakness; BEC Trends
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
802.1x Tips; Kazachstan TLS Interception; Cylance Weakness; BEC Trends
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6584.mp3" length="5918291" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6584.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6584</link>
<pubDate>Fri, 19 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[802.1x Tips<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Other+Side+of+Critical+Control+1+8021x+Wired+Network+Access+Controls/25146/">https://isc.sans.edu/forums/diary/The+Other+Side+of+Critical+Control+1+8021x+Wired+Network+Access+Controls/25146/</a><br/>
Kazachstan TLS Interception<br/>
 <a href="https://groups.google.com/forum/#!msg/mozilla.dev.security.policy/wnuKAhACo3E/cpsvHgcuDwAJ">https://groups.google.com/forum/#!msg/mozilla.dev.security.policy/wnuKAhACo3E/cpsvHgcuDwAJ</a><br/>
BEC Trends<br/>
 <a href="https://www.fincen.gov/sites/default/files/shared/FinCEN_Financial_Trend_Analysis_FINAL_508.pdf">https://www.fincen.gov/sites/default/files/shared/FinCEN_Financial_Trend_Analysis_FINAL_508.pdf</a><br/>
Cyclance Weakness<br/>
 <a href="https://skylightcyber.com/2019/07/18/cylance-i-kill-you/">https://skylightcyber.com/2019/07/18/cylance-i-kill-you/</a><br/>
]]></description>
<itunes:duration>7:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6584" type="text/plain" language="en" />
<itunes:keywords>cyclance, skylight, bec trends, fincen, kazachstan, tls, 802.1x, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6582</itunes:episode>
<itunes:subtitle>DNS TXT Records; Evilgnome Linux Malware; Interesting AMEX Phish
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS TXT Records; Evilgnome Linux Malware; Interesting AMEX Phish
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6582.mp3" length="5286341" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6582.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6582</link>
<pubDate>Thu, 18 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Analysis of DNS TXT Records<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzis+of+DNS+TXT+Records/25142/">https://isc.sans.edu/forums/diary/Analyzis+of+DNS+TXT+Records/25142/</a><br/>
Evil Gnome Linux Malware<br/>
 <a href="https://www.intezer.com/blog-evilgnome-rare-malware-spying-on-linux-desktop-users/">https://www.intezer.com/blog-evilgnome-rare-malware-spying-on-linux-desktop-users/</a><br/>
New American Express Phishing Attacks<br/>
 <a href="https://cofense.com/phishing-attacker-takes-american-express-victims-credentials/">https://cofense.com/phishing-attacker-takes-american-express-victims-credentials/</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6582" type="text/plain" language="en" />
<itunes:keywords>amex, phishing, base, evilgome, linux, malware, dns, txt, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6580</itunes:episode>
<itunes:subtitle>More Zoom Patches; Boarding Pass Hack; Android File Jacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Zoom Patches; Boarding Pass Hack; Android File Jacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6580.mp3" length="4782388" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6580.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6580</link>
<pubDate>Wed, 17 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Zoom/Apple Patches Additional Software<br/>
 <a href="https://www.theverge.com/2019/7/16/20696529/apple-mac-silent-update-zoom-ringcentral-zhumu-vulnerabilty-patched">https://www.theverge.com/2019/7/16/20696529/apple-mac-silent-update-zoom-ringcentral-zhumu-vulnerabilty-patched</a><br/>
Lenovo/IOMega NAS API Vulnerability<br/>
 <a href="https://www.theregister.co.uk/2019/07/16/iomega_nas_boxes/">https://www.theregister.co.uk/2019/07/16/iomega_nas_boxes/</a><br/>
Amadeus Vulnerability Allows Access to Boarding Passes<br/>
 <a href="https://www.7elements.co.uk/resources/technical-advisories/insecure-direct-object-reference-within-amadeus-check-in-application/">https://www.7elements.co.uk/resources/technical-advisories/insecure-direct-object-reference-within-amadeus-check-in-application/</a><br/>
FBI Releases GandGrab Master Keys<br/>
 <a href="https://www.documentcloud.org/documents/6199678-GandCrab-Master-Decryption-Keys-FLASH.html">https://www.documentcloud.org/documents/6199678-GandCrab-Master-Decryption-Keys-FLASH.html</a><br/>
Android Media File Jacking<br/>
 <a href="https://www.symantec.com/blogs/expert-perspectives/symantec-mobile-threat-defense-attackers-can-manipulate-your-whatsapp-and-telegram-media">https://www.symantec.com/blogs/expert-perspectives/symantec-mobile-threat-defense-attackers-can-manipulate-your-whatsapp-and-telegram-media</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6580" type="text/plain" language="en" />
<itunes:keywords>android, media file jacking, fbi, gandgrab, keys, amadeus, lenovo, iomega, nas, api, zoom, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6578</itunes:episode>
<itunes:subtitle>isodump.py released; Scrapy Vuln; Atlassian Crowd; iOS URL Schemes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
isodump.py released; Scrapy Vuln; Atlassian Crowd; iOS URL Schemes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6578.mp3" length="5475047" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6578.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6578</link>
<pubDate>Tue, 16 Jul 2019 03:00:04 GMT</pubDate>
<description><![CDATA[isodump.py and malicious ISO files<br/>
 <a href="https://isc.sans.edu/forums/diary/isodumppy+and+Malicious+ISO+Files/25134/">https://isc.sans.edu/forums/diary/isodumppy+and+Malicious+ISO+Files/25134/</a><br/>
Atlassian Crowd Vulnerability Details<br/>
 <a href="https://www.corben.io/atlassian-crowd-rce/">https://www.corben.io/atlassian-crowd-rce/</a><br/>
Scrapy Vulnerabilities<br/>
 <a href="https://medium.com/alertot/web-scraping-considered-dangerous-leaking-files-from-the-spiders-host-bd508f81d498">https://medium.com/alertot/web-scraping-considered-dangerous-leaking-files-from-the-spiders-host-bd508f81d498</a><br/>
iOS URL Scheme Susceptible to Hijacking<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/ios-url-scheme-susceptible-to-hijacking/">https://blog.trendmicro.com/trendlabs-security-intelligence/ios-url-scheme-susceptible-to-hijacking/</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6578" type="text/plain" language="en" />
<itunes:keywords>ios, url schemes, scrapy, atlassian, crowd, isodump, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6576</itunes:episode>
<itunes:subtitle>Magecart Targets S3; Atlassian Jira; Tracking Anonymized BLE Devices
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Magecart Targets S3; Atlassian Jira; Tracking Anonymized BLE Devices
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6576.mp3" length="5143342" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6576.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6576</link>
<pubDate>Mon, 15 Jul 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Magecart Targets S3 Buckets<br/>
 <a href="https://www.riskiq.com/blog/labs/magecart-amazon-s3-buckets/">https://www.riskiq.com/blog/labs/magecart-amazon-s3-buckets/</a><br/>
Atlassian Jira Vulnerability<br/>
 <a href="https://confluence.atlassian.com/jira/jira-security-advisory-2019-07-10-973486595.html">https://confluence.atlassian.com/jira/jira-security-advisory-2019-07-10-973486595.html</a><br/>
Microsoft to Detect Phishing in Forms<br/>
 <a href="https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=52927">https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=52927</a><br/>
Tracking Anonymized Bluetooth Devices<br/>
 <a href="https://petsymposium.org/2019/files/papers/issue3/popets-2019-0036.pdf">https://petsymposium.org/2019/files/papers/issue3/popets-2019-0036.pdf</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6576" type="text/plain" language="en" />
<itunes:keywords>tracking, privacy, bluetooth, ble, microsoft, phishing, forms, atlassian, jira, magecart, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6574</itunes:episode>
<itunes:subtitle>AZORult Sample; Zoom Followup; Apple Watch eavesdropping; PXE Windows Bug; @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AZORult Sample; Zoom Followup; Apple Watch eavesdropping; PXE Windows Bug; @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6574.mp3" length="11263571" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6574.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6574</link>
<pubDate>Fri, 12 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Analysis of a Recent AZORult Sample<br/>
 <a href="https://isc.sans.edu/forums/diary/Recent+AZORult+activity/25120/">https://isc.sans.edu/forums/diary/Recent+AZORult+activity/25120/</a><br/>
Apple Delete Zoom Web Server<br/>
 <a href="https://www.macrumors.com/2019/07/10/apple-update-remove-zoom-server/">https://www.macrumors.com/2019/07/10/apple-update-remove-zoom-server/</a><br/>
Apple Disables Walkie Talkie App <br/>
 <a href="https://techcrunch.com/2019/07/10/apple-disables-walkie-talkie-app-due-to-vulnerability-that-could-allow-iphone-eavesdropping/">https://techcrunch.com/2019/07/10/apple-disables-walkie-talkie-app-due-to-vulnerability-that-could-allow-iphone-eavesdropping/</a><br/>
Windows PXE Devices May Fail to Boot After Recent Update<br/>
 <a href="https://support.microsoft.com/en-in/help/4512816/devices-that-start-up-using-preboot-execution-environment-pxe-images-f">https://support.microsoft.com/en-in/help/4512816/devices-that-start-up-using-preboot-execution-environment-pxe-images-f</a><br/>
Sean Goodwin: Attackers Inside the WAlls: Detecting Malicious Activity<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/detection/paper/39055">https://www.sans.org/reading-room/whitepapers/detection/paper/39055</a><br/>
]]></description>
<itunes:duration>13:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6574" type="text/plain" language="en" />
<itunes:keywords>sti, sean goodwin, security onoin, windows pxe, apple, watch, walkie talkie, eavesdropping, zoom, azorult, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6572</itunes:episode>
<itunes:subtitle>Samba Disabling SMBv1; GnuPG Keyserver Update; eChoOraix Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Samba Disabling SMBv1; GnuPG Keyserver Update; eChoOraix Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6572.mp3" length="4260512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6572.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6572</link>
<pubDate>Thu, 11 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Samba Project Disabling SMBv1 By Default<br/>
 <a href="https://isc.sans.edu/forums/diary/Samba+Project+tells+us+Whats+New+SMBv1+Disabled+by+Default+finally/25116/">https://isc.sans.edu/forums/diary/Samba+Project+tells+us+Whats+New+SMBv1+Disabled+by+Default+finally/25116/</a><br/>
GnuPG Will No Longer Import Signatures From Keyservers<br/>
 <a href="https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html">https://lists.gnupg.org/pipermail/gnupg-announce/2019q3/000439.html</a><br/>
eChOraix Ransomware<br/>
 <a href="https://www.anomali.com/blog/the-ech0raix-ransomware">https://www.anomali.com/blog/the-ech0raix-ransomware</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6572" type="text/plain" language="en" />
<itunes:keywords>echoraix, ransomware, gnupg, pgp, keyservers, samba, smbv1, qnap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6570</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; Adobe Updates; Critical Zoom Video Conferencing Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; Adobe Updates; Critical Zoom Video Conferencing Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6570.mp3" length="5419463" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6570.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6570</link>
<pubDate>Wed, 10 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[MSFT Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/MSFT+July+2019+Patch+Tuesday/25110/">https://isc.sans.edu/forums/diary/MSFT+July+2019+Patch+Tuesday/25110/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Zoom Vulnerability<br/>
 <a href="https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5">https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6570" type="text/plain" language="en" />
<itunes:keywords>zoom, adobe, msft, video conferencing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6568</itunes:episode>
<itunes:subtitle>Canonical Hack; New Magecart Wave; Facebook Libra/Calibra Scams
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Canonical Hack; New Magecart Wave; Facebook Libra/Calibra Scams
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6568.mp3" length="4595870" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6568.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6568</link>
<pubDate>Tue, 09 Jul 2019 03:00:02 GMT</pubDate>
<description><![CDATA[Canonical Github Hack<br/>
 <a href="https://news.ycombinator.com/item?id=20373009">https://news.ycombinator.com/item?id=20373009</a><br/>
New Wave of Magecart Attacks<br/>
 <a href="https://gist.github.com/gwillem/5d936f5a84837d5c1dcb488ce256294a">https://gist.github.com/gwillem/5d936f5a84837d5c1dcb488ce256294a</a><br/>
Facebook's Libra Crpto Currency Already Impersonated<br/>
 <a href="https://www.digitalshadows.com/blog-and-research/facebooks-libra-cryptocurrency-cybercriminals-tipping-the-scales-in-their-favor/">https://www.digitalshadows.com/blog-and-research/facebooks-libra-cryptocurrency-cybercriminals-tipping-the-scales-in-their-favor/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6568" type="text/plain" language="en" />
<itunes:keywords>Facebook, libra, calibra, crypto, scam, magecart, canonical, github, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6566</itunes:episode>
<itunes:subtitle>DoH Or Not? Cisco Exploit, Magento Exploit, Malicious XSL Files
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DoH Or Not? Cisco Exploit, Magento Exploit, Malicious XSL Files
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6566.mp3" length="4774702" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6566.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6566</link>
<pubDate>Mon, 08 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Does "Godlua" Use DNS over HTTPS or Not?<br/>
 <a href="https://www.golem.de/news/verschluesseltes-dns-falschmeldung-in-propagandaschlacht-um-dns-ueber-https-1907-142358.html">https://www.golem.de/news/verschluesseltes-dns-falschmeldung-in-propagandaschlacht-um-dns-ueber-https-1907-142358.html</a><br/>
 <a href="https://blog.netlab.360.com/an-analysis-of-godlua-backdoor-en/">https://blog.netlab.360.com/an-analysis-of-godlua-backdoor-en/</a><br/>
Exploit for Cisco Authentication Bypass and RCE<br/>
 <a href="https://raw.githubusercontent.com/pedrib/PoC/master/advisories/cisco-dcnm-rce.txt">https://raw.githubusercontent.com/pedrib/PoC/master/advisories/cisco-dcnm-rce.txt</a><br/>
Magento RCE Exploit <br/>
 <a href="https://blog.ripstech.com/2019/magento-rce-via-xss/">https://blog.ripstech.com/2019/magento-rce-via-xss/</a><br/>
Malicous XSL Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+XSL+Files/25098/">https://isc.sans.edu/forums/diary/Malicious+XSL+Files/25098/</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6566" type="text/plain" language="en" />
<itunes:keywords>xsl, magento, cisco, exploit, rce, godlua, doh, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6564</itunes:episode>
<itunes:subtitle>Zipato SmartHub; Blocking DoH; Cloudflare Outage; Android Update; Powershell Killswitch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Zipato SmartHub; Blocking DoH; Cloudflare Outage; Android Update; Powershell Killswitch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6564.mp3" length="5182846" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6564.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6564</link>
<pubDate>Wed, 03 Jul 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Zipato SmartHub Vulnerabilities<br/>
 <a href="https://blackmarble.sh/zipato-smart-hub/">https://blackmarble.sh/zipato-smart-hub/</a><br/>
Blocking DNS over HTTPS<br/>
 <a href="https://github.com/bambenek/block-doh">https://github.com/bambenek/block-doh</a><br/>
Cloudflare Outage<br/>
 <a href="https://www.cloudflarestatus.com/incidents/tx4pgxs6zxdr">https://www.cloudflarestatus.com/incidents/tx4pgxs6zxdr</a><br/>
Android Update<br/>
 <a href="https://source.android.com/security/bulletin/2019-07-01">https://source.android.com/security/bulletin/2019-07-01</a><br/>
Powershell Kill Switch Commands<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Powershell+in+Basic+Incident+Response+A+Domain+Wide+KillSwitch/25088/">https://isc.sans.edu/forums/diary/Using+Powershell+in+Basic+Incident+Response+A+Domain+Wide+KillSwitch/25088/</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6564" type="text/plain" language="en" />
<itunes:keywords>powershell, android, cloudflare, doh, https, dns, zipato, smarthub, smarthome, iot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6562</itunes:episode>
<itunes:subtitle>Maldoc Payloads; Zyxel Patches; AMD Secure Memory Patch; Card Encrollment 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Maldoc Payloads; Zyxel Patches; AMD Secure Memory Patch; Card Encrollment 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6562.mp3" length="4517242" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6562.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6562</link>
<pubDate>Tue, 02 Jul 2019 00:53:24 GMT</pubDate>
<description><![CDATA[Maldoc Payloads in User Forms<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+Payloads+in+User+Forms/25084/">https://isc.sans.edu/forums/diary/Maldoc+Payloads+in+User+Forms/25084/</a><br/>
Zyxel Vulnerabilities<br/>
 <a href="https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml">https://www.zyxel.com/support/vulnerabilities-related-to-the-Free-Time-feature.shtml</a><br/>
AMD SEV DH Key Recovery<br/>
 <a href="https://seclists.org/fulldisclosure/2019/Jun/46">https://seclists.org/fulldisclosure/2019/Jun/46</a><br/>
Card Enrollment Service Fraud<br/>
 <a href="https://www.advanced-intel.com/post/card-enrollment-services-highly-effective-fraud-methodology-offered-in-russian-underground">https://www.advanced-intel.com/post/card-enrollment-services-highly-effective-fraud-methodology-offered-in-russian-underground</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6562" type="text/plain" language="en" />
<itunes:keywords>card enrollment, AMD SEV, Zyxel, Maldoc, user forms, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, June 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6560</itunes:episode>
<itunes:subtitle>Domain Wide Virustotal Search; Mozilla TLS Guide; SKS Attack; QR Code Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Domain Wide Virustotal Search; Mozilla TLS Guide; SKS Attack; QR Code Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6560.mp3" length="5662291" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6560.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6560</link>
<pubDate>Sun, 30 Jun 2019 17:35:02 GMT</pubDate>
<description><![CDATA[Collecting Hashes of Running Processes and verifying them with Virustotal Domain wide<br/>
<a href="https://isc.sans.edu/forums/diary/Verifying+Running+Processes+against+VirusTotal+DomainWide/25078/">https://isc.sans.edu/forums/diary/Verifying+Running+Processes+against+VirusTotal+DomainWide/25078/</a><br/>
Mozilla Server Side TLS Guide Updates<br/>
<a href="https://wiki.mozilla.org/Security/Server_Side_TLS">https://wiki.mozilla.org/Security/Server_Side_TLS</a><br/>
SKS Keyserver DoS Attack<br/>
 <a href="https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f">https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f</a><br/>
QR Code Phishing<br/>
 <a href="https://cofense.com/radar-phishing-using-qr-codes-evade-url-analysis/">https://cofense.com/radar-phishing-using-qr-codes-evade-url-analysis/</a><br/>
]]></description>
<itunes:duration>6:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6560" type="text/plain" language="en" />
<itunes:keywords>qr code, phishing, sks, keyserver, mozilla, pgp, gnupg, virustotal, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 28th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6558</itunes:episode>
<itunes:subtitle>New Brickerbot; Telco Service Provider Attachs; Malwaretising; Automating Phish Reporting Response @sans_edu 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Brickerbot; Telco Service Provider Attachs; Malwaretising; Automating Phish Reporting Response @sans_edu 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6558.mp3" length="14038981" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6558.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6558</link>
<pubDate>Thu, 27 Jun 2019 21:25:02 GMT</pubDate>
<description><![CDATA[New Brickerbot (Silex) Sightings<br/>
 <a href="https://twitter.com/_larry0/status/1143532888538984448">https://twitter.com/_larry0/status/1143532888538984448</a><br/>
Supply Chain Attacks Against Telco Providers<br/>
 <a href="https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers">https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers</a><br/>
GreenFlash Sundown Malwaretising Campaign<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2019/06/greenflash-sundown-exploit-kit-expands-via-large-malvertising-campaign/">https://blog.malwarebytes.com/threat-analysis/2019/06/greenflash-sundown-exploit-kit-expands-via-large-malvertising-campaign/</a><br/>
TrackThis Demonstrates How Advertisers Track You<br/>
 <a href="https://trackthis.link">https://trackthis.link</a><br/>
Geoff Parker: Automating Phsh Reporting Resposne<br/>
<a href="http://www.sans.org/reading-room/whitepapers/email/automating-response-phish-reporting-39000">http://www.sans.org/reading-room/whitepapers/email/automating-response-phish-reporting-39000</a><br/>
]]></description>
<itunes:duration>16:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6558" type="text/plain" language="en" />
<itunes:keywords>spam, phishing, automation, sti, sans_edu, trackthis, tracking, advertising, malvertising, greenflash sundown, supply chain, bricker bot, silex, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6556</itunes:episode>
<itunes:subtitle>Pitou.B Trojan; AWS VPC Traffic Mirroring; Elastic SIEM App; Spoofed Emergency Alerts 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Pitou.B Trojan; AWS VPC Traffic Mirroring; Elastic SIEM App; Spoofed Emergency Alerts 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6556.mp3" length="4864308" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6556.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6556</link>
<pubDate>Tue, 25 Jun 2019 22:50:03 GMT</pubDate>
<description><![CDATA[Rig Exploit Kit Installs Pitou.B. Trojan<br/>
 <a href="https://isc.sans.edu/forums/diary/Rig+Exploit+Kit+sends+PitouB+Trojan/25068/">https://isc.sans.edu/forums/diary/Rig+Exploit+Kit+sends+PitouB+Trojan/25068/</a><br/>
AWS VPC Traffic Mirroring <br/>
 <a href="https://aws.amazon.com/blogs/aws/new-vpc-traffic-mirroring">https://aws.amazon.com/blogs/aws/new-vpc-traffic-mirroring</a><br/>
Elastic SIEM App<br/>
 <a href="https://www.elastic.co/blog/introducing-elastic-siem">https://www.elastic.co/blog/introducing-elastic-siem</a><br/>
National Emergency Alerts Potentially Vulnerable to Attack<br/>
 <a href="https://www.colorado.edu/today/2019/06/11/emergency-alerts">https://www.colorado.edu/today/2019/06/11/emergency-alerts</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6556" type="text/plain" language="en" />
<itunes:keywords>emergency alerts, lte, siem, elastic, aws, vpc, mirroring, rig, pitou, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6554</itunes:episode>
<itunes:subtitle>Cloudflare Outage; WeTransfer Leak; Jenkins Pillage @cloudflare @dolosgroup 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cloudflare Outage; WeTransfer Leak; Jenkins Pillage @cloudflare @dolosgroup 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6554.mp3" length="6014110" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6554.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6554</link>
<pubDate>Mon, 24 Jun 2019 23:00:03 GMT</pubDate>
<description><![CDATA[Cloudflare Outage<br/>
 <a href="https://blog.cloudflare.com/how-verizon-and-a-bgp-optimizer-knocked-large-parts-of-the-internet-offline-today/">https://blog.cloudflare.com/how-verizon-and-a-bgp-optimizer-knocked-large-parts-of-the-internet-offline-today/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Extensive+BGP+Issues+Affecting+Cloudflare+and+possibly+others/25064/">https://isc.sans.edu/forums/diary/Extensive+BGP+Issues+Affecting+Cloudflare+and+possibly+others/25064/</a><br/>
WeTransfer Misdirects Files<br/>
 <a href="https://betanews.com/2019/06/21/wetransfer-fail/">https://betanews.com/2019/06/21/wetransfer-fail/</a><br/>
Jenkins Pillage<br/>
 <a href="https://dolosgroup.io/blog/2019/6/20/pillaging-the-jenkins-treasure-chest">https://dolosgroup.io/blog/2019/6/20/pillaging-the-jenkins-treasure-chest</a><br/>
]]></description>
<itunes:duration>7:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6554" type="text/plain" language="en" />
<itunes:keywords>jenkins, cloudflare, wetrasnfer, bpg, route leak, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 24th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6552</itunes:episode>
<itunes:subtitle>SSH Keys in Memory; #Bluekeep Patching; Android ADB/SSH Botnet @damientmiller @notninjacat
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SSH Keys in Memory; #Bluekeep Patching; Android ADB/SSH Botnet @damientmiller @notninjacat
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6552.mp3" length="4674131" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6552.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6552</link>
<pubDate>Sun, 23 Jun 2019 23:30:02 GMT</pubDate>
<description><![CDATA[SSH Will Start Encrypting Secret Keys in Memory<br/>
 <a href="https://marc.info/?l=openbsd-cvs&m=156109087822676&w=2">https://marc.info/?l=openbsd-cvs&m=156109087822676&w=2</a><br/>
Bluekeep Patchrate at 83.4%<br/>
 <a href="https://twitter.com/RavivTamir/status/1141788586922119168">https://twitter.com/RavivTamir/status/1141788586922119168</a><br/>
Android ADB/SSH Botnet<br/>
 <a href="https://www.bleepingcomputer.com/news/security/botnet-uses-ssh-and-adb-to-create-android-cryptomining-army/">https://www.bleepingcomputer.com/news/security/botnet-uses-ssh-and-adb-to-create-android-cryptomining-army/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6552" type="text/plain" language="en" />
<itunes:keywords>android, adb, ssh, bluekeep, ssh, openssh, encryption, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6550</itunes:episode>
<itunes:subtitle>Dell Support Assistant Update; Cisco RVxxxW RCE Vuln; STI Research: Biometrics @sans_edu #dell #cisco #biometrics
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dell Support Assistant Update; Cisco RVxxxW RCE Vuln; STI Research: Biometrics @sans_edu #dell #cisco #biometrics
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6550.mp3" length="12227594" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6550.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6550</link>
<pubDate>Fri, 21 Jun 2019 02:25:03 GMT</pubDate>
<description><![CDATA[Updates for Dell Support Assistant<br/>
 <a href="https://www.dell.com/support/article/us/en/04/sln317291/dsa-2019-084-dell-supportassist-for-business-pcs-and-dell-supportassist-for-home-pcs-security-update-for-pc-doctor-vulnerability?lang=en">https://www.dell.com/support/article/us/en/04/sln317291/dsa-2019-084-dell-supportassist-for-business-pcs-and-dell-supportassist-for-home-pcs-security-update-for-pc-doctor-vulnerability?lang=en</a><br/>
Critical Cisco Vulnerablity<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex</a><br/>
LoudMiner Comes with VM<br/>
 <a href="https://www.welivesecurity.com/2019/06/20/loudminer-mining-cracked-vst-software/">https://www.welivesecurity.com/2019/06/20/loudminer-mining-cracked-vst-software/</a><br/>
STI Student Dave Todd: Overcoming the Comliance Challenges in Biometrics<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/legal/paper/38970">https://www.sans.org/reading-room/whitepapers/legal/paper/38970</a><br/>
]]></description>
<itunes:duration>14:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6550" type="text/plain" language="en" />
<itunes:keywords>sti, biometrics, loudminer, cisco, qemu, virtualbox, dell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6548</itunes:episode>
<itunes:subtitle>WebLogic Critical Patch; Exim Exploits against Other Mail servers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebLogic Critical Patch; Exim Exploits against Other Mail servers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6548.mp3" length="4703392" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6548.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6548</link>
<pubDate>Thu, 20 Jun 2019 01:45:03 GMT</pubDate>
<description><![CDATA[Critical Patch For WebLogic<br/>
 <a href="https://isc.sans.edu/forums/diary/Critical+Actively+Exploited+WebLogic+Flaw+Patched+CVE20192729/25050/">https://isc.sans.edu/forums/diary/Critical+Actively+Exploited+WebLogic+Flaw+Patched+CVE20192729/25050/</a><br/>
Exim Exploits Against Other Mail Servers<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Detect+Exim+Return+of+the+Wizard+Attack/25052/">https://isc.sans.edu/forums/diary/Quick+Detect+Exim+Return+of+the+Wizard+Attack/25052/</a><br/>
SANS Fire Presentations (to be published soon)<br/>
 <a href="https://isc.sans.edu/presentations">https://isc.sans.edu/presentations</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6548" type="text/plain" language="en" />
<itunes:keywords>sansfire, presentations, exim, wizard, weblogic, oracle, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6546</itunes:episode>
<itunes:subtitle>SACK Panic Update; Critical Firefox Update; Google Site Reporter and Deceptive Site Protection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SACK Panic Update; Critical Firefox Update; Google Site Reporter and Deceptive Site Protection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6546.mp3" length="4321588" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6546.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6546</link>
<pubDate>Wed, 19 Jun 2019 02:05:02 GMT</pubDate>
<description><![CDATA[Critical Firefox Update<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/#CVE-2019-11707">https://www.mozilla.org/en-US/security/advisories/mfsa2019-18/#CVE-2019-11707</a><br/>
Bitdefender Releases GandCrap Decryptor<br/>
 <a href="https://labs.bitdefender.com/2019/06/good-riddance-gandcrab-were-still-fixing-the-mess-you-left-behind/">https://labs.bitdefender.com/2019/06/good-riddance-gandcrab-were-still-fixing-the-mess-you-left-behind/</a><br/>
Google Launches New Deceptive Site Protections in Chrome<br/>
 <a href="https://blog.chromium.org/2019/06/new-chrome-protections-from-deception.html">https://blog.chromium.org/2019/06/new-chrome-protections-from-deception.html</a><br/>
]]></description>
<itunes:duration>5:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6546" type="text/plain" language="en" />
<itunes:keywords>google, chrome, gandcrap, decryptor, firefox, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6544</itunes:episode>
<itunes:subtitle>TCP SACK Panic; Logitech Pointer Recall, Rig Exploit Kit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TCP SACK Panic; Logitech Pointer Recall, Rig Exploit Kit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6544.mp3" length="4847482" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6544.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6544</link>
<pubDate>Tue, 18 Jun 2019 02:30:02 GMT</pubDate>
<description><![CDATA[TCP SACK Panic DoS in Linux<br/>
 <a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md">https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md</a><br/>
 <a href="https://tools.ietf.org/html/rfc879">https://tools.ietf.org/html/rfc879</a><br/>
Logitech Pointer Recall<br/>
 <a href="https://www.heise.de/security/meldung/Angreifbare-Logitech-Presenter-Hersteller-tauscht-gefaehrliche-USB-Empfaenger-aus-4423627.html">https://www.heise.de/security/meldung/Angreifbare-Logitech-Presenter-Hersteller-tauscht-gefaehrliche-USB-Empfaenger-aus-4423627.html</a><br/>
An Infection from the Rig Exploit Kit<br/>
 <a href="https://isc.sans.edu/forums/diary/An+infection+from+Rig+exploit+kit/25040/">https://isc.sans.edu/forums/diary/An+infection+from+Rig+exploit+kit/25040/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6544" type="text/plain" language="en" />
<itunes:keywords>logitech, rig, sack, dos, linux, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6542</itunes:episode>
<itunes:subtitle>Whats App Phishing; Encrypted Email Phishing; Android Apps Link to Fake Sites
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Whats App Phishing; Encrypted Email Phishing; Android Apps Link to Fake Sites
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6542.mp3" length="4723502" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6542.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6542</link>
<pubDate>Mon, 17 Jun 2019 01:40:02 GMT</pubDate>
<description><![CDATA[Whats App Phishing<br/>
 <a href="https://www.heise.de/newsticker/meldung/Phishing-Mails-gaukeln-Ende-von-WhatsApp-Abonnement-vor-4447165.html">https://www.heise.de/newsticker/meldung/Phishing-Mails-gaukeln-Ende-von-WhatsApp-Abonnement-vor-4447165.html</a><br/>
Encrypted EMail Phishing<br/>
 <a href="https://www.bleepingcomputer.com/news/security/phishing-scam-asks-you-to-login-to-read-encrypted-message/">https://www.bleepingcomputer.com/news/security/phishing-scam-asks-you-to-login-to-read-encrypted-message/</a><br/>
Android Apps Link to Fake Sites<br/>
 <a href="https://news.drweb.com/show/?i=13313&lng=en&c=5">https://news.drweb.com/show/?i=13313&lng=en&c=5</a><br/>
Precomputed Hash Tables<br/>
 <a href="https://a.ndronic.us/pre-computed-hash-table-v-1-0/">https://a.ndronic.us/pre-computed-hash-table-v-1-0/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6542" type="text/plain" language="en" />
<itunes:keywords>hashes, android, phishing, encryption, whats app, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 14th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6540</itunes:episode>
<itunes:subtitle>#Exim Flaw Exploited; @YubiCo Recall; #Telegram Vuln; #Ghidra; VoWifi @sans_edu @0xAmit  
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#Exim Flaw Exploited; @YubiCo Recall; #Telegram Vuln; #Ghidra; VoWifi @sans_edu @0xAmit  
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6540.mp3" length="12821880" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6540.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6540</link>
<pubDate>Fri, 14 Jun 2019 01:10:02 GMT</pubDate>
<description><![CDATA[Exim Flaw Exploited<br/>
 <a href="https://www.cybereason.com/blog/new-pervasive-worm-exploiting-linux-exim-server-vulnerability">https://www.cybereason.com/blog/new-pervasive-worm-exploiting-linux-exim-server-vulnerability</a><br/>
Yubico Recalling FIPS Certified Yubikeys<br/>
 <a href="https://www.yubico.com/support/security-advisories/ysa-2019-02/">https://www.yubico.com/support/security-advisories/ysa-2019-02/</a><br/>
Vulnerable Infusion Pumps<br/>
 <a href="https://www.bd.com/en-us/support/product-security-and-privacy/product-security-bulletins/alaris-gateway-workstation-unauthorized-firmware">https://www.bd.com/en-us/support/product-security-and-privacy/product-security-bulletins/alaris-gateway-workstation-unauthorized-firmware</a><br/>
Telegram DDoS Attack<br/>
 <a href="https://twitter.com/telegram/status/1138768124914929664">https://twitter.com/telegram/status/1138768124914929664</a><br/>
Ghidra Tips for IDA Users: Function Call Graphs<br/>
 <a href="https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+4+function+call+graphs/25032/">https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+4+function+call+graphs/25032/</a><br/>
Joel Chapman: Security Consideration for Voice over Wifi (VoWifi) Systems<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/telephone/paper/38945">https://www.sans.org/reading-room/whitepapers/telephone/paper/38945</a><br/>
]]></description>
<itunes:duration>15:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6540" type="text/plain" language="en" />
<itunes:keywords>joel chapman, sti, vowifi, voice over wifi, ghidra, ida, telegram, ddos, infusion pumps, yubico, fips, exim, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 13th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6538</itunes:episode>
<itunes:subtitle>More SandboxEscaper; Bypassing NTML Message Signing; macOS Keysteal Details @simakov_marina @LinusHenze 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More SandboxEscaper; Bypassing NTML Message Signing; macOS Keysteal Details @simakov_marina @LinusHenze 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6538.mp3" length="4358889" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6538.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6538</link>
<pubDate>Thu, 13 Jun 2019 01:05:03 GMT</pubDate>
<description><![CDATA[Sandbox Escaper Publishes Additional CVE-2019-0841 Bypass<br/>
 <a href="http://archive.is/3toQY">http://archive.is/3toQY</a><br/>
 <a href="http://sandboxescaper.blogspot.com/p/disclosures_8.html">http://sandboxescaper.blogspot.com/p/disclosures_8.html</a><br/>
Bypassing NTLM Message Signing (CVE-2019-1040)<br/>
 <a href="https://blog.preempt.com/drop-the-mic">https://blog.preempt.com/drop-the-mic</a><br/>
Details About macOS Keysteal Vulnerability<br/>
 <a href="https://www.pinauten.de/resources/KeySteal_OBTS_2019.pdf">https://www.pinauten.de/resources/KeySteal_OBTS_2019.pdf</a><br/>
]]></description>
<itunes:duration>5:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6538" type="text/plain" language="en" />
<itunes:keywords>macos, keysteal, ntml, mic, sandboxescaper, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6536</itunes:episode>
<itunes:subtitle>Microsoft, Adobe, Intel, SAP Patches; GPS Woes; RAMBleed
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft, Adobe, Intel, SAP Patches; GPS Woes; RAMBleed
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6536.mp3" length="5232948" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6536.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6536</link>
<pubDate>Wed, 12 Jun 2019 01:45:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/MSFT+June+2019+Patch+Tuesday/25024/">https://isc.sans.edu/forums/diary/MSFT+June+2019+Patch+Tuesday/25024/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
SAP Security Notes<br/>
 <a href="https://www.onapsis.com/blog/sap-patch-notes-june-2019">https://www.onapsis.com/blog/sap-patch-notes-june-2019</a><br/>
Intel Updates<br/>
 <a href="https://www.us-cert.gov/ncas/current-activity/2019/06/11/Intel-Releases-Security-Updates-Mitigations-Multiple-Products">https://www.us-cert.gov/ncas/current-activity/2019/06/11/Intel-Releases-Security-Updates-Mitigations-Multiple-Products</a><br/>
Microsoft Certificate DoS<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1804">https://bugs.chromium.org/p/project-zero/issues/detail?id=1804</a><br/>
GPS Receiver Woes<br/>
 <a href="https://www.flightglobal.com/news/articles/collins-gps-outage-grounds-regional-flights-458819/">https://www.flightglobal.com/news/articles/collins-gps-outage-grounds-regional-flights-458819/</a><br/>
RAMBleed Attack<br/>
 <a href="https://www.documentcloud.org/documents/6150180-RamBleed-attack-CVE-2019-0174.html">https://www.documentcloud.org/documents/6150180-RamBleed-attack-CVE-2019-0174.html</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6536" type="text/plain" language="en" />
<itunes:keywords>rambleed, rowhammer, gps, microsoft, certificate, intel, sap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6534</itunes:episode>
<itunes:subtitle>JavaScript Deobfuscation; Spam Using DNS over HTTPS; BGP Leaks; VLC update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JavaScript Deobfuscation; Spam Using DNS over HTTPS; BGP Leaks; VLC update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6534.mp3" length="5183573" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6534.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6534</link>
<pubDate>Tue, 11 Jun 2019 01:20:02 GMT</pubDate>
<description><![CDATA[Interesting JavaScript Obfuscation Example<br/>
 <a href="https://isc.sans.edu/forums/diary/Interesting+JavaScript+Obfuscation+Example/25020/">https://isc.sans.edu/forums/diary/Interesting+JavaScript+Obfuscation+Example/25020/</a><br/>
Spam Taking Advantage of DNS over HTTPS<br/>
 <a href="https://myonlinesecurity.co.uk/it-looks-like-another-dns-compromise-hack-happening/">https://myonlinesecurity.co.uk/it-looks-like-another-dns-compromise-hack-happening/</a><br/>
European Mobile Operator Traffic Leaked to China<br/>
 <a href="https://arstechnica.com/information-technology/2019/06/bgp-mishap-sends-european-mobile-traffic-through-china-telecom-for-2-hours/?comments=1">https://arstechnica.com/information-technology/2019/06/bgp-mishap-sends-european-mobile-traffic-through-china-telecom-for-2-hours/?comments=1</a><br/>
VLC Update Patches Various Security Flaws<br/>
 <a href="http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security">http://www.jbkempf.com/blog/post/2019/VLC-3.0.7-and-security</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6534" type="text/plain" language="en" />
<itunes:keywords>vlc, bug bounty, european comission, mobile traffic, safe host, china telecom, spam, dns over https, doh, javascript obfuscation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6532</itunes:episode>
<itunes:subtitle>WMI Logs; DNS Logs and Sysmon; Komodo Wallet Highjack; MSFT SOC Lessons #MSFT #DNS 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WMI Logs; DNS Logs and Sysmon; Komodo Wallet Highjack; MSFT SOC Lessons #MSFT #DNS 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6532.mp3" length="6420417" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6532.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6532</link>
<pubDate>Mon, 10 Jun 2019 02:35:02 GMT</pubDate>
<description><![CDATA[Keep An Eye On Your WMI Logs<br/>
 <a href="https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Your+WMI+Logs/25012/">https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Your+WMI+Logs/25012/</a><br/>
Sysmon DNS Query Logging<br/>
 <a href="https://isc.sans.edu/forums/diary/Tip+Sysmon+Will+Log+DNS+Queries/25016/">https://isc.sans.edu/forums/diary/Tip+Sysmon+Will+Log+DNS+Queries/25016/</a><br/>
Komodo Agama Vulnerability and Breach <br/>
 <a href="https://komodoplatform.com/update-agama-vulnerability/">https://komodoplatform.com/update-agama-vulnerability/</a><br/>
Lessons Learned From Microsoft SOC<br/>
 <a href="https://www.microsoft.com/security/blog/2019/06/06/lessons-learned-from-the-microsoft-soc-part-2b-career-paths-and-readiness/">https://www.microsoft.com/security/blog/2019/06/06/lessons-learned-from-the-microsoft-soc-part-2b-career-paths-and-readiness/</a><br/>
]]></description>
<itunes:duration>7:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6532" type="text/plain" language="en" />
<itunes:keywords>msft, soc, agama, komodo, sysmon, dns, wmi, logs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6530</itunes:episode>
<itunes:subtitle>GoldBrute Botnet; Exim Vulnerability; iOS Apps Disabling TLS  @wandera @renato_marinho @bojanz
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GoldBrute Botnet; Exim Vulnerability; iOS Apps Disabling TLS  @wandera @renato_marinho @bojanz
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6530.mp3" length="6086885" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6530.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6530</link>
<pubDate>Thu, 06 Jun 2019 23:20:02 GMT</pubDate>
<description><![CDATA[GoldBrute Botnet Brute Forcing RDP<br/>
 <a href="https://isc.sans.edu/forums/diary/GoldBrute+Botnet+Brute+Forcing+15+Million+RDP+Servers/25002/">https://isc.sans.edu/forums/diary/GoldBrute+Botnet+Brute+Forcing+15+Million+RDP+Servers/25002/</a><br/>
Exim Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/Time+is+partially+on+our+side+the+new+Exim+vulnerability/25008/">https://isc.sans.edu/forums/diary/Time+is+partially+on+our+side+the+new+Exim+vulnerability/25008/</a><br/>
iOS App Developers Disabling TLS<br/>
 <a href="https://www.wandera.com/mobile-security/ios-app-developer-security-shortcuts/">https://www.wandera.com/mobile-security/ios-app-developer-security-shortcuts/</a><br/>
]]></description>
<itunes:duration>7:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6530" type="text/plain" language="en" />
<itunes:keywords>rdp, golbrute, exim, ios, tls, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 6th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6528</itunes:episode>
<itunes:subtitle>Android Updates; Chrome Updates; Bing Injecting Mac Malware  @AiroSecurity @Akamai
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Android Updates; Chrome Updates; Bing Injecting Mac Malware  @AiroSecurity @Akamai
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6528.mp3" length="4524192" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6528.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6528</link>
<pubDate>Thu, 06 Jun 2019 00:35:02 GMT</pubDate>
<description><![CDATA[Android Monthly Update<br/>
 <a href="https://source.android.com/security/bulletin/2019-06-01">https://source.android.com/security/bulletin/2019-06-01</a><br/>
Google Chrome Updates <br/>
 <a href="https://chromereleases.googleblog.com/2019/06/stable-channel-update-for-desktop.html">https://chromereleases.googleblog.com/2019/06/stable-channel-update-for-desktop.html</a><br/>
MacOS Malware Injects Bing Ads<br/>
 <a href="https://www.airoav.com/mitm-proxy-a-new-search-hijack-method-on-mojave/">https://www.airoav.com/mitm-proxy-a-new-search-hijack-method-on-mojave/</a><br/>
Kubernetes Vulnerability<br/>
 <a href="https://github.com/kubernetes/kubernetes/issues/78308">https://github.com/kubernetes/kubernetes/issues/78308</a><br/>
Vulnerabilities in Phihsing Kits<br/>
 <a href="https://blogs.akamai.com/sitr/2019/06/identifying-vulnerabilities-in-phishing-kits.html">https://blogs.akamai.com/sitr/2019/06/identifying-vulnerabilities-in-phishing-kits.html</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6528" type="text/plain" language="en" />
<itunes:keywords>phishing kits, kubernetes, kubelet, macos, bing, google, chrome, android, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 5th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6526</itunes:episode>
<itunes:subtitle>Notepad Bug; vim bug; New RDP Vulnerability; @rawsec @taviso
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Notepad Bug; vim bug; New RDP Vulnerability; @rawsec @taviso
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6526.mp3" length="4672308" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6526.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6526</link>
<pubDate>Wed, 05 Jun 2019 01:00:03 GMT</pubDate>
<description><![CDATA[Vulnerability in Notepad<br/>
 <a href="https://threatpost.com/researcher-exploits-microsofts-notepad-to-pop-a-shell/145242/">https://threatpost.com/researcher-exploits-microsofts-notepad-to-pop-a-shell/145242/</a><br/>
Vulnerability in vim/neovim<br/>
 <a href="https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md">https://github.com/numirias/security/blob/master/doc/2019-06-04_ace-vim-neovim.md</a><br/>
RDP Session Hijack Vulnerability<br/>
 <a href="https://kb.cert.org/vuls/id/576688/">https://kb.cert.org/vuls/id/576688/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6526" type="text/plain" language="en" />
<itunes:keywords>rdp, session hijack, vim, neovim, notepad, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6524</itunes:episode>
<itunes:subtitle>macOS Synthetic Clicks; Intel Microcode for Old Win 10; Fake AV in Games; GandGrab
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
macOS Synthetic Clicks; Intel Microcode for Old Win 10; Fake AV in Games; GandGrab
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6524.mp3" length="4600259" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6524.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6524</link>
<pubDate>Tue, 04 Jun 2019 02:00:03 GMT</pubDate>
<description><![CDATA[Bypassing macOS Synthetic Click Protection<br/>
 <a href="https://www.wired.com/story/apple-macos-bug-synthetic-clicks/">https://www.wired.com/story/apple-macos-bug-synthetic-clicks/</a><br/>
Intel Microcode Updates for Older Windows 10 Versions<br/>
 <a href="https://support.microsoft.com/en-us/help/4494454/kb4494454-intel-microcode-updates">https://support.microsoft.com/en-us/help/4494454/kb4494454-intel-microcode-updates</a><br/>
Fake AntiVirus Adds in Microsoft Games<br/>
 <a href="https://answers.microsoft.com/en-us/windows/forum/all/malvertising-attack-on-microsoft-games/ced7ab87-7e0e-422b-97b7-fbfaed2b68a0">https://answers.microsoft.com/en-us/windows/forum/all/malvertising-attack-on-microsoft-games/ced7ab87-7e0e-422b-97b7-fbfaed2b68a0</a><br/>
GandGrab Shutting Down<br/>
 <a href="https://www.zdnet.com/article/gandcrab-ransomware-operation-says-its-shutting-down/">https://www.zdnet.com/article/gandcrab-ransomware-operation-says-its-shutting-down/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6524" type="text/plain" language="en" />
<itunes:keywords>macos, clicks, objectivesee, gandgrab, fake antivirus, intel, microcode, windows 10, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6522</itunes:episode>
<itunes:subtitle>Google Outage; Siemens LOGO 8! BM Vulnerablity; Exposing tor users; nginx njs vulnerability; #google #siemens #nginx #tor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Outage; Siemens LOGO 8! BM Vulnerablity; Exposing tor users; nginx njs vulnerability; #google #siemens #nginx #tor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6522.mp3" length="5011685" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6522.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6522</link>
<pubDate>Mon, 03 Jun 2019 01:45:02 GMT</pubDate>
<description><![CDATA[Google Outage<br/>
 <a href="https://status.cloud.google.com/incident/compute/19003">https://status.cloud.google.com/incident/compute/19003</a><br/>
Major Vulnerability in Siemens LOGO Controllers<br/>
 <a href="https://cert-portal.siemens.com/productcert/pdf/ssa-542701.pdf">https://cert-portal.siemens.com/productcert/pdf/ssa-542701.pdf</a><br/>
Exposing TOR Users Via Cache Poisoning<br/>
 <a href="https://blog.duszynski.eu/tor-ip-disclosure-through-http-301-cache-poisoning/">https://blog.duszynski.eu/tor-ip-disclosure-through-http-301-cache-poisoning/</a><br/>
nginx njs Vulnerability<br/>
 <a href="https://github.com/nginx/njs/issues/131">https://github.com/nginx/njs/issues/131</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6522" type="text/plain" language="en" />
<itunes:keywords>tor, siemens, logo, google, outage, nginx, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 31st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6520</itunes:episode>
<itunes:subtitle>scdbg Shellcode Analysis; GitHub Auto Patching; Docker Malware and Shodan; Web Packaging
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
scdbg Shellcode Analysis; GitHub Auto Patching; Docker Malware and Shodan; Web Packaging
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6520.mp3" length="5661192" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6520.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6520</link>
<pubDate>Fri, 31 May 2019 02:10:02 GMT</pubDate>
<description><![CDATA[Analysing Shell Code with scdbg<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+First+Stage+Shellcode/24984/">https://isc.sans.edu/forums/diary/Analyzing+First+Stage+Shellcode/24984/</a><br/>
GitHub Automating Security Patches<br/>
 <a href="https://help.github.com/en/articles/configuring-automated-security-fixes">https://help.github.com/en/articles/configuring-automated-security-fixes</a><br/>
Exposed Docker Containers Uses for Cryptocoin Mining<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/infected-cryptocurrency-mining-containers-target-docker-hosts-with-exposed-apis-use-shodan-to-find-additional-victims/">https://blog.trendmicro.com/trendlabs-security-intelligence/infected-cryptocurrency-mining-containers-target-docker-hosts-with-exposed-apis-use-shodan-to-find-additional-victims/</a><br/>
Mozilla Objecting To Web Packaging<br/>
 <a href="https://docs.google.com/document/d/1ha00dSGKmjoEh2mRiG8FIA5sJ1KihTuZe-AXX1r8P-8/preview#">https://docs.google.com/document/d/1ha00dSGKmjoEh2mRiG8FIA5sJ1KihTuZe-AXX1r8P-8/preview#</a><br/>
]]></description>
<itunes:duration>6:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6520" type="text/plain" language="en" />
<itunes:keywords>mozillay, web packaging, docker, api, cryptocoin, shodan, github, scdbg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6518</itunes:episode>
<itunes:subtitle>MSFT ASA Malware Analysis; Docker Symlink Race Attack; Nanshu Campaign; #MSFT #docker
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT ASA Malware Analysis; Docker Symlink Race Attack; Nanshu Campaign; #MSFT #docker
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6518.mp3" length="5155043" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6518.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6518</link>
<pubDate>Thu, 30 May 2019 11:10:02 GMT</pubDate>
<description><![CDATA[Behavioural Malware Analysis With Microsoft Attack Surface Analyzer<br/>
 <a href="https://isc.sans.edu/forums/diary/Behavioural+Malware+Analysis+with+Microsoft+ASA/24980/">https://isc.sans.edu/forums/diary/Behavioural+Malware+Analysis+with+Microsoft+ASA/24980/</a><br/>
Docker Symlink Race Attack<br/>
 <a href="https://seclists.org/oss-sec/2019/q2/131">https://seclists.org/oss-sec/2019/q2/131</a><br/>
Nanshu Campaign Using Signed Rootkit<br/>
 <a href="https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/">https://www.guardicore.com/2019/05/nansh0u-campaign-hackers-arsenal-grows-stronger/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6518" type="text/plain" language="en" />
<itunes:keywords>nanshu, guardicore, docker, microsoft, asa, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 29th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6516</itunes:episode>
<itunes:subtitle>BASE64 Encoded Powershell; #BlueKeep Census; MSFT DHCP Client Vuln Analysis; @sensepost @ErrataRob @0xdf_
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BASE64 Encoded Powershell; #BlueKeep Census; MSFT DHCP Client Vuln Analysis; @sensepost @ErrataRob @0xdf_
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6516.mp3" length="5017541" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6516.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6516</link>
<pubDate>Wed, 29 May 2019 03:25:02 GMT</pubDate>
<description><![CDATA[Office Document And Base64 Encoded PowerShell Script<br/>
 <a href="https://isc.sans.edu/forums/diary/Office+Document+BASE64+PowerShell/24976/">https://isc.sans.edu/forums/diary/Office+Document+BASE64+PowerShell/24976/</a><br/>
 <a href="https://0xdf.gitlab.io/2019/05/21/malware-analysis-unnamed-emotet-doc.html">https://0xdf.gitlab.io/2019/05/21/malware-analysis-unnamed-emotet-doc.html</a><br/>
Enumeration of BlueKeep Vulnerable Hosts<br/>
 <a href="https://blog.erratasec.com/2019/05/almost-one-million-vulnerable-to.html">https://blog.erratasec.com/2019/05/almost-one-million-vulnerable-to.html</a><br/>
DHCP Client Vulnerablity Analysis<br/>
 <a href="https://sensepost.com/blog/2019/analysis-of-a-1day-cve-2019-0547-and-discovery-of-a-forgotten-condition-in-the-patch-cve-2019-0726-part-1-of-2/">https://sensepost.com/blog/2019/analysis-of-a-1day-cve-2019-0547-and-discovery-of-a-forgotten-condition-in-the-patch-cve-2019-0726-part-1-of-2/</a><br/>
Office File Deleting Phishing Emails<br/>
 <a href="https://www.bleepingcomputer.com/news/security/phishing-emails-pretend-to-be-office-365-file-deletion-alerts/">https://www.bleepingcomputer.com/news/security/phishing-emails-pretend-to-be-office-365-file-deletion-alerts/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6516" type="text/plain" language="en" />
<itunes:keywords>office, phishing, azure, dhcp, microsoft, msft, bluekeep, erratasec, powershell, base64, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 28th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6514</itunes:episode>
<itunes:subtitle>GateKeeper Bypass; FortiOS SSL VPN Vulnerablities; Customizing NMAP
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GateKeeper Bypass; FortiOS SSL VPN Vulnerablities; Customizing NMAP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6514.mp3" length="4851137" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6514.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6514</link>
<pubDate>Tue, 28 May 2019 00:40:02 GMT</pubDate>
<description><![CDATA[MacOS GateKeeper Bypass<br/>
 <a href="https://www.fcvl.net/vulnerabilities/macosx-gatekeeper-bypass">https://www.fcvl.net/vulnerabilities/macosx-gatekeeper-bypass</a><br/>
Fortinet FortiOS SSL VPN Vulnerabilities<br/>
 <a href="https://fortiguard.com/psirt">https://fortiguard.com/psirt</a><br/>
Customizing NMAP Service Detection<br/>
 <a href="https://isc.sans.edu/forums/diary/Video+nmap+Service+Detection+Customization/24970/">https://isc.sans.edu/forums/diary/Video+nmap+Service+Detection+Customization/24970/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6514" type="text/plain" language="en" />
<itunes:keywords>nmap, fortinet, fortios, ssl vpn, macos, gatekeeper, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 24th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6512</itunes:episode>
<itunes:subtitle>Custom URL Schemes; Skimming Trends; #Apple T2 Chip Update; #MSFT APT for MacOS @IntelAdvanced @zer0pwn
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Custom URL Schemes; Skimming Trends; #Apple T2 Chip Update; #MSFT APT for MacOS @IntelAdvanced @zer0pwn
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6512.mp3" length="5123226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6512.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6512</link>
<pubDate>Fri, 24 May 2019 00:25:02 GMT</pubDate>
<description><![CDATA[Dangers of Custom URL Schemes<br/>
 <a href="https://zeropwn.github.io/2019-05-22-fun-with-uri-handlers/">https://zeropwn.github.io/2019-05-22-fun-with-uri-handlers/</a><br/>
Update on Phyiscal Skimmer Market<br/>
 <a href="https://www.advanced-intel.com/blog/skimming-threat-landscape-technology-advances-lower-barriers-of-entry-for-novice-skimming-operators">https://www.advanced-intel.com/blog/skimming-threat-landscape-technology-advances-lower-barriers-of-entry-for-novice-skimming-operators</a><br/>
Apple Supplemental Update For masOS 10.14.5<br/>
 <a href="https://support.apple.com/kb/DL2005?locale=en_US">https://support.apple.com/kb/DL2005?locale=en_US</a><br/>
Microsoft Releases Advanced Threat Protection for MacOS<br/>
 <a href="https://techcommunity.microsoft.com/t5/Windows-Defender-ATP/Microsoft-Defender-ATP-for-Mac-now-in-open-public-preview/ba-p/634603">https://techcommunity.microsoft.com/t5/Windows-Defender-ATP/Microsoft-Defender-ATP-for-Mac-now-in-open-public-preview/ba-p/634603</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6512" type="text/plain" language="en" />
<itunes:keywords>microsoft, apt, macos, t2, skimmer, url schemes, origin, ea, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6510</itunes:episode>
<itunes:subtitle>Yet Another BlueKeep Update; SanboxExcaper; Signed Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Yet Another BlueKeep Update; SanboxExcaper; Signed Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6510.mp3" length="5306819" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6510.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6510</link>
<pubDate>Wed, 22 May 2019 22:55:02 GMT</pubDate>
<description><![CDATA[An Update on the Microsoft Windows RDP BlueKeep Vulnerablity<br/>
 <a href="https://isc.sans.edu/forums/diary/An+Update+on+the+Microsoft+Windows+RDP+Bluekeep+Vulnerability+CVE20190708+now+with+pcaps/24960/">https://isc.sans.edu/forums/diary/An+Update+on+the+Microsoft+Windows+RDP+Bluekeep+Vulnerability+CVE20190708+now+with+pcaps/24960/</a><br/>
New Zero Day Exploits by SandboxEscaper <br/>
 <a href="https://github.com/SandboxEscaper/polarbearrepo">https://github.com/SandboxEscaper/polarbearrepo</a><br/>
Signed Exploit Code<br/>
 <a href="https://medium.com/@chroniclesec/abusing-code-signing-for-profit-ef80a37b50f4">https://medium.com/@chroniclesec/abusing-code-signing-for-profit-ef80a37b50f4</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6510" type="text/plain" language="en" />
<itunes:keywords>certificates, code signign, sandboxescaper, task scheduler, rdp, bluekeep, cve-2019-0708, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6508</itunes:episode>
<itunes:subtitle>Shodan Monitoring; Smartphone Fingerprinting; Docker Password Issues; #bluekeep #suricata sigs;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Shodan Monitoring; Smartphone Fingerprinting; Docker Password Issues; #bluekeep #suricata sigs;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6508.mp3" length="4662798" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6508.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6508</link>
<pubDate>Tue, 21 May 2019 23:45:03 GMT</pubDate>
<description><![CDATA[Setting Up Shodan Monitoring<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Shodan+Monitoring/24956/">https://isc.sans.edu/forums/diary/Using+Shodan+Monitoring/24956/</a><br/>
Fingerprinting Smartphones With Gyroscope Data<br/>
 <a href="https://sensorid.cl.cam.ac.uk/">https://sensorid.cl.cam.ac.uk/</a><br/>
20% of Linux Docker Containers Without Password<br/>
 <a href="https://www.kennasecurity.com/20-of-the-1000-most-popular-docker-containers-have-no-root-password/">https://www.kennasecurity.com/20-of-the-1000-most-popular-docker-containers-have-no-root-password/</a><br/>
RDP #bluekeep Signature For Snort/Suricata<br/>
 <a href="https://github.com/nccgroup/Cyber-Defence/blob/master/Signatures/suricata/2019_05_rdp_cve_2019_0708.txt">https://github.com/nccgroup/Cyber-Defence/blob/master/Signatures/suricata/2019_05_rdp_cve_2019_0708.txt</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6508" type="text/plain" language="en" />
<itunes:keywords>bluekeep, snort, suricata, shodan, docker, passwords, smartphones, gyroscope, fingerprinting, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6506</itunes:episode>
<itunes:subtitle>MSFT RDP Vuln (#BlueKeep) Update; Sharepoint Exploited; JWT Risks; MuddyWater
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT RDP Vuln (#BlueKeep) Update; Sharepoint Exploited; JWT Risks; MuddyWater
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6506.mp3" length="4489811" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6506.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6506</link>
<pubDate>Mon, 20 May 2019 23:20:03 GMT</pubDate>
<description><![CDATA[MSFT RDP Vulnerability (#BlueKeep) Update<br/>
 <a href="https://twitter.com/search?q=%23bluekeep">https://twitter.com/search?q=%23bluekeep</a><br/>
Sharepoint Exploited<br/>
 <a href="https://isc.sans.edu/forums/diary/CVE20190604+Attack/24952/">https://isc.sans.edu/forums/diary/CVE20190604+Attack/24952/</a><br/>
Risks of JWT<br/>
 <a href="https://snikt.net/blog/2019/05/16/jwt-signature-vs-mac-attacks/">https://snikt.net/blog/2019/05/16/jwt-signature-vs-mac-attacks/</a><br/>
MuddyWater Campaign Evolves<br/>
 <a href="https://blog.talosintelligence.com/2019/05/recent-muddywater-associated-blackwater.html">https://blog.talosintelligence.com/2019/05/recent-muddywater-associated-blackwater.html</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6506" type="text/plain" language="en" />
<itunes:keywords>muddywater, cisco, jwt, sharepoint, msft, rdp, bluekeep, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6504</itunes:episode>
<itunes:subtitle>Google 0-Day Response Analysis; #ASUS WebStorage Exploited; #Apple Air Drop Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google 0-Day Response Analysis; #ASUS WebStorage Exploited; #Apple Air Drop Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6504.mp3" length="4743980" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6504.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6504</link>
<pubDate>Sun, 19 May 2019 23:40:02 GMT</pubDate>
<description><![CDATA[Google Analyzes Vendor Response to 0-Day Exploits<br/>
 <a href="https://googleprojectzero.blogspot.com/p/0day.html">https://googleprojectzero.blogspot.com/p/0day.html</a><br/>
ASUS WebStorage Abused For Malware Distribution<br/>
 <a href="https://www.welivesecurity.com/2019/05/14/plead-malware-mitm-asus-webstorage/">https://www.welivesecurity.com/2019/05/14/plead-malware-mitm-asus-webstorage/</a><br/>
Vulnerabilities in Apple Air Drop<br/>
 <a href="https://www.usenix.org/system/files/sec19fall_stute_prepub.pdf">https://www.usenix.org/system/files/sec19fall_stute_prepub.pdf</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6504" type="text/plain" language="en" />
<itunes:keywords>airdrop, apple, webstorage, asus, google, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6502</itunes:episode>
<itunes:subtitle>Vulnerability Scanner NTLM Relay; ARIN Revokes Malicious IPs; Cisco Patches; ILS Hacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Vulnerability Scanner NTLM Relay; ARIN Revokes Malicious IPs; Cisco Patches; ILS Hacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6502.mp3" length="5073855" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6502.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6502</link>
<pubDate>Fri, 17 May 2019 00:50:02 GMT</pubDate>
<description><![CDATA[The Risk of Authenticated Vulnerability Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Risk+of+Authenticated+Vulnerability+Scans/24942/">https://isc.sans.edu/forums/diary/The+Risk+of+Authenticated+Vulnerability+Scans/24942/</a><br/>
ARIN Revokes about 735,000 IP Addresses<br/>
 <a href="https://www.arin.net/vault/about_us/media/releases/20190513.html">https://www.arin.net/vault/about_us/media/releases/20190513.html</a><br/>
More Cisco Patches (Prime Infrastructure, EPN Manager)<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-pi-rce">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-pi-rce</a><br/>
Instrument Landing Systems Spoofing<br/>
 <a href="https://aanjhan.com/assets/ils_usenix2019.pdf">https://aanjhan.com/assets/ils_usenix2019.pdf</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6502" type="text/plain" language="en" />
<itunes:keywords>isf, dsr, landing system, planes, cisco, patches, arin, ip addresses, vulnerability scans, openvas, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6500</itunes:episode>
<itunes:subtitle>Forbes vs Magecart; TLS Tampering; Titan Key Update; Samba Patch; SAP Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Forbes vs Magecart; TLS Tampering; Titan Key Update; Samba Patch; SAP Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6500.mp3" length="4384853" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6500.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6500</link>
<pubDate>Thu, 16 May 2019 03:10:02 GMT</pubDate>
<description><![CDATA[Forbes Website Infected by Magecart<br/>
 <a href="https://twitter.com/bad_packets/status/1128517905765683201">https://twitter.com/bad_packets/status/1128517905765683201</a><br/>
Malware Randomizes TLS Ciphers<br/>
 <a href="https://blogs.akamai.com/sitr/2019/05/bots-tampering-with-tls-to-avoid-detection.html">https://blogs.akamai.com/sitr/2019/05/bots-tampering-with-tls-to-avoid-detection.html</a><br/>
Google Recalls Titan Security Keys<br/>
 <a href="https://security.googleblog.com/2019/05/titan-keys-update.html">https://security.googleblog.com/2019/05/titan-keys-update.html</a><br/>
SAMBA Update<br/>
 <a href="https://www.samba.org/samba/security/CVE-2018-16860.html">https://www.samba.org/samba/security/CVE-2018-16860.html</a><br/>
SAP Patches<br/>
 <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032">https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=520259032</a><br/>
]]></description>
<itunes:duration>5:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6500" type="text/plain" language="en" />
<itunes:keywords>SAP, SAMBA, Google, Titan, WebAuthn, TLS, ciphers, forbes, magecart, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6498</itunes:episode>
<itunes:subtitle>More #Intel CPU Issues; #MSFT Patches (watch out #RDP!); #Apple/#Adobe Updates; Broken Trust Seal Logs Keystrokes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More #Intel CPU Issues; #MSFT Patches (watch out #RDP!); #Apple/#Adobe Updates; Broken Trust Seal Logs Keystrokes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6498.mp3" length="5259644" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6498.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6498</link>
<pubDate>Wed, 15 May 2019 03:25:02 GMT</pubDate>
<description><![CDATA[New Intel CPU Vulnerabilities<br/>
<a href="https://cpu.fail/">https://cpu.fail/</a><br/>
Microsoft Patch Tuesday<br/>
<a href="https://isc.sans.edu/forums/diary/Microsoft+May+2019+Patch+Tuesday/24934/">https://isc.sans.edu/forums/diary/Microsoft+May+2019+Patch+Tuesday/24934/</a><br/>
Apple Updates<br/>
<a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Broken Trustseal<br/>
<a href="https://twitter.com/gwillem/status/1127890329175244800">https://twitter.com/gwillem/status/1127890329175244800</a><br/>
<a href="https://twitter.com/bestoftheweb/status/1128036593208524800">https://twitter.com/bestoftheweb/status/1128036593208524800</a><br/>
]]></description>
<itunes:duration>6:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6498" type="text/plain" language="en" />
<itunes:keywords>trust seal, best of the web, apple, rdp, microsoft, patches, intel, zombieland, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 14th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6496</itunes:episode>
<itunes:subtitle>Linux rds_tcp_kill_sock RCE; WhatsApp; Cisco Vuln; Linksys JNAP Exposure
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Linux rds_tcp_kill_sock RCE; WhatsApp; Cisco Vuln; Linksys JNAP Exposure
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6496.mp3" length="4679251" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6496.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6496</link>
<pubDate>Tue, 14 May 2019 04:20:02 GMT</pubDate>
<description><![CDATA[Linux Remote Code Execution When Closing TCP Sockets<br/>
 <a href="https://github.com/torvalds/linux/commit/cb66ddd156203daefb8d71158036b27b0e2caf63">https://github.com/torvalds/linux/commit/cb66ddd156203daefb8d71158036b27b0e2caf63</a><br/>
WhatsApp Buffer Overflow Exploited to Install Spyware<br/>
 <a href="https://www.facebook.com/security/advisories/cve-2019-3568">https://www.facebook.com/security/advisories/cve-2019-3568</a><br/>
Cisco Vulnerabilities Lead to Trust Anchor Module Exploit<br/>
 <a href="https://thrangrycat.com/">https://thrangrycat.com/</a><br/>
Linksys Unauthenticated Information Leak<br/>
 <a href="https://badpackets.net/over-25000-linksys-smart-wi-fi-routers-vulnerable-to-sensitive-information-disclosure-flaw/">https://badpackets.net/over-25000-linksys-smart-wi-fi-routers-vulnerable-to-sensitive-information-disclosure-flaw/</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6496" type="text/plain" language="en" />
<itunes:keywords>linksys, jnap, cisco, thrangrycat, whatsapp, spyware, linux, tcp, rce, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 13th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6494</itunes:episode>
<itunes:subtitle>#DSSuite; #Sqlite Vuln; #NVidia Patch; Windows 10 #FIDO2 Cert; #Google ADB Backup
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#DSSuite; #Sqlite Vuln; #NVidia Patch; Windows 10 #FIDO2 Cert; #Google ADB Backup
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6494.mp3" length="4337306" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6494.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6494</link>
<pubDate>Mon, 13 May 2019 02:45:03 GMT</pubDate>
<description><![CDATA[DSSuite - A Docker Container with Didier's Tools<br/>
 <a href="https://isc.sans.edu/forums/diary/DSSuite+A+Docker+Container+with+Didiers+Tools/24926/">https://isc.sans.edu/forums/diary/DSSuite+A+Docker+Container+with+Didiers+Tools/24926/</a><br/>
Sqlite3 Vulnerability<br/>
 <a href="https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0777">https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0777</a><br/>
NVidia Updates<br/>
 <a href="https://nvidia.custhelp.com/app/answers/detail/a_id/4797">https://nvidia.custhelp.com/app/answers/detail/a_id/4797</a><br/>
Windows 10 FIDO2 Certified<br/>
 <a href="https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/">https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/</a><br/>
Google May Remove ADB Backup/Restore from Future Android Versions<br/>
 <a href="https://www.xda-developers.com/adb-backup-and-restore-depreciated/">https://www.xda-developers.com/adb-backup-and-restore-depreciated/</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6494" type="text/plain" language="en" />
<itunes:keywords>google, windows, fido2, sqlite3, nvidia, dssuite, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6492</itunes:episode>
<itunes:subtitle>ELECTRICFISH; Fake Keepass Site; Android Updates; AV Company Breah
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ELECTRICFISH; Fake Keepass Site; Android Updates; AV Company Breah
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6492.mp3" length="4681443" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6492.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6492</link>
<pubDate>Fri, 10 May 2019 04:20:02 GMT</pubDate>
<description><![CDATA[US DHS Warns of North Korean ELECTRICFISH Malware<br/>
 <a href="https://www.us-cert.gov/ncas/analysis-reports/AR19-129A">https://www.us-cert.gov/ncas/analysis-reports/AR19-129A</a><br/>
Fake KeePass Site Spreading Malware<br/>
 <a href="https://twitter.com/berkcgoksel/status/1125727590440931329">https://twitter.com/berkcgoksel/status/1125727590440931329</a><br/>
Google Android Security Bulletin<br/>
 <a href="https://source.android.com/security/bulletin/2019-05-01">https://source.android.com/security/bulletin/2019-05-01</a><br/>
Three Anti-Virus Companies Breached<br/>
 <a href="https://www.advanced-intel.com/blog/top-tier-russian-hacking-collective-claims-breaches-of-three-major-anti-virus-companies">https://www.advanced-intel.com/blog/top-tier-russian-hacking-collective-claims-breaches-of-three-major-anti-virus-companies</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6492" type="text/plain" language="en" />
<itunes:keywords>fxmsp, electricfish, dhs, keepass, google, android, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6490</itunes:episode>
<itunes:subtitle>EMail Roulette; Lightneuron Exchange Compromise; Alpine Linux Docker; Wordpress Secures Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
EMail Roulette; Lightneuron Exchange Compromise; Alpine Linux Docker; Wordpress Secures Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6490.mp3" length="4847482" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6490.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6490</link>
<pubDate>Thu, 09 May 2019 03:48:10 GMT</pubDate>
<description><![CDATA[EMail Roulette May 2019<br/>
 <a href="https://isc.sans.edu/forums/diary/Email+roulette+May+2019/24918/">https://isc.sans.edu/forums/diary/Email+roulette+May+2019/24918/</a><br/>
Turla Lightneuron<br/>
 <a href="https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf">https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf</a><br/>
Alpine Linux Docker Image root User Hard Coded Credentials<br/>
 <a href="https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782">https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782</a><br/>
Worpress 5.2 Adds Digitially Signed Updates<br/>
 <a href="https://wordpress.org/support/wordpress-version/version-5-2/">https://wordpress.org/support/wordpress-version/version-5-2/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6490" type="text/plain" language="en" />
<itunes:keywords>wordpress, alpine, docker, root, password, updates, turla, lightneuron, exchange, email, roulette, ransomware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6488</itunes:episode>
<itunes:subtitle>Jenkins Exploit Mines Crypto; Confluence Miners; Cisco ESC REST Vuln; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Jenkins Exploit Mines Crypto; Confluence Miners; Cisco ESC REST Vuln; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6488.mp3" length="4200901" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6488.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6488</link>
<pubDate>Wed, 08 May 2019 01:25:02 GMT</pubDate>
<description><![CDATA[Jenkins Exploit Mines Cryptocurrencies<br/>
 <a href="https://isc.sans.edu/forums/diary/Vulnerable+Apache+Jenkins+exploited+in+the+wild/24916/">https://isc.sans.edu/forums/diary/Vulnerable+Apache+Jenkins+exploited+in+the+wild/24916/</a><br/>
Confluence Vulnerablity Exploited to Delivery Cryptocurrency Miner with Rootkit<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/cve-2019-3396-redux-confluence-vulnerability-exploited-to-deliver-cryptocurrency-miner-with-rootkit/">https://blog.trendmicro.com/trendlabs-security-intelligence/cve-2019-3396-redux-confluence-vulnerability-exploited-to-deliver-cryptocurrency-miner-with-rootkit/</a><br/>
Cisco Elastic Services Controller REST API Authentication Bypass<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190507-esc-authbypass">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190507-esc-authbypass</a><br/>
Google Chrome History Manipulation Prevention<br/>
 <a href="https://groups.google.com/a/chromium.org/forum/?#!msg/blink-dev/T8d4_BRb2xQ/WSdOiOFcBAAJ">https://groups.google.com/a/chromium.org/forum/?#!msg/blink-dev/T8d4_BRb2xQ/WSdOiOFcBAAJ</a><br/>
]]></description>
<itunes:duration>4:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6488" type="text/plain" language="en" />
<itunes:keywords>google chrome, history, cisco, elastic services controller, esc, rest, confluence, miner, jenkins, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6486</itunes:episode>
<itunes:subtitle>UTF-16 in UDF Files; VMWare Fusion RCE; Bad Bad Guy Passwords; Amazon S3 Path Style Access
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
UTF-16 in UDF Files; VMWare Fusion RCE; Bad Bad Guy Passwords; Amazon S3 Path Style Access
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6486.mp3" length="5209537" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6486.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6486</link>
<pubDate>Tue, 07 May 2019 01:35:02 GMT</pubDate>
<description><![CDATA[Decoding UTF-16 in UDF Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Text+and+TNULeNULxNULtNUL/24912/">https://isc.sans.edu/forums/diary/Text+and+TNULeNULxNULtNUL/24912/</a><br/>
VMWare Fusion 11 Guest VM RCE<br/>
 <a href="https://theevilbit.github.io/posts/vmware_fusion_11_guest_vm_rce_cve-2019-5514/">https://theevilbit.github.io/posts/vmware_fusion_11_guest_vm_rce_cve-2019-5514/</a><br/>
Hackers Are Using Bad Passwords Too<br/>
 <a href="https://www.ankitanubhav.info/post/c2bruting">https://www.ankitanubhav.info/post/c2bruting</a><br/>
Amazon S3 Discontinues Path Style Access<br/>
 <a href="https://www.bleepingcomputer.com/news/security/amazon-to-disable-s3-path-style-access-used-to-bypass-censorship/">https://www.bleepingcomputer.com/news/security/amazon-to-disable-s3-path-style-access-used-to-bypass-censorship/</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6486" type="text/plain" language="en" />
<itunes:keywords>amazone, s3, hackers, passwords, vmware, rce, websocket, udf, utf-16, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 6th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6484</itunes:episode>
<itunes:subtitle>Git Ransomware; DLink Ransomware Patch; Jenkins Plugins; Malicious WPAD
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Git Ransomware; DLink Ransomware Patch; Jenkins Plugins; Malicious WPAD
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6484.mp3" length="5504666" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6484.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6484</link>
<pubDate>Sun, 05 May 2019 23:45:02 GMT</pubDate>
<description><![CDATA[Git Ransomware<br/>
 <a href="https://www.theregister.co.uk/2019/05/03/git_ransomware_bitcoin/">https://www.theregister.co.uk/2019/05/03/git_ransomware_bitcoin/</a><br/>
DLink Ransomware Patch<br/>
 <a href="https://eu.dlink.com/de/de/support/support-news/2019/february/28/dns320_trojan_cr1pttor">https://eu.dlink.com/de/de/support/support-news/2019/february/28/dns320_trojan_cr1pttor</a><br/>
Jenkins Plugin Vulnerabilities<br/>
 <a href="https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2019/may/story-of-a-hundred-vulnerable-jenkins-plugins/">https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2019/may/story-of-a-hundred-vulnerable-jenkins-plugins/</a><br/>
Malicious WPAD Domains<br/>
 <a href="https://blog.redteam.pl/2019/05/badwpad-and-wpad-pl-wpadblocking-com.html">https://blog.redteam.pl/2019/05/badwpad-and-wpad-pl-wpadblocking-com.html</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6484" type="text/plain" language="en" />
<itunes:keywords>wpad, jenkins, dlink, ransomware, git, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6482</itunes:episode>
<itunes:subtitle>SAP Targeted; Cisco Nexus 9000; CryptoJacking Update; DLink; Securepairs; #righttorepair
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SAP Targeted; Cisco Nexus 9000; CryptoJacking Update; DLink; Securepairs; #righttorepair
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6482.mp3" length="5166380" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6482.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6482</link>
<pubDate>Fri, 03 May 2019 01:55:02 GMT</pubDate>
<description><![CDATA[New SAP Exploits Used to Target Exposed<br/>
 <a href="https://www.onapsis.com/10kblaze">https://www.onapsis.com/10kblaze</a><br/>
Cisco Patches SSH Default Credential Vulnerability in Nexus 9000 Switches<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey</a><br/>
Current State of JavaScript Crypto Jacking<br/>
 <a href="https://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/">https://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/</a><br/>
D-Link Camera Vulnerabilities<br/>
 <a href="https://www.welivesecurity.com/2019/05/02/d-link-camera-vulnerability-video-stream/">https://www.welivesecurity.com/2019/05/02/d-link-camera-vulnerability-video-stream/</a><br/>
Securepairs Promotes "Right to Repair"<br/>
 <a href="https://securepairs.org/">https://securepairs.org/</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6482" type="text/plain" language="en" />
<itunes:keywords>SAP, Cisco, Nexus, Crytpojacking, dlink, securepairs, right to repair, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6480</itunes:episode>
<itunes:subtitle>RCE in Dell SupportAssist; Creston Vuln; More JS Skimmers; S/Mime and PGP Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RCE in Dell SupportAssist; Creston Vuln; More JS Skimmers; S/Mime and PGP Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6480.mp3" length="5010224" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6480.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6480</link>
<pubDate>Thu, 02 May 2019 02:10:02 GMT</pubDate>
<description><![CDATA[RCE Vulnerability in Dell Support Assist<br/>
 <a href="https://d4stiny.github.io/Remote-Code-Execution-on-most-Dell-computers/">https://d4stiny.github.io/Remote-Code-Execution-on-most-Dell-computers/</a><br/>
Creston Multiple Vulnerabilities<br/>
 <a href="https://www.crestron.com/en-US/Security/Security_Advisories">https://www.crestron.com/en-US/Security/Security_Advisories</a><br/>
Polymorphic Skimmer Targeting 57 different Payment Gateways<br/>
 <a href="https://labs.sansec.io/2019/04/29/polymorphic-skimmer-57-payment-gateways/">https://labs.sansec.io/2019/04/29/polymorphic-skimmer-57-payment-gateways/</a><br/>
More Attacks Against S/Mime and PGP Signed Email<br/>
 <a href="https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf">https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6480" type="text/plain" language="en" />
<itunes:keywords>s/mime, pgp, email, signatures, skimmer, magecart, creston, dell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 1st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6478</itunes:episode>
<itunes:subtitle>WebLogic Ransom Ware; Facebook Location Leak, AutoMacTC, KAPE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebLogic Ransom Ware; Facebook Location Leak, AutoMacTC, KAPE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6478.mp3" length="4728992" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6478.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6478</link>
<pubDate>Wed, 01 May 2019 02:20:02 GMT</pubDate>
<description><![CDATA[Sodinokibi Ransomware Exploits WebLogic Server Vulnerability<br/>
 <a href="https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html">https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html</a><br/>
Facebook Leaking Sellers Exact Locations<br/>
 <a href="https://www.7elements.co.uk/resources/blog/facebooks-burglary-shopping-list/">https://www.7elements.co.uk/resources/blog/facebooks-burglary-shopping-list/</a><br/>
Revive Adserver Deserialization Vulnerability<br/>
 <a href="https://www.revive-adserver.com/security/revive-sa-2019-001/">https://www.revive-adserver.com/security/revive-sa-2019-001/</a><br/>
AutoMacTC: Automating Mac Forensics Triage<br/>
 <a href="https://www.crowdstrike.com/blog/automating-mac-forensic-triage/">https://www.crowdstrike.com/blog/automating-mac-forensic-triage/</a><br/>
Kroll Artifact Parser And Extractor (KAPE) <br/>
 <a href="https://learn.duffandphelps.com/kape">https://learn.duffandphelps.com/kape</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6478" type="text/plain" language="en" />
<itunes:keywords>kroll, automactc, kape, triage, incident response, revive, adserver, deserialization, facebook, location, sodinokibi, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6476</itunes:episode>
<itunes:subtitle>iLnkP2P Weakness; iFrame Tech Support Scam; Window 10 Users Avoiding October 2018 Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
iLnkP2P Weakness; iFrame Tech Support Scam; Window 10 Users Avoiding October 2018 Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6476.mp3" length="4924649" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6476.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6476</link>
<pubDate>Tue, 30 Apr 2019 01:30:02 GMT</pubDate>
<description><![CDATA[iLnkP2P Allows Access To Millions of Security Cameras<br/>
 <a href="https://hacked.camera">https://hacked.camera</a><br/>
Windows 10 Users Not Applying October Update<br/>
 <a href="https://reports.adduplex.com/#/r/2019-04">https://reports.adduplex.com/#/r/2019-04</a><br/>
iFrame "Ransom Support" Attacks<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/tech-support-scam-employs-new-trick-by-using-iframe-to-freeze-browsers/">https://blog.trendmicro.com/trendlabs-security-intelligence/tech-support-scam-employs-new-trick-by-using-iframe-to-freeze-browsers/</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6476" type="text/plain" language="en" />
<itunes:keywords>ilnkp2p, cameras, windows 10, updates, iframe, ransom, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 29th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6474</itunes:episode>
<itunes:subtitle>WebLogic Update; Docker Hub Breach;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebLogic Update; Docker Hub Breach;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6474.mp3" length="4474453" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6474.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6474</link>
<pubDate>Mon, 29 Apr 2019 02:40:01 GMT</pubDate>
<description><![CDATA[WebLogic Update<br/>
 <a href="https://isc.sans.edu/diary.html?storyid=24890">https://isc.sans.edu/diary.html?storyid=24890</a><br/>
Docker Hub Breach<br/>
 <a href="https://success.docker.com/article/docker-hub-user-notification">https://success.docker.com/article/docker-hub-user-notification</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6474" type="text/plain" language="en" />
<itunes:keywords>docker, docker hub, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6472</itunes:episode>
<itunes:subtitle>Windows Service Acccounts; Weblogic Flaw; Confluence Exploited; New Windows 10/Server Security Baseline
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Service Acccounts; Weblogic Flaw; Confluence Exploited; New Windows 10/Server Security Baseline
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6472.mp3" length="4568807" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6472.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6472</link>
<pubDate>Fri, 26 Apr 2019 03:15:02 GMT</pubDate>
<description><![CDATA[Unpatched Vulnerablity in WebLogic Exploited<br/>
<a href="https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+Alert+WebLogic+Zero+Day/24880/">https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+Alert+WebLogic+Zero+Day/24880/</a><br/>
Collecting Windows Service Accounts<br/>
<a href="https://isc.sans.edu/forums/diary/Service+Accounts+Redux+Collecting+Service+Accounts+with+PowerShell/24882/">https://isc.sans.edu/forums/diary/Service+Accounts+Redux+Collecting+Service+Accounts+with+PowerShell/24882/</a><br/>
Confluence Vulnerablity Exploited by GandGrab<br/>
<a href="https://blog.alertlogic.com/active-exploitation-of-confluence-vulnerability-cve-2019-3396-dropping-gandcrab-ransomware/">https://blog.alertlogic.com/active-exploitation-of-confluence-vulnerability-cve-2019-3396-dropping-gandcrab-ransomware/</a><br/>
New Micrsoft Security Baseline for Windows 10 / Windows Server<br/>
 <a href="https://blogs.technet.microsoft.com/secguide/2019/04/24/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903/">https://blogs.technet.microsoft.com/secguide/2019/04/24/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903/</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6472" type="text/plain" language="en" />
<itunes:keywords>microsoft, windows, security baseline, confluence, ransomware, gandgrab, serivce accounts, weblogic, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6470</itunes:episode>
<itunes:subtitle>Finding Domain Admins; X-Protect Covering PE Files; Hotspot Password Leak; Github Hosting Phishing Pages
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding Domain Admins; X-Protect Covering PE Files; Hotspot Password Leak; Github Hosting Phishing Pages
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6470.mp3" length="6286571" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6470.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6470</link>
<pubDate>Thu, 25 Apr 2019 03:15:02 GMT</pubDate>
<description><![CDATA[Rooting Out Unwanted Domain Admins With Powershell<br/>
<a href="https://isc.sans.edu/forums/diary/Where+have+all+the+Domain+Admins+gone+Rooting+out+Unwanted+Domain+Administrators/24874/">https://isc.sans.edu/forums/diary/Where+have+all+the+Domain+Admins+gone+Rooting+out+Unwanted+Domain+Administrators/24874/</a><br/>
Mac OS X-Protect Now Covering Windows Malware<br/>
<a href="https://twitter.com/patrickwardle/status/1120771284286103552">https://twitter.com/patrickwardle/status/1120771284286103552</a><br/>
Wifi Finder Leaks Hotspot Passwords<br/>
<a href="https://techcrunch.com/2019/04/22/hotspot-password-leak/">https://techcrunch.com/2019/04/22/hotspot-password-leak/</a><br/>
Github Hosting Phishing Pages<br/>
<a href="https://www.proofpoint.com/us/threat-insight/post/threat-actors-abuse-github-service-host-variety-phishing-kits">https://www.proofpoint.com/us/threat-insight/post/threat-actors-abuse-github-service-host-variety-phishing-kits</a><br/>
RSA Webinar: The Five Most Dangerous New Attack Techniques and How to Counter Them<br/>
<a href="https://www.rsaconference.com/videos/rsac-2019-the-five-most-dangerous-new-attack-techniques-and-how-to-counter-them-continued">https://www.rsaconference.com/videos/rsac-2019-the-five-most-dangerous-new-attack-techniques-and-how-to-counter-them-continued</a><br/>
]]></description>
<itunes:duration>7:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6470" type="text/plain" language="en" />
<itunes:keywords>rsa, heather, ed, alan, webinar, github, phishing, wifi finder, hotspot, password, x-protect, domain admins, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 24th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6468</itunes:episode>
<itunes:subtitle>VBA Macro Wtihout Source Code; More Shadowhammer Victims; Malicous Google Sites
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBA Macro Wtihout Source Code; More Shadowhammer Victims; Malicous Google Sites
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6468.mp3" length="4872356" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6468.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6468</link>
<pubDate>Wed, 24 Apr 2019 02:10:02 GMT</pubDate>
<description><![CDATA[Decoding Malicious VBA Office Document Without Source Code<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870/">https://isc.sans.edu/forums/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870/</a><br/>
More Updates on "ShadowHammer" Supply Chain Attack<br/>
 <a href="https://securelist.com/operation-shadowhammer-a-high-profile-supply-chain-attack/90380/">https://securelist.com/operation-shadowhammer-a-high-profile-supply-chain-attack/90380/</a><br/>
A Malicious Sight in Google Sites<br/>
 <a href="https://www.netskope.com/blog/malicious-google-sites">https://www.netskope.com/blog/malicious-google-sites</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6468" type="text/plain" language="en" />
<itunes:keywords>google sites, shadowhammer, vba, p-code, macro, decompiling, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6466</itunes:episode>
<itunes:subtitle>ACE Exploit; Younger Malware Senders; McAfee vs. Windows Update; Blocking Azure Blob Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ACE Exploit; Younger Malware Senders; McAfee vs. Windows Update; Blocking Azure Blob Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6466.mp3" length="4829564" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6466.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6466</link>
<pubDate>Mon, 22 Apr 2019 23:10:02 GMT</pubDate>
<description><![CDATA[.rar Files Exploiting ACE Vulneraiblity CVE-2018-20250<br/>
 <a href="https://isc.sans.edu/forums/diary/rar+Files+and+ACE+Exploit+CVE201820250/24864/">https://isc.sans.edu/forums/diary/rar+Files+and+ACE+Exploit+CVE201820250/24864/</a><br/>
Malware Senders Become Younger and Less Sophisticated (in German)<br/>
 <a href="https://www.heise.de/security/meldung/Malware-Verteiler-werden-immer-juenger-infizieren-sich-oft-selbst-4403823.html">https://www.heise.de/security/meldung/Malware-Verteiler-werden-immer-juenger-infizieren-sich-oft-selbst-4403823.html</a><br/>
McAfee Antivirus Affected by April Windows Update Crashes<br/>
 <a href="http://kc.mcafee.com/corporate/index?page=content&id=KB91465">http://kc.mcafee.com/corporate/index?page=content&id=KB91465</a><br/>
Rules to Protect Against Azure Blog Phishing in Outlook 365<br/>
 <a href="https://malware-research.org/simple-rule-to-protect-against-spoofed-windows-net-phishing-attacks/">https://malware-research.org/simple-rule-to-protect-against-spoofed-windows-net-phishing-attacks/</a><br/>
Windows 7 End of Support Messages<br/>
 <a href="https://www.windowslatest.com/2019/04/20/windows-7-users-are-now-receiving-the-end-of-support-notifications/">https://www.windowslatest.com/2019/04/20/windows-7-users-are-now-receiving-the-end-of-support-notifications/</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6466" type="text/plain" language="en" />
<itunes:keywords>ace, rar, winrar, malware, age, mcafee, windows update, azure, windows 7, blog storage, phishing, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6464</itunes:episode>
<itunes:subtitle>Analyzing UDF Files; HTML Link Ping; Edge User Agents; French Govt Chat User Managment
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing UDF Files; HTML Link Ping; Edge User Agents; French Govt Chat User Managment
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6464.mp3" length="5799802" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6464.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6464</link>
<pubDate>Mon, 22 Apr 2019 03:35:02 GMT</pubDate>
<description><![CDATA[Analyzing UDF Files Using Python<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+UDF+Files+with+Python/24860/">https://isc.sans.edu/forums/diary/Analyzing+UDF+Files+with+Python/24860/</a><br/>
HTML Ping To Be Adopted By All Major Browsers<br/>
 <a href="https://webkit.org/blog/8821/link-click-analytics-and-privacy/">https://webkit.org/blog/8821/link-click-analytics-and-privacy/</a><br/>
Microsoft to Modify Edge User Agent for Some Sites<br/>
 <a href="https://www.onmsft.com/news/new-edge-insider-browser-can-change-user-agent-strings-based-on-what-website-youre-visiting">https://www.onmsft.com/news/new-edge-insider-browser-can-change-user-agent-strings-based-on-what-website-youre-visiting</a><br/>
French Government Chat System Used Weak User Management<br/>
 <a href="https://m.heise.de/security/meldung/Tchap-Frankreichs-nicht-so-exklusiver-Regierungschat-4403961.html">https://m.heise.de/security/meldung/Tchap-Frankreichs-nicht-so-exklusiver-Regierungschat-4403961.html</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6464" type="text/plain" language="en" />
<itunes:keywords>france, government, chat, microsoft, edge, user-agent, ping, html, udf, python, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6462</itunes:episode>
<itunes:subtitle>Malicious UDF Files; Facebook Clear Text Passwords; Iranian Hackers Hacked; Win8 Live Tiles Takeover
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious UDF Files; Facebook Clear Text Passwords; Iranian Hackers Hacked; Win8 Live Tiles Takeover
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6462.mp3" length="5758110" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6462.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6462</link>
<pubDate>Fri, 19 Apr 2019 03:45:03 GMT</pubDate>
<description><![CDATA[Malware Delivered As a UDF .img file<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Sample+Delivered+Through+UDF+Image/24854/">https://isc.sans.edu/forums/diary/Malware+Sample+Delivered+Through+UDF+Image/24854/</a><br/>
Facebook Stored Passwords in Plain Text<br/>
 <a href="https://newsroom.fb.com/news/2019/03/keeping-passwords-secure/">https://newsroom.fb.com/news/2019/03/keeping-passwords-secure/</a><br/>
Iranian Statesponsored Malware and Data Leaked<br/>
 <a href="https://misterch0c.blogspot.com/2019/04/apt34-oilrig-leak.html">https://misterch0c.blogspot.com/2019/04/apt34-oilrig-leak.html</a><br/>
Windows 8 Live Tiles Domain Takeover<br/>
 <a href="https://www.golem.de/news/subdomain-takeover-microsoft-verliert-kontrolle-ueber-windows-kacheln-1904-140709.html">https://www.golem.de/news/subdomain-takeover-microsoft-verliert-kontrolle-ueber-windows-kacheln-1904-140709.html</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6462" type="text/plain" language="en" />
<itunes:keywords>windows 8, live tiles, iran, facebook, passwords, malware, udf, img, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6460</itunes:episode>
<itunes:subtitle>Sea Turtle; Broadcom Drivers; NamPoHyu, Confluence Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sea Turtle; Broadcom Drivers; NamPoHyu, Confluence Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6460.mp3" length="4612697" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6460.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6460</link>
<pubDate>Thu, 18 Apr 2019 03:05:02 GMT</pubDate>
<description><![CDATA[DNS Hijacking by Sea Turtle<br/>
 <a href="https://blog.talosintelligence.com/2019/04/seaturtle.html">https://blog.talosintelligence.com/2019/04/seaturtle.html</a><br/>
Broadcom Wifi Driver Vulnerabilities<br/>
 <a href="https://www.kb.cert.org/vuls/id/166939/">https://www.kb.cert.org/vuls/id/166939/</a><br/>
NamPoHyu Virus Infects Samba Servers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/nampohyu-virus-ransomware-targets-remote-samba-servers/">https://www.bleepingcomputer.com/news/security/nampohyu-virus-ransomware-targets-remote-samba-servers/</a><br/>
Increased Attacks on Confluence<br/>
 <a href="https://twitter.com/DFNCERT/status/1118468599230943233">https://twitter.com/DFNCERT/status/1118468599230943233</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6460" type="text/plain" language="en" />
<itunes:keywords>Altassian, confluence, nampohyu, ransomware, samba, broadcom, dns, sea turtle, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6458</itunes:episode>
<itunes:subtitle>CVE-2019-0726 (Win DHCP Client) PoC; Oracle CPU; WiPro Hacked; GHydra Tips
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2019-0726 (Win DHCP Client) PoC; Oracle CPU; WiPro Hacked; GHydra Tips
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6458.mp3" length="4699739" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6458.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6458</link>
<pubDate>Wed, 17 Apr 2019 03:20:03 GMT</pubDate>
<description><![CDATA[PoC Exploit for Windows 10 DHCP Client Vulnerability CVE-2019-0726 (russian)<br/>
 <a href="https://habr.com/ru/company/pt/blog/448378/">https://habr.com/ru/company/pt/blog/448378/</a><br/>
Oracle April 2019 Critical Patch Update<br/>
 <a href="https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html">https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html</a><br/>
WiPro Breached Via Phishing Attacks<br/>
 <a href="https://krebsonsecurity.com/2019/04/experts-breach-at-it-outsourcing-giant-wipro/">https://krebsonsecurity.com/2019/04/experts-breach-at-it-outsourcing-giant-wipro/</a><br/>
IDA and GHydra Part 2 (Strings And Parameters)<br/>
 <a href="https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+2+strings+and+parameters/24848/">https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+2+strings+and+parameters/24848/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6458" type="text/plain" language="en" />
<itunes:keywords>ida, gyhdra, wipro, phishing, oracle, cpu, dhcp, windows, cve-2019-0726, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6456</itunes:episode>
<itunes:subtitle>DNS False Positives; Adblock Code Injection; Executables in DICOM Images; Misleading VPN Ads
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS False Positives; Adblock Code Injection; Executables in DICOM Images; Misleading VPN Ads
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6456.mp3" length="5954866" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6456.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6456</link>
<pubDate>Tue, 16 Apr 2019 04:40:02 GMT</pubDate>
<description><![CDATA[Common "False Positives" in DNS Query Logs<br/>
 <a href="https://isc.sans.edu/forums/diary/Odd+DNS+Requests+that+are+Normal/24844/">https://isc.sans.edu/forums/diary/Odd+DNS+Requests+that+are+Normal/24844/</a><br/>
 <br/>
Adblock Plus Allows Filter List Providers to Inject Code in Pages<br/>
 <a href="https://armin.dev/blog/2019/04/adblock-plus-code-injection/">https://armin.dev/blog/2019/04/adblock-plus-code-injection/</a><br/>
Executables in Polyglot DICOM Images<br/>
 <a href="https://github.com/d00rt/pedicom/blob/master/doc/Attacking_Digital_Imaging_and_Communication_in_Medicine_(DICOM)_file_format_standard_-_Markel_Picado_Ortiz_(d00rt).pdf">https://github.com/d00rt/pedicom/blob/master/doc/Attacking_Digital_Imaging_and_Communication_in_Medicine_(DICOM)_file_format_standard_-_Markel_Picado_Ortiz_(d00rt).pdf</a><br/>
Malicious/Misleading VPN Ads<br/>
 <a href="https://www.bleepingcomputer.com/news/security/mobile-vpns-promoted-by-you-are-infected-or-hacked-ads/">https://www.bleepingcomputer.com/news/security/mobile-vpns-promoted-by-you-are-infected-or-hacked-ads/</a><br/>
]]></description>
<itunes:duration>7:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6456" type="text/plain" language="en" />
<itunes:keywords>vpn ads, polyglot, dicom, pedicom, adblock, dns, query logs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6454</itunes:episode>
<itunes:subtitle>MTA-STA; AirBNB Cameras; VPN Credentials; MSIE XXE Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MTA-STA; AirBNB Cameras; VPN Credentials; MSIE XXE Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6454.mp3" length="5396053" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6454.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6454</link>
<pubDate>Mon, 15 Apr 2019 04:35:03 GMT</pubDate>
<description><![CDATA[Configuring MTA-STS<br/>
 <a href="https://isc.sans.edu/forums/diary/Configuring+MTASTS+and+TLS+Reporting+For+Your+Domain/24840/">https://isc.sans.edu/forums/diary/Configuring+MTASTS+and+TLS+Reporting+For+Your+Domain/24840/</a><br/>
How to Find Hidden Cameras in Your AirBNB<br/>
 <a href="https://isc.sans.edu/forums/diary/How+to+Find+Hidden+Cameras+in+your+AirBNB/24834/">https://isc.sans.edu/forums/diary/How+to+Find+Hidden+Cameras+in+your+AirBNB/24834/</a><br/>
Insecure Storage of VPN Credentials<br/>
 <a href="https://www.kb.cert.org/vuls/id/192371/">https://www.kb.cert.org/vuls/id/192371/</a><br/>
Microsoft Patch Problems<br/>
 <a href="https://support.microsoft.com/en-us/help/4493472/windows-7-update-kb4493472">https://support.microsoft.com/en-us/help/4493472/windows-7-update-kb4493472</a><br/>
 <a href="https://support.microsoft.com/en-us/help/4493446/windows-8-1-update-kb4493446">https://support.microsoft.com/en-us/help/4493446/windows-8-1-update-kb4493446</a><br/>
Internet Explorer XML External Entity Vulnerability<br/>
 <a href="http://hyp3rlinx.altervista.org/advisories/MICROSOFT-INTERNET-EXPLORER-v11-XML-EXTERNAL-ENTITY-INJECTION-0DAY.txt">http://hyp3rlinx.altervista.org/advisories/MICROSOFT-INTERNET-EXPLORER-v11-XML-EXTERNAL-ENTITY-INJECTION-0DAY.txt</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6454" type="text/plain" language="en" />
<itunes:keywords>Internet explorer, msie, xml, xee, airbnb, cameras, vpn, mta-sts, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6452</itunes:episode>
<itunes:subtitle>GMail Supporting MTA-STS; Juniper Patch; Uniden IP Camera Site Hosting Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GMail Supporting MTA-STS; Juniper Patch; Uniden IP Camera Site Hosting Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6452.mp3" length="5277562" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6452.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6452</link>
<pubDate>Fri, 12 Apr 2019 00:55:02 GMT</pubDate>
<description><![CDATA[GMail Will Be Supporting MTA-STS and SMTP TLS Reporting<br/>
 <a href="https://tools.ietf.org/html/rfc8461">https://tools.ietf.org/html/rfc8461</a><br/>
 <a href="https://tools.ietf.org/html/rfc8460">https://tools.ietf.org/html/rfc8460</a><br/>
 <a href="https://www.zdnet.com/article/gmail-becomes-first-major-email-provider-to-support-mta-sts-and-tls-reporting/">https://www.zdnet.com/article/gmail-becomes-first-major-email-provider-to-support-mta-sts-and-tls-reporting/</a><br/>
Juniper Patch Fixes Static Password in Junos OS<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10923&actp=METADATA">https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10923&actp=METADATA</a><br/>
Uniden Commercial IP Camera Site Hosting Malware<br/>
 <a href="https://twitter.com/JayTHL/status/1116200014630596609">https://twitter.com/JayTHL/status/1116200014630596609</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6452" type="text/plain" language="en" />
<itunes:keywords>uniden, wordpress, malware, juniper, junos, password, grpc, gmail, mta-sts, smtp tls reporting, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6450</itunes:episode>
<itunes:subtitle>WPA3 Dragonblood Vulnerablity; HOPLIGHT Trojan; SneakyPastes
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WPA3 Dragonblood Vulnerablity; HOPLIGHT Trojan; SneakyPastes
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6450.mp3" length="6420057" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6450.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6450</link>
<pubDate>Thu, 11 Apr 2019 00:50:02 GMT</pubDate>
<description><![CDATA[WPA3 Dragonblood Vulnerability<br/>
 <a href="http://papers.mathyvanhoef.com/dragonblood.pdf">http://papers.mathyvanhoef.com/dragonblood.pdf</a><br/>
North Korean Trojan: HOPLIGHT<br/>
 <a href="https://www.us-cert.gov/ncas/analysis-reports/AR19-100A">https://www.us-cert.gov/ncas/analysis-reports/AR19-100A</a><br/>
Gaza Cybergang Group1 "SneakyPastes"<br/>
 <a href="https://securelist.com/gaza-cybergang-group1-operation-sneakypastes/90068/">https://securelist.com/gaza-cybergang-group1-operation-sneakypastes/90068/</a><br/>
]]></description>
<itunes:duration>7:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6450" type="text/plain" language="en" />
<itunes:keywords>gaza, cybergang, sneakypastes, pastebin, north korea, hoplight, wpa3, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6448</itunes:episode>
<itunes:subtitle>Microsoft/Adobe Patches; Food Poisoning Malspam; Axis Vulnerability; Golang Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft/Adobe Patches; Food Poisoning Malspam; Axis Vulnerability; Golang Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6448.mp3" length="5634505" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6448.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6448</link>
<pubDate>Tue, 09 Apr 2019 23:20:02 GMT</pubDate>
<description><![CDATA[Microsoft and Adobe Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+April+2019+Patch+Tuesday/24826/">https://isc.sans.edu/forums/diary/Microsoft+April+2019+Patch+Tuesday/24826/</a><br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Fake "Food Poisoning" emails in Germany (in german)<br/>
 <a href="https://www.polizei-praevention.de/aktuelles/erneut-mails-mit-schadsoftware-gegen-gewerbetreibende-im-umlauf.html">https://www.polizei-praevention.de/aktuelles/erneut-mails-mit-schadsoftware-gegen-gewerbetreibende-im-umlauf.html</a><br/>
Vulnerability in Apache Axis<br/>
 <a href="https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/">https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/</a><br/>
Golang DLL Injection Vulnerability<br/>
 <a href="https://www.openwall.com/lists/oss-security/2019/04/09/1">https://www.openwall.com/lists/oss-security/2019/04/09/1</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6448" type="text/plain" language="en" />
<itunes:keywords>golang, go, axis, soap, axis2, food poisoning, north korea, microsoft, adobe, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6446</itunes:episode>
<itunes:subtitle>TrendMicro Patch; Dovecot Patch; Apache Exploit; Using Javascript in Exploits; Ghidra vs. IDA
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TrendMicro Patch; Dovecot Patch; Apache Exploit; Using Javascript in Exploits; Ghidra vs. IDA
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6446.mp3" length="4673404" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6446.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6446</link>
<pubDate>Tue, 09 Apr 2019 01:30:03 GMT</pubDate>
<description><![CDATA[GHidra vs. IDA<br/>
 <a href="https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+1+the+decompilerunreachable+code/24822/">https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+1+the+decompilerunreachable+code/24822/</a><br/>
TrendMicro Patch<br/>
 <a href="https://success.trendmicro.com/solution/1122250">https://success.trendmicro.com/solution/1122250</a><br/>
Dovecot Patch<br/>
 <a href="https://dovecot.org/list/dovecot-news/2019-March/000403.html">https://dovecot.org/list/dovecot-news/2019-March/000403.html</a><br/>
Apache CVE-2019-0211 Exploit<br/>
 <a href="https://github.com/cfreal/exploits/tree/master/CVE-2019-0211-apache">https://github.com/cfreal/exploits/tree/master/CVE-2019-0211-apache</a><br/>
Using JavaScript in Exploits<br/>
 <a href="https://www.youtube.com/watch?v=HfpnloZM61I">https://www.youtube.com/watch?v=HfpnloZM61I</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6446" type="text/plain" language="en" />
<itunes:keywords>trendmicro, dovecot, apache, javascript, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6444</itunes:episode>
<itunes:subtitle>Fake Office365 Invoices; "well-known" hiding place; Altering CT Data; QT Framework Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake Office365 Invoices; "well-known" hiding place; Altering CT Data; QT Framework Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6444.mp3" length="5717882" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6444.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6444</link>
<pubDate>Sun, 07 Apr 2019 23:00:03 GMT</pubDate>
<description><![CDATA[Fake Office 365 Invoices Spread Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/Fake+Office+365+Payment+Information+Update/24818/">https://isc.sans.edu/forums/diary/Fake+Office+365+Payment+Information+Update/24818/</a><br/>
Malware Hiding in .well-known directory<br/>
 <a href="https://www.zscaler.com/blogs/research/abuse-hidden-well-known-directory-https-sites">https://www.zscaler.com/blogs/research/abuse-hidden-well-known-directory-https-sites</a><br/>
Altering CT Images to Manipulate Diagnosis<br/>
 <a href="https://arxiv.org/pdf/1901.03597.pdf">https://arxiv.org/pdf/1901.03597.pdf</a><br/>
QT Framework RCE Vulnerability<br/>
 <a href="https://www.zerodayinitiative.com/blog/2019/4/3/loading-up-a-pair-of-qt-bugs-detailing-cve-2019-1636-and-cve-2019-6739">https://www.zerodayinitiative.com/blog/2019/4/3/loading-up-a-pair-of-qt-bugs-detailing-cve-2019-1636-and-cve-2019-6739</a><br/>
]]></description>
<itunes:duration>6:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6444" type="text/plain" language="en" />
<itunes:keywords>qt rce, ct images, well-known, office365, fake invoice, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 5th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6442</itunes:episode>
<itunes:subtitle>Old Rule Triggers on New Exploit; Xiaomi Guardapp; Xwo Scanner; SmartWatches Pwned
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Old Rule Triggers on New Exploit; Xiaomi Guardapp; Xwo Scanner; SmartWatches Pwned
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6442.mp3" length="4873813" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6442.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6442</link>
<pubDate>Thu, 04 Apr 2019 23:35:02 GMT</pubDate>
<description><![CDATA[New Waves of Scans Detected By An Old Rule<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Waves+of+Scans+Detected+by+an+Old+Rule/24812/">https://isc.sans.edu/forums/diary/New+Waves+of+Scans+Detected+by+an+Old+Rule/24812/</a><br/>
Xiaomi GuardApp Vulnerable to Man in the Middle<br/>
 <a href="https://blog.checkpoint.com/2019/04/04/xiaomi-vulnerability-when-security-is-not-what-it-seems/">https://blog.checkpoint.com/2019/04/04/xiaomi-vulnerability-when-security-is-not-what-it-seems/</a><br/>
Xwo Web Scanner Hunting for MongoDB<br/>
 <a href="https://www.alienvault.com/blogs/labs-research/xwo-a-python-based-bot-scanner">https://www.alienvault.com/blogs/labs-research/xwo-a-python-based-bot-scanner</a><br/>
Vulnerable SmartWatches "Defaced"<br/>
 <a href="https://api.heise.de/svc/embetty/tweet/1112326532939374593-images-0">https://api.heise.de/svc/embetty/tweet/1112326532939374593-images-0</a><br/>
 <a href="https://www.heise.de/newsticker/meldung/Vidimensio-Smartwatches-Der-Sicherheits-Alptraum-geht-weiter-4359967.html">https://www.heise.de/newsticker/meldung/Vidimensio-Smartwatches-Der-Sicherheits-Alptraum-geht-weiter-4359967.html</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6442" type="text/plain" language="en" />
<itunes:keywords>smartwatch, xwo, xiaomi, guardapp, shellshock, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6440</itunes:episode>
<itunes:subtitle>Ghidra vs. IDA; IRS Phishing; Large Facebook Data Leak; PostgreSQL "COPY" Command
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ghidra vs. IDA; IRS Phishing; Large Facebook Data Leak; PostgreSQL "COPY" Command
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6440.mp3" length="4876377" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6440.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6440</link>
<pubDate>Thu, 04 Apr 2019 00:10:03 GMT</pubDate>
<description><![CDATA[Ghidra tips for IDA users: Automatic Comments for API Call Parameters<br/>
 <a href="https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+0+automatic+comments+for+API+call+parameters/24806/">https://isc.sans.edu/forums/diary/A+few+Ghidra+tips+for+IDA+users+part+0+automatic+comments+for+API+call+parameters/24806/</a><br/>
Security Awareness Newsletter: Making Passwords Simple<br/>
 <a href="https://www.sans.org/security-awareness-training/resources/making-passwords-simple">https://www.sans.org/security-awareness-training/resources/making-passwords-simple</a><br/>
IRS Themed Phishing Emails<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/tax-themed-email-campaigns-target-2019-filers">https://www.proofpoint.com/us/threat-insight/post/tax-themed-email-campaigns-target-2019-filers</a><br/>
Large Leak of Facebook User Data via 3rd Party App<br/>
 <a href="https://www.upguard.com/breaches/facebook-user-data-leak">https://www.upguard.com/breaches/facebook-user-data-leak</a><br/>
Arbitrary Command Execution in PostgreSQL<br/>
 <a href="https://medium.com/greenwolf-security/authenticated-arbitrary-command-execution-on-postgresql-9-3-latest-cd18945914d5">https://medium.com/greenwolf-security/authenticated-arbitrary-command-execution-on-postgresql-9-3-latest-cd18945914d5</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6440" type="text/plain" language="en" />
<itunes:keywords>postgres, postgresql, facebook, amazon, s3, irs, phishing, ouch, passwords, ghidra, ida, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6438</itunes:episode>
<itunes:subtitle>LaCie Drives Spread Fake AV; Unpatched IE/Edge SOP Bug; Apache Patch; Verzion Phish
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
LaCie Drives Spread Fake AV; Unpatched IE/Edge SOP Bug; Apache Patch; Verzion Phish
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6438.mp3" length="4511762" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6438.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6438</link>
<pubDate>Wed, 03 Apr 2019 01:25:02 GMT</pubDate>
<description><![CDATA[Compromised LaCie Drive Spread Fake AntiVirus<br/>
 <a href="https://isc.sans.edu/forums/diary/Fake+AV+is+Back+LaCie+Network+Drives+Used+to+Spread+Malware/24802/">https://isc.sans.edu/forums/diary/Fake+AV+is+Back+LaCie+Network+Drives+Used+to+Spread+Malware/24802/</a><br/>
Unpatched SOP Vulnerability in Internet Explorer/Edge<br/>
 <a href="https://thehackernews.com/2019/03/microsoft-edge-ie-zero-days.html">https://thehackernews.com/2019/03/microsoft-edge-ie-zero-days.html</a><br/>
Apache Fixes Privilege Escalation Flaw<br/>
 <a href="https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2019-0211">https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2019-0211</a><br/>
Verizon Users Phished for Credentials<br/>
 <a href="https://blog.lookout.com/mobile-phishing-verizon">https://blog.lookout.com/mobile-phishing-verizon</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6438" type="text/plain" language="en" />
<itunes:keywords>verizon, phish, apache, privilege escalation, sop, edge, internet explorer, msie, lacie, eset, fakeav, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6436</itunes:episode>
<itunes:subtitle>OpenOffice PDFs; Android Updates; Android Malware Redirects Phonecalls; Google Extends WebAuthn Support
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OpenOffice PDFs; Android Updates; Android Malware Redirects Phonecalls; Google Extends WebAuthn Support
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6436.mp3" length="3910889" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6436.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6436</link>
<pubDate>Tue, 02 Apr 2019 01:45:02 GMT</pubDate>
<description><![CDATA[Common "OpenAction" False Positive in PDFs Created by OpenOffice<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+PDFs+Created+with+OpenOfficeLibreOffice/24798/">https://isc.sans.edu/forums/diary/Analysis+of+PDFs+Created+with+OpenOfficeLibreOffice/24798/</a><br/>
Android Monthly Update<br/>
 <a href="https://source.android.com/security/bulletin/2019-04-01#2019-04-01-details">https://source.android.com/security/bulletin/2019-04-01#2019-04-01-details</a><br/>
Malicious Android App Forwards Banking Calls to Attacker<br/>
 <a href="https://www.blackhat.com/asia-19/briefings/schedule/index.html#when-voice-phishing-met-malicious-android-app-13419">https://www.blackhat.com/asia-19/briefings/schedule/index.html#when-voice-phishing-met-malicious-android-app-13419</a><br/>
Google Allowing WebAuthn Login from Firefox/Edge<br/>
 <a href="https://twitter.com/christiaanbrand/status/1111430192596025347">https://twitter.com/christiaanbrand/status/1111430192596025347</a><br/>
All Your Data Are Belong to Us: Defending Against Credential Stuffing Attacks<br/>
 <a href="https://www.sans.org/webcasts/data-belong-us-defend-credential-stuffing-110340">https://www.sans.org/webcasts/data-belong-us-defend-credential-stuffing-110340</a><br/>
]]></description>
<itunes:duration>4:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6436" type="text/plain" language="en" />
<itunes:keywords>credential stuffing, webcast, webauthn, google, firefox, edge, android, patches, phone redirect, openaction, pdf, openoffice, libreoffice, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 1st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6434</itunes:episode>
<itunes:subtitle>Reversing Golang; Kubernetes Vulnerability; VMWare Patches; ASUS MACs
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing Golang; Kubernetes Vulnerability; VMWare Patches; ASUS MACs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6434.mp3" length="4724238" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6434.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6434</link>
<pubDate>Sun, 31 Mar 2019 23:15:02 GMT</pubDate>
<description><![CDATA[Annotating Golang Binaries with Cutter and Jupyter<br/>
 <a href="https://isc.sans.edu/forums/diary/Annotating+Golang+binaries+with+Cutter+and+Jupyter/24790/">https://isc.sans.edu/forums/diary/Annotating+Golang+binaries+with+Cutter+and+Jupyter/24790/</a><br/>
ASUS Targeted MAC Addresses Available for Download<br/>
 <a href="https://skylightcyber.com/2019/03/28/unleash-the-hash-shadowhammer-mac-list/">https://skylightcyber.com/2019/03/28/unleash-the-hash-shadowhammer-mac-list/</a><br/>
Weaponized Version of New Zealand Attack Manifesto<br/>
 <a href="https://bluehexagon.ai/blog/weaponized-version-of-new-zealand-terror-suspects-manifesto-discovered-in-the-wild/">https://bluehexagon.ai/blog/weaponized-version-of-new-zealand-terror-suspects-manifesto-discovered-in-the-wild/</a><br/>
Kubernetes Directory Traversal<br/>
 <a href="https://www.twistlock.com/labs-blog/disclosing-directory-traversal-vulnerability-kubernetes-copy-cve-2019-1002101/">https://www.twistlock.com/labs-blog/disclosing-directory-traversal-vulnerability-kubernetes-copy-cve-2019-1002101/</a><br/>
VMWare Patches<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2019-0005.html">https://www.vmware.com/security/advisories/VMSA-2019-0005.html</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6434" type="text/plain" language="en" />
<itunes:keywords>vmwware, kubernetes, manifesto, asus, mac addresses, golang, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 29th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6432</itunes:episode>
<itunes:subtitle>Passive DNS; Incomplete Cisco RV320 Patch; TPLink Debug Port
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Passive DNS; Incomplete Cisco RV320 Patch; TPLink Debug Port
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6432.mp3" length="3790202" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6432.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6432</link>
<pubDate>Thu, 28 Mar 2019 20:45:02 GMT</pubDate>
<description><![CDATA[Creating Your Own Passive DNS Logs<br/>
 <a href="https://isc.sans.edu/forums/diary/Running+your+Own+Passive+DNS+Service/24784/">https://isc.sans.edu/forums/diary/Running+your+Own+Passive+DNS+Service/24784/</a><br/>
Incomplete Patch for Cisco RV320 Routers<br/>
 <a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-003/-cisco-rv320-unauthenticated-configuration-export">https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-003/-cisco-rv320-unauthenticated-configuration-export</a><br/>
 <a href="https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-004/-cisco-rv320-unauthenticated-diagnostic-data-retrieval">https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-004/-cisco-rv320-unauthenticated-diagnostic-data-retrieval</a><br/>
TPLink Debug Port Vulnerability<br/>
 <a href="https://twitter.com/mjg59/status/1111106885736787975">https://twitter.com/mjg59/status/1111106885736787975</a><br/>
 <a href="https://pastebin.com/GAzccR95">https://pastebin.com/GAzccR95</a><br/>
]]></description>
<itunes:duration>4:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6432" type="text/plain" language="en" />
<itunes:keywords>tplink, tpdp, cisco, rv320, dns, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 28th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6430</itunes:episode>
<itunes:subtitle>MSFT Application Guard for FF/Chrome; LTE Vulnerabilities; NVidia Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Application Guard for FF/Chrome; LTE Vulnerabilities; NVidia Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6430.mp3" length="4285383" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6430.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6430</link>
<pubDate>Wed, 27 Mar 2019 20:50:03 GMT</pubDate>
<description><![CDATA[Microsoft Releases Application Guard for Firefox and Chrome<br/>
 <a href="https://blogs.windows.com/windowsexperience/2019/03/15/announcing-windows-10-insider-preview-build-18358/">https://blogs.windows.com/windowsexperience/2019/03/15/announcing-windows-10-insider-preview-build-18358/</a><br/>
New Set of LTE Vulnerabilities<br/>
 <a href="https://syssec.kaist.ac.kr/pub/2019/kim_sp_2019.pdf">https://syssec.kaist.ac.kr/pub/2019/kim_sp_2019.pdf</a><br/>
NVidia Privilege Escalation<br/>
 <a href="https://rhinosecuritylabs.com/application-security/nvidia-arbitrary-file-writes-to-command-execution-cve-2019-5674/">https://rhinosecuritylabs.com/application-security/nvidia-arbitrary-file-writes-to-command-execution-cve-2019-5674/</a><br/>
]]></description>
<itunes:duration>5:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6430" type="text/plain" language="en" />
<itunes:keywords>nvidia, lte, microsoft, application guard, firefox, chrome, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 27th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6428</itunes:episode>
<itunes:subtitle>Apple Updates; ASUS Response; Firefox Cert Issues; UC Browser MITM Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; ASUS Response; Firefox Cert Issues; UC Browser MITM Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6428.mp3" length="4775076" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6428.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6428</link>
<pubDate>Tue, 26 Mar 2019 20:50:02 GMT</pubDate>
<description><![CDATA[Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
ASUS Response to Kaspersky Report<br/>
 <a href="https://www.asus.com/News/hqfgVUyZ6uyAyJe1">https://www.asus.com/News/hqfgVUyZ6uyAyJe1</a><br/>
Firefox Importing Windows Root Certificates<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1533397">https://bugzilla.mozilla.org/show_bug.cgi?id=1533397</a><br/>
UC Webbrowser MITM Vulnerability<br/>
 <a href="https://www.bleepingcomputer.com/news/security/uc-browser-for-android-desktop-exposes-500-million-users-to-mitm-attacks/">https://www.bleepingcomputer.com/news/security/uc-browser-for-android-desktop-exposes-500-million-users-to-mitm-attacks/</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6428" type="text/plain" language="en" />
<itunes:keywords>ucweb, uc webbrowser, firefox, certificates, asus, kasperksy, apple, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6426</itunes:episode>
<itunes:subtitle>ShadowHammer ASUS Backdoor; Telegram Unsend Feature; F5 BigIP Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ShadowHammer ASUS Backdoor; Telegram Unsend Feature; F5 BigIP Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6426.mp3" length="4483598" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6426.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6426</link>
<pubDate>Mon, 25 Mar 2019 21:00:07 GMT</pubDate>
<description><![CDATA[ASUS Live Update "ShadowHammer" Backdoor<br/>
 <a href="https://www.kaspersky.com/blog/shadow-hammer-teaser">https://www.kaspersky.com/blog/shadow-hammer-teaser</a><br/>
 <a href="https://shadowhammer.kaspersky.com/">https://shadowhammer.kaspersky.com/</a><br/>
Telegram Unsent Feature<br/>
 <a href="https://techcrunch.com/2019/03/25/going-going-gone/">https://techcrunch.com/2019/03/25/going-going-gone/</a><br/>
F5 Big IP Updates<br/>
 <a href="https://support.f5.com/csp/article/K14812883">https://support.f5.com/csp/article/K14812883</a><br/>
 <br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6426" type="text/plain" language="en" />
<itunes:keywords>f5, bigip, telegram, asus, shadowhammer, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6424</itunes:episode>
<itunes:subtitle>Reversing Golang; Reading QR Codes; Pwn2Own; Java Card Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing Golang; Reading QR Codes; Pwn2Own; Java Card Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6424.mp3" length="5173333" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6424.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6424</link>
<pubDate>Sun, 24 Mar 2019 19:55:03 GMT</pubDate>
<description><![CDATA[Reversing Malware Written In Golang<br/>
 <a href="https://isc.sans.edu/forums/diary/Introduction+to+analysing+Go+binaries/24770/">https://isc.sans.edu/forums/diary/Introduction+to+analysing+Go+binaries/24770/</a><br/>
More "VelvetSweatshop" Maldocs<br/>
 <a href="https://isc.sans.edu/forums/diary/VelvetSweatshop+Maldocs/24772/">https://isc.sans.edu/forums/diary/VelvetSweatshop+Maldocs/24772/</a><br/>
Reading QR Codes in Python<br/>
 <a href="https://isc.sans.edu/forums/diary/Decoding+QR+Codes+with+Python/24774/">https://isc.sans.edu/forums/diary/Decoding+QR+Codes+with+Python/24774/</a><br/>
Pwn2Own Contest: Firefox, Safari, Edge and others fall<br/>
 <a href="https://www.zdnet.com/article/tesla-car-hacked-at-pwn2own-contest/">https://www.zdnet.com/article/tesla-car-hacked-at-pwn2own-contest/</a><br/>
Norwegian Nokia Phones Sent Data to China (Article in Norwegian)<br/>
 <a href="https://nrkbeta.no/2019/03/21/norske-telefoner-sendte-personopplysninger-til-kina/">https://nrkbeta.no/2019/03/21/norske-telefoner-sendte-personopplysninger-til-kina/</a><br/>
Java Card Vulnerabilities<br/>
 <a href="https://seclists.org/fulldisclosure/2019/Mar/35">https://seclists.org/fulldisclosure/2019/Mar/35</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6424" type="text/plain" language="en" />
<itunes:keywords>java card, nokia, china, pwn2own, qr codes, velvetsweatshop, golang, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6422</itunes:episode>
<itunes:subtitle>Google Photo xsleaks; Fake CDC Emails; Atlassian Sourcetree Vulnerability; Microsoft Defender for MacOS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Photo xsleaks; Fake CDC Emails; Atlassian Sourcetree Vulnerability; Microsoft Defender for MacOS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6422.mp3" length="4617813" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6422.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6422</link>
<pubDate>Thu, 21 Mar 2019 18:00:03 GMT</pubDate>
<description><![CDATA[Google Photo Cross-Site-Leak Exposes Picture Meta Data<br/>
 <a href="https://www.imperva.com/blog/now-patched-google-photos-vulnerability-let-hackers-track-your-friends-and-location-history/">https://www.imperva.com/blog/now-patched-google-photos-vulnerability-let-hackers-track-your-friends-and-location-history/</a><br/>
Fake CDC EMails Spread GandCrab Ransomware<br/>
 <a href="https://myonlinesecurity.co.uk/fake-cdc-flu-pandemic-warning-delivers-gandcrab-5-2-ransomware/">https://myonlinesecurity.co.uk/fake-cdc-flu-pandemic-warning-delivers-gandcrab-5-2-ransomware/</a><br/>
Atlassian Sourcetree Vulnerability<br/>
 <a href="https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2019-03-06-966678691.html">https://confluence.atlassian.com/sourcetreekb/sourcetree-security-advisory-2019-03-06-966678691.html</a><br/>
Microsoft Defender for MacOS<br/>
 <a href="https://www.theregister.co.uk/2019/03/21/microsoft_defender_atp/">https://www.theregister.co.uk/2019/03/21/microsoft_defender_atp/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6422" type="text/plain" language="en" />
<itunes:keywords>atlassian, microsoft, macos, anti-malware, defender, cdc, email, gandgrab, google, xsleak, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6420</itunes:episode>
<itunes:subtitle>Using AD to Find Hosts Outside of AD; MSFT Anti Malware Crashing Windows; Less DDoS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Using AD to Find Hosts Outside of AD; MSFT Anti Malware Crashing Windows; Less DDoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6420.mp3" length="4783120" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6420.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6420</link>
<pubDate>Wed, 20 Mar 2019 18:40:02 GMT</pubDate>
<description><![CDATA[Using Active Directory (AD) To Find Hosts That Are Not in AD<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+AD+to+find+hosts+that+arent+in+AD+fun+with+the+IPAddress+construct/24762/">https://isc.sans.edu/forums/diary/Using+AD+to+find+hosts+that+arent+in+AD+fun+with+the+IPAddress+construct/24762/</a><br/>
Microsoft Anti Malware Crashing Windows<br/>
 <a href="https://social.technet.microsoft.com/Forums/en-US/18ab60a3-3b26-4a07-b68d-84085ce66ce5/scep-crashing-pcs?forum=ConfigMgrCompliance&prof=required">https://social.technet.microsoft.com/Forums/en-US/18ab60a3-3b26-4a07-b68d-84085ce66ce5/scep-crashing-pcs?forum=ConfigMgrCompliance&prof=required</a><br/>
Reduction in DDoS Attacks<br/>
 <a href="https://www.nexusguard.com/threat-report-q4-2018">https://www.nexusguard.com/threat-report-q4-2018</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6420" type="text/plain" language="en" />
<itunes:keywords>ddos, microsoft, anti malware, false positives, active directory, , cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6418</itunes:episode>
<itunes:subtitle>Cloudflare Proxy Detection Tools; BEC Moving to SMS; IPv6 and UPNP
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cloudflare Proxy Detection Tools; BEC Moving to SMS; IPv6 and UPNP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6418.mp3" length="5153590" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6418.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6418</link>
<pubDate>Tue, 19 Mar 2019 19:05:02 GMT</pubDate>
<description><![CDATA[Cloudflare Releases Proxy Detection Tools<br/>
 <a href="https://blog.cloudflare.com/monsters-in-the-middleboxes/">https://blog.cloudflare.com/monsters-in-the-middleboxes/</a><br/>
Business Email Compromise Moving to SMS<br/>
 <a href="https://www.agari.com/email-security-blog/bec-goes-mobile/">https://www.agari.com/email-security-blog/bec-goes-mobile/</a><br/>
JavaScript Requests Without Same Origin Policy Limitations<br/>
 <a href="https://www.forcepoint.com/blog/security-labs/attacking-internal-network-public-internet-using-browser-proxy">https://www.forcepoint.com/blog/security-labs/attacking-internal-network-public-internet-using-browser-proxy</a><br/>
Discovering IPv6 Hosts With UPNP<br/>
 <a href="https://blog.talosintelligence.com/2019/03/ipv6-unmasking-via-upnp.html#more">https://blog.talosintelligence.com/2019/03/ipv6-unmasking-via-upnp.html#more</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6418" type="text/plain" language="en" />
<itunes:keywords>ipv6, upnp, javascript, same origin policy, bec, sms, cloudflare, proxy, mitm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6416</itunes:episode>
<itunes:subtitle>Putty Updates; Fijitsu Keyboards; Signed Malware; Ubuntu 14.04 Support Ends; Mirai News
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Putty Updates; Fijitsu Keyboards; Signed Malware; Ubuntu 14.04 Support Ends; Mirai News
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6416.mp3" length="4796284" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6416.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6416</link>
<pubDate>Mon, 18 Mar 2019 18:40:02 GMT</pubDate>
<description><![CDATA[Putty Updates<br/>
 <a href="https://www.chiark.greenend.org.uk/~sgtatham/putty/">https://www.chiark.greenend.org.uk/~sgtatham/putty/</a><br/>
Fujitsu Wireless Keyboard Vulnerabilities<br/>
 <a href="https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-033.txt">https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-033.txt</a><br/>
Signed Malware Goes Undetected<br/>
 <a href="https://twitter.com/malwrhunterteam/status/1104082562216062978/photo/1?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1104082562216062978&ref_url=https%3A%2F%2Fwww.theregister.co.uk%2F2019%2F03%2F18%2Fsecurity_roundup_150319%2F">https://twitter.com/malwrhunterteam/status/1104082562216062978/photo/1?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1104082562216062978&ref_url=https%3A%2F%2Fwww.theregister.co.uk%2F2019%2F03%2F18%2Fsecurity_roundup_150319%2F</a><br/>
Free Support for Ubuntu 14.04 LTS Ends in April<br/>
 <a href="https://lists.ubuntu.com/archives/ubuntu-announce/2019-March/000241.html">https://lists.ubuntu.com/archives/ubuntu-announce/2019-March/000241.html</a><br/>
Latest Mirai Version with Even More Exploits<br/>
 <a href="https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/">https://unit42.paloaltonetworks.com/new-mirai-variant-targets-enterprise-wireless-presentation-display-systems/</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6416" type="text/plain" language="en" />
<itunes:keywords>mirai, putty, ubuntu, signed malware, fujitsu, keyboard, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, March 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6414</itunes:episode>
<itunes:subtitle>Jupyter and radare2; IMAP Brute Fording; GSuites SMS Disable; Bitlocker/TPM
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Jupyter and radare2; IMAP Brute Fording; GSuites SMS Disable; Bitlocker/TPM
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6414.mp3" length="5918659" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6414.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6414</link>
<pubDate>Sun, 17 Mar 2019 18:40:02 GMT</pubDate>
<description><![CDATA[Binary Analysis With Jupyter and Radare2<br/>
 <a href="https://isc.sans.edu/forums/diary/Binary+Analysis+with+Jupyter+and+Radare2/24748/">https://isc.sans.edu/forums/diary/Binary+Analysis+with+Jupyter+and+Radare2/24748/</a><br/>
IMAP Brute Forcing against Cloud Accounts<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/threat-actors-leverage-credential-dumps-phishing-and-legacy-email-protocols">https://www.proofpoint.com/us/threat-insight/post/threat-actors-leverage-credential-dumps-phishing-and-legacy-email-protocols</a><br/>
Google Allows GSuite Users to Disable SMS/Voice Authentication<br/>
 <a href="https://gsuiteupdates.googleblog.com/2019/03/more-control-over-2-step-verification-security-phone-sms.html">https://gsuiteupdates.googleblog.com/2019/03/more-control-over-2-step-verification-security-phone-sms.html</a><br/>
Sniffing Bitlocker Keys from TPM<br/>
 <a href="https://pulsesecurity.co.nz/articles/TPM-sniffing">https://pulsesecurity.co.nz/articles/TPM-sniffing</a><br/>
]]></description>
<itunes:duration>7:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6414" type="text/plain" language="en" />
<itunes:keywords>tpm, bitlocker, google, gsuite, 2fa, mfa, imap, brute forcing, phishing, jupyter, radare2, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6412</itunes:episode>
<itunes:subtitle>Analyzing ZIP Files in Ghydra; 64 Bit Cert Serial Number; Cisco Patch; Intel Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing ZIP Files in Ghydra; 64 Bit Cert Serial Number; Cisco Patch; Intel Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6412.mp3" length="4403143" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6412.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6412</link>
<pubDate>Fri, 15 Mar 2019 02:10:02 GMT</pubDate>
<description><![CDATA[Analyzing ZIP Files in Ghydra<br/>
 <a href="https://isc.sans.edu/forums/diary/Tip+Ghidra+ZIP+Files/24732/">https://isc.sans.edu/forums/diary/Tip+Ghidra+ZIP+Files/24732/</a><br/>
64 Bit Certificate Serial Number Revocation<br/>
 <a href="https://adamcaudill.com/2019/03/09/tls-64bit-ish-serial-numbers-mass-revocation/">https://adamcaudill.com/2019/03/09/tls-64bit-ish-serial-numbers-mass-revocation/</a><br/>
Cisco Default Account Problem<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190313-cspcscv">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190313-cspcscv</a><br/>
Intel Patches<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00185.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00185.html</a><br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00191.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00191.html</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6412" type="text/plain" language="en" />
<itunes:keywords>intel, me, cisco, certificiates, google, godaddy, darkmatter, ghydra, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 13th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6410</itunes:episode>
<itunes:subtitle>MSFT/Adobe Patch Tuesday; PSMiner; ACME RFC8555
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT/Adobe Patch Tuesday; PSMiner; ACME RFC8555
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6410.mp3" length="5200036" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6410.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6410</link>
<pubDate>Wed, 13 Mar 2019 01:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+March+2019+Patch+Tuesday/24742/">https://isc.sans.edu/forums/diary/Microsoft+March+2019+Patch+Tuesday/24742/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
PSMiner<br/>
 <a href="https://blog.360totalsecurity.com/en/new-mining-worm-psminer-uses-multiple-high-risk-vulnerabilities-to-spread/">https://blog.360totalsecurity.com/en/new-mining-worm-psminer-uses-multiple-high-risk-vulnerabilities-to-spread/</a><br/>
Automatic Certificate Managment Environment<br/>
 <a href="https://tools.ietf.org/html/rfc8555">https://tools.ietf.org/html/rfc8555</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6410" type="text/plain" language="en" />
<itunes:keywords>acme, letsencrypt, rfc8555, psminer, adobe, microsoft, monero, redis, elasticsearch, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6408</itunes:episode>
<itunes:subtitle>StackStorm Vulnerability; Secure Coding Study; Game Developer Supply Chain Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
StackStorm Vulnerability; Secure Coding Study; Game Developer Supply Chain Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6408.mp3" length="4293426" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6408.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6408</link>
<pubDate>Tue, 12 Mar 2019 00:35:02 GMT</pubDate>
<description><![CDATA[DevOps Tool StackStorm Vulnerability<br/>
 <a href="https://quitten.github.io/StackStorm/">https://quitten.github.io/StackStorm/</a><br/>
Developers Will Not Code Secure By Default<br/>
 <a href="https://net.cs.uni-bonn.de/fileadmin/user_upload/naiakshi/Naiakshina_Password_Study.pdf">https://net.cs.uni-bonn.de/fileadmin/user_upload/naiakshi/Naiakshina_Password_Study.pdf</a><br/>
Gaming Industry Supply Chain Attack<br/>
 <a href="https://www.welivesecurity.com/2019/03/11/gaming-industry-scope-attackers-asia/">https://www.welivesecurity.com/2019/03/11/gaming-industry-scope-attackers-asia/</a><br/>
]]></description>
<itunes:duration>5:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6408" type="text/plain" language="en" />
<itunes:keywords>devops, secure coding, gaming, backdoor, supply chain, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6406</itunes:episode>
<itunes:subtitle>Reversing HTA; Apache SOLR Patch; Vulnerable Car Alarms; Win7+Chrome Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing HTA; Apache SOLR Patch; Vulnerable Car Alarms; Win7+Chrome Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6406.mp3" length="5755916" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6406.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6406</link>
<pubDate>Sun, 10 Mar 2019 22:45:04 GMT</pubDate>
<description><![CDATA[Reversing HTA Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+and+Dirty+Malicious+HTA+Analysis/24728/">https://isc.sans.edu/forums/diary/Quick+and+Dirty+Malicious+HTA+Analysis/24728/</a><br/>
Apache SOLR Patch<br/>
 <a href="https://issues.apache.org/jira/browse/SOLR-13301">https://issues.apache.org/jira/browse/SOLR-13301</a><br/>
Windows 7 + Google Chrome Exploit in the Wild<br/>
 <a href="https://security.googleblog.com/2019/03/disclosing-vulnerabilities-to-protect.html">https://security.googleblog.com/2019/03/disclosing-vulnerabilities-to-protect.html</a><br/>
Vulnerable Car Alarms<br/>
 <a href="https://www.pentestpartners.com/security-blog/gone-in-six-seconds-exploiting-car-alarms/">https://www.pentestpartners.com/security-blog/gone-in-six-seconds-exploiting-car-alarms/</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6406" type="text/plain" language="en" />
<itunes:keywords>car alarm, windows 7, chrome, google, solr, apache, hta, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6404</itunes:episode>
<itunes:subtitle>RSA Panel; Disposable E-Mails; NetApp / Cisco Patches; Github/Slack as C&amp;C;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RSA Panel; Disposable E-Mails; NetApp / Cisco Patches; Github/Slack as C&amp;C;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6404.mp3" length="5374110" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6404.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6404</link>
<pubDate>Fri, 08 Mar 2019 03:45:03 GMT</pubDate>
<description><![CDATA[RSA Panel Video<br/>
 <a href="https://www.rsaconference.com/videos/the-five-most-dangerous-new-attack-techniques-and-how-to-counter-them">https://www.rsaconference.com/videos/the-five-most-dangerous-new-attack-techniques-and-how-to-counter-them</a><br/>
Disposable E-Mail Addresses<br/>
 <a href="https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Disposable+Email+Addresses/24716/">https://isc.sans.edu/forums/diary/Keep+an+Eye+on+Disposable+Email+Addresses/24716/</a><br/>
NetApp Default Account Vulnerability<br/>
 <a href="https://security.netapp.com/advisory/ntap-20190305-0001/">https://security.netapp.com/advisory/ntap-20190305-0001/</a><br/>
Cisco NS-OS NX-API Privilege Escalation<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-NXAPI-cmdinj">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-NXAPI-cmdinj</a><br/>
Slub Backdoor Users GitHub and Slack <br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/new-slub-backdoor-uses-github-communicates-via-slack/">https://blog.trendmicro.com/trendlabs-security-intelligence/new-slub-backdoor-uses-github-communicates-via-slack/</a><br/>
]]></description>
<itunes:duration>6:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6404" type="text/plain" language="en" />
<itunes:keywords>slack, slub, github, backdoor, cisco, ns-os, nx-api, netapp, e-mail, disposable, rsa, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6402</itunes:episode>
<itunes:subtitle>More Resume Malspam; Cloudflare Protects Drupal; Cisco Exploit; Monitorkit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Resume Malspam; Cloudflare Protects Drupal; Cisco Exploit; Monitorkit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6402.mp3" length="5401177" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6402.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6402</link>
<pubDate>Thu, 07 Mar 2019 04:05:02 GMT</pubDate>
<description><![CDATA[More Resume Malspam. Now With Trickbot and EternalBlue<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+with+passwordprotected+word+docs+still+pushing+IcedID+Bokbot+with+Trickbot/24708/">https://isc.sans.edu/forums/diary/Malspam+with+passwordprotected+word+docs+still+pushing+IcedID+Bokbot+with+Trickbot/24708/</a><br/>
Cloudflare Deploys Rules to Protect Against Recent Drupal Exploit<br/>
 <a href="https://www.bleepingcomputer.com/news/security/cloudflare-deploys-firewall-rule-to-block-new-drupal-exploits/">https://www.bleepingcomputer.com/news/security/cloudflare-deploys-firewall-rule-to-block-new-drupal-exploits/</a><br/>
Cisco DoS Vulnerability Activity Exploited<br/>
 <a href="https://www.pentestpartners.com/security-blog/cisco-rv130-its-2019-but-yet-strcpy/">https://www.pentestpartners.com/security-blog/cisco-rv130-its-2019-but-yet-strcpy/</a><br/>
MonitorKit uses macOS Game Engine to Analyze Security Events<br/>
 <a href="https://github.com/objective-see">https://github.com/objective-see</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6402" type="text/plain" language="en" />
<itunes:keywords>monitorkit, waddle, cloudflare, cisco, resume, malspam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 6th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6400</itunes:episode>
<itunes:subtitle>Comcast Mobile Phone PIN; NSA Releases Ghidra; Google Chrome Vuln Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Comcast Mobile Phone PIN; NSA Releases Ghidra; Google Chrome Vuln Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6400.mp3" length="4711808" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6400.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6400</link>
<pubDate>Wed, 06 Mar 2019 04:35:02 GMT</pubDate>
<description><![CDATA[Comcast Uses same "0000" PIN For All Number Porting Requests<br/>
 <a href="https://nakedsecurity.sophos.com/2019/03/05/comcast-security-nightmare-default-0000-pin-on-everybodys-account/">https://nakedsecurity.sophos.com/2019/03/05/comcast-security-nightmare-default-0000-pin-on-everybodys-account/</a><br/>
NSA Releases Ghidra Reverse Analysis Tool<br/>
 <a href="https://ghidra-sre.org/">https://ghidra-sre.org/</a><br/>
Recent Google Chrome Vulnerability Being Exploited<br/>
 <a href="https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html?m=1">https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html?m=1</a><br/>
Android Monthly Security Bulletin<br/>
 <a href="https://source.android.com/security/bulletin/2019-03-01">https://source.android.com/security/bulletin/2019-03-01</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6400" type="text/plain" language="en" />
<itunes:keywords>android, google, chrome, comcast, xfinity, ghidra, nsa, reverse analysis, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 5th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6398</itunes:episode>
<itunes:subtitle>MacOS Unpatches Priv. Esclation; Windows Exploit Suggester; GPS Jamming
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS Unpatches Priv. Esclation; Windows Exploit Suggester; GPS Jamming
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6398.mp3" length="4922455" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6398.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6398</link>
<pubDate>Tue, 05 Mar 2019 03:00:03 GMT</pubDate>
<description><![CDATA[MacOS Unpatched Privilge Escalation Vulnerability made Public<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1726">https://bugs.chromium.org/p/project-zero/issues/detail?id=1726</a><br/>
Windows Exploit Suggester Next Generation Released<br/>
 <a href="https://github.com/bitsadmin/wesng">https://github.com/bitsadmin/wesng</a><br/>
Docker Vulnerability used for Crypto Miners<br/>
 <a href="https://www.imperva.com/blog/hundreds-of-vulnerable-docker-hosts-exploited-by-cryptocurrency-miners/">https://www.imperva.com/blog/hundreds-of-vulnerable-docker-hosts-exploited-by-cryptocurrency-miners/</a><br/>
Russian GPS Jamming Exercises<br/>
 <a href="https://thebarentsobserver.com/en/security/2019/03/russian-military-officials-arrive-oslo-norway-provides-facts-gps-jamming">https://thebarentsobserver.com/en/security/2019/03/russian-military-officials-arrive-oslo-norway-provides-facts-gps-jamming</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6398" type="text/plain" language="en" />
<itunes:keywords>GPS jamming, docker, crypto miners, windows exploit suggester, macos, cow, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6396</itunes:episode>
<itunes:subtitle>Cisco Router Patch; Coldfusion Patch, Protonmail Ransomware, eBay Phish hosted on eBay
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco Router Patch; Coldfusion Patch, Protonmail Ransomware, eBay Phish hosted on eBay
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6396.mp3" length="4759710" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6396.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6396</link>
<pubDate>Mon, 04 Mar 2019 02:25:02 GMT</pubDate>
<description><![CDATA[Cisco Router Patch<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex</a><br/>
Coldfusion Patch and Exploit<br/>
 <a href="https://www.carehart.org/blog/client/index.cfm/2019/3/1/urgent_CF_security_update_Part_1">https://www.carehart.org/blog/client/index.cfm/2019/3/1/urgent_CF_security_update_Part_1</a><br/>
Ransomware Impersonates Protonmail<br/>
 <a href="https://twitter.com/demonslay335/status/1097866931762282498">https://twitter.com/demonslay335/status/1097866931762282498</a><br/>
eBay Site Used for eBay Phish (article in German)<br/>
 <a href="https://www.heise.de/security/meldung/eBay-Phishing-auf-eBay-Seite-4324266.html">https://www.heise.de/security/meldung/eBay-Phishing-auf-eBay-Seite-4324266.html</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6396" type="text/plain" language="en" />
<itunes:keywords>ebay, ransomware, phishing, ebaydesc, coldfusion, cisco, protonmail, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 1st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6394</itunes:episode>
<itunes:subtitle>Emotet Backend Analysis; Kaspersky vs. Chromecast; Wireshark 3.0; MageCart Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Backend Analysis; Kaspersky vs. Chromecast; Wireshark 3.0; MageCart Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6394.mp3" length="5129082" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6394.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6394</link>
<pubDate>Fri, 01 Mar 2019 02:40:02 GMT</pubDate>
<description><![CDATA[Emotet Backend Analysis<br/>
 <a href="https://maxkersten.nl/binary-analysis-course/malware-analysis/emotet-droppers/">https://maxkersten.nl/binary-analysis-course/malware-analysis/emotet-droppers/</a><br/>
Kaspersky Vs. Chromecast<br/>
 <a href="https://www.bleepingcomputer.com/news/security/kaspersky-av-having-certificate-conflicts-with-google-chromecast/">https://www.bleepingcomputer.com/news/security/kaspersky-av-having-certificate-conflicts-with-google-chromecast/</a><br/>
MageCart Updates<br/>
 <a href="https://www.riskiq.com/research/inside-magecart/">https://www.riskiq.com/research/inside-magecart/</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6394" type="text/plain" language="en" />
<itunes:keywords>magecart, kasperksy, chromecast, google, emotet, backend, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 28th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6392</itunes:episode>
<itunes:subtitle>Coinhive Shutting Down; Azure Blob Phishing; Old Elastic Exploit User; Drupal Vuln Exploited
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Coinhive Shutting Down; Azure Blob Phishing; Old Elastic Exploit User; Drupal Vuln Exploited
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6392.mp3" length="4323789" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6392.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6392</link>
<pubDate>Thu, 28 Feb 2019 02:40:03 GMT</pubDate>
<description><![CDATA[Coinhive Shutting Down<br/>
 <a href="https://coinhive.com/blog/en/discontinuation-of-coinhive">https://coinhive.com/blog/en/discontinuation-of-coinhive</a><br/>
Azure Blob Storage Phishing<br/>
 <a href="https://www.edgewave.com/phishing/feeling-blue-about-phishing/">https://www.edgewave.com/phishing/feeling-blue-about-phishing/</a><br/>
Old 2014 Elastic Search Vulnerability Exploited<br/>
 <a href="https://blog.talosintelligence.com/2019/02/cisco-talos-honeypot-analysis-reveals.html">https://blog.talosintelligence.com/2019/02/cisco-talos-honeypot-analysis-reveals.html</a><br/>
Latest Drupal Vulnerability Exploited<br/>
 <a href="https://www.imperva.com/blog/latest-drupal-rce-flaw-used-by-cryptocurrency-miners-and-other-attackers/">https://www.imperva.com/blog/latest-drupal-rce-flaw-used-by-cryptocurrency-miners-and-other-attackers/</a><br/>
F5 Big IP Patches<br/>
 <a href="https://support.f5.com/csp/article/K91026261">https://support.f5.com/csp/article/K91026261</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6392" type="text/plain" language="en" />
<itunes:keywords>coinhive, azure, phishing, blob, storage, elastic, drupal, f5, bigip, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 27th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6390</itunes:episode>
<itunes:subtitle>Thunderbolt Vulnerabilities; Alterting Signed PDFs; NVidia Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Thunderbolt Vulnerabilities; Alterting Signed PDFs; NVidia Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6390.mp3" length="4219562" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6390.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6390</link>
<pubDate>Wed, 27 Feb 2019 02:40:02 GMT</pubDate>
<description><![CDATA[Thunderbolt "Thunderclap" Vulnerabilities<br/>
 <a href="https://thunderclap.io/thunderclap-paper-ndss2019.pdf">https://thunderclap.io/thunderclap-paper-ndss2019.pdf</a><br/>
Altering Signed PDF Documents<br/>
 <a href="https://www.pdf-insecurity.org/">https://www.pdf-insecurity.org/</a><br/>
NVidia Patches<br/>
 <a href="https://nvidia.custhelp.com/app/answers/detail/a_id/4772">https://nvidia.custhelp.com/app/answers/detail/a_id/4772</a><br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6390" type="text/plain" language="en" />
<itunes:keywords>nvidia, pdf signatures, thunderbolt, thunderclap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 26th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6388</itunes:episode>
<itunes:subtitle>WinRAR ACE Exploited; QR Code Sextortion; Android FIDO2 Compliant; ICANN Pushing DNSSEC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WinRAR ACE Exploited; QR Code Sextortion; Android FIDO2 Compliant; ICANN Pushing DNSSEC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6388.mp3" length="6019970" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6388.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6388</link>
<pubDate>Tue, 26 Feb 2019 02:35:02 GMT</pubDate>
<description><![CDATA[WinRAR ACE Vulnerabilty used in Malspam<br/>
 <a href="https://twitter.com/360TIC/status/1099987939818299392">https://twitter.com/360TIC/status/1099987939818299392</a><br/>
Sextortion Email With QR Code<br/>
 <a href="https://isc.sans.edu/forums/diary/Sextortion+Email+Variant+With+QR+Code/24686/">https://isc.sans.edu/forums/diary/Sextortion+Email+Variant+With+QR+Code/24686/</a><br/>
ICANN Pushes DNSSEC to Defend Against DNS Zone Manipulation<br/>
 <a href="https://www.icann.org/news/announcement-2019-02-22-en">https://www.icann.org/news/announcement-2019-02-22-en</a><br/>
Android FIDO2 Certification<br/>
 <a href="https://fidoalliance.org/android-now-fido2-certified-accelerating-global-migration-beyond-passwords/">https://fidoalliance.org/android-now-fido2-certified-accelerating-global-migration-beyond-passwords/</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6388" type="text/plain" language="en" />
<itunes:keywords>fido2, icann, dnssec, sextortion, qr code, winrar, ace, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6386</itunes:episode>
<itunes:subtitle>B0r0nt0k Ransomware; DLink NAS Ransomware; Linkedin Job Offer Ruse
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
B0r0nt0k Ransomware; DLink NAS Ransomware; Linkedin Job Offer Ruse
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6386.mp3" length="4629522" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6386.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6386</link>
<pubDate>Mon, 25 Feb 2019 01:10:02 GMT</pubDate>
<description><![CDATA[B0ront0k Linux Server Ransomware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/b0r0nt0k-ransomware-wants-75-000-ransom-infects-linux-servers/">https://www.bleepingcomputer.com/news/security/b0r0nt0k-ransomware-wants-75-000-ransom-infects-linux-servers/</a><br/>
Cr1pt0r Ransomware Targets DLink NAS Devices<br/>
 <a href="https://www.bleepingcomputer.com/forums/t/691852/cr1ptt0r-ransomware-files-encrypted-readmetxt-support-topic/page-3">https://www.bleepingcomputer.com/forums/t/691852/cr1ptt0r-ransomware-files-encrypted-readmetxt-support-topic/page-3</a><br/>
LinkedIn Messages Used to Push Fake Job Offers<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/fake-jobs-campaigns-delivering-moreeggs-backdoor-fake-job-offers">https://www.proofpoint.com/us/threat-insight/post/fake-jobs-campaigns-delivering-moreeggs-backdoor-fake-job-offers</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6386" type="text/plain" language="en" />
<itunes:keywords>linux, server, ransomware, dlink, nas, b0ront0k, cr1pt0r, linkedin, job offer, malware, backdoor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6384</itunes:episode>
<itunes:subtitle>Adobe Reader/Acrobat Patch; MSFT IIS DoS; Drupal Fix; Linux Kernel RCE; MikroTik Open Proxy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe Reader/Acrobat Patch; MSFT IIS DoS; Drupal Fix; Linux Kernel RCE; MikroTik Open Proxy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6384.mp3" length="5528813" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6384.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6384</link>
<pubDate>Fri, 22 Feb 2019 03:25:02 GMT</pubDate>
<description><![CDATA[Adobe Re-Patches Reader/Acrobat Data Leakage Bug<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb19-13.html">https://helpx.adobe.com/security/products/acrobat/apsb19-13.html</a><br/>
Microsoft Releases Fix for DoS Vulnerability in IIS<br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190005">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/ADV190005</a><br/>
Drupal Fixes Remote Code Execution Vulnerability<br/>
 <a href="https://www.drupal.org/sa-core-2019-003">https://www.drupal.org/sa-core-2019-003</a><br/>
Linux Kernel Code Execution Vulnerablity<br/>
 <a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8912">https://nvd.nist.gov/vuln/detail/CVE-2019-8912</a><br/>
MikroTik Unauthenticated Proxy<br/>
 <a href="https://medium.com/tenable-techblog/mikrotik-firewall-nat-bypass-b8d46398bf24">https://medium.com/tenable-techblog/mikrotik-firewall-nat-bypass-b8d46398bf24</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6384" type="text/plain" language="en" />
<itunes:keywords>microtik, linux, proxy, code execution, kernel, crypto, drupal, iis, microsoft, dos, adobe, ntlm, smb, information leakage, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6382</itunes:episode>
<itunes:subtitle>Edge Flash Whitelist; Bank App Screenshot Grab; Password Manager Weaknesses
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Edge Flash Whitelist; Bank App Screenshot Grab; Password Manager Weaknesses
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6382.mp3" length="5153229" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6382.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6382</link>
<pubDate>Thu, 21 Feb 2019 02:50:03 GMT</pubDate>
<description><![CDATA[Microsoft Edge Whitelists Facebook to Run Flash<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1722">https://bugs.chromium.org/p/project-zero/issues/detail?id=1722</a><br/>
Chinese Android Banking App Stores Screenshots of Other Apps<br/>
 <a href="https://jqknews.com/news/141073-Jingdong_Finance_denied_stealing_user_information_saying_that_the_image_cache_was_only_local.html">https://jqknews.com/news/141073-Jingdong_Finance_denied_stealing_user_information_saying_that_the_image_cache_was_only_local.html</a><br/>
Password Manager Vulnerabilities<br/>
 <a href="https://www.securityevaluators.com/casestudies/password-manager-hacking/">https://www.securityevaluators.com/casestudies/password-manager-hacking/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6382" type="text/plain" language="en" />
<itunes:keywords>password manager, 1password, keypass, dashlane, android, screenshot, banking, edge, whitelist, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 20th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6380</itunes:episode>
<itunes:subtitle>Russian Malspam; GandCrab Decrypter; Phishing From Banks; SHA-2 Patch for Win7/2008
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Russian Malspam; GandCrab Decrypter; Phishing From Banks; SHA-2 Patch for Win7/2008
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6380.mp3" length="5166396" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6380.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6380</link>
<pubDate>Wed, 20 Feb 2019 03:35:03 GMT</pubDate>
<description><![CDATA[Russian Malspam Pushing Shade/Troldesh Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/More+Russian+language+malspam+pushing+Shade+Troldesh+ransomware/24668/">https://isc.sans.edu/forums/diary/More+Russian+language+malspam+pushing+Shade+Troldesh+ransomware/24668/</a><br/>
Bitdefender Releases GandCrab Decrypter<br/>
 <a href="https://labs.bitdefender.com/2019/02/new-gandcrab-v5-1-decryptor-available-now/">https://labs.bitdefender.com/2019/02/new-gandcrab-v5-1-decryptor-available-now/</a><br/>
Bank Infrastructure Used in Phishing Attacks (russian)<br/>
 <a href="https://www.group-ib.ru/blog/incident">https://www.group-ib.ru/blog/incident</a><br/>
SHA-2 Patch For Windows 7 / 2008 R2 SP1<br/>
 <a href="https://support.microsoft.com/en-us/help/4472027/2019-sha-2-code-signing-support-requirement-for-windows-and-wsus">https://support.microsoft.com/en-us/help/4472027/2019-sha-2-code-signing-support-requirement-for-windows-and-wsus</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6380" type="text/plain" language="en" />
<itunes:keywords>sha2, windows 7, 2008, phishing, russian, banks, bitdefender, gandgrab, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 19th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6378</itunes:episode>
<itunes:subtitle>What Do You Log; Spectre Followup; VMWare Fixes runc; Exposed Phonecall Recordings
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
What Do You Log; Spectre Followup; VMWare Fixes runc; Exposed Phonecall Recordings
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6378.mp3" length="4618552" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6378.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6378</link>
<pubDate>Tue, 19 Feb 2019 03:05:02 GMT</pubDate>
<description><![CDATA[Know What You Are Logging<br/>
 <a href="https://isc.sans.edu/forums/diary/Know+What+You+Are+Logging/24656/">https://isc.sans.edu/forums/diary/Know+What+You+Are+Logging/24656/</a><br/>
Spectre Software Mitigation Insufficient<br/>
 <a href="https://arxiv.org/pdf/1902.05178.pdf">https://arxiv.org/pdf/1902.05178.pdf</a><br/>
VMWare Releases Update To Address runc Vulnerability<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2019-0001.html">https://www.vmware.com/security/advisories/VMSA-2019-0001.html</a><br/>
Swedish Healthcare Breach Leaks Phone call Recordings<br/>
 <a href="https://computersweden.idg.se/2.2683/1.714787/inspelade-samtal-1177-vardguiden-oskyddade-internet">https://computersweden.idg.se/2.2683/1.714787/inspelade-samtal-1177-vardguiden-oskyddade-internet</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6378" type="text/plain" language="en" />
<itunes:keywords>healthcare, voip, call recordings, vmware, runc, spectre, google, chrome, loggin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6376</itunes:episode>
<itunes:subtitle>Snap Patches; Properties in Office Docs, Bro-Sysmon, Cryptojacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Snap Patches; Properties in Office Docs, Bro-Sysmon, Cryptojacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6376.mp3" length="4289042" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6376.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6376</link>
<pubDate>Mon, 18 Feb 2019 02:55:03 GMT</pubDate>
<description><![CDATA[Snap Patches Available<br/>
 <a href="https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SnapSocketParsing">https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SnapSocketParsing</a><br/>
Finding Property Values in Office Documents<br/>
 <a href="https://isc.sans.edu/forums/diary/Finding+Property+Values+in+Office+Documents/24652/">https://isc.sans.edu/forums/diary/Finding+Property+Values+in+Office+Documents/24652/</a><br/>
Bro-Sysmon <br/>
 <a href="https://engineering.salesforce.com/test-out-bro-sysmon-a6fad1c8bb88">https://engineering.salesforce.com/test-out-bro-sysmon-a6fad1c8bb88</a><br/>
Cryptojacking Apps in Microsoft App Store<br/>
 <a href="https://www.symantec.com/blogs/threat-intelligence/cryptojacking-apps-microsoft-store">https://www.symantec.com/blogs/threat-intelligence/cryptojacking-apps-microsoft-store</a><br/>
]]></description>
<itunes:duration>5:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6376" type="text/plain" language="en" />
<itunes:keywords>google tag manager, gtm, crytojacking, microsoft, store, bro, sysmon, office, oledump, snap, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6374</itunes:episode>
<itunes:subtitle>PDF includes SMB Link; QNAP Malware; Bomb Threat Spammers Arrested; MSP as Gateway
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF includes SMB Link; QNAP Malware; Bomb Threat Spammers Arrested; MSP as Gateway
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6374.mp3" length="4880768" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6374.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6374</link>
<pubDate>Fri, 15 Feb 2019 03:30:02 GMT</pubDate>
<description><![CDATA[PDF includes SMB Link<br/>
 <a href="https://isc.sans.edu/forums/diary/Suspicious+PDF+Connecting+to+a+Remote+SMB+Share/24646/">https://isc.sans.edu/forums/diary/Suspicious+PDF+Connecting+to+a+Remote+SMB+Share/24646/</a><br/>
QNAP Malware<br/>
 <a href="https://www.qnap.com/en/security-advisory/nas-201902-13">https://www.qnap.com/en/security-advisory/nas-201902-13</a><br/>
Bomb Threat Spammers Arrested<br/>
 <a href="https://www.justice.gov/usao-cdca/pr/members-hacker-collective-face-federal-charges-attacking-computer-systems-emailing-mass">https://www.justice.gov/usao-cdca/pr/members-hacker-collective-face-federal-charges-attacking-computer-systems-emailing-mass</a><br/>
Managed Service Providers Targeted By Ransomware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ransomware-attacks-target-msps-to-mass-infect-customers/">https://www.bleepingcomputer.com/news/security/ransomware-attacks-target-msps-to-mass-infect-customers/</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6374" type="text/plain" language="en" />
<itunes:keywords>qnap, msp, pdf, bomb, ransomware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 14th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6372</itunes:episode>
<itunes:subtitle>Fake Updates; Shlayer vs. Gatekeeper; Cisco Def. Passwd Patch; VFEMail
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake Updates; Shlayer vs. Gatekeeper; Cisco Def. Passwd Patch; VFEMail
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6372.mp3" length="4921000" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6372.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6372</link>
<pubDate>Thu, 14 Feb 2019 03:40:02 GMT</pubDate>
<description><![CDATA[Fake Updates Campaign Still Active in 2019<br/>
 <a href="https://isc.sans.edu/forums/diary/Fake+Updates+campaign+still+active+in+2019/24640/">https://isc.sans.edu/forums/diary/Fake+Updates+campaign+still+active+in+2019/24640/</a><br/>
macOS Malware (Shlayer) Disables Gatekeeper<br/>
 <a href="https://www.carbonblack.com/2019/02/12/tau-threat-intelligence-notification-new-macos-malware-variant-of-shlayer-osx-discovered/">https://www.carbonblack.com/2019/02/12/tau-threat-intelligence-notification-new-macos-malware-variant-of-shlayer-osx-discovered/</a><br/>
Microsoft Exchange Server Patch (Errata for yesterday's podcast)<br/>
 <a href="https://support.microsoft.com/en-ca/help/4490060/exchange-web-services-push-notifications-can-provide-unauthorized-acce">https://support.microsoft.com/en-ca/help/4490060/exchange-web-services-push-notifications-can-provide-unauthorized-acce</a><br/>
Cisco Network Assurance Engine Password Synchronization Issue<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190212-nae-dos">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190212-nae-dos</a><br/>
VFEMail Backup Failure<br/>
 <a href="https://www.vfemail.net/">https://www.vfemail.net/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6372" type="text/plain" language="en" />
<itunes:keywords>vfemail, backup, cisco, password, microsoft, exchange, shlayer, gatekeeper, macos, updates, fake, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 13th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6370</itunes:episode>
<itunes:subtitle>Microsoft Updates; Adobe Updates; Ubuntu snapd dirty_sock
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Updates; Adobe Updates; Ubuntu snapd dirty_sock
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6370.mp3" length="4557482" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6370.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6370</link>
<pubDate>Wed, 13 Feb 2019 03:10:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+February+2019+Patch+Tuesday/24638/">https://isc.sans.edu/forums/diary/Microsoft+February+2019+Patch+Tuesday/24638/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Ubuntu Linux snapd "dirty_sock" exploit<br/>
 <a href="https://shenaniganslabs.io/2019/02/13/Dirty-Sock.html">https://shenaniganslabs.io/2019/02/13/Dirty-Sock.html</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6370" type="text/plain" language="en" />
<itunes:keywords>ubuntu, snapd, dirty_sock, adobe, acrobat, cold fusion, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 12th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6368</itunes:episode>
<itunes:subtitle>Docker runc Vulnerability; MacOS Privacy Flaw; Android Crypto Clipper Malware; Not an E-Mail Virus
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Docker runc Vulnerability; MacOS Privacy Flaw; Android Crypto Clipper Malware; Not an E-Mail Virus
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6368.mp3" length="4138370" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6368.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6368</link>
<pubDate>Tue, 12 Feb 2019 03:20:02 GMT</pubDate>
<description><![CDATA[Severe Docker runc Vulnerability<br/>
 <a href="https://seclists.org/oss-sec/2019/q1/119">https://seclists.org/oss-sec/2019/q1/119</a><br/>
MacOS Mojave Privacy Flaw<br/>
 <a href="https://lapcatsoftware.com/articles/mojave-privacy3.html">https://lapcatsoftware.com/articles/mojave-privacy3.html</a><br/>
Android Malware Steals Crypto Addresses from Clipboard<br/>
 <a href="https://www.welivesecurity.com/2019/02/08/first-clipper-malware-google-play/">https://www.welivesecurity.com/2019/02/08/first-clipper-malware-google-play/</a><br/>
Not An E-Mail Virus, Just Intersting Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Have+You+Seen+an+Email+Virus+Recently/24634/">https://isc.sans.edu/forums/diary/Have+You+Seen+an+Email+Virus+Recently/24634/</a><br/>
]]></description>
<itunes:duration>4:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6368" type="text/plain" language="en" />
<itunes:keywords>email, virus, malware, android, macos, privacy, mojave, docker, runc, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6366</itunes:episode>
<itunes:subtitle>JavaScript Phishing; Translated Phishing; iPhone Screen Record
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
JavaScript Phishing; Translated Phishing; iPhone Screen Record
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6366.mp3" length="5740928" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6366.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6366</link>
<pubDate>Mon, 11 Feb 2019 03:25:02 GMT</pubDate>
<description><![CDATA[Phishing Kit with JavaScript Keylogger<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+Kit+with+JavaScript+Keylogger/24622/">https://isc.sans.edu/forums/diary/Phishing+Kit+with+JavaScript+Keylogger/24622/</a><br/>
Phishing Via Google Translate<br/>
 <a href="https://blogs.akamai.com/sitr/2019/02/phishing-attacks-against-facebook-google-via-google-translate.html">https://blogs.akamai.com/sitr/2019/02/phishing-attacks-against-facebook-google-via-google-translate.html</a><br/>
iPhone Apps Record Screens<br/>
 <a href="https://techcrunch.com/2019/02/06/iphone-session-replay-screenshots/">https://techcrunch.com/2019/02/06/iphone-session-replay-screenshots/</a><br/>
Packet Challenge<br/>
 <a href="https://johannes.homepc.org/packet10.txt">https://johannes.homepc.org/packet10.txt</a><br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6366" type="text/plain" language="en" />
<itunes:keywords>iphone, phishing, google translate, javascript, glassbox, record screen, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6364</itunes:episode>
<itunes:subtitle>Value of UAC; Apple Releases Facetime Patch; Skype Blured Background; 2nd MSFT Exchange Advisory
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Value of UAC; Apple Releases Facetime Patch; Skype Blured Background; 2nd MSFT Exchange Advisory
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6364.mp3" length="4611602" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6364.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6364</link>
<pubDate>Fri, 08 Feb 2019 03:40:02 GMT</pubDate>
<description><![CDATA[Value of UAC<br/>
 <a href="https://isc.sans.edu/forums/diary/UAC+is+not+all+that+bad+really/24620/">https://isc.sans.edu/forums/diary/UAC+is+not+all+that+bad+really/24620/</a><br/>
Apple Releases Facetime Patch<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Skype Video Now Allows For Blurred Background<br/>
 <a href="https://blogs.skype.com/news/2019/02/06/introducing-background-blur-in-skype/">https://blogs.skype.com/news/2019/02/06/introducing-background-blur-in-skype/</a><br/>
Microsoft Exchange Server Advisory<br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv190007">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/adv190007</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6364" type="text/plain" language="en" />
<itunes:keywords>exchange, ntlm, skype, blurred, apple, facetime, ios, mohjave, uac, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6362</itunes:episode>
<itunes:subtitle>PNG Android Vulnerability; Skia Graphics Library Vuln; Google Chrome Password Check;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PNG Android Vulnerability; Skia Graphics Library Vuln; Google Chrome Password Check;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6362.mp3" length="5424223" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6362.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6362</link>
<pubDate>Wed, 06 Feb 2019 23:50:02 GMT</pubDate>
<description><![CDATA[Android Monthly Security Update<br/>
 <a href="https://source.android.com/security/bulletin/2019-02-01.html">https://source.android.com/security/bulletin/2019-02-01.html</a><br/>
Skia Graphics Library Vulnerability<br/>
 <a href="https://googleprojectzero.blogspot.com/2019/02/the-curious-case-of-convexity-confusion.html">https://googleprojectzero.blogspot.com/2019/02/the-curious-case-of-convexity-confusion.html</a><br/>
Google Chrome Password Check<br/>
 <a href="https://chrome.google.com/webstore/detail/password-checkup/pncabnpcffmalkkjpajodfhijclecjno/related">https://chrome.google.com/webstore/detail/password-checkup/pncabnpcffmalkkjpajodfhijclecjno/related</a><br/>
Hancitor HelloFax Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+malspam+and+infection+traffic+from+Tuesday+20190205/24616/">https://isc.sans.edu/forums/diary/Hancitor+malspam+and+infection+traffic+from+Tuesday+20190205/24616/</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6362" type="text/plain" language="en" />
<itunes:keywords>Hancitor, hellofax, google, chrome, passwords, skia, android, png, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 6th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6360</itunes:episode>
<itunes:subtitle>Mimikatz Defenses; LibreOffice Vulnerability; Firefox 65 And HTTPS AV Scanning
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Mimikatz Defenses; LibreOffice Vulnerability; Firefox 65 And HTTPS AV Scanning
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6360.mp3" length="5640728" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6360.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6360</link>
<pubDate>Wed, 06 Feb 2019 00:50:02 GMT</pubDate>
<description><![CDATA[Mitigations against Mimikatz Style Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Mitigations+against+Mimikatz+Style+Attacks/24612/">https://isc.sans.edu/forums/diary/Mitigations+against+Mimikatz+Style+Attacks/24612/</a><br/>
LibreOffice Macro Vulnerability <br/>
 <a href="https://insert-script.blogspot.com/2019/02/libreoffice-cve-2018-16858-remote-code.html">https://insert-script.blogspot.com/2019/02/libreoffice-cve-2018-16858-remote-code.html</a><br/>
Firefox 65 Breaks HTTPS AV Scanning<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1523701">https://bugzilla.mozilla.org/show_bug.cgi?id=1523701</a><br/>
RDP Client Vulnerabilities<br/>
 <a href="https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/">https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/</a><br/>
DNS "Lookingglass" <br/>
 <a href="https://isc.sans.edu/tools/dnslookup.html">https://isc.sans.edu/tools/dnslookup.html</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6360" type="text/plain" language="en" />
<itunes:keywords>dns, lookingglass, firefox, tls, rdp, client, libreoffice, openoffice, mimikatz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 5th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6358</itunes:episode>
<itunes:subtitle>Exploiting Struts in vCenter; Wikipedia Tech Support Scam; Stealing MacOS Keychain; Spy Beauty Cameras
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exploiting Struts in vCenter; Wikipedia Tech Support Scam; Stealing MacOS Keychain; Spy Beauty Cameras
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6358.mp3" length="4515421" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6358.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6358</link>
<pubDate>Tue, 05 Feb 2019 02:05:02 GMT</pubDate>
<description><![CDATA[Exploiting Struts in vCenter<br/>
 <a href="https://isc.sans.edu/forums/diary/Struts+Vulnerability+CVE20175638+on+VMware+vCenter+the+Gift+that+Keeps+on+Giving/24606/">https://isc.sans.edu/forums/diary/Struts+Vulnerability+CVE20175638+on+VMware+vCenter+the+Gift+that+Keeps+on+Giving/24606/</a><br/>
Wikipedia Tech Support Scam<br/>
 <a href="https://isc.sans.edu/forums/diary/Wikipedia+Articles+as+part+of+Tech+Support+Scamming+Campaigns/24608/">https://isc.sans.edu/forums/diary/Wikipedia+Articles+as+part+of+Tech+Support+Scamming+Campaigns/24608/</a><br/>
Stealing MacOS Keychain<br/>
 <a href="https://www.youtube.com/watch?v=nYTBZ9iPqsU">https://www.youtube.com/watch?v=nYTBZ9iPqsU</a><br/>
Beauty Camera Ads for Android include Adware<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/various-google-play-beauty-camera-apps-sends-users-pornographic-content-redirects-them-to-phishing-websites-and-collects-their-pictures/">https://blog.trendmicro.com/trendlabs-security-intelligence/various-google-play-beauty-camera-apps-sends-users-pornographic-content-redirects-them-to-phishing-websites-and-collects-their-pictures/</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6358" type="text/plain" language="en" />
<itunes:keywords>beauty camera, android, spyware, adware, macos, keychain, wikipedia, tech support scam, sruts, vcenter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6356</itunes:episode>
<itunes:subtitle>Sextortion Update; Ubiquity Discovery DDoS; Google Typodomain Warnings; Youtube Extortion
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sextortion Update; Ubiquity Discovery DDoS; Google Typodomain Warnings; Youtube Extortion
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6356.mp3" length="6492105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6356.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6356</link>
<pubDate>Mon, 04 Feb 2019 03:30:03 GMT</pubDate>
<description><![CDATA[Sextortion EMail Update<br/>
<a href="https://isc.sans.edu/forums/diary/Sextortion+Follow+the+Money+Part+3+The+cashout+begins/24592/">https://isc.sans.edu/forums/diary/Sextortion+Follow+the+Money+Part+3+The+cashout+begins/24592/</a><br/>
Ubiquity Devices Used in DDoS Attack<br/>
<a href="https://blog.rapid7.com/2019/02/01/ubiquiti-discovery-service-exposures/?fbclid=IwAR0OUPQIfSV7YsBLvkjoC2WIbe_E4p9WGAM4LCTsL9TKr30I7aQ2Qwqoins">https://blog.rapid7.com/2019/02/01/ubiquiti-discovery-service-exposures/?fbclid=IwAR0OUPQIfSV7YsBLvkjoC2WIbe_E4p9WGAM4LCTsL9TKr30I7aQ2Qwqoins</a><br/>
Google Chrome Experimenting with Typo Domain Detection<br/>
<a href="https://www.usenix.org/conference/enigma2019/presentation/stark">https://www.usenix.org/conference/enigma2019/presentation/stark</a><br/>
YouTube Copyright Extortion<br/>
<a href="https://www.youtube.com/watch?v=Q0i-sLESXqo">https://www.youtube.com/watch?v=Q0i-sLESXqo</a><br/>
]]></description>
<itunes:duration>7:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6356" type="text/plain" language="en" />
<itunes:keywords>youtube, copyright, extortion, google, chrome, typo, ubiquity, discovery, ddos, sextortion, bitcoin, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 1st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6354</itunes:episode>
<itunes:subtitle>Tracking DNS Changes; Systemd Exploit; Windows Defender Boot Issues; MacOS Malware 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tracking DNS Changes; Systemd Exploit; Windows Defender Boot Issues; MacOS Malware 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6354.mp3" length="5097636" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6354.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6354</link>
<pubDate>Fri, 01 Feb 2019 00:40:02 GMT</pubDate>
<description><![CDATA[Tracking DNS Changes<br/>
 <a href="https://isc.sans.edu/forums/diary/Tracking+Unexpected+DNS+Changes/24596/">https://isc.sans.edu/forums/diary/Tracking+Unexpected+DNS+Changes/24596/</a><br/>
SystemD/JournalD PoC Exploit<br/>
 <a href="https://capsule8.com/blog/exploiting-systemd-journald-part-1/">https://capsule8.com/blog/exploiting-systemd-journald-part-1/</a><br/>
Windows Defender Boot Issues<br/>
 <a href="https://support.microsoft.com/en-us/help/4052623/update-for-windows-defender-antimalware-platform">https://support.microsoft.com/en-us/help/4052623/update-for-windows-defender-antimalware-platform</a><br/>
Mac Malware Steals Crytocurrency Exchange Cookies<br/>
 <a href="https://unit42.paloaltonetworks.com/mac-malware-steals-cryptocurrency-exchanges-cookies/">https://unit42.paloaltonetworks.com/mac-malware-steals-cryptocurrency-exchanges-cookies/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6354" type="text/plain" language="en" />
<itunes:keywords>mac, ox x, malware, cryptocurrency, cookies, windows, defender, boot, systemd, journald, dns, tracking, nagios, ossec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 31st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6352</itunes:episode>
<itunes:subtitle>Chrome Update; Firefox Update; Facbook/Google iOS Spy VPN; Samsung Store RCE
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chrome Update; Firefox Update; Facbook/Google iOS Spy VPN; Samsung Store RCE
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6352.mp3" length="4913684" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6352.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6352</link>
<pubDate>Thu, 31 Jan 2019 02:35:02 GMT</pubDate>
<description><![CDATA[Chrome Update<br/>
 <a href="https://www.zdnet.com/article/google-chrome-72-removes-hpkp-deprecates-tls-1-0-and-tls-1-1/">https://www.zdnet.com/article/google-chrome-72-removes-hpkp-deprecates-tls-1-0-and-tls-1-1/</a><br/>
Firefox Update<br/>
 <a href="https://techdows.com/2019/01/firefox-to-disable-extensions-in-private-browsing-mode-by-default.html">https://techdows.com/2019/01/firefox-to-disable-extensions-in-private-browsing-mode-by-default.html</a><br/>
Facebook (and Google) Research VPN<br/>
 <a href="https://techcrunch.com/2019/01/29/facebook-project-atlas/">https://techcrunch.com/2019/01/29/facebook-project-atlas/</a><br/>
 <a href="https://www.macrumors.com/2019/01/30/google-exploiting-apple-enterprise-certificate/">https://www.macrumors.com/2019/01/30/google-exploiting-apple-enterprise-certificate/</a><br/>
RCE In Samsung Store via "evilgrade" <br/>
 <a href="https://www.adyta.pt/en/2019/01/29/writeup-samsung-app-store-rce-via-mitm-2/">https://www.adyta.pt/en/2019/01/29/writeup-samsung-app-store-rce-via-mitm-2/</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6352" type="text/plain" language="en" />
<itunes:keywords>chrome, firefox, facebook, google, research vpn, vpn, rce, samsung, evilgrade, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 30th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6350</itunes:episode>
<itunes:subtitle>Phishing IPv6 Miss; Facetime Bug Update; Outlook 365 Error
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phishing IPv6 Miss; Facetime Bug Update; Outlook 365 Error
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6350.mp3" length="4901983" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6350.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6350</link>
<pubDate>Wed, 30 Jan 2019 01:55:03 GMT</pubDate>
<description><![CDATA[Phishing Not Ready for IPv6<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Not+So+Well+Done+Phish+Why+Attackers+need+to+Implement+IPv6+Now/24582/">https://isc.sans.edu/forums/diary/A+Not+So+Well+Done+Phish+Why+Attackers+need+to+Implement+IPv6+Now/24582/</a><br/>
Apple Disables Facetime Group Messages<br/>
 <a href="https://www.apple.com/support/systemstatus/">https://www.apple.com/support/systemstatus/</a><br/>
Outlook 365 Safe Link Errors<br/>
 <a href="https://twitter.com/Swiss_Jay/status/1090271197193940992">https://twitter.com/Swiss_Jay/status/1090271197193940992</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6350" type="text/plain" language="en" />
<itunes:keywords>outlook 365, 503, facetime, apple, ipv6, phishing, realtor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 29th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6348</itunes:episode>
<itunes:subtitle>Exchange Server Priv. Escalation; Facetime Spy Bug; AZORult 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Exchange Server Priv. Escalation; Facetime Spy Bug; AZORult 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6348.mp3" length="4345362" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6348.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6348</link>
<pubDate>Tue, 29 Jan 2019 02:15:03 GMT</pubDate>
<description><![CDATA[Relaying Exchange's NTLM Autentication to Become Domain Admin<br/>
 <a href="https://isc.sans.edu/forums/diary/Relaying+Exchanges+NTLM+authentication+to+domain+admin+and+more/24578/">https://isc.sans.edu/forums/diary/Relaying+Exchanges+NTLM+authentication+to+domain+admin+and+more/24578/</a><br/>
Facetime Bug Allows Users to Receive Audio before Call is Accepted<br/>
 <a href="https://9to5mac.com/2019/01/28/facetime-bug-hear-audio/">https://9to5mac.com/2019/01/28/facetime-bug-hear-audio/</a><br/>
AZORult Fake (signed) Google Update<br/>
 <a href="https://blog.minerva-labs.com/azorult-now-as-a-signed-google-update">https://blog.minerva-labs.com/azorult-now-as-a-signed-google-update</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6348" type="text/plain" language="en" />
<itunes:keywords>azorult, google, minerva, facetime, spy, exchange, ntlm, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 28th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6346</itunes:episode>
<itunes:subtitle>Cisco RV320/5 Vuln Exploited; Signed HTTP Exchanges; BGP Research Affects Routers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco RV320/5 Vuln Exploited; Signed HTTP Exchanges; BGP Research Affects Routers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6346.mp3" length="5935851" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6346.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6346</link>
<pubDate>Mon, 28 Jan 2019 03:00:03 GMT</pubDate>
<description><![CDATA[Cisco RV320/325 Router Vulnerability Exploited<br/>
 <a href="https://github.com/0x27/CiscoRV320Dump">https://github.com/0x27/CiscoRV320Dump</a><br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-inject</a><br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-rv-info</a><br/>
HTTP Signed Exchanges<br/>
 <a href="https://wicg.github.io/webpackage/draft-yasskin-http-origin-signed-responses.html">https://wicg.github.io/webpackage/draft-yasskin-http-origin-signed-responses.html</a><br/>
BGP Experiments Disrupt Routers<br/>
 <a href="https://mailman.nanog.org/pipermail/nanog/2019-January/098761.html">https://mailman.nanog.org/pipermail/nanog/2019-January/098761.html</a><br/>
Packet Challenge<br/>
 <a href="https://johannes.homepc.org/packet9.txt">https://johannes.homepc.org/packet9.txt</a><br/>
]]></description>
<itunes:duration>7:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6346" type="text/plain" language="en" />
<itunes:keywords>packetlife, packet, routers, bpg, HTTP Signed Exchanges, Cisco, RV320, RV325, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 25th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6344</itunes:episode>
<itunes:subtitle>Ghostscript RCE; Exchange Priv Escalation; iOS Remote Jailbreak
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ghostscript RCE; Exchange Priv Escalation; iOS Remote Jailbreak
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6344.mp3" length="4731554" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6344.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6344</link>
<pubDate>Fri, 25 Jan 2019 02:10:02 GMT</pubDate>
<description><![CDATA[Ghostscript Remote Code Execution Vulnerability<br/>
 <a href="https://www.openwall.com/lists/oss-security/2019/01/23/5">https://www.openwall.com/lists/oss-security/2019/01/23/5</a><br/>
Abusing Exchange to Obtain Domain Admin<br/>
 <a href="https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/">https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/</a><br/>
IPC Voucher UaF Remote Jailbreak<br/>
 <a href="http://blogs.360.cn/post/IPC%20Voucher%20UaF%20Remote%20Jailbreak%20Stage%202%20(EN).html">http://blogs.360.cn/post/IPC%20Voucher%20UaF%20Remote%20Jailbreak%20Stage%202%20(EN).html</a><br/>
Cisco Security Updates<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-bo">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190123-sdwan-bo</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6344" type="text/plain" language="en" />
<itunes:keywords>cisco, sd-wan, patches, ipc, uaf, ios, apple, jailbreak, exchange, domain admin, ghostscript, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 24th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6342</itunes:episode>
<itunes:subtitle>DHS Suggests Checking DNS; Azure Domain Abuse; Twitter Tech Support Scam
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DHS Suggests Checking DNS; Azure Domain Abuse; Twitter Tech Support Scam
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6342.mp3" length="4370232" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6342.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6342</link>
<pubDate>Thu, 24 Jan 2019 00:50:02 GMT</pubDate>
<description><![CDATA[DHS Emergency Directive Regarding DNS Tampering<br/>
 <a href="https://cyber.dhs.gov/ed/19-01/">https://cyber.dhs.gov/ed/19-01/</a><br/>
Abuse of Trusted Microsoft Azure Domains<br/>
 <a href="https://github.com/MicrosoftDocs/OfficeDocs-Enterprise/issues/233">https://github.com/MicrosoftDocs/OfficeDocs-Enterprise/issues/233</a><br/>
Tech Support Scammers Unmasked<br/>
 <a href="https://www.fidusinfosec.com/turning-the-tables-on-virgin-media-twitter-scammers/">https://www.fidusinfosec.com/turning-the-tables-on-virgin-media-twitter-scammers/</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6342" type="text/plain" language="en" />
<itunes:keywords>tech support scam, twitter, microsoft, azure, domains, dhs, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 23rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6340</itunes:episode>
<itunes:subtitle>Turning MISP Data into RPZs; APT Vulnerability; PEAR compromise; Apple Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Turning MISP Data into RPZs; APT Vulnerability; PEAR compromise; Apple Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6340.mp3" length="6013023" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6340.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6340</link>
<pubDate>Wed, 23 Jan 2019 00:55:02 GMT</pubDate>
<description><![CDATA[Turning MISP Data into RPZs<br/>
 <a href="https://isc.sans.edu/forums/diary/DNS+Firewalling+with+MISP/24556/">https://isc.sans.edu/forums/diary/DNS+Firewalling+with+MISP/24556/</a><br/>
Man in the Middle Vulnerablity in apt<br/>
 <a href="https://justi.cz/security/2019/01/22/apt-rce.html">https://justi.cz/security/2019/01/22/apt-rce.html</a><br/>
PHP PEAR Compromised Package<br/>
 <a href="http://pear.php.net">http://pear.php.net</a><br/>
Apple Security Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
]]></description>
<itunes:duration>7:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6340" type="text/plain" language="en" />
<itunes:keywords>apple, patches, ios, mac os, watchos, safari, tvos, php pear, apt, mitm, misp, rpz, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 22nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6338</itunes:episode>
<itunes:subtitle>Suspect GET Requests (need help!); DNS Flag Day
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Suspect GET Requests (need help!); DNS Flag Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6338.mp3" length="4644150" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6338.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6338</link>
<pubDate>Tue, 22 Jan 2019 02:15:02 GMT</pubDate>
<description><![CDATA[Suspicious GET Request: Do you know what it is?<br/>
 <a href="https://isc.sans.edu/forums/diary/Suspicious+GET+Request+Do+You+Know+What+This+Is/24552/">https://isc.sans.edu/forums/diary/Suspicious+GET+Request+Do+You+Know+What+This+Is/24552/</a><br/>
DNS Flag Day<br/>
 <a href="https://dnsflagday.net/">https://dnsflagday.net/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6338" type="text/plain" language="en" />
<itunes:keywords>dns, flag day, supicious get request, aes256, gpg, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 21st 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6336</itunes:episode>
<itunes:subtitle>Drupal Patch; WPML Hack; Google Drive for C&amp;C; Packet Challenge Solution
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Drupal Patch; WPML Hack; Google Drive for C&amp;C; Packet Challenge Solution
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6336.mp3" length="5245748" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6336.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6336</link>
<pubDate>Mon, 21 Jan 2019 03:55:03 GMT</pubDate>
<description><![CDATA[Drupal Patches<br/>
 <a href="https://www.drupal.org/sa-core-2019-002">https://www.drupal.org/sa-core-2019-002</a><br/>
 <a href="https://www.drupal.org/sa-core-2019-001">https://www.drupal.org/sa-core-2019-001</a><br/>
WPML User Data Compromised and Used in EMail To Customers<br/>
 <a href="https://wpml.org/2019/01/wpml-org-site-back-to-normal-after-an-attack-during-the-weekend/">https://wpml.org/2019/01/wpml-org-site-back-to-normal-after-an-attack-during-the-weekend/</a><br/>
Targeted Attack Uses Google Drive for Exfiltration<br/>
<a href="https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications/">https://unit42.paloaltonetworks.com/darkhydrus-delivers-new-trojan-that-can-use-google-drive-for-c2-communications/</a><br/>
Packet Challenge Solution<br/>
 <a href="https://johannes.homepc.org/packet8.txt">https://johannes.homepc.org/packet8.txt</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6336" type="text/plain" language="en" />
<itunes:keywords>drupal, wordpress, wpml, employee, insider, ssh, google drive, packet challenge, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 18th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6334</itunes:episode>
<itunes:subtitle>Android Malware Motion Evasion; Twitter for Android Bug; WebAuthn/FIDO2; Iranian RaaS
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Android Malware Motion Evasion; Twitter for Android Bug; WebAuthn/FIDO2; Iranian RaaS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6334.mp3" length="5337177" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6334.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6334</link>
<pubDate>Fri, 18 Jan 2019 02:05:03 GMT</pubDate>
<description><![CDATA[Android Malware Uses Motion Detection to Evade Analysis<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/google-play-apps-drop-anubis-banking-malware-use-motion-based-evasion-tactics/">https://blog.trendmicro.com/trendlabs-security-intelligence/google-play-apps-drop-anubis-banking-malware-use-motion-based-evasion-tactics/</a><br/>
Twitter for Android Bug<br/>
 <a href="https://help.twitter.com/en/protected-tweets-android">https://help.twitter.com/en/protected-tweets-android</a><br/>
Introduction to WebAuthn/FIDO2<br/>
 <a href="https://medium.com/@herrjemand/introduction-to-webauthn-api-5fd1fb46c285">https://medium.com/@herrjemand/introduction-to-webauthn-api-5fd1fb46c285</a><br/>
Ransomware As a Service<br/>
 <a href="https://www.bleepingcomputer.com/news/security/blackrouter-ransomware-promoted-as-a-raas-by-iranian-developer/">https://www.bleepingcomputer.com/news/security/blackrouter-ransomware-promoted-as-a-raas-by-iranian-developer/</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6334" type="text/plain" language="en" />
<itunes:keywords>ransomware as a service, ransomware, webauthn, fido2, raas, iran, twitter, android, malware, banking trojan, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 17th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6332</itunes:episode>
<itunes:subtitle>Emotet Update; Magecart Advertising; Premisys Vulnerabilities; ES File Explorer https://isc.sans.edu/podcastdetail.html?podcastid=6332</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Update; Magecart Advertising; Premisys Vulnerabilities; ES File Explorer https://isc.sans.edu/podcastdetail.html?podcastid=6332</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6332.mp3" length="4961958" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6332.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6332</link>
<pubDate>Thu, 17 Jan 2019 01:47:39 GMT</pubDate>
<description><![CDATA[Emotet and Other Malspam Campaigns Resume After Holiday Break<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+infections+and+followup+malware/24532/">https://isc.sans.edu/forums/diary/Emotet+infections+and+followup+malware/24532/</a><br/>
Magecart Delivered Via Compromised Advertising Sites<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/new-magecart-attack-delivered-through-compromised-advertising-supply-chain/">https://blog.trendmicro.com/trendlabs-security-intelligence/new-magecart-attack-delivered-through-compromised-advertising-supply-chain/</a><br/>
Premisys Identicard Vulnerabilities<br/>
 <a href="https://www.tenable.com/security/research/tra-2019-01">https://www.tenable.com/security/research/tra-2019-01</a><br/>
ES File Explorer Open Port Vulnerability<br/>
 <a href="https://github.com/fs0c131y/ESFileExplorerOpenPortVuln">https://github.com/fs0c131y/ESFileExplorerOpenPortVuln</a>]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6332" type="text/plain" language="en" />
<itunes:keywords>es file explorer, premisys, magecart, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 16th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6330</itunes:episode>
<itunes:subtitle>MSFT Skype/Team Foundation Server Patch; SCP Client Vulnerabilites; Hosting Vulnerabilites; Industri</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Skype/Team Foundation Server Patch; SCP Client Vulnerabilites; Hosting Vulnerabilites; Industri</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6330.mp3" length="5135307" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6330.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6330</link>
<pubDate>Wed, 16 Jan 2019 05:15:03 GMT</pubDate>
<description><![CDATA[MSFT Skype/Team Foundation Server Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Publishes+Patches+for+Skype+for+Business+and+Team+Foundation+Server/24540/">https://isc.sans.edu/forums/diary/Microsoft+Publishes+Patches+for+Skype+for+Business+and+Team+Foundation+Server/24540/</a><br/>
SCP Client Vulnerabilities<br/>
 <a href="https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt">https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt</a><br/>
Server Hosting Companies Trivilally Hacked<br/>
 <a href="https://www.websiteplanet.com/blog/report-popular-hosting-hacked/">https://www.websiteplanet.com/blog/report-popular-hosting-hacked/</a><br/>
Vulnerabilities in Industrial Remote Controls<br/>
 <a href="https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/attacks-against-industrial-machines-via-vulnerable-radio-remote-controllers-security-analysis-and-recommendations">https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/attacks-against-industrial-machines-via-vulnerable-radio-remote-controllers-security-analysis-and-recommendations</a><br/>
Oracle Quarterly Critical Patch Update<br/>
 <a href="https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html">https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6330" type="text/plain" language="en" />
<itunes:keywords>oracle, vulnerabilities, cpu, remote controls, crane, server hosting, hosting, scp, skype, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 15th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6328</itunes:episode>
<itunes:subtitle>Microsoft LAPS; Intel SGX Update; Godaddy Injecting JavaScript; Play with Docker
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft LAPS; Intel SGX Update; Godaddy Injecting JavaScript; Play with Docker
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6328.mp3" length="5036562" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6328.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6328</link>
<pubDate>Mon, 14 Jan 2019 23:30:02 GMT</pubDate>
<description><![CDATA[Microsoft LAPS - Blue Team / Red Team<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+LAPS+Blue+Team+Red+Team/24528/">https://isc.sans.edu/forums/diary/Microsoft+LAPS+Blue+Team+Red+Team/24528/</a><br/>
Intel SGX Platform Update<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00203.html">https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00203.html</a><br/>
Godaddy Injecting JavaScript<br/>
 <a href="https://www.igorkromin.net/index.php/2019/01/13/godaddy-is-sneakily-injecting-javascript-into-your-website-and-how-to-stop-it/">https://www.igorkromin.net/index.php/2019/01/13/godaddy-is-sneakily-injecting-javascript-into-your-website-and-how-to-stop-it/</a><br/>
Play with Docker Vulnerability<br/>
 <a href="https://www.cyberark.com/threat-research-blog/how-i-hacked-play-with-docker-and-remotely-ran-code-on-the-host/">https://www.cyberark.com/threat-research-blog/how-i-hacked-play-with-docker-and-remotely-ran-code-on-the-host/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6328" type="text/plain" language="en" />
<itunes:keywords>play with docker, pwd, godaddy, javascript, intel, sgx, patch, laps, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 14th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6326</itunes:episode>
<itunes:subtitle>.gov TLS Failures; Firefox Flash EOL; Fake Movie Malware; MSFT Patch Breaks Access 97
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
.gov TLS Failures; Firefox Flash EOL; Fake Movie Malware; MSFT Patch Breaks Access 97
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6326.mp3" length="4924286" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6326.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6326</link>
<pubDate>Mon, 14 Jan 2019 02:20:02 GMT</pubDate>
<description><![CDATA[Government Website TLS Certificates Expire due to Partial Shutdown<br/>
<a href="https://news.netcraft.com/archives/2019/01/10/gov-security-falters-during-u-s-shutdown.html">https://news.netcraft.com/archives/2019/01/10/gov-security-falters-during-u-s-shutdown.html</a><br/>
Firefox EOL Plan for Flash<br/>
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1519434">https://bugzilla.mozilla.org/show_bug.cgi?id=1519434</a><br/>
Fake Movie File Malware<br/>
<a href="https://www.bleepingcomputer.com/news/security/fake-movie-file-infects-pc-to-steal-cryptocurrency-poison-google-results/">https://www.bleepingcomputer.com/news/security/fake-movie-file-infects-pc-to-steal-cryptocurrency-poison-google-results/</a><br/>
Microsoft Windows Patch Breaks Access 97<br/>
<a href="https://borncity.com/win/2019/01/11/windows-january-2019-updates-breaks-access-to-access-dbs/">https://borncity.com/win/2019/01/11/windows-january-2019-updates-breaks-access-to-access-dbs/</a><br/>
Snorpy Assists in Snort Rule Writing<br/>
<a href="https://isc.sans.edu/forums/diary/Snorpy+a+Web+Base+Tool+to+Build+SnortSuricata+Rules/24522/">https://isc.sans.edu/forums/diary/Snorpy+a+Web+Base+Tool+to+Build+SnortSuricata+Rules/24522/</a><br/>
Packet Challenge]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6326" type="text/plain" language="en" />
<itunes:keywords>packet challenge, dns, packets, snorpy, snort, access, microsoft, patc, movie, malware, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 11th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6324</itunes:episode>
<itunes:subtitle>I Love You Again; Juniper got Love for you; Systemd doesn't love you; Iran Love DNS;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
I Love You Again; Juniper got Love for you; Systemd doesn't love you; Iran Love DNS;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6324.mp3" length="4788240" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6324.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6324</link>
<pubDate>Fri, 11 Jan 2019 00:05:02 GMT</pubDate>
<description><![CDATA[Old Tricks still work: I love you Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Heartbreaking+Emails+Love+You+Malspam/24512/">https://isc.sans.edu/forums/diary/Heartbreaking+Emails+Love+You+Malspam/24512/</a><br/>
Juniper Updates Released<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10916&cat=SIRT_1&actp=LIST">https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10916&cat=SIRT_1&actp=LIST</a><br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10918&cat=SIRT_1&actp=LIST">https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10918&cat=SIRT_1&actp=LIST</a><br/>
New Systemd/Journald Exploit Release<br/>
 <a href="https://www.qualys.com/2019/01/09/system-down/system-down.txt">https://www.qualys.com/2019/01/09/system-down/system-down.txt</a><br/>
Global DNS Hijacking<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html">https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6324" type="text/plain" language="en" />
<itunes:keywords>dns, iran, fireeye, systemd, journald, juniper, i love you, malspam, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 10th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6322</itunes:episode>
<itunes:subtitle>Face Recog. Test; Google DNS-over-TLS; Malwarebytes vs Win7
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Face Recog. Test; Google DNS-over-TLS; Malwarebytes vs Win7
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6322.mp3" length="4976221" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6322.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6322</link>
<pubDate>Thu, 10 Jan 2019 02:15:02 GMT</pubDate>
<description><![CDATA[Simple Mechanism for Creating Certificates<br/>
 <a href="https://blog.filippo.io/mkcert-valid-https-certificates-for-localhost/">https://blog.filippo.io/mkcert-valid-https-certificates-for-localhost/</a><br/>
Review of Smartphone Face Recognition<br/>
 <a href="https://www.consumentenbond.nl/veilig-internetten/gezichtsherkenning-te-hacken">https://www.consumentenbond.nl/veilig-internetten/gezichtsherkenning-te-hacken</a><br/>
Google Public DNS now supports DNS-over-TLS<br/>
 <a href="https://security.googleblog.com/2019/01/google-public-dns-now-supports-dns-over.html">https://security.googleblog.com/2019/01/google-public-dns-now-supports-dns-over.html</a><br/>
Malwarebytes Freezes Windows 7<br/>
 <a href="https://forums.malwarebytes.com/topic/241223-malwarebytes-for-windows-and-windows-7-freezelock-up/">https://forums.malwarebytes.com/topic/241223-malwarebytes-for-windows-and-windows-7-freezelock-up/</a><br/>
German Police Looking for MAC Address<br/>
 <a href="https://polizei.brandenburg.de/pressemeldung/f8-e0-79-af-57-eb-cyber-fahndung-nach-ma/1310909">https://polizei.brandenburg.de/pressemeldung/f8-e0-79-af-57-eb-cyber-fahndung-nach-ma/1310909</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6322" type="text/plain" language="en" />
<itunes:keywords>certificates, mkcert, face recognition, smart phones, dns-over-tls, port 853, malwarebytes, mac address, german police, dhl, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 9th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6320</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates; Google Play Store Adware; ETC 51% Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Updates; Google Play Store Adware; ETC 51% Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6320.mp3" length="4889914" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6320.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6320</link>
<pubDate>Wed, 09 Jan 2019 00:20:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+January+2019+Patch+Tuesday/24504/">https://isc.sans.edu/forums/diary/Microsoft+January+2019+Patch+Tuesday/24504/</a><br/>
 <a href="https://patchtuesdaydashboard.com/">https://patchtuesdaydashboard.com/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Google Play Store Adware<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/adware-disguised-as-game-tv-remote-control-apps-infect-9-million-google-play-users/">https://blog.trendmicro.com/trendlabs-security-intelligence/adware-disguised-as-game-tv-remote-control-apps-infect-9-million-google-play-users/</a><br/>
Ethereum Classic 51% Attack<br/>
 <a href="https://blog.coinbase.com/ethereum-classic-etc-is-currently-being-51-attacked-33be13ce32de">https://blog.coinbase.com/ethereum-classic-etc-is-currently-being-51-attacked-33be13ce32de</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6320" type="text/plain" language="en" />
<itunes:keywords>ethereum, etc, 51%, google, adware, adobe, microsoft, patch tuesday, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 8th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6318</itunes:episode>
<itunes:subtitle>Encrypted Word Doc; iOS Apps and Malware C&amp;C; NCSC Offers Help; Page Cache Side Channel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encrypted Word Doc; iOS Apps and Malware C&amp;C; NCSC Offers Help; Page Cache Side Channel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6318.mp3" length="5924516" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6318.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6318</link>
<pubDate>Tue, 08 Jan 2019 03:30:02 GMT</pubDate>
<description><![CDATA[Malware of the Day: Encrypted Word Document<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+Encrypted+Malicious+Office+Documents/24498/">https://isc.sans.edu/forums/diary/Analyzing+Encrypted+Malicious+Office+Documents/24498/</a><br/>
Apple iOS Apps Reaching Out to Malware Server<br/>
 <a href="https://www.wandera.com/risky-apps/">https://www.wandera.com/risky-apps/</a><br/>
NCSC Offers Assistance Against Attacks from Foreign Governments<br/>
 <a href="https://www.dni.gov/index.php/ncsc-how-we-work/ncsc-know-the-risk-raise-your-shield/ncsc-awareness-materials">https://www.dni.gov/index.php/ncsc-how-we-work/ncsc-know-the-risk-raise-your-shield/ncsc-awareness-materials</a><br/>
Hardware Agnostic Side Channel Attacks<br/>
 <a href="https://arxiv.org/abs/1901.01161">https://arxiv.org/abs/1901.01161</a><br/>
]]></description>
<itunes:duration>7:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6318" type="text/plain" language="en" />
<itunes:keywords>page cache, side channel, ncsc, ios, appstore, malware, encrypted, word, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 7th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6316</itunes:episode>
<itunes:subtitle>TAR Malware; ReiKey Protects Macs from Keystroke Loggers; Substition Cipher Font Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TAR Malware; ReiKey Protects Macs from Keystroke Loggers; Substition Cipher Font Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6316.mp3" length="5641451" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6316.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6316</link>
<pubDate>Mon, 07 Jan 2019 02:50:02 GMT</pubDate>
<description><![CDATA[Malware in TAR Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+tar+Attachments/24496/">https://isc.sans.edu/forums/diary/Malicious+tar+Attachments/24496/</a><br/>
ReiKey MacOS Keystoke Logger Detector<br/>
 <a href="https://objective-see.com/products/reikey.html">https://objective-see.com/products/reikey.html</a><br/>
Phishing Tool Kit uses Simple Substituion Fonts<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/phishing-template-uses-fake-fonts-decode-content-and-evade-detection">https://www.proofpoint.com/us/threat-insight/post/phishing-template-uses-fake-fonts-decode-content-and-evade-detection</a><br/>
]]></description>
<itunes:duration>6:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6316" type="text/plain" language="en" />
<itunes:keywords>phishing, fonts, substituion, tar, malware, keystroke logger, reikey, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 4th 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6314</itunes:episode>
<itunes:subtitle>Malware Leaks Data Via FTP; Hijacking Dormant Twitter Accounts; Critical Adobe Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Leaks Data Via FTP; Hijacking Dormant Twitter Accounts; Critical Adobe Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6314.mp3" length="5153954" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6314.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6314</link>
<pubDate>Fri, 04 Jan 2019 00:15:03 GMT</pubDate>
<description><![CDATA[Malware Leaks Victim Data via FTP<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Script+Leaking+Data+via+FTP/24484/">https://isc.sans.edu/forums/diary/Malicious+Script+Leaking+Data+via+FTP/24484/</a><br/>
Hijacking Dormant Twitter Accounts<br/>
 <a href="https://techcrunch.com/2019/01/02/hackers-islamic-state-propaganda-twitter/">https://techcrunch.com/2019/01/02/hackers-islamic-state-propaganda-twitter/</a><br/>
Android Authentication Bypass via Skype<br/>
 <a href="https://www.youtube.com/watch?v=EiEcwOfTFqI">https://www.youtube.com/watch?v=EiEcwOfTFqI</a><br/>
Critical Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb19-02.html">https://helpx.adobe.com/security/products/acrobat/apsb19-02.html</a><br/>
FilesLocker Ransomware Master Key Published<br/>
 <a href="https://www.bleepingcomputer.com/news/security/master-decryption-key-released-for-fileslocker-ransomware/">https://www.bleepingcomputer.com/news/security/master-decryption-key-released-for-fileslocker-ransomware/</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6314" type="text/plain" language="en" />
<itunes:keywords>fileslocker, ransomware, adobe, acrobat, reader, android, lock screen bypass, twitter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 3rd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6312</itunes:episode>
<itunes:subtitle>Gift Card Scams; Wifi Chipset Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Gift Card Scams; Wifi Chipset Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6312.mp3" length="4927581" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6312.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6312</link>
<pubDate>Thu, 03 Jan 2019 01:35:03 GMT</pubDate>
<description><![CDATA[Gift Card Scams<br/>
 <a href="https://isc.sans.edu/forums/diary/Gift+Card+Scams+on+the+rise/24482/">https://isc.sans.edu/forums/diary/Gift+Card+Scams+on+the+rise/24482/</a><br/>
WiFi Chipset Exploit<br/>
 <a href="https://2018.zeronights.ru/wp-content/uploads/materials/19-Researching-Marvell-Avastar-Wi-Fi.pdf?fbclid=IwAR07FmZGKLKdJAKI4g0o-Wm-dLGwclV8Hhi-L4_HRlklldY8UC6WY72AdAw">https://2018.zeronights.ru/wp-content/uploads/materials/19-Researching-Marvell-Avastar-Wi-Fi.pdf?fbclid=IwAR07FmZGKLKdJAKI4g0o-Wm-dLGwclV8Hhi-L4_HRlklldY8UC6WY72AdAw</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6312" type="text/plain" language="en" />
<itunes:keywords>wifi, gift cards, exploit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 2nd 2019</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6310</itunes:episode>
<itunes:subtitle>Vein Scanner Bypass; Lightbulb Bots; EU Open Source Bug Bounty
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Vein Scanner Bypass; Lightbulb Bots; EU Open Source Bug Bounty
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6310.mp3" length="6112863" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6310.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6310</link>
<pubDate>Wed, 02 Jan 2019 01:50:02 GMT</pubDate>
<description><![CDATA[Bypassing Vein Scanner Authentication (in german)<br/>
 <a href="https://media.ccc.de/v/35c3-9545-venenerkennung_hacken">https://media.ccc.de/v/35c3-9545-venenerkennung_hacken</a><br/>
Hacking Smart Lightbulbs and Firmware Exploits<br/>
 <a href="https://media.ccc.de/v/35c3-9723-smart_home_-_smart_hack">https://media.ccc.de/v/35c3-9723-smart_home_-_smart_hack</a><br/>
European Union Offers Bug Bounty for Open Source Software<br/>
 <a href="https://juliareda.eu/fossa/">https://juliareda.eu/fossa/</a><br/>
Bypassing Google ReCaptcha<br/>
 <a href="https://github.com/ecthros/uncaptcha2">https://github.com/ecthros/uncaptcha2</a><br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6310" type="text/plain" language="en" />
<itunes:keywords>ccc, vein, scanner, biometrics, lightbulb, iot, open source, bug bounty, recaptcha, uncaptcha, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 28th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6308</itunes:episode>
<itunes:subtitle>Phish with Click Counter; Insecure IPMI Ransomware; MS Edge RCE Exploit;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Phish with Click Counter; Insecure IPMI Ransomware; MS Edge RCE Exploit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6308.mp3" length="5111533" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6308.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6308</link>
<pubDate>Fri, 28 Dec 2018 01:40:02 GMT</pubDate>
<description><![CDATA[Phishing Attack Uses IP Counter<br/>
 <a href="https://isc.sans.edu/forums/diary/Matryoshka+Phish/24460/">https://isc.sans.edu/forums/diary/Matryoshka+Phish/24460/</a><br/>
JungleSec Ransomware Attacks via IPMI<br/>
 <a href="https://www.bleepingcomputer.com/news/security/junglesec-ransomware-infects-victims-through-ipmi-remote-consoles/">https://www.bleepingcomputer.com/news/security/junglesec-ransomware-infects-victims-through-ipmi-remote-consoles/</a><br/>
Microsoft Edge PoC RCE Exploit <br/>
 <a href="https://github.com/phoenhex/files/blob/master/pocs/cve-2018-8629-chakra.js">https://github.com/phoenhex/files/blob/master/pocs/cve-2018-8629-chakra.js</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6308" type="text/plain" language="en" />
<itunes:keywords>microsoft, edge, exploit, junglesec, ipmi, ransomware, phishing, ip counter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6306</itunes:episode>
<itunes:subtitle>Problems with IE Emergency Patch; Bitcoin Blacklists; D-Link Password Overflow;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Problems with IE Emergency Patch; Bitcoin Blacklists; D-Link Password Overflow;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6306.mp3" length="2310532" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6306.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6306</link>
<pubDate>Wed, 26 Dec 2018 23:20:01 GMT</pubDate>
<description><![CDATA[Problems with IE Emergency Patch<br/>
 <a href="https://support.microsoft.com/en-us/help/4483229/december192018kb4483229osbuild143932670">https://support.microsoft.com/en-us/help/4483229/december192018kb4483229osbuild143932670</a><br/>
Bitcoin Blacklists<br/>
 <a href="https://isc.sans.edu/forums/diary/Bitcoin+Blacklists/24456/">https://isc.sans.edu/forums/diary/Bitcoin+Blacklists/24456/</a><br/>
D-Link DIR-816 A2 Stack Overflow<br/>
 <a href="https://github.com/RootSoull/Vuln-Poc/tree/master/D-Link/DIR-816">https://github.com/RootSoull/Vuln-Poc/tree/master/D-Link/DIR-816</a><br/>
]]></description>
<itunes:duration>2:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6306" type="text/plain" language="en" />
<itunes:keywords>dlink, bitcoin, lenovo, emergency patch, problems, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 21st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6304</itunes:episode>
<itunes:subtitle>Windows 0-Day PoC; Targeted 2FA Attacks; Booter Services Shut Down; Intel VISA
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows 0-Day PoC; Targeted 2FA Attacks; Booter Services Shut Down; Intel VISA
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6304.mp3" length="4827739" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6304.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6304</link>
<pubDate>Fri, 21 Dec 2018 01:00:04 GMT</pubDate>
<description><![CDATA[Windows 0-Day PoC Published: Arbitrary File Read as System<br/>
 <a href="https://sandboxescaper.blogspot.com/2018/12/readfile-0day.html">https://sandboxescaper.blogspot.com/2018/12/readfile-0day.html</a><br/>
Attacks Against 2FA in the Middle East<br/>
 <a href="https://www.amnesty.org/en/latest/research/2018/12/when-best-practice-is-not-good-enough/">https://www.amnesty.org/en/latest/research/2018/12/when-best-practice-is-not-good-enough/</a><br/>
FBI Shuts Down Booter Services<br/>
 <a href="http://www.documentcloud.org/documents/5648950-DOJ-indictments-in-booter-cases.html">http://www.documentcloud.org/documents/5648950-DOJ-indictments-in-booter-cases.html</a><br/>
Intel VISA Undocumented Debug Feature<br/>
 <a href="https://www.blackhat.com/asia-19/briefings/schedule/index.html#intel-visa-through-the-rabbit-hole-13513">https://www.blackhat.com/asia-19/briefings/schedule/index.html#intel-visa-through-the-rabbit-hole-13513</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6304" type="text/plain" language="en" />
<itunes:keywords>intel, visa, fbi, booter, ddos, cloudflare, 2fa, middle east, amnesty, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 20th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6302</itunes:episode>
<itunes:subtitle>Emergency MSFT IE Patch; Restricting PowerShell; BMC Server Bricking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emergency MSFT IE Patch; Restricting PowerShell; BMC Server Bricking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6302.mp3" length="3598943" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6302.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6302</link>
<pubDate>Thu, 20 Dec 2018 00:25:03 GMT</pubDate>
<description><![CDATA[Microsoft Publishes Emergency Patch for Internet Explorer<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+OOB+Patch+for+Internet+Explorer+Scripting+Engine+Memory+Corruption+Vulnerability/24438/">https://isc.sans.edu/forums/diary/Microsoft+OOB+Patch+for+Internet+Explorer+Scripting+Engine+Memory+Corruption+Vulnerability/24438/</a><br/>
Restricting PowerShell Capabilities with NetSh<br/>
 <a href="https://isc.sans.edu/forums/diary/Restricting+PowerShell+Capabilities+with+NetSh/24434/">https://isc.sans.edu/forums/diary/Restricting+PowerShell+Capabilities+with+NetSh/24434/</a><br/>
Remotely Bricking a Server <br/>
 <a href="https://eclypsium.com/2018/12/19/remotely-bricking-a-server/">https://eclypsium.com/2018/12/19/remotely-bricking-a-server/</a><br/>
]]></description>
<itunes:duration>4:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6302" type="text/plain" language="en" />
<itunes:keywords>Microsoft, Internet Explorer, powershell, netsh, bmc, bricking, servers, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 19th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6300</itunes:episode>
<itunes:subtitle>ASUS/Gigabyte Vulns; Apple Phishing; Kibana Exploit; SANS Holiday Hack Challenge #kringlecon
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ASUS/Gigabyte Vulns; Apple Phishing; Kibana Exploit; SANS Holiday Hack Challenge #kringlecon
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6300.mp3" length="4707791" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6300.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6300</link>
<pubDate>Wed, 19 Dec 2018 01:00:04 GMT</pubDate>
<description><![CDATA[ASUS Vulnerabilities<br/>
 <a href="https://www.secureauth.com/labs/advisories/asus-drivers-elevation-privilege-vulnerabilities">https://www.secureauth.com/labs/advisories/asus-drivers-elevation-privilege-vulnerabilities</a><br/>
GIGABYTE Vulnerabilities <br/>
 <a href="https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities">https://www.secureauth.com/labs/advisories/gigabyte-drivers-elevation-privilege-vulnerabilities</a><br/>
Apple App Store Phishing<br/>
 <a href="https://www.bleepingcomputer.com/news/security/widespread-apple-id-phishing-attack-pretends-to-be-app-store-receipts">https://www.bleepingcomputer.com/news/security/widespread-apple-id-phishing-attack-pretends-to-be-app-store-receipts</a><br/>
Kibana Vulnerability Exploited<br/>
 <a href="https://www.cyberark.com/threat-research-blog/execute-this-i-know-you-have-it/">https://www.cyberark.com/threat-research-blog/execute-this-i-know-you-have-it/</a><br/>
Decrypter for InsaneCrypt and Everbe 1 <br/>
 <a href="https://www.bleepingcomputer.com/ransomware/decryptor/how-to-decrypt-the-insanecrypt-or-everbe-1-family-of-ransomware/">https://www.bleepingcomputer.com/ransomware/decryptor/how-to-decrypt-the-insanecrypt-or-everbe-1-family-of-ransomware/</a><br/>
 <a href="http://id-ransomware.malwarehunterteam.com/">http://id-ransomware.malwarehunterteam.com/</a><br/>
SANS Holiday Hack Challenge<br/>
 <a href="https://www.kringlecon.com">https://www.kringlecon.com</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6300" type="text/plain" language="en" />
<itunes:keywords>asus, gigabyte, apple, phishing, cecrypted, insanecrypt, everbe, kringlecon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 18th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6298</itunes:episode>
<itunes:subtitle>ZIPed Maldoc; Memes Covert Channel; Shamoon is Back
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ZIPed Maldoc; Memes Covert Channel; Shamoon is Back
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6298.mp3" length="4533707" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6298.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6298</link>
<pubDate>Tue, 18 Dec 2018 02:45:03 GMT</pubDate>
<description><![CDATA[Password Protected ZIP with Maldoc<br/>
 <a href="https://isc.sans.edu/forums/diary/Password+Protected+ZIP+with+Maldoc/24426/">https://isc.sans.edu/forums/diary/Password+Protected+ZIP+with+Maldoc/24426/</a><br/>
Memes Used as Covert Command and Control Channel<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/cybercriminals-use-malicious-memes-that-communicate-with-malware/">https://blog.trendmicro.com/trendlabs-security-intelligence/cybercriminals-use-malicious-memes-that-communicate-with-malware/</a><br/>
Shamoon Disk Whipper Malware is Back<br/>
 <a href="https://unit42.paloaltonetworks.com/shamoon-3-targets-oil-gas-organization/">https://unit42.paloaltonetworks.com/shamoon-3-targets-oil-gas-organization/</a><br/>
]]></description>
<itunes:duration>5:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6298" type="text/plain" language="en" />
<itunes:keywords>zipped, maldoc, password, meme, covert channel, shamoon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 17th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6296</itunes:episode>
<itunes:subtitle>Magellan Sqlite Vulnerability; Logitech Options Vuln; Intel NUC;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Magellan Sqlite Vulnerability; Logitech Options Vuln; Intel NUC;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6296.mp3" length="4176768" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6296.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6296</link>
<pubDate>Mon, 17 Dec 2018 04:55:02 GMT</pubDate>
<description><![CDATA[Magellan Sqlite Vulnerability<br/>
 <a href="https://blade.tencent.com/magellan/index_en.html">https://blade.tencent.com/magellan/index_en.html</a><br/>
Logitech Options Vulnerability<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1663">https://bugs.chromium.org/p/project-zero/issues/detail?id=1663</a><br/>
Intel NUC BIOS Protection Flaw<br/>
 <a href="https://embedi.org/blog/nuclear-explotion/">https://embedi.org/blog/nuclear-explotion/</a><br/>
HiddenTear Ransomware Decrypter<br/>
 <a href="https://www.bleepingcomputer.com/ransomware/decryptor/how-to-decrypt-hiddentear-ransomware-with-ht-brute-forcer/">https://www.bleepingcomputer.com/ransomware/decryptor/how-to-decrypt-hiddentear-ransomware-with-ht-brute-forcer/</a><br/>
]]></description>
<itunes:duration>4:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6296" type="text/plain" language="en" />
<itunes:keywords>magellan, sqlite, logitech, intel, nuc, bios, hiddentear, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 14th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6294</itunes:episode>
<itunes:subtitle>Fake E-Mail Bomb Threats; Phishing Via Non-Delivery Notices; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake E-Mail Bomb Threats; Phishing Via Non-Delivery Notices; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6294.mp3" length="5596836" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6294.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6294</link>
<pubDate>Fri, 14 Dec 2018 02:20:02 GMT</pubDate>
<description><![CDATA[Fake E-Mail Bomb Threats<br/>
 <a href="https://www.cnn.com/2018/12/13/us/email-bomb-threats/index.html">https://www.cnn.com/2018/12/13/us/email-bomb-threats/index.html</a><br/>
Phishing Via Non-Delivery Notices<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+Attack+Through+NonDelivery+Notification/24412/">https://isc.sans.edu/forums/diary/Phishing+Attack+Through+NonDelivery+Notification/24412/</a><br/>
LamePyre MacOS Malware<br/>
 <a href="https://blog.malwarebytes.com/detections/osx-lamepyre/">https://blog.malwarebytes.com/detections/osx-lamepyre/</a><br/>
]]></description>
<itunes:duration>6:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6294" type="text/plain" language="en" />
<itunes:keywords>phishing, bomb threats, non-delivery, outlook 365, lamepyre, macos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 13th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6292</itunes:episode>
<itunes:subtitle>DOSFuscation Leads to Emotet; OpenSSH Backdoors; Android Malware 2FA Bypass;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DOSFuscation Leads to Emotet; OpenSSH Backdoors; Android Malware 2FA Bypass;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6292.mp3" length="4142760" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6292.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6292</link>
<pubDate>Thu, 13 Dec 2018 01:20:02 GMT</pubDate>
<description><![CDATA[Yet Another DOSfuscation Sample<br/>
 <a href="https://isc.sans.edu/forums/diary/Yet+Another+DOSfuscation+Sample/24408/">https://isc.sans.edu/forums/diary/Yet+Another+DOSfuscation+Sample/24408/</a><br/>
OpenSSH Backdoors<br/>
 <a href="https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf">https://www.welivesecurity.com/wp-content/uploads/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf</a><br/>
Android Malware Bypasses 2FA For Paypal<br/>
 <a href="https://www.welivesecurity.com/2018/12/11/android-trojan-steals-money-paypal-accounts-2fa/">https://www.welivesecurity.com/2018/12/11/android-trojan-steals-money-paypal-accounts-2fa/</a><br/>
]]></description>
<itunes:duration>4:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6292" type="text/plain" language="en" />
<itunes:keywords>android, malware, 2fa, paypal, openssh, dosfuscation, word, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 12th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6290</itunes:episode>
<itunes:subtitle>#MSFT Patch Tuesday; #Adbode Patch; Certificate Authority DNS Spoofing Weakness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#MSFT Patch Tuesday; #Adbode Patch; Certificate Authority DNS Spoofing Weakness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6290.mp3" length="4648911" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6290.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6290</link>
<pubDate>Wed, 12 Dec 2018 00:55:02 GMT</pubDate>
<description><![CDATA[Microsoft December 2018 Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+December+2018+Patch+Tuesday/24404/">https://isc.sans.edu/forums/diary/Microsoft+December+2018+Patch+Tuesday/24404/</a><br/>
Adobe Patch Tuesday<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb18-41.html">https://helpx.adobe.com/security/products/acrobat/apsb18-41.html</a><br/>
Certificate Authority Weaknesses<br/>
 <a href="https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Heftrig-Off-Path-Attacks-Against-PKI.pdf">https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Heftrig-Off-Path-Attacks-Against-PKI.pdf</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6290" type="text/plain" language="en" />
<itunes:keywords>certificate authorities, CA, adobe, microsoft, dns, fragmentation, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 11th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6288</itunes:episode>
<itunes:subtitle>Kubernetes 2nd PoC; WebAssembly Creates Client Side Buffer Overflow; Etherum scans
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kubernetes 2nd PoC; WebAssembly Creates Client Side Buffer Overflow; Etherum scans
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6288.mp3" length="4847490" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6288.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6288</link>
<pubDate>Tue, 11 Dec 2018 03:50:02 GMT</pubDate>
<description><![CDATA[Kubernetes Unauthenticated PoC Exploit for CVE-2018-1002105<br/>
 <a href="https://github.com/evict/poc_CVE-2018-1002105#unauthenticated-poc">https://github.com/evict/poc_CVE-2018-1002105#unauthenticated-poc</a><br/>
WebAssembly Brings Buffer Overflows to Browsers<br/>
 <a href="https://www.forcepoint.com/blog/security-labs/new-whitepaper-memory-safety-old-vulnerabilities-become-new-webassembly">https://www.forcepoint.com/blog/security-labs/new-whitepaper-memory-safety-old-vulnerabilities-become-new-webassembly</a><br/>
Increased Ethereum Miner Attacks<br/>
 <a href="https://isc.sans.edu/port.html?port=8545">https://isc.sans.edu/port.html?port=8545</a><br/>
 <a href="https://www.zdnet.com/article/hackers-ramp-up-attacks-on-mining-rigs-before-ethereum-price-crashes-into-the-gutter">https://www.zdnet.com/article/hackers-ramp-up-attacks-on-mining-rigs-before-ethereum-price-crashes-into-the-gutter</a><br/>
Android Click Fraud Apps are Emulating iPhones for Higher Revenue<br/>
 <a href="https://www.bleepingcomputer.com/news/security/android-clickfraud-op-impersonates-iphones-to-bump-ad-premiums/">https://www.bleepingcomputer.com/news/security/android-clickfraud-op-impersonates-iphones-to-bump-ad-premiums/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6288" type="text/plain" language="en" />
<itunes:keywords>android, user-agent, iphone, click fraud, ethereum, json-rpc, api, miner, webassembly, buffer overflow, kubernetes, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 10th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6286</itunes:episode>
<itunes:subtitle>Analyzing Malicious Docker Images; Sextortion Ransomware; WebKit Exploit; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing Malicious Docker Images; Sextortion Ransomware; WebKit Exploit; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6286.mp3" length="4843830" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6286.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6286</link>
<pubDate>Mon, 10 Dec 2018 01:55:02 GMT</pubDate>
<description><![CDATA[Analyzing Malicious Docker Images<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Dive+into+malicious+Docker+Containers/24388/">https://isc.sans.edu/forums/diary/A+Dive+into+malicious+Docker+Containers/24388/</a><br/>
Arrest of Huawei CFO Inspires Advance Fee Scam<br/>
 <a href="https://isc.sans.edu/forums/diary/Arrest+of+Huawei+CFO+Inspires+Advance+Fee+Scam/24396/">https://isc.sans.edu/forums/diary/Arrest+of+Huawei+CFO+Inspires+Advance+Fee+Scam/24396/</a><br/>
Sextortion Messages Leading to Ransomware<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/sextortion-side-ransomware">https://www.proofpoint.com/us/threat-insight/post/sextortion-side-ransomware</a><br/>
WebKit Exploit Released<br/>
 <a href="https://github.com/LinusHenze/WebKit-RegEx-Exploit">https://github.com/LinusHenze/WebKit-RegEx-Exploit</a><br/>
Implants Found in Russian Banks<br/>
 <a href="https://securelist.com/darkvishnya/89169/">https://securelist.com/darkvishnya/89169/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6286" type="text/plain" language="en" />
<itunes:keywords>banks, webkit, exploit, safari, sextortion, ransomware, huawei, advance fee, docker, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 7th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6284</itunes:episode>
<itunes:subtitle>Adobe Vuln. PoC; WatchOS Update; Data Exfiltration; Marketing 2FA @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe Vuln. PoC; WatchOS Update; Data Exfiltration; Marketing 2FA @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6284.mp3" length="18114139" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6284.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6284</link>
<pubDate>Fri, 07 Dec 2018 00:45:03 GMT</pubDate>
<description><![CDATA[Adobe Vulnerability PoC Released<br/>
 <a href="https://isc.sans.edu/forums/diary/Is+it+Time+to+Uninstall+Flash+If+you+havent+already/24382/">https://isc.sans.edu/forums/diary/Is+it+Time+to+Uninstall+Flash+If+you+havent+already/24382/</a><br/>
WatchOS Update<br/>
 <a href="https://support.apple.com/en-us/HT209343">https://support.apple.com/en-us/HT209343</a><br/>
Data Exfiltration During Pentests<br/>
 <a href="https://isc.sans.edu/forums/diary/Data+Exfiltration+in+Penetration+Tests/24354/">https://isc.sans.edu/forums/diary/Data+Exfiltration+in+Penetration+Tests/24354/</a><br/>
PoC Exploit for Kubernetes Vulnerability<br/>
 <a href="https://github.com/evict/poc_CVE-2018-1002105">https://github.com/evict/poc_CVE-2018-1002105</a><br/>
Preston Ackerman: Marketing 2FA<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/authentication/swipe-tap-marketing-easier-2fa-increase-adoption-38695">https://www.sans.org/reading-room/whitepapers/authentication/swipe-tap-marketing-easier-2fa-increase-adoption-38695</a><br/>
]]></description>
<itunes:duration>21:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6284" type="text/plain" language="en" />
<itunes:keywords>2fa, sans_edu, ackerman, poc, kubernetes, exfiltration, pentesting, watchos, updates, adobe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 6th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6282</itunes:episode>
<itunes:subtitle>Flash Update; Apple Patches; 3-5G Network Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Flash Update; Apple Patches; 3-5G Network Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6282.mp3" length="4302577" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6282.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6282</link>
<pubDate>Thu, 06 Dec 2018 01:40:02 GMT</pubDate>
<description><![CDATA[Adobe Releases Emergency Flash Patch<br/>
 <a href="https://helpx.adobe.com/security/products/flash-player/apsb18-42.html">https://helpx.adobe.com/security/products/flash-player/apsb18-42.html</a><br/>
Apple Updates Everything (but not WatchOS)<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
New Privacy Issues Affecting 3G-5G protocols<br/>
 <a href="https://eprint.iacr.org/2018/1175">https://eprint.iacr.org/2018/1175</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6282" type="text/plain" language="en" />
<itunes:keywords>lte, 3g, 5g, sim, mobile, privacy, apple, ios, osx, macox, appletv, tvos, flash, adobe, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6280</itunes:episode>
<itunes:subtitle>Lokibot Update; Fake Ransomware Decrypt Service; Chrome 71 Released
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Lokibot Update; Fake Ransomware Decrypt Service; Chrome 71 Released
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6280.mp3" length="5412888" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6280.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6280</link>
<pubDate>Wed, 05 Dec 2018 00:00:03 GMT</pubDate>
<description><![CDATA[Fake Ransomware Decryption Service<br/>
 <a href="https://www.theregister.co.uk/2018/12/04/ransomware_helper_was_middleman_dr_shifro/">https://www.theregister.co.uk/2018/12/04/ransomware_helper_was_middleman_dr_shifro/</a><br/>
Latest Lokibot Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Lokibot+malware/24372/">https://isc.sans.edu/forums/diary/Malspam+pushing+Lokibot+malware/24372/</a><br/>
Chrome 71 Released<br/>
 <a href="https://www.bleepingcomputer.com/news/google/chrome-71-released-with-abusive-ad-filtering-and-audio-blocking/">https://www.bleepingcomputer.com/news/google/chrome-71-released-with-abusive-ad-filtering-and-audio-blocking/</a><br/>
RSA Followup Webcast<br/>
 <a href="https://www.rsaconference.com/videos/virtual-session-the-5-most-dangerous-new-attack-techniques-and-whats-to-come">https://www.rsaconference.com/videos/virtual-session-the-5-most-dangerous-new-attack-techniques-and-whats-to-come</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6280" type="text/plain" language="en" />
<itunes:keywords>RSA, Webcast, Chrome, lokibot, ransomware, marriott, spg, starwood, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 4th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6278</itunes:episode>
<itunes:subtitle>Hiding in Plain Doc; Kubernets Patch; US-Cert SamSam Alert; Tricky iOS App
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hiding in Plain Doc; Kubernets Patch; US-Cert SamSam Alert; Tricky iOS App
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6278.mp3" length="4127398" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6278.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6278</link>
<pubDate>Tue, 04 Dec 2018 01:10:02 GMT</pubDate>
<description><![CDATA[Word Maldoc: Yet Another Place to Hide a Command<br/>
 <a href="https://isc.sans.edu/forums/diary/Word+maldoc+yet+another+place+to+hide+a+command/24370/">https://isc.sans.edu/forums/diary/Word+maldoc+yet+another+place+to+hide+a+command/24370/</a><br/>
US-Cert Releases SamSam Alerts<br/>
 <a href="https://www.us-cert.gov/ncas/alerts/AA18-337A">https://www.us-cert.gov/ncas/alerts/AA18-337A</a><br/>
Kubernetes Patches<br/>
 <a href="https://groups.google.com/forum/#!topic/kubernetes-announce/GVllWCg6L88">https://groups.google.com/forum/#!topic/kubernetes-announce/GVllWCg6L88</a><br/>
Malicious iOS App Tricks User in Payment<br/>
 <a href="https://www.welivesecurity.com/2018/12/03/scam-ios-apps-promise-fitness-steal-money-instead/">https://www.welivesecurity.com/2018/12/03/scam-ios-apps-promise-fitness-steal-money-instead/</a><br/>
]]></description>
<itunes:duration>4:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6278" type="text/plain" language="en" />
<itunes:keywords>maldoc, word, oledump, us-cert, samsam, kubernetes, ios, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 3rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6276</itunes:episode>
<itunes:subtitle>KingMiner; Siglent Osciloscope Vuln; Autocad Malware;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
KingMiner; Siglent Osciloscope Vuln; Autocad Malware;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6276.mp3" length="5698139" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6276.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6276</link>
<pubDate>Mon, 03 Dec 2018 00:50:02 GMT</pubDate>
<description><![CDATA[KingMiner Improved Cryptomining<br/>
 <a href="https://research.checkpoint.com/kingminer-the-new-and-improved-cryptojacker/">https://research.checkpoint.com/kingminer-the-new-and-improved-cryptojacker/</a><br/>
Siglent Technologies Oscilloscope Vulnerabilities<br/>
 <a href="https://seclists.org/fulldisclosure/2018/Nov/68">https://seclists.org/fulldisclosure/2018/Nov/68</a><br/>
Autocad Malware<br/>
 <a href="https://www.forcepoint.com/blog/security-labs/autocad-malware-computer-aided-theft">https://www.forcepoint.com/blog/security-labs/autocad-malware-computer-aided-theft</a><br/>
ISC Stickers (login required. first 10 requests each day)<br/>
 <a href="https://isc.sans.edu/sticker.html">https://isc.sans.edu/sticker.html</a><br/>
]]></description>
<itunes:duration>6:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6276" type="text/plain" language="en" />
<itunes:keywords>autocad, kingminer, siglent, oscislloscope, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 30th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6274</itunes:episode>
<itunes:subtitle>Ancient Ransomware Family Still Active; Scamclub; Blocking Shodan @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ancient Ransomware Family Still Active; Scamclub; Blocking Shodan @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6274.mp3" length="11758756" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6274.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6274</link>
<pubDate>Fri, 30 Nov 2018 00:20:02 GMT</pubDate>
<description><![CDATA[Russian Language Malspam Pushing Shade (Troldesh) Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/Russian+language+malspam+pushing+Shade+Troldesh+ransomware/24358/">https://isc.sans.edu/forums/diary/Russian+language+malspam+pushing+Shade+Troldesh+ransomware/24358/</a><br/>
Scamclub Malvertising Against iOS Users<br/>
 <a href="https://blog.confiant.com/malvertising-attack-hijacks-300-million-sessions-over-48-hours-9d0218fe02cd">https://blog.confiant.com/malvertising-attack-hijacks-300-million-sessions-over-48-hours-9d0218fe02cd</a><br/>
Andre Shori: To Block Or Not To Block? Impact and Analysis of Actively Blocking Shodan Scans<br/>
 <a href="http://www.sans.org/reading-room/whitepapers/networksecurity/block-block-impact-analysis-actively-blocking-shodan-scans-38645">http://www.sans.org/reading-room/whitepapers/networksecurity/block-block-impact-analysis-actively-blocking-shodan-scans-38645</a><br/>
]]></description>
<itunes:duration>13:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6274" type="text/plain" language="en" />
<itunes:keywords>russian, troldesh, shade, ransomware, scamclub, malvertising, ios, andre shori, shodan, blocklist, sans_edu, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 29th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6272</itunes:episode>
<itunes:subtitle>Fake Flash Obfuscated Shell Script; Sennheiser Headsdown; MSFT Patches; 3ve Botnet
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake Flash Obfuscated Shell Script; Sennheiser Headsdown; MSFT Patches; 3ve Botnet
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6272.mp3" length="5323286" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6272.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6272</link>
<pubDate>Thu, 29 Nov 2018 02:25:02 GMT</pubDate>
<description><![CDATA[Obfuscated Shell Scripts: Fake MacOS Flash Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/More+obfuscated+shell+scripts+Fake+MacOS+Flash+update/24352/">https://isc.sans.edu/forums/diary/More+obfuscated+shell+scripts+Fake+MacOS+Flash+update/24352/</a><br/>
Sennheiser HeadSetup Certificate Authority Install<br/>
 <a href="https://www.secorvo.de/publikationen/headsetup-vulnerability-report-secorvo-2018.pdf">https://www.secorvo.de/publikationen/headsetup-vulnerability-report-secorvo-2018.pdf</a><br/>
Microsoft Fixes Shared Folder Permission Deletion Problem<br/>
 <a href="https://support.microsoft.com/en-us/help/4467684/windows-10-update-kb4467684">https://support.microsoft.com/en-us/help/4467684/windows-10-update-kb4467684</a><br/>
3ve Botnet Dismanteled <br/>
 <a href="https://services.google.com/fh/files/blogs/3ve_google_whiteops_whitepaper_final_nov_2018.pdf">https://services.google.com/fh/files/blogs/3ve_google_whiteops_whitepaper_final_nov_2018.pdf</a><br/>
]]></description>
<itunes:duration>6:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6272" type="text/plain" language="en" />
<itunes:keywords>3ve, eve, botnet, clickfraud, advertisement, microsoft, windows, sennheiser, headsetup, macos, flash, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 28th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6270</itunes:episode>
<itunes:subtitle>QNAP bash Malware; HTTPS Phishing Sites; Wildfire Scams; FTP Going Away
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
QNAP bash Malware; HTTPS Phishing Sites; Wildfire Scams; FTP Going Away
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6270.mp3" length="4548705" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6270.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6270</link>
<pubDate>Wed, 28 Nov 2018 01:50:02 GMT</pubDate>
<description><![CDATA[Obfuscated QNAP bash Malware;<br/>
 <a href="https://isc.sans.edu/forums/diary/Obfuscated+bash+script+targeting+QNap+boxes/24348/">https://isc.sans.edu/forums/diary/Obfuscated+bash+script+targeting+QNap+boxes/24348/</a><br/>
Half of All Phishing Sites Use HTTPS<br/>
 <a href="https://krebsonsecurity.com/2018/11/half-of-all-phishing-sites-now-have-the-padlock/">https://krebsonsecurity.com/2018/11/half-of-all-phishing-sites-now-have-the-padlock/</a><br/>
Chrome and Firefox to Remove FTP Support<br/>
 <a href="https://www.bleepingcomputer.com/news/google/chrome-and-firefox-developers-aim-to-remove-support-for-ftp/">https://www.bleepingcomputer.com/news/google/chrome-and-firefox-developers-aim-to-remove-support-for-ftp/</a><br/>
California Wildfire Used in BEC Scams<br/>
 <a href="https://www.agari.com/identity-intelligence-blog/california-wildfire-email-scams/">https://www.agari.com/identity-intelligence-blog/california-wildfire-email-scams/</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6270" type="text/plain" language="en" />
<itunes:keywords>wildfire, bec scam, ftp, chrome, firefox, https, phishing, qnap, bash, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6268</itunes:episode>
<itunes:subtitle>ViperMonkey; More Malicious NPM Libraries; BMC Lateral Movement;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ViperMonkey; More Malicious NPM Libraries; BMC Lateral Movement;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6268.mp3" length="5155421" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6268.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6268</link>
<pubDate>Tue, 27 Nov 2018 01:45:03 GMT</pubDate>
<description><![CDATA[ViperMonkey: VBA Maldoc Deobfuscation<br/>
 <a href="https://isc.sans.edu/forums/diary/ViperMonkey+VBA+maldoc+deobfuscation/24346/">https://isc.sans.edu/forums/diary/ViperMonkey+VBA+maldoc+deobfuscation/24346/</a><br/>
Malicious NPM Libraries <br/>
 <a href="https://medium.com/@cnorthwood/todays-javascript-trash-fire-and-pile-on-f3efcf8ac8c7">https://medium.com/@cnorthwood/todays-javascript-trash-fire-and-pile-on-f3efcf8ac8c7</a><br/>
Turning Your BMC Into A Revolving Door<br/>
 <a href="https://www.synacktiv.com/ressources/zeronights_2018_turning_your_bmc_into_a_revolving_door.pdf">https://www.synacktiv.com/ressources/zeronights_2018_turning_your_bmc_into_a_revolving_door.pdf</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6268" type="text/plain" language="en" />
<itunes:keywords>bmc, hp, ilo, npm, vipermonkey, vba, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6266</itunes:episode>
<itunes:subtitle>Attacks Against #Docker API; Mirai vs. Hadoop; #Rohammer for ECC
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Attacks Against #Docker API; Mirai vs. Hadoop; #Rohammer for ECC
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6266.mp3" length="4956470" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6266.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6266</link>
<pubDate>Mon, 26 Nov 2018 01:35:02 GMT</pubDate>
<description><![CDATA[Attacks Against Docker API<br/>
 <a href="https://isc.sans.edu/forums/diary/Moby+the+Shark/24340/">https://isc.sans.edu/forums/diary/Moby+the+Shark/24340/</a><br/>
Mirai Like Attack Hitting Hadoop<br/>
 <a href="https://asert.arbornetworks.com/mirai-not-just-for-iot-anymore/">https://asert.arbornetworks.com/mirai-not-just-for-iot-anymore/</a><br/>
New Rowhammer Variant Effects ECC Memory<br/>
 <a href="https://www.vusec.net/projects/eccploit/">https://www.vusec.net/projects/eccploit/</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6266" type="text/plain" language="en" />
<itunes:keywords>rowhammer, ecc, mirai, hadoop, docker, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 21st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6264</itunes:episode>
<itunes:subtitle>Critical Flash Update; Emotet Adds Thanksgiving Lure
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Critical Flash Update; Emotet Adds Thanksgiving Lure
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6264.mp3" length="2709528" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6264.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6264</link>
<pubDate>Wed, 21 Nov 2018 01:00:03 GMT</pubDate>
<description><![CDATA[Critical Flash Update<br/>
 <a href="https://helpx.adobe.com/security/products/flash-player/apsb18-44.html">https://helpx.adobe.com/security/products/flash-player/apsb18-44.html</a><br/>
Thanksgiving Lure for Emotet<br/>
 <a href="https://www.forcepoint.com/blog/security-labs/thanks-giving-emotet">https://www.forcepoint.com/blog/security-labs/thanks-giving-emotet</a><br/>
]]></description>
<itunes:duration>3:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6264" type="text/plain" language="en" />
<itunes:keywords>adobe, flash, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 20th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6262</itunes:episode>
<itunes:subtitle>Google Play Malware; ATM Vulnerabilities; Nagios XI Update</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Play Malware; ATM Vulnerabilities; Nagios XI Update</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6262.mp3" length="3981844" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6262.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6262</link>
<pubDate>Tue, 20 Nov 2018 00:45:04 GMT</pubDate>
<description><![CDATA[Google Play Malware<br/>
<a href="https://twitter.com/LukasStefanko">https://twitter.com/LukasStefanko</a><br/>
ATM Vulnerabilities<br/>
 <a href="https://www.ptsecurity.com/upload/corporate/ww-en/analytics/ATM-Vulnerabilities-2018-eng.pdf">https://www.ptsecurity.com/upload/corporate/ww-en/analytics/ATM-Vulnerabilities-2018-eng.pdf</a><br/>
Nagios XI Update<br/>
 <a href="https://www.tenable.com/security/research/tra-2018-37">https://www.tenable.com/security/research/tra-2018-37</a><br/>
]]></description>
<itunes:duration>4:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6262" type="text/plain" language="en" />
<itunes:keywords>nagios, atm, google play, eset, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 19th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6260</itunes:episode>
<itunes:subtitle>PCAP Analysis Tool; Lookyloo; Spoofing From in GMAIL
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PCAP Analysis Tool; Lookyloo; Spoofing From in GMAIL
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6260.mp3" length="4620013" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6260.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6260</link>
<pubDate>Sun, 18 Nov 2018 23:25:04 GMT</pubDate>
<description><![CDATA[Multipurpose PCAP Analysis Tool<br/>
 <a href="https://isc.sans.edu/forums/diary/Multipurpose+PCAP+Analysis+Tool/24322/">https://isc.sans.edu/forums/diary/Multipurpose+PCAP+Analysis+Tool/24322/</a><br/>
Quickly Investigating Websites with Lookyloo<br/>
 <a href="https://isc.sans.edu/forums/diary/Quickly+Investigating+Websites+with+Lookyloo/24320/">https://isc.sans.edu/forums/diary/Quickly+Investigating+Websites+with+Lookyloo/24320/</a><br/>
From Field Spoofing in GMail<br/>
 <a href="https://blog.cotten.io/hacking-gmail-with-weird-from-fields-d6494254722f?gi=ce61de4cb006">https://blog.cotten.io/hacking-gmail-with-weird-from-fields-d6494254722f?gi=ce61de4cb006</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6260" type="text/plain" language="en" />
<itunes:keywords>from header, email, gmail, spoofing, lookyloo, pcap analysis, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 16th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6258</itunes:episode>
<itunes:subtitle>Emotet Spreads IcedID; Miners Go Docker; GPS Watches; Firefox Breach Notification; Auditd @sans_edu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Spreads IcedID; Miners Go Docker; GPS Watches; Firefox Breach Notification; Auditd @sans_edu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6258.mp3" length="12595876" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6258.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6258</link>
<pubDate>Fri, 16 Nov 2018 00:55:03 GMT</pubDate>
<description><![CDATA[Emotet Spreading IcedID Banking Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Emotet+infection+with+IcedID+banking+Trojan/24312/">https://isc.sans.edu/forums/diary/Emotet+infection+with+IcedID+banking+Trojan/24312/</a><br/>
Crypto Miners Abusing Insecure Docker Installs<br/>
 <a href="https://forums.juniper.net/t5/Threat-Research/Container-Malware-Miners-Go-Docker-Hunting-In-The-Cloud/ba-p/400587">https://forums.juniper.net/t5/Threat-Research/Container-Malware-Miners-Go-Docker-Hunting-In-The-Cloud/ba-p/400587</a><br/>
GPS Watches Can Be Used To Track Kids<br/>
 <a href="https://www.pentestpartners.com/security-blog/tracking-and-snooping-on-a-million-kids/">https://www.pentestpartners.com/security-blog/tracking-and-snooping-on-a-million-kids/</a><br/>
Firefox Will Notify Users of Breached Sites<br/>
 <a href="https://blog.mozilla.org/blog/2018/11/14/firefox-monitor-launches-in-26-languages-and-adds-new-desktop-browser-feature/">https://blog.mozilla.org/blog/2018/11/14/firefox-monitor-launches-in-26-languages-and-adds-new-desktop-browser-feature/</a><br/>
David Kennel: All-Seeing Eye or Blind Man? Understanding the Linux Kernel Auditing System<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/linux/all-seeing-eye-blind-man-understanding-linux-kernel-auditing-system-38605">https://www.sans.org/reading-room/whitepapers/linux/all-seeing-eye-blind-man-understanding-linux-kernel-auditing-system-38605</a><br/>
]]></description>
<itunes:duration>14:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6258" type="text/plain" language="en" />
<itunes:keywords>emotet, icedid, banking malware, crypto miners, docker, gps, privacy, firefox, david kennel, auditd, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 15th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6256</itunes:episode>
<itunes:subtitle>Win32k Exploit Details (CVE-2018-8589); Pwn2OWn; More Spectre/Meltdown
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Win32k Exploit Details (CVE-2018-8589); Pwn2OWn; More Spectre/Meltdown
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6256.mp3" length="4893572" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6256.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6256</link>
<pubDate>Thu, 15 Nov 2018 01:35:02 GMT</pubDate>
<description><![CDATA[Details about Zero Day Exploit Taking Advantage of Win32k Vuln.<br/>
 <a href="https://securelist.com/a-new-exploit-for-zero-day-vulnerability-cve-2018-8589/88845/">https://securelist.com/a-new-exploit-for-zero-day-vulnerability-cve-2018-8589/88845/</a><br/>
PacSec Pwn2Own Results<br/>
 <a href="https://www.zerodayinitiative.com/blog/2018/11/13/pwn2own-tokyo-2018-day-one-results">https://www.zerodayinitiative.com/blog/2018/11/13/pwn2own-tokyo-2018-day-one-results</a><br/>
 <a href="https://www.zerodayinitiative.com/blog/2018/11/14/pwn2own-tokyo-2018-day-two-results-and-master-of-pwn">https://www.zerodayinitiative.com/blog/2018/11/14/pwn2own-tokyo-2018-day-two-results-and-master-of-pwn</a><br/>
More Spectre/Meltdown Flaws<br/>
 <a href="https://arxiv.org/pdf/1811.05441.pdf">https://arxiv.org/pdf/1811.05441.pdf</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6256" type="text/plain" language="en" />
<itunes:keywords>spectre, metdown, pwn2own, iphone, samsung, xiaomi, win32k, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 14th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6254</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6254.mp3" length="4298191" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6254.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6254</link>
<pubDate>Wed, 14 Nov 2018 00:10:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/November+2018+Microsoft+Patch+Tuesday/24308/">https://isc.sans.edu/forums/diary/November+2018+Microsoft+Patch+Tuesday/24308/</a><br/>
Adobe Security Bulletins<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6254" type="text/plain" language="en" />
<itunes:keywords>adobe, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 13th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6252</itunes:episode>
<itunes:subtitle>Google BPG Hijack via Russia; Bootable USB Microcode Loader; Wordpress GDPR Vuln.
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google BPG Hijack via Russia; Bootable USB Microcode Loader; Wordpress GDPR Vuln.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6252.mp3" length="4459832" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6252.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6252</link>
<pubDate>Tue, 13 Nov 2018 03:10:02 GMT</pubDate>
<description><![CDATA[Google BGP Hijack via Russia<br/>
 <a href="https://twitter.com/thousandeyes/status/1062102171506765825">https://twitter.com/thousandeyes/status/1062102171506765825</a><br/>
 <a href="https://www.wsj.com/articles/google-internet-traffic-is-briefly-misdirected-through-russia-china-1542068392">https://www.wsj.com/articles/google-internet-traffic-is-briefly-misdirected-through-russia-china-1542068392</a><br/>
Microcode Bootloader USB<br/>
 <a href="https://www.techpowerup.com/forums/threads/intel-microcode-boot-loader.248858/">https://www.techpowerup.com/forums/threads/intel-microcode-boot-loader.248858/</a><br/>
Wordpress GDPR Tool Vulnerable<br/>
 <a href="https://www.wordfence.com/blog/2018/11/trends-following-vulnerability-in-wp-gdpr-compliance-plugin/">https://www.wordfence.com/blog/2018/11/trends-following-vulnerability-in-wp-gdpr-compliance-plugin/</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6252" type="text/plain" language="en" />
<itunes:keywords>wordpress, gdpr, microcode, spectre, google, bpg, russia, china, nigeria, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 12th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6250</itunes:episode>
<itunes:subtitle>1.1.1.1 DNS For Mobile; CryotMiner Rootkits; Google Play Protect Success
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
1.1.1.1 DNS For Mobile; CryotMiner Rootkits; Google Play Protect Success
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6250.mp3" length="5451648" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6250.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6250</link>
<pubDate>Mon, 12 Nov 2018 00:55:02 GMT</pubDate>
<description><![CDATA[Cloudflare Releases Mobile Apps To Use 1.1.1.1<br/>
 <a href="https://blog.cloudflare.com/1-thing-you-can-do-to-make-your-internet-safer-and-faster/">https://blog.cloudflare.com/1-thing-you-can-do-to-make-your-internet-safer-and-faster/</a><br/>
Crypto Coin Miners Now With Rootkits<br/>
 <a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/cryptocurrency-mining-malware-targets-linux-systems-uses-rootkit-for-stealth">https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/cryptocurrency-mining-malware-targets-linux-systems-uses-rootkit-for-stealth</a><br/>
Google Play Protect Reduces Malware<br/>
 <a href="https://security.googleblog.com/2018/11/introducing-android-ecosystem-security.html">https://security.googleblog.com/2018/11/introducing-android-ecosystem-security.html</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6250" type="text/plain" language="en" />
<itunes:keywords>cloudflare, ios, android, cryot miners, rootkits, google, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6248</itunes:episode>
<itunes:subtitle>Cisco Updates; Ruby Deserialization; Ouch Newsletter; Blockchain Botnets @sans_edu 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco Updates; Ruby Deserialization; Ouch Newsletter; Blockchain Botnets @sans_edu 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6248.mp3" length="14437248" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6248.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6248</link>
<pubDate>Fri, 09 Nov 2018 01:55:03 GMT</pubDate>
<description><![CDATA[Cisco Security Bulletins<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Ruby Deserialization<br/>
 <a href="https://www.elttam.com.au/blog/ruby-deserialization/">https://www.elttam.com.au/blog/ruby-deserialization/</a><br/>
Ouch Newsletter: Am I Hacked?<br/>
 <a href="https://www.sans.org/security-awareness-training/resources/am-i-hacked">https://www.sans.org/security-awareness-training/resources/am-i-hacked</a><br/>
Jonathan Sweeny: Smart Contract Botnets<br/>
  <a href="https://www.sans.org/reading-room/whitepapers/covert/botnet-resiliency-private-blockchains-38050">https://www.sans.org/reading-room/whitepapers/covert/botnet-resiliency-private-blockchains-38050</a><br/>
  <a href="https://www.sans.org/reading-room/whitepapers/warfare/tearing-smart-contract-botnets-38650">https://www.sans.org/reading-room/whitepapers/warfare/tearing-smart-contract-botnets-38650</a><br/>
]]></description>
<itunes:duration>17:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6248" type="text/plain" language="en" />
<itunes:keywords>botnets, ethereum, jonathan sweeny, ouch, ruby, deserialization, cisco, struts, dirty cow, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 8th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6246</itunes:episode>
<itunes:subtitle>VirtualBox 0 Day; WooCommerce RCE #wordpress; Bing Notepad2 Malware; @Bsidesjax
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VirtualBox 0 Day; WooCommerce RCE #wordpress; Bing Notepad2 Malware; @Bsidesjax
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6246.mp3" length="5631583" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6246.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6246</link>
<pubDate>Thu, 08 Nov 2018 01:25:02 GMT</pubDate>
<description><![CDATA[VirtualBox 0 Day Guest Escape Exploit Released <br/>
 <a href="https://github.com/MorteNoir1/virtualbox_e1000_0day">https://github.com/MorteNoir1/virtualbox_e1000_0day</a><br/>
WooCommerce / Wordpress Bug Leads to RCE<br/>
 <a href="https://blog.ripstech.com/2018/wordpress-design-flaw-leads-to-woocommerce-rce/">https://blog.ripstech.com/2018/wordpress-design-flaw-leads-to-woocommerce-rce/</a><br/>
Bing Advertises Fake Version of Notepad2<br/>
 <a href="https://www.bleepingcomputer.com/news/security/beware-of-unofficial-sites-pushing-notepad2-adware-bundles/">https://www.bleepingcomputer.com/news/security/beware-of-unofficial-sites-pushing-notepad2-adware-bundles/</a><br/>
Jacksonville BSides<br/>
 <a href="https://bsidesjax.org">https://bsidesjax.org</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6246" type="text/plain" language="en" />
<itunes:keywords>bsides, bsidesjax, bing, notepad2, wordpress, woocommerce, virtualbox, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 7th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6244</itunes:episode>
<itunes:subtitle>Chinese Routing Leak; Android Update; Facetime PoC; U-Boot Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Chinese Routing Leak; Android Update; Facetime PoC; U-Boot Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6244.mp3" length="4913322" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6244.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6244</link>
<pubDate>Wed, 07 Nov 2018 00:25:02 GMT</pubDate>
<description><![CDATA[China Telecom's Internet Traffic Misdirection<br/>
 <a href="https://internetintel.oracle.com/blog-single.html?id=China+Telecom%27s+Internet+Traffic+Misdirection">https://internetintel.oracle.com/blog-single.html?id=China+Telecom%27s+Internet+Traffic+Misdirection</a><br/>
Android Security Updates; Last for Nexus<br/>
 <a href="https://source.android.com/security/bulletin/2018-11-01#framework">https://source.android.com/security/bulletin/2018-11-01#framework</a><br/>
PoC Facetime Exploit<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1641">https://bugs.chromium.org/p/project-zero/issues/detail?id=1641</a><br/>
Vulnerability in U-Boot Bootloader<br/>
 <a href="https://github.com/inversepath/usbarmory/blob/master/software/secure_boot/Security_Advisory-Ref_IPVR2018-0001.txt">https://github.com/inversepath/usbarmory/blob/master/software/secure_boot/Security_Advisory-Ref_IPVR2018-0001.txt</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6244" type="text/plain" language="en" />
<itunes:keywords>china telecom, bgp, android, nexus, facetime, uboot, u-boot, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 6th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6242</itunes:episode>
<itunes:subtitle>Struts 2.3 RCE; Fake Elon Musk Site Steals BTC; Bypassing SSD Encryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Struts 2.3 RCE; Fake Elon Musk Site Steals BTC; Bypassing SSD Encryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6242.mp3" length="4882598" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6242.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6242</link>
<pubDate>Tue, 06 Nov 2018 01:55:02 GMT</pubDate>
<description><![CDATA[Struts 2.3 Uses Outdated commons-fileupload library <br/>
 <a href="https://isc.sans.edu/forums/diary/Struts+23+Vulnerable+to+Two+Year+old+File+Upload+Flaw/24278/">https://isc.sans.edu/forums/diary/Struts+23+Vulnerable+to+Two+Year+old+File+Upload+Flaw/24278/</a><br/>
Fake Elon Musk Tweet used to steal Bitcoin<br/>
 <a href="https://www.bleepingcomputer.com/news/security/fake-elon-musk-twitter-bitcoin-scam-earned-180k-in-one-day/">https://www.bleepingcomputer.com/news/security/fake-elon-musk-twitter-bitcoin-scam-earned-180k-in-one-day/</a><br/>
Bypassing SSD Drive Hardware Encryption<br/>
 <a href="https://www.ru.nl/english/news-agenda/news/vm/icis/cyber-security/2018/radboud-university-researchers-discover-security/">https://www.ru.nl/english/news-agenda/news/vm/icis/cyber-security/2018/radboud-university-researchers-discover-security/</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6242" type="text/plain" language="en" />
<itunes:keywords>ssd, encryption, elon musk, bitcoin, struts, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6240</itunes:episode>
<itunes:subtitle>MacOS IR Beyond LaunchAgents; Dissecting CVE-2017-11882 Exploit; Portsmash, Edge Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS IR Beyond LaunchAgents; Dissecting CVE-2017-11882 Exploit; Portsmash, Edge Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6240.mp3" length="4470802" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6240.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6240</link>
<pubDate>Mon, 05 Nov 2018 00:40:02 GMT</pubDate>
<description><![CDATA[Beyond good ol' LaunchAgents<br/>
 <a href="https://isc.sans.edu/forums/diary/Beyond+good+ol+LaunchAgent+part+1/24274/">https://isc.sans.edu/forums/diary/Beyond+good+ol+LaunchAgent+part+1/24274/</a><br/>
Dissecting a CVE-2017-11882 Exploit<br/>
 <a href="https://isc.sans.edu/forums/diary/Dissecting+a+CVE201711882+Exploit/24272/">https://isc.sans.edu/forums/diary/Dissecting+a+CVE201711882+Exploit/24272/</a><br/>
Microsoft Edge Exploit About to Be Released<br/>
 <a href="https://twitter.com/Yux1xi">https://twitter.com/Yux1xi</a><br/>
Portsmash Vulnerability<br/>
 <a href="https://github.com/bbbrumley/portsmash">https://github.com/bbbrumley/portsmash</a><br/>
RC4 (Arcfour) Depreciation in SSH<br/>
 <a href="https://tools.ietf.org/html/draft-ietf-curdle-rc4-die-die-die-12">https://tools.ietf.org/html/draft-ietf-curdle-rc4-die-die-die-12</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6240" type="text/plain" language="en" />
<itunes:keywords>rc4, ssh, portshmash, intel, cpu, SMT, microsoft, edge, equation editor, launchagents, macos, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6238</itunes:episode>
<itunes:subtitle>Windows Defender Sandboxing Bug; BLE Vulnerability;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Defender Sandboxing Bug; BLE Vulnerability;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6238.mp3" length="4621476" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6238.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6238</link>
<pubDate>Thu, 01 Nov 2018 23:45:03 GMT</pubDate>
<description><![CDATA[Windows Defender Sandboxing Bug<br/>
 <a href="https://isc.sans.edu/forums/diary/Windows+Defenders+Sandbox/24266/">https://isc.sans.edu/forums/diary/Windows+Defenders+Sandbox/24266/</a><br/>
Bleedingbit Bluetooth Low Energy Vulnerability<br/>
 <a href="https://armis.com/bleedingbit/">https://armis.com/bleedingbit/</a><br/>
Cisco ASA/Firepower DoS Vulnerability Actively Exploited<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6238" type="text/plain" language="en" />
<itunes:keywords>cisco, bleedingbit, bluetooth, ble, meraki, windows, defender, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 1st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6236</itunes:episode>
<itunes:subtitle>Encrypted Word Maldocs; iOS/macOS ICMP Error RCE; iOS lock bypass;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encrypted Word Maldocs; iOS/macOS ICMP Error RCE; iOS lock bypass;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6236.mp3" length="4481777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6236.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6236</link>
<pubDate>Thu, 01 Nov 2018 00:45:03 GMT</pubDate>
<description><![CDATA[Encrypted Word Maldocs<br/>
 <a href="https://isc.sans.edu/forums/diary/More+malspam+using+passwordprotected+Word+docs/24262/">https://isc.sans.edu/forums/diary/More+malspam+using+passwordprotected+Word+docs/24262/</a><br/>
iOS / MacOS ICMP Error Remote Code Execution<br/>
 <a href="https://lgtm.com/blog/apple_xnu_icmp_error_CVE-2018-4407">https://lgtm.com/blog/apple_xnu_icmp_error_CVE-2018-4407</a><br/>
iOS Lock Screen Bypass<br/>
 <a href="https://www.youtube.com/watch?v=ojigFgwrtKs">https://www.youtube.com/watch?v=ojigFgwrtKs</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6236" type="text/plain" language="en" />
<itunes:keywords>ios, macos, os x, high sierra, sierra, mojave, icmp, rce, malspam, encrypted, word, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 31st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6234</itunes:episode>
<itunes:subtitle>Hancitor Update; Apple Updates; Telegram Clear Text Messages
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hancitor Update; Apple Updates; Telegram Clear Text Messages
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6234.mp3" length="3878714" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6234.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6234</link>
<pubDate>Wed, 31 Oct 2018 00:25:02 GMT</pubDate>
<description><![CDATA[Change in Strategy for Hancitor Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Campaign+evolution+Hancitor+malspam+starts+pushing+Ursnif+this+week/24256/">https://isc.sans.edu/forums/diary/Campaign+evolution+Hancitor+malspam+starts+pushing+Ursnif+this+week/24256/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Telegram Stores Conversations Locally<br/>
 <a href="https://twitter.com/nathanielrsuchy">https://twitter.com/nathanielrsuchy</a><br/>
]]></description>
<itunes:duration>4:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6234" type="text/plain" language="en" />
<itunes:keywords>telegram, apple, hancitor, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 30th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6232</itunes:episode>
<itunes:subtitle>PowerShell Cloning Maldoc; Unusual Malicious File Types; Crypto Tracker Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PowerShell Cloning Maldoc; Unusual Malicious File Types; Crypto Tracker Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6232.mp3" length="5092882" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6232.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6232</link>
<pubDate>Tue, 30 Oct 2018 02:40:02 GMT</pubDate>
<description><![CDATA[Maldoc Duplicating PowerShell<br/>
<a href="https://isc.sans.edu/forums/diary/Maldoc+Duplicating+PowerShell+Prior+to+Use/24254/">https://isc.sans.edu/forums/diary/Maldoc+Duplicating+PowerShell+Prior+to+Use/24254/</a><br/>
New File Types Emerge in Malware Spam Attachments<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/same-old-yet-brand-new-new-file-types-emerge-in-malware-spam-attachments/">https://blog.trendmicro.com/trendlabs-security-intelligence/same-old-yet-brand-new-new-file-types-emerge-in-malware-spam-attachments/</a><br/>
Malicious Mac Crypto Currency Tracker Installs Backdoor<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2018/10/mac-cryptocurrency-ticker-app-installs-backdoors/">https://blog.malwarebytes.com/threat-analysis/2018/10/mac-cryptocurrency-ticker-app-installs-backdoors/</a><br/>
Sandbox For Windows Defender<br/>
 <a href="https://cloudblogs.microsoft.com/microsoftsecure/2018/10/26/windows-defender-antivirus-can-now-run-in-a-sandbox/">https://cloudblogs.microsoft.com/microsoftsecure/2018/10/26/windows-defender-antivirus-can-now-run-in-a-sandbox/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6232" type="text/plain" language="en" />
<itunes:keywords>sandbox, windows defender, crypto tracker, backdoor, mac, malspam, powershell, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 29th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6230</itunes:episode>
<itunes:subtitle>Office Docs and Linux; Anaylzing Crompressed RTF; DHCPv6 systemd; Docker; Hadoop
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Office Docs and Linux; Anaylzing Crompressed RTF; DHCPv6 systemd; Docker; Hadoop
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6230.mp3" length="4147143" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6230.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6230</link>
<pubDate>Mon, 29 Oct 2018 01:35:02 GMT</pubDate>
<description><![CDATA[Dissecting Malicious Office Documents in Linux<br/>
 <a href="https://isc.sans.edu/forums/diary/Dissecting+Malicious+Office+Documents+with+Linux/24248/">https://isc.sans.edu/forums/diary/Dissecting+Malicious+Office+Documents+with+Linux/24248/</a><br/>
Analyzing Compressed RTF Documents<br/>
 <a href="https://isc.sans.edu/forums/diary/Detecting+Compressed+RTF/24250/">https://isc.sans.edu/forums/diary/Detecting+Compressed+RTF/24250/</a><br/>
SystemD DHCPv6 Remote Code Executing Vulnerability<br/>
 <a href="https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-15688">https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-15688</a><br/>
Cryptominers Scan for Docker Engine<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/misconfigured-container-abused-to-deliver-cryptocurrency-mining-malware">https://blog.trendmicro.com/trendlabs-security-intelligence/misconfigured-container-abused-to-deliver-cryptocurrency-mining-malware</a><br/>
DemonBot Targeting Hadoop<br/>
 <a href="https://blog.radware.com/security/2018/10/new-demonbot-discovered/">https://blog.radware.com/security/2018/10/new-demonbot-discovered/</a><br/>
]]></description>
<itunes:duration>4:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6230" type="text/plain" language="en" />
<itunes:keywords>demonbot, hadoop, radware, cryptominers, docker, systemd, dhcpv6, RTF, office, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6228</itunes:episode>
<itunes:subtitle>Scam Calls Targeting Chinese; X.org Priv. Elevation Flaw; MS Office Videos
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Scam Calls Targeting Chinese; X.org Priv. Elevation Flaw; MS Office Videos
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6228.mp3" length="4403508" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6228.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6228</link>
<pubDate>Fri, 26 Oct 2018 02:30:03 GMT</pubDate>
<description><![CDATA[Scam Calls Targeting Chinese Living in the US<br/>
 <a href="https://isc.sans.edu/forums/diary/Fake+BankPost+Office+Phone+Calls+Targeting+Chinese+Immigrants/24244/">https://isc.sans.edu/forums/diary/Fake+BankPost+Office+Phone+Calls+Targeting+Chinese+Immigrants/24244/</a><br/>
X.org Privilege Elevation Flaw<br/>
 <a href="https://lists.x.org/archives/xorg-announce/2018-October/002927.html">https://lists.x.org/archives/xorg-announce/2018-October/002927.html</a><br/>
Remote Videos in Office Documents<br/>
 <a href="https://blog.cymulate.com/abusing-microsoft-office-online-video">https://blog.cymulate.com/abusing-microsoft-office-online-video</a><br/>
Mac Malware Injects Ads<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/">https://blog.malwarebytes.com/threat-analysis/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection/</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6228" type="text/plain" language="en" />
<itunes:keywords>mac, malware, adware, videos, office, x.org, chinese, scam, phone, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 25th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6226</itunes:episode>
<itunes:subtitle>Reversing AutoIT; Arcserve Vulnerabilities; WebEx Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing AutoIT; Arcserve Vulnerabilities; WebEx Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6226.mp3" length="4549067" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6226.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6226</link>
<pubDate>Thu, 25 Oct 2018 02:55:03 GMT</pubDate>
<description><![CDATA[Reversing AutoIT<br/>
 <a href="https://isc.sans.edu/forums/diary/Diving+into+Malicious+AutoIT+Code/24238/">https://isc.sans.edu/forums/diary/Diving+into+Malicious+AutoIT+Code/24238/</a><br/>
Arcserve Vulnerabilities<br/>
 <a href="https://www.digitaldefense.com/blog/zero-day-alerts/arcserve-disclosure/">https://www.digitaldefense.com/blog/zero-day-alerts/arcserve-disclosure/</a><br/>
WebExec Vulnerability<br/>
 <a href="https://webexec.org/">https://webexec.org/</a><br/>
More ALPC Flaws from Sandbox Escaper<br/>
 <a href="https://twitter.com/SandboxEscaper/status/1054744201244692485">https://twitter.com/SandboxEscaper/status/1054744201244692485</a><br/>
 <a href="https://twitter.com/mkolsek/status/1054794984908562432">https://twitter.com/mkolsek/status/1054794984908562432</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6226" type="text/plain" language="en" />
<itunes:keywords>ALPC, sandboxescaper, webexec, arcserve, autoit, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 24th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6224</itunes:episode>
<itunes:subtitle>Malware Uses Decoy Picture; DoH Push Back; Signal Encryption Bug; Firefox 63
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Uses Decoy Picture; DoH Push Back; Signal Encryption Bug; Firefox 63
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6224.mp3" length="5001457" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6224.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6224</link>
<pubDate>Wed, 24 Oct 2018 02:35:01 GMT</pubDate>
<description><![CDATA[Malware Uses Decoy Picture<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Powershell+using+a+Decoy+Picture/24234/">https://isc.sans.edu/forums/diary/Malicious+Powershell+using+a+Decoy+Picture/24234/</a><br/>
DNS over HTTPS Pushback<br/>
 <a href="https://twitter.com/paulvixie/status/1053765281917661184">https://twitter.com/paulvixie/status/1053765281917661184</a><br/>
Signal Desktop Leaves Encryption Key Exposed<br/>
 <a href="https://twitter.com/nathanielrsuchy">https://twitter.com/nathanielrsuchy</a><br/>
Firefox 63 Allows Less Tracking<br/>
 <a href="https://blog.mozilla.org/security/2018/10/23/firefox-63-lets-users-block-tracking-cookies/">https://blog.mozilla.org/security/2018/10/23/firefox-63-lets-users-block-tracking-cookies/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6224" type="text/plain" language="en" />
<itunes:keywords>powershell, pictures, decoy, dns over https, doh, dot, signal, encryption, firefox, vpn, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 23rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6222</itunes:episode>
<itunes:subtitle>Compressed RTF in MSG File; FreeRTOS TCP/IP Vuln; VLC Vulns; Yammer Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Compressed RTF in MSG File; FreeRTOS TCP/IP Vuln; VLC Vulns; Yammer Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6222.mp3" length="4462390" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6222.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6222</link>
<pubDate>Tue, 23 Oct 2018 01:00:04 GMT</pubDate>
<description><![CDATA[MSG Files: Compressed RTF<br/>
 <a href="https://isc.sans.edu/forums/diary/MSG+Files+Compressed+RTF/24228/">https://isc.sans.edu/forums/diary/MSG+Files+Compressed+RTF/24228/</a><br/>
FreeRTOS TCP/IP Stack Vulnerabilities<br/>
 <a href="https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/">https://blog.zimperium.com/freertos-tcpip-stack-vulnerabilities-put-wide-range-devices-risk-compromise-smart-homes-critical-infrastructure-systems/</a><br/>
VLC/Live555 RTSP Server Vulnerability<br/>
 <a href="https://www.talosintelligence.com/reports/TALOS-2018-0684">https://www.talosintelligence.com/reports/TALOS-2018-0684</a><br/>
Microsoft Yammer Update<br/>
 <a href="https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-8569#ID0EGB">https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-8569#ID0EGB</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6222" type="text/plain" language="en" />
<itunes:keywords>yammer, live555, vlc, mplayer, freertos, msg, rtf, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 22nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6220</itunes:episode>
<itunes:subtitle>MacOS LaunchAgent; TLS Sessions; jQuery File Upload Plugin; Drupal
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS LaunchAgent; TLS Sessions; jQuery File Upload Plugin; Drupal
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6220.mp3" length="4240766" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6220.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6220</link>
<pubDate>Mon, 22 Oct 2018 02:20:02 GMT</pubDate>
<description><![CDATA[MacOS LaunchAgent<br/>
 <a href="https://isc.sans.edu/forums/diary/Beyond+good+ol+LaunchAgent+part+0/24230/">https://isc.sans.edu/forums/diary/Beyond+good+ol+LaunchAgent+part+0/24230/</a><br/>
TLS Session Tracking<br/>
 <a href="https://arxiv.org/pdf/1810.07304.pdf">https://arxiv.org/pdf/1810.07304.pdf</a><br/>
jQuery File Upload Plugin<br/>
 <a href="https://blogs.akamai.com/sitr/2018/10/having-the-security-rug-pulled-out-from-under-you.html">https://blogs.akamai.com/sitr/2018/10/having-the-security-rug-pulled-out-from-under-you.html</a><br/>
Drupal Update<br/>
 <a href="https://www.drupal.org/sa-core-2018-006">https://www.drupal.org/sa-core-2018-006</a><br/>
]]></description>
<itunes:duration>5:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6220" type="text/plain" language="en" />
<itunes:keywords>drupal, tls, tracking, jquery, macos, launchagent, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 19th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6218</itunes:episode>
<itunes:subtitle>Cisco Patches; 51% Crypto Currency Attack; VMWare Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco Patches; 51% Crypto Currency Attack; VMWare Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6218.mp3" length="3751074" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6218.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6218</link>
<pubDate>Fri, 19 Oct 2018 00:40:03 GMT</pubDate>
<description><![CDATA[Cisco Patches<br/>
 <a href="https://tools.cisco.com/security/center/Search.x?publicationTypeIDs=1&firstPublishedStartDate=2018%2F10%2F17&firstPublishedEndDate=2018%2F10%2F17&lastPublishedStartDate=2018%2F10%2F17&lastPublishedEndDate=2018%2F10%2F17">https://tools.cisco.com/security/center/Search.x?publicationTypeIDs=1&firstPublishedStartDate=2018%2F10%2F17&firstPublishedEndDate=2018%2F10%2F17&lastPublishedStartDate=2018%2F10%2F17&lastPublishedEndDate=2018%2F10%2F17</a><br/>
51% Attack Against Crypto Currencies<br/>
 <a href="https://old.reddit.com/r/CryptoCurrency/comments/9m1uuj/if_i_livestreamed_the_setup_and_execution_of/">https://old.reddit.com/r/CryptoCurrency/comments/9m1uuj/if_i_livestreamed_the_setup_and_execution_of/</a><br/>
VMWare Patch<br/>
 <a href="https://www.vmware.com/au/security/advisories/VMSA-2018-0026.html">https://www.vmware.com/au/security/advisories/VMSA-2018-0026.html</a><br/>
]]></description>
<itunes:duration>4:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6218" type="text/plain" language="en" />
<itunes:keywords>vmware, crypto coins, 51%, btcp, cisco, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 18th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6216</itunes:episode>
<itunes:subtitle>NewShareCount Abuse; D-Link Vulns; RID Hacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NewShareCount Abuse; D-Link Vulns; RID Hacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6216.mp3" length="4522004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6216.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6216</link>
<pubDate>Thu, 18 Oct 2018 01:20:02 GMT</pubDate>
<description><![CDATA[Abandoned "NewShareCount" Twitter Counter abused<br/>
 <a href="https://blog.sucuri.net/2018/10/malicious-redirects-from-newsharecounts-com-tweet-counter.html">https://blog.sucuri.net/2018/10/malicious-redirects-from-newsharecounts-com-tweet-counter.html</a><br/>
Multiple D-Link Vulnerabilities<br/>
 <a href="https://seclists.org/fulldisclosure/2018/Oct/36">https://seclists.org/fulldisclosure/2018/Oct/36</a><br/>
RID Hacking in Windows<br/>
 <a href="https://www.romhack.io/slides/RomHack%202018%20-%20Sebastian%20Castro%20-%20Windows%20RID%20Hijacking:%20Maintaining%20Access%20on%20Windows%20Machines.pdf">https://www.romhack.io/slides/RomHack%202018%20-%20Sebastian%20Castro%20-%20Windows%20RID%20Hijacking:%20Maintaining%20Access%20on%20Windows%20Machines.pdf</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6216" type="text/plain" language="en" />
<itunes:keywords>rid, windows, d-link, newsharecount, twitter, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 17th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6214</itunes:episode>
<itunes:subtitle>Oracle CPU; libssh vulnerability; Vending Machine Mobile App; TLS1.0/1.1
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oracle CPU; libssh vulnerability; Vending Machine Mobile App; TLS1.0/1.1
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6214.mp3" length="4811652" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6214.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6214</link>
<pubDate>Wed, 17 Oct 2018 01:30:02 GMT</pubDate>
<description><![CDATA[Oracle CPU<br/>
 <a href="https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html">https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html</a><br/>
libssh vulnerability<br/>
 <a href="https://www.libssh.org/security/advisories/CVE-2018-10933.txt">https://www.libssh.org/security/advisories/CVE-2018-10933.txt</a><br/>
Vending Machine Mobile App Compromise<br/>
 <a href="https://hackernoon.com/how-i-hacked-modern-vending-machines-43f4ae8decec">https://hackernoon.com/how-i-hacked-modern-vending-machines-43f4ae8decec</a><br/>
Browsers Announce Timeline to Discontinue TLS1.0/1.1 support<br/>
 <a href="https://blogs.windows.com/msedgedev/2018/10/15/modernizing-tls-edge-ie11/">https://blogs.windows.com/msedgedev/2018/10/15/modernizing-tls-edge-ie11/</a> <br/>
 <a href="https://security.googleblog.com/2018/10/modernizing-transport-security.html">https://security.googleblog.com/2018/10/modernizing-transport-security.html</a><br/>
 <a href="https://blog.mozilla.org/security/2018/10/15/removing-old-versions-of-tls/">https://blog.mozilla.org/security/2018/10/15/removing-old-versions-of-tls/</a><br/>
 <a href="https://webkit.org/blog/8462/deprecation-of-legacy-tls-1-0-and-1-1-versions/">https://webkit.org/blog/8462/deprecation-of-legacy-tls-1-0-and-1-1-versions/</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6214" type="text/plain" language="en" />
<itunes:keywords>oracle, cpu, libssh, vending machine, tls, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 16th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6212</itunes:episode>
<itunes:subtitle>CVE-2018-8495 PoE Exploit; Fake Mining Appsi; Fake Google Photo App
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2018-8495 PoE Exploit; Fake Mining Appsi; Fake Google Photo App
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6212.mp3" length="4694253" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6212.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6212</link>
<pubDate>Tue, 16 Oct 2018 02:25:03 GMT</pubDate>
<description><![CDATA[Proof Of Concept Exploit for Microsoft Edge Vulnerability CVE-2018-8495<br/>
 <a href="https://leucosite.com/Microsoft-Edge-RCE/">https://leucosite.com/Microsoft-Edge-RCE/</a><br/>
Fake Mining Apps<br/>
 <a href="https://www.fortinet.com/blog/threat-research/fortinet-discovers-new-android-apps-that-mine-the-unminable.html">https://www.fortinet.com/blog/threat-research/fortinet-discovers-new-android-apps-that-mine-the-unminable.html</a><br/>
Fake Google Photo App Turns out to be Ad-Clicker<br/>
 <a href="https://www.geeklatest.com/developer-tricks-microsoft-publishes-app-under-google-llc-name-in-windows-store/">https://www.geeklatest.com/developer-tricks-microsoft-publishes-app-under-google-llc-name-in-windows-store/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6212" type="text/plain" language="en" />
<itunes:keywords>google, poto app, windows store, mining, php, edge, vulnerability, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 15th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6210</itunes:episode>
<itunes:subtitle>Branch.io Bug Affects Millions; Medtronics; WebLogic; MSFT JET Database
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Branch.io Bug Affects Millions; Medtronics; WebLogic; MSFT JET Database
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6210.mp3" length="5294023" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6210.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6210</link>
<pubDate>Mon, 15 Oct 2018 00:30:02 GMT</pubDate>
<description><![CDATA[Many Large Websites Affected by Branch.io XSS Flaw<br/>
 <a href="https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/">https://www.vpnmentor.com/blog/dom-xss-bug-affecting-tinder-shopify-yelp/</a><br/>
Medtronics Pacemakers Disable Remote Update<br/>
 <a href="https://www.medtronic.com/content/dam/medtronic-com/us-en/corporate/documents/REV-Medtronic-2090-Security-Bulletin_FNL.pdf">https://www.medtronic.com/content/dam/medtronic-com/us-en/corporate/documents/REV-Medtronic-2090-Security-Bulletin_FNL.pdf</a><br/>
IBM Updates WebSphere Update<br/>
 <a href="https://www-01.ibm.com/support/docview.wss?uid=swg22016254">https://www-01.ibm.com/support/docview.wss?uid=swg22016254</a><br/>
Incomplete JET Database Patch<br/>
 <a href="https://blog.0patch.com/2018/10/patching-re-patching-and-meta-patching.html">https://blog.0patch.com/2018/10/patching-re-patching-and-meta-patching.html</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6210" type="text/plain" language="en" />
<itunes:keywords>branch.io, xss, tinder, medtronics, ibm, weblogic, deserialization, java, jet, microsoft, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 12th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6208</itunes:episode>
<itunes:subtitle>Equation Editor is Back;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Equation Editor is Back;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6208.mp3" length="4931600" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6208.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6208</link>
<pubDate>Thu, 11 Oct 2018 23:50:02 GMT</pubDate>
<description><![CDATA[New Campaign Using Old Equation Editor Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Campaign+Using+Old+Equation+Editor+Vulnerability/24196/">https://isc.sans.edu/forums/diary/New+Campaign+Using+Old+Equation+Editor+Vulnerability/24196/</a><br/>
Root Access Vulnerability in SONY Smart TVs<br/>
 <a href="https://www.fortinet.com/blog/threat-research/sony-smart-tv-exploit-inside-view-hijacking-your-living-room.html">https://www.fortinet.com/blog/threat-research/sony-smart-tv-exploit-inside-view-hijacking-your-living-room.html</a><br/>
MicroTik RouterOS Vulnerablities<br/>
 <a href="https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdf">https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdf</a><br/>
Reverse Analysis of WebAssembly<br/>
 <a href="https://www.forcepoint.com/blog/security-labs/manual-reverse-engineering-webassembly-static-code-analysis">https://www.forcepoint.com/blog/security-labs/manual-reverse-engineering-webassembly-static-code-analysis</a><br/>
Firefox Delays Symantec Certificate Distrust<br/>
 <a href="https://www.theregister.co.uk/2018/10/11/firefox_symantec_certs_delay/">https://www.theregister.co.uk/2018/10/11/firefox_symantec_certs_delay/</a><br/>
]]></description>
<itunes:duration>5:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6208" type="text/plain" language="en" />
<itunes:keywords>equation editor, maldoc, sony, smart tv, bravia, routeros, microtik, webassembly, firefox, symantec, certificates, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 11th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6206</itunes:episode>
<itunes:subtitle>Whats App Vuln; SSH Fingerprints; win32k Vuln Details; Juniper Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Whats App Vuln; SSH Fingerprints; win32k Vuln Details; Juniper Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6206.mp3" length="5386918" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6206.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6206</link>
<pubDate>Thu, 11 Oct 2018 02:25:02 GMT</pubDate>
<description><![CDATA[Remote Code Execution Vulnerability in WhatsApp<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1654">https://bugs.chromium.org/p/project-zero/issues/detail?id=1654</a><br/>
Salesforce Releases hashh Library<br/>
 <a href="https://github.com/salesforce/hassh">https://github.com/salesforce/hassh</a><br/>
CVE-2018-8453 Details from Kaspersky<br/>
 <a href="https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/">https://securelist.com/cve-2018-8453-used-in-targeted-attacks/88151/</a><br/>
Juniper Patches<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES">https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES</a><br/>
Experian Vulnerability Could Have Leaked Credit Freeze PINs<br/>
 <a href="https://www.nerdwallet.com/blog/finance/security-flaw-at-experian-allows-easy-access-to-pin-to-unlock-credit-freeze/">https://www.nerdwallet.com/blog/finance/security-flaw-at-experian-allows-easy-access-to-pin-to-unlock-credit-freeze/</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6206" type="text/plain" language="en" />
<itunes:keywords>experian, credit freeze, juniper, patches, salesforce, hassh, ssh, whatsapp, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 10th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6204</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates; Magecart hits Shopper Approved
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Updates; Magecart hits Shopper Approved
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6204.mp3" length="4656589" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6204.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6204</link>
<pubDate>Wed, 10 Oct 2018 04:20:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/October+2018+Microsoft+Patch+Tuesday/24186/">https://isc.sans.edu/forums/diary/October+2018+Microsoft+Patch+Tuesday/24186/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Magecart Infects "Shopper Approved" Plugin<br/>
 <a href="https://www.riskiq.com/blog/labs/magecart-shopper-approved/">https://www.riskiq.com/blog/labs/magecart-shopper-approved/</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6204" type="text/plain" language="en" />
<itunes:keywords>magecart, shopper approved, adobe, flash, pdf, microsoft, patches, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6202</itunes:episode>
<itunes:subtitle>Apple Updates; Intel 9th Gen CPU; Windows Deletes Files; macOS Code Signing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates; Intel 9th Gen CPU; Windows Deletes Files; macOS Code Signing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6202.mp3" length="3995008" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6202.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6202</link>
<pubDate>Tue, 09 Oct 2018 01:15:03 GMT</pubDate>
<description><![CDATA[Apple Updates iOS and iCloud for Windows<br/>
 <a href="https://support.apple.com/en-ca/HT209162">https://support.apple.com/en-ca/HT209162</a><br/>
 <a href="https://support.apple.com/en-ca/HT209141">https://support.apple.com/en-ca/HT209141</a><br/>
Intel Adds Spectre/Meltdown Mitigation to 9th Generation CPUs<br/>
 <a href="https://www.bleepingcomputer.com/news/security/spectre-and-meltdown-hardware-protection-added-to-intels-9th-gen-cpus/">https://www.bleepingcomputer.com/news/security/spectre-and-meltdown-hardware-protection-added-to-intels-9th-gen-cpus/</a><br/>
Windows October Update File Deleting Issues<br/>
 <a href="https://support.microsoft.com/en-us/help/4464619/windows-10-update-history">https://support.microsoft.com/en-us/help/4464619/windows-10-update-history</a><br/>
 <a href="https://blogs.technet.microsoft.com/filecab/2018/08/30/9205/">https://blogs.technet.microsoft.com/filecab/2018/08/30/9205/</a><br/>
macOS Code Signing Vulnerabilities<br/>
 <a href="https://www.virusbulletin.com/conference/vb2018/abstracts/code-signing-flaw-macos">https://www.virusbulletin.com/conference/vb2018/abstracts/code-signing-flaw-macos</a><br/>
]]></description>
<itunes:duration>4:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6202" type="text/plain" language="en" />
<itunes:keywords>macos, code signing, windows, intel, spectre, meltdown, apple, ios, icloud, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 8th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6200</itunes:episode>
<itunes:subtitle>WPA2 Krack Attack Update; Cisco Patches; git Vulnerability; SWATing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WPA2 Krack Attack Update; Cisco Patches; git Vulnerability; SWATing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6200.mp3" length="5792126" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6200.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6200</link>
<pubDate>Mon, 08 Oct 2018 01:45:03 GMT</pubDate>
<description><![CDATA[WPA2 Karck Attack Update<br/>
 <a href="https://www.krackattacks.com/followup.html#overview">https://www.krackattacks.com/followup.html#overview</a><br/>
Cisco Updates<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities">https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities</a><br/>
Seattle Police Tries to Stop SWATing<br/>
 <a href="https://www.seattle.gov/police/need-help/swatting">https://www.seattle.gov/police/need-help/swatting</a><br/>
git Vulnerability Fixed<br/>
 <a href="https://github.com/timwr/CVE-2017-1000117">https://github.com/timwr/CVE-2017-1000117</a><br/>
]]></description>
<itunes:duration>6:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6200" type="text/plain" language="en" />
<itunes:keywords>git, seattle, police, swatting, cisco, wpa2, krack, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6198</itunes:episode>
<itunes:subtitle>Bloomberg Hardware Implant Story; Cloudflare Phishing; DNSSEC Root KSK Rollover
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Bloomberg Hardware Implant Story; Cloudflare Phishing; DNSSEC Root KSK Rollover
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6198.mp3" length="6142114" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6198.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6198</link>
<pubDate>Fri, 05 Oct 2018 04:55:02 GMT</pubDate>
<description><![CDATA[Does the Chinese Military Manipulate Supermicro Motherboards?<br/>
 <a href="https://www.bloomberg.com/news/articles/2018-10-04/the-big-hack-amazon-apple-supermicro-and-beijing-respond">https://www.bloomberg.com/news/articles/2018-10-04/the-big-hack-amazon-apple-supermicro-and-beijing-respond</a><br/>
Cloudflare IPFS Gateway Used For Phishing<br/>
 <a href="https://www.bleepingcomputer.com/news/security/phishing-attacks-distributed-through-cloudflares-ipfs-gateway/">https://www.bleepingcomputer.com/news/security/phishing-attacks-distributed-through-cloudflares-ipfs-gateway/</a><br/>
DNSSEC Root Key Signing Key Rollover<br/>
 <a href="https://www.icann.org/resources/pages/ksk-rollover">https://www.icann.org/resources/pages/ksk-rollover</a><br/>
 <a href="https://www.icann.org/news/blog/2018-ksk-rollover-operator-preparedness-survey">https://www.icann.org/news/blog/2018-ksk-rollover-operator-preparedness-survey</a><br/>
]]></description>
<itunes:duration>7:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6198" type="text/plain" language="en" />
<itunes:keywords>dnssec, root key, ksk, cloudflare, phishing, bloomberg, china, supermicro, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 4th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6196</itunes:episode>
<itunes:subtitle>Behind the Phish; Azure Phish; Zoho Phishing and keylogging
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Behind the Phish; Azure Phish; Zoho Phishing and keylogging
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6196.mp3" length="5059604" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6196.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6196</link>
<pubDate>Thu, 04 Oct 2018 04:10:02 GMT</pubDate>
<description><![CDATA[Identifying a Phisher<br/>
 <a href="https://isc.sans.edu/forums/diary/Identifying+a+phisher/24164/">https://isc.sans.edu/forums/diary/Identifying+a+phisher/24164/</a><br/>
Phishing via Azure Blob Storage<br/>
 <a href="https://www.netskope.com/blog/phishing-in-the-public-cloud">https://www.netskope.com/blog/phishing-in-the-public-cloud</a><br/>
Zoho Domains Used for Phishing and Keyloggers<br/>
 <a href="https://cofense.com/staggering-amount-stolen-data-heading-zoho-domains/">https://cofense.com/staggering-amount-stolen-data-heading-zoho-domains/</a><br/>
Dell iDRAC Exploit<br/>
 <a href="https://www.servethehome.com/idracula-vulnerability-impacts-millions-of-legacy-dell-emc-servers/">https://www.servethehome.com/idracula-vulnerability-impacts-millions-of-legacy-dell-emc-servers/</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6196" type="text/plain" language="en" />
<itunes:keywords>phishing, azure, blog storage, zoho, dell, idrac, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 3rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6194</itunes:episode>
<itunes:subtitle>Yara Rules; GhostDNS; Foxit PDF Reader Vulns; Intel ME Manufacturing Mode
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Yara Rules; GhostDNS; Foxit PDF Reader Vulns; Intel ME Manufacturing Mode
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6194.mp3" length="4371332" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6194.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6194</link>
<pubDate>Wed, 03 Oct 2018 05:30:02 GMT</pubDate>
<description><![CDATA[How to Write Yara Rules<br/>
 <a href="https://isc.sans.edu/forums/diary/Developing+YARA+Rules+a+Practical+Example/24158/">https://isc.sans.edu/forums/diary/Developing+YARA+Rules+a+Practical+Example/24158/</a><br/>
GhostDNS DNS Changer Malware<br/>
 <a href="https://blog.netlab.360.com/70-different-types-of-home-routers-all-together-100000-are-being-hijacked-by-ghostdns-en/">https://blog.netlab.360.com/70-different-types-of-home-routers-all-together-100000-are-being-hijacked-by-ghostdns-en/</a><br/>
Foxit PDF Reader Vulnerabilities<br/>
 <a href="https://www.foxitsoftware.com/support/security-bulletins.php">https://www.foxitsoftware.com/support/security-bulletins.php</a><br/>
Apple Laptops Shipped With CPU in Manufacturing Mode<br/>
 <a href="http://blog.ptsecurity.com/2018/10/intel-me-manufacturing-mode-macbook.html">http://blog.ptsecurity.com/2018/10/intel-me-manufacturing-mode-macbook.html</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6194" type="text/plain" language="en" />
<itunes:keywords>apple, foxit, pdf, ghostdns, yara, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6192</itunes:episode>
<itunes:subtitle>Facebook Update; Adobe Acrobat Update; SMTP MTA Strict Transport Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Facebook Update; Adobe Acrobat Update; SMTP MTA Strict Transport Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6192.mp3" length="5196379" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6192.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6192</link>
<pubDate>Tue, 02 Oct 2018 05:30:03 GMT</pubDate>
<description><![CDATA[Update About Facebook Breach<br/>
 <a href="https://newsroom.fb.com/news/2018/09/security-update/">https://newsroom.fb.com/news/2018/09/security-update/</a><br/>
Adobe Acrobat/Reader Update<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb18-30.html">https://helpx.adobe.com/security/products/acrobat/apsb18-30.html</a><br/>
SMTP MTA Strict Transport Security (MTA-STS)<br/>
 <a href="https://www.rfc-editor.org/rfc/rfc8461.txt">https://www.rfc-editor.org/rfc/rfc8461.txt</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6192" type="text/plain" language="en" />
<itunes:keywords>faceboo, adobe, acrobat, smtp, mta-sts, rfc8461, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 1st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6190</itunes:episode>
<itunes:subtitle>Facebook Leak; Telegram leaks IPs; Browser Notifications; DDE Code Injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Facebook Leak; Telegram leaks IPs; Browser Notifications; DDE Code Injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6190.mp3" length="5211737" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6190.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6190</link>
<pubDate>Mon, 01 Oct 2018 02:50:01 GMT</pubDate>
<description><![CDATA[Facebook Leaks more than 50 Million Accounts<br/>
 <a href="https://newsroom.fb.com/news/2018/09/security-update/">https://newsroom.fb.com/news/2018/09/security-update/</a><br/>
Telegram Leaks Local IP Address By Default<br/>
 <a href="https://www.inputzero.io/2018/09/bug-bounty-telegram-cve-2018-17780.html">https://www.inputzero.io/2018/09/bug-bounty-telegram-cve-2018-17780.html</a><br/>
Site Tricks Users Into Subscribing to Browser Notifications<br/>
 <a href="https://www.bleepingcomputer.com/news/security/sites-trick-users-into-subscribing-to-browser-notification-spam/">https://www.bleepingcomputer.com/news/security/sites-trick-users-into-subscribing-to-browser-notification-spam/</a><br/>
DDE Code Injection <br/>
 <a href="https://isc.sans.edu/forums/diary/More+Excel+DDE+Code+Injection/24150/">https://isc.sans.edu/forums/diary/More+Excel+DDE+Code+Injection/24150/</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6190" type="text/plain" language="en" />
<itunes:keywords>dde, browser notifications, telegram, facebook, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 28th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6188</itunes:episode>
<itunes:subtitle>Enriching Radare2/x64dbg Output; Apple DEP; UEFI Rootkit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Enriching Radare2/x64dbg Output; Apple DEP; UEFI Rootkit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6188.mp3" length="4690232" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6188.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6188</link>
<pubDate>Fri, 28 Sep 2018 03:00:03 GMT</pubDate>
<description><![CDATA[Enriching Radare2 and x64dbg malware analysis with statically decoded strings<br/>
 <a href="https://isc.sans.edu/forums/diary/Enriching+Radare2+and+x64dbg+malware+analysis+with+statically+decoded+strings/24146/">https://isc.sans.edu/forums/diary/Enriching+Radare2+and+x64dbg+malware+analysis+with+statically+decoded+strings/24146/</a><br/>
Weaknesses in Apple's Mobile Device Management<br/>
 <a href="https://duo.com/labs/research/mdm-me-maybe">https://duo.com/labs/research/mdm-me-maybe</a><br/>
LoJax UEFI Rootkit<br/>
 <a href="https://www.welivesecurity.com/2018/09/27/lojax-first-uefi-rootkit-found-wild-courtesy-sednit-group/">https://www.welivesecurity.com/2018/09/27/lojax-first-uefi-rootkit-found-wild-courtesy-sednit-group/</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6188" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6186</itunes:episode>
<itunes:subtitle>Emotet Update; Fedora Crypto Policies; Android Banking Trojan
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Update; Fedora Crypto Policies; Android Banking Trojan
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6186.mp3" length="4238945" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6186.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6186</link>
<pubDate>Thu, 27 Sep 2018 04:30:02 GMT</pubDate>
<description><![CDATA[Emotet Malware Delivery Service Update<br/>
 <a href="https://isc.sans.edu/forums/diary/One+Emotet+infection+leads+to+three+followup+malware+infections/24140/">https://isc.sans.edu/forums/diary/One+Emotet+infection+leads+to+three+followup+malware+infections/24140/</a><br/>
Fedora Crypto Policy Update Causes SSH Issues<br/>
 <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1631970">https://bugzilla.redhat.com/show_bug.cgi?id=1631970</a><br/>
Android Banking Trojan Impersonates QRecorder<br/>
 <a href="https://lukasstefanko.com/2018/09/banking-trojan-found-on-google-play-stole-10000-euros-from-victims.html">https://lukasstefanko.com/2018/09/banking-trojan-found-on-google-play-stole-10000-euros-from-victims.html</a><br/>
Google Reverts Changes to Chrome<br/>
 <a href="https://www.blog.google/products/chrome/product-updates-based-your-feedback/amp/">https://www.blog.google/products/chrome/product-updates-based-your-feedback/amp/</a><br/>
]]></description>
<itunes:duration>5:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6186" type="text/plain" language="en" />
<itunes:keywords>google, chrome, android, qrecorder, fedora, emotet, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6184</itunes:episode>
<itunes:subtitle>Firefox Monitor;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Firefox Monitor;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6184.mp3" length="4268570" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6184.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6184</link>
<pubDate>Wed, 26 Sep 2018 05:30:02 GMT</pubDate>
<description><![CDATA[Firefox Haveibeenpwned Monitor<br/>
 <a href="https://blog.mozilla.org/blog/2018/09/25/introducing-firefox-monitor-helping-people-take-control-after-a-data-breach/">https://blog.mozilla.org/blog/2018/09/25/introducing-firefox-monitor-helping-people-take-control-after-a-data-breach/</a><br/>
Chrome 69 Privacy Issues<br/>
 <a href="https://www.bleepingcomputer.com/news/google/chrome-69-keeps-googles-cookies-after-you-clear-browser-data/">https://www.bleepingcomputer.com/news/google/chrome-69-keeps-googles-cookies-after-you-clear-browser-data/</a><br/>
Cisco FragmentSmack Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-ip-fragment">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180824-linux-ip-fragment</a><br/>
Micorsoft Bitlocker Turns itself Off During Updates<br/>
 <a href="https://social.technet.microsoft.com/Forums/en-US/0e48536f-40ff-4046-bd08-ed4a39b4840f/bitlocker-automatically-suspending-during-updates?forum=win10itprosecurity">https://social.technet.microsoft.com/Forums/en-US/0e48536f-40ff-4046-bd08-ed4a39b4840f/bitlocker-automatically-suspending-during-updates?forum=win10itprosecurity</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6184" type="text/plain" language="en" />
<itunes:keywords>cisco, fragmentsmack, microsoft, bitlocker, havibeenpwned, firefox, chrome, privacy, google, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 25th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6182</itunes:episode>
<itunes:subtitle>MacOS 10.14; More Sextortion; Mojave Privacy Bypass; Cloudflare ESNI
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS 10.14; More Sextortion; Mojave Privacy Bypass; Cloudflare ESNI
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6182.mp3" length="5005846" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6182.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6182</link>
<pubDate>Tue, 25 Sep 2018 03:20:02 GMT</pubDate>
<description><![CDATA[More Sextortion Emails<br/>
 <a href="https://isc.sans.edu/forums/diary/Sextortion+Spam+and+the+Infinite+Monkey+Theorem/24136/">https://isc.sans.edu/forums/diary/Sextortion+Spam+and+the+Infinite+Monkey+Theorem/24136/</a><br/>
MacOS 10.14 (Mojahve) Security Fixes<br/>
 <a href="https://support.apple.com/en-us/HT209139">https://support.apple.com/en-us/HT209139</a><br/>
Mojave Privacy Protection Bypass<br/>
 <a href="https://vimeo.com/291491984">https://vimeo.com/291491984</a><br/>
Cloudflare Supporting Encrypted SNI<br/>
 <a href="https://blog.cloudflare.com/esni/">https://blog.cloudflare.com/esni/</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6182" type="text/plain" language="en" />
<itunes:keywords>cloudflare, esni, mojave, os 10.14, sextortion, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 24th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6180</itunes:episode>
<itunes:subtitle>Odd DNS Requests; Securing APIs; Windows Jet DB 0day; Malicious Job Offers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd DNS Requests; Securing APIs; Windows Jet DB 0day; Malicious Job Offers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6180.mp3" length="3790575" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6180.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6180</link>
<pubDate>Mon, 24 Sep 2018 03:30:02 GMT</pubDate>
<description><![CDATA[Odd DNS Requests from Firewalls<br/>
 <a href="https://isc.sans.edu/forums/diary/Suspicious+DNS+Requests+Issued+by+a+Firewall/24128/">https://isc.sans.edu/forums/diary/Suspicious+DNS+Requests+Issued+by+a+Firewall/24128/</a><br/>
Securing API Connections<br/>
 <a href="https://isc.sans.edu/forums/diary/The+danger+of+sending+information+for+API+consumption+without+adequate+security+measures/24130/">https://isc.sans.edu/forums/diary/The+danger+of+sending+information+for+API+consumption+without+adequate+security+measures/24130/</a><br/>
Microsoft JET Database 0day<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-18-1075/">https://www.zerodayinitiative.com/advisories/ZDI-18-1075/</a><br/>
Western Digital Releases Patch for MyCloud Drives<br/>
 <a href="https://support.wdc.com/knowledgebase/answer.aspx?ID=25952&s">https://support.wdc.com/knowledgebase/answer.aspx?ID=25952&s</a><br/>
Job Offers With Malware Attachment<br/>
 <a href="https://www.bleepingcomputer.com/news/security/malware-disguised-as-job-offers-distributed-on-freelance-sites/">https://www.bleepingcomputer.com/news/security/malware-disguised-as-job-offers-distributed-on-freelance-sites/</a><br/>
]]></description>
<itunes:duration>4:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6180" type="text/plain" language="en" />
<itunes:keywords>job offers, microsoft jet, fingerprints, dns, firewalls, western digital, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 21st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6178</itunes:episode>
<itunes:subtitle>OSSEC Hunting; NSSLabs; Bitcoin DoS; WebAuthn
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OSSEC Hunting; NSSLabs; Bitcoin DoS; WebAuthn
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6178.mp3" length="10563604" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6178.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6178</link>
<pubDate>Fri, 21 Sep 2018 00:45:07 GMT</pubDate>
<description><![CDATA[Hunting for Suspicious Processes with OSSEC<br/>
 <a href="https://isc.sans.edu/forums/diary/Hunting+for+Suspicious+Processes+with+OSSEC/24122/">https://isc.sans.edu/forums/diary/Hunting+for+Suspicious+Processes+with+OSSEC/24122/</a><br/>
NSSLabs Sues Crowdstrike, Symantec, ESET<br/>
 <a href="https://www.nsslabs.com/blog/company/advancing-transparency-and-accountability-in-the-cybersecurity-industry/">https://www.nsslabs.com/blog/company/advancing-transparency-and-accountability-in-the-cybersecurity-industry/</a><br/>
Bitcoin Core Vulnerability<br/>
 <a href="https://motherboard.vice.com/amp/en_us/article/qvakp3/a-major-bug-in-bitcoin-software-could-have-crashed-the-currency?__twitter_impression=true">https://motherboard.vice.com/amp/en_us/article/qvakp3/a-major-bug-in-bitcoin-software-could-have-crashed-the-currency?__twitter_impression=true</a><br/>
WebAuthn Standard<br/>
 <a href="https://paragonie.com/blog/2018/08/security-concerns-surrounding-webauthn-don-t-implement-ecdaa-yet">https://paragonie.com/blog/2018/08/security-concerns-surrounding-webauthn-don-t-implement-ecdaa-yet</a><br/>
 <a href="https://fidoalliance.org/">https://fidoalliance.org/</a><br/>
]]></description>
<itunes:duration>12:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6178" type="text/plain" language="en" />
<itunes:keywords>hunting, ossec, nsslabs, crowdstrike, symantec, eset, bitcoin, webauthn, u2f, fido, paragon, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 20th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6176</itunes:episode>
<itunes:subtitle>Adobe PDF Updates; Credential Stuffing DDoS; Peekaboo;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe PDF Updates; Credential Stuffing DDoS; Peekaboo;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6176.mp3" length="4559676" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6176.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6176</link>
<pubDate>Thu, 20 Sep 2018 02:30:02 GMT</pubDate>
<description><![CDATA[Adobe Releases Special Patch for Acrobat and Reader<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb18-34.html">https://helpx.adobe.com/security/products/acrobat/apsb18-34.html</a><br/>
Akamai State of the Internet Report<br/>
 <a href="https://www.akamai.com/us/en/about/our-thinking/state-of-the-internet-report/global-state-of-the-internet-security-ddos-attack-reports.jsp">https://www.akamai.com/us/en/about/our-thinking/state-of-the-internet-report/global-state-of-the-internet-security-ddos-attack-reports.jsp</a><br/>
Peekabo DVR Vulnerability<br/>
 <a href="https://www.tenable.com/blog/tenable-research-advisory-peekaboo-critical-vulnerability-in-nuuo-network-video-recorder">https://www.tenable.com/blog/tenable-research-advisory-peekaboo-critical-vulnerability-in-nuuo-network-video-recorder</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6176" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 19th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6174</itunes:episode>
<itunes:subtitle>Certificate Transparency Tools; WD MyCloud; Kodi Malicious Add-Ons; Cloudflare DNSSEC Support
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Certificate Transparency Tools; WD MyCloud; Kodi Malicious Add-Ons; Cloudflare DNSSEC Support
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6174.mp3" length="4591861" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6174.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6174</link>
<pubDate>Wed, 19 Sep 2018 02:00:03 GMT</pubDate>
<description><![CDATA[Certificate Transparency Tools<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Certificate+Transparency+as+an+Attack+Defense+Tool/24114/">https://isc.sans.edu/forums/diary/Using+Certificate+Transparency+as+an+Attack+Defense+Tool/24114/</a><br/>
Kodi Malicious Add-Ons<br/>
 <a href="https://www.welivesecurity.com/2018/09/13/kodi-add-ons-launch-cryptomining-campaign/">https://www.welivesecurity.com/2018/09/13/kodi-add-ons-launch-cryptomining-campaign/</a><br/>
Cloudflare Making DNSSEC Adoption Easier<br/>
 <a href="https://blog.cloudflare.com/automatically-provision-and-maintain-dnssec/">https://blog.cloudflare.com/automatically-provision-and-maintain-dnssec/</a><br/>
Western Digital MyCloud Unauthenticated Admin Access<br/>
 <a href="https://www.securify.nl/advisory/SFY20180102/authentication-bypass-vulnerability-in-western-digital-my-cloud-allows-escalation-to-admin-privileges.html">https://www.securify.nl/advisory/SFY20180102/authentication-bypass-vulnerability-in-western-digital-my-cloud-allows-escalation-to-admin-privileges.html</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6174" type="text/plain" language="en" />
<itunes:keywords>Western Digital, MyCloud, Cloudflare, DNSSEC, Kodi, Cryptominers, Certificate Transparency, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 18th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6172</itunes:episode>
<itunes:subtitle>Analyzing Office Docs; Apple Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing Office Docs; Apple Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6172.mp3" length="4579423" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6172.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6172</link>
<pubDate>Tue, 18 Sep 2018 01:05:02 GMT</pubDate>
<description><![CDATA[Analyzing Office Docs<br/>
 <a href="https://isc.sans.edu/forums/diary/Dissecting+Malicious+MS+Office+Docs/24108/">https://isc.sans.edu/forums/diary/Dissecting+Malicious+MS+Office+Docs/24108/</a><br/>
Apple Updates Everything but macOS<br/>
 <a href="https://support.apple.com/en-us/HT201220">https://support.apple.com/en-us/HT201220</a><br/>
FBot Botnet<br/>
 <a href="https://blog.netlab.360.com/threat-alert-a-new-worm-fbot-cleaning-adbminer-is-using-a-blockchain-based-dns-en/">https://blog.netlab.360.com/threat-alert-a-new-worm-fbot-cleaning-adbminer-is-using-a-blockchain-based-dns-en/</a><br/>
Related STI Paper: Botnet Reciliency via Private Blockchain (Jonathan Sweeny)<br/>
<a href="https://www.sans.org/reading-room/whitepapers/covert/botnet-resiliency-private-blockchains-38050">https://www.sans.org/reading-room/whitepapers/covert/botnet-resiliency-private-blockchains-38050</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6172" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 17th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6170</itunes:episode>
<itunes:subtitle>Reversing Shortcuts; Not So Random UA; Safari DoS; Webroot SecureAnywhere; Intel ME
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing Shortcuts; Not So Random UA; Safari DoS; Webroot SecureAnywhere; Intel ME
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6170.mp3" length="4586370" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6170.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6170</link>
<pubDate>Mon, 17 Sep 2018 01:05:02 GMT</pubDate>
<description><![CDATA[Reversing Visual Basic Shortcuts<br/>
 <a href="https://isc.sans.edu/forums/diary/2020+malware+vision/24104/">https://isc.sans.edu/forums/diary/2020+malware+vision/24104/</a><br/>
Not So Random User Agent<br/>
 <a href="https://isc.sans.edu/forums/diary/User+Agent+String+uatoolsrandom/24102/">https://isc.sans.edu/forums/diary/User+Agent+String+uatoolsrandom/24102/</a><br/>
Safari DoS<br/>
 <a href="https://gist.github.com/pwnsdx/ce64de2760996a6c432f06d612e33aea">https://gist.github.com/pwnsdx/ce64de2760996a6c432f06d612e33aea</a><br/>
Webroot SecureAnywhere macOS Vulnerability<br/>
 <a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-16962--Webroot-SecureAnywhere-macOS-Kernel-Level-Memory-Corruption/">https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-16962--Webroot-SecureAnywhere-macOS-Kernel-Level-Memory-Corruption/</a><br/>
Intel Patches Management Engine Encryption Vulnerability<br/>
 <a href="http://blog.ptsecurity.com/2018/09/intel-me-encryption-vulnerability.html">http://blog.ptsecurity.com/2018/09/intel-me-encryption-vulnerability.html</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6170" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 14th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6168</itunes:episode>
<itunes:subtitle>Malicious MHT Files; Improved Coldboot Attacks; Hurricanes/Disasters; SAP Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious MHT Files; Improved Coldboot Attacks; Hurricanes/Disasters; SAP Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6168.mp3" length="4728632" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6168.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6168</link>
<pubDate>Fri, 14 Sep 2018 01:10:02 GMT</pubDate>
<description><![CDATA[Malicious MHT Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Delivered+Through+MHT+Files/24096/">https://isc.sans.edu/forums/diary/Malware+Delivered+Through+MHT+Files/24096/</a><br/>
Improved Coldboot Attack<br/>
 <a href="https://blog.f-secure.com/cold-boot-attacks/">https://blog.f-secure.com/cold-boot-attacks/</a><br/>
SAP Patches<br/>
 <a href="https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993">https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6168" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 13th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6166</itunes:episode>
<itunes:subtitle>Fragment Update; Magacart Script; Bypassing CSP With Polyglots
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fragment Update; Magacart Script; Bypassing CSP With Polyglots
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6166.mp3" length="5718625" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6166.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6166</link>
<pubDate>Thu, 13 Sep 2018 00:10:02 GMT</pubDate>
<description><![CDATA[So What is Going on With IPv4 Fragments these Days?<br/>
 <a href="https://isc.sans.edu/forums/diary/So+What+is+Going+on+With+IPv4+Fragments+these+Days/24092/">https://isc.sans.edu/forums/diary/So+What+is+Going+on+With+IPv4+Fragments+these+Days/24092/</a><br/>
Magacart Javascript Injection Attacks<br/>
 <a href="https://www.bleepingcomputer.com/news/security/feedify-service-compromised-with-magecart-information-stealing-script/">https://www.bleepingcomputer.com/news/security/feedify-service-compromised-with-magecart-information-stealing-script/</a><br/>
Bypassing CSP using Polyglot JPEGs<br/>
 <a href="https://portswigger.net/blog/bypassing-csp-using-polyglot-jpegs">https://portswigger.net/blog/bypassing-csp-using-polyglot-jpegs</a><br/>
]]></description>
<itunes:duration>6:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6166" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 12th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6164</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Patches; URL Spooing; Exploit Search Engine
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Patch Tuesday; Adobe Patches; URL Spooing; Exploit Search Engine
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6164.mp3" length="3998307" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6164.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6164</link>
<pubDate>Wed, 12 Sep 2018 00:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+September+Patch+Tuesday+Summary/24088/">https://isc.sans.edu/forums/diary/Microsoft+September+Patch+Tuesday+Summary/24088/</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Safari/Edge URL Bar Spoofing<br/>
 <a href="https://www.rafaybaloch.com/2018/09/apple-safari-microsoft-edge-browser.html">https://www.rafaybaloch.com/2018/09/apple-safari-microsoft-edge-browser.html</a><br/>
Exploit Search Engine<br/>
 <a href="https://sploitus.com">https://sploitus.com</a><br/>
]]></description>
<itunes:duration>4:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6164" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 11th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6162</itunes:episode>
<itunes:subtitle>Malicious LNK File Tricks; Trend Micro Apps Removed from Apple App Store
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious LNK File Tricks; Trend Micro Apps Removed from Apple App Store
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6162.mp3" length="4026829" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6162.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6162</link>
<pubDate>Mon, 10 Sep 2018 23:35:02 GMT</pubDate>
<description><![CDATA["findstr" used to extract malware from LNK files<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+dikona+or+glirote3/24084/">https://isc.sans.edu/forums/diary/What+is+dikona+or+glirote3/24084/</a><br/>
Tor Browser Javascript Vulnerability<br/>
 <a href="https://www.bleepingcomputer.com/news/security/exploit-affecting-tor-browser-burned-in-a-tweet/">https://www.bleepingcomputer.com/news/security/exploit-affecting-tor-browser-burned-in-a-tweet/</a><br/>
Trend Micro App Leaks Data / Removed from Appstore<br/>
 <a href="https://forums.malwarebytes.com/topic/217353-get-rid-of-open-any-files-rar-support/?tab=comments#comment-1194838">https://forums.malwarebytes.com/topic/217353-get-rid-of-open-any-files-rar-support/?tab=comments#comment-1194838</a><br/>
Chrome removes Subdomains from URL Bar<br/>
 <a href="https://bugs.chromium.org/p/chromium/issues/detail?id=881410">https://bugs.chromium.org/p/chromium/issues/detail?id=881410</a><br/>
]]></description>
<itunes:duration>4:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6162" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, September 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6160</itunes:episode>
<itunes:subtitle>Headless Browser Cryptocoin Mining; Adware Doctor Privacy; VPN Priv Escalation
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Headless Browser Cryptocoin Mining; Adware Doctor Privacy; VPN Priv Escalation
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6160.mp3" length="5515284" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6160.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6160</link>
<pubDate>Sun, 09 Sep 2018 18:55:02 GMT</pubDate>
<description><![CDATA[Crypto Mining in a Windows Headless Browser<br/>
 <a href="https://isc.sans.edu/forums/diary/Crypto+Mining+in+a+Windows+Headless+Browser/24078/">https://isc.sans.edu/forums/diary/Crypto+Mining+in+a+Windows+Headless+Browser/24078/</a><br/>
MacOS Adware Doctor Stealing Browser History<br/>
 <a href="https://twitter.com/privacyis1st/status/1031428304543395840">https://twitter.com/privacyis1st/status/1031428304543395840</a><br/>
 <a href="https://objective-see.com/blog/blog_0x37.html">https://objective-see.com/blog/blog_0x37.html</a><br/>
VPN Applications with Privilege Escalation Vulnerabilities<br/>
 <a href="https://blog.talosintelligence.com/2018/09/vulnerability-spotlight-Multi-provider-VPN-Client-Privilege-Escalation.html">https://blog.talosintelligence.com/2018/09/vulnerability-spotlight-Multi-provider-VPN-Client-Privilege-Escalation.html</a><br/>
Keybase Extension Allws Access By Scripts from Any Site<br/>
 <a href="https://palant.de/2018/09/06/keybase-our-browser-extension-subverts-our-encryption-but-why-should-we-care">https://palant.de/2018/09/06/keybase-our-browser-extension-subverts-our-encryption-but-why-should-we-care</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6160" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 7th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6158</itunes:episode>
<itunes:subtitle>Powershell Malware C# Code;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Powershell Malware C# Code;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6158.mp3" length="3977455" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6158.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6158</link>
<pubDate>Thu, 06 Sep 2018 19:55:02 GMT</pubDate>
<description><![CDATA[Malware Uses Powershell to Comple C# Code on the Fly<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+PowerShell+Compiling+C+Code+on+the+Fly/24072/">https://isc.sans.edu/forums/diary/Malicious+PowerShell+Compiling+C+Code+on+the+Fly/24072/</a><br/>
Stealing WiFi Credentials in Google Chrome<br/>
 <a href="https://www.surecloud.com/sc-blog/wifi-hijacking">https://www.surecloud.com/sc-blog/wifi-hijacking</a><br/>
DNS Spoofing and Certificate Authority Domain Validation<br/>
 <a href="https://www.theregister.co.uk/2018/09/06/boffins_break_cas_domain_validation/">https://www.theregister.co.uk/2018/09/06/boffins_break_cas_domain_validation/</a><br/>
Cisco Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=30#~Vulnerabilities">https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir&limit=30#~Vulnerabilities</a><br/>
]]></description>
<itunes:duration>4:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6158" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 6th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6156</itunes:episode>
<itunes:subtitle>MEGA Chrome Extension Hack; Python Package Installer Code Exec; Win Scheduler Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MEGA Chrome Extension Hack; Python Package Installer Code Exec; Win Scheduler Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6156.mp3" length="4298922" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6156.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6156</link>
<pubDate>Wed, 05 Sep 2018 19:45:02 GMT</pubDate>
<description><![CDATA[MEGA Chrome Extension Replaced with Password Stealer<br/>
 <a href="https://serhack.me/articles/mega-chrome-extension-hacked">https://serhack.me/articles/mega-chrome-extension-hacked</a><br/>
Python Package Installer May Execute Code<br/>
 <a href="https://github.com/mschwager/0wned">https://github.com/mschwager/0wned</a><br/>
Windows Scheduler Exploit Used in the Wild<br/>
 <a href="https://www.welivesecurity.com/2018/09/05/powerpool-malware-exploits-zero-day-vulnerability/">https://www.welivesecurity.com/2018/09/05/powerpool-malware-exploits-zero-day-vulnerability/</a><br/>
Where Have All My Certificates Gone?<br/>
 <a href="https://isc.sans.edu/forums/diary/Where+have+all+my+Certificates+gone+And+when+do+they+expire/24066/">https://isc.sans.edu/forums/diary/Where+have+all+my+Certificates+gone+And+when+do+they+expire/24066/</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6156" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6154</itunes:episode>
<itunes:subtitle>Microtik Exploits; Exposed git Directories; SSL Certs and Tor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microtik Exploits; Exposed git Directories; SSL Certs and Tor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6154.mp3" length="4663541" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6154.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6154</link>
<pubDate>Tue, 04 Sep 2018 21:40:02 GMT</pubDate>
<description><![CDATA[Some More Interesting MicroTik Router Exploits<br/>
 <a href="https://blog.netlab.360.com/7500-mikrotik-routers-are-forwarding-owners-traffic-to-the-attackers-how-is-yours-en/">https://blog.netlab.360.com/7500-mikrotik-routers-are-forwarding-owners-traffic-to-the-attackers-how-is-yours-en/</a><br/>
Exposed .git Directories<br/>
 <a href="https://lynt.cz/blog/global-scan-exposed-git">https://lynt.cz/blog/global-scan-exposed-git</a><br/>
SSL Certificates Expose Tor Servers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/public-ip-addresses-of-tor-sites-exposed-via-ssl-certificates/">https://www.bleepingcomputer.com/news/security/public-ip-addresses-of-tor-sites-exposed-via-ssl-certificates/</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6154" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 4th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6152</itunes:episode>
<itunes:subtitle>Reversing Medium Mobile App;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reversing Medium Mobile App;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6152.mp3" length="3965758" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6152.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6152</link>
<pubDate>Tue, 04 Sep 2018 04:50:02 GMT</pubDate>
<description><![CDATA[Reversing and Modifying the Medium Mobile App<br/>
 <a href="https://hackernoon.com/dont-publish-yet-reverse-engineering-the-medium-app-and-making-all-stories-in-it-free-48c8f2695687">https://hackernoon.com/dont-publish-yet-reverse-engineering-the-medium-app-and-making-all-stories-in-it-free-48c8f2695687</a><br/>
Active Directory Leaks via Azure <br/>
 <a href="https://www.blackhillsinfosec.com/red-teaming-microsoft-part-1-active-directory-leaks-via-azure/">https://www.blackhillsinfosec.com/red-teaming-microsoft-part-1-active-directory-leaks-via-azure/</a><br/>
Google Restricts Tech Support Ads<br/>
 <a href="https://www.blog.google/products/ads/restricting-ads-third-party-tech-support-services/?mod=article_inline">https://www.blog.google/products/ads/restricting-ads-third-party-tech-support-services/?mod=article_inline</a><br/>
]]></description>
<itunes:duration>4:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6152" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, September 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6150</itunes:episode>
<itunes:subtitle>OSX/MacOS Custom URL Schemes; Philips e-Alert Vulnerablity
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OSX/MacOS Custom URL Schemes; Philips e-Alert Vulnerablity
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6150.mp3" length="4007078" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6150.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6150</link>
<pubDate>Sun, 02 Sep 2018 18:45:03 GMT</pubDate>
<description><![CDATA[OSX/MacOS and Dangerous of Custom URL Schemes<br/>
 <a href="https://objective-see.com/blog/blog_0x38.html">https://objective-see.com/blog/blog_0x38.html</a><br/>
Philips e-Alert Vulnerability<br/>
 <a href="https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01">https://ics-cert.us-cert.gov/advisories/ICSA-18-242-01</a><br/>
]]></description>
<itunes:duration>4:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6150" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 31st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6148</itunes:episode>
<itunes:subtitle>Cryptocoin Miners Rule; Android Privacy Weakness; Mimecast EMail Stats
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cryptocoin Miners Rule; Android Privacy Weakness; Mimecast EMail Stats
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6148.mp3" length="5045335" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6148.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6148</link>
<pubDate>Thu, 30 Aug 2018 20:15:04 GMT</pubDate>
<description><![CDATA[Cryptocoin Miners are More Popular Than Ever and Dominate in Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Crypto+Mining+Is+More+Popular+Than+Ever/24050/">https://isc.sans.edu/forums/diary/Crypto+Mining+Is+More+Popular+Than+Ever/24050/</a><br/>
Cryptocoin Miners Deployed via Struts Vulnerability<br/>
 <a href="https://www.volexity.com/blog/2018/08/27/active-exploitation-of-new-apache-struts-vulnerability-cve-2018-11776-deploys-cryptocurrency-miner/">https://www.volexity.com/blog/2018/08/27/active-exploitation-of-new-apache-struts-vulnerability-cve-2018-11776-deploys-cryptocurrency-miner/</a><br/>
Mimecast Identifies Weaknesses in Existing EMail Filters<br/>
 <a href="https://www.mimecast.com/resources/ebooks/dates/2018/7/the-state-of-email-security-2018-report/">https://www.mimecast.com/resources/ebooks/dates/2018/7/the-state-of-email-security-2018-report/</a><br/>
Android Leaks Information to Processes<br/>
 <a href="https://wwws.nightwatchcybersecurity.com/2018/08/29/sensitive-data-exposure-via-wifi-broadcasts-in-android-os-cve-2018-9489/">https://wwws.nightwatchcybersecurity.com/2018/08/29/sensitive-data-exposure-via-wifi-broadcasts-in-android-os-cve-2018-9489/</a><br/>
]]></description>
<itunes:duration>5:59</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6148" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 30th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6146</itunes:episode>
<itunes:subtitle>More Octoprint Details #3dprint flaws; Packagist PHP Repo; More OpenSSH; TPM Flaws;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Octoprint Details #3dprint flaws; Packagist PHP Repo; More OpenSSH; TPM Flaws;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6146.mp3" length="5226002" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6146.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6146</link>
<pubDate>Wed, 29 Aug 2018 20:40:02 GMT</pubDate>
<description><![CDATA[More Octoprint Details<br/>
 <a href="https://isc.sans.edu/forums/diary/3D+Printers+in+The+Wild+What+Can+Go+Wrong/24044/">https://isc.sans.edu/forums/diary/3D+Printers+in+The+Wild+What+Can+Go+Wrong/24044/</a><br/>
Packagist Remote Code Injection Vulnerability<br/>
 <a href="https://justi.cz/security/2018/08/28/packagist-org-rce.html">https://justi.cz/security/2018/08/28/packagist-org-rce.html</a><br/>
More OpenSSH User Enumeration Issues<br/>
 <a href="http://seclists.org/oss-sec/2018/q3/180">http://seclists.org/oss-sec/2018/q3/180</a><br/>
Two new TPM Vulnerabilities<br/>
 <a href="https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-han.pdf">https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-han.pdf</a><br/>
]]></description>
<itunes:duration>6:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6146" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 29th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6144</itunes:episode>
<itunes:subtitle>Windows Priv. Escalation 0 Day;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows Priv. Escalation 0 Day;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6144.mp3" length="4505547" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6144.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6144</link>
<pubDate>Tue, 28 Aug 2018 20:35:02 GMT</pubDate>
<description><![CDATA[Microsoft Windows Task Scheduler Local Privilege Escalation Vulnerability<br/>
 <a href="https://www.kb.cert.org/vuls/id/906424">https://www.kb.cert.org/vuls/id/906424</a><br/>
3D Printers Exposed to Internet<br/>
 <a href="https://isc.sans.edu/forums/diary/OctoPrint+3D+Web+Interfaces+EXPOSED+Port+5000+default/24038/">https://isc.sans.edu/forums/diary/OctoPrint+3D+Web+Interfaces+EXPOSED+Port+5000+default/24038/</a><br/>
Firefox Nightly Built Removes Trust From Symantec Certificates<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1460062">https://bugzilla.mozilla.org/show_bug.cgi?id=1460062</a><br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1484006">https://bugzilla.mozilla.org/show_bug.cgi?id=1484006</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6144" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 28th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6142</itunes:episode>
<itunes:subtitle>HWorm Infection Date; Gnome "Bubblewrap"; Fortnite Android Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HWorm Infection Date; Gnome "Bubblewrap"; Fortnite Android Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6142.mp3" length="3755828" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6142.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6142</link>
<pubDate>Mon, 27 Aug 2018 20:45:03 GMT</pubDate>
<description><![CDATA[H-Worm Variant Notes Infection Date in Registry<br/>
 <a href="https://isc.sans.edu/forums/diary/When+was+this+machine+infected/24032/">https://isc.sans.edu/forums/diary/When+was+this+machine+infected/24032/</a><br/>
CentOS / Ubuntu Turn Off Gnome "Bubblewrap" Sandbox<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ubuntu-and-centos-are-undoing-a-gnome-security-feature/">https://www.bleepingcomputer.com/news/security/ubuntu-and-centos-are-undoing-a-gnome-security-feature/</a><br/>
Fortnite Android Arbitrary Code Install Vulnerability<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ubuntu-and-centos-are-undoing-a-gnome-security-feature/">https://www.bleepingcomputer.com/news/security/ubuntu-and-centos-are-undoing-a-gnome-security-feature/</a><br/>
]]></description>
<itunes:duration>4:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6142" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6140</itunes:episode>
<itunes:subtitle>Struts CVE-2018-11776 Exploit Public; Publisher Malware; AT Commands;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Struts CVE-2018-11776 Exploit Public; Publisher Malware; AT Commands;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6140.mp3" length="5080444" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6140.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6140</link>
<pubDate>Sun, 26 Aug 2018 19:40:02 GMT</pubDate>
<description><![CDATA[Struts Exploits for CVE-2018-11776 on Github (there are more. just a sample)<br/>
 <a href="https://github.com/mazen160/struts-pwn_CVE-2018-11776">https://github.com/mazen160/struts-pwn_CVE-2018-11776</a><br/>
 <a href="https://github.com/jiguang7/CVE-2018-11776">https://github.com/jiguang7/CVE-2018-11776</a><br/>
Publisher Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Publisher+Files+Delivering+Malware/24024/">https://isc.sans.edu/forums/diary/Microsoft+Publisher+Files+Delivering+Malware/24024/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Publisher+malware+static+analysis/24026/">https://isc.sans.edu/forums/diary/Microsoft+Publisher+malware+static+analysis/24026/</a><br/>
AT Commands<br/>
 <a href="https://atcommands.org/atdb/vendors">https://atcommands.org/atdb/vendors</a><br/>
Using a Microphone to Read Screen Content<br/>
 <a href="https://www.cs.tau.ac.il/~tromer/synesthesia/synesthesia.pdf">https://www.cs.tau.ac.il/~tromer/synesthesia/synesthesia.pdf</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6140" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 24th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6138</itunes:episode>
<itunes:subtitle>Formcrafts Phishing;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Formcrafts Phishing;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6138.mp3" length="5179918" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6138.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6138</link>
<pubDate>Thu, 23 Aug 2018 21:40:02 GMT</pubDate>
<description><![CDATA[Simple Phishing Through formcrafts.com<br/>
 <a href="https://isc.sans.edu/forums/diary/Simple+Phishing+Through+formcraftscom/24020/">https://isc.sans.edu/forums/diary/Simple+Phishing+Through+formcraftscom/24020/</a><br/>
Facebook's Onavo VPN removed from Apple AppStore<br/>
 <a href="https://www.wsj.com/articles/facebook-to-remove-data-security-app-from-apple-store-1534975340?mod=e2tw">https://www.wsj.com/articles/facebook-to-remove-data-security-app-from-apple-store-1534975340?mod=e2tw</a> (paywall)<br/>
 <a href="https://medium.com/@chronic_9612/notes-on-analytics-and-tracking-in-onavo-protect-for-ios-904bdff346c0">https://medium.com/@chronic_9612/notes-on-analytics-and-tracking-in-onavo-protect-for-ios-904bdff346c0</a><br/>
Phishing False Alarm<br/>
 <a href="https://www.cnn.com/2018/08/23/politics/dnc-hack-false-alarm/index.html">https://www.cnn.com/2018/08/23/politics/dnc-hack-false-alarm/index.html</a><br/>
Fake Crypto Trading App Stealing Crypot Currency From Mac Users<br/>
 <a href="https://www.businesswire.com/news/home/20180823005093/en/AppleJeus-Lazarus-Group-Hunts-Cryptocurrency-Exchanges-macOS">https://www.businesswire.com/news/home/20180823005093/en/AppleJeus-Lazarus-Group-Hunts-Cryptocurrency-Exchanges-macOS</a><br/>
Intel Simplifies Microcode License<br/>
 <a href="https://twitter.com/imadsousou/status/1032680311753072640">https://twitter.com/imadsousou/status/1032680311753072640</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6138" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 23rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6136</itunes:episode>
<itunes:subtitle>New Critical Apache Struts Vulnerability; Ghostscript Vuln; Photoshop CC Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Critical Apache Struts Vulnerability; Ghostscript Vuln; Photoshop CC Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6136.mp3" length="4464950" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6136.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6136</link>
<pubDate>Wed, 22 Aug 2018 21:30:02 GMT</pubDate>
<description><![CDATA[New Critical Apache Struts Vulnerability (CVE-2018-11776)<br/>
 <a href="https://semmle.com/news/apache-struts-CVE-2018-11776">https://semmle.com/news/apache-struts-CVE-2018-11776</a><br/>
 <a href="https://cwiki.apache.org/confluence/display/WW/S2-057">https://cwiki.apache.org/confluence/display/WW/S2-057</a><br/>
Hardening Apache Struts With SELinux<br/>
 <a href="https://doublepulsar.com/hardening-apache-struts-with-selinux-db3a9cd1a10c?gi=f23fc884264a">https://doublepulsar.com/hardening-apache-struts-with-selinux-db3a9cd1a10c?gi=f23fc884264a</a><br/>
Ghostscript Code Execution Vulnerability<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1640">https://bugs.chromium.org/p/project-zero/issues/detail?id=1640</a><br/>
Photoshop CC Patch<br/>
 <a href="https://helpx.adobe.com/security/products/photoshop/apsb18-28.html">https://helpx.adobe.com/security/products/photoshop/apsb18-28.html</a><br/>
]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6136" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 22nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6134</itunes:episode>
<itunes:subtitle>Malicious DLL Loaded with AutoIT; Critical Traefik Bug; Debian L1TF Patch Problem
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious DLL Loaded with AutoIT; Critical Traefik Bug; Debian L1TF Patch Problem
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6134.mp3" length="4476655" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6134.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6134</link>
<pubDate>Tue, 21 Aug 2018 21:05:03 GMT</pubDate>
<description><![CDATA[Malicious DDL Loaded Through AutoIT<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+DLL+Loaded+Through+AutoIT/24008/">https://isc.sans.edu/forums/diary/Malicious+DLL+Loaded+Through+AutoIT/24008/</a><br/>
Traefik Fixes TLS Private Key Exposure<br/>
 <a href="https://github.com/containous/traefik/issues/3651">https://github.com/containous/traefik/issues/3651</a><br/>
TLS Certificates Survive Domain Ownership<br/>
 <a href="https://insecure.design">https://insecure.design</a><br/>
Intel Microcode License Update Causes Problems for Debian Linux<br/>
 <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906158#14">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906158#14</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6134" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 21st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6132</itunes:episode>
<itunes:subtitle>Javascript ReDOS; OpenSSH User Enum Update; Turning (Page) Tables Exploit Technique
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Javascript ReDOS; OpenSSH User Enum Update; Turning (Page) Tables Exploit Technique
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6132.mp3" length="4449588" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6132.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6132</link>
<pubDate>Mon, 20 Aug 2018 21:40:02 GMT</pubDate>
<description><![CDATA[Regular Expression DDoS in Javascript<br/>
<a href="http://mp.binaervarianz.de/ReDoS_TR_Dec2017.pdf">http://mp.binaervarianz.de/ReDoS_TR_Dec2017.pdf</a><br/>
OpenSSH User Enumeration Update<br/>
 <a href="https://isc.sans.edu/forums/diary/OpenSSH+user+enumeration+CVE201815473/24004">https://isc.sans.edu/forums/diary/OpenSSH+user+enumeration+CVE201815473/24004</a><br/>
Turning (Page) Tables Exploit Technique<br/>
 <a href="https://cdn2.hubspot.net/hubfs/487909/Turning%20(Page)%20Tables_Slides.pdf">https://cdn2.hubspot.net/hubfs/487909/Turning%20(Page)%20Tables_Slides.pdf</a><br/>
]]></description>
<itunes:duration>5:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6132" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 20th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6130</itunes:episode>
<itunes:subtitle>CVE-2018-8373 (VBScript Vulnerability); PHP Deserialization Vuln; HP Fax Patches
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
CVE-2018-8373 (VBScript Vulnerability); PHP Deserialization Vuln; HP Fax Patches
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6130.mp3" length="4955004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6130.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6130</link>
<pubDate>Sun, 19 Aug 2018 20:05:02 GMT</pubDate>
<description><![CDATA[<br/>
Fragmentsmack Summary<br/>
 <a href="https://isc.sans.edu/forums/diary/Back+to+the+90s+FragmentSmack/23998/">https://isc.sans.edu/forums/diary/Back+to+the+90s+FragmentSmack/23998/</a><br/>
HP Does Not Release Patches for Non-Windows Users<br/>
 <a href="https://www.intego.com/mac-security-blog/exclusive-hp-leaves-mac-users-vulnerable-to-fax-hacks/">https://www.intego.com/mac-security-blog/exclusive-hp-leaves-mac-users-vulnerable-to-fax-hacks/</a><br/>
More about VB Script 0-Day Vulnerability and "Dark Hotel" (chinese only)<br/>
 <a href="https://ti.360.net/blog/articles/analyzing-attack-of-cve-2018-8373-and-darkhotel/">https://ti.360.net/blog/articles/analyzing-attack-of-cve-2018-8373-and-darkhotel/</a><br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/use-after-free-uaf-vulnerability-cve-2018-8373-in-vbscript-engine-affects-internet-explorer-to-run-shellcode/">https://blog.trendmicro.com/trendlabs-security-intelligence/use-after-free-uaf-vulnerability-cve-2018-8373-in-vbscript-engine-affects-internet-explorer-to-run-shellcode/</a><br/>
PHP Deserialization Vulnerability Code Execution<br/>
 <a href="https://cdn2.hubspot.net/hubfs/3853213/us-18-Thomas-It's-A-PHP-Unserialization-Vulnerability-Jim-But-Not-As-We-....pdf?">https://cdn2.hubspot.net/hubfs/3853213/us-18-Thomas-It's-A-PHP-Unserialization-Vulnerability-Jim-But-Not-As-We-....pdf?</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6130" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 17th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6128</itunes:episode>
<itunes:subtitle>Anonymize pcaps; OpenSSH User Enum Vuln; VoiceXML #XXE;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Anonymize pcaps; OpenSSH User Enum Vuln; VoiceXML #XXE;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6128.mp3" length="5528809" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6128.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6128</link>
<pubDate>Fri, 17 Aug 2018 00:10:02 GMT</pubDate>
<description><![CDATA[Anonymize PCAPS<br/>
 <a href="https://isc.sans.edu/forums/diary/Truncating+Payloads+and+Anonymizing+PCAP+files/23990/">https://isc.sans.edu/forums/diary/Truncating+Payloads+and+Anonymizing+PCAP+files/23990/</a><br/>
OpenSSH User Enumeration Vulnerability<br/>
 <a href="http://seclists.org/oss-sec/2018/q3/124">http://seclists.org/oss-sec/2018/q3/124</a><br/>
VoiceXML XML External Entity Vulnerability<br/>
 <a href="https://hackerone.com/reports/395296">https://hackerone.com/reports/395296</a><br/>
Skimreaper Credit Card Skimmer Detector<br/>
 <a href="http://skimreaper.com">http://skimreaper.com</a>  <br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6128" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 16th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6126</itunes:episode>
<itunes:subtitle>Maldoc Ransomware; Linux IP Frag DoS; macOS Scripting Mouse Clicks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Maldoc Ransomware; Linux IP Frag DoS; macOS Scripting Mouse Clicks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6126.mp3" length="4846390" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6126.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6126</link>
<pubDate>Thu, 16 Aug 2018 01:05:02 GMT</pubDate>
<description><![CDATA[<br/>
Password Protected Word Documents Push AZORult and Hermes Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/More+malspam+pushing+passwordprotected+Word+docs+for+AZORult+and+Hermes+Ransomware/23992/">https://isc.sans.edu/forums/diary/More+malspam+pushing+passwordprotected+Word+docs+for+AZORult+and+Hermes+Ransomware/23992/</a><br/>
Linux IP Fragmentation DoS<br/>
 <a href="https://www.kb.cert.org/vuls/id/641765">https://www.kb.cert.org/vuls/id/641765</a><br/>
Scripting Mouse Clicks to Bypass macOS Security<br/>
 <a href="https://speakerdeck.com/patrickwardle/the-mouse-is-mightier-than-the-sword">https://speakerdeck.com/patrickwardle/the-mouse-is-mightier-than-the-sword</a><br/>
Concentration of Coinhive Miners<br/>
 <a href="https://arxiv.org/pdf/1808.00811.pdf">https://arxiv.org/pdf/1808.00811.pdf</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6126" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 15th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6124</itunes:episode>
<itunes:subtitle>#MSFT Patch Tuesday; Oracle Patch; Intel Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#MSFT Patch Tuesday; Oracle Patch; Intel Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6124.mp3" length="5211010" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6124.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6124</link>
<pubDate>Wed, 15 Aug 2018 11:41:56 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday Summary<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+August+2018+Patch+Tuesday/23986/">https://isc.sans.edu/forums/diary/Microsoft+August+2018+Patch+Tuesday/23986/</a><br/>
Oracle Database Patch<br/>
 <a href="http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.html">http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.html</a><br/>
Intel Fixes Three More CPU Flaws<br/>
 <a href="https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-fault">https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-fault</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6124" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 14th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6122</itunes:episode>
<itunes:subtitle>New Sextortion Wave; Intel Puma; btlejack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Sextortion Wave; Intel Puma; btlejack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6122.mp3" length="4263440" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6122.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6122</link>
<pubDate>Tue, 14 Aug 2018 02:10:02 GMT</pubDate>
<description><![CDATA[New Sextorition Wave Using Partial Phone Numbers<br/>
 New Extortion Tricks: Now Including Your (Partial) Phone Number!<br/>
Intel Releases Patch for Puma Modem Chips<br/>
 <a href="https://www.dslreports.com/forum/r32071020-Internet-Rogers-modem-router-rebooting-on-wan-scans-by-design">https://www.dslreports.com/forum/r32071020-Internet-Rogers-modem-router-rebooting-on-wan-scans-by-design</a><br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-000097.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-000097.html</a><br/>
Bluetooth Low Energy Attack Tool<br/>
 <a href="https://github.com/virtualabs/btlejack">https://github.com/virtualabs/btlejack</a><br/>
Tesla Will Fix Cars if Researcher Breaks it While Hacking<br/>
 <a href="https://twitter.com/bitquark/status/1028373178421309440">https://twitter.com/bitquark/status/1028373178421309440</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6122" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 13th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6120</itunes:episode>
<itunes:subtitle>VIA C3 "God Mode"; Apple MDM Vulnerability; Peeking into MSG Files; JA3
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VIA C3 "God Mode"; Apple MDM Vulnerability; Peeking into MSG Files; JA3
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6120.mp3" length="5156512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6120.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6120</link>
<pubDate>Mon, 13 Aug 2018 01:50:02 GMT</pubDate>
<description><![CDATA[VIA C3 "God Mode"<br/>
 <a href="https://github.com/xoreaxeaxeax/rosenbridge">https://github.com/xoreaxeaxeax/rosenbridge</a><br/>
Apple MDM Vulnerablity<br/>
 <a href="https://www.wired.com/story/mac-remote-hack-wifi-enterprise/">https://www.wired.com/story/mac-remote-hack-wifi-enterprise/</a><br/>
Peeking into MSG Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Peeking+into+msg+files+revisited/23974/">https://isc.sans.edu/forums/diary/Peeking+into+msg+files+revisited/23974/</a><br/>
Hunting SSL/TLS Clients Using JA3<br/>
 <a href="https://isc.sans.edu/forums/diary/Hunting+SSLTLS+clients+using+JA3/23972/">https://isc.sans.edu/forums/diary/Hunting+SSLTLS+clients+using+JA3/23972/</a><br/>
Mobile Payment Terminal Vulnerabilities<br/>
 <a href="https://www.blackhat.com/us-18/briefings.html#for-the-love-of-money-finding-and-exploiting-vulnerabilities-in-mobile-point-of-sales-systems">https://www.blackhat.com/us-18/briefings.html#for-the-love-of-money-finding-and-exploiting-vulnerabilities-in-mobile-point-of-sales-systems</a><br/>
]]></description>
<itunes:duration>6:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6120" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 10th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6118</itunes:episode>
<itunes:subtitle>Pacemaker/Insulin Pump Vuln; Panic Attacks; Process Doppleganging
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Pacemaker/Insulin Pump Vuln; Panic Attacks; Process Doppleganging
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6118.mp3" length="4402775" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6118.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6118</link>
<pubDate>Fri, 10 Aug 2018 01:30:03 GMT</pubDate>
<description><![CDATA[Vulnerabilities in Pacemaker Programmer and Insulin Pumps<br/>
 <a href="https://arstechnica.com/information-technology/2018/08/lack-of-encryption-makes-hacks-on-life-saving-pacemakers-shockingly-easy/">https://arstechnica.com/information-technology/2018/08/lack-of-encryption-makes-hacks-on-life-saving-pacemakers-shockingly-easy/</a><br/>
"Panic Attacks" Against City Infrastructure<br/>
 <a href="https://www.bbc.com/news/technology-45128053">https://www.bbc.com/news/technology-45128053</a><br/>
Kaspersky VPN Leaks DNS Traffic<br/>
 <a href="https://www.inputzero.io/2018/08/kaspersky-vpn-leaks-dns-address.html">https://www.inputzero.io/2018/08/kaspersky-vpn-leaks-dns-address.html</a><br/>
Osiris Dropper Uses Process Dopplegaenging<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2018/08/osiris-using-process-doppelganging/">https://blog.malwarebytes.com/threat-analysis/2018/08/osiris-using-process-doppelganging/</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6118" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6116</itunes:episode>
<itunes:subtitle>Homebrew Exposed Github Creds; WhatsApp Vuln.; Netflix AWS Methodology
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Homebrew Exposed Github Creds; WhatsApp Vuln.; Netflix AWS Methodology
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6116.mp3" length="4316105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6116.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6116</link>
<pubDate>Thu, 09 Aug 2018 02:30:02 GMT</pubDate>
<description><![CDATA[Homebrew Exposed Github Credentials<br/>
 <a href="https://brew.sh/2018/08/05/security-incident-disclosure/">https://brew.sh/2018/08/05/security-incident-disclosure/</a><br/>
WhatsApp Vulnerability<br/>
 <a href="https://research.checkpoint.com/fakesapp-a-vulnerability-in-whatsapp/">https://research.checkpoint.com/fakesapp-a-vulnerability-in-whatsapp/</a><br/>
Netflix Releases Tool To Detected Cloud Credential Compromise<br/>
 <a href="https://medium.com/netflix-techblog/netflix-cloud-security-detecting-credential-compromise-in-aws-9493d6fd373a">https://medium.com/netflix-techblog/netflix-cloud-security-detecting-credential-compromise-in-aws-9493d6fd373a</a><br/>
]]></description>
<itunes:duration>5:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6116" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 8th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6114</itunes:episode>
<itunes:subtitle>Linux TCP DoS; Android August Updates; Lets Encrypt Trusted;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Linux TCP DoS; Android August Updates; Lets Encrypt Trusted;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6114.mp3" length="4697181" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6114.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6114</link>
<pubDate>Wed, 08 Aug 2018 03:30:04 GMT</pubDate>
<description><![CDATA[Linux TCP DoS Vulnerability<br/>
 <a href="https://www.kb.cert.org/vuls/id/962459">https://www.kb.cert.org/vuls/id/962459</a><br/>
Let's Encrypt Now Trusted By All Major Root CA Programs<br/>
 <a href="https://letsencrypt.org/2018/08/06/trusted-by-all-major-root-programs.html">https://letsencrypt.org/2018/08/06/trusted-by-all-major-root-programs.html</a><br/>
Android Updates<br/>
 <a href="https://source.android.com/security/bulletin/2018-08-01">https://source.android.com/security/bulletin/2018-08-01</a><br/>
OpenEMR Vulnerabilities <br/>
 <a href="https://insecurity.sh/assets/reports/openemr.pdf">https://insecurity.sh/assets/reports/openemr.pdf</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6114" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 7th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6112</itunes:episode>
<itunes:subtitle>Numeric Obfuscation; Crestron Touchscreen Vulnerability; Facbook TLS 1.3;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Numeric Obfuscation; Crestron Touchscreen Vulnerability; Facbook TLS 1.3;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6112.mp3" length="4218091" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6112.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6112</link>
<pubDate>Tue, 07 Aug 2018 01:45:06 GMT</pubDate>
<description><![CDATA[Numeric Obfuscation<br/>
 <a href="https://isc.sans.edu/forums/diary/Numeric+obfuscation+another+example/23960/">https://isc.sans.edu/forums/diary/Numeric+obfuscation+another+example/23960/</a><br/>
Crestron Touchscreen Vulnerability<br/>
 <a href="https://blog.securitycompass.com/security-advisory-regarding-crestron-tsw-xx60-touch-panel-devices-9f1a71a926a5">https://blog.securitycompass.com/security-advisory-regarding-crestron-tsw-xx60-touch-panel-devices-9f1a71a926a5</a><br/>
Facebook Releases "Fizz" TLS 1.3 Library<br/>
 <a href="https://github.com/facebookincubator/fizz">https://github.com/facebookincubator/fizz</a><br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6112" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 6th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6110</itunes:episode>
<itunes:subtitle>New WPA Attack; Fake Techsupport Better Targeting; HP Printer Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New WPA Attack; Fake Techsupport Better Targeting; HP Printer Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6110.mp3" length="4643049" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6110.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6110</link>
<pubDate>Mon, 06 Aug 2018 01:55:02 GMT</pubDate>
<description><![CDATA[New WPA Attack<br/>
 <a href="https://hashcat.net/forum/thread-7717.html">https://hashcat.net/forum/thread-7717.html</a><br/>
Fake Techsupport Uses More Intelligent Call Routing<br/>
 <a href="https://www.symantec.com/blogs/threat-intelligence/tech-support-scam-call-optimization">https://www.symantec.com/blogs/threat-intelligence/tech-support-scam-call-optimization</a><br/>
HP Printer Updates<br/>
 <a href="https://support.hp.com/us-en/document/c06097712">https://support.hp.com/us-en/document/c06097712</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6110" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 3rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6108</itunes:episode>
<itunes:subtitle>Malware in Animated GIF files; MicroTik Miner Botnet; MSFT Edge Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware in Animated GIF files; MicroTik Miner Botnet; MSFT Edge Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6108.mp3" length="5480901" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6108.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6108</link>
<pubDate>Fri, 03 Aug 2018 02:15:07 GMT</pubDate>
<description><![CDATA[Malware in Animated GIF Files<br/>
 <a href="https://isc.sans.edu/forums/diary/DHLthemed+malspam+reveals+embedded+malware+in+animated+gif/23944/">https://isc.sans.edu/forums/diary/DHLthemed+malspam+reveals+embedded+malware+in+animated+gif/23944/</a><br/>
MikroTik Miner Botnet<br/>
 <a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/Mass-MikroTik-Router-Infection-%E2%80%93-First-we-cryptojack-Brazil,-then-we-take-the-World-/">https://www.trustwave.com/Resources/SpiderLabs-Blog/Mass-MikroTik-Router-Infection-%E2%80%93-First-we-cryptojack-Brazil,-then-we-take-the-World-/</a><br/>
Microsoft Edge Vulnerability<br/>
 <a href="https://www.netsparker.com/blog/web-security/stealing-local-files-with-simple-html-file/">https://www.netsparker.com/blog/web-security/stealing-local-files-with-simple-html-file/</a><br/>
]]></description>
<itunes:duration>6:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6108" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6106</itunes:episode>
<itunes:subtitle>Facebook #smishing; Port 52869 UPNP Attacks; Google/Microsoft Improve Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Facebook #smishing; Port 52869 UPNP Attacks; Google/Microsoft Improve Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6106.mp3" length="5421659" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6106.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6106</link>
<pubDate>Thu, 02 Aug 2018 01:05:02 GMT</pubDate>
<description><![CDATA[Facebook Smishing Attack<br/>
 <a href="https://isc.sans.edu/forums/diary/Facebook+Phishing+via+SMS/23940/">https://isc.sans.edu/forums/diary/Facebook+Phishing+via+SMS/23940/</a><br/>
Port 52869 UPNP Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/When+Cameras+and+Routers+attack+Phones+Spike+in+CVE20148361+Exploits+Against+Port+52869/23942/">https://isc.sans.edu/forums/diary/When+Cameras+and+Routers+attack+Phones+Spike+in+CVE20148361+Exploits+Against+Port+52869/23942/</a><br/>
Microsoft Improves Account Security for Midterm Elections<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-accountguard-service-offers-protection-for-political-and-election-orgs/">https://www.bleepingcomputer.com/news/microsoft/microsoft-accountguard-service-offers-protection-for-political-and-election-orgs/</a><br/>
Google Improves "Government Sponsored Attacks" Alert for GSuite<br/>
 <a href="https://9to5google.com/2018/08/01/g-suite-admins-government-based-attackers/">https://9to5google.com/2018/08/01/g-suite-admins-government-based-attackers/</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6106" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 1st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6104</itunes:episode>
<itunes:subtitle>Powershell Inside Certificates; TEMPEST is Back; Big Star Labs Spyware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Powershell Inside Certificates; TEMPEST is Back; Big Star Labs Spyware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6104.mp3" length="5391307" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6104.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6104</link>
<pubDate>Wed, 01 Aug 2018 01:55:04 GMT</pubDate>
<description><![CDATA[Powershell Inside Certificates<br/>
 <a href="https://blog.nviso.be/2018/07/31/powershell-inside-a-certificate-part-1/">https://blog.nviso.be/2018/07/31/powershell-inside-a-certificate-part-1/</a><br/>
TEMPEST is Back<br/>
 <a href="http://youtu.be/BpNP9b3aIfY?a">http://youtu.be/BpNP9b3aIfY?a</a><br/>
Big Star Labs Spyware<br/>
 <a href="https://adguard.com/en/blog/big-star-labs-spyware/">https://adguard.com/en/blog/big-star-labs-spyware/</a><br/>
]]></description>
<itunes:duration>6:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6104" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 31st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6102</itunes:episode>
<itunes:subtitle>DOSFuscation; Lets Encrypt Outage; Malvertising Campaign; Keepass Correction
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DOSFuscation; Lets Encrypt Outage; Malvertising Campaign; Keepass Correction
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6102.mp3" length="5846979" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6102.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6102</link>
<pubDate>Tue, 31 Jul 2018 01:45:05 GMT</pubDate>
<description><![CDATA[DOSFuscation Campaign<br/>
<a href="https://isc.sans.edu/forums/diary/Malicious+Word+documents+using+DOSfuscation/23932/">https://isc.sans.edu/forums/diary/Malicious+Word+documents+using+DOSfuscation/23932/</a><br/>
Let's Encrypt Outage<br/>
<a href="https://letsencrypt.status.io">https://letsencrypt.status.io</a><br/>
Malvertising Campaign Insides<br/>
<a href="https://research.checkpoint.com/malvertising-campaign-based-secrets-lies/">https://research.checkpoint.com/malvertising-campaign-based-secrets-lies/</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6102" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 30th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6100</itunes:episode>
<itunes:subtitle>Sextortion BTC Earnings; Adware Laced Downloads; PDF Editor Supply Chain Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sextortion BTC Earnings; Adware Laced Downloads; PDF Editor Supply Chain Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6100.mp3" length="6037514" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6100.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6100</link>
<pubDate>Mon, 30 Jul 2018 00:25:03 GMT</pubDate>
<description><![CDATA[Summary of Earchings in Recent Sextortion Attack<br/>
<a href="https://isc.sans.edu/forums/diary/Sextortion+Follow+the+Money/23922/">https://isc.sans.edu/forums/diary/Sextortion+Follow+the+Money/23922/</a><br/>
Adware Distributed with Legitimate Applications<br/>
<a href="https://www.bleepingcomputer.com/news/security/fake-websites-for-keepass-7zip-audacity-others-found-pushing-adware/">https://www.bleepingcomputer.com/news/security/fake-websites-for-keepass-7zip-audacity-others-found-pushing-adware/</a><br/>
<a href="https://twitter.com/JusticeRage">https://twitter.com/JusticeRage</a><br/>
PDF Editor Supply Chain Exploit<br/>
<a href="https://cloudblogs.microsoft.com/microsoftsecure/2018/07/26/attack-inception-compromised-supply-chain-within-a-supply-chain-poses-new-risks/">https://cloudblogs.microsoft.com/microsoftsecure/2018/07/26/attack-inception-compromised-supply-chain-within-a-supply-chain-poses-new-risks/</a><br/>
]]></description>
<itunes:duration>7:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6100" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6098</itunes:episode>
<itunes:subtitle>NetSpectre; Google Play Outlaws Miners; Japanese Calendar
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NetSpectre; Google Play Outlaws Miners; Japanese Calendar
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6098.mp3" length="13347411" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6098.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6098</link>
<pubDate>Fri, 27 Jul 2018 00:35:05 GMT</pubDate>
<description><![CDATA[NetSpectre: Read Arbitrary Memory over the Network<br/>
 <a href="https://misc0110.net/web/files/netspectre.pdf">https://misc0110.net/web/files/netspectre.pdf</a><br/>
Google Play Store Bans Crypto Miners<br/>
 <a href="https://play.google.com/about/developer-content-policy-print/">https://play.google.com/about/developer-content-policy-print/</a><br/>
Japanese Calendar Issues<br/>
 <a href="https://blogs.msdn.microsoft.com/shawnste/2018/04/12/the-japanese-calendars-y2k-moment/">https://blogs.msdn.microsoft.com/shawnste/2018/04/12/the-japanese-calendars-y2k-moment/</a><br/>
Multiple Vulnerabilities in Samsung SmartThings Hub<br/>
 <a href="https://blog.talosintelligence.com/2018/07/samsung-smartthings-vulns.html?m=1">https://blog.talosintelligence.com/2018/07/samsung-smartthings-vulns.html?m=1</a><br/>
Times Change and Your Training Data Should Too: The Effect of Training Data Recency on Twitter Classifiers. Ryan O'Grady<br/>
<a href="https://www.sans.org/reading-room/whitepapers/artificialintelligence/times-change-training-data-too-effect-training-data-recency-twitter-classifiers-38500">https://www.sans.org/reading-room/whitepapers/artificialintelligence/times-change-training-data-too-effect-training-data-recency-twitter-classifiers-38500</a>]]></description>
<itunes:duration>15:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6098" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6096</itunes:episode>
<itunes:subtitle>Etherscan.io XSS; Tomcast Patch; DNS over HTTPs: Centralized or not?; ERP Systems Targeted
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Etherscan.io XSS; Tomcast Patch; DNS over HTTPs: Centralized or not?; ERP Systems Targeted
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6096.mp3" length="4479209" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6096.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6096</link>
<pubDate>Thu, 26 Jul 2018 01:40:04 GMT</pubDate>
<description><![CDATA[Etherscan.io XSS Vulnerability<br/>
 <a href="https://scotthelme.co.uk/xss-on-etherscan-io/">https://scotthelme.co.uk/xss-on-etherscan-io/</a><br/>
Tomcat Vulnerabilities Patched<br/>
 <a href="https://www.us-cert.gov/ncas/current-activity/2018/07/23/Apache-Releases-Security-Updates-Apache-Tomcat">https://www.us-cert.gov/ncas/current-activity/2018/07/23/Apache-Releases-Security-Updates-Apache-Tomcat</a><br/>
DNS over HTTPS Standard Finalized<br/>
 <a href="https://datatracker.ietf.org/wg/doh/about/">https://datatracker.ietf.org/wg/doh/about/</a><br/>
ERP Systems Targeted in Recent Attacks<br/>
 <a href="https://www.us-cert.gov/ncas/current-activity/2018/07/25/Malicious-Cyber-Activity-Targeting-ERP-Applications">https://www.us-cert.gov/ncas/current-activity/2018/07/25/Malicious-Cyber-Activity-Targeting-ERP-Applications</a><br/>
]]></description>
<itunes:duration>5:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6096" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 25th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6094</itunes:episode>
<itunes:subtitle>Emotet Update; Clear Text Phone Tracking; Bluetooth Bug; Apache OpenWhisk Bug
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Update; Clear Text Phone Tracking; Bluetooth Bug; Apache OpenWhisk Bug
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6094.mp3" length="4404971" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6094.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6094</link>
<pubDate>Wed, 25 Jul 2018 03:05:02 GMT</pubDate>
<description><![CDATA[Emotet Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Recent+Emotet+activity/23908/">https://isc.sans.edu/forums/diary/Recent+Emotet+activity/23908/</a><br/>
Clear Text Phone Tracking<br/>
 <a href="https://isc.sans.edu/forums/diary/Cell+Phone+Monitoring+Who+is+Watching+the+Watchers/23910/">https://isc.sans.edu/forums/diary/Cell+Phone+Monitoring+Who+is+Watching+the+Watchers/23910/</a><br/>
Bluetooth Bug<br/>
 <a href="https://www.kb.cert.org/vuls/id/304725">https://www.kb.cert.org/vuls/id/304725</a><br/>
Apache OpenWhisk Vulnerability<br/>
 <a href="https://www.puresec.io/blog/Apache_OpenWhisk_Mutability_Weakness?hs_preview=EpJUmSoY-5972289702">https://www.puresec.io/blog/Apache_OpenWhisk_Mutability_Weakness?hs_preview=EpJUmSoY-5972289702</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6094" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 24th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6092</itunes:episode>
<itunes:subtitle>More Spectre; IE 0Day Patch Patched; HTTP Insecure; DNS Rebinding Again;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Spectre; IE 0Day Patch Patched; HTTP Insecure; DNS Rebinding Again;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6092.mp3" length="5345950" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6092.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6092</link>
<pubDate>Tue, 24 Jul 2018 02:00:25 GMT</pubDate>
<description><![CDATA[More Spectre<br/>
 <a href="https://arxiv.org/pdf/1807.07940.pdf">https://arxiv.org/pdf/1807.07940.pdf</a><br/>
July IE Patch Fixed older Remote Code Exec. Bug<br/>
 <a href="http://blogs.360.cn/blog/from-a-patched-itw-0day-to-remote-code-execution-part-i-from-patch-to-new-0day/">http://blogs.360.cn/blog/from-a-patched-itw-0day-to-remote-code-execution-part-i-from-patch-to-new-0day/</a><br/>
Google Chrome 68 Released Today. HTTP sites marked as "insecure"<br/>
 <a href="https://support.google.com/chrome/a/answer/7679408?hl=en">https://support.google.com/chrome/a/answer/7679408?hl=en</a> <br/>
DNS Rebinding Vulnerablity Common in IoT<br/>
 <a href="https://www.armis.com/dns-rebinding-exposes-half-a-billion-iot-devices-in-the-enterprise/">https://www.armis.com/dns-rebinding-exposes-half-a-billion-iot-devices-in-the-enterprise/</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6092" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 23rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6090</itunes:episode>
<itunes:subtitle>New WebLogic Vuln Exploited; MSFt Edge XSS Protection Issue; Intel ME
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New WebLogic Vuln Exploited; MSFt Edge XSS Protection Issue; Intel ME
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6090.mp3" length="4424714" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6090.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6090</link>
<pubDate>Mon, 23 Jul 2018 00:30:16 GMT</pubDate>
<description><![CDATA[New WebLogic Vulnerability Already Exploited <br/>
 <a href="https://isc.sans.edu/forums/diary/Weblogic+Exploit+Code+Made+Public+CVE20182893/23896/">https://isc.sans.edu/forums/diary/Weblogic+Exploit+Code+Made+Public+CVE20182893/23896/</a><br/>
Microsoft Edge Turns off XSS Protection<br/>
 <a href="https://portswigger.net/daily-swig/xss-protection-disappears-from-microsoft-edge">https://portswigger.net/daily-swig/xss-protection-disappears-from-microsoft-edge</a><br/>
Intel Management Engine Vulnerabilities<br/>
 <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.html">https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.html</a><br/>
User Tracking With TLS 1.2 Certificates<br/>
 <a href="http://tma.ifip.org/wordpress/wp-content/uploads/2017/06/tma2017_paper2.pdf">http://tma.ifip.org/wordpress/wp-content/uploads/2017/06/tma2017_paper2.pdf</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6090" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 20th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6088</itunes:episode>
<itunes:subtitle>Cisco Patches; Smart Vacuum Bugs; Instagram 2FA Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco Patches; Smart Vacuum Bugs; Instagram 2FA Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6088.mp3" length="4408622" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6088.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6088</link>
<pubDate>Fri, 20 Jul 2018 02:50:03 GMT</pubDate>
<description><![CDATA[Cisco Patches<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Diqee Smart Vacuum Vulnerabilities<br/>
 <a href="http://en.diqee.com/goods/1994.html">http://en.diqee.com/goods/1994.html</a><br/>
Instagram About To Release 2FA Update<br/>
 <a href="https://techcrunch.com/2018/07/17/instagram-2-factor/">https://techcrunch.com/2018/07/17/instagram-2-factor/</a><br/>
Reporting Malicious Websites<br/>
 <a href="https://isc.sans.edu/forums/diary/Reporting+Malicious+Websites+in+2018/23892/">https://isc.sans.edu/forums/diary/Reporting+Malicious+Websites+in+2018/23892/</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6088" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 19th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6086</itunes:episode>
<itunes:subtitle>Port 15454; Oracle CPU; Venmo Public API rediscovered; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Port 15454; Oracle CPU; Venmo Public API rediscovered; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6086.mp3" length="4492009" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6086.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6086</link>
<pubDate>Thu, 19 Jul 2018 01:55:02 GMT</pubDate>
<description><![CDATA[Increase in scans for port 15454<br/>
 <a href="https://isc.sans.edu/forums/diary/Request+for+Packets+Port+15454/23888/">https://isc.sans.edu/forums/diary/Request+for+Packets+Port+15454/23888/</a><br/>
Oracle Quarterly Critical Patch Update<br/>
 <a href="http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html">http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html</a><br/>
Venmo Public Transaction API<br/>
 <a href="https://publicbydefault.fyi">https://publicbydefault.fyi</a><br/>
Credential Stuffing Responsible for Majority of Login Attempts<br/>
 <a href="http://info.shapesecurity.com/2018-Credential-Spill-Report-by-Shape-Security">http://info.shapesecurity.com/2018-Credential-Spill-Report-by-Shape-Security</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6086" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 18th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6084</itunes:episode>
<itunes:subtitle>Geolocating Login Attempts; Typo3 Update; Money Laundry Scheme
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Geolocating Login Attempts; Typo3 Update; Money Laundry Scheme
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6084.mp3" length="4565886" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6084.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6084</link>
<pubDate>Wed, 18 Jul 2018 02:00:06 GMT</pubDate>
<description><![CDATA[Searching for Geographically Improbably Login Attempts<br/>
 <a href="https://isc.sans.edu/forums/diary/Searching+for+Geographically+Improbable+Login+Attempts/23882/">https://isc.sans.edu/forums/diary/Searching+for+Geographically+Improbable+Login+Attempts/23882/</a><br/>
Typo3 CMS Update<br/>
 <a href="https://typo3.org/article/typo3-931-8717-and-7630-security-releases-published/">https://typo3.org/article/typo3-931-8717-and-7630-security-releases-published/</a><br/>
GitHub Expands Security Scanner to Python<br/>
 <a href="https://blog.github.com/2018-07-12-security-vulnerability-alerts-for-python/">https://blog.github.com/2018-07-12-security-vulnerability-alerts-for-python/</a><br/>
Money Laundry Scheme Exposed by Open Mongo database.<br/>
 <a href="https://kromtech.com/blog/security-center/digital-laundry">https://kromtech.com/blog/security-center/digital-laundry</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6084" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 17th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6082</itunes:episode>
<itunes:subtitle>Encrypted SNI in TLS 1.3; Microsoft Will Retire "Delta Updates"; GPS Spoofing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Encrypted SNI in TLS 1.3; Microsoft Will Retire "Delta Updates"; GPS Spoofing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6082.mp3" length="6647162" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6082.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6082</link>
<pubDate>Tue, 17 Jul 2018 03:10:04 GMT</pubDate>
<description><![CDATA[Encrypted SNI in TLS 1.3<br/>
 <a href="https://tools.ietf.org/html/draft-rescorla-tls-esni-00">https://tools.ietf.org/html/draft-rescorla-tls-esni-00</a><br/>
Microsoft to Retire "Delta Updates" <br/>
 <a href="https://techcommunity.microsoft.com/t5/Windows-IT-Pro-Blog/Windows-10-quality-updates-explained-amp-the-end-of-delta/ba-p/214426">https://techcommunity.microsoft.com/t5/Windows-IT-Pro-Blog/Windows-10-quality-updates-explained-amp-the-end-of-delta/ba-p/214426</a><br/>
 <br/>
Practical GPS Spoofing of Navigation Devices<br/>
 <a href="https://www.microsoft.com/en-us/research/uploads/prod/2018/06/security18gps.pdf">https://www.microsoft.com/en-us/research/uploads/prod/2018/06/security18gps.pdf</a><br/>
]]></description>
<itunes:duration>7:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6082" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 16th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6080</itunes:episode>
<itunes:subtitle>Cryptominer Attached to JS; Dahua Vuln Exploited by Search Engine; iPhone MDM Spy Campaign
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cryptominer Attached to JS; Dahua Vuln Exploited by Search Engine; iPhone MDM Spy Campaign
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6080.mp3" length="6070796" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6080.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6080</link>
<pubDate>Mon, 16 Jul 2018 04:25:02 GMT</pubDate>
<description><![CDATA[Processing JSON<br/>
 <a href="https://isc.sans.edu/forums/diary/Video+Retrieving+and+processing+JSON+data+BTC+example/23874/">https://isc.sans.edu/forums/diary/Video+Retrieving+and+processing+JSON+data+BTC+example/23874/</a><br/>
Cryptocoin Mining Javascript (yet again)<br/>
 <a href="https://isc.sans.edu/forums/diary/Cryptominer+Delivered+Though+Compromized+JavaScript+File/23870/">https://isc.sans.edu/forums/diary/Cryptominer+Delivered+Though+Compromized+JavaScript+File/23870/</a><br/>
Dahua Passwords Leaked/Cached by Search Engine<br/>
 <a href="https://www.bleepingcomputer.com/news/security/passwords-for-tens-of-thousands-of-dahua-devices-cached-in-iot-search-engine/">https://www.bleepingcomputer.com/news/security/passwords-for-tens-of-thousands-of-dahua-devices-cached-in-iot-search-engine/</a><br/>
MDM Used in Targeted Attack Against iPhone Users<br/>
 <a href="https://blog.talosintelligence.com/2018/07/Mobile-Malware-Campaign-uses-Malicious-MDM.html">https://blog.talosintelligence.com/2018/07/Mobile-Malware-Campaign-uses-Malicious-MDM.html</a><br/>
]]></description>
<itunes:duration>7:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6080" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 13th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6078</itunes:episode>
<itunes:subtitle>Extortion With Password; npm Package Malware; CIRCL IMAP Proxy; Banking Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Extortion With Password; npm Package Malware; CIRCL IMAP Proxy; Banking Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6078.mp3" length="4967434" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6078.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6078</link>
<pubDate>Fri, 13 Jul 2018 02:05:02 GMT</pubDate>
<description><![CDATA[Extortion Claims Include Leaked Passwords to Appear more Plausiable<br/>
 <a href="https://isc.sans.edu/forums/diary/New+Extortion+Tricks+Now+Including+Your+Password/23866/">https://isc.sans.edu/forums/diary/New+Extortion+Tricks+Now+Including+Your+Password/23866/</a><br/>
npm Package Compromised and Used To Steal Credentials<br/>
 <a href="https://github.com/eslint/eslint-scope/issues/39#issuecomment-404533026">https://github.com/eslint/eslint-scope/issues/39#issuecomment-404533026</a><br/>
CIRCL IMAP Proxy<br/>
 <a href="https://github.com/CIRCL/IMAP-Proxy">https://github.com/CIRCL/IMAP-Proxy</a><br/>
Checkpoint Names "Dorkbot" As A Top Threat (Signup required)<br/>
 <a href="https://research.checkpoint.com/cyber-attack-trends-2018-mid-year-report/">https://research.checkpoint.com/cyber-attack-trends-2018-mid-year-report/</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6078" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 12th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6076</itunes:episode>
<itunes:subtitle>Hello Peppa Followup; Spectre 1.1/2; Site Isolation in Chrome
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hello Peppa Followup; Spectre 1.1/2; Site Isolation in Chrome
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6076.mp3" length="4866135" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6076.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6076</link>
<pubDate>Thu, 12 Jul 2018 01:55:03 GMT</pubDate>
<description><![CDATA[Hello Peppa Followup<br/>
 <a href="https://isc.sans.edu/forums/diary/Well+Hello+Again+Peppa/23860/">https://isc.sans.edu/forums/diary/Well+Hello+Again+Peppa/23860/</a><br/>
Spectre 1.1 and 1.2<br/>
 <a href="https://people.csail.mit.edu/vlk/spectre11.pdf">https://people.csail.mit.edu/vlk/spectre11.pdf</a><br/>
Internet Exchanges Band Together against BGP Hijacking<br/>
 <a href="https://dyn.com/blog/shutting-down-the-bgp-hijack-factory/">https://dyn.com/blog/shutting-down-the-bgp-hijack-factory/</a><br/>
Google Enabled Site Isolation in Chrome<br/>
 <a href="https://www.bleepingcomputer.com/news/security/google-enables-site-isolation-feature-for-99-percent-of-chrome-desktop-users/">https://www.bleepingcomputer.com/news/security/google-enables-site-isolation-feature-for-99-percent-of-chrome-desktop-users/</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6076" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 11th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6074</itunes:episode>
<itunes:subtitle>MSFT Patch Tueday; SettingContent-ms Files Blacklisted; Adobe Patches; Stolen DLINK Certificate;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tueday; SettingContent-ms Files Blacklisted; Adobe Patches; Stolen DLINK Certificate;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6074.mp3" length="5113726" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6074.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6074</link>
<pubDate>Wed, 11 Jul 2018 01:30:11 GMT</pubDate>
<description><![CDATA[MSFT Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+July+2018+now+with+Dashboard/23858/">https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+July+2018+now+with+Dashboard/23858/</a><br/>
 <a href="https://patchtuesdaydashboard.com/">https://patchtuesdaydashboard.com/</a><br/>
SettingContent-ms Files Blacklisted<br/>
  <a href="https://support.office.com/en-us/article/packager-activation-in-office-365-desktop-applications-52808039-4a7c-4550-be3a-869dd338d834?ui=en-US&rs=en-US&ad=US">https://support.office.com/en-us/article/packager-activation-in-office-365-desktop-applications-52808039-4a7c-4550-be3a-869dd338d834?ui=en-US&rs=en-US&ad=US</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Stolen DLINK Certificate<br/>
 <a href="https://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/">https://www.welivesecurity.com/2018/07/09/certificates-stolen-taiwanese-tech-companies-plead-malware-campaign/</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6074" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 10th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6072</itunes:episode>
<itunes:subtitle>Reverse Shell via Weblogic; Apple Patchesi; Hardening Azure AD Password Selection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Reverse Shell via Weblogic; Apple Patchesi; Hardening Azure AD Password Selection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6072.mp3" length="4816762" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6072.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6072</link>
<pubDate>Tue, 10 Jul 2018 01:40:02 GMT</pubDate>
<description><![CDATA[Reverse Shell via Weblogic Flaw<br/>
 <a href="https://isc.sans.edu/forums/diary/Criminals+Dont+Read+Instructions+or+Use+Strong+Passwords/23850/">https://isc.sans.edu/forums/diary/Criminals+Dont+Read+Instructions+or+Use+Strong+Passwords/23850/</a><br/>
Apple Patches Everything Again<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Patches+Everything+Again/23852/">https://isc.sans.edu/forums/diary/Apple+Patches+Everything+Again/23852/</a><br/>
Microsoft Offers Better Azure AD Password Protection<br/>
 <a href="http://www.longevitytech.us/2018/07/09/azure-ad-password-protection-the-cloud-security-service-your-active-directory-needs-now/">http://www.longevitytech.us/2018/07/09/azure-ad-password-protection-the-cloud-security-service-your-active-directory-needs-now/</a> <br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6072" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6070</itunes:episode>
<itunes:subtitle>HP iLO 4 Exploit; Miner/Ransomware; Online Gas Station Heist;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HP iLO 4 Exploit; Miner/Ransomware; Online Gas Station Heist;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6070.mp3" length="3691091" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6070.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6070</link>
<pubDate>Mon, 09 Jul 2018 02:10:02 GMT</pubDate>
<description><![CDATA[Trivial Exploit For HP iLO 4 (patched last August)<br/>
 <a href="https://airbus-seclab.github.io/ilo/SSTIC2018-Article-subverting_your_server_through_its_bmc_the_hpe_ilo4_case-gazet_perigaud_czarny.pdf">https://airbus-seclab.github.io/ilo/SSTIC2018-Article-subverting_your_server_through_its_bmc_the_hpe_ilo4_case-gazet_perigaud_czarny.pdf</a><br/>
Flexible Miner/Ransomware<br/>
 <a href="https://securelist.com/to-crypt-or-to-mine-that-is-the-question/86307/">https://securelist.com/to-crypt-or-to-mine-that-is-the-question/86307/</a><br/>
Hacker Steals Gas From Gas Station<br/>
 <a href="https://gizmodo.com/hackers-reportedly-stole-600-gallons-of-gas-from-detroi-1827433411">https://gizmodo.com/hackers-reportedly-stole-600-gallons-of-gas-from-detroi-1827433411</a><br/>
]]></description>
<itunes:duration>4:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6070" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 6th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6068</itunes:episode>
<itunes:subtitle>Gentoo GitHub Breach PM; World Cup Used to Trap Israeli Soldiers
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Gentoo GitHub Breach PM; World Cup Used to Trap Israeli Soldiers
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6068.mp3" length="4304394" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6068.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6068</link>
<pubDate>Fri, 06 Jul 2018 00:45:04 GMT</pubDate>
<description><![CDATA[Gentoo GitHub Breach Post Morten<br/>
 <a href="https://wiki.gentoo.org/wiki/Github/2018-06-28">https://wiki.gentoo.org/wiki/Github/2018-06-28</a><br/>
Hamas Sets World Cup Trap for Israeli Soldiers<br/>
 <a href="https://www.reuters.com/article/us-israel-palestinians-cyber/israel-says-hamas-tried-to-snare-soldiers-in-world-cup-cyber-trap-idUSKBN1JT1ZX">https://www.reuters.com/article/us-israel-palestinians-cyber/israel-says-hamas-tried-to-snare-soldiers-in-world-cup-cyber-trap-idUSKBN1JT1ZX</a><br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6068" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6066</itunes:episode>
<itunes:subtitle>Watching Progress For Windows Scripts; Sylish Extension Steals History
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Watching Progress For Windows Scripts; Sylish Extension Steals History
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6066.mp3" length="2725244" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6066.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6066</link>
<pubDate>Thu, 05 Jul 2018 03:25:02 GMT</pubDate>
<description><![CDATA[Progress Indication For Scripts in Windows<br/>
<a href="https://isc.sans.edu/forums/diary/Progress+indication+for+scripts+on+Windows/23830/">https://isc.sans.edu/forums/diary/Progress+indication+for+scripts+on+Windows/23830/</a><br/>
Stylish Extension Steals History<br/>
<a href="https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/">https://robertheaton.com/2018/07/02/stylish-browser-extension-steals-your-internet-history/</a><br/>
Data Leaks From Android Apps<br/>
 <a href="https://recon.meddle.mobi/panoptispy/">https://recon.meddle.mobi/panoptispy/</a><br/>
]]></description>
<itunes:duration>3:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6066" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 3rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6064</itunes:episode>
<itunes:subtitle>Odd PHP Exploit Attempt; Diameter Security; Attack Against Trezor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd PHP Exploit Attempt; Diameter Security; Attack Against Trezor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6064.mp3" length="4530773" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6064.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6064</link>
<pubDate>Mon, 02 Jul 2018 22:25:03 GMT</pubDate>
<description><![CDATA[Odd PHP Exploit Attempt<br/>
 <a href="https://isc.sans.edu/forums/diary/Hello+Peppa+PHP+Scans/23826/">https://isc.sans.edu/forums/diary/Hello+Peppa+PHP+Scans/23826/</a><br/>
Diameter Security Report<br/>
 <a href="https://www.ptsecurity.com/ww-en/premium/diameter-2018/">https://www.ptsecurity.com/ww-en/premium/diameter-2018/</a><br/>
Attack Against Trezor via DNS or BGP<br/>
 <a href="https://blog.trezor.io/psa-phishing-alert-fake-trezor-wallet-website-3bcfdfc3eced">https://blog.trezor.io/psa-phishing-alert-fake-trezor-wallet-website-3bcfdfc3eced</a><br/>
Symantec Offers VPNFilter Check<br/>
 <a href="http://www.symantec.com/filtercheck/">http://www.symantec.com/filtercheck/</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6064" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6062</itunes:episode>
<itunes:subtitle>MacOS Malware; LTE Attacks; Rowhammer Exploit For Android (and counter measure)
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MacOS Malware; LTE Attacks; Rowhammer Exploit For Android (and counter measure)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6062.mp3" length="5458222" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6062.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6062</link>
<pubDate>Mon, 02 Jul 2018 01:30:05 GMT</pubDate>
<description><![CDATA[MacOS Malware Targeting Slack/Dicord Crypto Comunities<br/>
 <a href="https://isc.sans.edu/forums/diary/Crypto+community+target+of+MacOS+malware/23816/">https://isc.sans.edu/forums/diary/Crypto+community+target+of+MacOS+malware/23816/</a><br/>
New LTE Attacks Made Public<br/>
 <a href="https://alter-attack.net">https://alter-attack.net</a><br/>
Rowhammer Attacks Against Android<br/>
 <a href="https://rampageattack.com">https://rampageattack.com</a><br/>
]]></description>
<itunes:duration>6:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6062" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 29th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6060</itunes:episode>
<itunes:subtitle>Nice Miners; Disassembling Webassembly; Spectre Browser Bypass; Gentoo Github Repo Takeover
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Nice Miners; Disassembling Webassembly; Spectre Browser Bypass; Gentoo Github Repo Takeover
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6060.mp3" length="5072760" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6060.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6060</link>
<pubDate>Fri, 29 Jun 2018 03:40:03 GMT</pubDate>
<description><![CDATA[Less Greedy Cryptominers<br/>
 <a href="https://isc.sans.edu/forums/diary/New+and+Improved+Cryptominers+Now+with+50+less+Greed/23812/">https://isc.sans.edu/forums/diary/New+and+Improved+Cryptominers+Now+with+50+less+Greed/23812/</a><br/>
Disassemling Webassembly<br/>
 <a href="https://www.forcepoint.com/blog/security-labs/analyzing-webassembly-binaries">https://www.forcepoint.com/blog/security-labs/analyzing-webassembly-binaries</a><br/>
Spectre Browser Mitigation Bypass<br/>
 <a href="https://alephsecurity.com/2018/06/26/spectre-browser-query-cache/">https://alephsecurity.com/2018/06/26/spectre-browser-query-cache/</a><br/>
Gentoo Github Repository Compromise<br/>
 <a href="https://archives.gentoo.org/gentoo-announce/message/dc23d48d2258e1ed91599a8091167002">https://archives.gentoo.org/gentoo-announce/message/dc23d48d2258e1ed91599a8091167002</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6060" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 28th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6058</itunes:episode>
<itunes:subtitle>Magic Unicorn O365 API; Anonymizing Printers; Malware Analysis Opsec; CVE-2018-0296 (Cisco) Exploite</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Magic Unicorn O365 API; Anonymizing Printers; Malware Analysis Opsec; CVE-2018-0296 (Cisco) Exploite</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6058.mp3" length="6250729" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6058.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6058</link>
<pubDate>Wed, 27 Jun 2018 23:25:03 GMT</pubDate>
<description><![CDATA[Secret Office 365 Activity Log API Unveiled (plus tool to extract logs)<br/>
 <a href="http://lmgsecurity.com/exposing-the-secret-office-365-forensics-tool/">http://lmgsecurity.com/exposing-the-secret-office-365-forensics-tool/</a><br/>
Anonymizing Printers<br/>
 <a href="https://tu-dresden.de/ing/informatik/sya/ps/die-professur/news/geheime-daten-auf-dem-druckpapier-diplominformatiker-der-tu-dresden-entwickeln-verfahren-gegen-druckerueberwachung">https://tu-dresden.de/ing/informatik/sya/ps/die-professur/news/geheime-daten-auf-dem-druckpapier-diplominformatiker-der-tu-dresden-entwickeln-verfahren-gegen-druckerueberwachung</a><br/>
Silently Profiling Unknown Malware Samples<br/>
 <a href="https://isc.sans.edu/forums/diary/Silently+Profiling+Unknown+Malware+Samples/23808/">https://isc.sans.edu/forums/diary/Silently+Profiling+Unknown+Malware+Samples/23808/</a><br/>
Cisco CVE-2018-0296 Exploited<br/>
 <a href="https://www.bleepingcomputer.com/news/security/cisco-asa-flaw-exploited-in-the-wild-after-publication-of-two-pocs/">https://www.bleepingcomputer.com/news/security/cisco-asa-flaw-exploited-in-the-wild-after-publication-of-two-pocs/</a><br/>
]]></description>
<itunes:duration>7:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6058" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6056</itunes:episode>
<itunes:subtitle>Analyzing XPS Files; WPA3 Finalized
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing XPS Files; WPA3 Finalized
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6056.mp3" length="6093108" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6056.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6056</link>
<pubDate>Wed, 27 Jun 2018 07:00:59 GMT</pubDate>
<description><![CDATA[Analyzing XPS Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+XPS+files/23804/">https://isc.sans.edu/forums/diary/Analyzing+XPS+files/23804/</a><br/>
WPA3 Standard Finalized<br/>
 <a href="https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-wi-fi-certified-wpa3-security">https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-wi-fi-certified-wpa3-security</a><br/>
Executing Code with SettingContent-ms Files<br/>
 <a href="https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39">https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39</a><br/>
EFF Analysis of STARTTLS<br/>
 <a href="https://www.eff.org/deeplinks/2018/06/technical-deep-dive-starttls-everywhere">https://www.eff.org/deeplinks/2018/06/technical-deep-dive-starttls-everywhere</a><br/>
]]></description>
<itunes:duration>7:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6056" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6054</itunes:episode>
<itunes:subtitle>Guilty by Association; Filezila; iOS Pin Brute Forcing; Azure AD to Enforce 2FA
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Guilty by Association; Filezila; iOS Pin Brute Forcing; Azure AD to Enforce 2FA
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6054.mp3" length="6162956" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6054.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6054</link>
<pubDate>Tue, 26 Jun 2018 02:00:05 GMT</pubDate>
<description><![CDATA[Guilty By Association<br/>
 <a href="https://isc.sans.edu/forums/diary/Guilty+by+association/23800/">https://isc.sans.edu/forums/diary/Guilty+by+association/23800/</a><br/>
Filezila and Adware<br/>
 <a href="https://forum.filezilla-project.org/viewtopic.php?t=48441">https://forum.filezilla-project.org/viewtopic.php?t=48441</a><br/>
iOS Pin Brute Forcing Confusion<br/>
 <a href="https://twitter.com/hackerfantastic/status/1010631766087032832">https://twitter.com/hackerfantastic/status/1010631766087032832</a><br/>
 <a href="https://twitter.com/hackerfantastic/status/1010240042990596096">https://twitter.com/hackerfantastic/status/1010240042990596096</a><br/>
Azure Baseline Security Policy<br/>
 <a href="https://cloudblogs.microsoft.com/enterprisemobility/2018/06/22/baseline-security-policy-for-azure-ad-admin-accounts-in-public-preview/">https://cloudblogs.microsoft.com/enterprisemobility/2018/06/22/baseline-security-policy-for-azure-ad-admin-accounts-in-public-preview/</a><br/>
Phone Battery Usage as Keystroke Logger<br/>
 <a href="https://sites.google.com/site/silbersteinmark/Home/popets18power.pdf?attredirects=1">https://sites.google.com/site/silbersteinmark/Home/popets18power.pdf?attredirects=1</a><br/>
]]></description>
<itunes:duration>7:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6054" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 25th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6052</itunes:episode>
<itunes:subtitle>XPS Spam; Exploit Kit Trends; IETF Works To Deprecate TLS 1.0/1, Firebase Leaks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XPS Spam; Exploit Kit Trends; IETF Works To Deprecate TLS 1.0/1, Firebase Leaks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6052.mp3" length="4771411" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6052.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6052</link>
<pubDate>Mon, 25 Jun 2018 00:40:02 GMT</pubDate>
<description><![CDATA[XPS Documents Used for Spam<br/>
 <a href="https://isc.sans.edu/forums/diary/XPS+Attachment+Used+for+Phishing/23794/">https://isc.sans.edu/forums/diary/XPS+Attachment+Used+for+Phishing/23794/</a><br/>
New Exploit Kit Trends<br/>
 <a href="https://researchcenter.paloaltonetworks.com/2018/06/unit42-the-old-and-new-current-trends-in-web-based-threats/">https://researchcenter.paloaltonetworks.com/2018/06/unit42-the-old-and-new-current-trends-in-web-based-threats/</a><br/>
 <a href="https://blog.malwarebytes.com/cybercrime/2018/06/exploit-kits-spring-2018-review/">https://blog.malwarebytes.com/cybercrime/2018/06/exploit-kits-spring-2018-review/</a><br/>
Deprecating TLSv1.0 and TLSv1.1<br/>
 <a href="https://datatracker.ietf.org/doc/draft-moriarty-tls-oldversions-diediedie/">https://datatracker.ietf.org/doc/draft-moriarty-tls-oldversions-diediedie/</a><br/>
Leaky Firebase Installs<br/>
 <a href="http://info.appthority.com/-q2-2018-mtr-download-Firebase-vulnerability">http://info.appthority.com/-q2-2018-mtr-download-Firebase-vulnerability</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6052" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 22nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6050</itunes:episode>
<itunes:subtitle>Fake Android Fortnite; Fake Wannacry E-Mails; Cisco Bulletins; SamSam Ransomware; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake Android Fortnite; Fake Wannacry E-Mails; Cisco Bulletins; SamSam Ransomware; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6050.mp3" length="4910382" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6050.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6050</link>
<pubDate>Fri, 22 Jun 2018 03:15:02 GMT</pubDate>
<description><![CDATA[Fake Fortnite<br/>
 <a href="https://blog.malwarebytes.com/cybercrime/2018/06/fake-fortnite-android-links-found-youtube/">https://blog.malwarebytes.com/cybercrime/2018/06/fake-fortnite-android-links-found-youtube/</a><br/>
Fake Wannacry E-Mails<br/>
 <a href="https://twitter.com/actionfrauduk/status/1009803967705092096">https://twitter.com/actionfrauduk/status/1009803967705092096</a><br/>
Ransomware Installs In Internet Cafes<br/>
 <a href="http://hznews.hangzhou.com.cn/shehui/content/2018-06/16/content_7020998.htm">http://hznews.hangzhou.com.cn/shehui/content/2018-06/16/content_7020998.htm</a><br/>
OpenVPN Malicious Configuration Files<br/>
 <a href="https://medium.com/tenable-techblog/reverse-shell-from-an-openvpn-configuration-file-73fd8b1d38da">https://medium.com/tenable-techblog/reverse-shell-from-an-openvpn-configuration-file-73fd8b1d38da</a><br/>
 <br/>
Cisco Advisories<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6050" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 21st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6048</itunes:episode>
<itunes:subtitle>TLS Phishing; OpenBSD Disables Hyperthreading; Bithumb Breach;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
TLS Phishing; OpenBSD Disables Hyperthreading; Bithumb Breach;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6048.mp3" length="5763598" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6048.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6048</link>
<pubDate>Thu, 21 Jun 2018 03:30:02 GMT</pubDate>
<description><![CDATA[Netflix Phishing Sites Using TLS<br/>
 <a href="https://isc.sans.edu/forums/diary/Secure+Phishing+Netflix+Phishing+Goes+TLS/23786/">https://isc.sans.edu/forums/diary/Secure+Phishing+Netflix+Phishing+Goes+TLS/23786/</a><br/>
OpenBSD Disables Hyperthreading By Default<br/>
 <a href="https://www.mail-archive.com/source-changes@openbsd.org/msg99141.html">https://www.mail-archive.com/source-changes@openbsd.org/msg99141.html</a><br/>
Bithumb Cyrpto Currency Exchnage Breached Again<br/>
 <a href="https://www.bleepingcomputer.com/news/security/bithumb-hacked-second-time-in-a-year-hackers-steal-31-million/">https://www.bleepingcomputer.com/news/security/bithumb-hacked-second-time-in-a-year-hackers-steal-31-million/</a><br/>
Microsoft Edge CORS Bypass via Audio Files<br/>
 <a href="https://jakearchibald.com/2018/i-discovered-a-browser-bug/">https://jakearchibald.com/2018/i-discovered-a-browser-bug/</a><br/>
Microsoft Releases a Special Patch for Oracle Outside-In Libraries<br/>
 <a href="https://support.microsoft.com/en-us/help/4092041/description-of-the-security-update-for-microsoft-exchange-server-2013">https://support.microsoft.com/en-us/help/4092041/description-of-the-security-update-for-microsoft-exchange-server-2013</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6048" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 20th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6046</itunes:episode>
<itunes:subtitle>Malicious PS Script Disables Logging; Virustotal Monitor Service; Exposed Cloud Environments; Google</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious PS Script Disables Logging; Virustotal Monitor Service; Exposed Cloud Environments; Google</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6046.mp3" length="4644514" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6046.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6046</link>
<pubDate>Tue, 19 Jun 2018 23:55:02 GMT</pubDate>
<description><![CDATA[PowerShell ScriptBlock Loggin Bypass in the Wild<br/>
 <a href="https://isc.sans.edu/forums/diary/PowerShell+ScriptBlock+Logging+Or+Not/23782/">https://isc.sans.edu/forums/diary/PowerShell+ScriptBlock+Logging+Or+Not/23782/</a><br/>
Virustotal "False Positive" Alert<br/>
 <a href="http://blog.virustotal.com/2018/06/vtmonitor-to-mitigate-false-positives.html">http://blog.virustotal.com/2018/06/vtmonitor-to-mitigate-false-positives.html</a><br/>
Cloud Environments Explosed to the Internet<br/>
 <a href="https://info.lacework.com/hubfs/Containers%20At-Risk_%20A%20Review%20of%2021,000%20Cloud%20Environments.pdf">https://info.lacework.com/hubfs/Containers%20At-Risk_%20A%20Review%20of%2021,000%20Cloud%20Environments.pdf</a><br/>
Google Home DNS Rebinding Attack Reveals Geolocation<br/>
 <a href="https://www.tripwire.com/state-of-security/vert/googles-newest-feature-find-my-home">https://www.tripwire.com/state-of-security/vert/googles-newest-feature-find-my-home</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6046" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 19th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6044</itunes:episode>
<itunes:subtitle>Obfuscated JavaScript Targeting Mobile Devices; Axis Camera Vulnerabilities; Old Apple Cache Leak; A</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Obfuscated JavaScript Targeting Mobile Devices; Axis Camera Vulnerabilities; Old Apple Cache Leak; A</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6044.mp3" length="4964144" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6044.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6044</link>
<pubDate>Tue, 19 Jun 2018 01:35:03 GMT</pubDate>
<description><![CDATA[Obfuscated JavaScript Targeting Mobile Devices<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+JavaScript+Targeting+Mobile+Browsers/23778/">https://isc.sans.edu/forums/diary/Malicious+JavaScript+Targeting+Mobile+Browsers/23778/</a><br/>
Axis Camera Vulnerabilities<br/>
 <a href="https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/">https://blog.vdoo.com/2018/06/18/vdoo-discovers-significant-vulnerabilities-in-axis-cameras/</a><br/>
Apple Caches Confidential Data on Unencrypted Drives<br/>
 <a href="https://wojciechregula.blog/your-encrypted-photos-in-macos-cache/">https://wojciechregula.blog/your-encrypted-photos-in-macos-cache/</a><br/>
Andy Emulator Infected With CryptoMiner<br/>
 <a href="https://www.reddit.com/r/emulators/comments/8rj8g5/warning_andy_android_emulator_andyos_andyroid/">https://www.reddit.com/r/emulators/comments/8rj8g5/warning_andy_android_emulator_andyos_andyroid/</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6044" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 18th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6042</itunes:episode>
<itunes:subtitle>SMTP Exfil Puzzle; Encrypted Office Documents; Recent Port 8000 Scans; WebUSB Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SMTP Exfil Puzzle; Encrypted Office Documents; Recent Port 8000 Scans; WebUSB Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6042.mp3" length="5510520" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6042.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6042</link>
<pubDate>Mon, 18 Jun 2018 00:20:02 GMT</pubDate>
<description><![CDATA[SMTP Strangeness - Possible C2<br/>
 <a href="https://isc.sans.edu/forums/diary/SMTP+Strangeness+Possible+C2/23770/">https://isc.sans.edu/forums/diary/SMTP+Strangeness+Possible+C2/23770/</a><br/>
Encrypted Office Documents<br/>
 <a href="https://isc.sans.edu/forums/diary/Encrypted+Office+Documents/23774/">https://isc.sans.edu/forums/diary/Encrypted+Office+Documents/23774/</a><br/>
Recent Port 8000 Scans<br/>
 <a href="https://www.bleepingcomputer.com/news/security/all-that-port-8000-traffic-this-week-yeah-thats-satori-looking-for-new-bots/">https://www.bleepingcomputer.com/news/security/all-that-port-8000-traffic-this-week-yeah-thats-satori-looking-for-new-bots/</a><br/>
New Clipboard Cryptocoin Stealing Bot<br/>
 <a href="https://blog.360totalsecurity.com/en/new-cryptominer-hijacks-your-bitcoin-transaction-over-300000-computers-have-been-attacked/">https://blog.360totalsecurity.com/en/new-cryptominer-hijacks-your-bitcoin-transaction-over-300000-computers-have-been-attacked/</a><br/>
WebUSB Weakness<br/>
 <a href="https://pwnaccelerator.github.io/2018/webusb-yubico-disclosure.html">https://pwnaccelerator.github.io/2018/webusb-yubico-disclosure.html</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6042" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 15th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6040</itunes:episode>
<itunes:subtitle>A WordPress Compromise; Not-So-Smart Padlock; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
A WordPress Compromise; Not-So-Smart Padlock; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6040.mp3" length="10292965" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6040.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6040</link>
<pubDate>Fri, 15 Jun 2018 01:30:03 GMT</pubDate>
<description><![CDATA[Analyzing a Compromised Wordpress Site<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Bunch+of+Compromized+Wordpress+Sites/23764/">https://isc.sans.edu/forums/diary/A+Bunch+of+Compromized+Wordpress+Sites/23764/</a><br/>
Breacking Bluetooth Low Energy Smart Padlock<br/>
 <a href="https://www.pentestpartners.com/security-blog/totally-pwning-the-tapplock-smart-lock/">https://www.pentestpartners.com/security-blog/totally-pwning-the-tapplock-smart-lock/</a><br/>
WIM Disk Image Vulnerability<br/>
 <a href="https://blog.talosintelligence.com/2018/06/vulnerability-spotlight-talos-2018-0545.html">https://blog.talosintelligence.com/2018/06/vulnerability-spotlight-talos-2018-0545.html</a><br/>
Extracting Timely Sign-In Data from Office 365 Logs<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/logging/extracting-timely-sign-in-data-office-365-logs-38435">https://www.sans.org/reading-room/whitepapers/logging/extracting-timely-sign-in-data-office-365-logs-38435</a><br/>
]]></description>
<itunes:duration>12:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6040" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 14th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6038</itunes:episode>
<itunes:subtitle>Yet Another Router Botnet? Cortana FTW; Compromised #docker Images; Lazy FPU
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Yet Another Router Botnet? Cortana FTW; Compromised #docker Images; Lazy FPU
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6038.mp3" length="4954638" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6038.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6038</link>
<pubDate>Thu, 14 Jun 2018 00:45:04 GMT</pubDate>
<description><![CDATA[From MicroTik With Love: Yet Another Router Botnet?<br/>
 <a href="https://isc.sans.edu/forums/diary/From+Microtik+with+Love/23762/">https://isc.sans.edu/forums/diary/From+Microtik+with+Love/23762/</a><br/>
Using Cortana To Compromise Windows 10<br/>
 <a href="https://securingtomorrow.mcafee.com/mcafee-labs/want-to-break-into-a-locked-windows-10-device-ask-cortana-cve-2018-8140/">https://securingtomorrow.mcafee.com/mcafee-labs/want-to-break-into-a-locked-windows-10-device-ask-cortana-cve-2018-8140/</a><br/>
Compromised Docker Images<br/>
 <a href="https://kromtech.com/blog/security-center/cryptojacking-invades-cloud-how-modern-containerization-trend-is-exploited-by-attackers">https://kromtech.com/blog/security-center/cryptojacking-invades-cloud-how-modern-containerization-trend-is-exploited-by-attackers</a><br/>
Lazy FPU Save/Restore Allows Malware Access to FPU<br/>
 <a href="https://access.redhat.com/solutions/3485131">https://access.redhat.com/solutions/3485131</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6038" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 13th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6036</itunes:episode>
<itunes:subtitle>#MSFT Patch Tuesday; OS X Security Tools Code Verification Fail; Google Chrome Restricts Extension I</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#MSFT Patch Tuesday; OS X Security Tools Code Verification Fail; Google Chrome Restricts Extension I</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6036.mp3" length="4910388" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6036.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6036</link>
<pubDate>Wed, 13 Jun 2018 00:55:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+June+2018+Patch+Tuesday/23758/">https://isc.sans.edu/forums/diary/Microsoft+June+2018+Patch+Tuesday/23758/</a><br/>
Apple Code Signing Verification Vulnerability<br/>
 <a href="https://www.okta.com/security-blog/2018/06/issues-around-third-party-apple-code-signing-checks/">https://www.okta.com/security-blog/2018/06/issues-around-third-party-apple-code-signing-checks/</a><br/>
Google Chrome Restricting Inline Extension Install<br/>
 <a href="https://blog.chromium.org/2018/06/improving-extension-transparency-for.html">https://blog.chromium.org/2018/06/improving-extension-transparency-for.html</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6036" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 12th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6034</itunes:episode>
<itunes:subtitle>Lokibot Update; ETH JSON RPC Theft; Cryto Currency Miners Hiding; FBI BEC Arrest
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Lokibot Update; ETH JSON RPC Theft; Cryto Currency Miners Hiding; FBI BEC Arrest
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6034.mp3" length="4023527" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6034.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6034</link>
<pubDate>Tue, 12 Jun 2018 00:25:02 GMT</pubDate>
<description><![CDATA[More Malspam Pushing Lokibot<br/>
 <a href="https://isc.sans.edu/forums/diary/More+malspam+pushing+Lokibot/23754/">https://isc.sans.edu/forums/diary/More+malspam+pushing+Lokibot/23754/</a><br/>
Ethereum JSON RPC Theft<br/>
 <a href="https://twitter.com/360Netlab/status/1006065566728085504">https://twitter.com/360Netlab/status/1006065566728085504</a><br/>
CryptoCurrency Miner Plays hide-and-seek<br/>
 <a href="https://www.bleepingcomputer.com/news/security/cryptocurrency-miner-plays-hide-and-seek-with-popular-games-and-tools/">https://www.bleepingcomputer.com/news/security/cryptocurrency-miner-plays-hide-and-seek-with-popular-games-and-tools/</a><br/>
Apple Outlaws Crypto Currency Miners in App Store<br/>
 <a href="https://developer.apple.com/app-store/review/guidelines/#hardware-compatibility">https://developer.apple.com/app-store/review/guidelines/#hardware-compatibility</a><br/>
FBI Arrests Suspect in BEC Investigation<br/>
 <a href="https://www.fbi.gov/news/stories/international-bec-takedown-061118">https://www.fbi.gov/news/stories/international-bec-takedown-061118</a><br/>
]]></description>
<itunes:duration>4:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6034" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 11th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6032</itunes:episode>
<itunes:subtitle>Microsoft Paper: Device Security; Finding Deserialization Bugs With Freddy;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Microsoft Paper: Device Security; Finding Deserialization Bugs With Freddy;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6032.mp3" length="4640485" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6032.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6032</link>
<pubDate>Mon, 11 Jun 2018 00:40:18 GMT</pubDate>
<description><![CDATA[The Seven Properties of Highly Secure Devices<br/>
 <a href="https://www.microsoft.com/en-us/research/wp-content/uploads/2017/03/SevenPropertiesofHighlySecureDevices.pdf">https://www.microsoft.com/en-us/research/wp-content/uploads/2017/03/SevenPropertiesofHighlySecureDevices.pdf</a><br/>
Finding Deserialisation Issues With Burp<br/>
 <a href="https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/june/finding-deserialisation-issues-has-never-been-easier-freddy-the-serialisation-killer/">https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/june/finding-deserialisation-issues-has-never-been-easier-freddy-the-serialisation-killer/</a><br/>
FTC Starts Looking Into Cryptojacking<br/>
 <a href="https://www.consumer.ftc.gov/blog/2018/06/protecting-your-devices-cryptojacking">https://www.consumer.ftc.gov/blog/2018/06/protecting-your-devices-cryptojacking</a><br/>
Drupal Disputes Number of Vulnerable Sites<br/>
 <a href="https://groups.drupal.org/node/520149">https://groups.drupal.org/node/520149</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6032" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 8th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6031</itunes:episode>
<itunes:subtitle>Critical Adobe Flash Update; Supermicro Firmware Bug; Twitter Loot Collection; Sofacy Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Critical Adobe Flash Update; Supermicro Firmware Bug; Twitter Loot Collection; Sofacy Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6031.mp3" length="4724600" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6031.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6031</link>
<pubDate>Fri, 08 Jun 2018 02:00:06 GMT</pubDate>
<description><![CDATA[Critical Adobe Flash Update<br/>
 <a href="https://helpx.adobe.com/security/products/flash-player/apsb18-19.html">https://helpx.adobe.com/security/products/flash-player/apsb18-19.html</a><br/>
SuperMicro Firmware Vulnerability<br/>
 <a href="https://blog.eclypsium.com/2018/06/07/firmware-vulnerabilities-in-supermicro-systems/">https://blog.eclypsium.com/2018/06/07/firmware-vulnerabilities-in-supermicro-systems/</a><br/>
FOSCAM Video Camera Vulnerabilities<br/>
 <a href="https://blog.vdoo.com/2018/06/06/vdoo-has-found-major-vulnerabilities-in-foscam-cameras/">https://blog.vdoo.com/2018/06/06/vdoo-has-found-major-vulnerabilities-in-foscam-cameras/</a><br/>
Sofacy Update<br/>
 <a href="https://researchcenter.paloaltonetworks.com/2018/06/unit42-sofacy-groups-parallel-attacks/">https://researchcenter.paloaltonetworks.com/2018/06/unit42-sofacy-groups-parallel-attacks/</a><br/>
Automated Twitter Loot Collection<br/>
 <a href="https://isc.sans.edu/forums/diary/Automated+twitter+loot+collection/23743/">https://isc.sans.edu/forums/diary/Automated+twitter+loot+collection/23743/</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6031" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 7th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6029</itunes:episode>
<itunes:subtitle>VPNFilter Update; Prowli Botnet; Cisco Security Bulletings; F-Secure Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VPNFilter Update; Prowli Botnet; Cisco Security Bulletings; F-Secure Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6029.mp3" length="4285015" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6029.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6029</link>
<pubDate>Thu, 07 Jun 2018 02:50:04 GMT</pubDate>
<description><![CDATA[VPNFilter Update<br/>
 <a href="https://blog.talosintelligence.com/2018/06/vpnfilter-update.html">https://blog.talosintelligence.com/2018/06/vpnfilter-update.html</a><br/>
Prowli Botnet<br/>
 <a href="https://www.guardicore.com/2018/06/operation-prowli-traffic-manipulation-cryptocurrency-mining/">https://www.guardicore.com/2018/06/operation-prowli-traffic-manipulation-cryptocurrency-mining/</a><br/>
Cisco Security Bulletins<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
F-Secure RAR Vulnerability<br/>
 <a href="https://www.f-secure.com/en/web/labs_global/fsc-2018-2">https://www.f-secure.com/en/web/labs_global/fsc-2018-2</a><br/>
PCAP to Weblogs<br/>
 <a href="https://isc.sans.edu/forums/diary/Converting+PCAP+Web+Traffic+to+Apache+Log/23739/">https://isc.sans.edu/forums/diary/Converting+PCAP+Web+Traffic+to+Apache+Log/23739/</a><br/>
]]></description>
<itunes:duration>5:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6029" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 6th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6027</itunes:episode>
<itunes:subtitle>Post Exploit Script; Zip Slip Vulnerability; Redis Exploits; Drupalgeddon 2 Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Post Exploit Script; Zip Slip Vulnerability; Redis Exploits; Drupalgeddon 2 Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6027.mp3" length="4792994" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6027.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6027</link>
<pubDate>Wed, 06 Jun 2018 01:30:04 GMT</pubDate>
<description><![CDATA[Analysis of a Post Exploit Script<br/>
 Malicious Post-Exploitation Batch File<br/>
Zip Slip Vulnerability<br/>
 <a href="https://snyk.io/research/zip-slip-vulnerability">https://snyk.io/research/zip-slip-vulnerability</a><br/>
Redis Exploits<br/>
 <a href="https://www.incapsula.com/blog/report-75-of-open-redis-servers-are-infected.html">https://www.incapsula.com/blog/report-75-of-open-redis-servers-are-infected.html</a><br/>
Drupalgeddon 2 Update<br/>
 <a href="https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/">https://badpackets.net/over-100000-drupal-websites-vulnerable-to-drupalgeddon-2-cve-2018-7600/</a><br/>
]]></description>
<itunes:duration>5:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6027" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6025</itunes:episode>
<itunes:subtitle>Authenticode Challenges; Miconfigured G-Suite Lists; PQCrypto VPN #quantumcomputing 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Authenticode Challenges; Miconfigured G-Suite Lists; PQCrypto VPN #quantumcomputing 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6025.mp3" length="5089584" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6025.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6025</link>
<pubDate>Tue, 05 Jun 2018 01:25:03 GMT</pubDate>
<description><![CDATA[Running Only Signed Code. Does it work in Windows 10?<br/>
 <a href="https://isc.sans.edu/forums/diary/Digging+into+Authenticode+Certificates/23731/">https://isc.sans.edu/forums/diary/Digging+into+Authenticode+Certificates/23731/</a><br/>
Misconfigured G-Suite Mailing Lists<br/>
 <a href="https://www.kennasecurity.com/widespread-google-groups-misconfiguration-exposes-sensitive-information/">https://www.kennasecurity.com/widespread-google-groups-misconfiguration-exposes-sensitive-information/</a><br/>
Microsoft Releases Open Source Post Quantum VPN<br/>
 <a href="https://github.com/Microsoft/PQCrypto-VPN">https://github.com/Microsoft/PQCrypto-VPN</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6025" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 4th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6023</itunes:episode>
<itunes:subtitle>Apple Patches Everything; VPNFilter Compeback; Reversing with Radare2
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patches Everything; VPNFilter Compeback; Reversing with Radare2
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6023.mp3" length="4628782" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6023.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6023</link>
<pubDate>Mon, 04 Jun 2018 00:35:03 GMT</pubDate>
<description><![CDATA[Apple Patches Everything<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Security+Updates/23727/">https://isc.sans.edu/forums/diary/Apple+Security+Updates/23727/</a> <br/>
VPNFilter Makes a Comeback<br/>
 <a href="https://jask.com/from-russia-with-love/">https://jask.com/from-russia-with-love/</a><br/>
Reverse Analysis with Radare2<br/>
 <a href="https://isc.sans.edu/forums/diary/Binary+analysis+with+Radare2/23723/">https://isc.sans.edu/forums/diary/Binary+analysis+with+Radare2/23723/</a><br/>
Pet Location Tracker Vulnerabilities<br/>
 <a href="https://threatpost.com/pet-trackers-open-to-mitm-attacks-interception/132291/">https://threatpost.com/pet-trackers-open-to-mitm-attacks-interception/132291/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6023" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 1st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6021</itunes:episode>
<itunes:subtitle>Safely Resetting Routers (#VPNFilter); CSS3 Mix-Blend-Mode Leak; Apple iMessage Security
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Safely Resetting Routers (#VPNFilter); CSS3 Mix-Blend-Mode Leak; Apple iMessage Security
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6021.mp3" length="4848211" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6021.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6021</link>
<pubDate>Fri, 01 Jun 2018 01:05:03 GMT</pubDate>
<description><![CDATA[Safely Resetting Routers<br/>
 <a href="https://isc.sans.edu/forums/diary/Resetting+Your+Router+the+Paranoid+Right+Way/23719/">https://isc.sans.edu/forums/diary/Resetting+Your+Router+the+Paranoid+Right+Way/23719/</a><br/>
CSS mix-blend-mode Side Channel Attack<br/>
 <a href="https://www.evonide.com/side-channel-attacking-browsers-through-css3-features/">https://www.evonide.com/side-channel-attacking-browsers-through-css3-features/</a><br/>
New ActiveX Exploit Seen in the Wild<br/>
 <a href="https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=27263">https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=27263</a><br/>
Apple iMessage Security<br/>
 <a href="https://support.apple.com/en-us/HT202303">https://support.apple.com/en-us/HT202303</a><br/>
10 Year Old Vulnerability in Steam Discovered<br/>
 <a href="https://www.contextis.com/blog/frag-grenade-a-remote-code-execution-vulnerability-in-the-steam-client">https://www.contextis.com/blog/frag-grenade-a-remote-code-execution-vulnerability-in-the-steam-client</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6021" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 31st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6019</itunes:episode>
<itunes:subtitle>Windows JScript Vulnerability; Git Vulnerablity; SpamCannibal Blacklist;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Windows JScript Vulnerability; Git Vulnerablity; SpamCannibal Blacklist;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6019.mp3" length="4009630" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6019.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6019</link>
<pubDate>Thu, 31 May 2018 03:10:03 GMT</pubDate>
<description><![CDATA[Windows JScript Vulnerability<br/>
 <a href="https://www.zerodayinitiative.com/advisories/ZDI-18-534/">https://www.zerodayinitiative.com/advisories/ZDI-18-534/</a><br/>
Two Git Vulnerabilities Patched<br/>
 <a href="https://marc.info/?l=git&m=152761328506724&w=2">https://marc.info/?l=git&m=152761328506724&w=2</a><br/>
 <a href="https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/">https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/</a><br/>
SpamCannibal Blacklist Temporarily Marks All IPs as "Spam"<br/>
 <a href="https://twitter.com/GossiTheDog/status/1001778042400854016">https://twitter.com/GossiTheDog/status/1001778042400854016</a><br/>
QRadar Remote Code Execution<br/>
 <a href="https://blogs.securiteam.com/index.php/archives/3689">https://blogs.securiteam.com/index.php/archives/3689</a><br/>
]]></description>
<itunes:duration>4:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6019" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 30th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6017</itunes:episode>
<itunes:subtitle>New DNS Features; Apple Updates; EOS Scans; NPM isn't a Teapot; SQL As Covert Channel
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New DNS Features; Apple Updates; EOS Scans; NPM isn't a Teapot; SQL As Covert Channel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6017.mp3" length="5143712" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6017.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6017</link>
<pubDate>Tue, 29 May 2018 23:15:03 GMT</pubDate>
<description><![CDATA[New DNS Features<br/>
 <a href="https://isc.sans.edu/forums/diary/DNS+is+Changing+Are+you+Ready/23711/">https://isc.sans.edu/forums/diary/DNS+is+Changing+Are+you+Ready/23711/</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Scans For Misconfigured EOS Blockchain Nodes<br/>
 <a href="https://www.bleepingcomputer.com/news/security/misconfigured-eos-blockchain-nodes-under-attack/">https://www.bleepingcomputer.com/news/security/misconfigured-eos-blockchain-nodes-under-attack/</a><br/>
NPM Bug Causes Update Failures / Application Crashes<br/>
 <a href="https://github.com/npm/npm/issues/20791#issuecomment-392648459">https://github.com/npm/npm/issues/20791#issuecomment-392648459</a><br/>
MnuBot Exfiltrates Data Via MSSQL<br/>
 <a href="https://securityintelligence.com/new-banking-trojan-mnubot-discovered-by-ibm-x-force-research/">https://securityintelligence.com/new-banking-trojan-mnubot-discovered-by-ibm-x-force-research/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6017" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 29th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6015</itunes:episode>
<itunes:subtitle>Ultrasound Mobile Location Tracking; NSIS and Malware; Z-Wave Attacks; Electron Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ultrasound Mobile Location Tracking; NSIS and Malware; Z-Wave Attacks; Electron Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6015.mp3" length="5007297" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6015.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6015</link>
<pubDate>Tue, 29 May 2018 01:35:03 GMT</pubDate>
<description><![CDATA[Ultrasound Mobile Location Tracking<br/>
 <a href="https://isc.sans.edu/forums/diary/Do+you+hear+Laurel+or+Yanny+or+is+it+OnOff+Keying/23707/">https://isc.sans.edu/forums/diary/Do+you+hear+Laurel+or+Yanny+or+is+it+OnOff+Keying/23707/</a><br/>
Analyzing Malware Created with NSIS<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+analysis+of+malware+created+with+NSIS/23703/">https://isc.sans.edu/forums/diary/Quick+analysis+of+malware+created+with+NSIS/23703/</a><br/>
Obfuscated Word Macro<br/>
 <a href="https://isc.sans.edu/forums/diary/Antivirus+Evasion+Easy+as+123/23701/">https://isc.sans.edu/forums/diary/Antivirus+Evasion+Easy+as+123/23701/</a><br/>
Z-Wave Attacks<br/>
 <a href="https://www.pentestpartners.com/security-blog/z-shave-exploiting-z-wave-downgrade-attacks/">https://www.pentestpartners.com/security-blog/z-shave-exploiting-z-wave-downgrade-attacks/</a><br/>
 <a href="https://www.silabs.com/community/blog.entry.html/2018/05/23/tl_dr_your_door_is-g1zC">https://www.silabs.com/community/blog.entry.html/2018/05/23/tl_dr_your_door_is-g1zC</a><br/>
Electron Framework Protocol Handler Patch Bypass<br/>
 <a href="https://blog.doyensec.com/2018/05/24/electron-win-protocol-handler-bug-bypass.html">https://blog.doyensec.com/2018/05/24/electron-win-protocol-handler-bug-bypass.html</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6015" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 25th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6013</itunes:episode>
<itunes:subtitle>GDPR Day; Bitcoin Gold Double Spent Attack; Amazon Alexa Spy Bug; Verge Cryptocoin Attacked Again
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GDPR Day; Bitcoin Gold Double Spent Attack; Amazon Alexa Spy Bug; Verge Cryptocoin Attacked Again
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6013.mp3" length="3922952" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6013.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6013</link>
<pubDate>Fri, 25 May 2018 01:35:02 GMT</pubDate>
<description><![CDATA[GDPR Going Into Effect May 25th<br/>
 <a href="https://en.wikipedia.org/wiki/General_Data_Protection_Regulation">https://en.wikipedia.org/wiki/General_Data_Protection_Regulation</a><br/>
Bitcoin Gold Double Spent Attack<br/>
 <a href="https://forum.bitcoingold.org/t/double-spend-attack-on-exchanges/1362">https://forum.bitcoingold.org/t/double-spend-attack-on-exchanges/1362</a><br/>
Amazon Alexa Forwards Random Conversations<br/>
 <a href="https://www.kiro7.com/news/local/woman-says-her-amazon-device-recorded-private-conversation-sent-it-out-to-random-contact/755507974">https://www.kiro7.com/news/local/woman-says-her-amazon-device-recorded-private-conversation-sent-it-out-to-random-contact/755507974</a><br/>
Verge Crypto Coin Attacked Again<br/>
 <a href="https://www.bleepingcomputer.com/news/security/verge-cryptocurrency-network-falls-victim-to-same-attack-even-after-hard-fork/">https://www.bleepingcomputer.com/news/security/verge-cryptocurrency-network-falls-victim-to-same-attack-even-after-hard-fork/</a><br/>
]]></description>
<itunes:duration>4:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6013" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 24th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6011</itunes:episode>
<itunes:subtitle>VPNFilter; #DLink Vulnerabilities; #Firefox disables ambient light API
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VPNFilter; #DLink Vulnerabilities; #Firefox disables ambient light API
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6011.mp3" length="4704487" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6011.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6011</link>
<pubDate>Thu, 24 May 2018 01:40:03 GMT</pubDate>
<description><![CDATA[VPNFilter Malware Affecting Cisco Routers<br/>
 <a href="https://blog.talosintelligence.com/2018/05/VPNFilter.html">https://blog.talosintelligence.com/2018/05/VPNFilter.html</a><br/>
DLink Vulnerabilities<br/>
 <a href="https://securelist.com/backdoors-in-d-links-backyard/85530/">https://securelist.com/backdoors-in-d-links-backyard/85530/</a><br/>
Firefox Disabling "Spy APIs" and enabling 2FA<br/>
 <a href="https://www.fxsitecompat.com/en-CA/docs/2018/ambient-light-and-proximity-sensor-apis-have-been-disabled/">https://www.fxsitecompat.com/en-CA/docs/2018/ambient-light-and-proximity-sensor-apis-have-been-disabled/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6011" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 23rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6009</itunes:episode>
<itunes:subtitle>Malicious SYLK Files; Patches for BMW; Mac Crypto Miners; VMWare Spectre Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious SYLK Files; Patches for BMW; Mac Crypto Miners; VMWare Spectre Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6009.mp3" length="4080946" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6009.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6009</link>
<pubDate>Wed, 23 May 2018 01:30:02 GMT</pubDate>
<description><![CDATA[Malicious SYLK Files Used to Execute Code in Excel<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Distributed+via+slk+Files/23687/">https://isc.sans.edu/forums/diary/Malware+Distributed+via+slk+Files/23687/</a><br/>
BMW Releases Patches for Several Cars<br/>
 <a href="https://keenlab.tencent.com/en/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf">https://keenlab.tencent.com/en/Experimental_Security_Assessment_of_BMW_Cars_by_KeenLab.pdf</a><br/>
Mac Crypto Miners<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/mac-threat-analysis/2018/05/new-mac-cryptominer-uses-xmrig/">https://blog.malwarebytes.com/threat-analysis/mac-threat-analysis/2018/05/new-mac-cryptominer-uses-xmrig/</a><br/>
VMWare Spectre Updates<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2018-0012.html">https://www.vmware.com/security/advisories/VMSA-2018-0012.html</a><br/>
]]></description>
<itunes:duration>4:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6009" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 22nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6007</itunes:episode>
<itunes:subtitle>Spectre NG Patches; New TheMoon(Mirai?) Variants; Extracing Keys from ssh-agent in Windows
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Spectre NG Patches; New TheMoon(Mirai?) Variants; Extracing Keys from ssh-agent in Windows
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6007.mp3" length="4601354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6007.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6007</link>
<pubDate>Tue, 22 May 2018 01:55:02 GMT</pubDate>
<description><![CDATA[Spectre NG Patches<br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012</a><br/>
 <a href="https://newsroom.intel.com/editorials/addressing-new-research-for-side-channel-analysis/">https://newsroom.intel.com/editorials/addressing-new-research-for-side-channel-analysis/</a><br/>
 <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012">https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180012</a><br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1528">https://bugs.chromium.org/p/project-zero/issues/detail?id=1528</a><br/>
New "Moon" Variant<br/>
 <a href="http://blog.netlab.360.com/gpon-exploit-in-the-wild-iv-themoon-botnet-join-in-with-a-0day/">http://blog.netlab.360.com/gpon-exploit-in-the-wild-iv-themoon-botnet-join-in-with-a-0day/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Something+Wicked+this+way+comes/23681/">https://isc.sans.edu/forums/diary/Something+Wicked+this+way+comes/23681/</a><br/>
Extracting Keys From Windows ssh-agent<br/>
 <a href="https://blog.ropnop.com/extracting-ssh-private-keys-from-windows-10-ssh-agent/">https://blog.ropnop.com/extracting-ssh-private-keys-from-windows-10-ssh-agent/</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6007" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 21st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6005</itunes:episode>
<itunes:subtitle>Redis Cryptocoin Mining Worm; Rowhammer over the Network; DrayTek CSRF Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Redis Cryptocoin Mining Worm; Rowhammer over the Network; DrayTek CSRF Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6005.mp3" length="4860278" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6005.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6005</link>
<pubDate>Mon, 21 May 2018 01:00:03 GMT</pubDate>
<description><![CDATA[Redis Cryptocoin Mining Worm<br/>
 <a href="https://isc.sans.edu/forums/diary/Anatomy+of+a+Redis+mining+worm/23673/">https://isc.sans.edu/forums/diary/Anatomy+of+a+Redis+mining+worm/23673/</a><br/>
Evolving Chrome's Security Indicator<br/>
 <a href="https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html">https://blog.chromium.org/2018/05/evolving-chromes-security-indicators.html</a><br/>
DrayTek CSRF 0-Day Exploited to Change DNS Servers<br/>
 <a href="https://www.draytek.co.uk/support/security-advisories/kb-advisory-csrf-and-dns-dhcp-web-attacks">https://www.draytek.co.uk/support/security-advisories/kb-advisory-csrf-and-dns-dhcp-web-attacks</a><br/>
Rowhammer Remote Exploit<br/>
 <a href="https://www.cs.vu.nl/~herbertb/download/papers/throwhammer_atc18.pdf">https://www.cs.vu.nl/~herbertb/download/papers/throwhammer_atc18.pdf</a><br/>
 <a href="https://arxiv.org/abs/1805.04956">https://arxiv.org/abs/1805.04956</a> <br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6005" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 18th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6003</itunes:episode>
<itunes:subtitle>Claymore Miner Attack; PCI 3.2.1 Released; Keeper Update; Cisco Security Fixes 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Claymore Miner Attack; PCI 3.2.1 Released; Keeper Update; Cisco Security Fixes 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6003.mp3" length="4802495" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6003.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6003</link>
<pubDate>Fri, 18 May 2018 01:05:02 GMT</pubDate>
<description><![CDATA[Claymore Miner Attack<br/>
 <a href="https://isc.sans.edu/diary/Insecure+Claymore+Miner+Management+API+Exploited+in+the+Wild/23665/">https://isc.sans.edu/diary/Insecure+Claymore+Miner+Management+API+Exploited+in+the+Wild/23665/</a><br/>
PCI DSS Version 3.2.1. Released<br/>
 <a href="https://isc.sans.edu/forums/diary/PCI+DSS+version+321+is+out/23667/">https://isc.sans.edu/forums/diary/PCI+DSS+version+321+is+out/23667/</a><br/>
Keeper Releases Update<br/>
 <a href="https://keepersecurity.com/blog/2018/05/15/response-may-15-seclists-report/">https://keepersecurity.com/blog/2018/05/15/response-may-15-seclists-report/</a><br/>
Cisco Security Update<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a>]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6003" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 17th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>6001</itunes:episode>
<itunes:subtitle>Critical DHCP Client Vuln (RedHat ES); 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Critical DHCP Client Vuln (RedHat ES); 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/6001.mp3" length="5432990" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/6001.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/6001</link>
<pubDate>Wed, 16 May 2018 23:25:01 GMT</pubDate>
<description><![CDATA[Critical DHCP Client Vulnerability in RedHat Enterprise Server 6/7<br/>
 <a href="https://access.redhat.com/security/vulnerabilities/3442151">https://access.redhat.com/security/vulnerabilities/3442151</a><br/>
UPnP Misconfiguration DDoS Attack<br/>
 <a href="https://www.theregister.co.uk/2018/05/16/upnp_amplifies_ddos_attacks/">https://www.theregister.co.uk/2018/05/16/upnp_amplifies_ddos_attacks/</a><br/>
Ubuntu Snap Store Miner Incident Followup<br/>
 <a href="https://blog.ubuntu.com/2018/05/15/trust-and-security-in-the-snap-store">https://blog.ubuntu.com/2018/05/15/trust-and-security-in-the-snap-store</a><br/>
iOS / Android "Zipper Down" Vulnerability<br/>
 <a href="https://zipperdown.org/">https://zipperdown.org/</a><br/>
]]></description>
<itunes:duration>6:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=6001" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 16th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5999</itunes:episode>
<itunes:subtitle>PDF Exploit Live; Possible Keeper Password Manager Vuln; myetherwallet Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF Exploit Live; Possible Keeper Password Manager Vuln; myetherwallet Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5999.mp3" length="5842958" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5999.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5999</link>
<pubDate>Wed, 16 May 2018 00:30:02 GMT</pubDate>
<description><![CDATA[PDF Exploit (and Windows Priv. Escalation) Leaked<br/>
 <a href="https://www.welivesecurity.com/2018/05/15/tale-two-zero-days/">https://www.welivesecurity.com/2018/05/15/tale-two-zero-days/</a><br/>
Possible Vulnerability in Keeper Password Manager<br/>
 <a href="http://seclists.org/fulldisclosure/2018/May/41">http://seclists.org/fulldisclosure/2018/May/41</a><br/>
MyEtherWallet Phishing<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+emails+for+fake+MyEtherWallet+login+page/23655/">https://isc.sans.edu/forums/diary/Phishing+emails+for+fake+MyEtherWallet+login+page/23655/</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5999" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 15th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5997</itunes:episode>
<itunes:subtitle>PGP/SMIME #efail Vulnerability; Adobe PDF Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PGP/SMIME #efail Vulnerability; Adobe PDF Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5997.mp3" length="5485651" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5997.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5997</link>
<pubDate>Tue, 15 May 2018 01:10:01 GMT</pubDate>
<description><![CDATA[PGP/SMIME efail Vulnerability<br/>
 <a href="https://efail.de">https://efail.de</a><br/>
Adobe PDF Reader / Acrobat Bulletins<br/>
 <a href="https://helpx.adobe.com/security/products/acrobat/apsb18-09.html">https://helpx.adobe.com/security/products/acrobat/apsb18-09.html</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5997" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 14th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5995</itunes:episode>
<itunes:subtitle>Odd njRat Like Scans; Signal (Electron?) vulnerability; Electron Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Odd njRat Like Scans; Signal (Electron?) vulnerability; Electron Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5995.mp3" length="4952438" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5995.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5995</link>
<pubDate>Mon, 14 May 2018 00:10:01 GMT</pubDate>
<description><![CDATA[Odd njRat Like Scans<br/>
 Reversed C2 traffic from China<br/>
Signal Vulnerability (Possibly in Electron, which affects Skype/Slack/others)<br/>
 <a href="https://twitter.com/ortegaalfredo/status/995017143002509313">https://twitter.com/ortegaalfredo/status/995017143002509313</a><br/>
Electron Vulnerability <br/>
 <a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass/">https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass/</a><br/>
Cryptocoin Miner Found in Ubuntu Snap Store <br/>
 <a href="https://github.com/canonical-websites/snapcraft.io/issues/651">https://github.com/canonical-websites/snapcraft.io/issues/651</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5995" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 11th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5993</itunes:episode>
<itunes:subtitle>DNS Exfil in Windows; Fake Electrum Wallet; PoS Malware Source Code; Malicious Chrome Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DNS Exfil in Windows; Fake Electrum Wallet; PoS Malware Source Code; Malicious Chrome Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5993.mp3" length="4418860" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5993.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5993</link>
<pubDate>Fri, 11 May 2018 00:30:01 GMT</pubDate>
<description><![CDATA[DNS Exfiltration in Windows<br/>
 <a href="https://isc.sans.edu/forums/diary/Exfiltrating+data+from+very+isolated+environments/23645/">https://isc.sans.edu/forums/diary/Exfiltrating+data+from+very+isolated+environments/23645/</a><br/>
Fake Electrun Wallet<br/>
 <a href="https://github.com/spesmilo/electrum-docs/blob/master/decompiling_guide.md">https://github.com/spesmilo/electrum-docs/blob/master/decompiling_guide.md</a><br/>
Treasure Hunter PoS Malware Source Code Leaked<br/>
 <a href="https://www.flashpoint-intel.com/blog/treasurehunter-source-code-leaked/">https://www.flashpoint-intel.com/blog/treasurehunter-source-code-leaked/</a><br/>
More Malicious Chrome Extensions Spreading via Facebook<br/>
 <a href="https://blog.radware.com/security/2018/05/nigelthorn-malware-abuses-chrome-extensions/">https://blog.radware.com/security/2018/05/nigelthorn-malware-abuses-chrome-extensions/</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5993" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 10th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5991</itunes:episode>
<itunes:subtitle>Loyds Bank Phishing; Firefox Group Policy; OS Vendors Fix Intel Debug Flaw
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Loyds Bank Phishing; Firefox Group Policy; OS Vendors Fix Intel Debug Flaw
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5991.mp3" length="3391207" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5991.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5991</link>
<pubDate>Thu, 10 May 2018 01:40:04 GMT</pubDate>
<description><![CDATA[Loyds Bank Phish Leads to Trickbot<br/>
 <a href="https://isc.sans.edu/forums/diary/Nice+Phishing+Sample+Delivering+Trickbot/23641/">https://isc.sans.edu/forums/diary/Nice+Phishing+Sample+Delivering+Trickbot/23641/</a><br/>
Firefox Group Policy Engine<br/>
 <a href="https://www.bleepingcomputer.com/news/software/group-policy-support-coming-to-firefox-60/">https://www.bleepingcomputer.com/news/software/group-policy-support-coming-to-firefox-60/</a><br/>
OS Vendors Fix Intel Debug Flaw<br/>
 <a href="https://www.kb.cert.org/vuls/id/631579">https://www.kb.cert.org/vuls/id/631579</a><br/>
Cryptocoin Miner in Excel<br/>
 <a href="https://charles.dardaman.com/js_coinhive_in_excel">https://charles.dardaman.com/js_coinhive_in_excel</a><br/>
]]></description>
<itunes:duration>4:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5991" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5989</itunes:episode>
<itunes:subtitle>#MSFT Patch Tuesday; Office 365 Basestriker Vulnerability; wget cookie injection
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#MSFT Patch Tuesday; Office 365 Basestriker Vulnerability; wget cookie injection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5989.mp3" length="5349975" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5989.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5989</link>
<pubDate>Wed, 09 May 2018 02:19:12 GMT</pubDate>
<description><![CDATA[<br/>
Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+May+2018+Patch+Tuesday/23637/">https://isc.sans.edu/forums/diary/Microsoft+May+2018+Patch+Tuesday/23637/</a><br/>
Basestriker Vulnerability Hitting Office 365<br/>
 <a href="https://www.avanan.com/resources/basestriker-vulnerability-office-365">https://www.avanan.com/resources/basestriker-vulnerability-office-365</a><br/>
wget Cookie Injection Vulnerability<br/>
 <a href="http://seclists.org/fulldisclosure/2018/May/20">http://seclists.org/fulldisclosure/2018/May/20</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5989" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 8th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5987</itunes:episode>
<itunes:subtitle>Parsing Windows Job Files; SYN-ACK Dopplegangs; Drupal/Coinhive; Russia vs. Telegram
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Parsing Windows Job Files; SYN-ACK Dopplegangs; Drupal/Coinhive; Russia vs. Telegram
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5987.mp3" length="4095937" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5987.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5987</link>
<pubDate>Tue, 08 May 2018 01:40:02 GMT</pubDate>
<description><![CDATA[Parsing Windows Job Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/">https://isc.sans.edu/forums/diary/Adding+Persistence+Via+Scheduled+Tasks/23633/</a><br/>
SYN-ACK Ransomware Uses Dobbleganging Technique<br/>
 <a href="https://securelist.com/synack-targeted-ransomware-uses-the-doppelganging-technique/85431/">https://securelist.com/synack-targeted-ransomware-uses-the-doppelganging-technique/85431/</a><br/>
More Drupal Compromises<br/>
 <a href="https://badpackets.net/large-cryptojacking-campaign-targeting-vulnerable-drupal-websites/">https://badpackets.net/large-cryptojacking-campaign-targeting-vulnerable-drupal-websites/</a><br/>
Russia vs. Telegram<br/>
 <a href="https://twitter.com/instasegv/status/993521755192020992">https://twitter.com/instasegv/status/993521755192020992</a><br/>
 <a href="https://www.bleepingcomputer.com/news/government/russia-blocks-50-vpns-and-proxy-services-providing-access-to-telegram/">https://www.bleepingcomputer.com/news/government/russia-blocks-50-vpns-and-proxy-services-providing-access-to-telegram/</a><br/>
]]></description>
<itunes:duration>4:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5987" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 7th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5985</itunes:episode>
<itunes:subtitle>NPM Security; Popular GDPR Shield; More Spectre Flaws;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NPM Security; Popular GDPR Shield; More Spectre Flaws;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5985.mp3" length="4495660" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5985.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5985</link>
<pubDate>Mon, 07 May 2018 01:50:02 GMT</pubDate>
<description><![CDATA[Malicious NPM Library Stopped<br/>
 <a href="https://blog.npmjs.org/post/173526807575/reported-malicious-module-getcookies">https://blog.npmjs.org/post/173526807575/reported-malicious-module-getcookies</a><br/>
Popular GDPR Shield<br/>
 <a href="http://gdpr-shield.io">http://gdpr-shield.io</a> (currently down)<br/>
More Spectre Flaws<br/>
 <a href="https://www.heise.de/ct/artikel/Exclusive-Spectre-NG-Multiple-new-Intel-CPU-flaws-revealed-several-serious-4040648.html">https://www.heise.de/ct/artikel/Exclusive-Spectre-NG-Multiple-new-Intel-CPU-flaws-revealed-several-serious-4040648.html</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5985" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 4th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5983</itunes:episode>
<itunes:subtitle>More WebLogic xploits; Ouch! GDPR ; GitHub/Twitter pw loggin; #sans_edu Disrupting PowerShell Empire</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More WebLogic xploits; Ouch! GDPR ; GitHub/Twitter pw loggin; #sans_edu Disrupting PowerShell Empire</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5983.mp3" length="12452872" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5983.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5983</link>
<pubDate>Fri, 04 May 2018 01:30:02 GMT</pubDate>
<description><![CDATA[More WebLogic Exploits<br/>
 <a href="https://isc.sans.edu/forums/diary/WebLogic+Exploited+in+the+Wild+Again/23617/">https://isc.sans.edu/forums/diary/WebLogic+Exploited+in+the+Wild+Again/23617/</a><br/>
Ouch! GDPR Newsletter<br/>
 <a href="https://www.sans.org/security-awareness-training/ouch-newsletter">https://www.sans.org/security-awareness-training/ouch-newsletter</a><br/>
GitHub / Twitter Password Storage Issues<br/>
 <a href="https://blog.twitter.com/official/en_us/topics/company/2018/keeping-your-account-secure.html">https://blog.twitter.com/official/en_us/topics/company/2018/keeping-your-account-secure.html</a><br/>
 <a href="https://www.zdnet.com/article/github-says-bug-exposed-account-passwords/">https://www.zdnet.com/article/github-says-bug-exposed-account-passwords/</a><br/>
Facebook adds Homegraph Alert to Certificate Transparency log monitoring<br/>
 <a href="https://www.facebook.com/notes/protect-the-graph/phishing-domain-detection/2037453483161459/">https://www.facebook.com/notes/protect-the-graph/phishing-domain-detection/2037453483161459/</a><br/>
Disrupting the Empire: Identifying PowerShell Empire Command and Control Activity<br/>
<a href="https://www.sans.org/reading-room/whitepapers/forensics/disrupting-empire-identifying-powershell-empire-command-control-activity-38315">https://www.sans.org/reading-room/whitepapers/forensics/disrupting-empire-identifying-powershell-empire-command-control-activity-38315</a><br/>
]]></description>
<itunes:duration>14:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5983" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 3rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5981</itunes:episode>
<itunes:subtitle>GPS Jamming More Common; Windows Command Line Reference; LoJack "Phone Home";
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
GPS Jamming More Common; Windows Command Line Reference; LoJack "Phone Home";
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5981.mp3" length="5087024" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5981.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5981</link>
<pubDate>Thu, 03 May 2018 01:25:02 GMT</pubDate>
<description><![CDATA[GPS Jamming Becoming More Common<br/>
 <a href="https://www.avweb.com/avwebflash/news/GPS-Jamming-Major-Threat-to-Drone-230749-1.html">https://www.avweb.com/avwebflash/news/GPS-Jamming-Major-Threat-to-Drone-230749-1.html</a><br/>
 <a href="https://www.heise.de/newsticker/meldung/GPS-unter-Beschuss-Jamming-und-Spoofing-nehmen-zu-4038137.html">https://www.heise.de/newsticker/meldung/GPS-unter-Beschuss-Jamming-und-Spoofing-nehmen-zu-4038137.html</a><br/>
Windows Command Line References<br/>
 <a href="https://isc.sans.edu/forums/diary/Windows+Commands+Reference+An+InfoSec+Must+Have/23613/">https://isc.sans.edu/forums/diary/Windows+Commands+Reference+An+InfoSec+Must+Have/23613/</a><br/>
LoJack Laptop Anti-Theft Software "Phones Home" to Russia<br/>
 <a href="https://asert.arbornetworks.com/lojack-becomes-a-double-agent/">https://asert.arbornetworks.com/lojack-becomes-a-double-agent/</a><br/>
Google Maps Can Be Used as a URL Shortener<br/>
 <a href="https://nakedsecurity.sophos.com/2018/05/01/google-maps-open-redirect-flaw-abused-by-spammers/">https://nakedsecurity.sophos.com/2018/05/01/google-maps-open-redirect-flaw-abused-by-spammers/</a><br/>
Retrieving DVR Credentials via "Admin Cookie"<br/>
 <a href="https://github.com/ezelf/CVE-2018-9995_dvr_credentials">https://github.com/ezelf/CVE-2018-9995_dvr_credentials</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5981" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5979</itunes:episode>
<itunes:subtitle>Creating #MalDocs ; Google/Amazon vs. Domain Fronting; Google Chrome CT Enforcement
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Creating #MalDocs ; Google/Amazon vs. Domain Fronting; Google Chrome CT Enforcement
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5979.mp3" length="4699369" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5979.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5979</link>
<pubDate>Wed, 02 May 2018 02:10:02 GMT</pubDate>
<description><![CDATA[Creating Malicious Office Documents <br/>
 <a href="https://isc.sans.edu/forums/diary/Diving+into+a+Simple+Maldoc+Generator/23609/">https://isc.sans.edu/forums/diary/Diving+into+a+Simple+Maldoc+Generator/23609/</a><br/>
Google (and Amazon) Disable Domain Fronting<br/>
 <a href="https://arstechnica.com/information-technology/2018/04/google-disables-domain-fronting-capability-used-to-evade-censors/">https://arstechnica.com/information-technology/2018/04/google-disables-domain-fronting-capability-used-to-evade-censors/</a><br/>
Google Chrome To Enforce Certificate Transparency<br/>
 <a href="https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/wHILiYf31DE/iMFmpMEkAQAJ">https://groups.google.com/a/chromium.org/forum/#!msg/ct-policy/wHILiYf31DE/iMFmpMEkAQAJ</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5979" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 1st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5977</itunes:episode>
<itunes:subtitle>More Real Bad #WebLogic News; Facebook Messages Spread Malicious Chrome Extensions
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Real Bad #WebLogic News; Facebook Messages Spread Malicious Chrome Extensions
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5977.mp3" length="4779091" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5977.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5977</link>
<pubDate>Tue, 01 May 2018 02:05:02 GMT</pubDate>
<description><![CDATA[April WebLogic Patch Incomplete and Intense Scanning for WebLogic Under Way<br/>
 <a href="https://www.bleepingcomputer.com/news/security/hackers-scan-the-web-for-vulnerable-weblogic-servers-after-oracle-botches-patch/">https://www.bleepingcomputer.com/news/security/hackers-scan-the-web-for-vulnerable-weblogic-servers-after-oracle-botches-patch/</a><br/>
Facex Worm Spreads Malicious Chrome Extensions via Facebook<br/>
 <a href="https://blog.trendmicro.com/trendlabs-security-intelligence/facexworm-targets-cryptocurrency-trading-platforms-abuses-facebook-messenger-for-propagation/">https://blog.trendmicro.com/trendlabs-security-intelligence/facexworm-targets-cryptocurrency-trading-platforms-abuses-facebook-messenger-for-propagation/</a><br/>
$15 DTV Transmitter as a SDR<br/>
 <a href="https://hackernoon.com/osmo-fl2k-a-15-dtv-transmitter-fm-radio-hijack-and-gps-spoofing-device-68ac08ba7d76">https://hackernoon.com/osmo-fl2k-a-15-dtv-transmitter-fm-radio-hijack-and-gps-spoofing-device-68ac08ba7d76</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5977" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 30th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5975</itunes:episode>
<itunes:subtitle>Sample #Drupal Exploits; Triggering SMB Connections from PDFs; Win7/10 NTFS Crash DoS; Azucar Azure </itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Sample #Drupal Exploits; Triggering SMB Connections from PDFs; Win7/10 NTFS Crash DoS; Azucar Azure </itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5975.mp3" length="5516739" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5975.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5975</link>
<pubDate>Mon, 30 Apr 2018 03:00:08 GMT</pubDate>
<description><![CDATA[A Few Sample #Drupal Exploits including CVE-2018-7602<br/>
 <a href="https://isc.sans.edu/forums/diary/More+Threat+Hunting+with+User+Agent+and+Drupal+Exploits/23597/">https://isc.sans.edu/forums/diary/More+Threat+Hunting+with+User+Agent+and+Drupal+Exploits/23597/</a><br/>
Triggering SMB Connections to Steal NTLM Credentials via PDFs<br/>
 <a href="https://research.checkpoint.com/ntlm-credentials-theft-via-pdf-files/">https://research.checkpoint.com/ntlm-credentials-theft-via-pdf-files/</a><br/>
NTFS Crash DoS Exploit Published for Windwos 10 and 7<br/>
 <a href="https://github.com/mtivadar/windows10_ntfs_crash_dos">https://github.com/mtivadar/windows10_ntfs_crash_dos</a><br/>
Apple HomeKit / Secure Element Problems<br/>
 <a href="https://www.youtube.com/watch?v=1CNAMgctAp0">https://www.youtube.com/watch?v=1CNAMgctAp0</a><br/>
Azucar Assessing Azure Security<br/>
 <a href="https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/introducing-azucar/">https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/april/introducing-azucar/</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5975" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5973</itunes:episode>
<itunes:subtitle>New Drupal RCE Used In The Wild; HP iLO Ransomware; ZTE/Hypteroptic Default Password
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Drupal RCE Used In The Wild; HP iLO Ransomware; ZTE/Hypteroptic Default Password
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5973.mp3" length="6067139" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5973.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5973</link>
<pubDate>Fri, 27 Apr 2018 02:35:02 GMT</pubDate>
<description><![CDATA[HP iLO Ransomware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/ransomware-hits-hpe-ilo-remote-management-interfaces/">https://www.bleepingcomputer.com/news/security/ransomware-hits-hpe-ilo-remote-management-interfaces/</a><br/>
Total Meltdown Exploit Available<br/>
 <a href="https://blog.xpnsec.com/total-meltdown-cve-2018-1038/">https://blog.xpnsec.com/total-meltdown-cve-2018-1038/</a><br/>
WD My Cloud EX2 Access Control Bypass<br/>
 <a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/WD-My-Cloud-EX2-Serves-Your-Files-to-Anyone/">https://www.trustwave.com/Resources/SpiderLabs-Blog/WD-My-Cloud-EX2-Serves-Your-Files-to-Anyone/</a><br/>
Hyperoptic ZTE Home Router Hardcoded Account<br/>
 <a href="https://www.contextis.com/resources/advisories/hyperoptic-zte-home-routers">https://www.contextis.com/resources/advisories/hyperoptic-zte-home-routers</a><br/>
]]></description>
<itunes:duration>7:12</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5973" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5971</itunes:episode>
<itunes:subtitle>New Drupal RCE Vuln; Bash IRC Bot; Insecure Hotel Locks; Alexa Allowed Malicous Apps to Evesdrop
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Drupal RCE Vuln; Bash IRC Bot; Insecure Hotel Locks; Alexa Allowed Malicous Apps to Evesdrop
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5971.mp3" length="4515417" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5971.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5971</link>
<pubDate>Thu, 26 Apr 2018 03:05:01 GMT</pubDate>
<description><![CDATA[New Drupal Remote Code Execution Vulnerability<br/>
 <a href="https://www.drupal.org/sa-core-2018-004">https://www.drupal.org/sa-core-2018-004</a><br/>
Malicious Network Traffic From /bin/bash<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Network+Traffic+From+binbash/23591/">https://isc.sans.edu/forums/diary/Malicious+Network+Traffic+From+binbash/23591/</a><br/>
Insecure Hotel Locks<br/>
 <a href="https://safeandsavvy.f-secure.com/2018/04/25/researchers-find-way-to-generate-master-keys-to-hotels/">https://safeandsavvy.f-secure.com/2018/04/25/researchers-find-way-to-generate-master-keys-to-hotels/</a><br/>
Amazon Echo As Evesdropping Device (signin required)<br/>
 <a href="https://info.checkmarx.com/wp-alexa">https://info.checkmarx.com/wp-alexa</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5971" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 12th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5905</itunes:episode>
<itunes:subtitle>Don't Pay Ransomware; Microtik Malware; CNNVD Manipulated; Keeper S3 Blunder
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Don't Pay Ransomware; Microtik Malware; CNNVD Manipulated; Keeper S3 Blunder
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5905.mp3" length="6369584" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5905.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5905</link>
<pubDate>Mon, 12 Mar 2018 02:35:07 GMT</pubDate>
<description><![CDATA[Paying For Ransomware Often Fails to Recover Files<br/>
 <a href="https://cyber-edge.com/cdr/#about-this-report">https://cyber-edge.com/cdr/#about-this-report</a><br/>
Microtik Router Malware Infects Sysadmin PCs<br/>
 <a href="https://s3-eu-west-1.amazonaws.com/khub-media/wp-content/uploads/sites/43/2018/03/09133534/The-Slingshot-APT_report_ENG_final.pdf">https://s3-eu-west-1.amazonaws.com/khub-media/wp-content/uploads/sites/43/2018/03/09133534/The-Slingshot-APT_report_ENG_final.pdf</a><br/>
CNNVD Held Back Vulnerabilities<br/>
 <a href="https://www.recordedfuture.com/chinese-mss-vulnerability-influence/">https://www.recordedfuture.com/chinese-mss-vulnerability-influence/</a><br/>
Keeper Exposes S3 Bucket<br/>
 <a href="http://www.zdnet.com/article/password-manager-maker-keeper-hit-by-another-security-snafu/">http://www.zdnet.com/article/password-manager-maker-keeper-hit-by-another-security-snafu/</a><br/>
 <a href="https://keepersecurity.com/blog/2018/03/10/keepers-response-zdnets-article-regarding-s3-bucket-configuration-issue/">https://keepersecurity.com/blog/2018/03/10/keepers-response-zdnets-article-regarding-s3-bucket-configuration-issue/</a><br/>
Chip and Pin Clones<br/>
 <a href="https://www.kaspersky.com/blog/chip-n-pin-cloning/21502/">https://www.kaspersky.com/blog/chip-n-pin-cloning/21502/</a><br/>
]]></description>
<itunes:duration>7:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5905" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5903</itunes:episode>
<itunes:subtitle>Apache #Solr Vulnerability and #XMRig; CIRMEB4NK #IRC Bot; #Cisco Patches; Any.Run
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apache #Solr Vulnerability and #XMRig; CIRMEB4NK #IRC Bot; #Cisco Patches; Any.Run
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5903.mp3" length="5132373" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5903.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5903</link>
<pubDate>Fri, 09 Mar 2018 03:40:08 GMT</pubDate>
<description><![CDATA[Apache Solr Vulnerability used to Install Cryptocoin Miner<br/>
 <a href="https://isc.sans.edu/forums/diary/Apache+SOLR+the+new+target+for+cryptominers/23425/">https://isc.sans.edu/forums/diary/Apache+SOLR+the+new+target+for+cryptominers/23425/</a><br/>
CRIMEB4NK IRC Bot<br/>
 <a href="https://isc.sans.edu/forums/diary/CRIMEB4NK+IRC+Bot/23423/">https://isc.sans.edu/forums/diary/CRIMEB4NK+IRC+Bot/23423/</a><br/>
Cisco Patches<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x">https://tools.cisco.com/security/center/publicationListing.x</a><br/>
Any.Run Malware Analysis Tool<br/>
 <a href="https://any.run">https://any.run</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5903" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 8th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5901</itunes:episode>
<itunes:subtitle>Ransomware Update; How To Break Encryption; Android Mail Apps Leak Passwords; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ransomware Update; How To Break Encryption; Android Mail Apps Leak Passwords; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5901.mp3" length="4897223" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5901.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5901</link>
<pubDate>Thu, 08 Mar 2018 04:10:08 GMT</pubDate>
<description><![CDATA[Ransomware News: GlobeImposter Gets A Facelift, GandCrab is Still Out there<br/>
 <a href="https://isc.sans.edu/forums/diary/Ransomware+news+GlobeImposter+gets+a+facelift+GandCrab+is+still+out+there/23417/">https://isc.sans.edu/forums/diary/Ransomware+news+GlobeImposter+gets+a+facelift+GandCrab+is+still+out+there/23417/</a><br/>
How to Break Encryption<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2018/03/encryption-101-how-to-break-encryption/">https://blog.malwarebytes.com/threat-analysis/2018/03/encryption-101-how-to-break-encryption/</a><br/>
Bypassing Adobe Flash Security Protections<br/>
 <a href="https://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-protection-mechanism/">https://securingtomorrow.mcafee.com/mcafee-labs/hackers-bypassed-adobe-flash-protection-mechanism/</a><br/>
Hundreds of Bitcoin Mining Servers Stolen in Iceland<br/>
 <a href="https://www.theguardian.com/world/2018/mar/07/hundreds-of-bitcoin-mining-servers-stolen-in-iceland">https://www.theguardian.com/world/2018/mar/07/hundreds-of-bitcoin-mining-servers-stolen-in-iceland</a><br/>
Several Android Mail Apps Send Password To Developer (article in German)<br/>
 <a href="https://www.kuketz-blog.de/mail-apps-zahlreiche-android-apps-uebermitteln-login-passwort/">https://www.kuketz-blog.de/mail-apps-zahlreiche-android-apps-uebermitteln-login-passwort/</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5901" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 7th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5899</itunes:episode>
<itunes:subtitle>#Exim RCE Exploit for CVE-2018-6789; #MSFT Releases USB Fix; 123 Reg Loses Backups
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#Exim RCE Exploit for CVE-2018-6789; #MSFT Releases USB Fix; 123 Reg Loses Backups
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5899.mp3" length="4907830" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5899.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5899</link>
<pubDate>Wed, 07 Mar 2018 03:30:11 GMT</pubDate>
<description><![CDATA[Exploit for CVE-2018-6789<br/>
 <a href="https://devco.re/blog/2018/03/06/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en/">https://devco.re/blog/2018/03/06/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en/</a><br/>
Microsoft Fixes USB Issues Introduced By February Patches<br/>
 <a href="https://support.microsoft.com/en-us/help/4090913/march5-2018kb4090913osbuild16299-251">https://support.microsoft.com/en-us/help/4090913/march5-2018kb4090913osbuild16299-251</a><br/>
123 Reg Looses Backups<br/>
 <a href="https://www.bleepingcomputer.com/news/business/123-reg-backup-snafu-causes-clients-to-lose-files-since-august-2017/">https://www.bleepingcomputer.com/news/business/123-reg-backup-snafu-causes-clients-to-lose-files-since-august-2017/</a><br/>
Android March Security Bulletin<br/>
 <a href="https://source.android.com/security/bulletin/2018-03-01#media-framework">https://source.android.com/security/bulletin/2018-03-01#media-framework</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5899" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 6th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5897</itunes:episode>
<itunes:subtitle>Multifacetted Bash Script; More/Larger Memcached DDOS; Spring Data REST Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Multifacetted Bash Script; More/Larger Memcached DDOS; Spring Data REST Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5897.mp3" length="5743849" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5897.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5897</link>
<pubDate>Tue, 06 Mar 2018 01:30:12 GMT</pubDate>
<description><![CDATA[Malicious Bash Script with Multiple Features<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Bash+Script+with+Multiple+Features/23411/">https://isc.sans.edu/forums/diary/Malicious+Bash+Script+with+Multiple+Features/23411/</a><br/>
More Memcached DDoS Attacks<br/>
 <a href="https://www.arbornetworks.com/blog/asert/netscout-arbor-confirms-1-7-tbps-ddos-attack-terabit-attack-era-upon-us/">https://www.arbornetworks.com/blog/asert/netscout-arbor-confirms-1-7-tbps-ddos-attack-terabit-attack-era-upon-us/</a><br/>
Spring Framework Vulnerability <br/>
 <a href="https://lgtm.com/blog/spring_data_rest_CVE-2017-8046">https://lgtm.com/blog/spring_data_rest_CVE-2017-8046</a><br/>
LTE Vulnerabilities<br/>
 <a href="http://homepage.divms.uiowa.edu/~comarhaider/publications/LTE_NDSS18_paper.pdf">http://homepage.divms.uiowa.edu/~comarhaider/publications/LTE_NDSS18_paper.pdf</a><br/>
 <br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5897" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5895</itunes:episode>
<itunes:subtitle>Protective Malicious Monero Miners;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Protective Malicious Monero Miners;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5895.mp3" length="4630247" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5895.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5895</link>
<pubDate>Mon, 05 Mar 2018 02:55:06 GMT</pubDate>
<description><![CDATA[Protective Malicious Monero Crypto Coin Miners<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Crypto+Miners+Fight+For+CPU+Cycles/23407/">https://isc.sans.edu/forums/diary/The+Crypto+Miners+Fight+For+CPU+Cycles/23407/</a><br/>
memcached DDoS Attacks Ask For Ransom<br/>
 <a href="https://blogs.akamai.com/2018/03/memcached-now-with-extortion.html">https://blogs.akamai.com/2018/03/memcached-now-with-extortion.html</a><br/>
Cheap Android Trojans Come PreInstalled With Banking Malware<br/>
 <a href="https://news.drweb.com/show/?lng=en&i=11749&c=5">https://news.drweb.com/show/?lng=en&i=11749&c=5</a><br/>
RedDrop Android Malware Installed via 3rd Party App Stores <br/>
 <a href="https://www.wandera.com/blog/reddrop-malware/">https://www.wandera.com/blog/reddrop-malware/</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5895" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5893</itunes:episode>
<itunes:subtitle>Censoring Images At Scale in #WeChat; Trustico/Memcached Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Censoring Images At Scale in #WeChat; Trustico/Memcached Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5893.mp3" length="6750659" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5893.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5893</link>
<pubDate>Fri, 02 Mar 2018 03:10:08 GMT</pubDate>
<description><![CDATA[Censoring Images At Scale in #WeChat<br/>
 <a href="https://isc.sans.edu/forums/diary/Why+Does+Emperor+Xi+Dislike+Winnie+the+Pooh+and+Scrambled+Eggs/23395/">https://isc.sans.edu/forums/diary/Why+Does+Emperor+Xi+Dislike+Winnie+the+Pooh+and+Scrambled+Eggs/23395/</a><br/>
Trustico Update: Certificate Revocation List Monitor<br/>
 <a href="https://isc.sans.edu/crls.html">https://isc.sans.edu/crls.html</a><br/>
Memcached Update: Github Attack<br/>
 <a href="https://githubengineering.com/ddos-incident-report/">https://githubengineering.com/ddos-incident-report/</a><br/>
 <a href="http://powerofcommunity.net/poc2017/shengbao.pdf">http://powerofcommunity.net/poc2017/shengbao.pdf</a><br/>
Microsoft Releases Intel Spectre Microcode Updates<br/>
 <a href="https://support.microsoft.com/en-us/help/4090007/intel-microcode-updates">https://support.microsoft.com/en-us/help/4090007/intel-microcode-updates</a><br/>
]]></description>
<itunes:duration>8:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5893" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 1st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5891</itunes:episode>
<itunes:subtitle>More Memcache; Trustico TLS Issues; Flash is Out But So is DNSSEC?  
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Memcache; Trustico TLS Issues; Flash is Out But So is DNSSEC?  
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5891.mp3" length="5170416" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5891.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5891</link>
<pubDate>Thu, 01 Mar 2018 03:40:07 GMT</pubDate>
<description><![CDATA[How Did This Memcache Thing Happen?<br/>
 <a href="https://isc.sans.edu/forums/diary/How+did+this+Memcache+thing+happen/23391/">https://isc.sans.edu/forums/diary/How+did+this+Memcache+thing+happen/23391/</a><br/>
Trustico TLS Certificate Revocation<br/>
 <a href="https://groups.google.com/forum/#!msg/mozilla.dev.security.policy/wxX4Yv0E3Mk/QZt8UPhKAwAJ">https://groups.google.com/forum/#!msg/mozilla.dev.security.policy/wxX4Yv0E3Mk/QZt8UPhKAwAJ</a><br/>
Flash on Its Way Out<br/>
 <a href="https://www.bleepingcomputer.com/news/security/google-chrome-flash-usage-declines-from-80-percent-in-2014-to-under-8-percent-today/">https://www.bleepingcomputer.com/news/security/google-chrome-flash-usage-declines-from-80-percent-in-2014-to-under-8-percent-today/</a><br/>
DNSSEC Is Getting Better But Still Struggeling<br/>
 <a href="http://www.theregister.co.uk/2018/02/28/dutch_name_authority_dnssec_validation_errors_can_be_eliminated/">http://www.theregister.co.uk/2018/02/28/dutch_name_authority_dnssec_validation_errors_can_be_eliminated/</a><br/>
Smart TV Firmware Flaws<br/>
 <a href="https://www.av-comparatives.org/wp-content/uploads/2018/02/avc_sigma_medion_201802.pdf">https://www.av-comparatives.org/wp-content/uploads/2018/02/avc_sigma_medion_201802.pdf</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5891" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 28th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5889</itunes:episode>
<itunes:subtitle>memcached reflective DDoS; Formbook Info Stealer News; Critical SAML Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
memcached reflective DDoS; Formbook Info Stealer News; Critical SAML Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5889.mp3" length="4884483" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5889.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5889</link>
<pubDate>Wed, 28 Feb 2018 03:30:10 GMT</pubDate>
<description><![CDATA[Memcached Servers Used in Reflective DDoS Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Why+we+Dont+Deserve+the+Internet+Memcached+Reflected+DDoS+Attacks/23389/">https://isc.sans.edu/forums/diary/Why+we+Dont+Deserve+the+Internet+Memcached+Reflected+DDoS+Attacks/23389/</a><br/>
Malspam Pushing Formbook Info Stealer<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/23387/">https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/23387/</a><br/>
Various SAML Parsers Affected by Comment Parsing Vulnerability<br/>
 <a href="https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations">https://duo.com/blog/duo-finds-saml-vulnerabilities-affecting-multiple-implementations</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5889" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 27th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5887</itunes:episode>
<itunes:subtitle>Cloud Tools: AWSBucketDump, Cloudmapper; Selling Mac and "Find my Mac"; iTunes Store Support end for</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cloud Tools: AWSBucketDump, Cloudmapper; Selling Mac and "Find my Mac"; iTunes Store Support end for</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5887.mp3" length="3995118" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5887.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5887</link>
<pubDate>Tue, 27 Feb 2018 02:40:03 GMT</pubDate>
<description><![CDATA[Enumerating S3 Buckets<br/>
 <a href="https://github.com/jordanpotti/AWSBucketDump">https://github.com/jordanpotti/AWSBucketDump</a><br/>
Creating AWS Network Diagrams<br/>
 <a href="https://github.com/duo-labs/cloudmapper">https://github.com/duo-labs/cloudmapper</a><br/>
Selling Macs and "Find my Mac" Feature<br/>
 <a href="https://medium.com/@mulligan/how-i-sold-an-old-mac-and-unknowingly-tracked-its-location-for-over-3-years-9a35cd3ca4cf">https://medium.com/@mulligan/how-i-sold-an-old-mac-and-unknowingly-tracked-its-location-for-over-3-years-9a35cd3ca4cf</a><br/>
Apple Stopping Support for 1st Gen Apple TV and iTunes on Windows XP / Vista<br/>
 <a href="https://support.apple.com/en-us/HT208104">https://support.apple.com/en-us/HT208104</a><br/>
]]></description>
<itunes:duration>4:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5887" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5885</itunes:episode>
<itunes:subtitle>Taxslavyer vs. FTC: Fix Credential Stuffing Now; OMG Bot; Blackholing Advertising with Pi-Hole
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Taxslavyer vs. FTC: Fix Credential Stuffing Now; OMG Bot; Blackholing Advertising with Pi-Hole
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5885.mp3" length="4673548" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5885.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5885</link>
<pubDate>Mon, 26 Feb 2018 02:10:07 GMT</pubDate>
<description><![CDATA[Retrieving Malware Over Tor On Windows (Update)<br/>
 <a href="https://isc.sans.edu/forums/diary/Retrieving+malware+over+Tor+on+Windows/23379/">https://isc.sans.edu/forums/diary/Retrieving+malware+over+Tor+on+Windows/23379/</a><br/>
Blackholing Advertising Sites with Pi-Hole<br/>
 <a href="https://isc.sans.edu/forums/diary/Blackhole+Advertising+Sites+with+Pihole/23377/">https://isc.sans.edu/forums/diary/Blackhole+Advertising+Sites+with+Pihole/23377/</a><br/>
Taxslayer Consent Degree with FTC<br/>
 <a href="https://biglawbusiness.com/cybersecurity-enforcers-wake-up-to-unauthorized-computer-access-via-credential-stuffing/">https://biglawbusiness.com/cybersecurity-enforcers-wake-up-to-unauthorized-computer-access-via-credential-stuffing/</a><br/>
Fortinet (OMG) Mirai <br/>
 <a href="https://www.fortinet.com/blog/threat-research/omg--mirai-based-bot-turns-iot-devices-into-proxy-servers.html">https://www.fortinet.com/blog/threat-research/omg--mirai-based-bot-turns-iot-devices-into-proxy-servers.html</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5885" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5853</itunes:episode>
<itunes:subtitle>Adobe Flash 0-Day; Adaptive Phishing Kit; Crypto Miners Replace Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Adobe Flash 0-Day; Adaptive Phishing Kit; Crypto Miners Replace Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5853.mp3" length="4655455" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5853.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5853</link>
<pubDate>Fri, 02 Feb 2018 02:25:05 GMT</pubDate>
<description><![CDATA[Adobe Flash 0-Day<br/>
 <a href="https://isc.sans.edu/forums/diary/Adobe+Flash+0Day+Used+Against+South+Korean+Targets/23301/">https://isc.sans.edu/forums/diary/Adobe+Flash+0Day+Used+Against+South+Korean+Targets/23301/</a><br/>
Adaptive Phishing Kit<br/>
 <a href="https://isc.sans.edu/forums/diary/Adaptive+Phishing+Kit/23299/">https://isc.sans.edu/forums/diary/Adaptive+Phishing+Kit/23299/</a><br/>
Crypto Miners "Payload of Choice"<br/>
 <a href="http://blog.talosintelligence.com/2018/01/malicious-xmr-mining.html">http://blog.talosintelligence.com/2018/01/malicious-xmr-mining.html</a><br/>
Autosploit Links Shodan to Metasploit<br/>
 <a href="https://github.com/NullArray/AutoSploit">https://github.com/NullArray/AutoSploit</a><br/>
]]></description>
<itunes:duration>5:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5853" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 1st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5851</itunes:episode>
<itunes:subtitle>Tax Phishing Season; Hunting Miners with IR; MICROS POS Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tax Phishing Season; Hunting Miners with IR; MICROS POS Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5851.mp3" length="5762104" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5851.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5851</link>
<pubDate>Thu, 01 Feb 2018 04:05:05 GMT</pubDate>
<description><![CDATA[Tax Phishing Season Starts<br/>
 <a href="https://isc.sans.edu/forums/diary/Tax+Phishing+Time/23295/">https://isc.sans.edu/forums/diary/Tax+Phishing+Time/23295/</a><br/>
Using FLIR In Incident Response<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+FLIR+in+Incident+Response/23291/">https://isc.sans.edu/forums/diary/Using+FLIR+in+Incident+Response/23291/</a><br/>
Oracle MICROS POS Vulnerability<br/>
 <a href="https://erpscan.com/press-center/blog/oracle-micros-pos-breached/">https://erpscan.com/press-center/blog/oracle-micros-pos-breached/</a><br/>
]]></description>
<itunes:duration>6:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5851" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 31st 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5849</itunes:episode>
<itunes:subtitle>DCShadow Attack; Cisco WebVPN Vulnerability Update; Bypassing DDE Protection via OneNote
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DCShadow Attack; Cisco WebVPN Vulnerability Update; Bypassing DDE Protection via OneNote
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5849.mp3" length="5845867" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5849.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5849</link>
<pubDate>Tue, 30 Jan 2018 22:45:06 GMT</pubDate>
<description><![CDATA[DCShadow Attack<br/>
 <a href="https://www.dropbox.com/s/baypdb6glmvp0j9/Buehat%20IL%20v2.3.pdf">https://www.dropbox.com/s/baypdb6glmvp0j9/Buehat%20IL%20v2.3.pdf</a><br/>
 <a href="https://blog.alsid.eu/dcshadow-explained-4510f52fc19d">https://blog.alsid.eu/dcshadow-explained-4510f52fc19d</a><br/>
Cisco WebVPN Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Cisco+ASA+WebVPN+Vulnerability/23289/">https://isc.sans.edu/forums/diary/Cisco+ASA+WebVPN+Vulnerability/23289/</a><br/>
Reviving DDE Code Execution via OneNote<br/>
 <a href="https://posts.specterops.io/reviving-dde-using-onenote-and-excel-for-code-execution-d7226864caee">https://posts.specterops.io/reviving-dde-using-onenote-and-excel-for-code-execution-d7226864caee</a><br/>
]]></description>
<itunes:duration>6:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5849" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 30th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5847</itunes:episode>
<itunes:subtitle>Insecure Security: Lenovo Fingerprints; ClamAV; Malware Bytes; Cisco
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Insecure Security: Lenovo Fingerprints; ClamAV; Malware Bytes; Cisco
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5847.mp3" length="5212295" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5847.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5847</link>
<pubDate>Tue, 30 Jan 2018 02:50:06 GMT</pubDate>
<description><![CDATA[Lenovo Fingerprint Mananger Pro Vulnerability<br/>
 <a href="https://support.lenovo.com/us/en/product_security/len-15999">https://support.lenovo.com/us/en/product_security/len-15999</a><br/>
ClamAV Vulnerablities<br/>
 <a href="http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html">http://blog.clamav.net/2018/01/clamav-0993-has-been-released.html</a><br/>
 <a href="https://blog.malwarebytes.com/malwarebytes-news/2018/01/important-web-blocking-ram-usage/">https://blog.malwarebytes.com/malwarebytes-news/2018/01/important-web-blocking-ram-usage/</a><br/>
Malwarebytes Corrupted Update<br/>
 <a href="https://www.malwarebytes.com/pdf/WebProtectionFP.pdf">https://www.malwarebytes.com/pdf/WebProtectionFP.pdf</a><br/>
Cisco Adaptive Security Appliance Remote Code Execution Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180129-asa1</a><br/>
Web2Top Proxy onion.tor Appears to Steal Ransomware Payments<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/double-dipping-diverting-ransomware-bitcoin-payments-onion-domains">https://www.proofpoint.com/us/threat-insight/post/double-dipping-diverting-ransomware-bitcoin-payments-onion-domains</a><br/>
]]></description>
<itunes:duration>6:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5847" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 29th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5845</itunes:episode>
<itunes:subtitle>Pentests and Maldocs; Invetigating BITS; YouTube Hit By CryptoJacking; Coincheck Hack; PHPBB Malicio</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Pentests and Maldocs; Invetigating BITS; YouTube Hit By CryptoJacking; Coincheck Hack; PHPBB Malicio</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5845.mp3" length="5201561" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5845.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5845</link>
<pubDate>Mon, 29 Jan 2018 02:35:05 GMT</pubDate>
<description><![CDATA[Analyzing a Word Document Used in a Pentest<br/>
<a href="https://isc.sans.edu/forums/diary/Is+this+a+pentest/23283/">https://isc.sans.edu/forums/diary/Is+this+a+pentest/23283/</a><br/>
Analyzing BITS Activity<br/>
<a href="https://isc.sans.edu/forums/diary/Investigating+Microsoft+BITS+Activity/23281/">https://isc.sans.edu/forums/diary/Investigating+Microsoft+BITS+Activity/23281/</a><br/>
CryptoJacking on YouTube due to Malicious Ads<br/>
<a href="https://blog.trendmicro.com/trendlabs-security-intelligence/malvertising-campaign-abuses-googles-doubleclick-to-deliver-cryptocurrency-miners/">https://blog.trendmicro.com/trendlabs-security-intelligence/malvertising-campaign-abuses-googles-doubleclick-to-deliver-cryptocurrency-miners/</a><br/>
Coincheck Hack Nets 400M USD<br/>
<a href="https://coincheck.com/en/blog/4673">https://coincheck.com/en/blog/4673</a><br/>
PHPBB Mirror Compromissed<br/>
<a href="https://www.phpbb.com/community/viewtopic.php?f=14&t=2456896">https://www.phpbb.com/community/viewtopic.php?f=14&t=2456896</a><br/>
Microsoft Disables Sepctre Variant 2 Patches<br/>
<a href="https://support.microsoft.com/en-us/help/4078130/update-to-disable-mitigation-against-spectre-variant-2">https://support.microsoft.com/en-us/help/4078130/update-to-disable-mitigation-against-spectre-variant-2</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5845" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 26th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5843</itunes:episode>
<itunes:subtitle>Ransomware As A Service; libcurl Vulnerability; Hide 'N Seek Botnet
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ransomware As A Service; libcurl Vulnerability; Hide 'N Seek Botnet
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5843.mp3" length="14879847" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5843.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5843</link>
<pubDate>Thu, 25 Jan 2018 23:25:06 GMT</pubDate>
<description><![CDATA[Ransomware As a Service<br/>
 <a href="https://isc.sans.edu/forums/diary/Ransomware+as+a+Service/23277/">https://isc.sans.edu/forums/diary/Ransomware+as+a+Service/23277/</a><br/>
libcurl Vulnerability<br/>
 <a href="http://seclists.org/oss-sec/2018/q1/94">http://seclists.org/oss-sec/2018/q1/94</a><br/>
Hide 'N Seek IoT Botnet<br/>
 <a href="https://labs.bitdefender.com/2018/01/new-hide-n-seek-iot-botnet-using-custom-built-peer-to-peer-communication-spotted-in-the-wild/">https://labs.bitdefender.com/2018/01/new-hide-n-seek-iot-botnet-using-custom-built-peer-to-peer-communication-spotted-in-the-wild/</a><br/>
Container Intrusions: Assessing the Efficacy of Intrusion Detection and Analysis Methods for Linux Container Environments<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/detection/container-intrusions-assessing-efficacy-intrusion-detection-analysis-methods-linux-container-environments-38245">https://www.sans.org/reading-room/whitepapers/detection/container-intrusions-assessing-efficacy-intrusion-detection-analysis-methods-linux-container-environments-38245</a><br/>
]]></description>
<itunes:duration>17:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5843" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 25th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5841</itunes:episode>
<itunes:subtitle>RTF Files With Hancitor; Electron Dev Tool Creates Vulnerable Windows Apps;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RTF Files With Hancitor; Electron Dev Tool Creates Vulnerable Windows Apps;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5841.mp3" length="4717574" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5841.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5841</link>
<pubDate>Thu, 25 Jan 2018 02:45:06 GMT</pubDate>
<description><![CDATA[RTF Files For Hancitor Utilize Exploit for CVE-2017-11882<br/>
 <a href="https://isc.sans.edu/forums/diary/RTF+files+for+Hancitor+utilize+exploit+for+CVE201711882/23271/">https://isc.sans.edu/forums/diary/RTF+files+for+Hancitor+utilize+exploit+for+CVE201711882/23271/</a><br/>
Electron Fixes Protocol Handlers Flaw<br/>
 <a href="https://electronjs.org/blog/protocol-handler-fix">https://electronjs.org/blog/protocol-handler-fix</a><br/>
Xerox Workcenters Fudge Numbers<br/>
 <a href="http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_are_switching_written_numbers_when_scanning?">http://www.dkriesel.com/en/blog/2013/0802_xerox-workcentres_are_switching_written_numbers_when_scanning?</a><br/>
Tracking Users Using CSS<br/>
 <a href="https://github.com/jbtronics/CrookedStyleSheets">https://github.com/jbtronics/CrookedStyleSheets</a><br/>
]]></description>
<itunes:duration>5:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5841" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 24th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5839</itunes:episode>
<itunes:subtitle>Apple Patches; OpenSSL Patch Tuesday; Rapid Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Patches; OpenSSL Patch Tuesday; Rapid Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5839.mp3" length="4633282" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5839.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5839</link>
<pubDate>Wed, 24 Jan 2018 03:05:05 GMT</pubDate>
<description><![CDATA[Apple Patches Everything, Again<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Updates+Everything+Again/23269/">https://isc.sans.edu/forums/diary/Apple+Updates+Everything+Again/23269/</a><br/>
OpenSSL Introduces its Version of a "Patch Tuesday"<br/>
 <a href="https://www.openssl.org/blog/blog/2018/01/18/f2f-london/">https://www.openssl.org/blog/blog/2018/01/18/f2f-london/</a><br/>
"Rapid" Ransomware<br/>
 <a href="https://id-ransomware.blogspot.ru/2018/01/rapid-ransomware.html">https://id-ransomware.blogspot.ru/2018/01/rapid-ransomware.html</a> (Russian)<br/>
 <a href="https://www.bleepingcomputer.com/forums/t/667032/rapid-ransomware-rapid-paymeme-how-recovery-filestxt-support-topic/page-2">https://www.bleepingcomputer.com/forums/t/667032/rapid-ransomware-rapid-paymeme-how-recovery-filestxt-support-topic/page-2</a><br/>
]]></description>
<itunes:duration>5:30</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5839" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 23rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5837</itunes:episode>
<itunes:subtitle>HTTPs on Every Port? Curl over TOR; Spectre/Meltdown Microcode Update Woes; Quantum Cryptography Vid</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HTTPs on Every Port? Curl over TOR; Spectre/Meltdown Microcode Update Woes; Quantum Cryptography Vid</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5837.mp3" length="4272667" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5837.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5837</link>
<pubDate>Tue, 23 Jan 2018 02:40:05 GMT</pubDate>
<description><![CDATA[HTTPs on Every Port<br/>
 <a href="https://isc.sans.edu/forums/diary/HTTPS+on+every+port/23261/">https://isc.sans.edu/forums/diary/HTTPS+on+every+port/23261/</a><br/>
Curl over TOR<br/>
 <a href="https://isc.sans.edu/forums/diary/Retrieving+malware+over+Tor/23257/">https://isc.sans.edu/forums/diary/Retrieving+malware+over+Tor/23257/</a><br/>
Spectre/Meltdown Microcode Patch Problems<br/>
 <a href="https://newsroom.intel.com/news/root-cause-of-reboot-issue-identified-updated-guidance-for-customers-and-partners/">https://newsroom.intel.com/news/root-cause-of-reboot-issue-identified-updated-guidance-for-customers-and-partners/</a><br/>
 <a href="https://lkml.org/lkml/2018/1/21/192">https://lkml.org/lkml/2018/1/21/192</a><br/>
DNS Rebinding Attacks Against Geth<br/>
 <a href="https://ret2got.wordpress.com/2018/01/19/how-your-ethereum-can-be-stolen-using-dns-rebinding/">https://ret2got.wordpress.com/2018/01/19/how-your-ethereum-can-be-stolen-using-dns-rebinding/</a><br/>
Chinese Quantum Cryptography Satellite Link Transmits Intercontinental Videolink<br/>
 <a href="https://journals.aps.org/prl/abstract/10.1103/PhysRevLett.120.030501">https://journals.aps.org/prl/abstract/10.1103/PhysRevLett.120.030501</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5837" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 22nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5835</itunes:episode>
<itunes:subtitle>RTF Phish; Claymore Miner Attacks; Evrial Modifies Clipboard; Bug Bounty Legal Challenges
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
RTF Phish; Claymore Miner Attacks; Evrial Modifies Clipboard; Bug Bounty Legal Challenges
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5835.mp3" length="4436552" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5835.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5835</link>
<pubDate>Mon, 22 Jan 2018 02:30:07 GMT</pubDate>
<description><![CDATA[Analyzing an RTF Phishing Document<br/>
 <a href="https://isc.sans.edu/forums/diary/An+RTF+phish/23255/">https://isc.sans.edu/forums/diary/An+RTF+phish/23255/</a><br/>
Satori Variant Steals ETH from Miners<br/>
 <a href="http://blog.netlab.360.com/art-of-steal-satori-variant-is-robbing-eth-bitcoin-by-replacing-wallet-address-en/">http://blog.netlab.360.com/art-of-steal-satori-variant-is-robbing-eth-bitcoin-by-replacing-wallet-address-en/</a><br/>
Evrial Trojan Modifies Copy / Pasted Bitcoin Addresses<br/>
 <a href="https://twitter.com/malwrhunterteam/status/953313514629853184">https://twitter.com/malwrhunterteam/status/953313514629853184</a><br/>
Legal Challenges of Bug Bounties<br/>
 <a href="https://www.heise.de/security/meldung/US-Bug-Bountys-lassen-gute-Hacker-in-die-Falle-tappen-3946508.html">https://www.heise.de/security/meldung/US-Bug-Bountys-lassen-gute-Hacker-in-die-Falle-tappen-3946508.html</a><br/>
]]></description>
<itunes:duration>5:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5835" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 19th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5833</itunes:episode>
<itunes:subtitle>Oracle EBS Vulnerable via WebLogic; MSFT Resumes AMD Patches; Infusion Pump Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oracle EBS Vulnerable via WebLogic; MSFT Resumes AMD Patches; Infusion Pump Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5833.mp3" length="4338754" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5833.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5833</link>
<pubDate>Fri, 19 Jan 2018 02:55:05 GMT</pubDate>
<description><![CDATA[Oracle E-Business Suite Server Can Be Attackt via WebLogic<br/>
 <a href="https://www.onapsis.com/blog/oracle-january-cpu-analysis-64-patches-affect-business-critical-applications">https://www.onapsis.com/blog/oracle-january-cpu-analysis-64-patches-affect-business-critical-applications</a><br/>
Microsoft Resumes Patches for AMD Systems<br/>
 <a href="https://www.amd.com/en/corporate/speculative-execution">https://www.amd.com/en/corporate/speculative-execution</a><br/>
Speculations About Yet Another CPU Attack<br/>
 <a href="https://skyfallattack.com">https://skyfallattack.com</a><br/>
Smiths Medfusion 4000 Vulnerabilities<br/>
 <a href="https://github.com/sgayou/medfusion-4000-research/blob/master/doc/README.md#summary">https://github.com/sgayou/medfusion-4000-research/blob/master/doc/README.md#summary</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5833" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 18th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5831</itunes:episode>
<itunes:subtitle>Fresh From the Spam Filter; Auditing Secure USB Keys; iMessage DoS; BIND fixes DoS Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fresh From the Spam Filter; Auditing Secure USB Keys; iMessage DoS; BIND fixes DoS Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5831.mp3" length="4393575" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5831.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5831</link>
<pubDate>Thu, 18 Jan 2018 02:30:06 GMT</pubDate>
<description><![CDATA[Reviewing the Spam Filters: Malspam Pushing Gozi-ISFB<br/>
 <a href="https://isc.sans.edu/forums/diary/Reviewing+the+spam+filters+Malspam+pushing+GoziISFB/23245/">https://isc.sans.edu/forums/diary/Reviewing+the+spam+filters+Malspam+pushing+GoziISFB/23245/</a><br/>
Auditing Secure USB Keys<br/>
 <a href="https://www.j-michel.org/blog/2018/01/16/attacking-secure-usb-keys-behind-the-scene">https://www.j-michel.org/blog/2018/01/16/attacking-secure-usb-keys-behind-the-scene</a><br/>
Malicious Open Graph title Tag Crashes iMessage<br/>
 <a href="https://www.macrumors.com/2018/01/16/malicious-link-ios-mac-freezes/">https://www.macrumors.com/2018/01/16/malicious-link-ios-mac-freezes/</a><br/>
BIND Fixes DoS Vulnerablity<br/>
 <a href="https://kb.isc.org/article/AA-01542">https://kb.isc.org/article/AA-01542</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5831" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 9th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5817</itunes:episode>
<itunes:subtitle>WebLogic Flaw Used To Install Crypto Miner;  Fake AV Is Back
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WebLogic Flaw Used To Install Crypto Miner;  Fake AV Is Back
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5817.mp3" length="4603243" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5817.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5817</link>
<pubDate>Tue, 09 Jan 2018 00:10:05 GMT</pubDate>
<description><![CDATA[WebLogic Flaw Used to Install Monero Crypto Coin Miner<br/>
 <a href="https://isc.sans.edu/forums/diary/Campaign+is+using+a+recently+released+WebLogic+exploit+to+deploy+a+Monero+miner/23191/">https://isc.sans.edu/forums/diary/Campaign+is+using+a+recently+released+WebLogic+exploit+to+deploy+a+Monero+miner/23191/</a><br/>
Fake Anti-Virus Pages Poppding Up Like Weeds<br/>
 <a href="https://isc.sans.edu/forums/diary/Fake+antivirus+pages+popping+up+like+weeds/23207/">https://isc.sans.edu/forums/diary/Fake+antivirus+pages+popping+up+like+weeds/23207/</a><br/>
Apple Spectre/Meltdown Patches<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Meltdown Patch Fallout<br/>
 <a href="https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB43600/?l=en_US&fs=Search&pn=1&atype=">https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB43600/?l=en_US&fs=Search&pn=1&atype=</a><br/>
 <a href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=25114">https://forums.sandboxie.com/phpBB3/viewtopic.php?t=25114</a><br/>
 <a href="https://support.microsoft.com/en-us/help/4072699/january-3-2018-windows-security-updates-and-antivirus-software">https://support.microsoft.com/en-us/help/4072699/january-3-2018-windows-security-updates-and-antivirus-software</a><br/>
WPA3 Announced<br/>
 <a href="https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-security-enhancements">https://www.wi-fi.org/news-events/newsroom/wi-fi-alliance-introduces-security-enhancements</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5817" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 8th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5815</itunes:episode>
<itunes:subtitle>Weblogic Flaw Exploited by Cryptominer; More Spectre and Meltdown news;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Weblogic Flaw Exploited by Cryptominer; More Spectre and Meltdown news;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5815.mp3" length="4411893" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5815.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5815</link>
<pubDate>Mon, 08 Jan 2018 00:45:04 GMT</pubDate>
<description><![CDATA[Campaign is using a recently released WebLogic exploit to deploy a Monero miner<br/>
 <a href="https://isc.sans.edu/forums/diary/Campaign+is+using+a+recently+released+WebLogic+exploit+to+deploy+a+Monero+miner/23191/">https://isc.sans.edu/forums/diary/Campaign+is+using+a+recently+released+WebLogic+exploit+to+deploy+a+Monero+miner/23191/</a><br/>
Misc News about Meltdown and Spectre<br/>
 <a href="https://www.qualcomm.com/company/product-security/bulletins">https://www.qualcomm.com/company/product-security/bulletins</a><br/>
AMD Processor Flaw<br/>
 <a href="http://seclists.org/fulldisclosure/2018/Jan/12">http://seclists.org/fulldisclosure/2018/Jan/12</a><br/>
Western Digital MyCloud Backdoor<br/>
 <a href="http://gulftech.org/advisories/WDMyCloud%20Multiple%20Vulnerabilities/125">http://gulftech.org/advisories/WDMyCloud%20Multiple%20Vulnerabilities/125</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5815" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 5th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5813</itunes:episode>
<itunes:subtitle>SPECTRE and MELTDOWN Vulnerabilities (and MSFT emergency patch)</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SPECTRE and MELTDOWN Vulnerabilities (and MSFT emergency patch)</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5813.mp3" length="6515105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5813.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5813</link>
<pubDate>Fri, 05 Jan 2018 00:30:07 GMT</pubDate>
<description><![CDATA[SANS Special Webcast<br/>
<a href="https://www.sans.org/webcast/recording/citrix/106815/138095">https://www.sans.org/webcast/recording/citrix/106815/138095</a><br/>
ISC Diary with Links to Patches<br/>
 <a href="https://isc.sans.edu/forums/diary/Spectre+and+Meltdown+What+You+Need+to+Know+Right+Now/23193/">https://isc.sans.edu/forums/diary/Spectre+and+Meltdown+What+You+Need+to+Know+Right+Now/23193/</a><br/>
]]></description>
<itunes:duration>7:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5813" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 4th 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5811</itunes:episode>
<itunes:subtitle>Upcoming Intel CPU Vulnerability Patch; Crypto Miner Pool IP Feed; #Peoplesoft #Weblogic Exploits; B</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Upcoming Intel CPU Vulnerability Patch; Crypto Miner Pool IP Feed; #Peoplesoft #Weblogic Exploits; B</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5811.mp3" length="6352283" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5811.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5811</link>
<pubDate>Thu, 04 Jan 2018 01:20:04 GMT</pubDate>
<description><![CDATA[Intel CPU Vulnerablity<br/>
 <a href="https://meltdownattack.com">https://meltdownattack.com</a><br/>
Crypto Coin Mining Pool IP List<br/>
 <a href="https://isc.sans.edu/api/threatlist/miner">https://isc.sans.edu/api/threatlist/miner</a><br/>
Phishing to Rural America Leads to Six-figure Wire Fraud Losses<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+to+Rural+America+Leads+to+Sixfigure+Wire+Fraud+Losses/23185/">https://isc.sans.edu/forums/diary/Phishing+to+Rural+America+Leads+to+Sixfigure+Wire+Fraud+Losses/23185/</a><br/>
]]></description>
<itunes:duration>7:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5811" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 3rd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5809</itunes:episode>
<itunes:subtitle>Extracting URLs From PDFs; Local PE in macOS; 34C3 Videos; GPS Website Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Extracting URLs From PDFs; Local PE in macOS; 34C3 Videos; GPS Website Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5809.mp3" length="5704851" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5809.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5809</link>
<pubDate>Wed, 03 Jan 2018 01:55:04 GMT</pubDate>
<description><![CDATA[Extracting URLs From PDFs<br/>
 <a href="https://isc.sans.edu/forums/diary/PDF+documents+URLs+update/23167/">https://isc.sans.edu/forums/diary/PDF+documents+URLs+update/23167/</a><br/>
Priviledge Escalation Exploit for macOS <br/>
 <a href="https://siguza.github.io/IOHIDeous/">https://siguza.github.io/IOHIDeous/</a><br/>
34C3: Chaos Communications Congress<br/>
 <a href="https://media.ccc.de/c/34c3">https://media.ccc.de/c/34c3</a><br/>
Vulnerabilities in Online Geolocation Services<br/>
 <a href="https://0x0.li/trackmageddon/">https://0x0.li/trackmageddon/</a><br/>
]]></description>
<itunes:duration>6:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5809" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 2nd 2018</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5807</itunes:episode>
<itunes:subtitle>Analyzing Obuscated #RTF and #TNEF files; Record Number of CVEs; Sonos/Bose Vuln; More Backdoored Wo</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing Obuscated #RTF and #TNEF files; Record Number of CVEs; Sonos/Bose Vuln; More Backdoored Wo</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5807.mp3" length="6186184" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5807.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5807</link>
<pubDate>Mon, 01 Jan 2018 23:55:04 GMT</pubDate>
<description><![CDATA[Analyzing TNEF Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+TNEF+files/23175/">https://isc.sans.edu/forums/diary/Analyzing+TNEF+files/23175/</a><br/>
Obfuscated RTF Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Dealing+with+obfuscated+RTF+files/23169/">https://isc.sans.edu/forums/diary/Dealing+with+obfuscated+RTF+files/23169/</a><br/>
2017 Flood of CVEs<br/>
 <a href="https://isc.sans.edu/forums/diary/2017+The+Flood+of+CVEs/23173/">https://isc.sans.edu/forums/diary/2017+The+Flood+of+CVEs/23173/</a><br/>
Sonos/Bose Smart Speaker Flaws<br/>
 <a href="https://documents.trendmicro.com/assets/pdf/The-Sound-of-a-Targeted-Attack.pdf">https://documents.trendmicro.com/assets/pdf/The-Sound-of-a-Targeted-Attack.pdf</a><br/>
Web Trackers Exploit Login Managers<br/>
 <a href="https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/">https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/</a><br/>
Backdoored Wordpress Plugins<br/>
 <a href="https://www.bleepingcomputer.com/news/security/three-more-wordpress-plugins-found-hiding-a-backdoor/">https://www.bleepingcomputer.com/news/security/three-more-wordpress-plugins-found-hiding-a-backdoor/</a><br/>
]]></description>
<itunes:duration>7:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5807" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5805</itunes:episode>
<itunes:subtitle>Critical EMC SMB1 Flaw; EtherDelta DNS Hack; Engimail Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Critical EMC SMB1 Flaw; EtherDelta DNS Hack; Engimail Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5805.mp3" length="5286692" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5805.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5805</link>
<pubDate>Fri, 22 Dec 2017 03:15:05 GMT</pubDate>
<description><![CDATA[Critical Flaw in SMBv1 Implementation of Dell EMC Data Domain DD OS<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Dec/79">http://seclists.org/fulldisclosure/2017/Dec/79</a><br/>
Facebook Enables Feature To Review All E-Mails Sent By Facebook <br/>
 <a href="https://www.facebook.com/notes/facebook-security/new-security-feature-reveals-if-facebook-mails-are-legit/10154983636230766/">https://www.facebook.com/notes/facebook-security/new-security-feature-reveals-if-facebook-mails-are-legit/10154983636230766/</a><br/>
EtherDelta DNS Attack<br/>
 <a href="https://twitter.com/etherdelta">https://twitter.com/etherdelta</a><br/>
Enigmail Vulnerability<br/>
 <a href="https://enigmail.net/download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf">https://enigmail.net/download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5805" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5803</itunes:episode>
<itunes:subtitle>Kernel Hooking; Intel Memory Encryption / Linux Support for AMD's Encryption
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kernel Hooking; Intel Memory Encryption / Linux Support for AMD's Encryption
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5803.mp3" length="4096332" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5803.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5803</link>
<pubDate>Thu, 21 Dec 2017 01:40:04 GMT</pubDate>
<description><![CDATA[Kernel Hooking Basics<br/>
 <a href="https://isc.sans.edu/forums/diary/Guest+Diary+Etay+Nir+Kernel+Hooking+Basics/23155/">https://isc.sans.edu/forums/diary/Guest+Diary+Etay+Nir+Kernel+Hooking+Basics/23155/</a><br/>
Intel Memory Encryption<br/>
 <a href="https://software.intel.com/sites/default/files/managed/a5/16/Multi-Key-Total-Memory-Encryption-Spec.pdf">https://software.intel.com/sites/default/files/managed/a5/16/Multi-Key-Total-Memory-Encryption-Spec.pdf</a><br/>
 <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=33e63acc119d15c2fac3e3775f32d1ce7a01021b">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=33e63acc119d15c2fac3e3775f32d1ce7a01021b</a><br/>
 <br/>
WordPress Sites Infected with Monero Miners<br/>
 <a href="https://www.wordfence.com/blog/2017/12/aggressive-brute-force-wordpress-attack/">https://www.wordfence.com/blog/2017/12/aggressive-brute-force-wordpress-attack/</a><br/>
]]></description>
<itunes:duration>4:51</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5803" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5801</itunes:episode>
<itunes:subtitle>Dangers of Mouseover; Update on Adups; Comparing DNS Filters
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dangers of Mouseover; Update on Adups; Comparing DNS Filters
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5801.mp3" length="4617033" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5801.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5801</link>
<pubDate>Wed, 20 Dec 2017 00:00:10 GMT</pubDate>
<description><![CDATA[Example of "MouseOver" Link in a Powerpoint File<br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+MouseOver+Link+in+a+Powerpoint+File/23149/">https://isc.sans.edu/forums/diary/Example+of+MouseOver+Link+in+a+Powerpoint+File/23149/</a><br/>
Adups Malware Still Haunting Android Phones<br/>
 <a href="https://blog.malwarebytes.com/cybercrime/2017/12/mobile-menace-monday-upping-the-ante-on-adups-fwupgradeprovider/">https://blog.malwarebytes.com/cybercrime/2017/12/mobile-menace-monday-upping-the-ante-on-adups-fwupgradeprovider/</a><br/>
Popular Wordpress Captcha Included Backdoor<br/>
 <a href="https://www.wordfence.com/blog/2017/12/backdoor-captcha-plugin/">https://www.wordfence.com/blog/2017/12/backdoor-captcha-plugin/</a><br/>
Comparing DNS Filters<br/>
 <a href="https://medium.com/@nykolas.z/dns-security-filters-compared-quad9-x-opendns-x-comodo-secure-x-norton-connectsafe-x-yandex-safe-a00ace3bf21f">https://medium.com/@nykolas.z/dns-security-filters-compared-quad9-x-opendns-x-comodo-secure-x-norton-connectsafe-x-yandex-safe-a00ace3bf21f</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5801" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5799</itunes:episode>
<itunes:subtitle>Not So Malicious Word Doc; AMF Deserializer Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Not So Malicious Word Doc; AMF Deserializer Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5799.mp3" length="4447529" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5799.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5799</link>
<pubDate>Tue, 19 Dec 2017 02:20:03 GMT</pubDate>
<description><![CDATA[Not So Malicious Word Doc<br/>
 <a href="https://isc.sans.edu/forums/diary/Phish+or+scam+Part+1/23141/">https://isc.sans.edu/forums/diary/Phish+or+scam+Part+1/23141/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Phish+or+scam+Part+2/23145/">https://isc.sans.edu/forums/diary/Phish+or+scam+Part+2/23145/</a><br/>
AMF Descerializer Vulnerability<br/>
 <a href="http://codewhitesec.blogspot.com/2017/04/amf.html?m=1">http://codewhitesec.blogspot.com/2017/04/amf.html?m=1</a><br/>
Windows "Keeper" Password Manager Vulnerable<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1481&desc=3">https://bugs.chromium.org/p/project-zero/issues/detail?id=1481&desc=3</a><br/>
Android Malware Destroys Device<br/>
 <a href="https://securelist.com/jack-of-all-trades/83470/">https://securelist.com/jack-of-all-trades/83470/</a><br/>
]]></description>
<itunes:duration>5:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5799" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5797</itunes:episode>
<itunes:subtitle>VBA Macro Obfuscation; Large Scale BGP Attack; HSTS/key pinning weakness
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
VBA Macro Obfuscation; Large Scale BGP Attack; HSTS/key pinning weakness
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5797.mp3" length="4838625" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5797.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5797</link>
<pubDate>Mon, 18 Dec 2017 01:45:03 GMT</pubDate>
<description><![CDATA[Microsoft Office VBA Macro Obfuscation via Metadata<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Office+VBA+Macro+Obfuscation+via+Metadata/23139/">https://isc.sans.edu/forums/diary/Microsoft+Office+VBA+Macro+Obfuscation+via+Metadata/23139/</a><br/>
Large Scale BGP Attack<br/>
 <a href="https://bgpmon.net/popular-destinations-rerouted-to-russia/">https://bgpmon.net/popular-destinations-rerouted-to-russia/</a><br/>
HSTS and HPKP Weaknesses in Firefox, IE/Edge and Chrome<br/>
 <a href="http://blog.en.elevenpaths.com/2017/12/breaking-out-hsts-and-hpkp-on-firefox.html">http://blog.en.elevenpaths.com/2017/12/breaking-out-hsts-and-hpkp-on-firefox.html</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5797" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5795</itunes:episode>
<itunes:subtitle>Citizen Lab Security Planner; Minor Apple Updates; Fortinet Shared Key
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Citizen Lab Security Planner; Minor Apple Updates; Fortinet Shared Key
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5795.mp3" length="4558692" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5795.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5795</link>
<pubDate>Fri, 15 Dec 2017 02:05:03 GMT</pubDate>
<description><![CDATA[Citizen Lab Security Planner<br/>
 <a href="https://securityplanner.org/">https://securityplanner.org/</a><br/>
Apple Update to iOS/tvOS/iCloud (Windows)<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Fortinet Client Credentials Shared Key<br/>
 <a href="https://www.sec-consult.com/en/blog/advisories/vpn-credentials-disclosure-in-fortinet-forticlient/index.html">https://www.sec-consult.com/en/blog/advisories/vpn-credentials-disclosure-in-fortinet-forticlient/index.html</a><br/>
Fox-It Victim of a Man-in-the-Middle Attack<br/>
 <a href="https://blog.fox-it.com/2017/12/14/lessons-learned-from-a-man-in-the-middle-attack/">https://blog.fox-it.com/2017/12/14/lessons-learned-from-a-man-in-the-middle-attack/</a><br/>
]]></description>
<itunes:duration>5:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5795" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5793</itunes:episode>
<itunes:subtitle>Tracking New Domains; PAN-OS RCE As root; Hiding Changes from git-diff
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Tracking New Domains; PAN-OS RCE As root; Hiding Changes from git-diff
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5793.mp3" length="4414895" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5793.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5793</link>
<pubDate>Thu, 14 Dec 2017 03:20:03 GMT</pubDate>
<description><![CDATA[Tracking Newly Registered Domains<br/>
 <a href="https://isc.sans.edu/forums/diary/Tracking+Newly+Registered+Domains/23127/">https://isc.sans.edu/forums/diary/Tracking+Newly+Registered+Domains/23127/</a><br/>
Critical Palo Alto Firewall Flaws Allow RCE as root<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Dec/38">http://seclists.org/fulldisclosure/2017/Dec/38</a><br/>
Hiding Changes from git-diff<br/>
 <a href="https://www.twistlock.com/2017/12/13/hiding-content-git-escape-sequence-twistlock-labs-experiment/">https://www.twistlock.com/2017/12/13/hiding-content-git-escape-sequence-twistlock-labs-experiment/</a><br/>
Apple Airport Update<br/>
 <a href="https://support.apple.com/en-us/HT208354">https://support.apple.com/en-us/HT208354</a><br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5793" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5791</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; Obtaining Misleading EV Certs; Robot TLS Attack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; Obtaining Misleading EV Certs; Robot TLS Attack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5791.mp3" length="5489341" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5791.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5791</link>
<pubDate>Wed, 13 Dec 2017 03:20:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday Summary<br/>
 <a href="https://isc.sans.edu/forums/diary/December+Microsoft+Patch+Tuesday+Summary/23123/">https://isc.sans.edu/forums/diary/December+Microsoft+Patch+Tuesday+Summary/23123/</a><br/>
EV Certificate Model Broken?<br/>
 <a href="https://stripe.ian.sh">https://stripe.ian.sh</a><br/>
ROBOT Attack Against TLS<br/>
 <a href="https://robotattack.org">https://robotattack.org</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5791" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5789</itunes:episode>
<itunes:subtitle>Porn Spam Pushing Coin Miner; Recover Edited Windows Logs; Proxy Botnet News
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Porn Spam Pushing Coin Miner; Recover Edited Windows Logs; Proxy Botnet News
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5789.mp3" length="5484705" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5789.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5789</link>
<pubDate>Tue, 12 Dec 2017 01:30:03 GMT</pubDate>
<description><![CDATA[Pornographic Spam Messages Used to Deliver Crypto Coin Miner<br/>
 <a href="https://isc.sans.edu/forums/diary/Pornographic+malspam+pushes+coin+miner+malware/23119/">https://isc.sans.edu/forums/diary/Pornographic+malspam+pushes+coin+miner+malware/23119/</a><br/>
Microsoft Leaks Secret SSL Key For Dynamics 365<br/>
 <a href="https://medium.com/matthias-gliwka/microsoft-leaks-tls-private-key-for-cloud-erp-product-10b56f7d648">https://medium.com/matthias-gliwka/microsoft-leaks-tls-private-key-for-cloud-erp-product-10b56f7d648</a><br/>
Proxy Botnet Used to Launch Variety of Web Application Attacks<br/>
 <a href="https://news.drweb.com/show/?i=11627&lng=en">https://news.drweb.com/show/?i=11627&lng=en</a><br/>
FoxIT Releases Utility to Recover Manipulated Windows Logs<br/>
 <a href="https://github.com/fox-it/danderspritz-evtx">https://github.com/fox-it/danderspritz-evtx</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5789" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5787</itunes:episode>
<itunes:subtitle>HP Keyboard Drivers Key Stroke Logger; Android App Signature Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HP Keyboard Drivers Key Stroke Logger; Android App Signature Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5787.mp3" length="5239125" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5787.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5787</link>
<pubDate>Mon, 11 Dec 2017 01:45:03 GMT</pubDate>
<description><![CDATA[Sometimes An RTF Document is Just an RTF Document<br/>
 <a href="https://isc.sans.edu/forums/diary/Sometimes+its+a+dud/23115/">https://isc.sans.edu/forums/diary/Sometimes+its+a+dud/23115/</a><br/>
HP Keyboard Drivers Can Log Keystrokes<br/>
 <a href="https://support.hp.com/us-en/document/c05827409">https://support.hp.com/us-en/document/c05827409</a><br/>
 <a href="https://zwclose.github.io/HP-keylogger/">https://zwclose.github.io/HP-keylogger/</a><br/>
Android App Signature Bypass<br/>
 <a href="https://www.guardsquare.com/en/blog/new-android-vulnerability-allows-attackers-modify-apps-without-affecting-their-signatures">https://www.guardsquare.com/en/blog/new-android-vulnerability-allows-attackers-modify-apps-without-affecting-their-signatures</a><br/>
MSFT Patches Antimalware Engine<br/>
 <a href="https://portal.msrc.microsoft.com/en-US/eula">https://portal.msrc.microsoft.com/en-US/eula</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5787" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5785</itunes:episode>
<itunes:subtitle>Intel ME xploit demoed at BH Europe;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Intel ME xploit demoed at BH Europe;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5785.mp3" length="5988649" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5785.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5785</link>
<pubDate>Fri, 08 Dec 2017 02:15:03 GMT</pubDate>
<description><![CDATA[Positive Technologies Demonstrates Intel ME Exploit at Blackhat Europe<br/>
 <a href="https://www.blackhat.com/docs/eu-17/materials/eu-17-Goryachy-How-To-Hack-A-Turned-Off-Computer-Or-Running-Unsigned-Code-In-Intel-Management-Engine.pdf">https://www.blackhat.com/docs/eu-17/materials/eu-17-Goryachy-How-To-Hack-A-Turned-Off-Computer-Or-Running-Unsigned-Code-In-Intel-Management-Engine.pdf</a><br/>
Tracking Users Without GPS<br/>
 <a href="http://ieeexplore.ieee.org/document/8038870/">http://ieeexplore.ieee.org/document/8038870/</a><br/>
Process Doppelgaenger Anti-Malware Bypass<br/>
 <a href="https://www.blackhat.com/docs/eu-17/materials/eu-17-Liberman-Lost-In-Transaction-Process-Doppelganging.pdf">https://www.blackhat.com/docs/eu-17/materials/eu-17-Liberman-Lost-In-Transaction-Process-Doppelganging.pdf</a><br/>
Friday Webcast About Recent OWASP Top 10 Update<br/>
 <a href="https://www.sans.org/webcasts/owasp-top-10-2017-106560">https://www.sans.org/webcasts/owasp-top-10-2017-106560</a><br/>
]]></description>
<itunes:duration>7:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5785" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5783</itunes:episode>
<itunes:subtitle>Apple Updates Everything; Reverse DNS; Another Crytocoin Exchange Hacked
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Updates Everything; Reverse DNS; Another Crytocoin Exchange Hacked
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5783.mp3" length="5164159" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5783.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5783</link>
<pubDate>Wed, 06 Dec 2017 23:50:02 GMT</pubDate>
<description><![CDATA[Apple Updates Everything<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+Updates+Everything+Again/23107/">https://isc.sans.edu/forums/diary/Apple+Updates+Everything+Again/23107/</a><br/>
Do Not Trust Reverse DNS. And here is an example why<br/>
 <a href="https://isc.sans.edu/forums/diary/PSA+Do+not+Trust+Reverse+DNS+and+why+does+an+address+resolve+to+localhost/23105/">https://isc.sans.edu/forums/diary/PSA+Do+not+Trust+Reverse+DNS+and+why+does+an+address+resolve+to+localhost/23105/</a><br/>
NiceHash Hacked<br/>
 <a href="https://www.reddit.com/r/NiceHash/comments/7i0s6o/official_press_release_statement_by_nicehash/">https://www.reddit.com/r/NiceHash/comments/7i0s6o/official_press_release_statement_by_nicehash/</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5783" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5781</itunes:episode>
<itunes:subtitle>AI.Type Data Exposed; Mailsploit From Spoofing Tool; StorageCrypt; Android Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AI.Type Data Exposed; Mailsploit From Spoofing Tool; StorageCrypt; Android Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5781.mp3" length="4260857" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5781.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5781</link>
<pubDate>Wed, 06 Dec 2017 03:40:03 GMT</pubDate>
<description><![CDATA[AI.Type Data Exposed in MongoDB Database<br/>
 <a href="https://mackeepersecurity.com/post/virtual-keyboard-developer-leaked-31-million-of-client-records">https://mackeepersecurity.com/post/virtual-keyboard-developer-leaked-31-million-of-client-records</a><br/>
Mailsploit Makes it Easier to Spoof From Headers in E-Mails<br/>
 <a href="https://www.mailsploit.com">https://www.mailsploit.com</a><br/>
StorageCrypt Ransomware Encrypts NAS Devices<br/>
 <a href="https://www.bleepingcomputer.com/news/security/storagecrypt-ransomware-infecting-nas-devices-using-sambacry/">https://www.bleepingcomputer.com/news/security/storagecrypt-ransomware-infecting-nas-devices-using-sambacry/</a><br/>
Android December Update<br/>
 <a href="https://source.android.com/security/bulletin/2017-12-01">https://source.android.com/security/bulletin/2017-12-01</a><br/>
]]></description>
<itunes:duration>5:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5781" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5779</itunes:episode>
<itunes:subtitle>SOC Automation and TheHive; SSL/TLS for Scapy; TouchID ssh login
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SOC Automation and TheHive; SSL/TLS for Scapy; TouchID ssh login
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5779.mp3" length="5542493" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5779.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5779</link>
<pubDate>Tue, 05 Dec 2017 03:10:02 GMT</pubDate>
<description><![CDATA[Incidence Response Using TheHive<br/>
 <a href="https://isc.sans.edu/forums/diary/IR+using+the+Hive+Project/23099/">https://isc.sans.edu/forums/diary/IR+using+the+Hive+Project/23099/</a><br/>
SSL/TLS For Scapy<br/>
 <a href="https://github.com/tintinweb/scapy-ssl_tls">https://github.com/tintinweb/scapy-ssl_tls</a><br/>
tvOS 11.2 Released (but no details about security content yet)<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
System Vendors Ship Laptops With Intel ME Disabled<br/>
 <a href="https://www.reddit.com/r/linuxhardware/comments/7grglm/how_to_buy_a_dell_laptop_with_the_intel_me/">https://www.reddit.com/r/linuxhardware/comments/7grglm/how_to_buy_a_dell_laptop_with_the_intel_me/</a><br/>
 <a href="http://blog.system76.com/post/168050597573/system76-me-firmware-updates-plan">http://blog.system76.com/post/168050597573/system76-me-firmware-updates-plan</a><br/>
 <br/>
Hacker Falsified Jail Records To Free Friend<br/>
 <a href="https://www.justice.gov/usao-edmi/pr/ann-arbor-man-pleads-guilty-computer-intrusion-case">https://www.justice.gov/usao-edmi/pr/ann-arbor-man-pleads-guilty-computer-intrusion-case</a><br/>
SeKey: Touch ID Control for ssh-agent<br/>
 <a href="https://github.com/ntrippar/sekey">https://github.com/ntrippar/sekey</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5779" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 4th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5777</itunes:episode>
<itunes:subtitle>Banking Malware Uses Old Tricks To Avoid Detection; JotForm Phishing; iOS 11.2
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Banking Malware Uses Old Tricks To Avoid Detection; JotForm Phishing; iOS 11.2
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5777.mp3" length="4772410" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5777.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5777</link>
<pubDate>Mon, 04 Dec 2017 00:55:03 GMT</pubDate>
<description><![CDATA[Brazilian Banking Malware Uses UTF-16 Encoded .BAT File <br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+campaign+uses+old+bat+script+to+spread+banking+malware+and+it+is+flying+under+the+radar/23091/">https://isc.sans.edu/forums/diary/Phishing+campaign+uses+old+bat+script+to+spread+banking+malware+and+it+is+flying+under+the+radar/23091/</a><br/>
Phishing Abuse of JotForm<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+Kit+AbUsing+Cloud+Services/23089/">https://isc.sans.edu/forums/diary/Phishing+Kit+AbUsing+Cloud+Services/23089/</a><br/>
Apple Releases iOS 11.2<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
 (no details live yet)<br/>
Critical Patch For RSA Authentication Agent<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Nov/46">http://seclists.org/fulldisclosure/2017/Nov/46</a><br/>
 <a href="https://community.rsa.com/community/products/securid/authentication-agent-web-apache">https://community.rsa.com/community/products/securid/authentication-agent-web-apache</a><br/>
Slurp S3 Bucket Enumerator<br/>
 <a href="https://github.com/bbb31/slurp.git">https://github.com/bbb31/slurp.git</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5777" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5775</itunes:episode>
<itunes:subtitle>What is Emotet Up To; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
What is Emotet Up To; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5775.mp3" length="12267092" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5775.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5775</link>
<pubDate>Fri, 01 Dec 2017 03:50:03 GMT</pubDate>
<description><![CDATA[More Malspam Pushing Emotet Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/More+Malspam+pushing+Emotet+malware/23083/">https://isc.sans.edu/forums/diary/More+Malspam+pushing+Emotet+malware/23083/</a><br/>
Google Chrome To Block Some Third Party Software Mid-2018<br/>
 <a href="https://blog.chromium.org/2017/11/reducing-chrome-crashes-caused-by-third.html">https://blog.chromium.org/2017/11/reducing-chrome-crashes-caused-by-third.html</a><br/>
European Union Funds VLC Bug Bounty<br/>
 <a href="https://joinup.ec.europa.eu/news/hackerone-vlc">https://joinup.ec.europa.eu/news/hackerone-vlc</a><br/>
STI Student Scott Perry: Virtual System Forensics<br/>
 <a href="http://www.sans.org/reading-room/whitepapers/bestprac/exploring-effectiveness-approaches-discovering-acquiring-virtualized-servers-esxi-38155">http://www.sans.org/reading-room/whitepapers/bestprac/exploring-effectiveness-approaches-discovering-acquiring-virtualized-servers-esxi-38155</a><br/>
]]></description>
<itunes:duration>14:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5775" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 30th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5773</itunes:episode>
<itunes:subtitle>Apple Fixes Root Login Flaw; Insecure Crypto Wallets; Persistent Cryptojacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Apple Fixes Root Login Flaw; Insecure Crypto Wallets; Persistent Cryptojacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5773.mp3" length="4531590" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5773.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5773</link>
<pubDate>Thu, 30 Nov 2017 01:05:02 GMT</pubDate>
<description><![CDATA[Apple Releases Security Update 2017-001 To Fix Passwordless Root Bug<br/>
 <a href="https://support.apple.com/en-us/HT208315">https://support.apple.com/en-us/HT208315</a><br/>
Insecure Android Crypto Currency Wallets<br/>
 <a href="https://www.htbridge.com/news/security-cryptocurrency-mobile-apps.html">https://www.htbridge.com/news/security-cryptocurrency-mobile-apps.html</a><br/>
Coinhive Miner Now As Pop-Under<br/>
 <a href="https://blog.malwarebytes.com/cybercrime/2017/11/persistent-drive-by-cryptomining-coming-to-a-browser-near-you/">https://blog.malwarebytes.com/cybercrime/2017/11/persistent-drive-by-cryptomining-coming-to-a-browser-near-you/</a><br/>
Fileless Malicious PowerShell Sample<br/>
 <a href="https://isc.sans.edu/forums/diary/Fileless+Malicious+PowerShell+Sample/23081/">https://isc.sans.edu/forums/diary/Fileless+Malicious+PowerShell+Sample/23081/</a><br/>
.dev TLD Now Requires HTTPS in Chrome<br/>
 <a href="http://www.theregister.co.uk/2017/11/29/google_dev_network/">http://www.theregister.co.uk/2017/11/29/google_dev_network/</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5773" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 29th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5771</itunes:episode>
<itunes:subtitle>High Sierra Passwordless Root Account; Defeating Facial Recognition
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
High Sierra Passwordless Root Account; Defeating Facial Recognition
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5771.mp3" length="5346503" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5771.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5771</link>
<pubDate>Wed, 29 Nov 2017 01:20:02 GMT</pubDate>
<description><![CDATA[Password Less Root Account Allows for Trivial Privilege Escalation on MacOS High Sierra<br/>
<a href="https://twitter.com/lemiorhan/status/935578694541770752">https://twitter.com/lemiorhan/status/935578694541770752</a><br/>
<a href="https://support.apple.com/en-us/HT204012">https://support.apple.com/en-us/HT204012</a><br/>
Defeating Facial Recognition<br/>
 <a href="https://arxiv.org/abs/1711.09001">https://arxiv.org/abs/1711.09001</a><br/>
Bitcoin Gold Wallet App Compromise<br/>
 <a href="https://bitcoingold.org/critical-warning-nov-26/">https://bitcoingold.org/critical-warning-nov-26/</a><br/>
Project Exodus Identified Trackers in Android Apps<br/>
 <a href="https://reports.exodus-privacy.eu.org/reports/apps/">https://reports.exodus-privacy.eu.org/reports/apps/</a><br/>
]]></description>
<itunes:duration>6:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5771" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5769</itunes:episode>
<itunes:subtitle>Golden SAML Ticket; Facebook Poll Image Leak;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Golden SAML Ticket; Facebook Poll Image Leak;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5769.mp3" length="5526370" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5769.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5769</link>
<pubDate>Tue, 28 Nov 2017 02:10:02 GMT</pubDate>
<description><![CDATA[Golden SAML Ticket Attack<br/>
 <a href="https://www.cyberark.com/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-cloud-apps/">https://www.cyberark.com/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-cloud-apps/</a><br/>
Facebook Poll Image Vulnerability<br/>
 <a href="https://blog.darabi.me/2017/11/image-removal-vulnerability-in-facebook.html">https://blog.darabi.me/2017/11/image-removal-vulnerability-in-facebook.html</a><br/>
]]></description>
<itunes:duration>6:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5769" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5767</itunes:episode>
<itunes:subtitle>Critical #Exim Vuln; CoinPouch Loses Verge Coins; Bitcoin Routing Attacks; #ETH #BTC #CoinPouch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Critical #Exim Vuln; CoinPouch Loses Verge Coins; Bitcoin Routing Attacks; #ETH #BTC #CoinPouch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5767.mp3" length="4939021" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5767.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5767</link>
<pubDate>Mon, 27 Nov 2017 02:30:03 GMT</pubDate>
<description><![CDATA[Critical Exim Mail Server Vulnerability (Exploit released!)<br/>
 <a href="https://bugs.exim.org/show_bug.cgi?id=2199">https://bugs.exim.org/show_bug.cgi?id=2199</a><br/>
CoinPouch "Verge" Token Loss<br/>
 <a href="http://www.documentcloud.org/documents/4309909-StatementonVerge-11-21-17.html">http://www.documentcloud.org/documents/4309909-StatementonVerge-11-21-17.html</a><br/>
Bitcoin Routing Attacks<br/>
 <a href="https://btc-hijack.ethz.ch">https://btc-hijack.ethz.ch</a><br/>
Scanning Ethereum Smart Contracts For Vulnerabilities<br/>
 <a href="https://hackernoon.com/scanning-ethereum-smart-contracts-for-vulnerabilities-b5caefd995df">https://hackernoon.com/scanning-ethereum-smart-contracts-for-vulnerabilities-b5caefd995df</a><br/>
Fortiweb Manager Vulnerability<br/>
 <a href="https://fortiguard.com/psirt/FG-IR-17-248">https://fortiguard.com/psirt/FG-IR-17-248</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5767" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5765</itunes:episode>
<itunes:subtitle>Ethereum JSON-RPC Scans; Updated OWASP Top 10 Released; TPLink Firmware Fail
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Ethereum JSON-RPC Scans; Updated OWASP Top 10 Released; TPLink Firmware Fail
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5765.mp3" length="5741798" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5765.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5765</link>
<pubDate>Wed, 22 Nov 2017 00:50:01 GMT</pubDate>
<description><![CDATA[Ethereum JSON-RPC Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Internet+Wide+Ethereum+JSONRPC+Scans/23061/">https://isc.sans.edu/forums/diary/Internet+Wide+Ethereum+JSONRPC+Scans/23061/</a><br/>
Updated OWASP Top 10 Released<br/>
 <a href="https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf">https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf</a><br/>
TPLink Often Provides Outdated Firmware Version For Download<br/>
 <a href="https://www.ctrl.blog/entry/tplink-firmware-outdated-downloads">https://www.ctrl.blog/entry/tplink-firmware-outdated-downloads</a><br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5765" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5763</itunes:episode>
<itunes:subtitle>Intel ME Update; Fuzzing x86 CPUs; Android MediaProjection API Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Intel ME Update; Fuzzing x86 CPUs; Android MediaProjection API Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5763.mp3" length="4802454" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5763.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5763</link>
<pubDate>Tue, 21 Nov 2017 03:37:03 GMT</pubDate>
<description><![CDATA[Intel Patches Several Vulnerabilities in its Management Engine<br/>
 <a href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr">https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-fr</a><br/>
Sandsifter CPU Fuzzer<br/>
 <a href="https://github.com/xoreaxeaxeax/sandsifter/">https://github.com/xoreaxeaxeax/sandsifter/</a><br/>
Android MediaProjection API Allows For Screen Capture / Audio Recording Without User Consent<br/>
 <a href="https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-android-MediaProjection-tapjacking-advisory-2017-11-13.pdf">https://labs.mwrinfosecurity.com/assets/BlogFiles/mwri-android-MediaProjection-tapjacking-advisory-2017-11-13.pdf</a><br/>
BusyBox Autocompletion Vulnerability<br/>
 <a href="https://www.twistlock.com/2017/11/20/cve-2017-16544-busybox-autocompletion-vulnerability/">https://www.twistlock.com/2017/11/20/cve-2017-16544-busybox-autocompletion-vulnerability/</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5763" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5762</itunes:episode>
<itunes:subtitle>Scanning For BTC Wallets; Fake Resume Banking Malware; BigIp TLS Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Scanning For BTC Wallets; Fake Resume Banking Malware; BigIp TLS Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5762.mp3" length="6011363" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5762.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5762</link>
<pubDate>Mon, 20 Nov 2017 03:00:06 GMT</pubDate>
<description><![CDATA[Bitcoin Pickpockets Scanning For Wallets<br/>
 <a href="https://isc.sans.edu/forums/diary/BTC+Pickpockets/23052/">https://isc.sans.edu/forums/diary/BTC+Pickpockets/23052/</a><br/>
Resume-themed Malspam Pushing Smoker Loader<br/>
 <a href="https://isc.sans.edu/forums/diary/Resumethemed+malspam+pushing+Smoke+Loader/23054/">https://isc.sans.edu/forums/diary/Resumethemed+malspam+pushing+Smoke+Loader/23054/</a><br/>
F5-BigIP TLS Vulnerability<br/>
 <a href="https://support.f5.com/csp/article/K21905460">https://support.f5.com/csp/article/K21905460</a><br/>
Microsoft Updates Patches / May Have Lost Sourcecode<br/>
 <a href="https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html">https://0patch.blogspot.com/2017/11/did-microsoft-just-manually-patch-their.html</a><br/>
 <a href="http://borncity.com/win/2017/11/17/microsoft-confirms-epson-dot-matrix-printer-issue-after-november-2017-patchday-here-are-fixes/">http://borncity.com/win/2017/11/17/microsoft-confirms-epson-dot-matrix-printer-issue-after-november-2017-patchday-here-are-fixes/</a><br/>
Windows 8 And Later Fail To Apply ASLR Correctly<br/>
 <a href="https://www.kb.cert.org/vuls/id/817544">https://www.kb.cert.org/vuls/id/817544</a><br/>
StartCom TLS Certificate Authority Shutting Down<br/>
 <a href="http://www.zdnet.com/article/startcom-to-shut-down-all-certificates-revoked-in-2020/">http://www.zdnet.com/article/startcom-to-shut-down-all-certificates-revoked-in-2020/</a><br/>
]]></description>
<itunes:duration>7:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5762" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5760</itunes:episode>
<itunes:subtitle>Oracle Critical PeopleSoft Patch; Exposing IPs for Hidden Services
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oracle Critical PeopleSoft Patch; Exposing IPs for Hidden Services
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5760.mp3" length="5055099" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5760.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5760</link>
<pubDate>Fri, 17 Nov 2017 02:15:05 GMT</pubDate>
<description><![CDATA[A Domain Dashboard For Splunk<br/>
 <a href="https://isc.sans.edu/forums/diary/Suspicious+Domains+Tracking+Dashboard/23046/">https://isc.sans.edu/forums/diary/Suspicious+Domains+Tracking+Dashboard/23046/</a><br/>
Oracle Critical PeopleSoft Patch<br/>
 <a href="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html#AppendixFMW">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html#AppendixFMW</a><br/>
GitHub Introducing Security Alerts for Dependencies<br/>
 <a href="https://github.com/blog/2470-introducing-security-alerts-on-github">https://github.com/blog/2470-introducing-security-alerts-on-github</a><br/>
Exposing IP Addresses For Hidden Services<br/>
 <a href="http://sh1ttykids.hateblo.jp/entry/2017/11/16/182001">http://sh1ttykids.hateblo.jp/entry/2017/11/16/182001</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5760" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5758</itunes:episode>
<itunes:subtitle>Malicious Document Turns Off Word Protections; Google Play Store "flooded" with Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Document Turns Off Word Protections; Google Play Store "flooded" with Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5758.mp3" length="5238444" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5758.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5758</link>
<pubDate>Thu, 16 Nov 2017 02:00:13 GMT</pubDate>
<description><![CDATA[Malicious Document Turns Off Word Macro Protections<br/>
 <a href="https://isc.sans.edu/forums/diary/If+you+want+something+done+right+do+it+yourself/23042/">https://isc.sans.edu/forums/diary/If+you+want+something+done+right+do+it+yourself/23042/</a><br/>
Blueborne Affects Amazon Echo and Google Home Devices (now patched)<br/>
 <a href="http://go.armis.com/hubfs/BlueBorne%20Technical%20White%20Paper.pdf">http://go.armis.com/hubfs/BlueBorne%20Technical%20White%20Paper.pdf</a><br/>
More Malicious Apps In Google's Play Store<br/>
 <a href="https://www.bleepingcomputer.com/news/security/google-play-store-sees-sudden-surge-of-malicious-apps/">https://www.bleepingcomputer.com/news/security/google-play-store-sees-sudden-surge-of-malicious-apps/</a><br/>
OnePlus Phones Found With Preinstalled Debug App <br/>
 <a href="https://twitter.com/fs0c131y">https://twitter.com/fs0c131y</a><br/>
 <a href="https://twitter.com/__Tux/status/754085708843786240">https://twitter.com/__Tux/status/754085708843786240</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5758" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5756</itunes:episode>
<itunes:subtitle>MSFT and Adobe Updates; AV Quarantine Priv. Escalation; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT and Adobe Updates; AV Quarantine Priv. Escalation; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5756.mp3" length="4846973" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5756.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5756</link>
<pubDate>Wed, 15 Nov 2017 03:35:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Adobe Patches<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Abusing Anti-Virus Quarantine Folders for Priv. Escalation<br/>
 <a href="https://bogner.sh/2017/11/avgater-getting-local-admin-by-abusing-the-anti-virus-quarantine/">https://bogner.sh/2017/11/avgater-getting-local-admin-by-abusing-the-anti-virus-quarantine/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5756" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5754</itunes:episode>
<itunes:subtitle>FaceID Beaten By Mask; Using Heart Movement as Biometric ID; URL Validation Libraries allow SSRF
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
FaceID Beaten By Mask; Using Heart Movement as Biometric ID; URL Validation Libraries allow SSRF
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5754.mp3" length="6672265" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5754.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5754</link>
<pubDate>Tue, 14 Nov 2017 04:00:15 GMT</pubDate>
<description><![CDATA[FaceID Beaten By Mask<br/>
<a href="http://www.bkav.com/d/top-news/-/view_content/content/103968/face-id-beaten-by-mask-not-an-effective-security-measure">http://www.bkav.com/d/top-news/-/view_content/content/103968/face-id-beaten-by-mask-not-an-effective-security-measure</a><br/>
Various URL Validation and HTTP Request Libraries Allow SSRF<br/>
<a href="https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf">https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf</a><br/>
Using Heart Rythm As Biometric ID<br/>
<a href="http://www.buffalo.edu/news/releases/2017/09/034.html">http://www.buffalo.edu/news/releases/2017/09/034.html</a><br/>
]]></description>
<itunes:duration>7:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5754" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5752</itunes:episode>
<itunes:subtitle>Auditing TLS Root Certs; How Google Accounts Are Hijacked; Battling E-Mail Phishing; Hacking Airplan</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Auditing TLS Root Certs; How Google Accounts Are Hijacked; Battling E-Mail Phishing; Hacking Airplan</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5752.mp3" length="5625371" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5752.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5752</link>
<pubDate>Mon, 13 Nov 2017 01:20:02 GMT</pubDate>
<description><![CDATA[Auditing TLS Root Certificates on Windows<br/>
 <a href="https://isc.sans.edu/forums/diary/Keep+An+Eye+on+your+Root+Certificates/23030/">https://isc.sans.edu/forums/diary/Keep+An+Eye+on+your+Root+Certificates/23030/</a><br/>
How Google Accounts Are Hijacked<br/>
 <a href="https://security.googleblog.com/2017/11/new-research-understanding-root-cause.html">https://security.googleblog.com/2017/11/new-research-understanding-root-cause.html</a><br/>
Battling E-Mail Phishing<br/>
 <a href="https://isc.sans.edu/forums/diary/Battling+email+phishing/23028/">https://isc.sans.edu/forums/diary/Battling+email+phishing/23028/</a><br/>
Hacking Airplanes<br/>
 <a href="http://www.aviationtoday.com/2017/11/08/boeing-757-testing-shows-airplanes-vulnerable-hacking-dhs-says/">http://www.aviationtoday.com/2017/11/08/boeing-757-testing-shows-airplanes-vulnerable-hacking-dhs-says/</a><br/>
]]></description>
<itunes:duration>6:41</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5752" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5750</itunes:episode>
<itunes:subtitle>Twilio Credentials Found in Mobile Apps; Drive By Crypto Currency; Intel ME Decode via USB
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Twilio Credentials Found in Mobile Apps; Drive By Crypto Currency; Intel ME Decode via USB
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5750.mp3" length="6018668" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5750.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5750</link>
<pubDate>Fri, 10 Nov 2017 02:10:02 GMT</pubDate>
<description><![CDATA[Twilio Credentials Found in Mobile Apps (requires registration)<br/>
 <a href="http://info.appthority.com/-q4-2017-mtr-download-eavesdropper">http://info.appthority.com/-q4-2017-mtr-download-eavesdropper</a><br/>
Drive By Cryto Currency Mining Keeps Increasing<br/>
 <a href="https://go.malwarebytes.com/rs/805-USG-300/images/Drive-by_Mining_FINAL.pdf">https://go.malwarebytes.com/rs/805-USG-300/images/Drive-by_Mining_FINAL.pdf</a><br/>
 <br/>
Intel's Management Engine Firmware Decoded<br/>
 <a href="https://twitter.com/h0t_max">https://twitter.com/h0t_max</a><br/>
 <a href="https://www.theregister.co.uk/2017/11/09/chipzilla_come_closer_closer_listen_dump_ime/">https://www.theregister.co.uk/2017/11/09/chipzilla_come_closer_closer_listen_dump_ime/</a><br/>
]]></description>
<itunes:duration>7:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5750" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 9th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5748</itunes:episode>
<itunes:subtitle>Gaming Keyboard Exfiltrates Data; Logitech Will Brick Harmony Link; Amazon Introduces Addtl Security</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Gaming Keyboard Exfiltrates Data; Logitech Will Brick Harmony Link; Amazon Introduces Addtl Security</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5748.mp3" length="5423963" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5748.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5748</link>
<pubDate>Thu, 09 Nov 2017 00:50:03 GMT</pubDate>
<description><![CDATA[Mantistek Gaming Keyboard Cloud Driver Exfiltrates Keystroke Data<br/>
<a href="https://thehackernews.com/2017/11/mantistek-keyboard-keylogger.html">https://thehackernews.com/2017/11/mantistek-keyboard-keylogger.html</a><br/>
Logitech Will Discontinue Harmony Link Device and Brick it via Firmware Update in March 2018<br/>
<a href="https://www.theverge.com/circuitbreaker/2017/11/8/16623076/logitech-harmony-link-discontinued-bricked">https://www.theverge.com/circuitbreaker/2017/11/8/16623076/logitech-harmony-link-discontinued-bricked</a><br/>
Amazon Is Introducing Additional Security Features for S3<br/>
<a href="https://aws.amazon.com/blogs/aws/new-amazon-s3-encryption-security-features/">https://aws.amazon.com/blogs/aws/new-amazon-s3-encryption-security-features/</a><br/>
]]></description>
<itunes:duration>6:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5748" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5746</itunes:episode>
<itunes:subtitle>Interesting RTF Maldoc; Multiple Linux USB Flaws; Android Updates; Ethereum Bug Locks $280 Million
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Interesting RTF Maldoc; Multiple Linux USB Flaws; Android Updates; Ethereum Bug Locks $280 Million
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5746.mp3" length="5495930" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5746.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5746</link>
<pubDate>Wed, 08 Nov 2017 01:21:55 GMT</pubDate>
<description><![CDATA[Interesting RTF Maldoc VBA Dropper<br/>
 <a href="https://isc.sans.edu/forums/diary/Interesting+VBA+Dropper/23016/">https://isc.sans.edu/forums/diary/Interesting+VBA+Dropper/23016/</a><br/>
Multiple Linux USB Flaws Made Public<br/>
 <a href="http://www.openwall.com/lists/oss-security/2017/11/06/8">http://www.openwall.com/lists/oss-security/2017/11/06/8</a><br/>
Google Android November Patches<br/>
 <a href="https://source.android.com/security/bulletin/2017-11-01#media-framework">https://source.android.com/security/bulletin/2017-11-01#media-framework</a><br/>
Ethereum Multi Signature Wallet Bug Cause Loss of $280 Million<br/>
 <a href="https://paritytech.io/blog/security-alert.html">https://paritytech.io/blog/security-alert.html</a><br/>
 <a href="https://github.com/paritytech/parity/issues/6995">https://github.com/paritytech/parity/issues/6995</a><br/>
]]></description>
<itunes:duration>6:31</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5746" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5744</itunes:episode>
<itunes:subtitle>Fake WhatsApp App in Google Play Store; Crunchyroll redirect; Recovering iOS Backups
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fake WhatsApp App in Google Play Store; Crunchyroll redirect; Recovering iOS Backups
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5744.mp3" length="5298425" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5744.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5744</link>
<pubDate>Tue, 07 Nov 2017 02:10:02 GMT</pubDate>
<description><![CDATA[Fake WhatsApp App in Google Play Store<br/>
 <a href="https://www.reddit.com/r/Android/comments/7ahujw/psa_two_different_developers_under_the_same_name/">https://www.reddit.com/r/Android/comments/7ahujw/psa_two_different_developers_under_the_same_name/</a><br/>
Crunchyroll.com Redirect Leads to Malware<br/>
 <a href="https://blog.ellation.com/crunchyroll-com-update-a2a593cf9155">https://blog.ellation.com/crunchyroll-com-update-a2a593cf9155</a><br/>
 <a href="https://bartblaze.blogspot.com.au/2017/11/crunchyroll-hack-delivers-malware.html">https://bartblaze.blogspot.com.au/2017/11/crunchyroll-hack-delivers-malware.html</a><br/>
Recovering Previously Encrypted iOS Backups<br/>
 <a href="https://www.gillware.com/forensics/blog/digital-forensics-case-study/new-solution-encrypted-backups/">https://www.gillware.com/forensics/blog/digital-forensics-case-study/new-solution-encrypted-backups/</a><br/>
]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5744" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5742</itunes:episode>
<itunes:subtitle>PDF Parser; Pwn20wn; OpenSSL Patch; IEEE P1735 Encryption Standard Broken
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PDF Parser; Pwn20wn; OpenSSL Patch; IEEE P1735 Encryption Standard Broken
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5742.mp3" length="4420007" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5742.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5742</link>
<pubDate>Mon, 06 Nov 2017 01:35:02 GMT</pubDate>
<description><![CDATA[PDF Parser for URLs and Text Content of PDFs<br/>
 <a href="https://isc.sans.edu/forums/diary/Extracting+the+text+from+PDF+documents/23008/">https://isc.sans.edu/forums/diary/Extracting+the+text+from+PDF+documents/23008/</a> <a href="https://isc.sans.edu/forums/diary/PDF+documents+URLs/23006/">https://isc.sans.edu/forums/diary/PDF+documents+URLs/23006/</a><br/>
 <br/>
Mobile Pwn2Own Contest 2017<br/>
 <a href="https://www.zerodayinitiative.com/blog">https://www.zerodayinitiative.com/blog</a><br/>
OpenSSL Patch<br/>
 <a href="https://www.openssl.org/news/secadv/20171102.txt">https://www.openssl.org/news/secadv/20171102.txt</a><br/>
IEEE P1735 Standard Leads to Weak Crypto<br/>
 <a href="https://eprint.iacr.org/2017/828.pdf">https://eprint.iacr.org/2017/828.pdf</a><br/>
]]></description>
<itunes:duration>5:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5742" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5740</itunes:episode>
<itunes:subtitle>Leaked Code-Signing Keys; Popular iOS Apps Do Not Use TLS Correctly; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Leaked Code-Signing Keys; Popular iOS Apps Do Not Use TLS Correctly; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5740.mp3" length="6073573" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5740.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5740</link>
<pubDate>Thu, 02 Nov 2017 21:15:04 GMT</pubDate>
<description><![CDATA[Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKI<br/>
 <a href="http://www.umiacs.umd.edu/~tdumitra/papers/CCS-2017.pdf">http://www.umiacs.umd.edu/~tdumitra/papers/CCS-2017.pdf</a><br/>
Half of Most Popular Free iOS Apps do not use TLS correctly<br/>
 <a href="http://www.zeit.de/digital/datenschutz/2017-10/iphone-ios-apps-hacker-verschluesselung/komplettansicht#comments">http://www.zeit.de/digital/datenschutz/2017-10/iphone-ios-apps-hacker-verschluesselung/komplettansicht#comments</a><br/>
Image Downloader Chrome Extension Includes Adware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/psa-beware-the-image-downloader-chrome-adware-extension/">https://www.bleepingcomputer.com/news/security/psa-beware-the-image-downloader-chrome-adware-extension/</a><br/>
Employees Pay Up Ransomware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/59-percent-of-employees-hit-by-ransomware-at-work-paid-ransom-out-of-their-own-pockets/">https://www.bleepingcomputer.com/news/security/59-percent-of-employees-hit-by-ransomware-at-work-paid-ransom-out-of-their-own-pockets/</a><br/>
]]></description>
<itunes:duration>7:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5740" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 2nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5738</itunes:episode>
<itunes:subtitle>Proper SSH Configuration on Cisco IOS; Ethereum Miner Hijacks; Copy/Past Bitcoin Wallet Theft;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Proper SSH Configuration on Cisco IOS; Ethereum Miner Hijacks; Copy/Past Bitcoin Wallet Theft;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5738.mp3" length="4729796" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5738.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5738</link>
<pubDate>Wed, 01 Nov 2017 22:10:03 GMT</pubDate>
<description><![CDATA[Configuring SSH Properly on Cisco IOS<br/>
 <a href="https://isc.sans.edu/forums/diary/Securing+SSH+Services+Go+Blue+Team/22992/">https://isc.sans.edu/forums/diary/Securing+SSH+Services+Go+Blue+Team/22992/</a><br/>
Ethereum Miners Hijacked via Default SSH Credentials<br/>
 <a href="https://labs.bitdefender.com/2017/11/ethereum-os-miners-targeted-by-ssh-based-hijacker/">https://labs.bitdefender.com/2017/11/ethereum-os-miners-targeted-by-ssh-based-hijacker/</a><br/>
Crypto Shuffler Steals Bitcoin From Clipboard<br/>
 <a href="https://www.kaspersky.com/blog/cryptoshuffler-bitcoin-stealer/19976/">https://www.kaspersky.com/blog/cryptoshuffler-bitcoin-stealer/19976/</a><br/>
Google Calender Event Injection Added To Mail Snipper<br/>
 <a href="https://www.blackhillsinfosec.com/google-calendar-event-injection-mailsniper/">https://www.blackhillsinfosec.com/google-calendar-event-injection-mailsniper/</a><br/>
November Ouch! Newsletter released: Shopping Security Online<br/>
 <a href="https://securingthehuman.sans.org/resources/newsletters/ouch/2017?utm_medium=Social&utm_source=Twitter&utm_content=OUCH+Nov+2017+all+languages+&utm_campaign=STH+Ouch+#november2017">https://securingthehuman.sans.org/resources/newsletters/ouch/2017?utm_medium=Social&utm_source=Twitter&utm_content=OUCH+Nov+2017+all+languages+&utm_campaign=STH+Ouch+#november2017</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5738" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5736</itunes:episode>
<itunes:subtitle>Malicious Powershell Code; Apple Updates Everything
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious Powershell Code; Apple Updates Everything
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5736.mp3" length="4503503" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5736.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5736</link>
<pubDate>Tue, 31 Oct 2017 21:15:04 GMT</pubDate>
<description><![CDATA[Malicious Powershell Code<br/>
 <a href="https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/">https://isc.sans.edu/forums/diary/Some+Powershell+Malicious+Code/22988/</a><br/>
Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-gb/HT201222">https://support.apple.com/en-gb/HT201222</a><br/>
Internet Draft To Update IoT Devices<br/>
 <a href="https://tools.ietf.org/html/draft-moran-suit-architecture-00">https://tools.ietf.org/html/draft-moran-suit-architecture-00</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5736" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 31st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5734</itunes:episode>
<itunes:subtitle>Google Moving Away From Key Pinning; New Dutch Law May Affect CAs;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Google Moving Away From Key Pinning; New Dutch Law May Affect CAs;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5734.mp3" length="5167305" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5734.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5734</link>
<pubDate>Mon, 30 Oct 2017 22:40:03 GMT</pubDate>
<description><![CDATA[Google Chrome Moving Away from HTTPS Public Key Pinning (HPKP)<br/>
 <a href="https://groups.google.com/a/chromium.org/forum/#!msg/blink-dev/he9tr7p3rZ8/eNMwKPmUBAAJ">https://groups.google.com/a/chromium.org/forum/#!msg/blink-dev/he9tr7p3rZ8/eNMwKPmUBAAJ</a><br/>
Effort To Remove Trust From Dutch CA Over New Intercept Law<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1408647">https://bugzilla.mozilla.org/show_bug.cgi?id=1408647</a> <br/>
Crypto Coin Mining Feature Found in Google App Store Downloads<br/>
 <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/coin-miner-mobile-malware-returns-hits-google-play/">http://blog.trendmicro.com/trendlabs-security-intelligence/coin-miner-mobile-malware-returns-hits-google-play/</a><br/>
]]></description>
<itunes:duration>6:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5734" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 30th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5732</itunes:episode>
<itunes:subtitle>Critical New #Oracle IM Patch; "CatchAll" Chrome Plugin; ACE Malware; FEMA Fraud
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Critical New #Oracle IM Patch; "CatchAll" Chrome Plugin; ACE Malware; FEMA Fraud
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5732.mp3" length="4297105" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5732.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5732</link>
<pubDate>Sun, 29 Oct 2017 19:06:05 GMT</pubDate>
<description><![CDATA[Critical New Oracle Patch<br/>
 <a href="http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html">http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html</a><br/>
CatchAll Google Chrome Plugins<br/>
 <a href="https://isc.sans.edu/forums/diary/CatchAll+Google+Chrome+Malicious+Extension+Steals+All+Posted+Data/22976/">https://isc.sans.edu/forums/diary/CatchAll+Google+Chrome+Malicious+Extension+Steals+All+Posted+Data/22976/</a><br/>
ACE Files Used For Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Remember+ACE+files/22978/">https://isc.sans.edu/forums/diary/Remember+ACE+files/22978/</a><br/>
 <br/>
]]></description>
<itunes:duration>5:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5732" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5730</itunes:episode>
<itunes:subtitle>Kaspersky Publishes Investigation Results; Inineon Bug Test; Micropath DDE; Finding Miners
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Kaspersky Publishes Investigation Results; Inineon Bug Test; Micropath DDE; Finding Miners
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5730.mp3" length="5028022" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5730.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5730</link>
<pubDate>Thu, 26 Oct 2017 20:10:02 GMT</pubDate>
<description><![CDATA[Results of Kaspersky's Internal Investigation<br/>
<a href="https://www.kaspersky.com/blog/internal-investigation-preliminary-results/19894/">https://www.kaspersky.com/blog/internal-investigation-preliminary-results/19894/</a><br/>
Infineon Bug Testing Tool<br/>
 <a href="https://gist.githubusercontent.com/marcan/fc87aa78085c2b6f979aefc73fdc381f/raw/526bc2f2249a2e3f5d4450c7c412e0dbf57b2288/roca_test.py">https://gist.githubusercontent.com/marcan/fc87aa78085c2b6f979aefc73fdc381f/raw/526bc2f2249a2e3f5d4450c7c412e0dbf57b2288/roca_test.py</a><br/>
 <a href="https://github.com/ThomasHabets/simple-tpm-pk11/blob/master/check-srk/check-srk.cc">https://github.com/ThomasHabets/simple-tpm-pk11/blob/master/check-srk/check-srk.cc</a><br/>
Micropatch Available for "DDE Vulnerability" <br/>
 <a href="https://0patch.blogspot.com/2017/10/0patching-office-dde-ddeauto.html">https://0patch.blogspot.com/2017/10/0patching-office-dde-ddeauto.html</a><br/>
Finding Cryptocurrency Miners<br/>
 <a href="https://medium.com/@s3yfullah/hacking-cryptocurrency-miners-with-osint-techniques-677bbb3e0157">https://medium.com/@s3yfullah/hacking-cryptocurrency-miners-with-osint-techniques-677bbb3e0157</a><br/>
]]></description>
<itunes:duration>5:58</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5730" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 26th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5728</itunes:episode>
<itunes:subtitle>Coinhive Domain Compromise; Dell Loses Control of Domain; "Uncaptcha" breaks Recaptcha
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Coinhive Domain Compromise; Dell Loses Control of Domain; "Uncaptcha" breaks Recaptcha
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5728.mp3" length="5404138" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5728.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5728</link>
<pubDate>Wed, 25 Oct 2017 21:00:24 GMT</pubDate>
<description><![CDATA[Coinhive Domain Compromise<br/>
 <a href="https://coinhive.com/blog/dns-breach">https://coinhive.com/blog/dns-breach</a><br/>
Dell Loses Control of Backup and Recovery Cloud Storage Domain<br/>
 <a href="https://krebsonsecurity.com/2017/10/dell-lost-control-of-key-customer-support-domain-for-a-month-in-2017/#more-41267">https://krebsonsecurity.com/2017/10/dell-lost-control-of-key-customer-support-domain-for-a-month-in-2017/#more-41267</a><br/>
Google ReCaptcha Broken<br/>
 <a href="https://github.com/ecthros/uncaptcha">https://github.com/ecthros/uncaptcha</a><br/>
Users in Iran Targeted by Cryptoransomware Masquerading as VPN<br/>
 <a href="https://www.bleepingcomputer.com/news/security/tyrant-ransomware-spreads-in-iran-disguised-as-popular-vpn-app/">https://www.bleepingcomputer.com/news/security/tyrant-ransomware-spreads-in-iran-disguised-as-popular-vpn-app/</a><br/>
Crypto Currency Phishing<br/>
 <a href="https://www.dearbytes.com/blog/cryptocurrency-phishing/">https://www.dearbytes.com/blog/cryptocurrency-phishing/</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5728" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 25th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5726</itunes:episode>
<itunes:subtitle>Don't trust Extensions; Petya Variant #BadRabbit; More TLS Traffic; Static PRNG Seeds
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Don't trust Extensions; Petya Variant #BadRabbit; More TLS Traffic; Static PRNG Seeds
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5726.mp3" length="4278959" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5726.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5726</link>
<pubDate>Tue, 24 Oct 2017 19:40:02 GMT</pubDate>
<description><![CDATA[Stop Relying on File Extensions<br/>
 <a href="https://isc.sans.edu/forums/diary/Stop+relying+on+file+extensions/22962/">https://isc.sans.edu/forums/diary/Stop+relying+on+file+extensions/22962/</a><br/>
BadRabbit New Ransomware Wave Hitting Russia and Ukraine<br/>
 <a href="https://isc.sans.edu/forums/diary/BadRabbit+New+ransomware+wave+hitting+RU+UA/22964/">https://isc.sans.edu/forums/diary/BadRabbit+New+ransomware+wave+hitting+RU+UA/22964/</a><br/>
<a href="https://www.welivesecurity.com/2017/10/24/kiev-metro-hit-new-variant-infamous-diskcoder-ransomware/">https://www.welivesecurity.com/2017/10/24/kiev-metro-hit-new-variant-infamous-diskcoder-ransomware/</a><br/>
Over 70% Of Web Traffic Now via TLS<br/>
 <a href="https://transparencyreport.google.com/https/overview?hl=en">https://transparencyreport.google.com/https/overview?hl=en</a><br/>
Static RNG Seeds in Fortinet Devices<br/>
 <a href="https://duhkattack.com">https://duhkattack.com</a><br/>
]]></description>
<itunes:duration>5:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5726" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5724</itunes:episode>
<itunes:subtitle>SOCKS Proxies; DNS over TLS Coming to Android; Fake Crypt Currency Trading App
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SOCKS Proxies; DNS over TLS Coming to Android; Fake Crypt Currency Trading App
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5724.mp3" length="5098117" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5724.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5724</link>
<pubDate>Mon, 23 Oct 2017 21:27:11 GMT</pubDate>
<description><![CDATA[Is a Telco in Brazil Hosing An Epidemic of Open SOCKS Proxies?<br/>
 <a href="https://isc.sans.edu/forums/diary/Is+a+telco+in+Brazil+hosting+an+epidemic+of+open+SOCKS+proxies/22956/">https://isc.sans.edu/forums/diary/Is+a+telco+in+Brazil+hosting+an+epidemic+of+open+SOCKS+proxies/22956/</a><br/>
Android May Be Adding DNS Over TLS<br/>
 <a href="https://www.xda-developers.com">https://www.xda-developers.com</a><br/>
 <a href="https://tools.ietf.org/html/rfc7858">https://tools.ietf.org/html/rfc7858</a><br/>
Fake Crypto Currency Trading Applications<br/>
 <a href="https://www.welivesecurity.com/2017/10/23/fake-cryptocurrency-apps-google-harvesting-credentials/">https://www.welivesecurity.com/2017/10/23/fake-cryptocurrency-apps-google-harvesting-credentials/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5724" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, October 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5722</itunes:episode>
<itunes:subtitle>IoT "Reaper" Botnet; Mac Malware in Media Player; Expanded Google App Bug Bounty
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
IoT "Reaper" Botnet; Mac Malware in Media Player; Expanded Google App Bug Bounty
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5722.mp3" length="4747781" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5722.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5722</link>
<pubDate>Sun, 22 Oct 2017 16:15:04 GMT</pubDate>
<description><![CDATA[IoT "Reaper" Botnet<br/>
 <a href="http://blog.netlab.360.com/iot_reaper-a-rappid-spreading-new-iot-botnet-en/">http://blog.netlab.360.com/iot_reaper-a-rappid-spreading-new-iot-botnet-en/</a><br/>
 <a href="https://research.checkpoint.com/new-iot-botnet-storm-coming/">https://research.checkpoint.com/new-iot-botnet-storm-coming/</a><br/>
Elmedia Player and Folx Infected with Proton Malware<br/>
 <a href="https://www.eltima.com/blog/2017/10/elmedia-player-and-folx-malware-threat-neutralized.html">https://www.eltima.com/blog/2017/10/elmedia-player-and-folx-malware-threat-neutralized.html</a><br/>
Google Expands Bug Bounty To Popular Android Apps<br/>
 <a href="https://www.google.com/about/appsecurity/play-rewards/index.html">https://www.google.com/about/appsecurity/play-rewards/index.html</a><br/>
Increased Use of Last Week's Flash Vulnerability<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/apt28-racing-exploit-cve-2017-11292-flash-vulnerability-patches-are-deployed">https://www.proofpoint.com/us/threat-insight/post/apt28-racing-exploit-cve-2017-11292-flash-vulnerability-patches-are-deployed</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5722" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5720</itunes:episode>
<itunes:subtitle>Loky Ransomware Updates; Authedmine vs. Coinhive; SSH Key Scans;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Loky Ransomware Updates; Authedmine vs. Coinhive; SSH Key Scans;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5720.mp3" length="4947257" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5720.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5720</link>
<pubDate>Fri, 20 Oct 2017 00:40:03 GMT</pubDate>
<description><![CDATA[Locky Ransomware Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Necurs+Botnet+malspam+pushes+Locky+using+DDE+attack/22946/">https://isc.sans.edu/forums/diary/Necurs+Botnet+malspam+pushes+Locky+using+DDE+attack/22946/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/HSBCthemed+malspam+uses+ISO+attachments+to+push+Loki+Bot+malware/22942/">https://isc.sans.edu/forums/diary/HSBCthemed+malspam+uses+ISO+attachments+to+push+Loki+Bot+malware/22942/</a><br/>
Authedmine To Replace Coinhive<br/>
 <a href="https://coinhive.com/blog/authedmine">https://coinhive.com/blog/authedmine</a><br/>
Attackers Scan for SSH Keys via Webexploits<br/>
 <a href="https://www.wordfence.com/blog/2017/10/ssh-key-website-scans/">https://www.wordfence.com/blog/2017/10/ssh-key-website-scans/</a><br/>
Attacking Colocated Virtual Machines with Rowhammer<br/>
 <a href="https://thisissecurity.stormshield.com/2017/10/19/attacking-co-hosted-vm-hacker-hammer-two-memory-modules/">https://thisissecurity.stormshield.com/2017/10/19/attacking-co-hosted-vm-hacker-hammer-two-memory-modules/</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5720" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5718</itunes:episode>
<itunes:subtitle>Baselining Servers;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Baselining Servers;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5718.mp3" length="4404777" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5718.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5718</link>
<pubDate>Thu, 19 Oct 2017 07:20:03 GMT</pubDate>
<description><![CDATA[Baselining Servers to Detect Outliers<br/>
 <a href="https://isc.sans.edu/forums/diary/Baselining+Servers+to+Detect+Outliers/22940/">https://isc.sans.edu/forums/diary/Baselining+Servers+to+Detect+Outliers/22940/</a><br/>
Test Script Available for KRACK Vulnerability<br/>
 <a href="https://github.com/vanhoefm/krackattacks-test-ap-ft">https://github.com/vanhoefm/krackattacks-test-ap-ft</a><br/>
WaterMiner Distributed With Gaming Mods<br/>
 <a href="https://minerva-labs.com/post/waterminer-a-new-evasive-crypto-miner">https://minerva-labs.com/post/waterminer-a-new-evasive-crypto-miner</a><br/>
Microsoft Releases Fall Creators Update<br/>
 <a href="https://blogs.windows.com/windowsexperience/2017/10/17/whats-new-windows-10-fall-creators-update/#76CQXoUYxT81RLJi.97">https://blogs.windows.com/windowsexperience/2017/10/17/whats-new-windows-10-fall-creators-update/#76CQXoUYxT81RLJi.97</a><br/>
]]></description>
<itunes:duration>5:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5718" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5716</itunes:episode>
<itunes:subtitle>Hancitor Uses DDE Attack; Ifinieon RSA Weakness; Chrome Improvements 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Hancitor Uses DDE Attack; Ifinieon RSA Weakness; Chrome Improvements 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5716.mp3" length="4500142" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5716.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5716</link>
<pubDate>Wed, 18 Oct 2017 04:05:02 GMT</pubDate>
<description><![CDATA[Hancitor Malspam Uses DDE Attack To Spread Banking Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+malspam+uses+DDE+attack/22936/">https://isc.sans.edu/forums/diary/Hancitor+malspam+uses+DDE+attack/22936/</a><br/>
Infineon RSA Key Generation Weakness<br/>
 <a href="https://crocs.fi.muni.cz/public/papers/rsa_ccs17">https://crocs.fi.muni.cz/public/papers/rsa_ccs17</a><br/>
Chrome Improving Security<br/>
 <a href="https://www.blog.google/products/chrome/cleaner-safer-web-chrome-cleanup/">https://www.blog.google/products/chrome/cleaner-safer-web-chrome-cleanup/</a><br/>
]]></description>
<itunes:duration>5:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5716" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5714</itunes:episode>
<itunes:subtitle>WPA2 "Krack" Attack; Adobe Flash Update; Identical Binaries but Different Hash 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WPA2 "Krack" Attack; Adobe Flash Update; Identical Binaries but Different Hash 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5714.mp3" length="7298252" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5714.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5714</link>
<pubDate>Mon, 16 Oct 2017 22:40:03 GMT</pubDate>
<description><![CDATA[WPA2 "Krack" Attack<br/>
 <a href="https://www.krackattacks.com/">https://www.krackattacks.com/</a><br/>
 <a href="https://securingthehuman.sans.org/blog/2017/10/16/28748/">https://securingthehuman.sans.org/blog/2017/10/16/28748/</a><br/>
Adobe Flash Player Update<br/>
 <a href="https://helpx.adobe.com/security/products/flash-player/apsb17-32.html">https://helpx.adobe.com/security/products/flash-player/apsb17-32.html</a><br/>
Two (identical) uTorrent Binaries With Different Hashes<br/>
 <a href="https://isc.sans.edu/forums/diary/Its+in+the+signature/22928/">https://isc.sans.edu/forums/diary/Its+in+the+signature/22928/</a> ]]></description>
<itunes:duration>8:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5714" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5712</itunes:episode>
<itunes:subtitle>.MSG Files; Danger of Abandoned Domains;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
.MSG Files; Danger of Abandoned Domains;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5712.mp3" length="4620185" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5712.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5712</link>
<pubDate>Sun, 15 Oct 2017 22:58:38 GMT</pubDate>
<description><![CDATA[Peeking Into an Outlook .msg File<br/>
 <a href="https://isc.sans.edu/forums/diary/Peeking+into+msg+files/22926/">https://isc.sans.edu/forums/diary/Peeking+into+msg+files/22926/</a><br/>
Abandoned Domains / Equifax/Transunion Lead to Fake Falsh Update<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2017/10/equifax-transunion-websites-push-fake-flash-player/">https://blog.malwarebytes.com/threat-analysis/2017/10/equifax-transunion-websites-push-fake-flash-player/</a><br/>
Microsoft Patch Causes Corrupted Systems<br/>
 <a href="https://support.microsoft.com/en-us/help/4049094">https://support.microsoft.com/en-us/help/4049094</a><br/>
DoubleLocker Android Ransomware<br/>
 <a href="https://www.welivesecurity.com/2017/10/13/doublelocker-innovative-android-malware/">https://www.welivesecurity.com/2017/10/13/doublelocker-innovative-android-malware/</a><br/>
Chrome Extension Mines Crypto Currency<br/>
 <a href="https://www.bleepingcomputer.com/news/security/chrome-extension-uses-your-gmail-to-register-domains-names-and-injects-coinhive/">https://www.bleepingcomputer.com/news/security/chrome-extension-uses-your-gmail-to-register-domains-names-and-injects-coinhive/</a><br/>
]]></description>
<itunes:duration>5:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5712" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5710</itunes:episode>
<itunes:subtitle>Configuration Version Control; Using HDD as Microphone; More JS Crypto Currency Miners
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Configuration Version Control; Using HDD as Microphone; More JS Crypto Currency Miners
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5710.mp3" length="4976313" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5710.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5710</link>
<pubDate>Thu, 12 Oct 2017 22:30:05 GMT</pubDate>
<description><![CDATA[Version Control Tools Are Not Only For Developers<br/>
 <a href="https://isc.sans.edu/forums/diary/Version+control+tools+arent+only+for+Developers/22922/">https://isc.sans.edu/forums/diary/Version+control+tools+arent+only+for+Developers/22922/</a><br/>
Coin Hive Javascript Crypto Currency Miner Found on Piratebay<br/>
 <a href="https://twitter.com/esterling_/status/918240914623090695">https://twitter.com/esterling_/status/918240914623090695</a><br/>
 <a href="https://crypto-loot.com">https://crypto-loot.com</a><br/>
Macro-less Code Exec in MSWord Rediscovered<br/>
 <a href="https://sensepost.com/blog/2017/macro-less-code-exec-in-msword/">https://sensepost.com/blog/2017/macro-less-code-exec-in-msword/</a><br/>
 <a href="https://blog.nviso.be/2017/10/11/detecting-dde-in-ms-office-documents/">https://blog.nviso.be/2017/10/11/detecting-dde-in-ms-office-documents/</a><br/>
Hard Disks Can Be Used As Microphones<br/>
 <a href="https://github.com/ortegaalfredo/kscope/blob/master/doc/HDD-microphones.pdf">https://github.com/ortegaalfredo/kscope/blob/master/doc/HDD-microphones.pdf</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5710" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5708</itunes:episode>
<itunes:subtitle>Outlook S/MIME Flaw; #RubyGems Vuln; #Google Home Mini Recording Flaw; #Camaradar
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Outlook S/MIME Flaw; #RubyGems Vuln; #Google Home Mini Recording Flaw; #Camaradar
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5708.mp3" length="5561255" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5708.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5708</link>
<pubDate>Wed, 11 Oct 2017 22:40:02 GMT</pubDate>
<description><![CDATA[Outlook Includes plain text version of e-mail with S/MIME Encryption<br/>
 <a href="https://www.sec-consult.com/en/blog/2017/10/fake-crypto-microsoft-outlook-smime-cleartext-disclosure-cve-2017-11776/index.html">https://www.sec-consult.com/en/blog/2017/10/fake-crypto-microsoft-outlook-smime-cleartext-disclosure-cve-2017-11776/index.html</a><br/>
RubyGems Remote Code Execution Vulnerability<br/>
 <a href="http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html">http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html</a><br/>
Google Home Mini Recorded Everything<br/>
 <a href="http://www.androidpolice.com/2017/10/10/google-nerfing-home-minis-mine-spied-everything-said-247/">http://www.androidpolice.com/2017/10/10/google-nerfing-home-minis-mine-spied-everything-said-247/</a><br/>
Cameradar Finds Open RTSP Streams<br/>
 <a href="https://github.com/EtixLabs/cameradar">https://github.com/EtixLabs/cameradar</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5708" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5706</itunes:episode>
<itunes:subtitle>#MSFT Monthly Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#MSFT Monthly Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5706.mp3" length="4959650" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5706.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5706</link>
<pubDate>Wed, 11 Oct 2017 00:30:06 GMT</pubDate>
<description><![CDATA[Microsoft Monthly Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/October+2017+Security+Updates/22916/">https://isc.sans.edu/forums/diary/October+2017+Security+Updates/22916/</a><br/>
Spoofed iOS iCloud Login <br/>
 <a href="https://krausefx.com/blog/ios-privacy-stealpassword-easily-get-the-users-apple-id-password-just-by-asking">https://krausefx.com/blog/ios-privacy-stealpassword-easily-get-the-users-apple-id-password-just-by-asking</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5706" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5704</itunes:episode>
<itunes:subtitle>Base64 Encoded Word Documents
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Base64 Encoded Word Documents
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5704.mp3" length="5518694" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5704.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5704</link>
<pubDate>Mon, 09 Oct 2017 23:15:05 GMT</pubDate>
<description><![CDATA[Base64 Encoded Word Documents<br/>
 <a href="https://isc.sans.edu/forums/diary/Base64+All+The+Things/22912/">https://isc.sans.edu/forums/diary/Base64+All+The+Things/22912/</a><br/>
Skimmer Scanner Helps Find Credit Card Skimmers<br/>
 <a href="https://github.com/sparkfunX/Skimmer_Scanner">https://github.com/sparkfunX/Skimmer_Scanner</a><br/>
TLS 1.3 Remains "On Hold"<br/>
 <a href="https://www.ietf.org/mail-archive/web/tls/current/msg24517.html">https://www.ietf.org/mail-archive/web/tls/current/msg24517.html</a><br/>
FIDO U2F Key Review / Test<br/>
 <a href="https://www.imperialviolet.org/2017/10/08/securitykeytest.html">https://www.imperialviolet.org/2017/10/08/securitykeytest.html</a><br/>
]]></description>
<itunes:duration>6:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5704" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Sunday, October 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5702</itunes:episode>
<itunes:subtitle>Payment Handler API; OpenSSH Version 7.6 Released; Microsoft Unanounced Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Payment Handler API; OpenSSH Version 7.6 Released; Microsoft Unanounced Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5702.mp3" length="6889182" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5702.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5702</link>
<pubDate>Sun, 08 Oct 2017 13:39:15 GMT</pubDate>
<description><![CDATA[Payment Handler API<br/>
 <a href="https://w3c.github.io/payment-handler/">https://w3c.github.io/payment-handler/</a><br/>
 <a href="https://blog.lukaszolejnik.com/privacy-of-web-request-api/">https://blog.lukaszolejnik.com/privacy-of-web-request-api/</a><br/>
OpenSSH Version 7.6 Released<br/>
 <a href="http://www.openssh.com/txt/release-7.6">http://www.openssh.com/txt/release-7.6</a><br/>
Microsoft Delaying Some Patches for Earlier Windows Versions<br/>
 <a href="https://googleprojectzero.blogspot.sg/2017/10/using-binary-diffing-to-discover.html">https://googleprojectzero.blogspot.sg/2017/10/using-binary-diffing-to-discover.html</a><br/>
The Dangers of Cables<br/>
 <a href="https://isc.sans.edu/forums/diary/Whats+in+a+cable+The+dangers+of+unauthorized+cables/22904/">https://isc.sans.edu/forums/diary/Whats+in+a+cable+The+dangers+of+unauthorized+cables/22904/</a><br/>
]]></description>
<itunes:duration>8:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5702" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5700</itunes:episode>
<itunes:subtitle>New Tool: pcap2curl; MacOS High Sierra Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
New Tool: pcap2curl; MacOS High Sierra Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5700.mp3" length="13178366" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5700.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5700</link>
<pubDate>Fri, 06 Oct 2017 01:45:06 GMT</pubDate>
<description><![CDATA[Extract HTTP Requests from PCAPs and Turn Them Into cURL Commands<br/>
 <a href="https://isc.sans.edu/forums/diary/pcap2curl+Turning+a+pcap+file+into+a+set+of+cURL+commands+for+replay/22900/">https://isc.sans.edu/forums/diary/pcap2curl+Turning+a+pcap+file+into+a+set+of+cURL+commands+for+replay/22900/</a><br/>
Apple Patches Embarrasing MacOS High Sierra Flaw<br/>
 <a href="https://www.appleworld.today/blog/2017/10/5/macos-high-sierra-flaw-exposes-passwords-of-encrypted-apfs-volumes">https://www.appleworld.today/blog/2017/10/5/macos-high-sierra-flaw-exposes-passwords-of-encrypted-apfs-volumes</a><br/>
Another Tomcat PUT Vulnerability<br/>
 <a href="https://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb@%3Cannounce.tomcat.apache.org%3E">https://lists.apache.org/thread.html/3fd341a604c4e9eab39e7eaabbbac39c30101a022acc11dd09d7ebcb@%3Cannounce.tomcat.apache.org%3E</a><br/>
Dallas Haselhorst: HL7 Healthcare Protocol<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/hipaa/hl7-data-interfaces-medical-environments-understanding-fundamental-flaw-healthcare-38005">https://www.sans.org/reading-room/whitepapers/hipaa/hl7-data-interfaces-medical-environments-understanding-fundamental-flaw-healthcare-38005</a><br/>
 <a href="https://www.sans.org/reading-room/whitepapers/vpns/hl7-data-interfaces-medical-environments-attacking-defending-achilles-heel-healthcare-38010">https://www.sans.org/reading-room/whitepapers/vpns/hl7-data-interfaces-medical-environments-attacking-defending-achilles-heel-healthcare-38010</a><br/>
 <a href="https://www.tripwire.com/state-of-security/security-data-protection/hl7-data-interfaces-in-medical-environments/">https://www.tripwire.com/state-of-security/security-data-protection/hl7-data-interfaces-in-medical-environments/</a><br/>
]]></description>
<itunes:duration>15:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5700" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5698</itunes:episode>
<itunes:subtitle>#CSAM; Improved Rowhammer Attacks; VMWare Escape Metasploit Modules
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#CSAM; Improved Rowhammer Attacks; VMWare Escape Metasploit Modules
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5698.mp3" length="4763572" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5698.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5698</link>
<pubDate>Wed, 04 Oct 2017 23:31:48 GMT</pubDate>
<description><![CDATA[Cyber Security Awareness Month: Ouch! Newsletter<br/>
 <a href="https://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201710_en.pdf">https://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201710_en.pdf</a><br/>
Modified Rowhammer Attack Bypasses Current Defenses<br/>
 <a href="https://arxiv.org/pdf/1710.00551.pdf">https://arxiv.org/pdf/1710.00551.pdf</a><br/>
Metasploit Modules For VMWare Escape<br/>
 <a href="https://www.zerodayinitiative.com/blog/2017/10/04/vmware-escapology-how-to-houdini-the-hypervisor">https://www.zerodayinitiative.com/blog/2017/10/04/vmware-escapology-how-to-houdini-the-hypervisor</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5698" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 4th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5696</itunes:episode>
<itunes:subtitle>Fedex Malspam Pushes Formbook; Fake and Vulnerable Wordpress Plugins
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Fedex Malspam Pushes Formbook; Fake and Vulnerable Wordpress Plugins
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5696.mp3" length="5074906" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5696.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5696</link>
<pubDate>Wed, 04 Oct 2017 00:00:16 GMT</pubDate>
<description><![CDATA[Fedex Malspam Pushes Formbook Infostealer Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/22888/">https://isc.sans.edu/forums/diary/Malspam+pushing+Formbook+info+stealer/22888/</a><br/>
Wordpress Plugins Heavily Abused For Site Defacements<br/>
 <a href="https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild/">https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild/</a><br/>
Fake WordPress Security Plugin Being Advertised<br/>
 <a href="https://blog.sucuri.net/2017/09/fake-plugins-fake-security.html">https://blog.sucuri.net/2017/09/fake-plugins-fake-security.html</a><br/>
Proof Of Concept Information Disclosure for Internet Explorer<br/>
 <a href="https://www.brokenbrowser.com/revealing-the-content-of-the-address-bar-ie/">https://www.brokenbrowser.com/revealing-the-content-of-the-address-bar-ie/</a><br/>
Nzyme Wifi Frame Recording and Forensics<br/>
 <a href="https://wtf.horse/2017/10/02/introducing-nzyme-wifi-802-11-frame-recording-and-forensics/">https://wtf.horse/2017/10/02/introducing-nzyme-wifi-802-11-frame-recording-and-forensics/</a><br/>
Cyber Security Interviews<br/>
 <a href="https://twitter.com/CSI_Podcast/status/915026734801489921">https://twitter.com/CSI_Podcast/status/915026734801489921</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5696" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5694</itunes:episode>
<itunes:subtitle>Passive DNS; Bypassing Domain Authentication;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Passive DNS; Bypassing Domain Authentication;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5694.mp3" length="4945408" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5694.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5694</link>
<pubDate>Tue, 03 Oct 2017 01:30:04 GMT</pubDate>
<description><![CDATA[Passive DNS<br/>
 Investigating Security Incidents with Passive DNS<br/>
Bypassing Domain Authentication<br/>
 <a href="https://medium.freecodecamp.org/how-i-hacked-hundreds-of-companies-through-their-helpdesk-b7680ddc2d4c">https://medium.freecodecamp.org/how-i-hacked-hundreds-of-companies-through-their-helpdesk-b7680ddc2d4c</a><br/>
DNSMasq Vulnerabilities<br/>
 <a href="https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html">https://security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5694" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 2nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5692</itunes:episode>
<itunes:subtitle>More Javascript Monero Miners; OS X Patches JS Quarantine Bypass; Mac EFI Patch Status
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Javascript Monero Miners; OS X Patches JS Quarantine Bypass; Mac EFI Patch Status
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5692.mp3" length="4518048" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5692.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5692</link>
<pubDate>Mon, 02 Oct 2017 00:17:39 GMT</pubDate>
<description><![CDATA[Who's Borrowing Your Resources. Javascript Monero Miners on Video Sites<br/>
 <a href="https://isc.sans.edu/forums/diary/Whos+Borrowing+your+Resources/22882/">https://isc.sans.edu/forums/diary/Whos+Borrowing+your+Resources/22882/</a><br/>
OS X Silently Patches Javascript Quarantine Bypass<br/>
 <a href="https://www.wearesegment.com/research/Mac-OS-X-Local-Javascript-Quarantine-Bypass.html">https://www.wearesegment.com/research/Mac-OS-X-Local-Javascript-Quarantine-Bypass.html</a><br/>
Apple EFI Updates Often Not Applied<br/>
 <a href="https://duo.com/blog/the-apple-of-your-efi-mac-firmware-security-research">https://duo.com/blog/the-apple-of-your-efi-mac-firmware-security-research</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5692" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 29th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5690</itunes:episode>
<itunes:subtitle>Dealing With Massive PCAPs; Illusion Gap AV Bypass; DNSSEC KSK Update Delayed
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Dealing With Massive PCAPs; Illusion Gap AV Bypass; DNSSEC KSK Update Delayed
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5690.mp3" length="4886422" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5690.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5690</link>
<pubDate>Fri, 29 Sep 2017 00:20:02 GMT</pubDate>
<description><![CDATA[Dealing With Massive Packet Captures<br/>
 <a href="https://isc.sans.edu/forums/diary/The+easy+way+to+analyze+huge+amounts+of+PCAP+data/22876/">https://isc.sans.edu/forums/diary/The+easy+way+to+analyze+huge+amounts+of+PCAP+data/22876/</a><br/>
Illusion Gap Anti-Virus Bypass<br/>
 <a href="https://www.cyberark.com/threat-research-blog/illusion-gap-antivirus-bypass-part-1/">https://www.cyberark.com/threat-research-blog/illusion-gap-antivirus-bypass-part-1/</a><br/>
DNSSEC KSK Update Delayed<br/>
 <a href="https://www.icann.org/news/announcement-2017-09-27-en">https://www.icann.org/news/announcement-2017-09-27-en</a><br/>
Linux PIE/Stack Corruption<br/>
 <a href="https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt">https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5690" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5688</itunes:episode>
<itunes:subtitle>Everything About JPEGs; Linux 4.14; CLKSCREW;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Everything About JPEGs; Linux 4.14; CLKSCREW;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5688.mp3" length="4414143" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5688.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5688</link>
<pubDate>Thu, 28 Sep 2017 01:15:05 GMT</pubDate>
<description><![CDATA[Everything You Ever Wanted To Know About JPEGs (and more)<br/>
 <a href="https://isc.sans.edu/forums/diary/It+is+a+resume+Part+3/22808/">https://isc.sans.edu/forums/diary/It+is+a+resume+Part+3/22808/</a><br/>
Linux 4.14 Memory Encryption<br/>
 <a href="https://lwn.net/Articles/686808/">https://lwn.net/Articles/686808/</a><br/>
CLKSCREW: Exposing Secure Enclaves via Energy Management<br/>
 <a href="https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-tang.pdf">https://www.usenix.org/system/files/conference/usenixsecurity17/sec17-tang.pdf</a><br/>
~<br/>
~<br/>
~<br/>
~<br/>
]]></description>
<itunes:duration>5:14</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5688" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5686</itunes:episode>
<itunes:subtitle>XPCTRA Malware; Mobile Invetment Vulns; iOS Wifi Exploit PoC; "Dirty Cow" used in Android Malware</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
XPCTRA Malware; Mobile Invetment Vulns; iOS Wifi Exploit PoC; "Dirty Cow" used in Android Malware</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5686.mp3" length="4464175" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5686.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5686</link>
<pubDate>Wed, 27 Sep 2017 02:30:05 GMT</pubDate>
<description><![CDATA[XPCTRA Steals Banking / Cryptocurrency Info<br/>
 <a href="https://isc.sans.edu/forums/diary/XPCTRA+Malware+Steals+Banking+and+Digital+Wallet+Users+Credentials/22868/">https://isc.sans.edu/forums/diary/XPCTRA+Malware+Steals+Banking+and+Digital+Wallet+Users+Credentials/22868/</a><br/>
Vulnerable Mobile Investment Applications<br/>
 <a href="http://blog.ioactive.com/2017/09/are-you-trading-securely-insights-into.html">http://blog.ioactive.com/2017/09/are-you-trading-securely-insights-into.html</a><br/>
iOS WiFi Exploit PoC Code Published<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1289">https://bugs.chromium.org/p/project-zero/issues/detail?id=1289</a><br/>
Android Malware Exploiting "Dirty Cow"<br/>
 <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/zniu-first-android-malware-exploit-dirty-cow-vulnerability/">http://blog.trendmicro.com/trendlabs-security-intelligence/zniu-first-android-malware-exploit-dirty-cow-vulnerability/</a>]]></description>
<itunes:duration>5:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5686" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 26th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5684</itunes:episode>
<itunes:subtitle>macOS High Sierra; Possible macOS Keychain Leak; Showtime Making You Mine Monero
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
macOS High Sierra; Possible macOS Keychain Leak; Showtime Making You Mine Monero
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5684.mp3" length="4764605" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5684.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5684</link>
<pubDate>Tue, 26 Sep 2017 02:20:03 GMT</pubDate>
<description><![CDATA[macOS High Sierra Security Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Possible macOS Keychain Leak<br/>
 <a href="https://twitter.com/patrickwardle/status/912254053849079808">https://twitter.com/patrickwardle/status/912254053849079808</a><br/>
Monero Cryptocoin Miner Found on Showtime Website<br/>
 <a href="https://badpackets.net/coinhive-miner-found-on-official-showtime-network-websites-in-latest-case-of-cryptojacking/">https://badpackets.net/coinhive-miner-found-on-official-showtime-network-websites-in-latest-case-of-cryptojacking/</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5684" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 25th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5682</itunes:episode>
<itunes:subtitle>Forensics and "mount --bind"; Adobe PGP Error; AVAST Update; Go Keyboard Spyware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Forensics and "mount --bind"; Adobe PGP Error; AVAST Update; Go Keyboard Spyware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5682.mp3" length="5050988" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5682.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5682</link>
<pubDate>Mon, 25 Sep 2017 00:45:04 GMT</pubDate>
<description><![CDATA[Forensic Use of "mount --bind"<br/>
 <a href="https://isc.sans.edu/forums/diary/Forensic+use+of+mount+bind/22854/">https://isc.sans.edu/forums/diary/Forensic+use+of+mount+bind/22854/</a><br/>
Adobe Publishes Secret PGP Key By Mistake<br/>
 <a href="https://twitter.com/jupenur/status/911286403434246144">https://twitter.com/jupenur/status/911286403434246144</a><br/>
AVAST Publishes CCleaner Update<br/>
 <a href="https://blog.avast.com/avast-threat-labs-analysis-of-ccleaner-incident">https://blog.avast.com/avast-threat-labs-analysis-of-ccleaner-incident</a><br/>
Compromised Android Keyboard App<br/>
 <a href="https://blog.adguard.com/en/go-spy-go-popular-android-keyboard-from-china-crosses-the-red-line/">https://blog.adguard.com/en/go-spy-go-popular-android-keyboard-from-china-crosses-the-red-line/</a><br/>
]]></description>
<itunes:duration>6:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5682" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5680</itunes:episode>
<itunes:subtitle>More DDoS Extortion; .Net ex-0-day Moves from APT to Crimeware; CCleaner Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More DDoS Extortion; .Net ex-0-day Moves from APT to Crimeware; CCleaner Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5680.mp3" length="4730615" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5680.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5680</link>
<pubDate>Fri, 22 Sep 2017 01:50:03 GMT</pubDate>
<description><![CDATA[More (Likely Fake) DDoS Extortion Attempts<br/>
 <a href="https://isc.sans.edu/forums/diary/Emails+threatening+DDoS+allegedly+from+Phantom+Squad/22856/">https://isc.sans.edu/forums/diary/Emails+threatening+DDoS+allegedly+from+Phantom+Squad/22856/</a><br/>
CVE-2017-8759 Used in Cyber Crime Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Email+attachment+using+CVE20178759+exploit+targets+Argentina/22850/">https://isc.sans.edu/forums/diary/Email+attachment+using+CVE20178759+exploit+targets+Argentina/22850/</a><br/>
CCleaner Command and Control Server<br/>
 <a href="http://blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html?m=1">http://blog.talosintelligence.com/2017/09/ccleaner-c2-concern.html?m=1</a><br/>
Vulnerability in Intel Managment Engine Can Lead to Execution of Unsigned Code<br/>
 <a href="https://www.blackhat.com/eu-17/briefings/schedule/#how-to-hack-a-turned-off-computer-or-running-unsigned-code-in-intel-management-engine-8668">https://www.blackhat.com/eu-17/briefings/schedule/#how-to-hack-a-turned-off-computer-or-running-unsigned-code-in-intel-management-engine-8668</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5680" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5678</itunes:episode>
<itunes:subtitle>Locky Again; Viacom S3 Leak; iOS 11 Outlook.com Bug;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Locky Again; Viacom S3 Leak; iOS 11 Outlook.com Bug;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5678.mp3" length="4736445" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5678.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5678</link>
<pubDate>Thu, 21 Sep 2017 00:25:02 GMT</pubDate>
<description><![CDATA[Newest Locky Update: RAR Attachments and "Invoice" E-Mails<br/>
 <a href="https://isc.sans.edu/forums/diary/Ongoing+Ykcol+Locky+campaign/22848/">https://isc.sans.edu/forums/diary/Ongoing+Ykcol+Locky+campaign/22848/</a><br/>
Viacom S3 Bucket Leak<br/>
 <a href="https://www.upguard.com/breaches/cloud-leak-viacom">https://www.upguard.com/breaches/cloud-leak-viacom</a><br/>
iOS 11 Outlook.com Bug<br/>
 <a href="https://support.apple.com/en-us/HT208136">https://support.apple.com/en-us/HT208136</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5678" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5676</itunes:episode>
<itunes:subtitle>mac-robber; iOS Update; #Tomcat RCE Vulnerability; iTerm DNS Data Leak;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
mac-robber; iOS Update; #Tomcat RCE Vulnerability; iTerm DNS Data Leak;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5676.mp3" length="5070222" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5676.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5676</link>
<pubDate>Wed, 20 Sep 2017 01:55:03 GMT</pubDate>
<description><![CDATA[Mac-Robber Python Rewrite<br/>
 <a href="https://isc.sans.edu/forums/diary/New+tool+macrobberpy/22844/">https://isc.sans.edu/forums/diary/New+tool+macrobberpy/22844/</a><br/>
Apache Tomcat Patch<br/>
 <a href="https://www.us-cert.gov/ncas/current-activity/2017/09/19/Apache-Releases-Security-Updates-Apache-Tomcat">https://www.us-cert.gov/ncas/current-activity/2017/09/19/Apache-Releases-Security-Updates-Apache-Tomcat</a><br/>
Apple Updates For iOS, Xcode, tvOS, watchOS and Safari<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5676" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5674</itunes:episode>
<itunes:subtitle>#CCleaner Compromise; Word #INCLUDEPICTURE; security.txt file 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#CCleaner Compromise; Word #INCLUDEPICTURE; security.txt file 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5674.mp3" length="6850794" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5674.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5674</link>
<pubDate>Tue, 19 Sep 2017 04:50:03 GMT</pubDate>
<description><![CDATA[CCleaner Compromise<br/>
 <a href="http://blog.talosintelligence.com/2017/09/avast-distributes-malware.html">http://blog.talosintelligence.com/2017/09/avast-distributes-malware.html</a><br/>
 <a href="http://www.piriform.com/news/release-announcements/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users">http://www.piriform.com/news/release-announcements/2017/9/18/security-notification-for-ccleaner-v5336162-and-ccleaner-cloud-v1073191-for-32-bit-windows-users</a><br/>
Word INCLUDEPICTURE Feature Abuse<br/>
 <a href="https://securelist.com/an-undocumented-word-feature-abused-by-attackers/81899/">https://securelist.com/an-undocumented-word-feature-abused-by-attackers/81899/</a><br/>
security.txt file<br/>
 <a href="https://www.ietf.org/id/draft-foudil-securitytxt-00.txt">https://www.ietf.org/id/draft-foudil-securitytxt-00.txt</a><br/>
 <a href="https://www.ietf.org/rfc/rfc2142.txt">https://www.ietf.org/rfc/rfc2142.txt</a><br/>
]]></description>
<itunes:duration>8:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5674" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5672</itunes:episode>
<itunes:subtitle>WSL #Bashware; Javascript Crypto Currency Miner; #NodeJS DoS; #HTTPS Interception
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
WSL #Bashware; Javascript Crypto Currency Miner; #NodeJS DoS; #HTTPS Interception
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5672.mp3" length="4971502" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5672.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5672</link>
<pubDate>Mon, 18 Sep 2017 00:50:02 GMT</pubDate>
<description><![CDATA[Bashware: Bypassing Windows Security via Linux (WSL)<br/>
<a href="https://research.checkpoint.com/beware-bashware-new-method-malware-bypass-security-solutions/">https://research.checkpoint.com/beware-bashware-new-method-malware-bypass-security-solutions/</a><br/>
Javascript Rogue Crypto Currency Miner<br/>
 <a href="https://www.welivesecurity.com/2017/09/14/cryptocurrency-web-mining-union-profit/">https://www.welivesecurity.com/2017/09/14/cryptocurrency-web-mining-union-profit/</a><br/>
NodeJS Hash Table DoS<br/>
 <a href="https://medium.com/@ahmadbamieh/nodejs-constant-hashtables-seeds-vulnerability-f03bf70e3593">https://medium.com/@ahmadbamieh/nodejs-constant-hashtables-seeds-vulnerability-f03bf70e3593</a><br/>
HTTPS Interception<br/>
 <a href="https://blog.cloudflare.com/understanding-the-prevalence-of-web-traffic-interception/">https://blog.cloudflare.com/understanding-the-prevalence-of-web-traffic-interception/</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5672" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5670</itunes:episode>
<itunes:subtitle>Webshells and Backdoors; D-Link Patch; Google Play Store Malware; Elasticsearch Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Webshells and Backdoors; D-Link Patch; Google Play Store Malware; Elasticsearch Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5670.mp3" length="4595340" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5670.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5670</link>
<pubDate>Fri, 15 Sep 2017 03:55:03 GMT</pubDate>
<description><![CDATA[Another Webshell; Another Backdoor<br/>
 <a href="https://isc.sans.edu/forums/diary/Another+webshell+another+backdoor/22826/">https://isc.sans.edu/forums/diary/Another+webshell+another+backdoor/22826/</a><br/>
D-Link Vulnerability<br/>
 <a href="https://pierrekim.github.io/blog/2017-09-08-dlink-850l-mydlink-cloud-0days-vulnerabilities.html">https://pierrekim.github.io/blog/2017-09-08-dlink-850l-mydlink-cloud-0days-vulnerabilities.html</a><br/>
Chrome To Label FTP As Insecure<br/>
 <a href="https://groups.google.com/a/chromium.org/forum/#!msg/security-dev/HknIAQwMoWo/xYyezYV5AAAJ">https://groups.google.com/a/chromium.org/forum/#!msg/security-dev/HknIAQwMoWo/xYyezYV5AAAJ</a><br/>
More Google Play Store Malware<br/>
 <a href="https://blog.checkpoint.com/2017/09/14/expensivewall-dangerous-packed-malware-google-play-will-hit-wallet/">https://blog.checkpoint.com/2017/09/14/expensivewall-dangerous-packed-malware-google-play-will-hit-wallet/</a><br/>
Elasticsearch Botnet<br/>
 <a href="https://mackeepersecurity.com/post/kromtech-discovers-massive-elasticsearch-infected-malware-botnet">https://mackeepersecurity.com/post/kromtech-discovers-massive-elasticsearch-infected-malware-botnet</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5670" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5668</itunes:episode>
<itunes:subtitle>"Rogue" IPv6;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
"Rogue" IPv6;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5668.mp3" length="4220428" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5668.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5668</link>
<pubDate>Thu, 14 Sep 2017 03:25:03 GMT</pubDate>
<description><![CDATA[No IPv6? Challenge Accepted<br/>
 <a href="https://isc.sans.edu/forums/diary/No+IPv6+Challenge+Accepted+Part+1/22820/">https://isc.sans.edu/forums/diary/No+IPv6+Challenge+Accepted+Part+1/22820/</a><br/>
Exploiting CVE-2017-8759<br/>
 <a href="https://www.mdsec.co.uk/2017/09/exploiting-cve-2017-8759-soap-wsdl-parser-code-injection/">https://www.mdsec.co.uk/2017/09/exploiting-cve-2017-8759-soap-wsdl-parser-code-injection/</a><br/>
Wordpress Plugin Found With Backdoor<br/>
 <a href="https://www.pluginvulnerabilities.com/2017/09/11/wordpress-poor-handling-of-plugin-security-exacerbates-malicious-takeover-of-display-widgets/">https://www.pluginvulnerabilities.com/2017/09/11/wordpress-poor-handling-of-plugin-security-exacerbates-malicious-takeover-of-display-widgets/</a><br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5668" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5666</itunes:episode>
<itunes:subtitle>#MSFT Patch Tuesday; BlueBorne Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#MSFT Patch Tuesday; BlueBorne Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5666.mp3" length="4765680" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5666.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5666</link>
<pubDate>Wed, 13 Sep 2017 04:15:07 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2017/09/zero-day-used-to-distribute-finspy.html">https://www.fireeye.com/blog/threat-research/2017/09/zero-day-used-to-distribute-finspy.html</a><br/>
 <a href="https://technet.microsoft.com/security/advisories">https://technet.microsoft.com/security/advisories</a><br/>
BlueBorne Bluetooth Vulnerability<br/>
 <a href="http://go.armis.com/hubfs/BlueBorne%20Technical%20White%20Paper.pdf">http://go.armis.com/hubfs/BlueBorne%20Technical%20White%20Paper.pdf</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5666" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5664</itunes:episode>
<itunes:subtitle>Cisco Struts Updates; Comodo Violating CAA; Identifying malware TLS connections
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Cisco Struts Updates; Comodo Violating CAA; Identifying malware TLS connections
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5664.mp3" length="5568523" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5664.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5664</link>
<pubDate>Tue, 12 Sep 2017 03:30:06 GMT</pubDate>
<description><![CDATA[Cisco Struts Updates<br/>
<a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170909-struts2-rce">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170909-struts2-rce</a><br/>
Google Chrome Warning Users of Anti-Malware SSL Interception<br/>
 <a href="https://twitter.com/sashaperigo/status/906263091624591360">https://twitter.com/sashaperigo/status/906263091624591360</a><br/>
Machinelearning To Identify Malicious TLS Connections<br/>
 <a href="https://arxiv.org/pdf/1607.01639.pdf">https://arxiv.org/pdf/1607.01639.pdf</a><br/>
Comodo Breaking CAA Standard<br/>
 <a href="https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/msg08027.html">https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/msg08027.html</a><br/>
]]></description>
<itunes:duration>6:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5664" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5662</itunes:episode>
<itunes:subtitle>Analyzing JPEGs; WINspect; PSSetLoadImageNotifyRoutine; IOTA Cryto Currency
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing JPEGs; WINspect; PSSetLoadImageNotifyRoutine; IOTA Cryto Currency
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5662.mp3" length="4898637" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5662.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5662</link>
<pubDate>Mon, 11 Sep 2017 04:20:02 GMT</pubDate>
<description><![CDATA[Analyzing JPEG Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+JPEG+files/22806/">https://isc.sans.edu/forums/diary/Analyzing+JPEG+files/22806/</a><br/>
Auditing Windows With WINspect<br/>
 <a href="https://isc.sans.edu/forums/diary/Windows+Auditing+with+WINspect/22810/">https://isc.sans.edu/forums/diary/Windows+Auditing+with+WINspect/22810/</a><br/>
Windows PSSetLoadImageNotifyRoutine Vulnerability<br/>
 <a href="https://breakingmalware.com/documentation/windows-pssetloadimagenotifyroutine-callbacks-good-bad-unclear-part-1/">https://breakingmalware.com/documentation/windows-pssetloadimagenotifyroutine-callbacks-good-bad-unclear-part-1/</a><br/>
IOTA Cryptocurrency Vulnerable Hash Function<br/>
 <a href="https://medium.com/@neha/cryptographic-vulnerabilities-in-iota-9a6a9ddc4367">https://medium.com/@neha/cryptographic-vulnerabilities-in-iota-9a6a9ddc4367</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5662" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5660</itunes:episode>
<itunes:subtitle>More Struts Issues; Equifax Compromise;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Struts Issues; Equifax Compromise;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5660.mp3" length="13137598" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5660.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5660</link>
<pubDate>Fri, 08 Sep 2017 01:25:03 GMT</pubDate>
<description><![CDATA[Yet Another Struts RCE Vulnerability<br/>
 <a href="https://struts.apache.org/docs/s2-053.html">https://struts.apache.org/docs/s2-053.html</a><br/>
Equifax Compromise<br/>
 <a href="https://www.bloomberg.com/news/articles/2017-09-07/three-equifax-executives-sold-stock-before-revealing-cyber-hack">https://www.bloomberg.com/news/articles/2017-09-07/three-equifax-executives-sold-stock-before-revealing-cyber-hack</a><br/>
Hash Extension Flaws<br/>
 <a href="https://isc.sans.edu/forums/diary/Modern+Web+Application+Penetration+Testing+Hash+Length+Extension+Attacks/22792/">https://isc.sans.edu/forums/diary/Modern+Web+Application+Penetration+Testing+Hash+Length+Extension+Attacks/22792/</a><br/>
Matt Hosburgh: Offensive Intrusion Analysis: Uncovering Insiders with Threat Hunting and Active Defense<br/>
]]></description>
<itunes:duration>15:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5660" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5658</itunes:episode>
<itunes:subtitle>Struts2 Exploit Public; More MongoDB Ransom
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Struts2 Exploit Public; More MongoDB Ransom
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5658.mp3" length="4442859" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5658.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5658</link>
<pubDate>Thu, 07 Sep 2017 02:10:03 GMT</pubDate>
<description><![CDATA[Struts2 Metasploit Module<br/>
 <a href="https://github.com/rapid7/metasploit-framework/pull/8924/commits/5ea83fee5ee8c23ad95608b7e2022db5b48340ef">https://github.com/rapid7/metasploit-framework/pull/8924/commits/5ea83fee5ee8c23ad95608b7e2022db5b48340ef</a><br/>
Google Docs Table With Hacked MongoDB Databases<br/>
 <a href="https://docs.google.com/spreadsheets/d/1QonE9oeMOQHVh8heFIyeqrjfKEViL0poLnY8mAakKhM/edit#gid=1781677175">https://docs.google.com/spreadsheets/d/1QonE9oeMOQHVh8heFIyeqrjfKEViL0poLnY8mAakKhM/edit#gid=1781677175</a><br/>
Bypassing Cloudflare<br/>
 <a href="https://rhinosecuritylabs.com/cloud-security/cloudflare-bypassing-cloud-security/">https://rhinosecuritylabs.com/cloud-security/cloudflare-bypassing-cloud-security/</a><br/>
]]></description>
<itunes:duration>5:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5658" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5656</itunes:episode>
<itunes:subtitle>#Mirai Decay; #Struts Vulnerability;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#Mirai Decay; #Struts Vulnerability;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5656.mp3" length="5711542" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5656.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5656</link>
<pubDate>Wed, 06 Sep 2017 00:35:02 GMT</pubDate>
<description><![CDATA[A Look Back At Nira and What's Next<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Mirai+Botnet+A+Look+Back+and+Ahead+At+Whats+Next/22786/">https://isc.sans.edu/forums/diary/The+Mirai+Botnet+A+Look+Back+and+Ahead+At+Whats+Next/22786/</a><br/>
New Struts Vulnerability and Patch<br/>
 <a href="https://isc.sans.edu/forums/diary/Struts+vulnerability+patch+released+by+apache+patch+now/22788">https://isc.sans.edu/forums/diary/Struts+vulnerability+patch+released+by+apache+patch+now/22788</a><br/>
Mastercard Internet Gateway Service Flaw<br/>
 <a href="http://tinyhack.com/2017/09/05/mastercard-internet-gateway-service-hashing-design-flaw/">http://tinyhack.com/2017/09/05/mastercard-internet-gateway-service-hashing-design-flaw/</a><br/>
Mac OS X High Sierra Insecure Kernel Module Loading<br/>
 <a href="https://objective-see.com/blog/blog_0x21.html">https://objective-see.com/blog/blog_0x21.html</a><br/>
]]></description>
<itunes:duration>6:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5656" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5654</itunes:episode>
<itunes:subtitle>Locky Back Via Fake Fonts; Asterisk RTPBleed; Arris AT&amp;T Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Locky Back Via Fake Fonts; Asterisk RTPBleed; Arris AT&amp;T Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5654.mp3" length="5311864" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5654.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5654</link>
<pubDate>Tue, 05 Sep 2017 00:05:02 GMT</pubDate>
<description><![CDATA[Locky Ransom Ware is Back and This Time Pretents to Be a Font<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Locky+ransomware+tries+HoeflerText+notifications+for+Chrome+and+FireFox/22776/">https://isc.sans.edu/forums/diary/Malspam+pushing+Locky+ransomware+tries+HoeflerText+notifications+for+Chrome+and+FireFox/22776/</a><br/>
When is a PDF Just a PDF?<br/>
 <a href="https://isc.sans.edu/forums/diary/It+is+a+resume+Part+1/22780/">https://isc.sans.edu/forums/diary/It+is+a+resume+Part+1/22780/</a><br/>
Asterisk Vulnerable to RTPBleed<br/>
 <a href="https://github.com/EnableSecurity/advisories/tree/master/ES2017-04-asterisk-rtp-bleed">https://github.com/EnableSecurity/advisories/tree/master/ES2017-04-asterisk-rtp-bleed</a><br/>
Arris AT&T Modems With Backdoor<br/>
 <a href="https://www.nomotion.net/blog/sharknatto/">https://www.nomotion.net/blog/sharknatto/</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5654" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5652</itunes:episode>
<itunes:subtitle>Remote Work in a SOC; Linux RNG Reviewed; Turning Speaker into Microphones
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Remote Work in a SOC; Linux RNG Reviewed; Turning Speaker into Microphones
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5652.mp3" length="12121056" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5652.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5652</link>
<pubDate>Fri, 01 Sep 2017 02:45:05 GMT</pubDate>
<description><![CDATA[Is Remote Work Feasible in a SOC?<br/>
<a href="https://isc.sans.edu/forums/diary/Remote+SOC+Workers+Concerns/22772/">https://isc.sans.edu/forums/diary/Remote+SOC+Workers+Concerns/22772/</a><br/>
Linux Random Number Generator Reviewed<br/>
<a href="https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Studien/LinuxRNG/LinuxRNG_EN.pdf?__blob=publicationFile&v=5">https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Studien/LinuxRNG/LinuxRNG_EN.pdf?__blob=publicationFile&v=5</a><br/>
Adobe Acrobat and Reader Security Patch<br/>
 <a href="https://blogs.adobe.com/psirt/?p=1484">https://blogs.adobe.com/psirt/?p=1484</a><br/>
Turning Speakers into Microphones<br/>
<a href="https://www.usenix.org/system/files/conference/woot17/woot17-paper-guri.pdf">https://www.usenix.org/system/files/conference/woot17/woot17-paper-guri.pdf</a><br/>
]]></description>
<itunes:duration>14:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5652" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 31st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5650</itunes:episode>
<itunes:subtitle>ConnManDo Vulnerablity; Trickbot Goes After Coinbase; Pacemaker Patch; Inaudible Audio Commands
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
ConnManDo Vulnerablity; Trickbot Goes After Coinbase; Pacemaker Patch; Inaudible Audio Commands
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5650.mp3" length="5455226" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5650.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5650</link>
<pubDate>Wed, 30 Aug 2017 23:05:03 GMT</pubDate>
<description><![CDATA[IoT Gear Affected by ConnMan Vulnerablity<br/>
 <a href="http://connmando.nri-secure.co.jp/index.html">http://connmando.nri-secure.co.jp/index.html</a><br/>
Trickbot Going After Coinbase<br/>
 <a href="https://blogs.forcepoint.com/security-labs/trickbot-goes-after-cryptocurrency">https://blogs.forcepoint.com/security-labs/trickbot-goes-after-cryptocurrency</a><br/>
Pacemakers Need Patch<br/>
 <a href="https://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm573669.htm">https://www.fda.gov/MedicalDevices/Safety/AlertsandNotices/ucm573669.htm</a><br/>
Inaudible Voice Commands<br/>
 <a href="https://arxiv.org/pdf/1708.07238.pdf">https://arxiv.org/pdf/1708.07238.pdf</a><br/>
]]></description>
<itunes:duration>6:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5650" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 30th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5648</itunes:episode>
<itunes:subtitle>More Chrome Extension Banking Malware; Ransomware Spreading via RDP; More Leaked Passwords
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More Chrome Extension Banking Malware; Ransomware Spreading via RDP; More Leaked Passwords
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5648.mp3" length="5135168" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5648.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5648</link>
<pubDate>Wed, 30 Aug 2017 00:25:03 GMT</pubDate>
<description><![CDATA[Another Chrome Extension Banking Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Second+Google+Chrome+Extension+Banker+Malware+in+Two+Weeks/22766/">https://isc.sans.edu/forums/diary/Second+Google+Chrome+Extension+Banker+Malware+in+Two+Weeks/22766/</a><br/>
Vulnerable Docker VM<br/>
 <a href="https://www.notsosecure.com/vulnerable-docker-vm/">https://www.notsosecure.com/vulnerable-docker-vm/</a><br/>
Large Spam E-Mail and Password List Discovered<br/>
 <a href="https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump/">https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump/</a><br/>
]]></description>
<itunes:duration>6:06</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5648" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 29th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5646</itunes:episode>
<itunes:subtitle>DVRs Again; Disabling Intel ME; Wire-X Android DDoS Bot
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DVRs Again; Disabling Intel ME; Wire-X Android DDoS Bot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5646.mp3" length="4751257" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5646.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5646</link>
<pubDate>Tue, 29 Aug 2017 01:50:02 GMT</pubDate>
<description><![CDATA[Survey of Recent DVR Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/An+Update+On+DVR+Malware+A+DVR+Torture+Chamber/22762/">https://isc.sans.edu/forums/diary/An+Update+On+DVR+Malware+A+DVR+Torture+Chamber/22762/</a><br/>
Disabling Intel ME<br/>
<a href="http://blog.ptsecurity.com/2017/08/disabling-intel-me.html">http://blog.ptsecurity.com/2017/08/disabling-intel-me.html</a><br/>
Wire-X Takedown<br/>
<a href="https://blogs.akamai.com/2017/08/the-wirex-botnet-an-example-of-cross-organizational-cooperation.html">https://blogs.akamai.com/2017/08/the-wirex-botnet-an-example-of-cross-organizational-cooperation.html</a><br/>
]]></description>
<itunes:duration>5:38</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5646" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5644</itunes:episode>
<itunes:subtitle>Analyzing 7zip Malware; Worldwide DNS Manipulation; Crypto Miner Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Analyzing 7zip Malware; Worldwide DNS Manipulation; Crypto Miner Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5644.mp3" length="5738966" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5644.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5644</link>
<pubDate>Mon, 28 Aug 2017 00:40:03 GMT</pubDate>
<description><![CDATA[Analyzing 7zip Malware<br/>
<a href="https://isc.sans.edu/forums/diary/Malware+analysis+searching+for+dots/22758/">https://isc.sans.edu/forums/diary/Malware+analysis+searching+for+dots/22758/</a><br/>
Worldwide DNS Manipulation Survey<br/>
<a href="https://people.eecs.berkeley.edu/~pearce/papers/dns_usenix_2017.pdf">https://people.eecs.berkeley.edu/~pearce/papers/dns_usenix_2017.pdf</a><br/>
Sophos Withdraws UTM Update<br/>
<a href="https://community.sophos.com/products/unified-threat-management/b/utm-blog/posts/utm-up2date-9-503-released">https://community.sophos.com/products/unified-threat-management/b/utm-blog/posts/utm-up2date-9-503-released</a><br/>
Crypto Currency Malware<br/>
<a href="https://resources.netskope.com/h/i/361264722-coin-mining-malware-heads-to-the-cloud-with-zminer">https://resources.netskope.com/h/i/361264722-coin-mining-malware-heads-to-the-cloud-with-zminer</a><br/>
]]></description>
<itunes:duration>6:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5644" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 25th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5642</itunes:episode>
<itunes:subtitle>HPE iLO Vuln; Facebook Messenger Malspam; Samsung Failed TV Update
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HPE iLO Vuln; Facebook Messenger Malspam; Samsung Failed TV Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5642.mp3" length="10412979" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5642.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5642</link>
<pubDate>Fri, 25 Aug 2017 00:05:03 GMT</pubDate>
<description><![CDATA[Critical HPE iLo Vulnerability<br/>
 <a href="http://h20565.www2.hpe.com/hpsc/doc/public/display?docId=hpesbhf03769en_us">http://h20565.www2.hpe.com/hpsc/doc/public/display?docId=hpesbhf03769en_us</a><br/>
Facebook Messenger Spam Leads to Malware<br/>
 <a href="https://securelist.com/new-multi-platform-malwareadware-spreading-via-facebook-messenger/81590/">https://securelist.com/new-multi-platform-malwareadware-spreading-via-facebook-messenger/81590/</a><br/>
iOS 10.3.1 Kernel Exploit Released<br/>
 <a href="https://blog.zimperium.com/ziva-video-audio-ios-kernel-exploit/">https://blog.zimperium.com/ziva-video-audio-ios-kernel-exploit/</a><br/>
Samsung Bricks Smart TVs With Update<br/>
 <a href="https://eu.community.samsung.com/t5/TV-Audio-Video/Samsung-MU-Series-2017-Smart-TV-s-will-do-nothing-after-Samsung/td-p/250277">https://eu.community.samsung.com/t5/TV-Audio-Video/Samsung-MU-Series-2017-Smart-TV-s-will-do-nothing-after-Samsung/td-p/250277</a><br/>
John Bambenek's DGA Feeds<br/>
 <a href="http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt">http://osint.bambenekconsulting.com/feeds/c2-ipmasterlist.txt</a>]]></description>
<itunes:duration>12:23</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5642" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5640</itunes:episode>
<itunes:subtitle>Malware Loading Avast Safe Zone Browser?
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Loading Avast Safe Zone Browser?
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5640.mp3" length="4827964" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5640.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5640</link>
<pubDate>Thu, 24 Aug 2017 00:05:03 GMT</pubDate>
<description><![CDATA[Malware Loading Avast Safe Zone Browser<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+script+dropping+an+executable+signed+by+Avast/22748/">https://isc.sans.edu/forums/diary/Malicious+script+dropping+an+executable+signed+by+Avast/22748/</a><br/>
Ropemaker E-Mail Content<br/>
 <a href="https://www.mimecast.com/globalassets/documents/whitepapers/wp_the_ropemaker_email_exploit.pdf">https://www.mimecast.com/globalassets/documents/whitepapers/wp_the_ropemaker_email_exploit.pdf</a><br/>
Cloud Based Accounts Increasingly a Target<br/>
 <a href="https://www.microsoft.com/en-us/security/intelligence-report">https://www.microsoft.com/en-us/security/intelligence-report</a><br/>
More Malware Found At Ukraining Accounting Software Makers<br/>
<a href="https://issp.ua/issp_system_images/UPD_samples_analysis_eng.pdf">https://issp.ua/issp_system_images/UPD_samples_analysis_eng.pdf</a><br/>
]]></description>
<itunes:duration>5:44</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5640" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 23rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5638</itunes:episode>
<itunes:subtitle>Keychain iCloud Storage Risks; Room Mapping With Speakers; .fish Used For Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Keychain iCloud Storage Risks; Room Mapping With Speakers; .fish Used For Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5638.mp3" length="4330564" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5638.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5638</link>
<pubDate>Wed, 23 Aug 2017 00:55:03 GMT</pubDate>
<description><![CDATA[Elcomsoft Releases Ability to Retrieve Apple Keychain from iCloud<br/>
 <a href="https://www.elcomsoft.com/eppb.html">https://www.elcomsoft.com/eppb.html</a><br/>
Mapping Rooms With Smart Speakers<br/>
 <a href="http://musicattacks.cs.washington.edu/activity-information-leakage.pdf">http://musicattacks.cs.washington.edu/activity-information-leakage.pdf</a><br/>
Netcraft Identifies .fish Domain Used For Phishing<br/>
 <a href="https://news.netcraft.com/archives/2017/08/21/first-fishy-phishing-sites-sighted.html">https://news.netcraft.com/archives/2017/08/21/first-fishy-phishing-sites-sighted.html</a><br/>
]]></description>
<itunes:duration>5:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5638" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5636</itunes:episode>
<itunes:subtitle>Enigma Cryto Currency Theft; Bitcoin Privacy Threats; SyncCrypt ZIP in Images
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Enigma Cryto Currency Theft; Bitcoin Privacy Threats; SyncCrypt ZIP in Images
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5636.mp3" length="4872563" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5636.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5636</link>
<pubDate>Tue, 22 Aug 2017 01:05:02 GMT</pubDate>
<description><![CDATA[Hackers Scam $ 500,000 From Enigma Digital Currency Investors<br/>
 <a href="http://www.theregister.co.uk/2017/08/21/enigma_digital_currency_investors_scammed/">http://www.theregister.co.uk/2017/08/21/enigma_digital_currency_investors_scammed/</a><br/>
Bitcoin Privacy Threats<br/>
 <a href="https://arxiv.org/abs/1708.04748">https://arxiv.org/abs/1708.04748</a><br/>
$500 iPhone PIN Brute Forcing Box<br/>
 <a href="https://www.youtube.com/watch?v=IXglwbyMydM">https://www.youtube.com/watch?v=IXglwbyMydM</a><br/>
SyncCrypt Bypasses Antivirus Filters With Images<br/>
 <a href="https://www.bleepingcomputer.com/news/security/synccrypt-ransomware-hides-inside-jpg-files-appends-kk-extension/">https://www.bleepingcomputer.com/news/security/synccrypt-ransomware-hides-inside-jpg-files-appends-kk-extension/</a><br/>
]]></description>
<itunes:duration>5:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5636" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5634</itunes:episode>
<itunes:subtitle>EngineBox Banking Malware; Invoice Malware; iOS SEP Key; FoxIT Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
EngineBox Banking Malware; Invoice Malware; iOS SEP Key; FoxIT Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5634.mp3" length="4597324" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5634.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5634</link>
<pubDate>Sun, 20 Aug 2017 23:20:02 GMT</pubDate>
<description><![CDATA[EngineBox Banking Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/EngineBox+Malware+Supports+10+Brazilian+Banks/22736/">https://isc.sans.edu/forums/diary/EngineBox+Malware+Supports+10+Brazilian+Banks/22736/</a><br/>
It's Not An Invoice <br/>
 <a href="https://isc.sans.edu/forums/diary/Its+Not+An+Invoice/22738/">https://isc.sans.edu/forums/diary/Its+Not+An+Invoice/22738/</a><br/>
iOS Secure Enclave Key Posted<br/>
 <a href="https://www.theiphonewiki.com/wiki/Greensburg_14G60_%28iPhone6,1%29">https://www.theiphonewiki.com/wiki/Greensburg_14G60_%28iPhone6,1%29</a><br/>
Vulnerabilities in FoxIT PDF Reader<br/>
 <a href="https://www.thezdi.com/blog/2017/8/17/busting-myths-in-foxit-reader">https://www.thezdi.com/blog/2017/8/17/busting-myths-in-foxit-reader</a><br/>
]]></description>
<itunes:duration>5:27</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5634" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5632</itunes:episode>
<itunes:subtitle>Maldoc Uses Link Auto-Update; Rowhammer for SSD
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Maldoc Uses Link Auto-Update; Rowhammer for SSD
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5632.mp3" length="13790120" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5632.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5632</link>
<pubDate>Fri, 18 Aug 2017 01:05:02 GMT</pubDate>
<description><![CDATA[Maldoc with auto-updated link<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+with+autoupdated+link/22730/">https://isc.sans.edu/forums/diary/Maldoc+with+autoupdated+link/22730/</a><br/>
Rowhammer is Back: SSD Memory Affected<br/>
 <a href="https://www.usenix.org/system/files/conference/woot17/woot17-paper-kurmus.pdf">https://www.usenix.org/system/files/conference/woot17/woot17-paper-kurmus.pdf</a><br/>
Nathaniel Quist: Active Defense in a Labyrinth of Deception<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/ActiveDefense/active-defense-labyrinth-deception-37462">https://www.sans.org/reading-room/whitepapers/ActiveDefense/active-defense-labyrinth-deception-37462</a><br/>
]]></description>
<itunes:duration>16:24</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5632" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5630</itunes:episode>
<itunes:subtitle>Paypal Phishing Kit; ShadowPad; Audio CAPTCHA Attacks;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Paypal Phishing Kit; ShadowPad; Audio CAPTCHA Attacks;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5630.mp3" length="5335265" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5630.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5630</link>
<pubDate>Thu, 17 Aug 2017 03:25:03 GMT</pubDate>
<description><![CDATA[Analysis of a Paypal Phishing Kit<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+Paypal+phishing+kit/22726/">https://isc.sans.edu/forums/diary/Analysis+of+a+Paypal+phishing+kit/22726/</a><br/>
ShadowPad Backdoor in NetSarang Equipment<br/>
 <a href="https://securelist.com/shadowpad-in-corporate-networks/81432/">https://securelist.com/shadowpad-in-corporate-networks/81432/</a><br/>
Solving Captcha Audio Challenges<br/>
 <a href="http://uncaptcha.cs.umd.edu/papers/uncaptcha_woot17.pdf">http://uncaptcha.cs.umd.edu/papers/uncaptcha_woot17.pdf</a><br/>
]]></description>
<itunes:duration>6:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5630" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5628</itunes:episode>
<itunes:subtitle>Trickbot via Malspam; Malware via Phone; DJI "Go" App Found to Use JSPatch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Trickbot via Malspam; Malware via Phone; DJI "Go" App Found to Use JSPatch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5628.mp3" length="5105036" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5628.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5628</link>
<pubDate>Wed, 16 Aug 2017 00:10:03 GMT</pubDate>
<description><![CDATA[Malspam Pushing Trickbot Banking Trojan<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Trickbot+banking+Trojan/22720/">https://isc.sans.edu/forums/diary/Malspam+pushing+Trickbot+banking+Trojan/22720/</a><br/>
Banker Google Chrome Extension Targeting Brazil<br/>
 <a href="https://isc.sans.edu/forums/diary/BankerGoogleChromeExtensiontargetingBrazil/22722/">https://isc.sans.edu/forums/diary/BankerGoogleChromeExtensiontargetingBrazil/22722/</a><br/>
DJI "Go" App May Be Using JSPatch To Modify Applications After Install<br/>
 <a href="https://www.rcgroups.com/forums/showpost.php?p=38096850&postcount=2713">https://www.rcgroups.com/forums/showpost.php?p=38096850&postcount=2713</a><br/>
Smartlocks Bricked After Auto-Update<br/>
 <a href="http://www.securitysales.com/news/smart-locks-lobotomized-failed-update/">http://www.securitysales.com/news/smart-locks-lobotomized-failed-update/</a><br/>
]]></description>
<itunes:duration>6:03</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5628" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5626</itunes:episode>
<itunes:subtitle>SPAM vs. Malware; Android Intra-Library Collusion; SonicSpy
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SPAM vs. Malware; Android Intra-Library Collusion; SonicSpy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5626.mp3" length="5184723" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5626.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5626</link>
<pubDate>Tue, 15 Aug 2017 00:05:03 GMT</pubDate>
<description><![CDATA[When A Malicious Looking E-Mail Turns Out to be "just" spam<br/>
 <a href="https://isc.sans.edu/forums/diary/Sometimes+its+just+SPAM/22716/">https://isc.sans.edu/forums/diary/Sometimes+its+just+SPAM/22716/</a><br/>
Android iOS Intra-Library Collusion<br/>
 <a href="https://arxiv.org/abs/1708.03520">https://arxiv.org/abs/1708.03520</a><br/>
SonicSpy: Android Spyware Apps<br/>
 <a href="https://blog.lookout.com/sonicspy-spyware-threat-technical-research">https://blog.lookout.com/sonicspy-spyware-threat-technical-research</a><br/>
Checking For Breached Passwords in Active Directory<br/>
 <a href="https://jacksonvd.com/checking-for-breached-passwords-in-active-directory/">https://jacksonvd.com/checking-for-breached-passwords-in-active-directory/</a><br/>
]]></description>
<itunes:duration>6:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5626" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5624</itunes:episode>
<itunes:subtitle>OWA Attacks; Phishing Tests;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
OWA Attacks; Phishing Tests;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5624.mp3" length="4773708" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5624.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5624</link>
<pubDate>Mon, 14 Aug 2017 00:45:04 GMT</pubDate>
<description><![CDATA[Outlook Web Access Based Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Outlook+Web+Access+based+attacks/22710/">https://isc.sans.edu/forums/diary/Outlook+Web+Access+based+attacks/22710/</a><br/>
The Good Phishing Email<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Good+Phishing+Email/22712/">https://isc.sans.edu/forums/diary/The+Good+Phishing+Email/22712/</a><br/>
Git/CVS/Mercurial and others: ssh vulnerablity<br/>
 <a href="http://blog.recurity-labs.com/2017-08-10/scm-vulns">http://blog.recurity-labs.com/2017-08-10/scm-vulns</a><br/>
Postgresql Vulnerablities<br/>
 <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1477185">https://bugzilla.redhat.com/show_bug.cgi?id=1477185</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5624" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5622</itunes:episode>
<itunes:subtitle>Maldoc Analysis With ViperMonkey; More WoSign Trouble; SMS Touch Bugs; Mac Adware
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Maldoc Analysis With ViperMonkey; More WoSign Trouble; SMS Touch Bugs; Mac Adware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5622.mp3" length="4854451" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5622.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5622</link>
<pubDate>Fri, 11 Aug 2017 01:45:04 GMT</pubDate>
<description><![CDATA[Maldoc Analysis With ViperMonkey<br/>
 <a href="https://isc.sans.edu/forums/diary/Maldoc+Analysis+with+ViperMonkey/22702/">https://isc.sans.edu/forums/diary/Maldoc+Analysis+with+ViperMonkey/22702/</a><br/>
Microsoft Joins Google/Mozilla in Banishing WoSign and StartCom From Trusted CA List<br/>
 <a href="https://blogs.technet.microsoft.com/mmpc/2017/08/08/microsoft-to-remove-wosign-and-startcom-certificates-in-windows-10/">https://blogs.technet.microsoft.com/mmpc/2017/08/08/microsoft-to-remove-wosign-and-startcom-certificates-in-windows-10/</a><br/>
SMS Touch App Leaking Messages<br/>
 <a href="https://www.zscaler.com/blogs/research/mobile-app-wall-shame-sms-touch">https://www.zscaler.com/blogs/research/mobile-app-wall-shame-sms-touch</a><br/>
Mac Adware Mughthesec<br/>
 <a href="https://objective-see.com/blog/blog_0x20.html">https://objective-see.com/blog/blog_0x20.html</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5622" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5620</itunes:episode>
<itunes:subtitle>DirectDefense Accuses Carbon Black of Data Leak;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DirectDefense Accuses Carbon Black of Data Leak;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5620.mp3" length="5781351" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5620.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5620</link>
<pubDate>Thu, 10 Aug 2017 00:20:03 GMT</pubDate>
<description><![CDATA[DirectDefense Accuses Carbon Black of Data Leak<br/>
 <a href="https://www.carbonblack.com/2017/08/09/directdefense-incorrectly-asserts-architectural-flaw-in-cb-response/">https://www.carbonblack.com/2017/08/09/directdefense-incorrectly-asserts-architectural-flaw-in-cb-response/</a><br/>
 <a href="https://www.directdefense.com/harvesting-cb-response-data-leaks-fun-profit/">https://www.directdefense.com/harvesting-cb-response-data-leaks-fun-profit/</a><br/>
Vulnerabilities in Solar Generation<br/>
 <a href="https://horusscenario.com">https://horusscenario.com</a><br/>
Hunting Malicious npm Packages<br/>
 <a href="https://duo.com/blog/hunting-malicious-npm-packages">https://duo.com/blog/hunting-malicious-npm-packages</a><br/>
]]></description>
<itunes:duration>6:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5620" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 9th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5618</itunes:episode>
<itunes:subtitle>MSFT, Adobe and Android Updates; Contract Malspam
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT, Adobe and Android Updates; Contract Malspam
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5618.mp3" length="5018957" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5618.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5618</link>
<pubDate>Wed, 09 Aug 2017 01:50:03 GMT</pubDate>
<description><![CDATA[Microsoft Updates<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+August+2017/22694/">https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+August+2017/22694/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security.html">https://helpx.adobe.com/security.html</a><br/>
Android Patches<br/>
 <a href="https://source.android.com/security/bulletin/2017-08-01">https://source.android.com/security/bulletin/2017-08-01</a><br/>
How Are People Fooled By This? Email To Sign a Contract Provides Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/How+are+people+fooled+by+this+Email+to+sign+a+contract+provides+malware+instead/22696/">https://isc.sans.edu/forums/diary/How+are+people+fooled+by+this+Email+to+sign+a+contract+provides+malware+instead/22696/</a><br/>
]]></description>
<itunes:duration>5:57</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5618" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5616</itunes:episode>
<itunes:subtitle>PHPMyAdmin Scans; Hotspot Shield FTC Complaints
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
PHPMyAdmin Scans; Hotspot Shield FTC Complaints
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5616.mp3" length="4821025" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5616.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5616</link>
<pubDate>Mon, 07 Aug 2017 23:15:04 GMT</pubDate>
<description><![CDATA[PHPMyAdmin Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Increase+of+phpMyAdmin+scans/22688/">https://isc.sans.edu/forums/diary/Increase+of+phpMyAdmin+scans/22688/</a><br/>
Hotspot Shield Leakes Private User Data<br/>
 <a href="https://cdt.org/files/2017/08/FTC-CDT-VPN-complaint-8-7-17.pdf">https://cdt.org/files/2017/08/FTC-CDT-VPN-complaint-8-7-17.pdf</a><br/>
Debian Turning Off Support for TLS 1.0/1.1<br/>
 <a href="https://lists.debian.org/debian-devel-announce/2017/08/msg00004.html">https://lists.debian.org/debian-devel-announce/2017/08/msg00004.html</a><br/>
Ongoing Phishing Attacks Against Google Chrome Plugin Developers<br/>
 <a href="https://www.bleepingcomputer.com/news/security/chrome-extension-developers-under-a-barrage-of-phishing-attacks/">https://www.bleepingcomputer.com/news/security/chrome-extension-developers-under-a-barrage-of-phishing-attacks/</a><br/>
]]></description>
<itunes:duration>5:43</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5616" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, August 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5614</itunes:episode>
<itunes:subtitle>Opengraph Link Obfuscation; Cerber Steals Bitcoins;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Opengraph Link Obfuscation; Cerber Steals Bitcoins;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5614.mp3" length="5240474" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5614.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5614</link>
<pubDate>Mon, 07 Aug 2017 01:45:04 GMT</pubDate>
<description><![CDATA[Opengraph Used to Obfuscate Facebook Links<br/>
 <a href="https://isc.sans.edu/forums/diary/Use+of+the+Open+Graph+Protocol+to+Disguise+Malicious+Facebook+Links/22684/">https://isc.sans.edu/forums/diary/Use+of+the+Open+Graph+Protocol+to+Disguise+Malicious+Facebook+Links/22684/</a><br/>
Cerber Adding Bitcoin and Password Stealer to Crypto Ransomware<br/>
 <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/cerber-ransomware-evolves-now-steals-bitcoin-wallets/">http://blog.trendmicro.com/trendlabs-security-intelligence/cerber-ransomware-evolves-now-steals-bitcoin-wallets/</a><br/>
Symantec Selling Certificate Business To Digicert<br/>
 <a href="https://www.heise.de/security/meldung/Nachspiel-einer-fatalen-Panne-Symantec-verkauft-Zertifikatssparte-an-DigiCert-3793482.html">https://www.heise.de/security/meldung/Nachspiel-einer-fatalen-Panne-Symantec-verkauft-Zertifikatssparte-an-DigiCert-3793482.html</a><br/>
Siemens Medical Imaging Systems Vulnerable to Old Windows Flaws<br/>
 <a href="https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-822184.pdf">https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-822184.pdf</a><br/>
]]></description>
<itunes:duration>6:13</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5614" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, August 4th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5612</itunes:episode>
<itunes:subtitle>#RPi Honeypot
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
#RPi Honeypot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5612.mp3" length="4918097" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5612.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5612</link>
<pubDate>Fri, 04 Aug 2017 00:25:03 GMT</pubDate>
<description><![CDATA[Raspberry Pi Honeypot<br/>
 <a href="https://github.com/DShield-ISC/dshield">https://github.com/DShield-ISC/dshield</a><br/>
Troy Hunt Releases Password List<br/>
 <a href="https://haveibeenpwned.com/Passwords">https://haveibeenpwned.com/Passwords</a><br/>
Typosquatting npm Packages<br/>
 <a href="http://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry">http://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry</a><br/>
SEC503: Intrusion Detection in Depth Berlin (Oct 23rd-28th)<br/>
 <a href="https://www.sans.org/event/berlin-2017/course/intrusion-detection-in-depth">https://www.sans.org/event/berlin-2017/course/intrusion-detection-in-depth</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5612" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, August 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5610</itunes:episode>
<itunes:subtitle>Attacking #NoSQL; Web Developer Toolbar Hijacked; #Amazon stops selling #Blu
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Attacking #NoSQL; Web Developer Toolbar Hijacked; #Amazon stops selling #Blu
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5610.mp3" length="4508897" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5610.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5610</link>
<pubDate>Wed, 02 Aug 2017 23:25:03 GMT</pubDate>
<description><![CDATA[Attacking NoSQL Applications<br/>
 <a href="https://isc.sans.edu/forums/diary/Attacking+NoSQL+applications+part+2/22676/">https://isc.sans.edu/forums/diary/Attacking+NoSQL+applications+part+2/22676/</a><br/>
Web Developer Chrome Toolbar Replaced with AdWare<br/>
 <a href="https://twitter.com/chrispederick">https://twitter.com/chrispederick</a><br/>
Android Banking Trojans<br/>
 <a href="https://securelist.com/a-new-era-in-mobile-banking-trojans/79198/">https://securelist.com/a-new-era-in-mobile-banking-trojans/79198/</a><br/>
Amazon Stops Selling Blu Smartphones<br/>
 <a href="http://www.zdnet.com/article/amazon-halts-blu-phone-sales-over-potential-security-issue/">http://www.zdnet.com/article/amazon-halts-blu-phone-sales-over-potential-security-issue/</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5610" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, August 2nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5608</itunes:episode>
<itunes:subtitle>Detect SMB Versions; CopyFish Adware; McAffee Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Detect SMB Versions; CopyFish Adware; McAffee Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5608.mp3" length="5313287" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5608.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5608</link>
<pubDate>Wed, 02 Aug 2017 01:40:02 GMT</pubDate>
<description><![CDATA[Detect SMB Versions with nmap<br/>
 <a href="https://isc.sans.edu/forums/diary/Rooting+Out+Hosts+that+Support+Older+Samba+Versions/22672/">https://isc.sans.edu/forums/diary/Rooting+Out+Hosts+that+Support+Older+Samba+Versions/22672/</a><br/>
CopyFish Google Chrome Extension Replaced by Adware<br/>
 <a href="https://a9t9.com/blog/chrome-extension-adware/">https://a9t9.com/blog/chrome-extension-adware/</a><br/>
StartCom Applying to be Included in Mozilla SSL CAs again<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1311832#c12">https://bugzilla.mozilla.org/show_bug.cgi?id=1311832#c12</a><br/>
McAffee Uses Mixed SSL/nonSSL Content For Online Malware Scan<br/>
 <a href="https://blogs.securiteam.com/index.php/archives/3350">https://blogs.securiteam.com/index.php/archives/3350</a><br/>
Netflix Releases DoS Testing Tool<br/>
 <a href="https://medium.com/netflix-techblog/starting-the-avalanche-640e69b14a06">https://medium.com/netflix-techblog/starting-the-avalanche-640e69b14a06</a><br/>
]]></description>
<itunes:duration>6:18</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5608" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, August 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5606</itunes:episode>
<itunes:subtitle>Outlook Patches; Social Media Recon; ShieldFS Protecting Files
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Outlook Patches; Social Media Recon; ShieldFS Protecting Files
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5606.mp3" length="4779844" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5606.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5606</link>
<pubDate>Tue, 01 Aug 2017 00:50:03 GMT</pubDate>
<description><![CDATA[MSFT Re-Releases June Outlook Update<br/>
 <a href="https://support.office.com/en-us/article/Outlook-known-issues-in-the-June-2017-security-updates-3f6dbffd-8505-492d-b19f-b3b89369ed9b?ui=en-US&rs=en-US&ad=US&fromAR=1">https://support.office.com/en-us/article/Outlook-known-issues-in-the-June-2017-security-updates-3f6dbffd-8505-492d-b19f-b3b89369ed9b?ui=en-US&rs=en-US&ad=US&fromAR=1</a><br/>
Iranian Hackers Use Social Media To Collect Data<br/>
 <a href="https://www.darkreading.com/attacks-breaches/iranian-hackers-ensnared-targets-via-phony-female-photographer/d/d-id/1329502?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple">https://www.darkreading.com/attacks-breaches/iranian-hackers-ensnared-targets-via-phony-female-photographer/d/d-id/1329502?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple</a><br/>
ShieldFS Self Healing Filesystem<br/>
 <a href="http://shieldfs.necst.it/continella-shieldfs-2016.pdf">http://shieldfs.necst.it/continella-shieldfs-2016.pdf</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5606" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 31st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5604</itunes:episode>
<itunes:subtitle>SMBloris; SMS Phishing; Car Hacking
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
SMBloris; SMS Phishing; Car Hacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5604.mp3" length="4889570" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5604.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5604</link>
<pubDate>Mon, 31 Jul 2017 00:40:03 GMT</pubDate>
<description><![CDATA[SMBloris DoS Attack Locks Up Windows<br/>
 <a href="https://twitter.com/jennamagius/status/891434286212984832">https://twitter.com/jennamagius/status/891434286212984832</a><br/>
 <a href="https://isc.sans.edu/forums/diary/SMBLoris+the+new+SMB+flaw/22662/">https://isc.sans.edu/forums/diary/SMBLoris+the+new+SMB+flaw/22662/</a><br/>
Text Banking Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Text+Banking+Scams/22666/">https://isc.sans.edu/forums/diary/Text+Banking+Scams/22666/</a><br/>
Nissan Leaf WiFi Vulnerability<br/>
 <a href="https://github.com/HackingThings/Publications/blob/cdb72df7c3feffd02593a31d67a34ae353b09114/2017/DC25_Driving%20down%20the%20rabbit%20hole-Mickey_Jesse_Oleksander.pdf">https://github.com/HackingThings/Publications/blob/cdb72df7c3feffd02593a31d67a34ae353b09114/2017/DC25_Driving%20down%20the%20rabbit%20hole-Mickey_Jesse_Oleksander.pdf</a><br/>
]]></description>
<itunes:duration>5:48</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5604" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5602</itunes:episode>
<itunes:subtitle>HTTP Middlemen Vulnerabilities; Goldeneye/Petya Decrypte;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
HTTP Middlemen Vulnerabilities; Goldeneye/Petya Decrypte;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5602.mp3" length="11382399" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5602.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5602</link>
<pubDate>Fri, 28 Jul 2017 03:20:02 GMT</pubDate>
<description><![CDATA[Targeting HTTP's Hidden Attack-Surface<br/>
 <a href="http://blog.portswigger.net/2017/07/cracking-lens-targeting-https-hidden.html">http://blog.portswigger.net/2017/07/cracking-lens-targeting-https-hidden.html</a><br/>
Petya/Goldeneye Decrypter<br/>
 <a href="https://blog.malwarebytes.com/malwarebytes-news/2017/07/bye-bye-petya-decryptor-old-versions-released/">https://blog.malwarebytes.com/malwarebytes-news/2017/07/bye-bye-petya-decryptor-old-versions-released/</a><br/>
TinyPot, My Small Honeypot<br/>
 <a href="https://isc.sans.edu/forums/diary/TinyPot+My+Small+Honeypot/22654/">https://isc.sans.edu/forums/diary/TinyPot+My+Small+Honeypot/22654/</a><br/>
Shaun McCullough<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/testing/docker-create-multi-container-environments-research-sharing-lateral-movement-37855">https://www.sans.org/reading-room/whitepapers/testing/docker-create-multi-container-environments-research-sharing-lateral-movement-37855</a><br/>
]]></description>
<itunes:duration>13:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5602" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5600</itunes:episode>
<itunes:subtitle>Emotet Malspam; Broadpwn Released
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Emotet Malspam; Broadpwn Released
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5600.mp3" length="4373443" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5600.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5600</link>
<pubDate>Thu, 27 Jul 2017 02:15:05 GMT</pubDate>
<description><![CDATA[Malspam Pushing Emotet Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+pushing+Emotet+malware/22650/">https://isc.sans.edu/forums/diary/Malspam+pushing+Emotet+malware/22650/</a><br/>
Broadpwn Released<br/>
 <a href="http://blog.exodusintel.com/2017/07/26/broadpwn/">http://blog.exodusintel.com/2017/07/26/broadpwn/</a><br/>
Microsoft Announces Windows 10 Bug Bounty<br/>
 <a href="https://blogs.technet.microsoft.com/msrc/2017/07/26/announcing-the-windows-bounty-program/">https://blogs.technet.microsoft.com/msrc/2017/07/26/announcing-the-windows-bounty-program/</a><br/>
Custom Map Vulnearbilty in Valve Games<br/>
 <a href="https://oneupsecurity.com/research/remote-code-execution-in-source-games">https://oneupsecurity.com/research/remote-code-execution-in-source-games</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5600" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 26th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5598</itunes:episode>
<itunes:subtitle>Flash is Dead (official); SSL Fingerprinting Tool; More iCloud Ransom Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Flash is Dead (official); SSL Fingerprinting Tool; More iCloud Ransom Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5598.mp3" length="4847611" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5598.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5598</link>
<pubDate>Wed, 26 Jul 2017 01:05:02 GMT</pubDate>
<description><![CDATA[Adobe Announces End of Flash for 2020<br/>
 <a href="https://blogs.adobe.com/conversations/2017/07/adobe-flash-update.html">https://blogs.adobe.com/conversations/2017/07/adobe-flash-update.html</a><br/>
JA3 Hash To Fingerprint SSL/TLS Connections<br/>
 <a href="https://github.com/salesforce/ja3">https://github.com/salesforce/ja3</a><br/>
 <a href="https://engineering.salesforce.com/open-sourcing-ja3-92c9e53c3c41">https://engineering.salesforce.com/open-sourcing-ja3-92c9e53c3c41</a><br/>
New Wave of Apple iCloud Ransom Attacks<br/>
 <a href="https://www.heise.de/mac-and-i/meldung/Erneut-iCloud-Erpressungswelle-ueber-Meinen-Mac-suchen-und-Mein-iPhone-suchen-3782075.html">https://www.heise.de/mac-and-i/meldung/Erneut-iCloud-Erpressungswelle-ueber-Meinen-Mac-suchen-und-Mein-iPhone-suchen-3782075.html</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5598" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 25th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5596</itunes:episode>
<itunes:subtitle>Uber Driver Scam; Critical Netscaler SD-WAN 9.1.2 Issue; Mac Malware FruitFly
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Uber Driver Scam; Critical Netscaler SD-WAN 9.1.2 Issue; Mac Malware FruitFly
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5596.mp3" length="6105162" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5596.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5596</link>
<pubDate>Tue, 25 Jul 2017 01:10:02 GMT</pubDate>
<description><![CDATA[Uber Drivers Targeted in Social Engineering Scam<br/>
 <a href="https://isc.sans.edu/forums/diary/Uber+drivers+new+threat+the+passenger/22626/">https://isc.sans.edu/forums/diary/Uber+drivers+new+threat+the+passenger/22626/</a><br/>
Mac Malware FruitFly2<br/>
 <a href="https://motherboard.vice.com/en_us/article/zmv79w/mysterious-mac-malware-has-infected-hundreds-of-victims-for-years">https://motherboard.vice.com/en_us/article/zmv79w/mysterious-mac-malware-has-infected-hundreds-of-victims-for-years</a><br/>
Exploit Released for Critical Netscaler SD WAN 9.1.2 Vulnerability<br/>
 <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-6316">http://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-6316</a> <br/>
]]></description>
<itunes:duration>7:15</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5596" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5594</itunes:episode>
<itunes:subtitle>Malicious .iso Attachments; Maldocs With .lnk File; Ethereum Compromise
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malicious .iso Attachments; Maldocs With .lnk File; Ethereum Compromise
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5594.mp3" length="4248242" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5594.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5594</link>
<pubDate>Mon, 24 Jul 2017 02:35:02 GMT</pubDate>
<description><![CDATA[Malicious .iso Attachments<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+iso+Attachments/22636/">https://isc.sans.edu/forums/diary/Malicious+iso+Attachments/22636/</a><br/>
Maldoc with .lnk File<br/>
 <a href="https://isc.sans.edu/forums/diary/Another+lnk+File/22640/">https://isc.sans.edu/forums/diary/Another+lnk+File/22640/</a><br/>
Large Ethereum Hack<br/>
 <a href="http://hackingdistributed.com/2017/07/22/deep-dive-parity-bug/">http://hackingdistributed.com/2017/07/22/deep-dive-parity-bug/</a><br/>
]]></description>
<itunes:duration>5:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5594" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5592</itunes:episode>
<itunes:subtitle>Symantec Sloppy Key Verification; Gnome Thumbnailer RCE;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Symantec Sloppy Key Verification; Gnome Thumbnailer RCE;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5592.mp3" length="9249711" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5592.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5592</link>
<pubDate>Fri, 21 Jul 2017 00:15:04 GMT</pubDate>
<description><![CDATA[Symantec Sloppy Key Verification Leads To Revocation of Certificates<br/>
 <a href="https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-with-a-Fake-Private-Key.html">https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-with-a-Fake-Private-Key.html</a><br/>
Gnome Thumbnailer Executes Code<br/>
 <a href="http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html">http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html</a><br/>
]]></description>
<itunes:duration>11:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5592" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5590</itunes:episode>
<itunes:subtitle>Web Error Logs; Apple Updates Everything;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Web Error Logs; Apple Updates Everything;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5590.mp3" length="5064473" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5590.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5590</link>
<pubDate>Thu, 20 Jul 2017 00:05:02 GMT</pubDate>
<description><![CDATA[Bots Searching for Keys and Config Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Bots+Searching+for+Keys+Config+Files/22630/">https://isc.sans.edu/forums/diary/Bots+Searching+for+Keys+Config+Files/22630/</a><br/>
Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Trend Micro Sees SambaCry Exploits<br/>
 <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/linux-users-urged-update-new-threat-exploits-sambacry/">http://blog.trendmicro.com/trendlabs-security-intelligence/linux-users-urged-update-new-threat-exploits-sambacry/</a><br/>
Google Increases Developer Scrutiny<br/>
 <a href="https://developers.googleblog.com/2017/05/updating-developer-identity-guidelines.html">https://developers.googleblog.com/2017/05/updating-developer-identity-guidelines.html</a><br/>
]]></description>
<itunes:duration>6:01</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5590" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5588</itunes:episode>
<itunes:subtitle>Oracle CPU; Cisco WebEx Patch; NodeJSUpdate; Coindash Hack
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Oracle CPU; Cisco WebEx Patch; NodeJSUpdate; Coindash Hack
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5588.mp3" length="4857913" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5588.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5588</link>
<pubDate>Wed, 19 Jul 2017 00:15:04 GMT</pubDate>
<description><![CDATA[Oracle Quarterly Critical Patch Update<br/>
 <a href="http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html">http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html</a><br/>
Cisco WebEx Plugin Update<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170717-webex">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170717-webex</a><br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1324&desc=2">https://bugs.chromium.org/p/project-zero/issues/detail?id=1324&desc=2</a><br/>
Node.JS DoS Vulnerability <br/>
 <a href="https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/">https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/</a><br/>
Bitdefender Remote Stack Buffer Overflow<br/>
 <a href="https://landave.io/2017/07/bitdefender-remote-stack-buffer-overflow-via-7z-ppmd/">https://landave.io/2017/07/bitdefender-remote-stack-buffer-overflow-via-7z-ppmd/</a><br/>
Coindash Hack<br/>
 <a href="https://twitter.com/coindashio/status/886936799695818752">https://twitter.com/coindashio/status/886936799695818752</a><br/>
 <a href="https://www.coindash.io">https://www.coindash.io</a><br/>
DowJones Leaks Customer Data via S3 Buckets<br/>
 <a href="https://www.upguard.com/breaches/cloud-leak-dow-jones">https://www.upguard.com/breaches/cloud-leak-dow-jones</a><br/>
]]></description>
<itunes:duration>5:46</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5588" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5586</itunes:episode>
<itunes:subtitle>Brazil Phishing Scam Targeting 2FA; FreeRadius Update;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Brazil Phishing Scam Targeting 2FA; FreeRadius Update;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5586.mp3" length="4850412" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5586.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5586</link>
<pubDate>Tue, 18 Jul 2017 00:50:03 GMT</pubDate>
<description><![CDATA[SMS Phishing Asks Victims to Upload Picture of Token Card<br/>
 <a href="https://isc.sans.edu/forums/diary/SMS+Phishing+induces+victims+to+photograph+its+own+token+card/22616/">https://isc.sans.edu/forums/diary/SMS+Phishing+induces+victims+to+photograph+its+own+token+card/22616/</a><br/>
Critical FreeRADIUS Update<br/>
 <a href="https://guidovranken.wordpress.com/2017/07/17/11-remote-vulnerabilities-inc-2x-rce-in-freeradius-packet-parsers/">https://guidovranken.wordpress.com/2017/07/17/11-remote-vulnerabilities-inc-2x-rce-in-freeradius-packet-parsers/</a><br/>
OS X Malware Installs Crypto Messenger Signal<br/>
 <a href="https://blog.checkpoint.com/2017/07/13/osxdok-refuses-go-away-money/">https://blog.checkpoint.com/2017/07/13/osxdok-refuses-go-away-money/</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5586" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5584</itunes:episode>
<itunes:subtitle>NemucodAES Update; Excel and LNK; Gandi Domain Hijack; iSmart Alarm Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
NemucodAES Update; Excel and LNK; Gandi Domain Hijack; iSmart Alarm Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5584.mp3" length="4570143" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5584.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5584</link>
<pubDate>Mon, 17 Jul 2017 00:45:04 GMT</pubDate>
<description><![CDATA[NemucodAES UPS Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/NemucodAES+and+the+malspam+that+distributes+it/22614/">https://isc.sans.edu/forums/diary/NemucodAES+and+the+malspam+that+distributes+it/22614/</a><br/>
Analyzing Malicious Office Document With LNK<br/>
 <a href="https://isc.sans.edu/forums/diary/Office+maldoc+lnk/22618/">https://isc.sans.edu/forums/diary/Office+maldoc+lnk/22618/</a><br/>
Gandi Breach Leads to Domain Compromise<br/>
 <a href="https://news.gandi.net/en/2017/07/detailed-incident-report/">https://news.gandi.net/en/2017/07/detailed-incident-report/</a><br/>
iSmart Alarm Vulnerabilities<br/>
 <a href="http://dojo.bullguard.com/blog/burglar-hacker-when-a-physical-security-is-compromised-by-iot-vulnerabilities/">http://dojo.bullguard.com/blog/burglar-hacker-when-a-physical-security-is-compromised-by-iot-vulnerabilities/</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5584" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5582</itunes:episode>
<itunes:subtitle>Malware Loads ffmpeg; SAP Updates; Password Managers and Cloud Sync
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Malware Loads ffmpeg; SAP Updates; Password Managers and Cloud Sync
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5582.mp3" length="12557310" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5582.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5582</link>
<pubDate>Thu, 13 Jul 2017 19:50:03 GMT</pubDate>
<description><![CDATA[Malware Loads ffmpeg For Video Recording Features<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2017/07/malware-abusing-ffmpeg/">https://blog.malwarebytes.com/threat-analysis/2017/07/malware-abusing-ffmpeg/</a><br/>
Password Managers and Cloud Storage<br/>
 <a href="https://discussions.agilebits.com/discussion/76956/can-i-still-buy-standalone-license-for-the-1password-no-longer-being-marketed/p8">https://discussions.agilebits.com/discussion/76956/can-i-still-buy-standalone-license-for-the-1password-no-longer-being-marketed/p8</a><br/>
SAP Point of Sales Express Patch<br/>
 <a href="https://erpscan.com/press-center/blog/sap-cyber-threat-intelligence-report-july-2017/">https://erpscan.com/press-center/blog/sap-cyber-threat-intelligence-report-july-2017/</a><br/>
Roderick Currie: Car Hacking Developments<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/internet/developments-car-hacking-36607">https://www.sans.org/reading-room/whitepapers/internet/developments-car-hacking-36607</a><br/>
]]></description>
<itunes:duration>14:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5582" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5580</itunes:episode>
<itunes:subtitle>Simple File Integrity Checks; Ethereum Scams; 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Simple File Integrity Checks; Ethereum Scams; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5580.mp3" length="4848724" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5580.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5580</link>
<pubDate>Wed, 12 Jul 2017 21:30:04 GMT</pubDate>
<description><![CDATA[Simple File Integrity Monitoring With Backup Scripts<br/>
 <a href="https://isc.sans.edu/forums/diary/Backup+Scripts+the+FIM+of+the+Poor/22606/">https://isc.sans.edu/forums/diary/Backup+Scripts+the+FIM+of+the+Poor/22606/</a><br/>
Ethereum Wallet Services Targeted By Scammers<br/>
 <a href="http://www.ibtimes.co.uk/ethereum-under-siege-scammers-make-700000-6-days-slack-reddit-phishing-attacks-1629866">http://www.ibtimes.co.uk/ethereum-under-siege-scammers-make-700000-6-days-slack-reddit-phishing-attacks-1629866</a><br/>
MongoDB Security Surprises For Shared Hosting<br/>
 <a href="https://medium.com/@alexbyk/mongodb-at-shared-hosting-security-surprises-c441ecb84b54">https://medium.com/@alexbyk/mongodb-at-shared-hosting-security-surprises-c441ecb84b54</a><br/>
Trend Micro Vulnerabilities<br/>
 <a href="https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities">https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities</a><br/>
]]></description>
<itunes:duration>5:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5580" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5578</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; AT&amp;T Cell Phone Takeover
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
MSFT Patch Tuesday; AT&amp;T Cell Phone Takeover
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5578.mp3" length="4674781" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5578.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5578</link>
<pubDate>Tue, 11 Jul 2017 21:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday <br/>
 <a href="https://isc.sans.edu/diary//22602">https://isc.sans.edu/diary//22602</a><br/>
AT&T Cell Phone Takeover<br/>
 <a href="https://carpeaqua.com/2017/07/07/hack-the-planet/">https://carpeaqua.com/2017/07/07/hack-the-planet/</a><br/>
Systemd Invalid Username Bug To Be Fixed<br/>
 <a href="https://github.com/systemd/systemd/pull/6300">https://github.com/systemd/systemd/pull/6300</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5578" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, July 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5576</itunes:episode>
<itunes:subtitle>Takeover of .io TLD; OpenBSD Even More Random; Malwarebytes quarterly report
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Takeover of .io TLD; OpenBSD Even More Random; Malwarebytes quarterly report
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5576.mp3" length="4768742" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5576.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5576</link>
<pubDate>Mon, 10 Jul 2017 21:00:32 GMT</pubDate>
<description><![CDATA[Takeover of .io TLD<br/>
 <a href="https://thehackerblog.com/the-io-error-taking-control-of-all-io-domains-with-a-targeted-registration/">https://thehackerblog.com/the-io-error-taking-control-of-all-io-domains-with-a-targeted-registration/</a><br/>
Malwarebytes Quarterly Malware Report<br/>
 <a href="https://www.malwarebytes.com/pdf/white-papers/CybercrimeTacticsAndTechniques-Q2-2017.pdf">https://www.malwarebytes.com/pdf/white-papers/CybercrimeTacticsAndTechniques-Q2-2017.pdf</a><br/>
OpenBSD Introducing KARL To Randomize Kernel Layout at Boot<br/>
 <a href="https://marc.info/?l=openbsd-tech&m=149732026405941&w=2">https://marc.info/?l=openbsd-tech&m=149732026405941&w=2</a><br/>
]]></description>
<itunes:duration>5:39</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5576" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, July 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5574</itunes:episode>
<itunes:subtitle>More DDoS Ransom; Using SOF-ELK For Hunting; Template Attacks 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
More DDoS Ransom; Using SOF-ELK For Hunting; Template Attacks 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5574.mp3" length="5006451" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5574.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5574</link>
<pubDate>Sun, 09 Jul 2017 20:40:02 GMT</pubDate>
<description><![CDATA[More DDoS Ransom Demands<br/>
 <a href="https://isc.sans.edu/forums/diary/Adversary+hunting+with+SOFELK/22592/">https://isc.sans.edu/forums/diary/Adversary+hunting+with+SOFELK/22592/</a><br/>
Adversary Hunting With SOF-ELK<br/>
 <a href="https://isc.sans.edu/forums/diary/Adversary+hunting+with+SOFELK/22592/">https://isc.sans.edu/forums/diary/Adversary+hunting+with+SOFELK/22592/</a><br/>
Petya Master Key Published<br/>
 <a href="https://twitter.com/JanusSecretary/status/882663988429021184?ref_src=twsrc%5Etfw&ref_url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fauthor-of-original-petya-ransomware-publishes-master-decryption-key%2F">https://twitter.com/JanusSecretary/status/882663988429021184?ref_src=twsrc%5Etfw&ref_url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fauthor-of-original-petya-ransomware-publishes-master-decryption-key%2F</a><br/>
Template Attacks Against Critical Infrastructure<br/>
 <a href="http://blog.talosintelligence.com/2017/07/template-injection.html">http://blog.talosintelligence.com/2017/07/template-injection.html</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5574" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, July 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5572</itunes:episode>
<itunes:subtitle>Finding Odd Domain Names; BitTorrent Sync 2.0 Log Files; BIND TSIG Exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Finding Odd Domain Names; BitTorrent Sync 2.0 Log Files; BIND TSIG Exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5572.mp3" length="4660182" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5572.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5572</link>
<pubDate>Thu, 06 Jul 2017 20:05:02 GMT</pubDate>
<description><![CDATA[Finding Odd Domain Names<br/>
 <a href="https://isc.sans.edu/forums/diary/Selecting+domains+with+random+names/22580/">https://isc.sans.edu/forums/diary/Selecting+domains+with+random+names/22580/</a><br/>
BitTorrent Sync 2.0 Log Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Investigation+of+BitTorrent+Sync+v20+as+a+P2P+Cloud+Service+Part+2+Log+Files+artefacts/22582/">https://isc.sans.edu/forums/diary/Investigation+of+BitTorrent+Sync+v20+as+a+P2P+Cloud+Service+Part+2+Log+Files+artefacts/22582/</a><br/>
Cisco Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170705-esc2">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170705-esc2</a><br/>
Finding Weak Password Hashing Algorithms Via Hash Collisions<br/>
 <a href="https://www.netsparker.com/blog/web-security/collision-based-hashing-algorithm-disclosure/">https://www.netsparker.com/blog/web-security/collision-based-hashing-algorithm-disclosure/</a><br/>
BIND TSIG Exploit<br/>
 <a href="http://www.synacktiv.ninja/ressources/CVE-2017-3143_BIND9_TSIG_dynamic_updates_vulnerability_Synacktiv.pdf">http://www.synacktiv.ninja/ressources/CVE-2017-3143_BIND9_TSIG_dynamic_updates_vulnerability_Synacktiv.pdf</a><br/>
]]></description>
<itunes:duration>5:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5572" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, July 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5570</itunes:episode>
<itunes:subtitle>AVTest Report; #MSFT Update Prompts; Relaxed Laptop Ban; MeDOC Raid
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
AVTest Report; #MSFT Update Prompts; Relaxed Laptop Ban; MeDOC Raid
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5570.mp3" length="4078418" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5570.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5570</link>
<pubDate>Wed, 05 Jul 2017 19:40:02 GMT</pubDate>
<description><![CDATA[AVTest Report: Ransomware not a big deal; Android/MacOS Catching up to Windows<br/>
 <a href="https://www.av-test.org/fileadmin/pdf/security_report/AV-TEST_Security_Report_2016-2017.pdf">https://www.av-test.org/fileadmin/pdf/security_report/AV-TEST_Security_Report_2016-2017.pdf</a><br/>
Microsoft Will Prompt Users to Update Windows 10<br/>
 <a href="https://support.microsoft.com/en-us/help/4023814">https://support.microsoft.com/en-us/help/4023814</a><br/>
Bithumb Bitcoin Exchange Hacked (Article in Korean)<br/>
 <a href="http://bithumb.cafe/archives/7329">http://bithumb.cafe/archives/7329</a><br/>
Turkish Airlines and Emirates Remove Laptop Ban<br/>
 <a href="http://www.theregister.co.uk/2017/07/05/emirates_and_turkish_airlines_lift_laptop_ban_on_us_flights/">http://www.theregister.co.uk/2017/07/05/emirates_and_turkish_airlines_lift_laptop_ban_on_us_flights/</a><br/>
Ukrainian Authorities Raid MeDoc (Article in Ukrainian)<br/>
 <a href="https://cyberpolice.gov.ua/news/prykryttyam-najmasshtabnishoyi-kiberataky-v-istoriyi-ukrayiny-stav-virus-diskcoderc-881/">https://cyberpolice.gov.ua/news/prykryttyam-najmasshtabnishoyi-kiberataky-v-istoriyi-ukrayiny-stav-virus-diskcoderc-881/</a><br/>
]]></description>
<itunes:duration>4:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5570" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, July 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5568</itunes:episode>
<itunes:subtitle>Skype Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Skype Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5568.mp3" length="4980671" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5568.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5568</link>
<pubDate>Tue, 04 Jul 2017 23:05:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches Skype Vulnerability<br/>
 <a href="https://www.vulnerability-lab.com/get_content.php?id=2071">https://www.vulnerability-lab.com/get_content.php?id=2071</a><br/>
SystemD Invalid Username Bug Not Considered a Vulnerability (or Bug)<br/>
 <a href="https://github.com/systemd/systemd/issues/6237">https://github.com/systemd/systemd/issues/6237</a><br/>
Cisco Fixes SNMP Vulnerability in IOS and IOS XE<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170629-snmp</a><br/>
Smartphones Can Be Compromised with shady replacement parts<br/>
 <a href="https://iss.oy.ne.ro/Shattered">https://iss.oy.ne.ro/Shattered</a><br/>
Siemens Fixes Intel AMT Bug<br/>
 <a href="https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-874235.pdf">https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-874235.pdf</a><br/>
Update For libgcrypt<br/>
 <a href="https://www.ubuntuupdates.org/package/core/zesty/main/updates/libgcrypt20-dev">https://www.ubuntuupdates.org/package/core/zesty/main/updates/libgcrypt20-dev</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5568" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 30th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5566</itunes:episode>
<itunes:subtitle>News from Blank Slate; Azure AD Connect Bug; #SANSEDU #STI
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
News from Blank Slate; Azure AD Connect Bug; #SANSEDU #STI
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5566.mp3" length="12711679" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5566.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5566</link>
<pubDate>Fri, 30 Jun 2017 01:25:02 GMT</pubDate>
<description><![CDATA[Catching up With Blank Slate<br/>
 <a href="https://isc.sans.edu/forums/diary/Catching+up+with+Blank+Slate+a+malspam+campaign+still+going+strong/22570/">https://isc.sans.edu/forums/diary/Catching+up+with+Blank+Slate+a+malspam+campaign+still+going+strong/22570/</a><br/>
Azure AD Connect Vulnerability<br/>
 <a href="https://technet.microsoft.com/library/security/4033453.aspx#ID0EN">https://technet.microsoft.com/library/security/4033453.aspx#ID0EN</a><br/>
Exploit Available For Stack Clash Vulnerability<br/>
 <a href="https://www.qualys.com/research/security-advisories/">https://www.qualys.com/research/security-advisories/</a><br/>
Paul Herschberger: Data Breach Impact Estimation<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/dlp/data-breach-impact-estimation-37502">https://www.sans.org/reading-room/whitepapers/dlp/data-breach-impact-estimation-37502</a><br/>
]]></description>
<itunes:duration>15:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5566" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 29th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5564</itunes:episode>
<itunes:subtitle>Petya Update; Ubuntu systemd Vuln; BPG Attacks against Bitcoin
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Petya Update; Ubuntu systemd Vuln; BPG Attacks against Bitcoin
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5564.mp3" length="4731086" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5564.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5564</link>
<pubDate>Thu, 29 Jun 2017 01:10:02 GMT</pubDate>
<description><![CDATA[Petya Ransomware Update<br/>
<a href="https://isc.sans.edu/forums/diary/Petya+I+hardly+know+ya+an+ISC+update+on+the+20170627+ransomware+outbreak/22566/">https://isc.sans.edu/forums/diary/Petya+I+hardly+know+ya+an+ISC+update+on+the+20170627+ransomware+outbreak/22566/</a><br/>
Ubuntu systemd Vulnerability<br/>
<a href="https://www.ubuntu.com/usn/usn-3341-1/">https://www.ubuntu.com/usn/usn-3341-1/</a><br/>
Microsoft Will Include EMET in Windows 10<br/>
<a href="https://blogs.technet.microsoft.com/mmpc/2017/06/27/whats-new-in-windows-defender-atp-fall-creators-update/">https://blogs.technet.microsoft.com/mmpc/2017/06/27/whats-new-in-windows-defender-atp-fall-creators-update/</a><br/>
BGB Attacks Against Bitcoin<br/>
<a href="https://blog.acolyer.org/2017/06/27/hijacking-bitcoin-routing-attacks-on-cryptocurrencies/">https://blog.acolyer.org/2017/06/27/hijacking-bitcoin-routing-attacks-on-cryptocurrencies/</a><br/>
]]></description>
<itunes:duration>5:37</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5564" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5562</itunes:episode>
<itunes:subtitle>Petya/Goldeneye Variant Makes the Rounds 
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
Petya/Goldeneye Variant Makes the Rounds 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5562.mp3" length="4316672" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5562.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5562</link>
<pubDate>Wed, 28 Jun 2017 00:00:08 GMT</pubDate>
<description><![CDATA[Petya/Goldeneye Variant Makes the Rounds<br/>
 <a href="https://isc.sans.edu/forums/diary/Checking+out+the+new+Petya+variant/22562/">https://isc.sans.edu/forums/diary/Checking+out+the+new+Petya+variant/22562/</a><br/>
]]></description>
<itunes:duration>5:07</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5562" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5560</itunes:episode>
<itunes:subtitle>BitTorrent Sync 2.0 Forensics;
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
BitTorrent Sync 2.0 Forensics;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5560.mp3" length="5286575" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5560.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5560</link>
<pubDate>Tue, 27 Jun 2017 00:15:04 GMT</pubDate>
<description><![CDATA[Investigation of BitTorrent Sync (v.2.0) as a P2P Cloud (Part 1)<br/>
 <a href="https://isc.sans.edu/forums/diary/Investigation+of+BitTorrent+Sync+v20+as+a+P2P+Cloud+Part+1/22554/">https://isc.sans.edu/forums/diary/Investigation+of+BitTorrent+Sync+v20+as+a+P2P+Cloud+Part+1/22554/</a><br/>
Ransomware Payment Spurres More DDoS Ransomware Attacks<br/>
 <a href="https://www.bleepingcomputer.com/news/security/-1-million-ransomware-payment-has-spurred-new-ddos-for-bitcoin-attacks/">https://www.bleepingcomputer.com/news/security/-1-million-ransomware-payment-has-spurred-new-ddos-for-bitcoin-attacks/</a><br/>
Speed Trap Cameras in Australia Infected with WannaCrypt<br/>
 <a href="http://www.camerassavelives.vic.gov.au/utility/latest+news/investigation+underway+into+cameras+affected+by+software+virus">http://www.camerassavelives.vic.gov.au/utility/latest+news/investigation+underway+into+cameras+affected+by+software+virus</a><br/>
More Vulnerablities in Windows Defender<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1282&desc=2">https://bugs.chromium.org/p/project-zero/issues/detail?id=1282&desc=2</a><br/>
npm Developer Accounts Reset After Password Reuse Discovery<br/>
 <a href="https://github.com/ChALkeR/notes/blob/master/Gathering-weak-npm-credentials.md">https://github.com/ChALkeR/notes/blob/master/Gathering-weak-npm-credentials.md</a><br/>
]]></description>
<itunes:duration>6:16</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5560" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 26th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5558</itunes:episode>
<itunes:subtitle>DDOS Extortion; Laptop Travel; MSFT Leaks Code; Locky back for XP
</itunes:subtitle>
<itunes:summary>Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 
DDOS Extortion; Laptop Travel; MSFT Leaks Code; Locky back for XP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5558.mp3" length="5565181" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5558.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5558</link>
<pubDate>Sun, 25 Jun 2017 22:50:03 GMT</pubDate>
<description><![CDATA[Fake DDoS Extortions Continue<br/>
<a href="https://isc.sans.edu/forums/diary/Fake+DDoS+Extortions+Continue+Please+Forward+Us+Any+Threats+You+Have+Received/22550/">https://isc.sans.edu/forums/diary/Fake+DDoS+Extortions+Continue+Please+Forward+Us+Any+Threats+You+Have+Received/22550/</a><br/>
Traveling with a Laptop<br/>
<a href="https://isc.sans.edu/forums/diary/Traveling+with+a+Laptop+Surviving+a+Laptop+Ban+How+to+Let+Go+of+Precious/22462/">https://isc.sans.edu/forums/diary/Traveling+with+a+Laptop+Surviving+a+Laptop+Ban+How+to+Let+Go+of+Precious/22462/</a><br/>
Side Channel Attacks on the Cheap<br/>
 <a href="https://www.fox-it.com/nl/wp-content/uploads/sites/12/Tempest_attacks_against_AES.pdf">https://www.fox-it.com/nl/wp-content/uploads/sites/12/Tempest_attacks_against_AES.pdf</a><br/>
Latest Locky Variant Hunting Down Windows XP Users<br/>
 <a href="http://blog.talosintelligence.com/2017/06/necurs-locky-campaign.html">http://blog.talosintelligence.com/2017/06/necurs-locky-campaign.html</a><br/>
Windows Beta Builts and Source Code Leaked<br/>
 <a href="http://www.theregister.co.uk/2017/06/23/windows_10_leak/">http://www.theregister.co.uk/2017/06/23/windows_10_leak/</a><br/>
]]></description>
<itunes:duration>6:36</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5558" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber security, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 23rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5556</itunes:episode>
<itunes:subtitle>Obfuscation Techniques;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Obfuscation Techniques;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5556.mp3" length="10024718" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5556.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5556</link>
<pubDate>Fri, 23 Jun 2017 01:35:03 GMT</pubDate>
<description><![CDATA[<br/>
Obfuscating Without XOR<br/>
 <a href="https://isc.sans.edu/forums/diary/Obfuscating+without+XOR/22544/">https://isc.sans.edu/forums/diary/Obfuscating+without+XOR/22544/</a><br/>
Airbnb OAUTH Token Theft<br/>
 <a href="https://www.arneswinnen.net/2017/06/authentication-bypass-on-airbnb-via-oauth-tokens-theft/">https://www.arneswinnen.net/2017/06/authentication-bypass-on-airbnb-via-oauth-tokens-theft/</a><br/>
Critical Drupal Vulnerablity <br/>
 <a href="https://www.drupal.org/SA-CORE-2017-003">https://www.drupal.org/SA-CORE-2017-003</a><br/>
Auditing Docker Containers<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/auditing/checklist-audit-docker-containers-37437">https://www.sans.org/reading-room/whitepapers/auditing/checklist-audit-docker-containers-37437</a><br/>
]]></description>
<itunes:duration>11:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5556" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5554</itunes:episode>
<itunes:subtitle>OpenVPN Post-Audit Vulnerabilities; WannaCry Aftershocks
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
OpenVPN Post-Audit Vulnerabilities; WannaCry Aftershocks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5554.mp3" length="4214699" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5554.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5554</link>
<pubDate>Thu, 22 Jun 2017 11:17:13 GMT</pubDate>
<description><![CDATA[New Vulnerabilities Found in OpenVPN<br/>
 <a href="https://guidovranken.wordpress.com/2017/06/21/the-openvpn-post-audit-bug-bonanza/">https://guidovranken.wordpress.com/2017/06/21/the-openvpn-post-audit-bug-bonanza/</a><br/>
RAR Unpack Vulnerability Affects BitDefender<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1278&desc=6">https://bugs.chromium.org/p/project-zero/issues/detail?id=1278&desc=6</a><br/>
Honda Plant Shuts Down Over Wannacry<br/>
 <a href="https://www.bleepingcomputer.com/news/security/one-month-later-wannacry-ransomware-is-still-shutting-down-factories/">https://www.bleepingcomputer.com/news/security/one-month-later-wannacry-ransomware-is-still-shutting-down-factories/</a><br/>
]]></description>
<itunes:duration>5:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5554" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5552</itunes:episode>
<itunes:subtitle>Cisco Ships Private Key in Video Player; Windows Error Reports;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Cisco Ships Private Key in Video Player; Windows Error Reports;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5552.mp3" length="4951372" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5552.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5552</link>
<pubDate>Wed, 21 Jun 2017 01:40:02 GMT</pubDate>
<description><![CDATA[Cisco Ships Private Key For drmlocal.cisco.com With Video Player<br/>
 <a href="https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/T6emeoE-lCU">https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/T6emeoE-lCU</a><br/>
Windows Error Reporting: DFIR Benefits and Privacy Concerns<br/>
<a href="https://isc.sans.edu/forums/diary/Windows+Error+Reporting+DFIR+Benefits+and+Privacy+Concerns/22536/">https://isc.sans.edu/forums/diary/Windows+Error+Reporting+DFIR+Benefits+and+Privacy+Concerns/22536/</a><br/>
Deteting Memory Curruption in glibc<br/>
 <a href="https://github.com/DhavalKapil/libdheap">https://github.com/DhavalKapil/libdheap</a><br/>
Let's Encrypt ACME Protocol To Become IETF Standard<br/>
 <a href="https://tools.ietf.org/html/draft-ietf-acme-acme-06">https://tools.ietf.org/html/draft-ietf-acme-acme-06</a><br/>
Microsoft Publishes Analysis of NSA Exploits<br/>
 <a href="https://blogs.technet.microsoft.com/mmpc/2017/06/16/analysis-of-the-shadow-brokers-release-and-mitigation-with-windows-10-virtualization-based-security/">https://blogs.technet.microsoft.com/mmpc/2017/06/16/analysis-of-the-shadow-brokers-release-and-mitigation-with-windows-10-virtualization-based-security/</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5552" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5550</itunes:episode>
<itunes:subtitle>Stack Clash Vulnerablitiy; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Stack Clash Vulnerablitiy; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5550.mp3" length="6156512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5550.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5550</link>
<pubDate>Tue, 20 Jun 2017 00:45:04 GMT</pubDate>
<description><![CDATA[Stack Clash Vulnerability Affects Various Unix Based Operating Systems<br/>
 <a href="https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt">https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt</a><br/>
Separation Of Duties / Malicious Administrators<br/>
 <a href="https://isc.sans.edu/forums/diary/As+Your+Admin+Walks+Out+the+Door/22530/">https://isc.sans.edu/forums/diary/As+Your+Admin+Walks+Out+the+Door/22530/</a><br/>
Progress in Sattelite Based Quantum Cryptography<br/>
 <a href="https://www.wired.com/story/chinese-satellite-relays-a-quantum-signal-between-cities/">https://www.wired.com/story/chinese-satellite-relays-a-quantum-signal-between-cities/</a><br/>
 <a href="https://www.helpnetsecurity.com/2017/06/19/extremely-secure-data-encryption/">https://www.helpnetsecurity.com/2017/06/19/extremely-secure-data-encryption/</a><br/>
Women Connect Event Minneapolis: <br/>
<a href="https://www.sans.org/event/minneapolis-2017/bonus-sessions/12162">https://www.sans.org/event/minneapolis-2017/bonus-sessions/12162</a><br/>
]]></description>
<itunes:duration>7:19</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5550" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5548</itunes:episode>
<itunes:subtitle>Port 83 Uptick; WINS DoS Not Fixed; SMB1 will be turned off
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Port 83 Uptick; WINS DoS Not Fixed; SMB1 will be turned off
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5548.mp3" length="4527438" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5548.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5548</link>
<pubDate>Mon, 19 Jun 2017 02:10:02 GMT</pubDate>
<description><![CDATA[Uptick in Port 83 Traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+going+on+with+Port+83/22524/">https://isc.sans.edu/forums/diary/What+is+going+on+with+Port+83/22524/</a><br/>
WINS DoS Vulnerability will not be fixed by Microsoft<br/>
 <a href="https://blog.fortinet.com/2017/06/14/wins-server-remote-memory-corruption-vulnerability-in-microsoft-windows-server">https://blog.fortinet.com/2017/06/14/wins-server-remote-memory-corruption-vulnerability-in-microsoft-windows-server</a><br/>
Microsoft to Release Patch to Turn off SMB1<br/>
 <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-to-disable-smbv1-in-windows-starting-this-fall/">https://www.bleepingcomputer.com/news/microsoft/microsoft-to-disable-smbv1-in-windows-starting-this-fall/</a><br/>
UK Hacker Stole Personell Data For US Military Sattelite Network<br/>
 <a href="https://public-newsroom-nca-01.azurewebsites.net/news/hacker-stole-satellite-data-from-us-department-of-defence">https://public-newsroom-nca-01.azurewebsites.net/news/hacker-stole-satellite-data-from-us-department-of-defence</a><br/>
Sophos Web Appliance Will Now Update via https<br/>
 <a href="https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-v4-3-2---security-and-defect-fix-rollup">https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-v4-3-2---security-and-defect-fix-rollup</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5548" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5546</itunes:episode>
<itunes:subtitle>Cherry Blossom Wifi Hacking; DVR Vulns; MSFT Defender Vulns
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Cherry Blossom Wifi Hacking; DVR Vulns; MSFT Defender Vulns
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5546.mp3" length="15255974" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5546.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5546</link>
<pubDate>Fri, 16 Jun 2017 00:05:03 GMT</pubDate>
<description><![CDATA[WikiLeaks Releases Documents About Cherry Blossom Wifi Hacking Toolkit<br/>
 <a href="https://wikileaks.org/vault7/#Cherry%20Blossom">https://wikileaks.org/vault7/#Cherry%20Blossom</a><br/>
More DVR Vulnerabilities<br/>
 <a href="https://www.pentestpartners.com/security-blog/what-did-mirai-miss-making-a-better-bigger-botnet/">https://www.pentestpartners.com/security-blog/what-did-mirai-miss-making-a-better-bigger-botnet/</a><br/>
More Microsoft Windows Defender Vulnerabilities<br/>
 <a href="http://www.theregister.co.uk/2017/06/15/microsoft_how_about_sandboxing_windows_defenders_engine/">http://www.theregister.co.uk/2017/06/15/microsoft_how_about_sandboxing_windows_defenders_engine/</a><br/>
  <br/>
Decryption Utility For Jaff Crypto Ransomware<br/>
 <a href="https://noransom.kaspersky.com">https://noransom.kaspersky.com</a><br/>
Preston Ackerman: Two Factor Authentication by Home End-Users<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/authentication/impediments-adoption-two-factor-authentication-home-end-users-37607">https://www.sans.org/reading-room/whitepapers/authentication/impediments-adoption-two-factor-authentication-home-end-users-37607</a><br/>
 <br/>
]]></description>
<itunes:duration>18:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5546" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5544</itunes:episode>
<itunes:subtitle>Malicious Headphones; Systemd Odd Defaults; VoLTE Vulnerabilities;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Malicious Headphones; Systemd Odd Defaults; VoLTE Vulnerabilities;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5544.mp3" length="5410075" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5544.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5544</link>
<pubDate>Wed, 14 Jun 2017 23:45:03 GMT</pubDate>
<description><![CDATA[Systemd Odd Defaults<br/>
 <a href="https://isc.sans.edu/forums/diary/Systemd+Could+Fallback+to+Google+DNS/22516/">https://isc.sans.edu/forums/diary/Systemd+Could+Fallback+to+Google+DNS/22516/</a><br/>
Voice over LTE Vulnerabilities<br/>
 <a href="https://www.sstic.org/media/SSTIC2017/SSTIC-actes/remote_geolocation_and_tracing_of_subscribers_usin/SSTIC2017-Article-remote_geolocation_and_tracing_of_subscribers_using_4g_volte_android_phone-le-moal_ventuzelo_coudray.pdf">https://www.sstic.org/media/SSTIC2017/SSTIC-actes/remote_geolocation_and_tracing_of_subscribers_usin/SSTIC2017-Article-remote_geolocation_and_tracing_of_subscribers_using_4g_volte_android_phone-le-moal_ventuzelo_coudray.pdf</a><br/>
Tails 3.0 Released<br/>
 <a href="https://tails.boum.org/install/download/index.en.html">https://tails.boum.org/install/download/index.en.html</a><br/>
Nexus 9 Headphone Jack Vulnerability<br/>
 <a href="https://alephsecurity.com/2017/06/13/nexus9-ephemeral-fiq/">https://alephsecurity.com/2017/06/13/nexus9-ephemeral-fiq/</a><br/>
]]></description>
<itunes:duration>6:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5544" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5542</itunes:episode>
<itunes:subtitle>MSFT Patches Remaining #NSA Exploits (incl. Win XP); North Korea Builds DDoS Botnet
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
MSFT Patches Remaining #NSA Exploits (incl. Win XP); North Korea Builds DDoS Botnet
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5542.mp3" length="5458831" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5542.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5542</link>
<pubDate>Wed, 14 Jun 2017 01:45:04 GMT</pubDate>
<description><![CDATA[MSFT June Patchday Fixes Remaining Known NSA Vulnerabilities<br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+and+Adobe+June+2017+Patch+Tuesday+Two+Exploited+Vulnerabilities+Patched/22512/">https://isc.sans.edu/forums/diary/Microsoft+and+Adobe+June+2017+Patch+Tuesday+Two+Exploited+Vulnerabilities+Patched/22512/</a> <br/>
North Korea Building DDoS Botnet<br/>
 <a href="https://www.us-cert.gov/ncas/alerts/TA17-164A">https://www.us-cert.gov/ncas/alerts/TA17-164A</a><br/>
]]></description>
<itunes:duration>6:29</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5542" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5540</itunes:episode>
<itunes:subtitle>Industroyer/ #CrashOverride Power System Malware; Mac Spyware 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Industroyer/ #CrashOverride Power System Malware; Mac Spyware 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5540.mp3" length="4974354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5540.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5540</link>
<pubDate>Tue, 13 Jun 2017 00:15:02 GMT</pubDate>
<description><![CDATA[Industropyer / CrashOverride Malware Analysis From Power System Attacks<br/>
<a href="https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/">https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/</a><br/>
<a href="https://dragos.com/blog/crashoverride/CrashOverride-01.pdf">https://dragos.com/blog/crashoverride/CrashOverride-01.pdf</a><br/>
MacSpy Spyware As A Service For Macs<br/>
<a href="http://www.alienvault.com/blogs/labs-research/macspy-os-x-rat-as-a-service">http://www.alienvault.com/blogs/labs-research/macspy-os-x-rat-as-a-service</a><br/>
VolUtility Memory Analysis Made Easy<br/>
<a href="https://isc.sans.edu/forums/diary/An+Introduction+to+VolUtility/22508/">https://isc.sans.edu/forums/diary/An+Introduction+to+VolUtility/22508/</a><br/>
Google News Abused For Spam<br/>
<a href="http://www.theregister.co.uk/2017/06/12/googles_news_algorithm_serves_up_penis_pills_for_all/">http://www.theregister.co.uk/2017/06/12/googles_news_algorithm_serves_up_penis_pills_for_all/</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5540" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5538</itunes:episode>
<itunes:subtitle>SAMBA Vuln. Exploited;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
SAMBA Vuln. Exploited;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5538.mp3" length="4986868" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5538.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5538</link>
<pubDate>Mon, 12 Jun 2017 00:20:03 GMT</pubDate>
<description><![CDATA[SAMBA Vulnerability Exploited To Install Bitcoin Miners<br/>
 <a href="https://securelist.com/78674/sambacry-is-coming/">https://securelist.com/78674/sambacry-is-coming/</a><br/>
Intel's AMT Technology Used For Covert Channel<br/>
 <a href="https://blogs.technet.microsoft.com/mmpc/2017/06/07/platinum-continues-to-evolve-find-ways-to-maintain-invisibility/">https://blogs.technet.microsoft.com/mmpc/2017/06/07/platinum-continues-to-evolve-find-ways-to-maintain-invisibility/</a><br/>
Broadcom Vulnerablities to be Announced<br/>
 <a href="https://www.blackhat.com/us-17/briefings.html#broadpwn-remotely-compromising-android-and-ios-via-a-bug-in-broadcoms-wi-fi-chipsets">https://www.blackhat.com/us-17/briefings.html#broadpwn-remotely-compromising-android-and-ios-via-a-bug-in-broadcoms-wi-fi-chipsets</a><br/>
Release Lag In National Vulnerablity Database<br/>
 <a href="https://www.recordedfuture.com/vulnerability-disclosure-delay/">https://www.recordedfuture.com/vulnerability-disclosure-delay/</a><br/>
]]></description>
<itunes:duration>5:55</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5538" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 9th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5536</itunes:episode>
<itunes:subtitle>Cisco DCNM Vulnerabilities; Peoplesoft Default Accts; Camera Vulns;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Cisco DCNM Vulnerabilities; Peoplesoft Default Accts; Camera Vulns;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5536.mp3" length="10545590" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5536.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5536</link>
<pubDate>Fri, 09 Jun 2017 01:25:03 GMT</pubDate>
<description><![CDATA[Cisco Prime Data Center Network Manager Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-dcnm1">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-dcnm1</a><br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-dcnm2">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170607-dcnm2</a><br/>
Oracle Peoplesoft Default Accounts<br/>
 <a href="https://erpscan.com/press-center/blog/peoplesoft-default-accounts/">https://erpscan.com/press-center/blog/peoplesoft-default-accounts/</a><br/>
FOSCAM Camera Default Passwords and Other Vulnerabilities<br/>
 <a href="http://images.news.f-secure.com/Web/FSecure/%7B43df9e0d-20a8-404a-86d0-70dcca00b6e5%7D_vulnerabilities-in-foscam-IP-cameras_report.pdf">http://images.news.f-secure.com/Web/FSecure/%7B43df9e0d-20a8-404a-86d0-70dcca00b6e5%7D_vulnerabilities-in-foscam-IP-cameras_report.pdf</a><br/>
Android Malware With Code Injections<br/>
 <a href="https://securelist.com/78648/dvmap-the-first-android-malware-with-code-injection/">https://securelist.com/78648/dvmap-the-first-android-malware-with-code-injection/</a><br/>
STI Student John Dittmer: Legal Implication of Vulnerablity Scans<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/legal/minimizing-legal-risk-cybersecurity-scanning-tools-37522">https://www.sans.org/reading-room/whitepapers/legal/minimizing-legal-risk-cybersecurity-scanning-tools-37522</a><br/>
]]></description>
<itunes:duration>12:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5536" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5534</itunes:episode>
<itunes:subtitle>RevenueHits and Deceptive Ads; Instagram Covert Channel
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
RevenueHits and Deceptive Ads; Instagram Covert Channel
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5534.mp3" length="5079609" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5534.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5534</link>
<pubDate>Thu, 08 Jun 2017 00:35:02 GMT</pubDate>
<description><![CDATA[Deceptive Advertisements: What They Do And Where They Come From<br/>
 <a href="https://isc.sans.edu/forums/diary/Deceptive+Advertisements+What+they+do+and+where+they+come+from/22494/">https://isc.sans.edu/forums/diary/Deceptive+Advertisements+What+they+do+and+where+they+come+from/22494/</a><br/>
Instagram as Covert Channel<br/>
 <a href="https://www.welivesecurity.com/2017/06/06/turlas-watering-hole-campaign-updated-firefox-extension-abusing-instagram/">https://www.welivesecurity.com/2017/06/06/turlas-watering-hole-campaign-updated-firefox-extension-abusing-instagram/</a><br/>
Domain Shadowing Used in Rik Exploit Kit<br/>
 <a href="https://blogs.rsa.com/shadowfall/">https://blogs.rsa.com/shadowfall/</a><br/>
]]></description>
<itunes:duration>6:02</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5534" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, June 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5532</itunes:episode>
<itunes:subtitle>Finding XOR Keys Part 2; Instagram Not Using TLS; Printer Dots Lead to Arrest
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Finding XOR Keys Part 2; Instagram Not Using TLS; Printer Dots Lead to Arrest
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5532.mp3" length="4612678" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5532.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5532</link>
<pubDate>Tue, 06 Jun 2017 23:55:02 GMT</pubDate>
<description><![CDATA[Finding XOR Keys Part 2<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+and+XOR+Part+2/22490/">https://isc.sans.edu/forums/diary/Malware+and+XOR+Part+2/22490/</a><br/>
Instagram Stories Not Using TLS<br/>
 <a href="https://vvyper.com/2017/05/22/instagram-stories-ssl/">https://vvyper.com/2017/05/22/instagram-stories-ssl/</a><br/>
Printer "Dots" May Have Lead to Arrest of NSA Contractor<br/>
 <a href="http://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html#.WTc9SMbMyRt">http://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html#.WTc9SMbMyRt</a><br/>
Exfiltrating Data via Blinking LED<br/>
 <a href="https://arxiv.org/abs/1706.01140">https://arxiv.org/abs/1706.01140</a><br/>
]]></description>
<itunes:duration>5:28</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5532" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, June 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5530</itunes:episode>
<itunes:subtitle>Finding XOR Keys; Maping IMSI Catchers; TLD Hijacking
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Finding XOR Keys; Maping IMSI Catchers; TLD Hijacking
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5530.mp3" length="5903241" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5530.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5530</link>
<pubDate>Tue, 06 Jun 2017 00:35:03 GMT</pubDate>
<description><![CDATA[Finding XOR Keys Used To Encode Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+and+XOR+Part+1/22486/">https://isc.sans.edu/forums/diary/Malware+and+XOR+Part+1/22486/</a><br/>
Citywide IMSI Discovery<br/>
 <a href="https://seaglass.cs.washington.edu">https://seaglass.cs.washington.edu</a><br/>
Hijacking Country Level Domains<br/>
 <a href="https://thehackerblog.com/the-journey-to-hijacking-a-countrys-tld-the-hidden-risks-of-domain-extensions/index.html">https://thehackerblog.com/the-journey-to-hijacking-a-countrys-tld-the-hidden-risks-of-domain-extensions/index.html</a><br/>
]]></description>
<itunes:duration>7:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5530" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, June 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5528</itunes:episode>
<itunes:subtitle>Bitcoin Phishing; Powerpoint Mouseover; Pandemic; Mozillay moving from OCSP
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Bitcoin Phishing; Powerpoint Mouseover; Pandemic; Mozillay moving from OCSP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5528.mp3" length="6377958" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5528.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5528</link>
<pubDate>Mon, 05 Jun 2017 00:25:03 GMT</pubDate>
<description><![CDATA[Phishing Campaigns for Bitcoin<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+Campaigns+Follow+Trends/22482/">https://isc.sans.edu/forums/diary/Phishing+Campaigns+Follow+Trends/22482/</a><br/>
Mouseover May Trigger Powerpoint Macro<br/>
 <a href="https://www.dodgethissecurity.com/2017/06/02/new-powerpoint-mouseover-based-downloader-analysis-results/">https://www.dodgethissecurity.com/2017/06/02/new-powerpoint-mouseover-based-downloader-analysis-results/</a><br/>
Vault 7 "Pandemic" Tool<br/>
 <a href="https://wikileaks.org/vault7/document/Pandemic-1_1-S-NF/Pandemic-1_1-S-NF.pdf">https://wikileaks.org/vault7/document/Pandemic-1_1-S-NF/Pandemic-1_1-S-NF.pdf</a><br/>
Mozilla Considering Move Away From OCSP<br/>
 <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1366100">https://bugzilla.mozilla.org/show_bug.cgi?id=1366100</a><br/>
Defending Web Application Security Minneapolis<br/>
 <a href="https://www.sans.org/event/minneapolis-2017">https://www.sans.org/event/minneapolis-2017</a><br/>
Intrusion Detection in Depth Columbia MD<br/>
 <a href="https://www.sans.org/event/columbia-2017/course/intrusion-detection-in-depth">https://www.sans.org/event/columbia-2017/course/intrusion-detection-in-depth</a><br/>
]]></description>
<itunes:duration>7:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5528" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, June 2nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5526</itunes:episode>
<itunes:subtitle>Dangerous Invites; onelogin breach; Google AMP Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Dangerous Invites; onelogin breach; Google AMP Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5526.mp3" length="9079642" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5526.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5526</link>
<pubDate>Fri, 02 Jun 2017 00:05:02 GMT</pubDate>
<description><![CDATA[Sharing Private Data With Webcast Invitations<br/>
 <a href="https://isc.sans.edu/forums/diary/Sharing+Private+Data+with+Webcast+Invitations/22478/">https://isc.sans.edu/forums/diary/Sharing+Private+Data+with+Webcast+Invitations/22478/</a><br/>
onelogin breach<br/>
 <a href="https://www.onelogin.com/blog/may-31-2017-security-incident">https://www.onelogin.com/blog/may-31-2017-security-incident</a><br/>
Google AMP Phishing<br/>
 <a href="https://citizenlab.org/2017/05/tainted-leaks-disinformation-phish/">https://citizenlab.org/2017/05/tainted-leaks-disinformation-phish/</a><br/>
STI Student Paper: Kevin Kelly Tesla Crypt<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/bestprac/indicators-compromise-teslacrypt-malware-37622">https://www.sans.org/reading-room/whitepapers/bestprac/indicators-compromise-teslacrypt-malware-37622</a><br/>
]]></description>
<itunes:duration>10:47</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5526" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, June 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5524</itunes:episode>
<itunes:subtitle>ACH Part 2; Wcry Craches Win XP; Jeep Dealer DB Used to Steal Cars
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
ACH Part 2; Wcry Craches Win XP; Jeep Dealer DB Used to Steal Cars
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5524.mp3" length="5191878" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5524.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5524</link>
<pubDate>Thu, 01 Jun 2017 01:40:03 GMT</pubDate>
<description><![CDATA[Analysis of Competing Hypotheses, WCry and Lazarus <br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+Competing+Hypotheses+WCry+and+Lazarus+ACH+part+2/22470/">https://isc.sans.edu/forums/diary/Analysis+of+Competing+Hypotheses+WCry+and+Lazarus+ACH+part+2/22470/</a><br/>
Windows XP Not Stable Enough for WannaCry <br/>
 <a href="https://blog.kryptoslogic.com/malware/2017/05/29/two-weeks-later.html">https://blog.kryptoslogic.com/malware/2017/05/29/two-weeks-later.html</a><br/>
Mexican Biker Gang Uses Jeep Database to Steal Car<br/>
 <a href="https://regmedia.co.uk/2017/05/31/indictment5_30.pdf">https://regmedia.co.uk/2017/05/31/indictment5_30.pdf</a><br/>
Dangers of Public WAS Snapshots<br/>
 <a href="https://www.nvteh.com/news/problems-with-public-ebs-snapshots">https://www.nvteh.com/news/problems-with-public-ebs-snapshots</a><br/>
]]></description>
<itunes:duration>6:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5524" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 31st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5522</itunes:episode>
<itunes:subtitle>FreeRADIUS Vulnerability; MSFT Malware Protection Updates;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
FreeRADIUS Vulnerability; MSFT Malware Protection Updates;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5522.mp3" length="5510587" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5522.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5522</link>
<pubDate>Wed, 31 May 2017 11:23:39 GMT</pubDate>
<description><![CDATA[FreeRADIUS Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/FreeRadius+Authentication+Bypass/22466/">https://isc.sans.edu/forums/diary/FreeRadius+Authentication+Bypass/22466/</a><br/>
Microsoft Malware Protection Engine Update<br/>
 <a href="http://seclists.org/microsoft/2017/q2/8">http://seclists.org/microsoft/2017/q2/8</a><br/>
Chrome UI Bug May Allow Unnoticed Recording<br/>
 <a href="https://medium.com/@barzik/the-new-html5-video-audio-api-has-privacy-issues-on-desktop-chrome-5832c99c7659">https://medium.com/@barzik/the-new-html5-video-audio-api-has-privacy-issues-on-desktop-chrome-5832c99c7659</a><br/>
AWS Auditing Tools<br/>
 <a href="https://summitroute.com/blog/2017/05/30/free_tools_for_auditing_the_security_of_an_aws_account/">https://summitroute.com/blog/2017/05/30/free_tools_for_auditing_the_security_of_an_aws_account/</a><br/>
SANS Social Denver June 14th <br/>
 <a href="https://pages.sans.org/denversocial">https://pages.sans.org/denversocial</a><br/>
]]></description>
<itunes:duration>6:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5522" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 30th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5520</itunes:episode>
<itunes:subtitle>Microsoft $MFT DoS Exploit; SMTP Proxy/Split Tunnel Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Microsoft $MFT DoS Exploit; SMTP Proxy/Split Tunnel Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5520.mp3" length="6034111" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5520.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5520</link>
<pubDate>Tue, 30 May 2017 01:00:07 GMT</pubDate>
<description><![CDATA[Analysis of Competing Hypotheses<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+Competing+Hypotheses+ACH+part+1/22460/">https://isc.sans.edu/forums/diary/Analysis+of+Competing+Hypotheses+ACH+part+1/22460/</a><br/>
Microsoft Master File Table BSOD Exploit<br/>
 <a href="http://www.theregister.co.uk/2017/05/29/microsoft_master_file_table_bug_exploited_to_bsod_windows_7_81/">http://www.theregister.co.uk/2017/05/29/microsoft_master_file_table_bug_exploited_to_bsod_windows_7_81/</a><br/>
SMTP Split Tunnel / Transparent Proxy Exploit<br/>
 <a href="https://blog.securolytics.io/2017/05/split-tunnel-smtp-exploit-explained/">https://blog.securolytics.io/2017/05/split-tunnel-smtp-exploit-explained/</a><br/>
]]></description>
<itunes:duration>7:10</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5520" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 26th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5518</itunes:episode>
<itunes:subtitle>Samba Remote Code Exec; Pacemaker Vuln; Patching takes down AU Hospitals
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Samba Remote Code Exec; Pacemaker Vuln; Patching takes down AU Hospitals
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5518.mp3" length="11384468" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5518.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5518</link>
<pubDate>Thu, 25 May 2017 23:10:04 GMT</pubDate>
<description><![CDATA[Samba Remote Code Execution Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/Critical+Vulnerability+in+Samba+from+350+onwards/22452/">https://isc.sans.edu/forums/diary/Critical+Vulnerability+in+Samba+from+350+onwards/22452/</a><br/>
Pacemaker Vulnerabilities<br/>
 <a href="http://blog.whitescope.io/2017/05/understanding-pacemaker-systems.html">http://blog.whitescope.io/2017/05/understanding-pacemaker-systems.html</a><br/>
Patching May have Affected Access to Australian Health Systems<br/>
 <a href="http://www.cairnspost.com.au/news/cairns-hospital-suffers-software-catastrophe-with-possible-loss-of-patient-data/news-story/c828de3f4a0f73132ec3d19284cbae88">http://www.cairnspost.com.au/news/cairns-hospital-suffers-software-catastrophe-with-possible-loss-of-patient-data/news-story/c828de3f4a0f73132ec3d19284cbae88</a><br/>
]]></description>
<itunes:duration>13:32</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5518" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 25th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5516</itunes:episode>
<itunes:subtitle>Jaff Ransomware Makeover; OpenVPN Access Server Vuln; Credential Dump
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Jaff Ransomware Makeover; OpenVPN Access Server Vuln; Credential Dump
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5516.mp3" length="5115979" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5516.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5516</link>
<pubDate>Thu, 25 May 2017 00:00:09 GMT</pubDate>
<description><![CDATA[Jaff Ransomware Gets a Makeover<br/>
 <a href="https://isc.sans.edu/forums/diary/Jaff+ransomware+gets+a+makeover/22446/">https://isc.sans.edu/forums/diary/Jaff+ransomware+gets+a+makeover/22446/</a><br/>
OpenVPN Access Server Vulnerability<br/>
 <a href="http://seclists.org/oss-sec/2017/q2/332">http://seclists.org/oss-sec/2017/q2/332</a><br/>
Large Credential Dumps Used in Password Brute Forcing Attacks<br/>
 <a href="http://info.digitalshadows.com/AccountTakeover-WhitePapersPage_Registration.html">http://info.digitalshadows.com/AccountTakeover-WhitePapersPage_Registration.html</a><br/>
]]></description>
<itunes:duration>6:04</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5516" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5514</itunes:episode>
<itunes:subtitle>Subtitle File Vulnerabilities; Iris Scanner Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information and cyber security. 
Subtitle File Vulnerabilities; Iris Scanner Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5514.mp3" length="4685145" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5514.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5514</link>
<pubDate>Wed, 24 May 2017 00:25:03 GMT</pubDate>
<description><![CDATA[Multiple Video Players are Vulnerable to Code Execution via Subtitle Files<br/>
 <a href="http://blog.checkpoint.com/2017/05/23/hacked-in-translation/">http://blog.checkpoint.com/2017/05/23/hacked-in-translation/</a><br/>
Samsung Galaxy S8 Iris Scanner Bypass<br/>
 <a href="https://www.ccc.de/en/updates/2017/iriden">https://www.ccc.de/en/updates/2017/iriden</a><br/>
Verizon XSS Flaw in Web Messaging Application<br/>
 <a href="https://randywestergren.com/xss-sms-hacking-text-messages-verizon-messages">https://randywestergren.com/xss-sms-hacking-text-messages-verizon-messages</a><br/>
]]></description>
<itunes:duration>5:33</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5514" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 23rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5512</itunes:episode>
<itunes:subtitle>Uber TLS Phish; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Uber TLS Phish; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5512.mp3" length="5680638" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5512.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5512</link>
<pubDate>Tue, 23 May 2017 01:00:05 GMT</pubDate>
<description><![CDATA[Fake "Uber Disputes" Site Lures Victims With Valid TLS Certificate<br/>
 <a href="https://isc.sans.edu/forums/diary/Investigating+Sites+After+They+are+Gone+And+a+Case+of+Uber+Phishing+With+SSL/22440/">https://isc.sans.edu/forums/diary/Investigating+Sites+After+They+are+Gone+And+a+Case+of+Uber+Phishing+With+SSL/22440/</a><br/>
Let's Encrypt Outage<br/>
 <a href="http://letsencrypt.status.io/pages/history/55957a99e800baa4470002da">http://letsencrypt.status.io/pages/history/55957a99e800baa4470002da</a><br/>
 <a href="https://community.letsencrypt.org/t/ocsp-and-issuance-outage-2017-05-19/34506">https://community.letsencrypt.org/t/ocsp-and-issuance-outage-2017-05-19/34506</a><br/>
More ImageMagik Flaws<br/>
 <a href="https://scarybeastsecurity.blogspot.com/2017/05/bleed-continues-18-byte-file-14k-bounty.html">https://scarybeastsecurity.blogspot.com/2017/05/bleed-continues-18-byte-file-14k-bounty.html</a><br/>
]]></description>
<itunes:duration>6:45</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5512" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5510</itunes:episode>
<itunes:subtitle>Typosquatting (again); 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Typosquatting (again); 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5510.mp3" length="4508336" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5510.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5510</link>
<pubDate>Mon, 22 May 2017 00:20:03 GMT</pubDate>
<description><![CDATA[Typosquatting: A recent example and what to do with look alike domains<br/>
 <a href="https://isc.sans.edu/forums/diary/Typosquatting+Awareness+and+Hunting/22436/">https://isc.sans.edu/forums/diary/Typosquatting+Awareness+and+Hunting/22436/</a><br/>
Netgear Collecting Analytics Data in Recent Update<br/>
 <a href="https://kb.netgear.com/000038663/What-router-analytics-data-is-collected-and-how-is-the-data-being-used-by-NETGEAR">https://kb.netgear.com/000038663/What-router-analytics-data-is-collected-and-how-is-the-data-being-used-by-NETGEAR</a><br/>
 disable: <a href="https://kb.netgear.com/000038661/How-do-I-Enable-Disable-Router-Analytics-Data-Collection">https://kb.netgear.com/000038661/How-do-I-Enable-Disable-Router-Analytics-Data-Collection</a><br/>
WannaCry Updates<br/>
 <a href="https://venturebeat.com/2017/05/19/ransomware-wannacry-causes-fewer-tears-than-feared/">https://venturebeat.com/2017/05/19/ransomware-wannacry-causes-fewer-tears-than-feared/</a><br/>
 <br/>
LastPass Authenticator Cloud Backup<br/>
 <a href="https://blog.lastpass.com/2017/05/announcing-cloud-backup-for-lastpass-authenticator-easier-multifactor-security-for-everyone.html/">https://blog.lastpass.com/2017/05/announcing-cloud-backup-for-lastpass-authenticator-easier-multifactor-security-for-everyone.html/</a><br/>
]]></description>
<itunes:duration>5:21</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5510" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5508</itunes:episode>
<itunes:subtitle>Patch Rediscovery; WannaKey; CVE Bot
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Patch Rediscovery; WannaKey; CVE Bot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5508.mp3" length="11051597" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5508.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5508</link>
<pubDate>Fri, 19 May 2017 02:25:03 GMT</pubDate>
<description><![CDATA[Discovering Relevant CVEs with CVE Bot<br/>
 <a href="https://isc.sans.edu/forums/diary/My+Little+CVE+Bot/22432/">https://isc.sans.edu/forums/diary/My+Little+CVE+Bot/22432/</a><br/>
Probablility of Vulnerability Re-Discovery<br/>
 <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2928758">https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2928758</a><br/>
Wannakey May Recover WannaCry Keys<br/>
 <a href="https://github.com/aguinet/wannakey">https://github.com/aguinet/wannakey</a><br/>
Finding Bad With Splunk<br/>
 <a href="https://www.sans.org/reading-room/whitepapers/critical/finding-bad-splunk-3748">https://www.sans.org/reading-room/whitepapers/critical/finding-bad-splunk-3748</a><br/>
]]></description>
<itunes:duration>13:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5508" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5506</itunes:episode>
<itunes:subtitle>NIST Password Guidance; Exploiting PeopleSoft XXE; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
NIST Password Guidance; Exploiting PeopleSoft XXE; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5506.mp3" length="4579042" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5506.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5506</link>
<pubDate>Thu, 18 May 2017 04:05:03 GMT</pubDate>
<description><![CDATA[Handbreak Proton Malware Used to Steal Sourcecode<br/>
 <a href="https://panic.com/blog/stolen-source-code/">https://panic.com/blog/stolen-source-code/</a><br/>
NIST Password Guidance Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Wait+What+We+dont+have+to+change+passwords+every+90+days/22428/">https://isc.sans.edu/forums/diary/Wait+What+We+dont+have+to+change+passwords+every+90+days/22428/</a><br/>
Exploiting XXE Vulnerabilities in Peoplesoft<br/>
 <a href="https://www.ambionics.io/blog/oracle-peoplesoft-xxe-to-rce">https://www.ambionics.io/blog/oracle-peoplesoft-xxe-to-rce</a><br/>
]]></description>
<itunes:duration>5:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5506" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5504</itunes:episode>
<itunes:subtitle>DocuSign Spam; HP Updates Audio Driver; Chrome Credential Stealing
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
DocuSign Spam; HP Updates Audio Driver; Chrome Credential Stealing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5504.mp3" length="4685861" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5504.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5504</link>
<pubDate>Wed, 17 May 2017 03:10:03 GMT</pubDate>
<description><![CDATA[Docusign Breach Leads to Increase in Phishing Email<br/>
 <a href="https://trust.docusign.com/en-us/personal-safeguards/">https://trust.docusign.com/en-us/personal-safeguards/</a><br/>
HP Updates Audio Drivers (twice) to Remove Keylogger<br/>
 <a href="https://support.hp.com/us-en/document/c05519670">https://support.hp.com/us-en/document/c05519670</a><br/>
Chrome File Download Behaviour Can Lead to SMB Credential Theft<br/>
 <a href="http://defensecode.com/news_article.php?id=21">http://defensecode.com/news_article.php?id=21</a><br/>
]]></description>
<itunes:duration>5:34</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5504" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5502</itunes:episode>
<itunes:subtitle>Apple Updates Everything; OpenVPN Audit; Car Insurance Privacy Issues
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Apple Updates Everything; OpenVPN Audit; Car Insurance Privacy Issues
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5502.mp3" length="5810762" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5502.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5502</link>
<pubDate>Tue, 16 May 2017 03:10:03 GMT</pubDate>
<description><![CDATA[Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
OpenVPN Audit Results<br/>
 <a href="https://www.privateinternetaccess.com/blog/2017/05/openvpn-2-4-evaluation-summary-report/">https://www.privateinternetaccess.com/blog/2017/05/openvpn-2-4-evaluation-summary-report/</a><br/>
Italian Car Insurance Leaks User Driving Data<br/>
 <a href="https://www.andreascarpino.it/posts/how-my-car-insurance-exposed-my-position.html">https://www.andreascarpino.it/posts/how-my-car-insurance-exposed-my-position.html</a><br/>
]]></description>
<itunes:duration>6:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5502" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5500</itunes:episode>
<itunes:subtitle>WannaCry/WannaCrypt Malware Spreading Rapidly #WannaCry #WannaCrypt
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
WannaCry/WannaCrypt Malware Spreading Rapidly #WannaCry #WannaCrypt
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5500.mp3" length="6055400" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5500.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5500</link>
<pubDate>Mon, 15 May 2017 03:00:11 GMT</pubDate>
<description><![CDATA[WannaCry Malware Links<br/>
 Latest updates see <a href="https://isc.sans.edu">https://isc.sans.edu</a><br/>
 Webcast: <a href="https://www.sans.org/webcasts/special-webcast-wannacry-ransomeware-threat-105160">https://www.sans.org/webcasts/special-webcast-wannacry-ransomeware-threat-105160</a><br/>
 PowerPoint: <a href="https://isc.sans.edu/presentations/WannaCry.ppt">https://isc.sans.edu/presentations/WannaCry.ppt</a><br/>
 <br/>
]]></description>
<itunes:duration>7:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5500" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5498</itunes:episode>
<itunes:subtitle>Conexant Audio Drivers Log Keystrokes; Encase Vulnerabilty
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Conexant Audio Drivers Log Keystrokes; Encase Vulnerabilty
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5498.mp3" length="11216699" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5498.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5498</link>
<pubDate>Fri, 12 May 2017 03:20:02 GMT</pubDate>
<description><![CDATA[Conexant Audio Drivers Log Keystrokes;<br/>
 <a href="https://www.modzero.ch/modlog/archives/2017/05/11/en_keylogger_in_hewlett-packard_audio_driver/index.html">https://www.modzero.ch/modlog/archives/2017/05/11/en_keylogger_in_hewlett-packard_audio_driver/index.html</a><br/>
Rig Exploit Kit Used to Send Ramnit Trojan<br/>
 <a href="https://isc.sans.edu/forums/diary/Seamless+Campaign+using+Rig+Exploit+Kit+to+send+Ramnit+Trojan/22404/">https://isc.sans.edu/forums/diary/Seamless+Campaign+using+Rig+Exploit+Kit+to+send+Ramnit+Trojan/22404/</a><br/>
Encase Forensic Imager Exploit<br/>
 <a href="http://blog.sec-consult.com/2017/05/chainsaw-of-custody-manipulating.html">http://blog.sec-consult.com/2017/05/chainsaw-of-custody-manipulating.html</a><br/>
]]></description>
<itunes:duration>13:20</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5498" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5496</itunes:episode>
<itunes:subtitle>Review OAUTH Permissions; OS X EFI Monitor; MS Edge SOP Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Review OAUTH Permissions; OS X EFI Monitor; MS Edge SOP Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5496.mp3" length="7325692" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5496.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5496</link>
<pubDate>Thu, 11 May 2017 08:00:04 GMT</pubDate>
<description><![CDATA[How to Review OAUTH Application Permissions for Popular Sites<br/>
 <a href="https://isc.sans.edu/forums/diary/OAuth+and+Its+High+Time+for+Some+Personal+SecurityScaping+Today/22400/">https://isc.sans.edu/forums/diary/OAuth+and+Its+High+Time+for+Some+Personal+SecurityScaping+Today/22400/</a><br/>
Apple Working on Firmware Integrity Check<br/>
 <a href="http://apple.stackexchange.com/questions/282028/pop-up-firmware-changes-detected-randomly-appear">http://apple.stackexchange.com/questions/282028/pop-up-firmware-changes-detected-randomly-appear</a><br/>
Panda Mobile Anti Malware Releases Patch for Evilgrade Bug<br/>
<a href="https://www.contextis.com/resources/blog/exploiting-vulnerable-pandas/">https://www.contextis.com/resources/blog/exploiting-vulnerable-pandas/</a><br/>
ASUS RT Router Vulnerabilities<br/>
<a href="https://wwws.nightwatchcybersecurity.com/2017/05/09/multiple-vulnerabilities-in-asus-routers/">https://wwws.nightwatchcybersecurity.com/2017/05/09/multiple-vulnerabilities-in-asus-routers/</a><br/>
Microsoft Edge SOP Bypass<br/>
<a href="https://www.brokenbrowser.com/sop-bypass-uxss-stealing-credentials-pretty-fast/">https://www.brokenbrowser.com/sop-bypass-uxss-stealing-credentials-pretty-fast/</a><br/>
Linux Kernel Packet Socket Vulnerability Exploit<br/>
 <a href="https://googleprojectzero.blogspot.com/2017/05/exploiting-linux-kernel-via-packet.html">https://googleprojectzero.blogspot.com/2017/05/exploiting-linux-kernel-via-packet.html</a><br/>
]]></description>
<itunes:duration>8:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5496" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5494</itunes:episode>
<itunes:subtitle>MSFT Patch Tuesday; Cisco CMP-Telnet Patch; WolfSSL Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
MSFT Patch Tuesday; Cisco CMP-Telnet Patch; WolfSSL Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5494.mp3" length="4905599" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5494.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5494</link>
<pubDate>Tue, 09 May 2017 22:30:05 GMT</pubDate>
<description><![CDATA[Microsoft Path Tuesday Summary <br/>
 <a href="https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+and+Adobe/22396/">https://isc.sans.edu/forums/diary/Microsoft+Patch+Tuesday+and+Adobe/22396/</a><br/>
Snake For Mac OS X Included in Handbrake<br/>
 <a href="https://blog.fox-it.com/2017/05/03/snake-coming-soon-in-mac-os-x-flavour/">https://blog.fox-it.com/2017/05/03/snake-coming-soon-in-mac-os-x-flavour/</a><br/>
Cisco Patches CMP-Telnet Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp</a><br/>
WolfSSL Library X.509 Certificate Text Parsing Code Execution Vulnerability<br/>
 <a href="http://blog.talosintelligence.com/2017/05/wolfssl-x509-vuln.html">http://blog.talosintelligence.com/2017/05/wolfssl-x509-vuln.html</a><br/>
]]></description>
<itunes:duration>5:49</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5494" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 9th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5492</itunes:episode>
<itunes:subtitle>P2P Botnet Analysis; MSFT Malware Engine Patch; OS X Keychain Vuln (Patched)
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
P2P Botnet Analysis; MSFT Malware Engine Patch; OS X Keychain Vuln (Patched)
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5492.mp3" length="5553901" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5492.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5492</link>
<pubDate>Tue, 09 May 2017 03:15:03 GMT</pubDate>
<description><![CDATA[Exploring a P2P Transient Botnet - From Discovery to Enumeration<br/>
 <a href="https://isc.sans.edu/forums/diary/Exploring+a+P2P+Transient+Botnet+From+Discovery+to+Enumeration/22392/">https://isc.sans.edu/forums/diary/Exploring+a+P2P+Transient+Botnet+From+Discovery+to+Enumeration/22392/</a><br/>
Video Conversion Application Handbrake Compromised<br/>
 <a href="https://forum.handbrake.fr/viewtopic.php?f=33&t=36364">https://forum.handbrake.fr/viewtopic.php?f=33&t=36364</a><br/>
Emergency Update for Microsoft Malware Protection Engine<br/>
 <a href="https://technet.microsoft.com/en-us/library/security/4022344">https://technet.microsoft.com/en-us/library/security/4022344</a><br/>
OS X Keychain OTR Vulnerability<br/>
 <a href="https://medium.com/@longtermsec/bypassing-otr-signature-verification-to-steal-icloud-keychain-secrets-9e92ab55b605">https://medium.com/@longtermsec/bypassing-otr-signature-verification-to-steal-icloud-keychain-secrets-9e92ab55b605</a><br/>
]]></description>
<itunes:duration>6:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5492" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5490</itunes:episode>
<itunes:subtitle>Intel AMT Bug Details
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Intel AMT Bug Details
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5490.mp3" length="5121616" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5490.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5490</link>
<pubDate>Sun, 07 May 2017 23:40:03 GMT</pubDate>
<description><![CDATA[Tenable Discovers Details Regarding Intel AMT Vulnerability <br/>
 <a href="http://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability">http://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability</a><br/>
Android Apps Use Ultrasound Beacons To Track Users<br/>
 <a href="http://christian.wressnegger.info/content/projects/sidechannels/2017-eurosp.pdf">http://christian.wressnegger.info/content/projects/sidechannels/2017-eurosp.pdf</a><br/>
HTTP Headers... the Achilles' Heel of Many Applications<br/>
 <a href="https://isc.sans.edu/forums/diary/HTTP+Headers+the+Achilles+heel+of+many+applications/22382/">https://isc.sans.edu/forums/diary/HTTP+Headers+the+Achilles+heel+of+many+applications/22382/</a><br/>
]]></description>
<itunes:duration>6:05</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5490" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, May 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5488</itunes:episode>
<itunes:subtitle>Google OAUTH Spam Wrapup; Master Fingerprint Set
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Google OAUTH Spam Wrapup; Master Fingerprint Set
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5488.mp3" length="4368699" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5488.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5488</link>
<pubDate>Fri, 05 May 2017 00:50:02 GMT</pubDate>
<description><![CDATA[Google OAUTH Spam Wrapup<br/>
 <a href="https://threatpost.com/1-million-gmail-users-impacted-by-google-docs-phishing-attack/125436/">https://threatpost.com/1-million-gmail-users-impacted-by-google-docs-phishing-attack/125436/</a><br/>
Artificial Master Fingerprint Set<br/>
 <a href="https://wp.nyu.edu/memon/the-master-print/">https://wp.nyu.edu/memon/the-master-print/</a><br/>
rpcbind denial of service<br/>
 <a href="https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/">https://guidovranken.wordpress.com/2017/05/03/rpcbomb-remote-rpcbind-denial-of-service-patches/</a><br/>
Debian Discontinue FTP Support for Downloads<br/>
 <a href="https://www.debian.org/News/2017/20170425">https://www.debian.org/News/2017/20170425</a><br/>
]]></description>
<itunes:duration>5:11</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5488" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, May 4th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5486</itunes:episode>
<itunes:subtitle>Google Docs OAUTH Phish;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Google Docs OAUTH Phish;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5486.mp3" length="7096963" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5486.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5486</link>
<pubDate>Wed, 03 May 2017 22:10:03 GMT</pubDate>
<description><![CDATA[Google Docs OAUTH Phishing E-Mails<br/>
 <a href="https://isc.sans.edu/forums/diary/OAUTH+phishing+against+Google+Docs+beware/22372/">https://isc.sans.edu/forums/diary/OAUTH+phishing+against+Google+Docs+beware/22372/</a> <br/>
 Review Google App  Permissions <a href="https://myaccount.google.com/u/0/permissions?pli=1">https://myaccount.google.com/u/0/permissions?pli=1</a><br/>
SS7 Exploits Documented in Banking Attacks<br/>
 <a href="http://www.sueddeutsche.de/digital/it-sicherheit-schwachstelle-im-mobilfunknetz-kriminelle-hacker-raeumen-konten-leer-1.3486504">http://www.sueddeutsche.de/digital/it-sicherheit-schwachstelle-im-mobilfunknetz-kriminelle-hacker-raeumen-konten-leer-1.3486504</a><br/>
 <a href="http://www.theregister.co.uk/2017/05/03/hackers_fire_up_ss7_flaw/">http://www.theregister.co.uk/2017/05/03/hackers_fire_up_ss7_flaw/</a><br/>
]]></description>
<itunes:duration>8:26</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5486" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, May 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5484</itunes:episode>
<itunes:subtitle>Scans for Intel Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Scans for Intel Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5484.mp3" length="4563977" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5484.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5484</link>
<pubDate>Tue, 02 May 2017 23:25:03 GMT</pubDate>
<description><![CDATA[Scans Sighted for Ports Used by Intel Remote Management Interface<br/>
 <a href="https://isc.sans.edu/port.html?port=16992">https://isc.sans.edu/port.html?port=16992</a><br/>
 <a href="https://isc.sans.edu/port.html?port=16993">https://isc.sans.edu/port.html?port=16993</a><br/>
Outlook Forms Can Run Macros<br/>
 <a href="https://sensepost.com/blog/2017/outlook-forms-and-shells/">https://sensepost.com/blog/2017/outlook-forms-and-shells/</a><br/>
Jenkins Vulnerability<br/>
 <a href="https://jenkins.io/security/advisory/2017-04-26/">https://jenkins.io/security/advisory/2017-04-26/</a><br/>
Google Android May Patchday<br/>
 <a href="https://source.android.com/security/bulletin/2017-05-01">https://source.android.com/security/bulletin/2017-05-01</a><br/>
IBM Storwize USB Stick Malware<br/>
 <a href="http://www-01.ibm.com/support/docview.wss?uid=ssg1S1010146&myns=s028&mynp=OCSTHGUJ&mynp=OCSTLM5A&mynp=OCSTLM6B&mynp=OCHW206&mync=E&cm_sp=s028-_-OCSTHGUJ-OCSTLM5A-OCSTLM6B-OCHW206-_-E">http://www-01.ibm.com/support/docview.wss?uid=ssg1S1010146&myns=s028&mynp=OCSTHGUJ&mynp=OCSTLM5A&mynp=OCSTLM6B&mynp=OCHW206&mync=E&cm_sp=s028-_-OCSTHGUJ-OCSTLM5A-OCSTLM6B-OCHW206-_-E</a><br/>
]]></description>
<itunes:duration>5:25</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5484" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, May 2nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5482</itunes:episode>
<itunes:subtitle>Critical Intel AMT/ISM/SBT Vulnerablity; chkrootkit local root exploit
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Critical Intel AMT/ISM/SBT Vulnerablity; chkrootkit local root exploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5482.mp3" length="4969861" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5482.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5482</link>
<pubDate>Tue, 02 May 2017 00:59:10 GMT</pubDate>
<description><![CDATA[Intel AMT, SBT and ISM Escalation of Privilege Vulnerability <br/>
 <a href="https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr">https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr</a><br/>
 <a href="https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/">https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/</a><br/>
 <br/>
Local Root Exploit in chkrootkit<br/>
 <a href="https://lepetithacker.wordpress.com/2017/04/30/local-root-exploit-in-chkrootkit/">https://lepetithacker.wordpress.com/2017/04/30/local-root-exploit-in-chkrootkit/</a><br/>
Escape Sequence Exploits in Various Linux Terminals<br/>
 <a href="http://www.openwall.com/lists/oss-security/2017/05/01/13">http://www.openwall.com/lists/oss-security/2017/05/01/13</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5482" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, May 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5480</itunes:episode>
<itunes:subtitle>Simple Obfuscation Bypasses AV; OS X Proxy Malware;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Simple Obfuscation Bypasses AV; OS X Proxy Malware;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5480.mp3" length="4923359" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5480.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5480</link>
<pubDate>Mon, 01 May 2017 01:50:03 GMT</pubDate>
<description><![CDATA[Simple Javascript Word Macro Not Recognized By Many AV Products<br/>
 <a href="https://isc.sans.edu/forums/diary/Another+Day+Another+Obfuscation+Technique/22354/">https://isc.sans.edu/forums/diary/Another+Day+Another+Obfuscation+Technique/22354/</a><br/>
OS X Malware Adds Proxy To Intercept HTTPS<br/>
 <a href="http://blog.checkpoint.com/2017/04/27/osx-malware-catching-wants-read-https-traffic/">http://blog.checkpoint.com/2017/04/27/osx-malware-catching-wants-read-https-traffic/</a><br/>
OVH Vulnerability Put Servers at Risk<br/>
 <a href="https://jrwr.io/doku.php?id=blog:ovh_vrack_security_issue">https://jrwr.io/doku.php?id=blog:ovh_vrack_security_issue</a><br/>
]]></description>
<itunes:duration>5:50</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5480" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5478</itunes:episode>
<itunes:subtitle>BGP Attack against VISA; Antminer DoS Vuln; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
BGP Attack against VISA; Antminer DoS Vuln; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5478.mp3" length="5300391" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5478.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5478</link>
<pubDate>Fri, 28 Apr 2017 01:20:02 GMT</pubDate>
<description><![CDATA[VISA IP Block Hijacked By Russian ISP<br/>
 <a href="https://isc.sans.edu/forums/diary/BGP+Hijacking+The+Internet+is+StillAgain+Broken/22350/">https://isc.sans.edu/forums/diary/BGP+Hijacking+The+Internet+is+StillAgain+Broken/22350/</a><br/>
Antminer "Checking" DoS Vulnerability<br/>
 <a href="http://www.antbleed.com">http://www.antbleed.com</a><br/>
Symantec Offers Audits To Stave Off Google's CA Blacklisting<br/>
 <a href="https://www.symantec.com/connect/blogs/symantec-ca-proposal">https://www.symantec.com/connect/blogs/symantec-ca-proposal</a><br/>
NoMX Security E-Mail Appliance Pentest<br/>
 <a href="https://scotthelme.co.uk/nomx-the-worlds-most-secure-communications-protocol/">https://scotthelme.co.uk/nomx-the-worlds-most-secure-communications-protocol/</a><br/>
 vendor response: www.nomx.com<br/>
SANS Defending Web Applications<br/>
 <a href="https://www.sans.org/dev522">https://www.sans.org/dev522</a>]]></description>
<itunes:duration>6:17</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5478" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, Cyber, Infosec, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5476</itunes:episode>
<itunes:subtitle>Bots Disrupt More ISPs; Samsung TV Exploit; Coldfusion Update; SNMP Auth bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Bots Disrupt More ISPs; Samsung TV Exploit; Coldfusion Update; SNMP Auth bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5476.mp3" length="4711923" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5476.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5476</link>
<pubDate>Thu, 27 Apr 2017 01:50:02 GMT</pubDate>
<description><![CDATA[Bots Disrupts US ISP<br/>
 <a href="https://www.bleepingcomputer.com/news/security/us-isp-goes-down-as-two-malware-families-go-to-war-over-its-modems/">https://www.bleepingcomputer.com/news/security/us-isp-goes-down-as-two-malware-families-go-to-war-over-its-modems/</a><br/>
Samsung Smart TV Wi-Fi Direct Exploit<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Apr/101">http://seclists.org/fulldisclosure/2017/Apr/101</a><br/>
Adobe Publishes ColdFusion Update<br/>
 <a href="https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html">https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html</a><br/>
SNMP Misconfiguration Eliminates Community String Validation<br/>
 <a href="https://stringbleed.github.io/#">https://stringbleed.github.io/#</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5476" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 26th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5474</itunes:episode>
<itunes:subtitle>What are CAA Records? Hyndai Car Hacking. Display Software Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
What are CAA Records? Hyndai Car Hacking. Display Software Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5474.mp3" length="4956933" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5474.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5474</link>
<pubDate>Wed, 26 Apr 2017 00:30:03 GMT</pubDate>
<description><![CDATA[CAA Records and Certificate Issuance<br/>
 <a href="https://isc.sans.edu/forums/diary/CAA+Records+and+Certificate+Issuance/22342/">https://isc.sans.edu/forums/diary/CAA+Records+and+Certificate+Issuance/22342/</a><br/>
Hyundai Blue Link Infomration Disclosure<br/>
 <a href="https://community.rapid7.com/community/infosec/blog/2017/04/25/r7-2017-02-hyundai-blue-link-potential-info-disclosure-fixed">https://community.rapid7.com/community/infosec/blog/2017/04/25/r7-2017-02-hyundai-blue-link-potential-info-disclosure-fixed</a><br/>
HP, Philips, Fujitsu Display Software Privilege Escalation<br/>
 <a href="http://blog.sec-consult.com/2017/04/what-unites-hp-philips-and-fujitsu-one.html">http://blog.sec-consult.com/2017/04/what-unites-hp-philips-and-fujitsu-one.html</a><br/>
]]></description>
<itunes:duration>5:53</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5474" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 25th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5472</itunes:episode>
<itunes:subtitle>Android SOCKS Proxy Malware;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Android SOCKS Proxy Malware;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5472.mp3" length="4340339" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5472.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5472</link>
<pubDate>Tue, 25 Apr 2017 01:40:02 GMT</pubDate>
<description><![CDATA[Android Malware MilyDoor Builds Backdoor Into Networks Via SSH/SOCKS<br/>
 <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/dresscode-android-malware-finds-successor-milkydoor/">http://blog.trendmicro.com/trendlabs-security-intelligence/dresscode-android-malware-finds-successor-milkydoor/</a><br/>
Remote Code Execution Flaw in Squirrelmail<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Apr/81">http://seclists.org/fulldisclosure/2017/Apr/81</a><br/>
Atlassian Confluence Update<br/>
 <a href="https://confluence.atlassian.com/doc/confluence-security-advisory-2017-04-19-887071137.html">https://confluence.atlassian.com/doc/confluence-security-advisory-2017-04-19-887071137.html</a><br/>
TCP Proxy Over Named Pipes / SMB<br/>
 <a href="https://github.com/dxflatline/flatpipes">https://github.com/dxflatline/flatpipes</a><br/>
]]></description>
<itunes:duration>5:09</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5472" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5470</itunes:episode>
<itunes:subtitle>Port 81; CVE-2017-0199 HTA Exploit Analysis; NVidia installs Node.js
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Port 81; CVE-2017-0199 HTA Exploit Analysis; NVidia installs Node.js
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5470.mp3" length="4527369" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5470.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5470</link>
<pubDate>Mon, 24 Apr 2017 02:05:02 GMT</pubDate>
<description><![CDATA[Increase in Port 81 Traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/WTF+tcp+port+81/22332/">https://isc.sans.edu/forums/diary/WTF+tcp+port+81/22332/</a><br/>
Analyzing a Document and Malware Trying to Exploit CVE-2017-0199 (HTA)<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Documents+A+Bit+Of+News/22334/">https://isc.sans.edu/forums/diary/Malicious+Documents+A+Bit+Of+News/22334/</a><br/>
DOUBLEPULSAR Detected on Tens of Thousands of Systems<br/>
 <a href="http://www.theregister.co.uk/2017/04/21/windows_hacked_nsa_shadow_brokers/">http://www.theregister.co.uk/2017/04/21/windows_hacked_nsa_shadow_brokers/</a><br/>
NVidia Includes Node.js Server With Drivers<br/>
 <a href="http://blog.sec-consult.com/2017/04/application-whitelisting-application.html">http://blog.sec-consult.com/2017/04/application-whitelisting-application.html</a><br/>
Android SMSVova Spyware Survives in Google Play Store for 3 Years<br/>
 <a href="https://www.zscaler.com/blogs/research/android-spyware-smsvova-posing-system-update-play-store">https://www.zscaler.com/blogs/research/android-spyware-smsvova-posing-system-update-play-store</a><br/>
]]></description>
<itunes:duration>5:22</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5470" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5468</itunes:episode>
<itunes:subtitle>#DNS Covert Channels; Ambient Light Sensors;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#DNS Covert Channels; Ambient Light Sensors;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5468.mp3" length="5007222" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5468.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5468</link>
<pubDate>Thu, 20 Apr 2017 23:45:03 GMT</pubDate>
<description><![CDATA[Detecting Covert DNS Channels <br/>
 <a href="https://isc.sans.edu/forums/diary/DNS+Query+Length+Because+Size+Does+Matter/22326/">https://isc.sans.edu/forums/diary/DNS+Query+Length+Because+Size+Does+Matter/22326/</a><br/>
Ambient Light Sensors May Become Accessible Via JavaScript<br/>
 <a href="https://blog.lukaszolejnik.com/stealing-sensitive-browser-data-with-the-w3c-ambient-light-sensor-api/">https://blog.lukaszolejnik.com/stealing-sensitive-browser-data-with-the-w3c-ambient-light-sensor-api/</a><br/>
BIND Name Server Update<br/>
 <a href="https://kb.isc.org/article/AA-01491">https://kb.isc.org/article/AA-01491</a><br/>
Entropy As A Service<br/>
 <a href="https://www.getnetrandom.com">https://www.getnetrandom.com</a><br/>
Webcast: NoSQL Doesn't Make You NoVulnerable<br/>
 <a href="https://www.sans.org/webcasts/nosql-doesnt-novulnerable-104897">https://www.sans.org/webcasts/nosql-doesnt-novulnerable-104897</a><br/>
]]></description>
<itunes:duration>5:56</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5468" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5466</itunes:episode>
<itunes:subtitle>More About #Excel Macros; Bose SpyPhones; Own/NextCloud Buggy Bugreports
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
More About #Excel Macros; Bose SpyPhones; Own/NextCloud Buggy Bugreports
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5466.mp3" length="4779183" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5466.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5466</link>
<pubDate>Thu, 20 Apr 2017 00:40:02 GMT</pubDate>
<description><![CDATA[Hunting and Analyzing Malicious Excel Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Hunting+for+Malicious+Excel+Sheets/22322/">https://isc.sans.edu/forums/diary/Hunting+for+Malicious+Excel+Sheets/22322/</a><br/>
Bose May Be Spying on Listeners<br/>
 <a href="https://www.scribd.com/document/345620278/Bose-Privacy-Complaint">https://www.scribd.com/document/345620278/Bose-Privacy-Complaint</a><br/>
Microsoft No-Password Sign In<br/>
 <a href="https://blogs.technet.microsoft.com/enterprisemobility/2017/04/18/no-password-phone-sign-in-for-microsoft-accounts/">https://blogs.technet.microsoft.com/enterprisemobility/2017/04/18/no-password-phone-sign-in-for-microsoft-accounts/</a><br/>
Owncloud/Nextcloud Bug Reports Include Passwords<br/>
 <a href="https://blog.hboeck.de/archives/885-Passwords-in-the-Bug-Reports-OwncloudNextcloud.html">https://blog.hboeck.de/archives/885-Passwords-in-the-Bug-Reports-OwncloudNextcloud.html</a><br/>
Fuzzing Used to Find a Tcpdump Vulnerability<br/>
 <a href="https://www.softscheck.com/en/identifying-security-vulnerabilities-with-cloud-fuzzing/">https://www.softscheck.com/en/identifying-security-vulnerabilities-with-cloud-fuzzing/</a><br/>
DNS Homograph Detection<br/>
 <a href="https://github.com/dutchcoders/homographs">https://github.com/dutchcoders/homographs</a><br/>
For Friday's (and other upcoming webcasts), see<br/>
 <a href="https://www.sans.org/webcasts">https://www.sans.org/webcasts</a><br/>
]]></description>
<itunes:duration>5:40</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5466" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5464</itunes:episode>
<itunes:subtitle>#CVE-2017-0199 Details; Old Windows Versions vs. New CPUs; #Forensics and Win10
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#CVE-2017-0199 Details; Old Windows Versions vs. New CPUs; #Forensics and Win10
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5464.mp3" length="4968182" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5464.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5464</link>
<pubDate>Wed, 19 Apr 2017 01:10:02 GMT</pubDate>
<description><![CDATA[Details about how to exploit CVE-2017-0199<br/>
 <a href="https://rewtin.blogspot.com.au/2017/04/cve-2017-0199-practical-exploitation-poc.html">https://rewtin.blogspot.com.au/2017/04/cve-2017-0199-practical-exploitation-poc.html</a><br/>
 <br/>
User Provided Patch To Help Update Old Operating Systems on New CPU<br/>
 <a href="https://github.com/zeffy/kb4012218-19">https://github.com/zeffy/kb4012218-19</a><br/>
Forensics Tools and Issues With Windows 10 Compact OS<br/>
 <a href="https://www.heise.de/security/artikel/Forensik-Tools-patzen-bei-neuer-Windows-Kompression-3676075.html">https://www.heise.de/security/artikel/Forensik-Tools-patzen-bei-neuer-Windows-Kompression-3676075.html</a><br/>
]]></description>
<itunes:duration>5:54</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5464" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5462</itunes:episode>
<itunes:subtitle>Detecting IDN Phishing; Old Linux Kernel Bug Surfaces; Edge Leaks Info
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Detecting IDN Phishing; Old Linux Kernel Bug Surfaces; Edge Leaks Info
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5462.mp3" length="6007011" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5462.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5462</link>
<pubDate>Tue, 18 Apr 2017 00:15:04 GMT</pubDate>
<description><![CDATA[Detecting IDN Phishing Domains<br/>
 <a href="https://isc.sans.edu/forums/diary/Tool+to+Detect+Active+Phishing+Attacks+Using+Unicode+LookAlike+Domains/22310/">https://isc.sans.edu/forums/diary/Tool+to+Detect+Active+Phishing+Attacks+Using+Unicode+LookAlike+Domains/22310/</a><br/>
Old Linux Kernel Bug Allows for Remote Code Execution via UDP<br/>
 <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191">https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=197c949e7798fbf28cfadc69d9ca0c2abbf93191</a><br/>
Microsoft Edge JavaScript "fetch" Function Can Be Used to Leak User Data<br/>
 <a href="http://mov.sx/2017/04/16/microsoft-edge-leaks-url.html">http://mov.sx/2017/04/16/microsoft-edge-leaks-url.html</a><br/>
]]></description>
<itunes:duration>7:08</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5462" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5460</itunes:episode>
<itunes:subtitle>What you need to know: Eternalblue and Doublepulsar in 5min
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
What you need to know: Eternalblue and Doublepulsar in 5min
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5460.mp3" length="4703455" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5460.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5460</link>
<pubDate>Mon, 17 Apr 2017 00:25:02 GMT</pubDate>
<description><![CDATA[Detecting SMB Cover Channel "Doublepulsar"<br/>
 <a href="https://isc.sans.edu/forums/diary/Detecting+SMB+Covert+Channel+Double+Pulsar/22312/">https://isc.sans.edu/forums/diary/Detecting+SMB+Covert+Channel+Double+Pulsar/22312/</a><br/>
ETERNALBLUE: Windows SMBv1 Exploit<br/>
 <a href="https://isc.sans.edu/forums/diary/ETERNALBLUE+Windows+SMBv1+Exploit+Patched/22304/">https://isc.sans.edu/forums/diary/ETERNALBLUE+Windows+SMBv1+Exploit+Patched/22304/</a><br/>
]]></description>
<itunes:duration>5:35</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5460" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5458</itunes:episode>
<itunes:subtitle>Filter Packets By Process; C-LDAP DDoS;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Filter Packets By Process; C-LDAP DDoS;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5458.mp3" length="4805644" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5458.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5458</link>
<pubDate>Fri, 14 Apr 2017 01:30:03 GMT</pubDate>
<description><![CDATA[Packet Captures Filtered By Process<br/>
 <a href="https://isc.sans.edu/forums/diary/Packet+Captures+Filtered+by+Process/22296/">https://isc.sans.edu/forums/diary/Packet+Captures+Filtered+by+Process/22296/</a><br/>
C-LDAP Used to Amplify DDoS Attack <br/>
 <a href="https://isc.sans.edu/forums/diary/Akamai+reports+UDP+DDOS+Using+CLDAP+reaching+24Gbps/22300/">https://isc.sans.edu/forums/diary/Akamai+reports+UDP+DDOS+Using+CLDAP+reaching+24Gbps/22300/</a><br/>
Juniper Updates<br/>
 <a href="https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES">https://kb.juniper.net/InfoCenter/index?page=content&channel=SECURITY_ADVISORIES</a><br/>
SAP Patches Code Injection in TREX<br/>
 <a href="https://erpscan.com/press-center/press-release/critical-vulnerability-affects-sap-hana-dozen-sap-applications/">https://erpscan.com/press-center/press-release/critical-vulnerability-affects-sap-hana-dozen-sap-applications/</a><br/>
More Details About Dallas Siren Hack<br/>
 <a href="https://duo.com/blog/the-dallas-county-siren-hack">https://duo.com/blog/the-dallas-county-siren-hack</a><br/>
]]></description>
<itunes:duration>5:42</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5458" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5456</itunes:episode>
<itunes:subtitle>MOLE Ransomware; Netflix Traffic Analysis;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
MOLE Ransomware; Netflix Traffic Analysis;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5456.mp3" length="4943632" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5456.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5456</link>
<pubDate>Thu, 13 Apr 2017 02:05:02 GMT</pubDate>
<description><![CDATA[Mole Ransomware Delivered via Fake USPS E-Mails<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+on+20170411+pushes+yet+another+ransomware+variant/22290/">https://isc.sans.edu/forums/diary/Malspam+on+20170411+pushes+yet+another+ransomware+variant/22290/</a><br/>
Identifying HTTPS-Protected Netflix Videos in Real-Time<br/>
 <a href="https://www.mjkranch.com/docs/CODASPY17_Kranch_Reed_IdentifyingHTTPSNetflix.pdf">https://www.mjkranch.com/docs/CODASPY17_Kranch_Reed_IdentifyingHTTPSNetflix.pdf</a><br/>
SMS Messages Used to Control Oven<br/>
 <a href="https://www.pentestpartners.com/blog/iot-Aga-cast-iron-security-flaw/">https://www.pentestpartners.com/blog/iot-Aga-cast-iron-security-flaw/</a><br/>
Android Hardening TLS Use<br/>
 <a href="https://android-developers.googleblog.com/2017/04/android-o-to-drop-insecure-tls-version.html">https://android-developers.googleblog.com/2017/04/android-o-to-drop-insecure-tls-version.html</a><br/>
]]></description>
<itunes:duration>5:52</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5456" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5454</itunes:episode>
<itunes:subtitle>#MSFT/#Adobe Patch Tuesday Unhinged; Solaris 0-Day; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#MSFT/#Adobe Patch Tuesday Unhinged; Solaris 0-Day; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5454.mp3" length="5516238" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5454.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5454</link>
<pubDate>Wed, 12 Apr 2017 01:25:02 GMT</pubDate>
<description><![CDATA[MSFT/Adobe Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/April+2017+Microsoft+Patch+Tuesday/22288/">https://isc.sans.edu/forums/diary/April+2017+Microsoft+Patch+Tuesday/22288/</a><br/>
Solaris 0-Day<br/>
 <a href="https://twitter.com/hackerfantastic/status/851555538597011460">https://twitter.com/hackerfantastic/status/851555538597011460</a><br/>
OWASP Top 10 Update<br/>
 <a href="https://github.com/OWASP/Top10/raw/master/2017/OWASP%20Top%2010%20-%202017%20RC1-English.pdf">https://github.com/OWASP/Top10/raw/master/2017/OWASP%20Top%2010%20-%202017%20RC1-English.pdf</a><br/>
]]></description>
<itunes:duration>05:00:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5454" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5452</itunes:episode>
<itunes:subtitle>TPLink Modem SMS Vulnerability;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
TPLink Modem SMS Vulnerability;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5452.mp3" length="4486481" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5452.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5452</link>
<pubDate>Tue, 11 Apr 2017 02:40:03 GMT</pubDate>
<description><![CDATA[TPLink Modem Responds With Admin Password to SMS<br/>
 <a href="http://www.theregister.co.uk/2017/04/10/tplink_3gwifi_modem_spills_credentials_to_an_evil_text_message/">http://www.theregister.co.uk/2017/04/10/tplink_3gwifi_modem_spills_credentials_to_an_evil_text_message/</a><br/>
Fake Google Map Weblinks<br/>
 <a href="https://www.bleepingcomputer.com/news/google/thousands-of-fake-google-maps-listings-redirect-users-to-fraudulent-sites-each-month/">https://www.bleepingcomputer.com/news/google/thousands-of-fake-google-maps-listings-redirect-users-to-fraudulent-sites-each-month/</a><br/>
Apple Fixes Apple Music For Android<br/>
 <a href="http://seclists.org/bugtraq/2017/Apr/26">http://seclists.org/bugtraq/2017/Apr/26</a><br/>
Dalles Sirens Hacked via Wireless Attacks<br/>
 <a href="http://www.theregister.co.uk/2017/04/10/hackers_set_off_dallas_emergency_siren_system/">http://www.theregister.co.uk/2017/04/10/hackers_set_off_dallas_emergency_siren_system/</a><br/>
NATO Discovers (finally?) that IPv6 Can be Used As a Covert Channel<br/>
 <a href="https://t.co/FvSSwhtUH7">https://t.co/FvSSwhtUH7</a><br/>
]]></description>
<itunes:duration>05:00:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5452" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5450</itunes:episode>
<itunes:subtitle>Alexa/Umbrella Whitelisting;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Alexa/Umbrella Whitelisting;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5450.mp3" length="5453322" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5450.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5450</link>
<pubDate>Mon, 10 Apr 2017 01:25:02 GMT</pubDate>
<description><![CDATA[Domain Whitelisting with Alexa and Umbrella Lists (and update)<br/>
 <a href="https://isc.sans.edu/forums/diary/Domain+Whitelisting+With+Alexa+and+Umbrella+Lists/22270/">https://isc.sans.edu/forums/diary/Domain+Whitelisting+With+Alexa+and+Umbrella+Lists/22270/</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Domain+Whitelisting+With+Alexa+and+Umbrella+Lists+update/22274/">https://isc.sans.edu/forums/diary/Domain+Whitelisting+With+Alexa+and+Umbrella+Lists+update/22274/</a><br/>
SANS Security West (San Diego)<br/>
  <a href="https://www.sans.org/event/sans-security-west-2017">https://www.sans.org/event/sans-security-west-2017</a><br/>
Dallas Tornado Sirens Hacked<br/>
 <a href="https://www.washingtonpost.com/news/the-intersect/wp/2017/04/09/someone-hacked-every-tornado-siren-in-dallas-it-was-loud/?utm_term=.ca706deea318">https://www.washingtonpost.com/news/the-intersect/wp/2017/04/09/someone-hacked-every-tornado-siren-in-dallas-it-was-loud/?utm_term=.ca706deea318</a><br/>
Shadowbroker Files<br/>
 <a href="https://github.com/x0rz/EQGRP">https://github.com/x0rz/EQGRP</a><br/>
Word Vulnerability<br/>
 <a href="https://securingtomorrow.mcafee.com/mcafee-labs/critical-office-zero-day-attacks-detected-wild/">https://securingtomorrow.mcafee.com/mcafee-labs/critical-office-zero-day-attacks-detected-wild/</a><br/>
]]></description>
<itunes:duration>05:00:00</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5450" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, April 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5449</itunes:episode>
<itunes:subtitle>Antivirus Assisted Attacks;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Antivirus Assisted Attacks;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5449.mp3" length="4783988" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5449.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5449</link>
<pubDate>Fri, 07 Apr 2017 02:20:02 GMT</pubDate>
<description><![CDATA[Automatically Inferring Malware Signatures for Anti-Virus Assisted Attacks<br/>
 <a href="https://www.sec.cs.tu-bs.de/pubs/2017-asiaccs.pdf">https://www.sec.cs.tu-bs.de/pubs/2017-asiaccs.pdf</a><br/>
Cisco Aironet Default Credentials<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ame">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ame</a><br/>
Intercepting Two-Factor Authentication<br/>
 <a href="https://breakdev.org/evilginx-advanced-phishing-with-two-factor-authentication-bypass/">https://breakdev.org/evilginx-advanced-phishing-with-two-factor-authentication-bypass/</a><br/>
QNAP NAS Vulnerabilities<br/>
 <a href="https://sintonen.fi/advisories/qnap-qts-multiple-rce-vulnerabilities.txt">https://sintonen.fi/advisories/qnap-qts-multiple-rce-vulnerabilities.txt</a><br/>
]]></description>
<itunes:duration>5:40
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5449" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, April 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5447</itunes:episode>
<itunes:subtitle>Attackers Chasing Whitelists; Struts2 Vuln Installing Cerber
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Attackers Chasing Whitelists; Struts2 Vuln Installing Cerber
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5447.mp3" length="5406367" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5447.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5447</link>
<pubDate>Thu, 06 Apr 2017 03:40:02 GMT</pubDate>
<description><![CDATA[Whitelists: The Holy Grail of Attackers<br/>
 <a href="https://isc.sans.edu/forums/diary/Whitelists+The+Holy+Grail+of+Attackers/22262/">https://isc.sans.edu/forums/diary/Whitelists+The+Holy+Grail+of+Attackers/22262/</a><br/>
Java Struts2 Vulnerability Used To Install Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/Java+Struts2+Vulnerability+Used+To+Install+Cerber+Crypto+Ransomware/22264/">https://isc.sans.edu/forums/diary/Java+Struts2+Vulnerability+Used+To+Install+Cerber+Crypto+Ransomware/22264/</a><br/>
Brazilian Bank Looses Control Over Domains<br/>
 <a href="https://threatpost.com/lessons-from-top-to-bottom-compromise-of-brazilian-bank/124770/">https://threatpost.com/lessons-from-top-to-bottom-compromise-of-brazilian-bank/124770/</a><br/>
Google Android April Patch Day<br/>
 <a href="https://source.android.com/security/bulletin/2017-04-01#security-vulnerability-summary">https://source.android.com/security/bulletin/2017-04-01#security-vulnerability-summary</a><br/>
Radware Observes "BrickerBot" Destroying Devices<br/>
 <a href="https://security.radware.com/ddos-threats-attacks/brickerbot-pdos-permanent-denial-of-service/">https://security.radware.com/ddos-threats-attacks/brickerbot-pdos-permanent-denial-of-service/</a><br/>
Struts2 Vulnerability Webcast<br/>
 <a href="https://www.sans.org/webcasts/struts-shock-current-attacks-struts2-defend-104787">https://www.sans.org/webcasts/struts-shock-current-attacks-struts2-defend-104787</a><br/>
]]></description>
<itunes:duration>6:25
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5447" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, April 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5445</itunes:episode>
<itunes:subtitle>Exploiting Broadcom Wi-Fi;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Exploiting Broadcom Wi-Fi;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5445.mp3" length="5038759" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5445.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5445</link>
<pubDate>Wed, 05 Apr 2017 02:35:02 GMT</pubDate>
<description><![CDATA[Exploiting Broadcom's Wi-Fi Stack<br/>
 <a href="https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html">https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html</a><br/>
Covert Channel Between Virtual Machines Via CPU Cache<br/>
 <a href="https://cmaurice.fr/pdf/ndss17_maurice.pdf">https://cmaurice.fr/pdf/ndss17_maurice.pdf</a><br/>
40 Vulnerabilities in Samsung Tizen<br/>
 <a href="https://motherboard.vice.com/en_us/article/samsung-tizen-operating-system-bugs-vulnerabilities">https://motherboard.vice.com/en_us/article/samsung-tizen-operating-system-bugs-vulnerabilities</a><br/>
]]></description>
<itunes:duration>5:59
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5445" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, April 4th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5443</itunes:episode>
<itunes:subtitle>#iOS Emergency Patch; ISO #SHA1 Collsisions; #Skype Malvertising
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#iOS Emergency Patch; ISO #SHA1 Collsisions; #Skype Malvertising
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5443.mp3" length="4696501" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5443.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5443</link>
<pubDate>Tue, 04 Apr 2017 02:15:02 GMT</pubDate>
<description><![CDATA[Apple Releases iOS 10.3.1 to Remedy Wifi Remote Code Execution<br/>
 <a href="https://support.apple.com/en-us/HT207688">https://support.apple.com/en-us/HT207688</a><br/>
Practical Use of SHA1 Collisions: ISO Images<br/>
 <a href="https://isc.sans.edu/forums/diary/A+Practical+Use+for+a+SHA1+Collision/22257/">https://isc.sans.edu/forums/diary/A+Practical+Use+for+a+SHA1+Collision/22257/</a><br/>
Microsoft Defender False Positive <br/>
 <a href="https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FBluber.A">https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FBluber.A</a><br/>
Cracking Weak Session Secrets<br/>
 <a href="https://martinfowler.com/articles/session-secret.html">https://martinfowler.com/articles/session-secret.html</a><br/>
Skype Malvertising Advertises Fake Flash Players<br/>
 <a href="https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/">https://www.bleepingcomputer.com/news/security/skype-malvertising-campaign-pushes-fake-flash-player/</a><br/>
]]></description>
<itunes:duration>5:34
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5443" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, April 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5441</itunes:episode>
<itunes:subtitle>More LastPass Patches;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
More LastPass Patches;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5441.mp3" length="5038901" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5441.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5441</link>
<pubDate>Mon, 03 Apr 2017 02:20:01 GMT</pubDate>
<description><![CDATA[Google Discovers More LastPass Vulnerabilities; <br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1225&desc=6">https://bugs.chromium.org/p/project-zero/issues/detail?id=1225&desc=6</a><br/>
Attacking KeePass<br/>
 <a href="https://www.slideshare.net/harmj0y/a-case-study-in-attacking-keepass">https://www.slideshare.net/harmj0y/a-case-study-in-attacking-keepass</a><br/>
 <a href="https://github.com/HarmJ0y/KeeThief">https://github.com/HarmJ0y/KeeThief</a><br/>
Bypassing Cylance<br/>
 <a href="http://www.blackhillsinfosec.com/?p=5792">http://www.blackhillsinfosec.com/?p=5792</a><br/>
Mimi Penguin: Extracting Credentials From Memory on Linux Tools<br/>
 <a href="https://github.com/huntergregal/mimipenguin">https://github.com/huntergregal/mimipenguin</a><br/>
Windows 2003 / IIS 6 Exploit <br/>
 <a href="https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html">https://0patch.blogspot.com/2017/03/0patching-immortal-cve-2017-7269.html</a><br/>
 <a href="https://github.com/rapid7/metasploit-framework/pull/8162">https://github.com/rapid7/metasploit-framework/pull/8162</a><br/>
]]></description>
<itunes:duration>5:59
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5441" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 31st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5439</itunes:episode>
<itunes:subtitle>PowerShell EncodedCommand; GitHub Developers Targeted
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
PowerShell EncodedCommand; GitHub Developers Targeted
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5439.mp3" length="4790393" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5439.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5439</link>
<pubDate>Fri, 31 Mar 2017 02:40:02 GMT</pubDate>
<description><![CDATA[Diverting built-in features for the bad<br/>
 <a href="https://isc.sans.edu/forums/diary/Diverting+builtin+features+for+the+bad/22250/">https://isc.sans.edu/forums/diary/Diverting+builtin+features+for+the+bad/22250/</a><br/>
Fake Job Offers to GitHub Developers Include Malware<br/>
 <a href="http://researchcenter.paloaltonetworks.com/2017/03/unit42-dimnie-hiding-plain-sight/">http://researchcenter.paloaltonetworks.com/2017/03/unit42-dimnie-hiding-plain-sight/</a><br/>
Drones With Lasers!<br/>
 <a href="https://arxiv.org/pdf/1703.07751.pdf">https://arxiv.org/pdf/1703.07751.pdf</a><br/>
]]></description>
<itunes:duration>5:41
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5439" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 30th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5437</itunes:episode>
<itunes:subtitle>Better Phishing E-Mails; Crusader Adware; VMWare Patch
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Better Phishing E-Mails; Crusader Adware; VMWare Patch
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5437.mp3" length="4333988" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5437.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5437</link>
<pubDate>Thu, 30 Mar 2017 02:00:02 GMT</pubDate>
<description><![CDATA[Logical and Physical Security Correlation<br/>
 <a href="https://isc.sans.edu/forums/diary/Logical+Physical+Security+Correlation/22243/">https://isc.sans.edu/forums/diary/Logical+Physical+Security+Correlation/22243/</a><br/>
Recent Mirai DDoS Attacks<br/>
 <a href="https://www.incapsula.com/blog/new-mirai-variant-ddos-us-college.html">https://www.incapsula.com/blog/new-mirai-variant-ddos-us-college.html</a><br/>
Crusader Injects Fake Support Phone Numbers into Websites<br/>
 <a href="https://www.bleepingcomputer.com/news/security/adware-replaces-phone-numbers-for-security-firms-returned-in-search-results/">https://www.bleepingcomputer.com/news/security/adware-replaces-phone-numbers-for-security-firms-returned-in-search-results/</a><br/>
VMWare Closes Pwn2Own Guest Escape Vulnerabilities<br/>
 <a href="http://www.vmware.com/security/advisories/VMSA-2017-0006.html">http://www.vmware.com/security/advisories/VMSA-2017-0006.html</a><br/>
Apple iCloud for Windows Update<br/>
 <a href="https://support.apple.com/de-de/HT207607">https://support.apple.com/de-de/HT207607</a><br/>
]]></description>
<itunes:duration>5:08
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5437" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 29th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5435</itunes:episode>
<itunes:subtitle>New Struts2 Exploit for Recent Vulnerability; Symantec CA SSL Checker
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
New Struts2 Exploit for Recent Vulnerability; Symantec CA SSL Checker
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5435.mp3" length="4619089" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5435.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5435</link>
<pubDate>Wed, 29 Mar 2017 02:00:02 GMT</pubDate>
<description><![CDATA[New Exploit Variant for Recent Struts2 Vulnerability<br/>
 <a href="https://blog.gdssecurity.com/labs/2017/3/27/an-analysis-of-cve-2017-5638.html">https://blog.gdssecurity.com/labs/2017/3/27/an-analysis-of-cve-2017-5638.html</a><br/>
PoC Exploit for iBook ePub Javascript Vulnerability<br/>
 <a href="https://s1gnalcha0s.github.io/ibooks/epub/2017/03/27/This-book-reads-you-using-JavaScript.html">https://s1gnalcha0s.github.io/ibooks/epub/2017/03/27/This-book-reads-you-using-JavaScript.html</a><br/>
Microsoft Docs.com Leak<br/>
 <a href="https://twitter.com/gossithedog/status/845446263244050434">https://twitter.com/gossithedog/status/845446263244050434</a><br/>
Symantec SSL CA tool<br/>
 <a href="https://www.renditioninfosec.com/socapps/sslcheck/index.php">https://www.renditioninfosec.com/socapps/sslcheck/index.php</a><br/>
]]></description>
<itunes:duration>5:29
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5435" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5433</itunes:episode>
<itunes:subtitle>Apple Updates Everything (Again); IIS6/Win2013 WebDav Exploit; Symantec SSL Update
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Apple Updates Everything (Again); IIS6/Win2013 WebDav Exploit; Symantec SSL Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5433.mp3" length="5701217" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5433.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5433</link>
<pubDate>Tue, 28 Mar 2017 01:50:02 GMT</pubDate>
<description><![CDATA[Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
IIS 6 / Windows Server 2003 Exploit<br/>
 <a href="https://github.com/edwardz246003/IIS_exploit/blob/master/exploit.py">https://github.com/edwardz246003/IIS_exploit/blob/master/exploit.py</a><br/>
Symantec SSL Update<br/>
 <a href="https://www.symantec.com/connect/blogs/message-our-ca-customers">https://www.symantec.com/connect/blogs/message-our-ca-customers</a><br/>
]]></description>
<itunes:duration>6:46
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5433" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5431</itunes:episode>
<itunes:subtitle>#Symantec vs. #Google SSL;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Symantec vs. #Google SSL;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5431.mp3" length="5521455" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5431.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5431</link>
<pubDate>Mon, 27 Mar 2017 02:35:02 GMT</pubDate>
<description><![CDATA[Google Announces Removal of Symantec CAs for Extended Validation<br/>
 <a href="https://www.symantec.com/connect/blogs/symantec-backs-its-ca">https://www.symantec.com/connect/blogs/symantec-backs-its-ca</a><br/>
 <a href="https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/eUAKwjihhBs">https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/eUAKwjihhBs</a><br/>
 <a href="https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md">https://chromium.googlesource.com/chromium/src/+/master/net/data/ssl/symantec/README.md</a><br/>
Spoofing Referrer in Microsoft Edge<br/>
 <a href="https://www.brokenbrowser.com/referer-spoofing-patch-bypass/">https://www.brokenbrowser.com/referer-spoofing-patch-bypass/</a><br/>
Smart TV Compromise Via Broadcast Signals<br/>
 <a href="https://www.youtube.com/watch?v=bOJ_8QHX6OA">https://www.youtube.com/watch?v=bOJ_8QHX6OA</a><br/>
Defending Web Applications Class<br/>
 <a href="https://www.sans.org/event/sans-security-west-2017/course/defending-web-applications-security-essentials">https://www.sans.org/event/sans-security-west-2017/course/defending-web-applications-security-essentials</a><br/>
]]></description>
<itunes:duration>6:33
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5431" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5429</itunes:episode>
<itunes:subtitle>Fake BTS Used to Spread Malware; Another Lastpass Update
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Fake BTS Used to Spread Malware; Another Lastpass Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5429.mp3" length="5552745" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5429.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5429</link>
<pubDate>Fri, 24 Mar 2017 03:25:02 GMT</pubDate>
<description><![CDATA["Swearing Trojan" Uses Fake BTSs To Spread Malware<br/>
 <a href="http://blog.checkpoint.com/2017/03/21/swearing-trojan-continues-rage-even-authors-arrest/">http://blog.checkpoint.com/2017/03/21/swearing-trojan-continues-rage-even-authors-arrest/</a><br/>
Lastpass Updates ClickJacking Exploit (Again)<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1188&desc=2">https://bugs.chromium.org/p/project-zero/issues/detail?id=1188&desc=2</a><br/>
Application Verifier "Bug" <br/>
 <a href="https://github.com/ionescu007/HookingNirvana/blob/master/Esoteric%20Hooks.pdf">https://github.com/ionescu007/HookingNirvana/blob/master/Esoteric%20Hooks.pdf</a><br/>
]]></description>
<itunes:duration>6:35
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5429" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 23rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5427</itunes:episode>
<itunes:subtitle>#iPhone Threats;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#iPhone Threats;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5427.mp3" length="5043597" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5427.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5427</link>
<pubDate>Thu, 23 Mar 2017 02:55:01 GMT</pubDate>
<description><![CDATA[Criminals Threaten to Erase Millions of iCloud Conntected Apple devices<br/>
 <a href="https://motherboard.vice.com/en_us/article/hackers-we-will-remotely-wipe-iphones-unless-apple-pays-ransom?utm_source=vicefbus">https://motherboard.vice.com/en_us/article/hackers-we-will-remotely-wipe-iphones-unless-apple-pays-ransom?utm_source=vicefbus</a><br/>
Siemens Control Systems Affected by Fake Firmware<br/>
 <a href="https://dragos.com/blog/mimics/">https://dragos.com/blog/mimics/</a><br/>
GitHub Used for C&C<br/>
 <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/winnti-abuses-github/">http://blog.trendmicro.com/trendlabs-security-intelligence/winnti-abuses-github/</a><br/>
Adium IM Vulnerable to Older libpurple Issue<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Mar/57">http://seclists.org/fulldisclosure/2017/Mar/57</a><br/>
]]></description>
<itunes:duration>5:59
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5427" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5425</itunes:episode>
<itunes:subtitle>Password Encrypted Word File; Patch LastPass! NestCam DoS 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Password Encrypted Word File; Patch LastPass! NestCam DoS 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5425.mp3" length="4596357" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5425.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5425</link>
<pubDate>Wed, 22 Mar 2017 02:25:02 GMT</pubDate>
<description><![CDATA[Password Encrypted Word File Delivers Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+with+passwordprotected+Word+documents/22203/">https://isc.sans.edu/forums/diary/Malspam+with+passwordprotected+Word+documents/22203/</a><br/>
Critical LastPass Vulnerability<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1209">https://bugs.chromium.org/p/project-zero/issues/detail?id=1209</a><br/>
Nest Camera Bluetooth Vulnerability<br/>
 <a href="https://github.com/jasondoyle/Google-Nest-Cam-Bug-Disclosures/blob/master/README.md">https://github.com/jasondoyle/Google-Nest-Cam-Bug-Disclosures/blob/master/README.md</a><br/>
]]></description>
<itunes:duration>5:27
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5425" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5423</itunes:episode>
<itunes:subtitle>#Cisco CMP (Telnet!) RCE;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Cisco CMP (Telnet!) RCE;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5423.mp3" length="5058842" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5423.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5423</link>
<pubDate>Tue, 21 Mar 2017 02:50:02 GMT</pubDate>
<description><![CDATA[CISCO Releases Advisory With Details Regarding CMP Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170317-cmp</a><br/>
Pwn2Own Contest Leads to Exploits Against All Browsers (and VM!)<br/>
 <a href="https://www.zerodayinitiative.com/blog/2017/3/17/the-results-pwn2own-2017-day-three">https://www.zerodayinitiative.com/blog/2017/3/17/the-results-pwn2own-2017-day-three</a><br/>
Git Moving Away From SHA1 (likely to SHA3)<br/>
 <a href="https://news.ycombinator.com/item?id=13906804">https://news.ycombinator.com/item?id=13906804</a><br/>
Proxy Security<br/>
 <a href="https://isc.sans.edu/forums/diary/What+is+really+being+proxied/22165/">https://isc.sans.edu/forums/diary/What+is+really+being+proxied/22165/</a><br/>
 <a href="https://www.us-cert.gov/ncas/alerts/TA17-075A">https://www.us-cert.gov/ncas/alerts/TA17-075A</a><br/>
]]></description>
<itunes:duration>6:00
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5423" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5421</itunes:episode>
<itunes:subtitle>Multistage Downloader; Attacks Against ZRTP; MySQL-UNSHA1
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Multistage Downloader; Attacks Against ZRTP; MySQL-UNSHA1
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5421.mp3" length="4914414" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5421.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5421</link>
<pubDate>Mon, 20 Mar 2017 02:10:02 GMT</pubDate>
<description><![CDATA[An Example of a Multiple States Dropper<br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+Multiple+Stages+Dropper/22197/">https://isc.sans.edu/forums/diary/Example+of+Multiple+Stages+Dropper/22197/</a><br/>
Real-World Wiretaping Attacks Against ZRTP<br/>
 <a href="https://www.ibr.cs.tu-bs.de/papers/schuermann-popets2017.pdf">https://www.ibr.cs.tu-bs.de/papers/schuermann-popets2017.pdf</a><br/>
Authenticating Against MySQL Server Using a Hashed Password<br/>
 <a href="https://github.com/cyrus-and/mysql-unsha1">https://github.com/cyrus-and/mysql-unsha1</a><br/>
]]></description>
<itunes:duration>5:50
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5421" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5419</itunes:episode>
<itunes:subtitle>#Ubiquity Flaw; #MACOS RAT
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Ubiquity Flaw; #MACOS RAT
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5419.mp3" length="5107903" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5419.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5419</link>
<pubDate>Fri, 17 Mar 2017 03:05:02 GMT</pubDate>
<description><![CDATA[Certain Ubiquity Equipment Vulnerable to CSRF/Code Execution<br/>
 <a href="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170316-0_Ubiquiti_Networks_authenticated_command_injection_v10.txt">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170316-0_Ubiquiti_Networks_authenticated_command_injection_v10.txt</a><br/>
Proton Mac OS RAT<br/>
 <a href="https://www.cybersixgill.com/proton-a-new-mac-os-rat/">https://www.cybersixgill.com/proton-a-new-mac-os-rat/</a><br/>
Linux Kernel n_hdlc Privilege Escalation<br/>
 <a href="http://seclists.org/oss-sec/2017/q1/569">http://seclists.org/oss-sec/2017/q1/569</a><br/>
VMWare Copy/Paste Exploit Fixed<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2017-0005.html">https://www.vmware.com/security/advisories/VMSA-2017-0005.html</a><br/>
]]></description>
<itunes:duration>6:04
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5419" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5417</itunes:episode>
<itunes:subtitle>thecounter twitter hack; Telegram/WhatsApp Vulnerability
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
thecounter twitter hack; Telegram/WhatsApp Vulnerability
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5417.mp3" length="5490972" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5417.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5417</link>
<pubDate>Thu, 16 Mar 2017 03:05:02 GMT</pubDate>
<description><![CDATA[Twitter App "Twitter Counter" Compromise Leads to Unauthorized Tweets From a Large Number of Accounts<br/>
 <a href="https://twitter.com/thecounter">https://twitter.com/thecounter</a><br/>
Telegram and WhatsApp Image Vulnerability<br/>
 <a href="http://blog.checkpoint.com/2017/03/15/check-point-discloses-vulnerability-whatsapp-telegram/">http://blog.checkpoint.com/2017/03/15/check-point-discloses-vulnerability-whatsapp-telegram/</a><br/>
RSA Panel Webcast<br/>
 <a href="https://cc.readytalk.com/registration/#/?meeting=6oowksc223hm&campaign=ijmt1z8qsc1q">https://cc.readytalk.com/registration/#/?meeting=6oowksc223hm&campaign=ijmt1z8qsc1q</a><br/>
]]></description>
<itunes:duration>6:31
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5417" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5415</itunes:episode>
<itunes:subtitle>Microsoft's Double Patch Tuesday
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Microsoft's Double Patch Tuesday
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5415.mp3" length="4969073" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5415.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5415</link>
<pubDate>Wed, 15 Mar 2017 03:00:01 GMT</pubDate>
<description><![CDATA[Microsoft's Double Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/February+and+March+Microsoft+Patch+Tuesday/22185/">https://isc.sans.edu/forums/diary/February+and+March+Microsoft+Patch+Tuesday/22185/</a><br/>
]]></description>
<itunes:duration>5:54
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5415" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5413</itunes:episode>
<itunes:subtitle>#SHA3 Sigs; Webkit Attack Against Switch; Outdated JS Libs
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#SHA3 Sigs; Webkit Attack Against Switch; Outdated JS Libs
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5413.mp3" length="4807374" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5413.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5413</link>
<pubDate>Tue, 14 Mar 2017 01:10:02 GMT</pubDate>
<description><![CDATA[Creating SHA3 Hashes with sigs.py<br/>
 <a href="https://isc.sans.edu/forums/diary/New+tool+sigspy/22181/">https://isc.sans.edu/forums/diary/New+tool+sigspy/22181/</a><br/>
Canada Revenue Agency Website Attacked / Down over Struts2<br/>
 <a href="http://www.cbc.ca/news/politics/cra-internet-vulnerability-government-1.4022591">http://www.cbc.ca/news/politics/cra-internet-vulnerability-government-1.4022591</a><br/>
Webkit Exploit Adobted to Nintendo Switch<br/>
 <a href="https://www.youtube.com/watch?v=xkdPjbaLngE">https://www.youtube.com/watch?v=xkdPjbaLngE</a><br/>
Analysis of Outdated Javascript Libraries on the Web <br/>
 <a href="http://www.ccs.neu.edu/home/arshad/publications/ndss2017jslibs.pdf">http://www.ccs.neu.edu/home/arshad/publications/ndss2017jslibs.pdf</a><br/>
Github Enterprise SAML Authentication Bypass<br/>
 <a href="http://www.economyofmechanism.com/github-saml">http://www.economyofmechanism.com/github-saml</a><br/>
]]></description>
<itunes:duration>5:42
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5413" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5411</itunes:episode>
<itunes:subtitle>#GeoLocation Trouble; Mobile PIN Heat Signature;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#GeoLocation Trouble; Mobile PIN Heat Signature;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5411.mp3" length="5563535" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5411.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5411</link>
<pubDate>Mon, 13 Mar 2017 02:15:01 GMT</pubDate>
<description><![CDATA[Issues With Out Of Date Geo Location Databases<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Side+Effect+of+GeoIP+Filters/22173/">https://isc.sans.edu/forums/diary/The+Side+Effect+of+GeoIP+Filters/22173/</a><br/>
Recovering Mobile Device PINs via Thermal Images<br/>
 <a href="http://www.mkhamis.com/data/papers/abdelrahman2017chi.pdf">http://www.mkhamis.com/data/papers/abdelrahman2017chi.pdf</a><br/>
Unmasking Randomized MAC Addresses<br/>
 <a href="https://arxiv.org/abs/1703.02874v1">https://arxiv.org/abs/1703.02874v1</a><br/>
Mobile Phone Supply Chain Attacks<br/>
 <a href="http://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/">http://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/</a><br/>
]]></description>
<itunes:duration>6:36
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5411" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5409</itunes:episode>
<itunes:subtitle>#Struts2 Update; Drupal7 Services Module RCE; Haraka Xploit
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Struts2 Update; Drupal7 Services Module RCE; Haraka Xploit
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5409.mp3" length="4463469" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5409.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5409</link>
<pubDate>Fri, 10 Mar 2017 03:20:02 GMT</pubDate>
<description><![CDATA[Struts 2 Update<br/>
<a href="https://isc.sans.edu/forums/diary/Critical+Apache+Struts+2+Vulnerability+Patch+Now/22169/">https://isc.sans.edu/forums/diary/Critical+Apache+Struts+2+Vulnerability+Patch+Now/22169/</a><br/>
Exploits Against Haraka Mail Server<br/>
 <a href="https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py">https://github.com/outflanknl/Exploits/blob/master/harakiri-CVE-2016-1000282.py</a><br/>
 <br/>
Android Password Stealing Apps<br/>
 <a href="http://www.welivesecurity.com/2017/03/09/new-instagram-credentials-stealers-discovered-google-play/">http://www.welivesecurity.com/2017/03/09/new-instagram-credentials-stealers-discovered-google-play/</a><br/>
Drupal Services Module Vulnerability and Exploit<br/>
 <a href="https://www.ambionics.io/blog/drupal-services-module-rce">https://www.ambionics.io/blog/drupal-services-module-rce</a><br/>
 <a href="https://www.drupal.org/node/2858847">https://www.drupal.org/node/2858847</a><br/>
]]></description>
<itunes:duration>5:18
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5409" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 9th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5407</itunes:episode>
<itunes:subtitle>Nintendo Switch; Patch Struts! Dockerscan
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Nintendo Switch; Patch Struts! Dockerscan
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5407.mp3" length="4733316" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5407.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5407</link>
<pubDate>Thu, 09 Mar 2017 02:30:03 GMT</pubDate>
<description><![CDATA[Security Researches Target Nintendo Switch<br/>
 <a href="https://twitter.com/qlutoo">https://twitter.com/qlutoo</a><br/>
 <a href="https://www.youtube.com/watch?v=CwdDN1kA93Q&feature=youtu.be">https://www.youtube.com/watch?v=CwdDN1kA93Q&feature=youtu.be</a><br/>
Dockerscan <br/>
 <a href="https://github.com/cr0hn/dockerscan">https://github.com/cr0hn/dockerscan</a><br/>
1 in 5 Websites still rely on SHA-1 Based Certificates<br/>
 <a href="http://www.theregister.co.uk/2017/03/08/sha1_certificate_survey/">http://www.theregister.co.uk/2017/03/08/sha1_certificate_survey/</a><br/>
Not All Malware Samples Are Complex<br/>
 <a href="https://isc.sans.edu/forums/diary/Not+All+Malware+Samples+Are+Complex/22163/">https://isc.sans.edu/forums/diary/Not+All+Malware+Samples+Are+Complex/22163/</a><br/>
Struts Vulnerability Included in Metasploit <br/>
 <a href="https://github.com/rapid7/metasploit-framework/issues/8064">https://github.com/rapid7/metasploit-framework/issues/8064</a><br/>
 <a href="https://cwiki.apache.org/confluence/display/WW/S2-045?from=groupmessage">https://cwiki.apache.org/confluence/display/WW/S2-045?from=groupmessage</a><br/>
]]></description>
<itunes:duration>5:37
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5407" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5405</itunes:episode>
<itunes:subtitle>#CIA Leak; #Shamoon now #Stonedrill;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#CIA Leak; #Shamoon now #Stonedrill;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5405.mp3" length="5629687" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5405.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5405</link>
<pubDate>Wed, 08 Mar 2017 02:50:02 GMT</pubDate>
<description><![CDATA[CIA Leak (note that link lead directly to leaked documents)<br/>
 <a href="https://wikileaks.com/ciav7p1/">https://wikileaks.com/ciav7p1/</a><br/>
From Shamoon To Stonedrill: Evolution of Wipers Attacking Saudi Organziations<br/>
 <a href="https://securelist.com/files/2017/03/Report_Shamoon_StoneDrill_final.pdf">https://securelist.com/files/2017/03/Report_Shamoon_StoneDrill_final.pdf</a><br/>
WordPress Update<br/>
 <a href="https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/">https://wordpress.org/news/2017/03/wordpress-4-7-3-security-and-maintenance-release/</a><br/>
Reading Secret Keys From SGX Enclaves<br/>
 <a href="https://arxiv.org/abs/1702.08719">https://arxiv.org/abs/1702.08719</a><br/>
]]></description>
<itunes:duration>6:41
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5405" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, March 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5403</itunes:episode>
<itunes:subtitle>#Typosquatting With Followup; #Apple to Fix iPhone #911 DDoS; Nextcloud Scan; Disconnect MyCloud
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Typosquatting With Followup; #Apple to Fix iPhone #911 DDoS; Nextcloud Scan; Disconnect MyCloud
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5403.mp3" length="5366162" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5403.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5403</link>
<pubDate>Tue, 07 Mar 2017 02:50:02 GMT</pubDate>
<description><![CDATA[Typosquatting Against Santander Bank in Brazil With Phone Call Follow-up<br/>
 <a href="https://isc.sans.edu/forums/diary/A+very+convincing+Typosquatting+Social+Engineering+campaign+is+targeting+Santander+corporate+customers+in+Brazil/22157/">https://isc.sans.edu/forums/diary/A+very+convincing+Typosquatting+Social+Engineering+campaign+is+targeting+Santander+corporate+customers+in+Brazil/22157/</a><br/>
Post Mortem on 911 DDoS Attack<br/>
 <a href="https://www.wsj.com/articles/how-a-cyberattack-overwhelmed-the-911-system-1488554972">https://www.wsj.com/articles/how-a-cyberattack-overwhelmed-the-911-system-1488554972</a><br/>
Nextcloud/Owncloud Scanner<br/>
 <a href="https://scan.nextcloud.com">https://scan.nextcloud.com</a><br/>
Western Digital MyCloud Vulnerability<br/>
 <a href="https://blog.exploitee.rs/2017/hacking_wd_mycloud/">https://blog.exploitee.rs/2017/hacking_wd_mycloud/</a><br/>
]]></description>
<itunes:duration>6:22
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5403" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, March 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5401</itunes:episode>
<itunes:subtitle>Malware Image Use Implicates Innocent Sites; Applying SHA1 Collisions to Bittorent
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Malware Image Use Implicates Innocent Sites; Applying SHA1 Collisions to Bittorent
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5401.mp3" length="5108468" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5401.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5401</link>
<pubDate>Mon, 06 Mar 2017 02:25:02 GMT</pubDate>
<description><![CDATA[How Your Pictures Affect Your Website Reputation<br/>
<a href="https://isc.sans.edu/forums/diary/How+your+pictures+may+affect+your+website+reputation/22151/">https://isc.sans.edu/forums/diary/How+your+pictures+may+affect+your+website+reputation/22151/</a><br/>
De-Obuscating Padded Code<br/>
<a href="https://isc.sans.edu/forums/diary/Another+example+of+maldoc+string+obfuscation+with+extra+bonus+UAC+bypass/22153/">https://isc.sans.edu/forums/diary/Another+example+of+maldoc+string+obfuscation+with+extra+bonus+UAC+bypass/22153/</a><br/>
FoxIT PDF Reader Vulnerability<br/>
<a href="https://www.foxitsoftware.com/support/security-bulletins.php#content-2017">https://www.foxitsoftware.com/support/security-bulletins.php#content-2017</a><br/>
Applying SHA1 Shatter Attack To Bittorent<br/>
<a href="https://biterrant.io">https://biterrant.io</a><br/>
Gargoyle Memory Scanning Evasion<br/>
<a href="https://jlospinoso.github.io/security/assembly/c/cpp/developing/software/2017/03/04/gargoyle-memory-analysis-evasion.html">https://jlospinoso.github.io/security/assembly/c/cpp/developing/software/2017/03/04/gargoyle-memory-analysis-evasion.html</a><br/>
Attacking Synergy Clients<br/>
<a href="https://www.n00py.io/2017/03/compromising-synergy-clients-with-a-rogue-synergy-server/">https://www.n00py.io/2017/03/compromising-synergy-clients-with-a-rogue-synergy-server/</a><br/>
]]></description>
<itunes:duration>6:04
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5401" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, March 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5399</itunes:episode>
<itunes:subtitle>#BEC and #SPF; Infected Developers Publish Android Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#BEC and #SPF; Infected Developers Publish Android Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5399.mp3" length="4619104" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5399.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5399</link>
<pubDate>Fri, 03 Mar 2017 02:15:02 GMT</pubDate>
<description><![CDATA[Business E-Mail Compromise and Sender Policy Framework Typos (SPF)<br/>
 <a href="https://isc.sans.edu/forums/diary/Phishing+for+Big+Money+Wire+Transfers+is+Still+Alive+and+Well+or+For+Want+of+Good+Punctuation+all+was+Lost/22141/">https://isc.sans.edu/forums/diary/Phishing+for+Big+Money+Wire+Transfers+is+Still+Alive+and+Well+or+For+Want+of+Good+Punctuation+all+was+Lost/22141/</a><br/>
Android Developers Infected With Malware Publishing Malicious Apps<br/>
 <a href="http://researchcenter.paloaltonetworks.com/2017/03/unit42-google-play-apps-infected-malicious-iframes/">http://researchcenter.paloaltonetworks.com/2017/03/unit42-google-play-apps-infected-malicious-iframes/</a><br/>
DBLTek GoIP Backdoor<br/>
 <a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/Undocumented-Backdoor-Account-in-DBLTek-GoIP/">https://www.trustwave.com/Resources/SpiderLabs-Blog/Undocumented-Backdoor-Account-in-DBLTek-GoIP/</a><br/>
Decrypting Findzip/Patcher Ransomware<br/>
 <a href="https://blog.malwarebytes.com/cybercrime/2017/02/decrypting-after-a-findzip-ransomware-infection/">https://blog.malwarebytes.com/cybercrime/2017/02/decrypting-after-a-findzip-ransomware-infection/</a><br/>
]]></description>
<itunes:duration>5:29
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5399" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, March 2nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5397</itunes:episode>
<itunes:subtitle>#LDAP and #STARTTLS; NextGen Gallery #SQLi; Breaking CAPTCHAS
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#LDAP and #STARTTLS; NextGen Gallery #SQLi; Breaking CAPTCHAS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5397.mp3" length="5059865" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5397.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5397</link>
<pubDate>Thu, 02 Mar 2017 02:55:02 GMT</pubDate>
<description><![CDATA[LDAP and STARTTLS<br/>
 <a href="https://isc.sans.edu/forums/diary/SSLTLS+on+port+389+Say+what/22135/">https://isc.sans.edu/forums/diary/SSLTLS+on+port+389+Say+what/22135/</a><br/>
Wordpress NextGen Gallery Plugin SQL Injection Vulnerability<br/>
 <a href="https://blog.sucuri.net/2017/02/sql-injection-vulnerability-nextgen-gallery-wordpress.html">https://blog.sucuri.net/2017/02/sql-injection-vulnerability-nextgen-gallery-wordpress.html</a><br/>
Password Manager Insecurities<br/>
 <a href="https://team-sik.org/trent_portfolio/password-manager-apps/">https://team-sik.org/trent_portfolio/password-manager-apps/</a><br/>
Slack Insecure Cross Window Messaging<br/>
 <a href="https://labs.detectify.com/2017/02/28/hacking-slack-using-postmessage-and-websocket-reconnect-to-steal-your-precious-token/">https://labs.detectify.com/2017/02/28/hacking-slack-using-postmessage-and-websocket-reconnect-to-steal-your-precious-token/</a><br/>
Google Voice Recognition Used to Break Google ReCaptcha Audio Challenge<br/>
 <a href="https://east-ee.com/2017/02/28/rebreakcaptcha-breaking-googles-recaptcha-v2-using-google/">https://east-ee.com/2017/02/28/rebreakcaptcha-breaking-googles-recaptcha-v2-using-google/</a><br/>
]]></description>
<itunes:duration>6:00
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5397" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, March 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5395</itunes:episode>
<itunes:subtitle>#AWS IPv4 Resuse; #AWS #S3 Outage;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#AWS IPv4 Resuse; #AWS #S3 Outage;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5395.mp3" length="4534961" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5395.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5395</link>
<pubDate>Wed, 01 Mar 2017 01:55:02 GMT</pubDate>
<description><![CDATA[Amazon Cloud IPv4 Reuse Leads to Stray Requests<br/>
 <a href="https://isc.sans.edu/forums/diary/My+Catch+Of+4+Months+In+The+Amazon+IP+Address+Space/22129">https://isc.sans.edu/forums/diary/My+Catch+Of+4+Months+In+The+Amazon+IP+Address+Space/22129</a><br/>
Amazon S3 Outage<br/>
 <a href="https://isc.sans.edu/forums/diary/Amazon+S3+Outage/22131/">https://isc.sans.edu/forums/diary/Amazon+S3+Outage/22131/</a><br/>
CloudPets Leaks Recordings<br/>
 <a href="https://www.troyhunt.com/data-from-connected-cloudpets-teddy-bears-leaked-and-ransomed-exposing-kids-voice-messages/">https://www.troyhunt.com/data-from-connected-cloudpets-teddy-bears-leaked-and-ransomed-exposing-kids-voice-messages/</a><br/>
ESET Antivirus Vulnerability Puts Macs at Risk<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Feb/68">http://seclists.org/fulldisclosure/2017/Feb/68</a><br/>
Analysis of a Simple PHP Backdoor<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+Simple+PHP+Backdoor/22127/">https://isc.sans.edu/forums/diary/Analysis+of+a+Simple+PHP+Backdoor/22127/</a><br/>
]]></description>
<itunes:duration>5:23
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5395" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 28th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5393</itunes:episode>
<itunes:subtitle>TLS 1.3 Bluecoat Issue
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
TLS 1.3 Bluecoat Issue
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5393.mp3" length="4990037" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5393.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5393</link>
<pubDate>Tue, 28 Feb 2017 02:10:02 GMT</pubDate>
<description><![CDATA[Google Chrome TLS 1.3 Update Causes Issues With Bluecoat<br/>
 <a href="https://bugs.chromium.org/p/chromium/issues/detail?id=694593">https://bugs.chromium.org/p/chromium/issues/detail?id=694593</a><br/>
Windows 10 Will Implmenet "Gatekeeper" Like Technology<br/>
 <a href="https://twitter.com/vitorgrs/status/835674417602637824">https://twitter.com/vitorgrs/status/835674417602637824</a><br/>
Google Releases E2EMail Chrome Plugin<br/>
 <a href="https://security.googleblog.com/2017/02/e2email-research-project-has-left-nest_24.html">https://security.googleblog.com/2017/02/e2email-research-project-has-left-nest_24.html</a><br/>
Decrypting SCOM "RunAs" Credentials<br/>
 <a href="https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2017/february/scomplicated-decrypting-scom-runas-credentials/">https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2017/february/scomplicated-decrypting-scom-runas-credentials/</a><br/>
]]></description>
<itunes:duration>5:55
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5393" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5391</itunes:episode>
<itunes:subtitle>Cloudflare Data Leak; Dynamite Phishing
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Cloudflare Data Leak; Dynamite Phishing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5391.mp3" length="4457111" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5391.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5391</link>
<pubDate>Mon, 27 Feb 2017 03:00:01 GMT</pubDate>
<description><![CDATA[Cloudflare Leaks Data<br/>
 <a href="https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/">https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/</a><br/>
IE/Edge Denial of Service<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1011#c2">https://bugs.chromium.org/p/project-zero/issues/detail?id=1011#c2</a><br/>
"Dynamite Phishing" <br/>
 <a href="https://isc.sans.edu/forums/diary/Dynamite+Phishing/22121/">https://isc.sans.edu/forums/diary/Dynamite+Phishing/22121/</a><br/>
Google Credentials Problems<br/>
 <a href="https://productforums.google.com/forum/#!category-topic/gmail/LOt2x1_c3KM">https://productforums.google.com/forum/#!category-topic/gmail/LOt2x1_c3KM</a><br/>
]]></description>
<itunes:duration>5:17
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5391" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5389</itunes:episode>
<itunes:subtitle>#SHA1 Collisions Found; Mirai Botnet Arrest
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#SHA1 Collisions Found; Mirai Botnet Arrest
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5389.mp3" length="4667922" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5389.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5389</link>
<pubDate>Fri, 24 Feb 2017 02:40:02 GMT</pubDate>
<description><![CDATA[Researchers Find SHA1 Collision<br/>
 <a href="https://shattered.io/static/shattered.pdf">https://shattered.io/static/shattered.pdf</a><br/>
Arrest Made in Deutsche Telekom DSL Modem Attack<br/>
 <a href="https://www.bleepingcomputer.com/news/security/uk-police-arrest-suspect-behind-mirai-malware-attacks-on-deutsche-telekom/">https://www.bleepingcomputer.com/news/security/uk-police-arrest-suspect-behind-mirai-malware-attacks-on-deutsche-telekom/</a><br/>
]]></description>
<itunes:duration>5:32
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5389" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 23rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5387</itunes:episode>
<itunes:subtitle>#Stethoscope for #MDM; #Firefox Fingerprinting; #JudasDNS
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Stethoscope for #MDM; #Firefox Fingerprinting; #JudasDNS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5387.mp3" length="4545253" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5387.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5387</link>
<pubDate>Thu, 23 Feb 2017 03:15:02 GMT</pubDate>
<description><![CDATA[User Centric Mobile Device Security With Stethoscope<br/>
 <a href="http://techblog.netflix.com/2017/02/introducing-netflix-stethoscope.html">http://techblog.netflix.com/2017/02/introducing-netflix-stethoscope.html</a><br/>
Fingerprinting Firefox With Intermediate Certificates<br/>
 <a href="https://shiftordie.de/blog/2017/02/21/fingerprinting-firefox-users-with-cached-intermediate-ca-certificates-fiprinca/">https://shiftordie.de/blog/2017/02/21/fingerprinting-firefox-users-with-cached-intermediate-ca-certificates-fiprinca/</a><br/>
JudasDNS Attack DNS Proxy<br/>
 <a href="https://github.com/mandatoryprogrammer/JudasDNS">https://github.com/mandatoryprogrammer/JudasDNS</a><br/>
]]></description>
<itunes:duration>5:23
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5387" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 22nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5385</itunes:episode>
<itunes:subtitle>MSFT Releases Flash Patch; Off-Primise #Wifi; #Bugdrop
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
MSFT Releases Flash Patch; Off-Primise #Wifi; #Bugdrop
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5385.mp3" length="4247072" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5385.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5385</link>
<pubDate>Wed, 22 Feb 2017 03:10:02 GMT</pubDate>
<description><![CDATA[Microsoft Releases Flash Patch From Skipped February Update<br/>
  <a href="https://technet.microsoft.com/en-us/library/security/MS17-005">https://technet.microsoft.com/en-us/library/security/MS17-005</a><br/>
Investigating Off-Premise Wireless Behaviour<br/>
 <a href="https://isc.sans.edu/forums/diary/Investigating+OffPremise+Wireless+Behaviour+or+I+Know+What+You+Connected+To/22089/">https://isc.sans.edu/forums/diary/Investigating+OffPremise+Wireless+Behaviour+or+I+Know+What+You+Connected+To/22089/</a><br/>
"Bugdrop" Steals Large Amount of Audio<br/>
 <a href="https://cyberx-labs.com/en/blog/operation-bugdrop-cyberx-discovers-large-scale-cyber-reconnaissance-operation/">https://cyberx-labs.com/en/blog/operation-bugdrop-cyberx-discovers-large-scale-cyber-reconnaissance-operation/</a><br/>
]]></description>
<itunes:duration>5:02
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5385" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 21st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5383</itunes:episode>
<itunes:subtitle>FTP Relay Postfix Hardening; Car Hacking; Xen Disclosure Policy
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
FTP Relay Postfix Hardening; Car Hacking; Xen Disclosure Policy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5383.mp3" length="4986345" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5383.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5383</link>
<pubDate>Tue, 21 Feb 2017 02:50:02 GMT</pubDate>
<description><![CDATA[Hardening Postfix Against FTP Relay Attacks<br/>
 <a href="https://isc.sans.edu/forums/diary/Hardening+Postfix+Against+FTP+Relay+Attacks/22086/">https://isc.sans.edu/forums/diary/Hardening+Postfix+Against+FTP+Relay+Attacks/22086/</a><br/>
Kaspersky Examins Mobile Car Apps<br/>
 <a href="https://securelist.com/analysis/publications/77576/mobile-apps-and-stealing-a-connected-car/">https://securelist.com/analysis/publications/77576/mobile-apps-and-stealing-a-connected-car/</a><br/>
Cars "Remember" Prior Owners<br/>
 <a href="http://money.cnn.com/2017/02/17/technology/used-car-hack-safety-location/">http://money.cnn.com/2017/02/17/technology/used-car-hack-safety-location/</a><br/>
Xen Project Reconsidering Vulnerability Disclosure Policy<br/>
 <a href="https://blog.xenproject.org/2017/02/14/request-for-comment-scope-of-vulnerabilities-for-which-xsas-are-issued/">https://blog.xenproject.org/2017/02/14/request-for-comment-scope-of-vulnerabilities-for-which-xsas-are-issued/</a><br/>
Stagefright Vulnerability had minimal affect on Android Security <br/>
 <a href="https://www.rsaconference.com/speakers/adrian_ludwig">https://www.rsaconference.com/speakers/adrian_ludwig</a><br/>
]]></description>
<itunes:duration>5:55
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5383" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5381</itunes:episode>
<itunes:subtitle>Backing up Router/Switch Config; #Windows #EMF #0Day
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Backing up Router/Switch Config; #Windows #EMF #0Day
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5381.mp3" length="4600406" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5381.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5381</link>
<pubDate>Mon, 20 Feb 2017 03:10:02 GMT</pubDate>
<description><![CDATA[RTRBK: Router, Switch, Firewall Backups in Powershell<br/>
 <a href="https://isc.sans.edu/forums/diary/RTRBK+Router+Switch+Firewall+Backups+in+PowerShell+tool+drop/22079/">https://isc.sans.edu/forums/diary/RTRBK+Router+Switch+Firewall+Backups+in+PowerShell+tool+drop/22079/</a><br/>
Windows EMF Imge 0-Day Memory Leak<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=992">https://bugs.chromium.org/p/project-zero/issues/detail?id=992</a><br/>
Brazillian Traffic Ticket Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Brazilian+malspam+sends+Autoitbased+malware/22081/">https://isc.sans.edu/forums/diary/Brazilian+malspam+sends+Autoitbased+malware/22081/</a><br/>
Using XXE To Send E-Mail<br/>
 <a href="https://shiftordie.de/blog/2017/02/18/smtp-over-xxe/">https://shiftordie.de/blog/2017/02/18/smtp-over-xxe/</a><br/>
]]></description>
<itunes:duration>5:27
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5381" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5379</itunes:episode>
<itunes:subtitle>#AVM Key Leak; #OpenSSL Update; MMU #ASLR Bypass
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#AVM Key Leak; #OpenSSL Update; MMU #ASLR Bypass
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5379.mp3" length="6022175" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5379.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5379</link>
<pubDate>Fri, 17 Feb 2017 06:35:02 GMT</pubDate>
<description><![CDATA[AVM Private Key Leak Puts Cable Modems At Risk<br/>
 <a href="https://isc.sans.edu/forums/diary/AVM+Private+Key+Leak+Puts+Cable+Modems+Worldwide+At+Risk/22076/">https://isc.sans.edu/forums/diary/AVM+Private+Key+Leak+Puts+Cable+Modems+Worldwide+At+Risk/22076/</a><br/>
OpenSSL Update<br/>
 <a href="https://isc.sans.edu/forums/diary/OpenSSL+110e+Update+No+need+to+panic+openssl/22074/">https://isc.sans.edu/forums/diary/OpenSSL+110e+Update+No+need+to+panic+openssl/22074/</a><br/>
Microsoft Update Delayed<br/>
 <a href="https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/">https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/</a><br/>
ANC Attack ASLR Bypass<br/>
 <a href="https://www.vusec.net/projects/anc/">https://www.vusec.net/projects/anc/</a><br/>
]]></description>
<itunes:duration>7:09
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5379" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5377</itunes:episode>
<itunes:subtitle>#RSAC2017; Collecting WiFi Client History; XAgent; Conference Phone
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#RSAC2017; Collecting WiFi Client History; XAgent; Conference Phone
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5377.mp3" length="4615406" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5377.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5377</link>
<pubDate>Thu, 16 Feb 2017 05:20:02 GMT</pubDate>
<description><![CDATA[How Was Your Stay At The Hotel La Playa<br/>
 <a href="https://isc.sans.edu/forums/diary/How+was+your+stay+at+the+Hotel+La+Playa/22069">https://isc.sans.edu/forums/diary/How+was+your+stay+at+the+Hotel+La+Playa/22069</a><br/>
XAgent OS X Malware<br/>
 <a href="https://labs.bitdefender.com/2017/02/new-xagent-mac-malware-linked-with-the-apt28/">https://labs.bitdefender.com/2017/02/new-xagent-mac-malware-linked-with-the-apt28/</a><br/>
Conference Phone Compromise <br/>
 <a href="https://www.contextis.com//resources/blog/phwning-boardroom-hacking-android-conference-phone/">https://www.contextis.com//resources/blog/phwning-boardroom-hacking-android-conference-phone/</a><br/>
]]></description>
<itunes:duration>5:28
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5377" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 15th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5375</itunes:episode>
<itunes:subtitle>#NoPatchTuesday; #Adobe &amp; #Websphere Patch; Operation Kingphish
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#NoPatchTuesday; #Adobe &amp; #Websphere Patch; Operation Kingphish
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5375.mp3" length="4868579" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5375.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5375</link>
<pubDate>Wed, 15 Feb 2017 04:00:02 GMT</pubDate>
<description><![CDATA[Microsoft Cancels Patch Tuesday<br/>
 <a href="https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/">https://blogs.technet.microsoft.com/msrc/2017/02/14/february-2017-security-update-release/</a><br/>
Adobe Update For Flash<br/>
 <a href="https://helpx.adobe.com/security/products/flash-player/apsb17-04.html">https://helpx.adobe.com/security/products/flash-player/apsb17-04.html</a><br/>
WebSephere Update<br/>
 <a href="http://www-01.ibm.com/support/docview.wss?uid=swg21997743">http://www-01.ibm.com/support/docview.wss?uid=swg21997743</a><br/>
Operation Kingphish<br/>
 <a href="https://medium.com/amnesty-insights/operation-kingphish-uncovering-a-campaign-of-cyber-attacks-against-civil-society-in-qatar-and-aa40c9e08852#.965et86vk">https://medium.com/amnesty-insights/operation-kingphish-uncovering-a-campaign-of-cyber-attacks-against-civil-society-in-qatar-and-aa40c9e08852#.965et86vk</a><br/>
Hacking Node-Serialize<br/>
 <a href="http://blog.websecurify.com/2017/02/hacking-node-serialize.html">http://blog.websecurify.com/2017/02/hacking-node-serialize.html</a><br/>
]]></description>
<itunes:duration>5:46
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5375" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 14th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5373</itunes:episode>
<itunes:subtitle>#Packettotal; Simple Static Malware Analyzer #SSMA
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Packettotal; Simple Static Malware Analyzer #SSMA
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5373.mp3" length="4604675" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5373.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5373</link>
<pubDate>Tue, 14 Feb 2017 02:50:02 GMT</pubDate>
<description><![CDATA[New Tool: Packettotal.com<br/>
 <a href="http://www.packettotal.com">http://www.packettotal.com</a><br/>
What Not To Decrypt When Intercepting SSL<br/>
 <a href="https://isc.sans.edu/forums/diary/Stuff+I+Learned+Decrypting/22059/">https://isc.sans.edu/forums/diary/Stuff+I+Learned+Decrypting/22059/</a><br/>
 webcast: <a href="https://www.sans.org/webcasts/8-ways-watch-invisible-analyzing-encrypted-network-traffic-103277">https://www.sans.org/webcasts/8-ways-watch-invisible-analyzing-encrypted-network-traffic-103277</a><br/>
Simple Static Malware Analyzer<br/>
 <a href="https://github.com/secrary/SSMA">https://github.com/secrary/SSMA</a><br/>
Critical Firefox for Android Vulnerability<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2017-04/">https://www.mozilla.org/en-US/security/advisories/mfsa2017-04/</a><br/>
Ubuntu ntfs-3g Privilege Escalation<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1072">https://bugs.chromium.org/p/project-zero/issues/detail?id=1072</a><br/>
Microsoft Patch Tuesday Changes<br/>
 <a href="http://www.infoworld.com/article/3139922/microsoft-windows/microsoft-to-revamp-its-documentation-for-security-patches.html">http://www.infoworld.com/article/3139922/microsoft-windows/microsoft-to-revamp-its-documentation-for-security-patches.html</a><br/>
]]></description>
<itunes:duration>5:28
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5373" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5371</itunes:episode>
<itunes:subtitle>#Samsung #KNOX Patch; #MongoDB Audit; Crypto in #PHP
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Samsung #KNOX Patch; #MongoDB Audit; Crypto in #PHP
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5371.mp3" length="5022962" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5371.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5371</link>
<pubDate>Mon, 13 Feb 2017 02:15:02 GMT</pubDate>
<description><![CDATA[Vulnerabilities in Samsung KNOX<br/>
<a href="https://googleprojectzero.blogspot.de/2017/02/lifting-hyper-visor-bypassing-samsungs.html">https://googleprojectzero.blogspot.de/2017/02/lifting-hyper-visor-bypassing-samsungs.html</a><br/>
Auditing MongoDB Configurations<br/>
 <a href="https://github.com/stampery/mongoaudit">https://github.com/stampery/mongoaudit</a><br/>
Reversing Javascript<br/>
 <a href="https://isc.sans.edu/forums/diary/Analysis+of+a+Suspicious+Piece+of+JavaScript/22056/">https://isc.sans.edu/forums/diary/Analysis+of+a+Suspicious+Piece+of+JavaScript/22056/</a><br/>
Wordpress REST API Flaw Widely Exploited<br/>
 <a href="https://www.wordfence.com/blog/2017/02/rapid-growth-in-rest-api-defacements/">https://www.wordfence.com/blog/2017/02/rapid-growth-in-rest-api-defacements/</a><br/>
Cryptographically Secure PHP Development<br/>
 <a href="https://paragonie.com/blog/2017/02/cryptographically-secure-php-development">https://paragonie.com/blog/2017/02/cryptographically-secure-php-development</a><br/>
DEV522 Web Application Security Essentials<br/>
 <a href="https://www.sans.org/event/sans-2017/course/defending-web-applications-security-essentials">https://www.sans.org/event/sans-2017/course/defending-web-applications-security-essentials</a><br/>
]]></description>
<itunes:duration>5:57
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5371" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5369</itunes:episode>
<itunes:subtitle>#Ticketbleed F5 #TLS Vulnerability; Malware Update; #iCloud Retaining Deleted Browser History
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Ticketbleed F5 #TLS Vulnerability; Malware Update; #iCloud Retaining Deleted Browser History
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5369.mp3" length="5267917" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5369.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5369</link>
<pubDate>Fri, 10 Feb 2017 02:10:02 GMT</pubDate>
<description><![CDATA[F5 Big IP Ticketbleed Vulnerability<br/>
<a href="https://filippo.io/Ticketbleed/">https://filippo.io/Ticketbleed/</a><br/>
CryptoShield Ransomware from Rig EK<br/>
 <a href="https://isc.sans.edu/forums/diary/CryptoShield+Ransomware+from+Rig+EK/22047/">https://isc.sans.edu/forums/diary/CryptoShield+Ransomware+from+Rig+EK/22047/</a><br/>
Hancitor/Pony Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/HancitorPony+malspam/22053/">https://isc.sans.edu/forums/diary/HancitorPony+malspam/22053/</a><br/>
Apple Retaining Old Browser History Data<br/>
 <a href="https://blog.elcomsoft.com/2017/02/elcomsoft-extracts-deleted-safari-browsing-history-from-icloud/#more-3769">https://blog.elcomsoft.com/2017/02/elcomsoft-extracts-deleted-safari-browsing-history-from-icloud/#more-3769</a><br/>
Brute Forcing LUKS Passwords<br/>
 <a href="https://0x00sec.org/t/breaking-encryption-hashed-passwords-luks-devices/811">https://0x00sec.org/t/breaking-encryption-hashed-passwords-luks-devices/811</a><br/>
]]></description>
<itunes:duration>6:15
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5369" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 9th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5367</itunes:episode>
<itunes:subtitle>Cloud Metadata URLs; #Intel Atom #C2000 Fiasko; #MacOS Word Macro Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Cloud Metadata URLs; #Intel Atom #C2000 Fiasko; #MacOS Word Macro Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5367.mp3" length="5428049" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5367.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5367</link>
<pubDate>Thu, 09 Feb 2017 02:45:02 GMT</pubDate>
<description><![CDATA[Cloud Metadata URLs<br/>
 <a href="https://isc.sans.edu/forums/diary/Cloud+Metadata+Urls/22046/">https://isc.sans.edu/forums/diary/Cloud+Metadata+Urls/22046/</a><br/>
Intel Atom C2000 Chip Failures<br/>
 <a href="http://www.theregister.co.uk/2017/02/06/cisco_intel_decline_to_link_product_warning_to_faulty_chip/">http://www.theregister.co.uk/2017/02/06/cisco_intel_decline_to_link_product_warning_to_faulty_chip/</a><br/>
More W-2 Scams, Now Combined With Wire Transfer Scams<br/>
 <a href="https://nakedsecurity.sophos.com/2017/02/08/beware-the-latest-tax-season-spear-phishing-scam/">https://nakedsecurity.sophos.com/2017/02/08/beware-the-latest-tax-season-spear-phishing-scam/</a><br/>
Macro Malware Coming to MacOS<br/>
 <a href="https://objective-see.com/blog/blog_0x17.html">https://objective-see.com/blog/blog_0x17.html</a><br/>
]]></description>
<itunes:duration>6:26
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5367" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 8th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5365</itunes:episode>
<itunes:subtitle>Emoji Passwords; iOS Apps and TLS; Web Bluetooth; Spoofing GMail
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Emoji Passwords; iOS Apps and TLS; Web Bluetooth; Spoofing GMail
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5365.mp3" length="5972562" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5365.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5365</link>
<pubDate>Wed, 08 Feb 2017 00:30:02 GMT</pubDate>
<description><![CDATA[Using Emojis as Passwords<br/>
 <a href="https://isc.sans.edu/forums/diary/My+Password+is+taco+Using+Emojis+for+Stronger+Passwords/22042/">https://isc.sans.edu/forums/diary/My+Password+is+taco+Using+Emojis+for+Stronger+Passwords/22042/</a><br/>
Popular iOS Applications Not Using TLS<br/>
 <a href="https://medium.com/@chronic_9612/76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-2c9a2409dd1#.nv0mf6w4e">https://medium.com/@chronic_9612/76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-2c9a2409dd1#.nv0mf6w4e</a><br/>
Web Bluetooth Security Model<br/>
 <a href="https://medium.com/@jyasskin/the-web-bluetooth-security-model-666b4e7eed2#.kqtxdk70h">https://medium.com/@jyasskin/the-web-bluetooth-security-model-666b4e7eed2#.kqtxdk70h</a><br/>
E-Mail Spoofing in GMail<br/>
 <a href="https://www.linkedin.com/pulse/aware-sender-spoofing-amongst-gmail-users-renato-marinho">https://www.linkedin.com/pulse/aware-sender-spoofing-amongst-gmail-users-renato-marinho</a><br/>
]]></description>
<itunes:duration>7:05
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5365" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, February 7th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5363</itunes:episode>
<itunes:subtitle>Defining "not malicious"; OpenBSD http server DoS; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Defining "not malicious"; OpenBSD http server DoS; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5363.mp3" length="4928835" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5363.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5363</link>
<pubDate>Tue, 07 Feb 2017 03:50:01 GMT</pubDate>
<description><![CDATA[Malicous or Not? Help Me Decide<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Or+Not+You+decide/22040/">https://isc.sans.edu/forums/diary/Malicious+Or+Not+You+decide/22040/</a><br/>
OpenBSD Http Server DoS Vulnerability<br/>
 <a href="https://pierrekim.github.io/blog/2017-02-07-openbsd-httpd-CVE-2017-5850.html">https://pierrekim.github.io/blog/2017-02-07-openbsd-httpd-CVE-2017-5850.html</a><br/>
Bypassing Tor Browser Via Windows DRM<br/>
 <a href="https://www.myhackerhouse.com/windows_drm_vs_torbrowser/">https://www.myhackerhouse.com/windows_drm_vs_torbrowser/</a><br/>
Freedom Hosting II Compromise<br/>
 <a href="https://www.scmagazineuk.com/major-dark-web-host-hacked-381000-sets-of-user-details-leaked-online/article/636259/">https://www.scmagazineuk.com/major-dark-web-host-hacked-381000-sets-of-user-details-leaked-online/article/636259/</a><br/>
]]></description>
<itunes:duration>5:51
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5363" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, February 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5361</itunes:episode>
<itunes:subtitle>Malware on #Pastebin; McAfee ePO Patch #sqlinj ; #Whatsapp used to spread malware
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Malware on #Pastebin; McAfee ePO Patch #sqlinj ; #Whatsapp used to spread malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5361.mp3" length="4612803" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5361.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5361</link>
<pubDate>Mon, 06 Feb 2017 02:20:02 GMT</pubDate>
<description><![CDATA[Base64 Encoded Malware Samples on Pastebin<br/>
 <a href="https://isc.sans.edu/forums/diary/Many+Malware+Samples+Found+on+Pastebin/22036/">https://isc.sans.edu/forums/diary/Many+Malware+Samples+Found+on+Pastebin/22036/</a><br/>
Cisco Recaling Meraki Access Points over Fatal Hardware Flaw<br/>
 <a href="http://www.cisco.com/c/en/us/support/web/clock-signal.html">http://www.cisco.com/c/en/us/support/web/clock-signal.html</a><br/>
SQL Injection Vulnerability in McAfee e Policy Orchastrator<br/>
 <a href="https://kc.mcafee.com/corporate/index?page=content&id=SB10187">https://kc.mcafee.com/corporate/index?page=content&id=SB10187</a><br/>
Update from Microsoft on SMB 3 Vulnerability<br/>
 <a href="https://threatpost.com/microsoft-waits-for-patch-tuesday-to-fix-smb-zero-day/123541/">https://threatpost.com/microsoft-waits-for-patch-tuesday-to-fix-smb-zero-day/123541/</a><br/>
Malicious Files Sent via Whatsapp to Target Indian Military<br/>
 <a href="http://economictimes.indiatimes.com/news/defence/defence-security-forces-alerted-against-whatsapp-virus/articleshow/56258702.cms">http://economictimes.indiatimes.com/news/defence/defence-security-forces-alerted-against-whatsapp-virus/articleshow/56258702.cms</a><br/>
]]></description>
<itunes:duration>5:28
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5361" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, February 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5359</itunes:episode>
<itunes:subtitle>SMB 3 0-Day DoS Exploit; WordPress Update; Webroot BSOD
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
SMB 3 0-Day DoS Exploit; WordPress Update; Webroot BSOD
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5359.mp3" length="4600409" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5359.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5359</link>
<pubDate>Fri, 03 Feb 2017 00:10:02 GMT</pubDate>
<description><![CDATA[SMB 3 0-Day DoS Exploit<br/>
 <a href="https://isc.sans.edu/forums/diary/Windows+SMBv3+Denial+of+Service+Proof+of+Concept+0+Day+Exploit/22029/">https://isc.sans.edu/forums/diary/Windows+SMBv3+Denial+of+Service+Proof+of+Concept+0+Day+Exploit/22029/</a><br/>
WordPress Update Silently Fixes Security Flaw<br/>
 <a href="https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/">https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/</a><br/>
Webroot Update Patches BSOD Flaw<br/>
 <a href="https://community.webroot.com/t5/Product-Questions/BSOD-0x50-PAGE-FAULT-IN-NONPAGED-AREA/td-p/284302?sf54120672=1&sf54123115=1">https://community.webroot.com/t5/Product-Questions/BSOD-0x50-PAGE-FAULT-IN-NONPAGED-AREA/td-p/284302?sf54120672=1&sf54123115=1</a><br/>
Google Adds Support for Mandatory Two-Factor Authentication to G-Suite<br/>
 <a href="https://security.googleblog.com/2017/02/better-and-more-usable-protection-from.html">https://security.googleblog.com/2017/02/better-and-more-usable-protection-from.html</a><br/>
Cisco Prime Home Vulnerablity <br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-prime-home">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170201-prime-home</a><br/>
]]></description>
<itunes:duration>5:27
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5359" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, February 2nd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5357</itunes:episode>
<itunes:subtitle>#tcpdump update; #redis #CSRF; Compromised Machine Post Mortem 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#tcpdump update; #redis #CSRF; Compromised Machine Post Mortem 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5357.mp3" length="4210474" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5357.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5357</link>
<pubDate>Thu, 02 Feb 2017 03:30:02 GMT</pubDate>
<description><![CDATA[Multiple Vulnerabilites in tcpdump<br/>
 <a href="https://isc.sans.edu/forums/diary/Multiple+Vulnerabilities+in+tcpdump/22017/">https://isc.sans.edu/forums/diary/Multiple+Vulnerabilities+in+tcpdump/22017/</a><br/>
Quick Analysis of Data Left Available by Attackers<br/>
 <a href="https://isc.sans.edu/forums/diary/Quick+Analysis+of+Data+Left+Available+by+Attackers/22015/">https://isc.sans.edu/forums/diary/Quick+Analysis+of+Data+Left+Available+by+Attackers/22015/</a><br/>
Securing The Human Ouch! Newsletter<br/>
 <a href="https://securingthehuman.sans.org/ouch/">https://securingthehuman.sans.org/ouch/</a><br/>
Redis CSRF Vulnerability Exploit<br/>
 <a href="https://github.com/dxa4481/whatsinmyredis">https://github.com/dxa4481/whatsinmyredis</a>]]></description>
<itunes:duration>4:59
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5357" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, February 1st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5355</itunes:episode>
<itunes:subtitle>#UAC Bypass and #Keybase; #tcpdump vulnerable; Postscript showpage vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#UAC Bypass and #Keybase; #tcpdump vulnerable; Postscript showpage vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5355.mp3" length="4717015" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5355.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5355</link>
<pubDate>Wed, 01 Feb 2017 02:55:02 GMT</pubDate>
<description><![CDATA[Fileless UAC Bypass Used to Drop Keybase Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+Office+files+using+fileless+UAC+bypass+to+drop+KEYBASE+malware/22011/">https://isc.sans.edu/forums/diary/Malicious+Office+files+using+fileless+UAC+bypass+to+drop+KEYBASE+malware/22011/</a><br/>
Apple Removes Activation Lock Test Tool After Abuse<br/>
 <a href="https://www.macrumors.com/2017/01/30/activation-lock-website-used-in-hack/">https://www.macrumors.com/2017/01/30/activation-lock-website-used-in-hack/</a><br/>
Multiple Vulnerabilities in tcpdump<br/>
 <a href="https://www.debian.org/security/2017/dsa-3775">https://www.debian.org/security/2017/dsa-3775</a><br/>
Postscript Printer Vulnerabilities<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Jan/89">http://seclists.org/fulldisclosure/2017/Jan/89</a><br/>
Stop Disabling SELinux <br/>
 <a href="https://learntemail.sam.today/blog/stop-disabling-selinux:-a-real-world-guide/">https://learntemail.sam.today/blog/stop-disabling-selinux:-a-real-world-guide/</a><br/>
]]></description>
<itunes:duration>5:36
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5355" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 31st 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5353</itunes:episode>
<itunes:subtitle>Decompiling #py2exe; Leaked Calls; #FB introduces delegated recovery
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Decompiling #py2exe; Leaked Calls; #FB introduces delegated recovery
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5353.mp3" length="5561318" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5353.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5353</link>
<pubDate>Tue, 31 Jan 2017 12:55:02 GMT</pubDate>
<description><![CDATA[py2exe Decompiling Part 2<br/>
<a href="https://isc.sans.edu/forums/diary/py2exe+Decompiling+Part+2/22005/">https://isc.sans.edu/forums/diary/py2exe+Decompiling+Part+2/22005/</a><br/>
Telemarketer Leaks Call Recordings<br/>
 <a href="https://mackeeper.com/blog/post/326-telemarketing-company-leaks-400k-of-sensitive-files">https://mackeeper.com/blog/post/326-telemarketing-company-leaks-400k-of-sensitive-files</a><br/>
Facebook Introduces Delegated Recovery Protocol<br/>
 <a href="https://github.com/facebookincubator/DelegatedRecovery/">https://github.com/facebookincubator/DelegatedRecovery/</a><br/>
 <a href="https://raw.githubusercontent.com/facebookincubator/DelegatedRecovery/master/draft-hill-delegated-recovery.raw.txt">https://raw.githubusercontent.com/facebookincubator/DelegatedRecovery/master/draft-hill-delegated-recovery.raw.txt</a><br/>
Another Cisco WebEx Update<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170124-webex">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170124-webex</a><br/>
Cryptkeeper Does Not Correctly Encrypt Folders<br/>
 <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852751">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852751</a><br/>
]]></description>
<itunes:duration>6:36
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5353" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 30th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5351</itunes:episode>
<itunes:subtitle>DC Traffic Cams and #Hotel Locks Held #Ransom; #Android Not So Private #VPN Apps
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
DC Traffic Cams and #Hotel Locks Held #Ransom; #Android Not So Private #VPN Apps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5351.mp3" length="5632918" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5351.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5351</link>
<pubDate>Mon, 30 Jan 2017 03:15:02 GMT</pubDate>
<description><![CDATA[Port 5358 Scans for Devices<br/>
 <a href="https://isc.sans.edu/forums/diary/Request+for+Packets+and+Logs+TCP+5358/21997/">https://isc.sans.edu/forums/diary/Request+for+Packets+and+Logs+TCP+5358/21997/</a><br/>
OpenSSH Vulnerablity<br/>
 <a href="http://www.openwall.com/lists/oss-security/2017/01/26/2">http://www.openwall.com/lists/oss-security/2017/01/26/2</a><br/>
Ransomware Hits Traffic Cameras in DC<br/>
 <a href="https://www.washingtonpost.com/local/public-safety/hackers-hit-dc-police-closed-circuit-camera-network-city-officials-disclose/2017/01/27/d285a4a4-e4f5-11e6-ba11-63c4b4fb5a63_print.html">https://www.washingtonpost.com/local/public-safety/hackers-hit-dc-police-closed-circuit-camera-network-city-officials-disclose/2017/01/27/d285a4a4-e4f5-11e6-ba11-63c4b4fb5a63_print.html</a><br/>
Hotel Hit By Ransomware<br/>
 <a href="http://www.thelocal.at/20170128/hotel-ransomed-by-hackers-as-guests-locked-in-rooms">http://www.thelocal.at/20170128/hotel-ransomed-by-hackers-as-guests-locked-in-rooms</a><br/>
Not So Private Android VPNs<br/>
<a href="http://www.icir.org/vern/papers/vpn-apps-imc16.pdf">http://www.icir.org/vern/papers/vpn-apps-imc16.pdf</a><br/>
Google Starting its own Certificate Authority<br/>
<a href="https://security.googleblog.com/2017/01/the-foundation-of-more-secure-web.html">https://security.googleblog.com/2017/01/the-foundation-of-more-secure-web.html</a><br/>
]]></description>
<itunes:duration>6:41
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5351" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 27th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5349</itunes:episode>
<itunes:subtitle>Threatintel Automation Risks; Android Ransomware; WebEx Update
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Threatintel Automation Risks; Android Ransomware; WebEx Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5349.mp3" length="4711897" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5349.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5349</link>
<pubDate>Fri, 27 Jan 2017 01:20:01 GMT</pubDate>
<description><![CDATA[IOCs: Risks of False Positive Floods<br/>
 <a href="https://isc.sans.edu/forums/diary/IOCs+Risks+of+False+Positive+Alerts+Flood+Ahead/21977/">https://isc.sans.edu/forums/diary/IOCs+Risks+of+False+Positive+Alerts+Flood+Ahead/21977/</a><br/>
Android Ransomware in Google Play Store<br/>
 <a href="http://blog.checkpoint.com/2017/01/24/charger-malware/">http://blog.checkpoint.com/2017/01/24/charger-malware/</a><br/>
OpenSSL Update<br/>
 <a href="https://www.openssl.org/news/vulnerabilities.html#y2017">https://www.openssl.org/news/vulnerabilities.html#y2017</a><br/>
Facebook To Implement U2F (FIDO) Login<br/>
 <a href="https://www.facebook.com/notes/facebook-security/security-key-for-safer-logins-with-a-touch/10154125089265766">https://www.facebook.com/notes/facebook-security/security-key-for-safer-logins-with-a-touch/10154125089265766</a><br/>
WebEx Update<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1100">https://bugs.chromium.org/p/project-zero/issues/detail?id=1100</a><br/>
]]></description>
<itunes:duration>5:35
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5349" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 26th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5347</itunes:episode>
<itunes:subtitle>More Cisco WebEx News; Malicious #SVG Files; W2 Scams Are Back
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
More Cisco WebEx News; Malicious #SVG Files; W2 Scams Are Back
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5347.mp3" length="4906041" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5347.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5347</link>
<pubDate>Thu, 26 Jan 2017 02:20:01 GMT</pubDate>
<description><![CDATA[Cisco WebEx Remains Vulnerable. Other Browsers Affected<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170124-webex">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170124-webex</a><br/>
Malicious SVG Files Fund in the Wild<br/>
 <a href="https://isc.sans.edu/forums/diary/Malicious+SVG+Files+in+the+Wild/21971/">https://isc.sans.edu/forums/diary/Malicious+SVG+Files+in+the+Wild/21971/</a><br/>
W2 Scams Hitting Again<br/>
 <a href="http://www.nbcdfw.com/news/local/Argyle-ISD-Employees-Hit-with-Data-Breach-411337825.html">http://www.nbcdfw.com/news/local/Argyle-ISD-Employees-Hit-with-Data-Breach-411337825.html</a><br/>
XXE Entity Vulnerability in Uber<br/>
 <a href="https://httpsonly.blogspot.co.ke/2017/01/0day-writeup-xxe-in-ubercom.html?m=1">https://httpsonly.blogspot.co.ke/2017/01/0day-writeup-xxe-in-ubercom.html?m=1</a><br/>
Firefox 51 Released<br/>
 <a href="https://blog.mozilla.org/security/2017/01/20/communicating-the-dangers-of-non-secure-http/">https://blog.mozilla.org/security/2017/01/20/communicating-the-dangers-of-non-secure-http/</a><br/>
]]></description>
<itunes:duration>5:49
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5347" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 25th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5345</itunes:episode>
<itunes:subtitle>WebEx Plugin Fixed; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
WebEx Plugin Fixed; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5345.mp3" length="4577857" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5345.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5345</link>
<pubDate>Wed, 25 Jan 2017 04:35:01 GMT</pubDate>
<description><![CDATA[Cisco Releases Patch for Chrome Webex Plugin<br/>
 <a href="https://continuum.cisco.com/2017/01/23/its-a-good-idea-to-patch-your-webex-chrome-extension-now/">https://continuum.cisco.com/2017/01/23/its-a-good-idea-to-patch-your-webex-chrome-extension-now/</a><br/>
Companies Fall For Fake Ransomware<br/>
 <a href="https://www.citrix.com/blogs/2017/01/24/bluff-ransomware-attacks-bamboozle-british-businesses/">https://www.citrix.com/blogs/2017/01/24/bluff-ransomware-attacks-bamboozle-british-businesses/</a><br/>
systemd priviledge escalation vulnerablity<br/>
 <a href="http://www.openwall.com/lists/oss-security/2017/01/24/4">http://www.openwall.com/lists/oss-security/2017/01/24/4</a><br/>
nginx update released<br/>
 <a href="http://nginx.org/en/CHANGES">http://nginx.org/en/CHANGES</a><br/>
]]></description>
<itunes:duration>5:26
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5345" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 24th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5343</itunes:episode>
<itunes:subtitle>#IPv6 Fragments; #Apple Updates Everything; #WebEx Backdoor
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#IPv6 Fragments; #Apple Updates Everything; #WebEx Backdoor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5343.mp3" length="4799653" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5343.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5343</link>
<pubDate>Tue, 24 Jan 2017 02:50:02 GMT</pubDate>
<description><![CDATA[Experimenting With IPv6 Fragments<br/>
 <a href="https://isc.sans.edu/forums/diary/How+to+Have+Fun+With+IPv6+Fragments+and+Scapy/21963/">https://isc.sans.edu/forums/diary/How+to+Have+Fun+With+IPv6+Fragments+and+Scapy/21963/</a><br/>
Apple Updates Everything<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
WebEx Secret Install URL<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=1096">https://bugs.chromium.org/p/project-zero/issues/detail?id=1096</a><br/>
Vulnerability in Symantec Norton Download Manager<br/>
 <a href="https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2017&suid=20170117_00">https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2017&suid=20170117_00</a><br/>
Exploit for Microsoft RDC Client on Mac<br/>
 <a href="https://www.wearesegment.com/research/Microsoft-Remote-Desktop-Client-for-Mac-Remote-Code-Execution">https://www.wearesegment.com/research/Microsoft-Remote-Desktop-Client-for-Mac-Remote-Code-Execution</a><br/>
]]></description>
<itunes:duration>5:42
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5343" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 23rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5341</itunes:episode>
<itunes:subtitle>Sage 2.0 Ransomware; Starwars Twitter Bots; Symantec SSL Cert Problem
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Sage 2.0 Ransomware; Starwars Twitter Bots; Symantec SSL Cert Problem
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5341.mp3" length="4855233" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5341.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5341</link>
<pubDate>Mon, 23 Jan 2017 08:05:02 GMT</pubDate>
<description><![CDATA[Sage 2.0 Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/Sage+20+Ransomware/21959/">https://isc.sans.edu/forums/diary/Sage+20+Ransomware/21959/</a><br/>
Starwars Twitter Botner<br/>
 <a href="https://regmedia.co.uk/2017/01/20/starwarsbotnet.pdf">https://regmedia.co.uk/2017/01/20/starwarsbotnet.pdf</a><br/>
Symantec Messes Up SSL Certificates Again<br/>
<a href="https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/msg05455.html">https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/msg05455.html</a><br/>
Github CSP Experiences<br/>
 <a href="https://githubengineering.com/githubs-post-csp-journey/">https://githubengineering.com/githubs-post-csp-journey/</a><br/>
Podcast Survey<br/>
 <a href="https://www.surveymonkey.com/r/sbn2017">https://www.surveymonkey.com/r/sbn2017</a><br/>
]]></description>
<itunes:duration>5:46
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5341" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 20th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5339</itunes:episode>
<itunes:subtitle>Open Hadoop At Risk;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Open Hadoop At Risk;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5339.mp3" length="5213183" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5339.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5339</link>
<pubDate>Thu, 19 Jan 2017 20:50:02 GMT</pubDate>
<description><![CDATA[Open Hadoop Instances Are At Risk<br/>
 <a href="http://www.threatgeek.com/2017/01/open-hadoop-installs-wiped-worldwide.html">http://www.threatgeek.com/2017/01/open-hadoop-installs-wiped-worldwide.html</a><br/>
Upcoming SHA-1 Deadlines<br/>
 <a href="https://blog.mozilla.org/security/2016/10/18/phasing-out-sha-1-on-the-public-web/">https://blog.mozilla.org/security/2016/10/18/phasing-out-sha-1-on-the-public-web/</a> <br/>
Google "Verify Apps" Algorithm<br/>
 <a href="https://blog.google/topics/connected-workspaces/silence-speaks-louder-words-when-finding-malware/">https://blog.google/topics/connected-workspaces/silence-speaks-louder-words-when-finding-malware/</a><br/>
Practical JSONP Injection <br/>
 <a href="https://securitycafe.ro/2017/01/18/practical-jsonp-injection/">https://securitycafe.ro/2017/01/18/practical-jsonp-injection/</a><br/>
Necurs Decline Huring Loky Distribution<br/>
 <a href="http://blog.talosintel.com/2017/01/locky-struggles.html">http://blog.talosintel.com/2017/01/locky-struggles.html</a><br/>
]]></description>
<itunes:duration>6:11
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5339" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 19th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5337</itunes:episode>
<itunes:subtitle>US-Cert Considers Netbios/SMBv1 Harmfull; IPv6 Atomic Fragments
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
US-Cert Considers Netbios/SMBv1 Harmfull; IPv6 Atomic Fragments
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5337.mp3" length="5450594" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5337.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5337</link>
<pubDate>Wed, 18 Jan 2017 22:14:48 GMT</pubDate>
<description><![CDATA[US-Cert Considers Netbios/SMBv1 Harmfull<br/>
 <a href="https://www.us-cert.gov/ncas/current-activity/2017/01/16/SMB-Security-Best-Practices">https://www.us-cert.gov/ncas/current-activity/2017/01/16/SMB-Security-Best-Practices</a><br/>
IPv6 Atomic Fragments Can Lead to DDoS Attack<br/>
 <a href="https://tools.ietf.org/html/rfc8021">https://tools.ietf.org/html/rfc8021</a><br/>
Facebook Was Affectd by ImageTragick Flaw<br/>
 <a href="http://4lemon.ru/2017-01-17_facebook_imagetragick_remote_code_execution.html">http://4lemon.ru/2017-01-17_facebook_imagetragick_remote_code_execution.html</a><br/>
Malwarebytes Identifies Old Mac Backdoor<br/>
 <a href="https://blog.malwarebytes.com/threat-analysis/2017/01/new-mac-backdoor-using-antiquated-code/">https://blog.malwarebytes.com/threat-analysis/2017/01/new-mac-backdoor-using-antiquated-code/</a><br/>
Oracle Quarterly Critical Patch Update<br/>
<a href="http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA">http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA</a>]]></description>
<itunes:duration>6:28
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5337" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 18th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5335</itunes:episode>
<itunes:subtitle>Efficient Whois Lookups; Dovecot Passes Audit; Secrets in Mobile Apps
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Efficient Whois Lookups; Dovecot Passes Audit; Secrets in Mobile Apps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5335.mp3" length="4484029" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5335.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5335</link>
<pubDate>Tue, 17 Jan 2017 20:55:01 GMT</pubDate>
<description><![CDATA[domain_stats.py: A Web API For SEIM Phishing Hunts;<br/>
 <a href="https://isc.sans.edu/forums/diary/domainstatspy+a+web+api+for+SEIM+phishing+hunts/21943/">https://isc.sans.edu/forums/diary/domainstatspy+a+web+api+for+SEIM+phishing+hunts/21943/</a><br/>
Mutiple RCE in ZyXEL/Billion/True Online Routers<br/>
 <a href="http://seclists.org/fulldisclosure/2017/Jan/40">http://seclists.org/fulldisclosure/2017/Jan/40</a><br/>
Dovecot Passes Security Audit<br/>
 <a href="https://wiki.mozilla.org/images/4/4d/Dovecot-report.pdf">https://wiki.mozilla.org/images/4/4d/Dovecot-report.pdf</a><br/>
Dutch Web Developers Left Backdoors Behind<br/>
 <a href="http://www.theregister.co.uk/2017/01/17/police_warn_of_dutch_developer_who_built_backdoors_for_carding/">http://www.theregister.co.uk/2017/01/17/police_warn_of_dutch_developer_who_built_backdoors_for_carding/</a><br/>
Mobile Applications Contain Secrets<br/>
 <a href="https://hackernoon.com/we-reverse-engineered-16k-apps-heres-what-we-found-51bdf3b456bb">https://hackernoon.com/we-reverse-engineered-16k-apps-heres-what-we-found-51bdf3b456bb</a><br/>
]]></description>
<itunes:duration>5:19
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5335" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 17th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5333</itunes:episode>
<itunes:subtitle>Whitelisting #Apache Extension; #Wordpress 4.7.1 released;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Whitelisting #Apache Extension; #Wordpress 4.7.1 released;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5333.mp3" length="4602354" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5333.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5333</link>
<pubDate>Mon, 16 Jan 2017 20:50:02 GMT</pubDate>
<description><![CDATA[Whitelisting File Extensions in Apache<br/>
  <a href="https://isc.sans.edu/forums/diary/Whitelisting+File+Extensions+in+Apache/21937/">https://isc.sans.edu/forums/diary/Whitelisting+File+Extensions+in+Apache/21937/</a><br/>
Wordpress 4.7.1 Updates PHPMailer<br/>
 <a href="https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/">https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/</a><br/>
Tricky Phishing Attacks Harvesting Google Passwords<br/>
 <a href="https://www.wordfence.com/blog/2017/01/gmail-phishing-data-uri/">https://www.wordfence.com/blog/2017/01/gmail-phishing-data-uri/</a><br/>
More Refined Browser Fingerprinting Via GPU Features<br/>
 <a href="https://drive.google.com/file/d/0B4s900Byvv1ibW5uc1NiU2g3R3c/view">https://drive.google.com/file/d/0B4s900Byvv1ibW5uc1NiU2g3R3c/view</a><br/>
]]></description>
<itunes:duration>5:27
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5333" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 16th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5331</itunes:episode>
<itunes:subtitle>Evil Back Files; #Apache Server-Status; There is no Backdoor in #WhatsApp ; Injecting #Javascript in</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Evil Back Files; #Apache Server-Status; There is no Backdoor in #WhatsApp ; Injecting #Javascript in</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5331.mp3" length="6202467" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5331.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5331</link>
<pubDate>Sun, 15 Jan 2017 19:30:02 GMT</pubDate>
<description><![CDATA[Backup Files Are Good if They are Outside Your Web Servers Document Root<br/>
 <a href="https://isc.sans.edu/forums/diary/Backup+Files+Are+Good+but+Can+Be+Evil/21935/">https://isc.sans.edu/forums/diary/Backup+Files+Are+Good+but+Can+Be+Evil/21935/</a><br/>
Exploiting Apache Server Status<br/>
 <a href="http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html">http://blog.mazinahmed.net/2017/01/exploiting-misconfigured-apache-server-status-instances.html</a><br/>
WhatsApp  Backdoor  Controversy<br/>
 <a href="https://www.theguardian.com/technology/2017/jan/13/whatsapp-backdoor-allows-snooping-on-encrypted-messages">https://www.theguardian.com/technology/2017/jan/13/whatsapp-backdoor-allows-snooping-on-encrypted-messages</a><br/>
 <a href="https://whispersystems.org/blog/there-is-no-whatsapp-backdoor/">https://whispersystems.org/blog/there-is-no-whatsapp-backdoor/</a><br/>
Hardening Windows 10<br/>
 <a href="https://blogs.technet.microsoft.com/mmpc/2017/01/13/hardening-windows-10-with-zero-day-exploit-mitigations/">https://blogs.technet.microsoft.com/mmpc/2017/01/13/hardening-windows-10-with-zero-day-exploit-mitigations/</a><br/>
Injecting JavaScript Into PDFs<br/>
 <a href="http://insert-script.blogspot.in/2016/10/pdf-how-to-steal-pdfs-by-injecting.html">http://insert-script.blogspot.in/2016/10/pdf-how-to-steal-pdfs-by-injecting.html</a><br/>
]]></description>
<itunes:duration>7:22
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5331" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 13th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5329</itunes:episode>
<itunes:subtitle>Reading #SRUM Data; #Docker Updates; Exploiting #DNS Operational Issues; Updated SSL #CRL Data
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Reading #SRUM Data; #Docker Updates; Exploiting #DNS Operational Issues; Updated SSL #CRL Data
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5329.mp3" length="5444245" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5329.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5329</link>
<pubDate>Fri, 13 Jan 2017 02:00:02 GMT</pubDate>
<description><![CDATA[System Resources Utilization Monitor #SRUM<br/>
  <a href="https://isc.sans.edu/forums/diary/System+Resource+Utilization+Monitor/21927/">https://isc.sans.edu/forums/diary/System+Resource+Utilization+Monitor/21927/</a><br/>
Docker Fixes Privilege Escalation Vulnerability <br/>
 <a href="http://seclists.org/fulldisclosure/2017/Jan/21">http://seclists.org/fulldisclosure/2017/Jan/21</a><br/>
Taking Over Expired Name Servers<br/>
 <a href="https://thehackerblog.com/respect-my-authority-hijacking-broken-nameservers-to-compromise-your-target/">https://thehackerblog.com/respect-my-authority-hijacking-broken-nameservers-to-compromise-your-target/</a><br/>
Updated Certificate Revocation Data<br/>
  <a href="https://isc.sans.edu/crls.html">https://isc.sans.edu/crls.html</a><br/>
Shadow Broker Releasing More Tools and Going  Dark <br/>
  <a href="https://heimdalsecurity.com/blog/security-alert-the-shadow-brokers-windows-hacking-tools/">https://heimdalsecurity.com/blog/security-alert-the-shadow-brokers-windows-hacking-tools/</a><br/>
Extracting Fingerprints from Selfies<br/>
 <a href="http://www.japantimes.co.jp/news/2017/01/11/national/crime-legal/researchers-warn-fingerprint-theft-peace-sign/">http://www.japantimes.co.jp/news/2017/01/11/national/crime-legal/researchers-warn-fingerprint-theft-peace-sign/</a><br/>
]]></description>
<itunes:duration>6:28
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5329" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 12th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5327</itunes:episode>
<itunes:subtitle>Fake Parking Ticket Installing Backdoor; GoDaddy SSL Validation Bug; DVR Master Passwd List Leaked
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Fake Parking Ticket Installing Backdoor; GoDaddy SSL Validation Bug; DVR Master Passwd List Leaked
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5327.mp3" length="5113471" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5327.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5327</link>
<pubDate>Thu, 12 Jan 2017 02:10:02 GMT</pubDate>
<description><![CDATA[Hancitor/Pny/Vawtrak installed by Malicious Word Document in Fake Parking Ticket E-Mail<br/>
 <a href="https://isc.sans.edu/forums/diary/HancitorPonyVawtrak+malspam/21919/">https://isc.sans.edu/forums/diary/HancitorPonyVawtrak+malspam/21919/</a><br/>
Godaddy Revokes > 6,000 SSL Certs After Validation Bug<br/>
 <a href="https://www.godaddy.com/garage/godaddy/information-about-ssl-bug/">https://www.godaddy.com/garage/godaddy/information-about-ssl-bug/</a><br/>
DVR Master Password List Leaked<br/>
 <a href="https://www.pentestpartners.com/blog/leaked-dvr-creds-added-to-the-iot-fail-list/">https://www.pentestpartners.com/blog/leaked-dvr-creds-added-to-the-iot-fail-list/</a><br/>
Autofill Enables Information Leakage<br/>
 <a href="https://github.com/anttiviljami/browser-autofill-phishing">https://github.com/anttiviljami/browser-autofill-phishing</a><br/>
]]></description>
<itunes:duration>6:04
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5327" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 11th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5325</itunes:episode>
<itunes:subtitle>#MSFT and #Adobe Patches; Port 37777 "MapTable" Requests;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#MSFT and #Adobe Patches; Port 37777 "MapTable" Requests;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5325.mp3" length="4707512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5325.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5325</link>
<pubDate>Wed, 11 Jan 2017 03:05:01 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday Summary<br/>
 <a href="https://isc.sans.edu/forums/diary/January+2017+Microsoft+Patch+Tuesday/21915/">https://isc.sans.edu/forums/diary/January+2017+Microsoft+Patch+Tuesday/21915/</a><br/>
Adobe Patch Tuesday Summary<br/>
 <a href="https://isc.sans.edu/forums/diary/Adobe+January+2017+Patches/21917/">https://isc.sans.edu/forums/diary/Adobe+January+2017+Patches/21917/</a><br/>
Port 37777 "MapTable" Requests<br/>
 <a href="https://isc.sans.edu/forums/diary/Port+37777+MapTable+Requests/21913/">https://isc.sans.edu/forums/diary/Port+37777+MapTable+Requests/21913/</a><br/>
CVE 2016-7200/7201 Exploit Included in Sundown Exploit Kit<br/>
 <a href="http://malware.dontneedcoffee.com/2017/01/CVE-2016-7200-7201.html">http://malware.dontneedcoffee.com/2017/01/CVE-2016-7200-7201.html</a><br/>
]]></description>
<itunes:duration>5:35
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5325" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 10th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5323</itunes:episode>
<itunes:subtitle>DVWS: Experiment With WebSocket Vulns; Cracking Long Passwords; #VNC Library Update
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
DVWS: Experiment With WebSocket Vulns; Cracking Long Passwords; #VNC Library Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5323.mp3" length="4879156" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5323.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5323</link>
<pubDate>Mon, 09 Jan 2017 23:30:02 GMT</pubDate>
<description><![CDATA[Damn Vulnerable Web Sockets (DVWS) Demonstrates WebSocket Vulnerabilities<br/>
 <a href="https://github.com/interference-security/DVWS">https://github.com/interference-security/DVWS</a><br/>
St. Jude Medical Patches Vulnerable Cardiac Devices<br/>
 <a href="https://threatpost.com/st-jude-medical-patches-vulnerable-cardiac-devices/122955/">https://threatpost.com/st-jude-medical-patches-vulnerable-cardiac-devices/122955/</a><br/>
Cracking Hashes of Passwords 12 Characters and Longer<br/>
 <a href="http://www.netmux.com/blog/cracking-12-character-above-passwords">http://www.netmux.com/blog/cracking-12-character-above-passwords</a><br/>
VNC Library Update<br/>
 <a href="https://www.debian.org/security/2017/dsa-3753">https://www.debian.org/security/2017/dsa-3753</a><br/>
]]></description>
<itunes:duration>5:47
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5323" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, January 9th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5321</itunes:episode>
<itunes:subtitle>Careful With #Virustotal and Insecure Securitytools; Elaborate #Ransomware Scams
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Careful With #Virustotal and Insecure Securitytools; Elaborate #Ransomware Scams
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5321.mp3" length="4842741" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5321.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5321</link>
<pubDate>Mon, 09 Jan 2017 03:00:02 GMT</pubDate>
<description><![CDATA[Careful With Security Tools That Submit Files to Virustotal<br/>
 <a href="https://isc.sans.edu/forums/diary/Great+Misadventures+of+Security+Vendors+Absurd+Sandboxing+Edition/21895/">https://isc.sans.edu/forums/diary/Great+Misadventures+of+Security+Vendors+Absurd+Sandboxing+Edition/21895/</a><br/>
Vulnerable Security Tools Can Be Used Against You<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+Security+Tools+to+Compromize+a+Network/21903/">https://isc.sans.edu/forums/diary/Using+Security+Tools+to+Compromize+a+Network/21903/</a><br/>
Elaborate Ransomware Attacks<br/>
 <a href="http://www.actionfraud.police.uk/news/department-of-education-ransomware-alert-jan17">http://www.actionfraud.police.uk/news/department-of-education-ransomware-alert-jan17</a><br/>
E-Mail and iTunes Popup Extortion<br/>
 <a href="https://blog.malwarebytes.com/101/mac-the-basics/2017/01/tech-support-scam-page-attempts-denial-of-service-via-mail-app/">https://blog.malwarebytes.com/101/mac-the-basics/2017/01/tech-support-scam-page-attempts-denial-of-service-via-mail-app/</a><br/>
]]></description>
<itunes:duration>5:45
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5321" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, January 6th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5319</itunes:episode>
<itunes:subtitle>Google.com.br DNS Hijack; Spreadshirt Attacked With Leaked Passwords; Ransomware Adds DDoS
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Google.com.br DNS Hijack; Spreadshirt Attacked With Leaked Passwords; Ransomware Adds DDoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5319.mp3" length="5074134" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5319.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5319</link>
<pubDate>Fri, 06 Jan 2017 01:40:02 GMT</pubDate>
<description><![CDATA[Google.com.br DNS Hijack<br/>
 <a href="https://www.linkedin.com/pulse/googlecombr-hacked-renato-marinho">https://www.linkedin.com/pulse/googlecombr-hacked-renato-marinho</a><br/>
Attackers Use Stolen Passwords To Take Over Spreadshirt.com Accounts.<br/>
 <a href="https://www.heise.de/security/meldung/Angriff-auf-Spreadshirt-Konten-3589579.html">https://www.heise.de/security/meldung/Angriff-auf-Spreadshirt-Konten-3589579.html</a> (sorry, only in German)<br/>
Ransomware Adding DDoS Component<br/>
 <a href="https://www.bleepingcomputer.com/news/security/firecrypt-ransomware-comes-with-a-ddos-component/">https://www.bleepingcomputer.com/news/security/firecrypt-ransomware-comes-with-a-ddos-component/</a><br/>
Old Malware Returning in Targeted Attacks<br/>
 <a href="https://blogs.forcepoint.com/security-labs/mm-core-memory-backdoor-returns-bigboss-and-sillygoose">https://blogs.forcepoint.com/security-labs/mm-core-memory-backdoor-returns-bigboss-and-sillygoose</a><br/>
]]></description>
<itunes:duration>6:01
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5319" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, January 5th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5317</itunes:episode>
<itunes:subtitle>Insecure #MonboDB Held Ransom; Android Updates; #XSHM To Find #Wordpress Inside 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Insecure #MonboDB Held Ransom; Android Updates; #XSHM To Find #Wordpress Inside 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5317.mp3" length="4548428" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5317.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5317</link>
<pubDate>Thu, 05 Jan 2017 02:10:02 GMT</pubDate>
<description><![CDATA[GRE Packets May Be Related To Linux Kernel Bug<br/>
  <a href="http://www.openwall.com/lists/oss-security/2016/10/13/11">http://www.openwall.com/lists/oss-security/2016/10/13/11</a><br/>
Insecure MongoDB Instances Hit By Fake Ransomware<br/>
 <a href="https://twitter.com/0xDUDE">https://twitter.com/0xDUDE</a><br/>
Android Security Update<br/>
 <a href="https://source.android.com/security/bulletin/2017-01-01.html">https://source.android.com/security/bulletin/2017-01-01.html</a><br/>
Identifying WordPress Websites on Local Networks<br/>
 <a href="https://www.netsparker.com/blog/web-security/bruteforce-wordpress-local-networks-xshm-attack/">https://www.netsparker.com/blog/web-security/bruteforce-wordpress-local-networks-xshm-attack/</a><br/>
]]></description>
<itunes:duration>5:24
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5317" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, January 4th 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5315</itunes:episode>
<itunes:subtitle>Removing "Ransom Ware" From TVs; libpng Patch; Kaspersky AV SSL Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Removing "Ransom Ware" From TVs; libpng Patch; Kaspersky AV SSL Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5315.mp3" length="4195628" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5315.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5315</link>
<pubDate>Tue, 03 Jan 2017 23:35:02 GMT</pubDate>
<description><![CDATA[Removing "Ransom Ware" From Android Based LG TVs<br/>
 <a href="https://www.youtube.com/watch?v=0WZ4uLFTHEE">https://www.youtube.com/watch?v=0WZ4uLFTHEE</a><br/>
libpng Patches 30 Year Old Bug<br/>
 <a href="http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.567619">http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.567619</a><br/>
Kaspersky Antivirus SSL Interception Vulnerability<br/>
 <a href="https://bugs.chromium.org/p/project-zero/issues/detail?id=978">https://bugs.chromium.org/p/project-zero/issues/detail?id=978</a><br/>
Thunderbird Update Fixes Critical Vulnerability<br/>
 <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2016-96/">https://www.mozilla.org/en-US/security/advisories/mfsa2016-96/</a><br/>
]]></description>
<itunes:duration>4:58
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5315" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, January 3rd 2017</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5313</itunes:episode>
<itunes:subtitle>Leap Second Errors; #ATT Shutting Down 2G; iMessage Vuln; Truffle Hog
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Leap Second Errors; #ATT Shutting Down 2G; iMessage Vuln; Truffle Hog
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5313.mp3" length="4299065" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5313.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5313</link>
<pubDate>Tue, 03 Jan 2017 01:50:01 GMT</pubDate>
<description><![CDATA[AT&T 2G Network Shutdown<br/>
 <a href="https://www.att.com/esupport/article.html#!/wireless/KM1084805">https://www.att.com/esupport/article.html#!/wireless/KM1084805</a><br/>
Leap Second<br/>
 <a href="https://blog.cloudflare.com/how-and-why-the-leap-second-affected-cloudflare-dns/">https://blog.cloudflare.com/how-and-why-the-leap-second-affected-cloudflare-dns/</a><br/>
Thunderbird Patch<br/>
 <a href="https://www.heise.de/security/meldung/Thunderbird-Mozilla-schliesst-mit-Sicherheitsupdate-kritische-Luecken-3583472.html">https://www.heise.de/security/meldung/Thunderbird-Mozilla-schliesst-mit-Sicherheitsupdate-kritische-Luecken-3583472.html</a><br/>
iMessage Crash<br/>
 <a href="https://vincedes3.com/crash-message-app-iphone/">https://vincedes3.com/crash-message-app-iphone/</a><br/>
Truffle Hog<br/>
 <a href="https://github.com/dxa4481/truffleHog">https://github.com/dxa4481/truffleHog</a><br/>
]]></description>
<itunes:duration>5:06
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5313" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 30th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5311</itunes:episode>
<itunes:subtitle>Protocol 47 (GRE) Traffic; US-CERT Releases Russian IoCs; Android #Switcher Malware
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Protocol 47 (GRE) Traffic; US-CERT Releases Russian IoCs; Android #Switcher Malware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5311.mp3" length="3332628" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5311.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5311</link>
<pubDate>Fri, 30 Dec 2016 00:00:02 GMT</pubDate>
<description><![CDATA[Protocol 47 (GRE) Traffic<br/>
 <a href="https://isc.sans.edu/forums/diary/Increase+in+Protocol+47+denys/21865/">https://isc.sans.edu/forums/diary/Increase+in+Protocol+47+denys/21865/</a><br/>
US Cert Releases "Grizzly Steppe" Report<br/>
 <a href="https://www.us-cert.gov/security-publications/GRIZZLY-STEPPE-Russian-Malicious-Cyber-Activity">https://www.us-cert.gov/security-publications/GRIZZLY-STEPPE-Russian-Malicious-Cyber-Activity</a><br/>
Android Malware Changes Router DNS Settings<br/>
 <a href="https://securelist.com/blog/mobile/76969/switcher-android-joins-the-attack-the-router-club/">https://securelist.com/blog/mobile/76969/switcher-android-joins-the-attack-the-router-club/</a><br/>
]]></description>
<itunes:duration>3:57
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5311" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 29th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5309</itunes:episode>
<itunes:subtitle>More PHPMailer Issues; Picking Smart Locks; #IPv6 Scanning
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
More PHPMailer Issues; Picking Smart Locks; #IPv6 Scanning
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5309.mp3" length="4215346" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5309.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5309</link>
<pubDate>Thu, 29 Dec 2016 00:25:02 GMT</pubDate>
<description><![CDATA[More PHPMailer Issues. Update Again<br/>
 <a href="https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities">https://github.com/PHPMailer/PHPMailer/wiki/About-the-CVE-2016-10033-and-CVE-2016-10045-vulnerabilities</a><br/>
CCC Talk: Lockpicking in the IoT<br/>
 <a href="https://media.ccc.de/v/33c3-8019-lockpicking_in_the_iot">https://media.ccc.de/v/33c3-8019-lockpicking_in_the_iot</a><br/>
CCC Talk: IPv6 Scanning <br/>
 <a href="https://media.ccc.de/v/33c3-8061-you_can_-j_reject_but_you_can_not_hide_global_scanning_of_the_ipv6_internet">https://media.ccc.de/v/33c3-8061-you_can_-j_reject_but_you_can_not_hide_global_scanning_of_the_ipv6_internet</a><br/>
]]></description>
<itunes:duration>5:00
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5309" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 28th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5307</itunes:episode>
<itunes:subtitle>Manipulating Airline Bookings; PHPMailer Exploit; Signal Uses Domain Fronting 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Manipulating Airline Bookings; PHPMailer Exploit; Signal Uses Domain Fronting 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5307.mp3" length="4664977" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5307.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5307</link>
<pubDate>Wed, 28 Dec 2016 00:30:02 GMT</pubDate>
<description><![CDATA[Using Daemonlogger as a Software Tap<br/>
 <a href="https://isc.sans.edu/forums/diary/Using+daemonlogger+as+a+Software+Tap/21859/">https://isc.sans.edu/forums/diary/Using+daemonlogger+as+a+Software+Tap/21859/</a><br/>
CCC Conference<br/>
 <a href="https://events.ccc.de/congress/2016/wiki/Main_Page">https://events.ccc.de/congress/2016/wiki/Main_Page</a><br/>
PHPMailer Exploit Released<br/>
 <a href="https://legalhackers.com/exploits/CVE-2016-10033/PHPMailer-RCE-exploit-poc.txt">https://legalhackers.com/exploits/CVE-2016-10033/PHPMailer-RCE-exploit-poc.txt</a><br/>
Patch For Exim Mail Server<br/>
 <a href="https://exim.org/static/doc/CVE-2016-9963.txt">https://exim.org/static/doc/CVE-2016-9963.txt</a><br/>
Signal Uses  Domain Fronting  To Evade Censor Ship<br/>
 <a href="https://whispersystems.org/blog/doodles-stickers-censorship/">https://whispersystems.org/blog/doodles-stickers-censorship/</a><br/>
]]></description>
<itunes:duration>5:32
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5307" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 27th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5305</itunes:episode>
<itunes:subtitle>#PHPMailer Flaw; Malware Using Ping Delay; #Apple Extends TLS Deadline
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#PHPMailer Flaw; Malware Using Ping Delay; #Apple Extends TLS Deadline
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5305.mp3" length="5084857" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5305.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5305</link>
<pubDate>Tue, 27 Dec 2016 00:30:22 GMT</pubDate>
<description><![CDATA[Criticial RCE Flaw in PHPMailer<br/>
 <a href="https://isc.sans.edu/forums/diary/Critical+security+update+PHPMailer+5218+CVE201610033/21855/">https://isc.sans.edu/forums/diary/Critical+security+update+PHPMailer+5218+CVE201610033/21855/</a><br/>
Malware Delays Execution with "Ping"<br/>
 <a href="https://isc.sans.edu/forums/diary/Pinging+All+The+Way/21849/">https://isc.sans.edu/forums/diary/Pinging+All+The+Way/21849/</a><br/>
Apple Extends TLS Deadline<br/>
 <a href="https://isc.sans.edu/forums/diary/Pinging+All+The+Way/21849/">https://isc.sans.edu/forums/diary/Pinging+All+The+Way/21849/</a><br/>
]]></description>
<itunes:duration>6:02
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5305" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 22nd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5303</itunes:episode>
<itunes:subtitle>#Mirai keeps shifting; #Ukraine Power Issues; #OutMine Hacks @Netflix; #Methbot
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Mirai keeps shifting; #Ukraine Power Issues; #OutMine Hacks @Netflix; #Methbot
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5303.mp3" length="3896854" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5303.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5303</link>
<pubDate>Wed, 21 Dec 2016 23:20:02 GMT</pubDate>
<description><![CDATA[Mirai Trying Various Telnet Alternatives<br/>
 <a href="https://isc.sans.edu/forums/diary/UPDATED+x1+Mirai+Scanning+for+Port+6789+Looking+for+New+Victims+Now+hitting+tcp23231/21833/">https://isc.sans.edu/forums/diary/UPDATED+x1+Mirai+Scanning+for+Port+6789+Looking+for+New+Victims+Now+hitting+tcp23231/21833/</a><br/>
Ukraining Power Outages<br/>
 <a href="http://uawire.org/news/ukrenergo-claims-that-blackouts-in-kyiv-could-have-been-caused-by-hackers">http://uawire.org/news/ukrenergo-claims-that-blackouts-in-kyiv-could-have-been-caused-by-hackers</a><br/>
OurMine Hacks Netflix and Other Twitter Accounts<br/>
 <a href="http://www.bbc.com/news/technology-38390343?ocid=socialflow_twitter">http://www.bbc.com/news/technology-38390343?ocid=socialflow_twitter</a><br/>
Methbot Generating Millions of Dollars With Click Fraud<br/>
 <a href="http://go.whiteops.com/rs/179-SQE-823/images/WO_Methbot_Operation_WP.pdf">http://go.whiteops.com/rs/179-SQE-823/images/WO_Methbot_Operation_WP.pdf</a><br/>
]]></description>
<itunes:duration>4:37
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5303" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 21st 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5301</itunes:episode>
<itunes:subtitle>vSphere Data Protection Known SSH Key; NMap 7.4 Released; SCCM Software Metering
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
vSphere Data Protection Known SSH Key; NMap 7.4 Released; SCCM Software Metering
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5301.mp3" length="4294201" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5301.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5301</link>
<pubDate>Wed, 21 Dec 2016 00:35:01 GMT</pubDate>
<description><![CDATA[vSphere Data Protection Known SSH Key<br/>
 <a href="http://www.vmware.com/security/advisories/VMSA-2016-0024.html">http://www.vmware.com/security/advisories/VMSA-2016-0024.html</a><br/>
nmap Update<br/>
 <a href="https://nmap.org/download.html">https://nmap.org/download.html</a><br/>
SCCM Software Metering<br/>
 <a href="https://www.fireeye.com/blog/threat-research/2016/12/do_you_see_what_icc.html">https://www.fireeye.com/blog/threat-research/2016/12/do_you_see_what_icc.html</a><br/>
CryptXXX Version 3 Decryptor Available<br/>
 <a href="https://noransom.kaspersky.com">https://noransom.kaspersky.com</a><br/>
Airline Inflight Entertainment System Hack<br/>
 <a href="http://blog.ioactive.com/2016/12/in-flight-hacking-system.html">http://blog.ioactive.com/2016/12/in-flight-hacking-system.html</a><br/>
SEC503, Intrusion Detection in Depth: Brussles January 16th-21st 2017<br/>
 <a href="https://www.sans.org/event/brussels-winter-2017/course/intrusion-detection-in-depth">https://www.sans.org/event/brussels-winter-2017/course/intrusion-detection-in-depth</a><br/>
]]></description>
<itunes:duration>5:05
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5301" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 20th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5299</itunes:episode>
<itunes:subtitle>Port 6789 Scans; OpenSSH Update; Google Releases Crypto Test Tool
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Port 6789 Scans; OpenSSH Update; Google Releases Crypto Test Tool
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5299.mp3" length="3615853" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5299.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5299</link>
<pubDate>Tue, 20 Dec 2016 01:00:02 GMT</pubDate>
<description><![CDATA[Mirai Likely Behind Port 6789 Scans. Yet Another Backdoor<br/>
 <a href="https://isc.sans.edu/forums/diary/Mirai+Scanning+for+Port+6789+Looking+for+New+Victims/21833/">https://isc.sans.edu/forums/diary/Mirai+Scanning+for+Port+6789+Looking+for+New+Victims/21833/</a><br/>
OpenSSH update<br/>
 <a href="https://www.openssh.com/releasenotes.html#7.4">https://www.openssh.com/releasenotes.html#7.4</a><br/>
Google Releases Tool to Audit Crypto Libraries<br/>
 <a href="https://security.googleblog.com/2016/12/project-wycheproof.html">https://security.googleblog.com/2016/12/project-wycheproof.html</a><br/>
Escaping A Restricted Shell<br/>
 <a href="https://humblesec.wordpress.com/2016/12/08/escaping-a-restricted-shell/">https://humblesec.wordpress.com/2016/12/08/escaping-a-restricted-shell/</a><br/>
]]></description>
<itunes:duration>4:17
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5299" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 19th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5297</itunes:episode>
<itunes:subtitle>Verizon Webmail #XSS; Limit Powershell Connections; Cerber Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Verizon Webmail #XSS; Limit Powershell Connections; Cerber Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5297.mp3" length="4953147" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5297.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5297</link>
<pubDate>Mon, 19 Dec 2016 02:25:01 GMT</pubDate>
<description><![CDATA[Verizon Webmail XSS Exploit<br/>
 <a href="https://randywestergren.com/persistent-xss-verizons-webmail-client/">https://randywestergren.com/persistent-xss-verizons-webmail-client/</a><br/>
Blocking Powershell Connections via Windows Firewall<br/>
 <a href="https://isc.sans.edu/forums/diary/Blocking+Powershell+Connection+via+Windows+Firewall/21829/">https://isc.sans.edu/forums/diary/Blocking+Powershell+Connection+via+Windows+Firewall/21829/</a><br/>
Exploit Kits Delivering Cerber Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/One+if+by+email+and+two+if+by+EK+The+Cerbers+are+coming/21823/">https://isc.sans.edu/forums/diary/One+if+by+email+and+two+if+by+EK+The+Cerbers+are+coming/21823/</a><br/>
More Security Companies joining "No More Ransom"<br/>
 <a href="https://www.nomoreransom.org">https://www.nomoreransom.org</a><br/>
IT Contractor Trying to Take Over Radio Station<br/>
 <a href="https://regmedia.co.uk/2016/12/16/kcohvtaylorfiling.pdf">https://regmedia.co.uk/2016/12/16/kcohvtaylorfiling.pdf</a><br/>
Holiday Safe Computing Tips<br/>
 <a href="https://isc.sans.edu/forums/diary/Holiday+Safe+Computing+Tips/21827/">https://isc.sans.edu/forums/diary/Holiday+Safe+Computing+Tips/21827/</a><br/>
]]></description>
<itunes:duration>5:52
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5297" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 16th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5295</itunes:episode>
<itunes:subtitle>Domaincops Malware; FileVault2 Vulnerability; DNS Changer is Back
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Domaincops Malware; FileVault2 Vulnerability; DNS Changer is Back
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5295.mp3" length="4562967" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5295.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5295</link>
<pubDate>Fri, 16 Dec 2016 01:40:02 GMT</pubDate>
<description><![CDATA[Domain Cops Malware Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/Domaincop+malpsam/21821/">https://isc.sans.edu/forums/diary/Domaincop+malpsam/21821/</a><br/>
OS X Filevault Password Retrieval<br/>
 <a href="http://blog.frizk.net/2016/12/filevault-password-retrieval.html">http://blog.frizk.net/2016/12/filevault-password-retrieval.html</a><br/>
QEMU/Xen Vulnerability <br/>
 <a href="http://xenbits.xen.org/xsa/advisory-199.html">http://xenbits.xen.org/xsa/advisory-199.html</a><br/>
DNS Changer Attacking Home Routers<br/>
 <a href="https://www.proofpoint.com/us/threat-insight/post/home-routers-under-attack-malvertising-windows-android-devices">https://www.proofpoint.com/us/threat-insight/post/home-routers-under-attack-malvertising-windows-android-devices</a><br/>
]]></description>
<itunes:duration>5:25
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5295" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 15th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5293</itunes:episode>
<itunes:subtitle>#UAC Bypass JScript Dropper; Skype Desktop API Access; FB Cert. Transp. Monitor
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#UAC Bypass JScript Dropper; Skype Desktop API Access; FB Cert. Transp. Monitor
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5293.mp3" length="4609418" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5293.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5293</link>
<pubDate>Thu, 15 Dec 2016 02:05:02 GMT</pubDate>
<description><![CDATA[Malicious JavaScript Bypasses UAC<br/>
 <a href="https://isc.sans.edu/forums/diary/UAC+Bypass+in+JScript+Dropper/21813/">https://isc.sans.edu/forums/diary/UAC+Bypass+in+JScript+Dropper/21813/</a><br/>
Skype Unauthorized API Access Blocked<br/>
 <a href="https://www.trustwave.com/Resources/SpiderLabs-Blog/A-Backdoor-in-Skype-for-Mac-OS-X/?page=1&year=0&month=0">https://www.trustwave.com/Resources/SpiderLabs-Blog/A-Backdoor-in-Skype-for-Mac-OS-X/?page=1&year=0&month=0</a><br/>
Facebook Anounces Certificate Transparency Monitoring Tool<br/>
 <a href="https://www.facebook.com/notes/protect-the-graph/introducing-our-certificate-transparency-monitoring-tool/1811919779048165">https://www.facebook.com/notes/protect-the-graph/introducing-our-certificate-transparency-monitoring-tool/1811919779048165</a><br/>
Another Tor Browser (and Firefox) Bug Fixed<br/>
 <a href="https://blog.torproject.org/blog/tor-browser-608-released">https://blog.torproject.org/blog/tor-browser-608-released</a><br/>
Cheap Android Phones Arrive With Malware Preinstalled<br/>
 <a href="https://news.drweb.com/show/?i=10345&lng=en">https://news.drweb.com/show/?i=10345&lng=en</a><br/>
Exploit for Nagios <br/>
 <a href="https://legalhackers.com/advisories/Nagios-Exploit-Command-Injection-CVE-2016-9565-2008-4796.html">https://legalhackers.com/advisories/Nagios-Exploit-Command-Injection-CVE-2016-9565-2008-4796.html</a><br/>
]]></description>
<itunes:duration>5:28
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5293" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 14th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5291</itunes:episode>
<itunes:subtitle>#MSFT Patches; MacOS Updates; iOS Profile Vuln PoC Released; #Netgear Update
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#MSFT Patches; MacOS Updates; iOS Profile Vuln PoC Released; #Netgear Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5291.mp3" length="4240289" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5291.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5291</link>
<pubDate>Wed, 14 Dec 2016 04:00:03 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday + Adobe Flash<br/>
 <a href="https://isc.sans.edu/mspatchdays.html?viewday=2016-12-13">https://isc.sans.edu/mspatchdays.html?viewday=2016-12-13</a><br/>
Apple Updates<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
More Netgear Products Vulnerable; Beta Patch Available<br/>
 <a href="http://kb.netgear.com/000036386/CVE-2016-582384?cid=wmt_netgear_organic">http://kb.netgear.com/000036386/CVE-2016-582384?cid=wmt_netgear_organic</a><br/>
iOS Profile Vulnerability PoC Available<br/>
 <a href="https://cxsecurity.com/issue/WLB-2016110046">https://cxsecurity.com/issue/WLB-2016110046</a><br/>
]]></description>
<itunes:duration>5:02
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5291" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 13th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5289</itunes:episode>
<itunes:subtitle>#iOS, #tvos, #watchOS Patches; #McAfee AV Scan Vulnerabilities; Ransomware Snowball Marketing
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#iOS, #tvos, #watchOS Patches; #McAfee AV Scan Vulnerabilities; Ransomware Snowball Marketing
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5289.mp3" length="4910758" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5289.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5289</link>
<pubDate>Tue, 13 Dec 2016 01:10:02 GMT</pubDate>
<description><![CDATA[Apple Releases Patches for iOS/WatchOS and tvOS<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Windows 8/10 Update Causing DHCP Problems<br/>
 <a href="https://community.plus.net/t5/Broadband/Windows-8-10-Issues/m-p/1393675#M310992">https://community.plus.net/t5/Broadband/Windows-8-10-Issues/m-p/1393675#M310992</a><br/>
McAfee VirusScan Enterprise for Linux Vulnerabilities<br/>
 <a href="https://nation.state.actor/mcafee.html">https://nation.state.actor/mcafee.html</a><br/>
Snowball Marketing for Ransomware<br/>
 <a href="https://www.bleepingcomputer.com/news/security/new-scheme-spread-popcorn-time-ransomware-get-chance-of-free-decryption-key/">https://www.bleepingcomputer.com/news/security/new-scheme-spread-popcorn-time-ransomware-get-chance-of-free-decryption-key/</a><br/>
Europol Arrests DDoS Miscreants<br/>
 <a href="http://www.theregister.co.uk/2016/12/12/europol_arrests_34_ddos_kiddies/">http://www.theregister.co.uk/2016/12/12/europol_arrests_34_ddos_kiddies/</a><br/>
5 Questions to Ask you IoT Vendor<br/>
 <a href="https://isc.sans.edu/forums/diary/5+Questions+to+Ask+your+IoT+Vendors+But+Do+Not+Expect+an+Answer/21807/">https://isc.sans.edu/forums/diary/5+Questions+to+Ask+your+IoT+Vendors+But+Do+Not+Expect+an+Answer/21807/</a><br/>
]]></description>
<itunes:duration>5:49
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5289" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 12th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5287</itunes:episode>
<itunes:subtitle>Malware Anti-Reversing Trick; #PwC ACE Makes #SAP Vulnerable;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Malware Anti-Reversing Trick; #PwC ACE Makes #SAP Vulnerable;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5287.mp3" length="4869152" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5287.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5287</link>
<pubDate>Sun, 11 Dec 2016 22:50:02 GMT</pubDate>
<description><![CDATA[Malware Uses NTP to Prevent Reverse Analsys<br/>
 <a href="https://isc.sans.edu/forums/diary/Sleeping+VBS+Really+Wants+To+Sleep/21801/">https://isc.sans.edu/forums/diary/Sleeping+VBS+Really+Wants+To+Sleep/21801/</a><br/>
PwC ACE Tool For SAP Introduces Security Vulnerability into SAP<br/>
 <a href="http://seclists.org/fulldisclosure/2016/Dec/33">http://seclists.org/fulldisclosure/2016/Dec/33</a><br/>
Steganography Used to Hide Exploits in Images<br/>
 <a href="https://isc.sans.edu/forums/diary/Steganography+in+Action+Image+Steganography+StegExpose/21803/">https://isc.sans.edu/forums/diary/Steganography+in+Action+Image+Steganography+StegExpose/21803/</a><br/>
Netgear R7000 and R6400 Aribtrary Command Execution<br/>
 <a href="http://www.kb.cert.org/vuls/id/582384">http://www.kb.cert.org/vuls/id/582384</a><br/>
Holiday Hack Challenge<br/>
 <a href="https://holidayhackchallenge.com">https://holidayhackchallenge.com</a>]]></description>
<itunes:duration>5:47
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5287" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 9th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5285</itunes:episode>
<itunes:subtitle>Domaincops Malware; Yahoo Mail XSS; Trend Office Scan False Positive
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Domaincops Malware; Yahoo Mail XSS; Trend Office Scan False Positive
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5285.mp3" length="5032070" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5285.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5285</link>
<pubDate>Fri, 09 Dec 2016 00:40:02 GMT</pubDate>
<description><![CDATA[Domaincops Malware<br/>
 <a href="https://isc.sans.edu/forums/diary/Good+Cop+Bad+Cop+Domain+Cop/21795/">https://isc.sans.edu/forums/diary/Good+Cop+Bad+Cop+Domain+Cop/21795/</a><br/>
Yahoo Mail Persistent XSS<br/>
 <a href="https://klikki.fi/adv/yahoo2.html">https://klikki.fi/adv/yahoo2.html</a><br/>
Trend Office Scan False Positives<br/>
 <a href="https://www.reddit.com/r/sysadmin/comments/5gs2gv/anyone_else_also_affected_by_a_deleted/">https://www.reddit.com/r/sysadmin/comments/5gs2gv/anyone_else_also_affected_by_a_deleted/</a><br/>
Linux Privilege Escalation due ot af_packet.c race condition<br/>
 <a href="http://seclists.org/oss-sec/2016/q4/607">http://seclists.org/oss-sec/2016/q4/607</a><br/>
]]></description>
<itunes:duration>5:58
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5285" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 8th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5283</itunes:episode>
<itunes:subtitle>AV Exclusion Abused by Targeted Attacks; Android Update; Firefox SVG XDomain Cookies
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
AV Exclusion Abused by Targeted Attacks; Android Update; Firefox SVG XDomain Cookies
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5283.mp3" length="5059973" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5283.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5283</link>
<pubDate>Thu, 08 Dec 2016 00:35:01 GMT</pubDate>
<description><![CDATA[Attackers are using AV Exclusion Lists to Bypass AV<br/>
 <a href="http://www.theregister.co.uk/2016/12/07/clever_crims_using_av_exclusion_lists_as_malware_safe_harbour/">http://www.theregister.co.uk/2016/12/07/clever_crims_using_av_exclusion_lists_as_malware_safe_harbour/</a><br/>
Android Update Patches "Dirty Cow"<br/>
 <a href="https://source.android.com/security/bulletin/2016-12-01.html">https://source.android.com/security/bulletin/2016-12-01.html</a><br/>
"Goldeneye" Ransomware May Use Stolen Data For Realistic E-Mails<br/>
 <a href="https://www.heise.de/security/meldung/Goldeneye-nutzt-Informationen-vom-Arbeitsamt-fuer-aeusserst-gezielte-Angriffe-3564386.html">https://www.heise.de/security/meldung/Goldeneye-nutzt-Informationen-vom-Arbeitsamt-fuer-aeusserst-gezielte-Angriffe-3564386.html</a><br/>
Firefox Cross Domain Cookie Vulnerability<br/>
 <a href="https://insert-script.blogspot.ch/2016/12/firefox-svg-cross-domain-cookie.html">https://insert-script.blogspot.ch/2016/12/firefox-svg-cross-domain-cookie.html</a><br/>
]]></description>
<itunes:duration>6:00
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5283" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, December 7th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5281</itunes:episode>
<itunes:subtitle>Attacking MongoDB;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Attacking MongoDB;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5281.mp3" length="5472397" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5281.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5281</link>
<pubDate>Wed, 07 Dec 2016 00:40:02 GMT</pubDate>
<description><![CDATA[Attacking NoSQL Applications<br/>
 <a href="https://isc.sans.edu/forums/diary/Attacking+NoSQL+applications/21787/">https://isc.sans.edu/forums/diary/Attacking+NoSQL+applications/21787/</a><br/>
Heap Buffer Overflow in Encase Forensic Imager<br/>
 <a href="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20161128-0_Guidance_Software_Encase_DoS_heap_buffer_overflow_vulnerabilities_v10.txt">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20161128-0_Guidance_Software_Encase_DoS_heap_buffer_overflow_vulnerabilities_v10.txt</a><br/>
Raspbian To Increase Default Security<br/>
 <a href="https://www.raspberrypi.org/blog/a-security-update-for-raspbian-pixel/">https://www.raspberrypi.org/blog/a-security-update-for-raspbian-pixel/</a><br/>
SONY Camera Backdoor<br/>
 <a href="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20161206-0_Sony_IPELA_Engine_IP_Cameras_Backdoors_v10.txt">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20161206-0_Sony_IPELA_Engine_IP_Cameras_Backdoors_v10.txt</a><br/>
Feedback: <a href="https://isc.sans.edu/contact.html">https://isc.sans.edu/contact.html</a><br/>
]]></description>
<itunes:duration>6:30
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5281" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, December 6th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5279</itunes:episode>
<itunes:subtitle>Guessing CC Numbers; Hancitor Reversing Video; Guess CC Number Fast
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Guessing CC Numbers; Hancitor Reversing Video; Guess CC Number Fast
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5279.mp3" length="4639640" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5279.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5279</link>
<pubDate>Tue, 06 Dec 2016 01:00:04 GMT</pubDate>
<description><![CDATA[Video Walk Through: Analysing Hancitor Malicious Document<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+Maldoc+Videos/21783/">https://isc.sans.edu/forums/diary/Hancitor+Maldoc+Videos/21783/</a><br/>
Rapid Distributed Credit Card Number Brute Forcing<br/>
 <a href="http://eprint.ncl.ac.uk/file_store/production/230123/19180242-D02E-47AC-BDB3-73C22D6E1FDB.pdf">http://eprint.ncl.ac.uk/file_store/production/230123/19180242-D02E-47AC-BDB3-73C22D6E1FDB.pdf</a><br/>
Cloudflare Detecting Large DDoS Attacks Over Thanksgiving / Cyber Monday <br/>
 <a href="https://blog.cloudflare.com/the-daily-ddos-ten-days-of-massive-attacks/">https://blog.cloudflare.com/the-daily-ddos-ten-days-of-massive-attacks/</a><br/>
Free Windows Tool to Harden Networks: SAMRi10<br/>
 <a href="https://gallery.technet.microsoft.com/SAMRi10-Hardening-Remote-48d94b5b">https://gallery.technet.microsoft.com/SAMRi10-Hardening-Remote-48d94b5b</a><br/>
NY State Outlawing Automated Ticket Purchasing Software<br/>
 <a href="https://www.nysenate.gov/legislation/bills/2015/S8123">https://www.nysenate.gov/legislation/bills/2015/S8123</a><br/>
]]></description>
<itunes:duration>5:30
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5279" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, December 5th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5277</itunes:episode>
<itunes:subtitle>#CSP Bypass With #Polyglot Images; Finding #SQL Injection via Stack Overflow; Mirai Update
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#CSP Bypass With #Polyglot Images; Finding #SQL Injection via Stack Overflow; Mirai Update
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5277.mp3" length="4552004" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5277.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5277</link>
<pubDate>Sun, 04 Dec 2016 23:50:02 GMT</pubDate>
<description><![CDATA[CSP Bypass with Polyglot Images<br/>
 <a href="http://blog.portswigger.net/2016/12/bypassing-csp-using-polyglot-jpegs.html">http://blog.portswigger.net/2016/12/bypassing-csp-using-polyglot-jpegs.html</a><br/>
 also see this Youtube video on Polyglot Images: <a href="https://www.youtube.com/watch?v=Ub5G_t-gUBc">https://www.youtube.com/watch?v=Ub5G_t-gUBc</a><br/>
Stack Overflow SQL Injection Questions<br/>
 <a href="https://laurent22.github.io/so-injections/">https://laurent22.github.io/so-injections/</a><br/>
Mirai Update: More Outages and Vulnerable Chipset Identified<br/>
 <a href="http://www.theregister.co.uk/2016/12/02/broadband_mirai_takedown_analysis/">http://www.theregister.co.uk/2016/12/02/broadband_mirai_takedown_analysis/</a><br/>
SEC503 Intrusion Detection in Depth in Brussles (Jan 2017):<br/>
 <a href="https://www.sans.org/event/brussels-winter-2017/course/intrusion-detection-in-depth">https://www.sans.org/event/brussels-winter-2017/course/intrusion-detection-in-depth</a><br/>
]]></description>
<itunes:duration>5:24
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5277" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, December 2nd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5275</itunes:episode>
<itunes:subtitle>Beamgun vs. Poisontap; Shamoon is Back; British ISP Suffers Outage
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Beamgun vs. Poisontap; Shamoon is Back; British ISP Suffers Outage
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5275.mp3" length="4369041" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5275.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5275</link>
<pubDate>Fri, 02 Dec 2016 03:00:02 GMT</pubDate>
<description><![CDATA[Open Source Tool "Beamgun" Fights Rogue USB Devices on Windows<br/>
 <a href="https://github.com/JLospinoso/beamgun">https://github.com/JLospinoso/beamgun</a><br/>
"Shamoon" Malware is back with a new destructive attack against Saudi Arabia<br/>
 <a href="https://www.bloomberg.com/news/articles/2016-12-01/destructive-hacks-strike-saudi-arabia-posing-challenge-to-trump">https://www.bloomberg.com/news/articles/2016-12-01/destructive-hacks-strike-saudi-arabia-posing-challenge-to-trump</a><br/>
British ISP "KCOM" Suffering Outage After Attack<br/>
 <a href="http://www.hulldailymail.co.uk/kcom-blames-cyber-attack-for-thousands-losing-internet-access-in-hull/story-29944084-detail/story.html#xf23rtZbUqlh5uXY.99">http://www.hulldailymail.co.uk/kcom-blames-cyber-attack-for-thousands-losing-internet-access-in-hull/story-29944084-detail/story.html#xf23rtZbUqlh5uXY.99</a><br/>
Microsoft Fixes Long Known Priviledge Escalation Issue<br/>
 <a href="https://threatpost.com/microsoft-silently-fixes-kernel-bug-that-led-to-chrome-sandbox-bypass/122179/">https://threatpost.com/microsoft-silently-fixes-kernel-bug-that-led-to-chrome-sandbox-bypass/122179/</a><br/>
]]></description>
<itunes:duration>5:11
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5275" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, December 1st 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5273</itunes:episode>
<itunes:subtitle>Mozilla Patches #Firefox 0-Day; SQL Slammer; #Goolian Malware; Bypassing #SAML
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Mozilla Patches #Firefox 0-Day; SQL Slammer; #Goolian Malware; Bypassing #SAML
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5273.mp3" length="5433206" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5273.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5273</link>
<pubDate>Wed, 30 Nov 2016 23:10:01 GMT</pubDate>
<description><![CDATA[Mozilla Patches Firefox 0-Day (Exploit already avaiable!)<br/>
 <a href="https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+in+Firefox+used+to+Attack+Tor+Browser/21769/">https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+in+Firefox+used+to+Attack+Tor+Browser/21769/</a><br/>
SQL Slammer "Resurgance" ? <br/>
 <a href="https://isc.sans.edu/forums/diary/Take+Back+Wednesday+SQL+Slammer+still+alive+but+barely+kicking/21767/">https://isc.sans.edu/forums/diary/Take+Back+Wednesday+SQL+Slammer+still+alive+but+barely+kicking/21767/</a><br/>
Goolian Android Malware<br/>
 <a href="http://blog.checkpoint.com/2016/11/30/1-million-google-accounts-breached-gooligan/">http://blog.checkpoint.com/2016/11/30/1-million-google-accounts-breached-gooligan/</a><br/>
Bypassing SAML 2.0 SSO <br/>
 <a href="http://research.aurainfosec.io/bypassing-saml20-SSO/">http://research.aurainfosec.io/bypassing-saml20-SSO/</a><br/>
Webcast: The Six Most Dangerous New Cyber Attack Techniques<br/>
 <a href="https://cc.readytalk.com/registration/#/?meeting=9yq9nbx4tp7a&campaign=nggmjhc39guc">https://cc.readytalk.com/registration/#/?meeting=9yq9nbx4tp7a&campaign=nggmjhc39guc</a><br/>
]]></description>
<itunes:duration>6:27
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5273" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 30th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5271</itunes:episode>
<itunes:subtitle>Telekom Router's Not TR-069 Vulnerable; Software Only Defenses Against #Rowhammer
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Telekom Router's Not TR-069 Vulnerable; Software Only Defenses Against #Rowhammer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5271.mp3" length="4977713" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5271.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5271</link>
<pubDate>Tue, 29 Nov 2016 23:25:02 GMT</pubDate>
<description><![CDATA[Mirai/TR-069 Update: Deutsche Telekom Routers May have been DDoSed by Traffic Volume, not Exploit<br/>
 <a href="https://comsecuris.com/blog/posts/were_900k_deutsche_telekom_routers_compromised_by_mirai/">https://comsecuris.com/blog/posts/were_900k_deutsche_telekom_routers_compromised_by_mirai/</a><br/>
Bitlocker Encrypted Drives Exposed During System Upgrade <br/>
 <a href="http://blog.win-fu.com/2016/11/every-windows-10-in-place-upgrade-is.html">http://blog.win-fu.com/2016/11/every-windows-10-in-place-upgrade-is.html</a><br/>
Software-Only Defenses Against Rowhammer<br/>
 <a href="https://arxiv.org/abs/1611.08396">https://arxiv.org/abs/1611.08396</a><br/>
]]></description>
<itunes:duration>5:54
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5271" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 29th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5269</itunes:episode>
<itunes:subtitle>#Mirai Variant Attacking Routers via TR-069 Vuln; #Paypal #OAuth Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Mirai Variant Attacking Routers via TR-069 Vuln; #Paypal #OAuth Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5269.mp3" length="4998432" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5269.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5269</link>
<pubDate>Tue, 29 Nov 2016 00:10:02 GMT</pubDate>
<description><![CDATA[Mirai Variant Scanning Port 5555 and 7547 For TR-069/SOAP Vulnerability<br/>
 <a href="https://isc.sans.edu/forums/diary/Port+7547+SOAP+Remote+Code+Execution+Attack+Against+DSL+Modems/21759/">https://isc.sans.edu/forums/diary/Port+7547+SOAP+Remote+Code+Execution+Attack+Against+DSL+Modems/21759/</a><br/>
Paypal OAuth Vulnerability <br/>
 <a href="http://blog.intothesymmetry.com/2016/11/all-your-paypal-tokens-belong-to-me.html">http://blog.intothesymmetry.com/2016/11/all-your-paypal-tokens-belong-to-me.html</a><br/>
]]></description>
<itunes:duration>5:56
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5269" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 28th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5267</itunes:episode>
<itunes:subtitle>Extracting Shellcode from JS; Scapy vs. #CozyDuke; Images Spread Facebook Malware? MUNI for Free thx</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Extracting Shellcode from JS; Scapy vs. #CozyDuke; Images Spread Facebook Malware? MUNI for Free thx</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5267.mp3" length="5336130" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5267.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5267</link>
<pubDate>Mon, 28 Nov 2016 00:10:02 GMT</pubDate>
<description><![CDATA[Extracting Shellcode from Javascript<br/>
 <a href="https://isc.sans.edu/forums/diary/Extracting+Shellcode+From+JavaScript/21753/">https://isc.sans.edu/forums/diary/Extracting+Shellcode+From+JavaScript/21753/</a><br/>
Using Scapy to Test CozyDuke Snort Signatures<br/>
 <a href="https://isc.sans.edu/forums/diary/Scapy+vs+CozyDuke/21755/">https://isc.sans.edu/forums/diary/Scapy+vs+CozyDuke/21755/</a><br/>
Malicious JPEG Spreading via Facebook<br/>
 <a href="http://blog.checkpoint.com/2016/11/24/imagegate-check-point-uncovers-new-method-distributing-malware-images/">http://blog.checkpoint.com/2016/11/24/imagegate-check-point-uncovers-new-method-distributing-malware-images/</a><br/>
San Francisco Public Transport ("MUNI") hit by Ransomware<br/>
 <a href="http://sanfrancisco.cbslocal.com/2016/11/26/you-hacked-cyber-attackers-crash-muni-computer-system-across-sf/">http://sanfrancisco.cbslocal.com/2016/11/26/you-hacked-cyber-attackers-crash-muni-computer-system-across-sf/</a><br/>
Tesla Smartphone App Vulnerability<br/>
 <a href="https://promon.co/blog/tesla-cars-can-be-stolen-by-hacking-the-app/">https://promon.co/blog/tesla-cars-can-be-stolen-by-hacking-the-app/</a><br/>
]]></description>
<itunes:duration>6:20
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5267" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 23rd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5265</itunes:episode>
<itunes:subtitle>Wordpress Update Vuln; Turning Speakers into Microphones;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Wordpress Update Vuln; Turning Speakers into Microphones;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5265.mp3" length="5659542" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5265.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5265</link>
<pubDate>Wed, 23 Nov 2016 01:30:02 GMT</pubDate>
<description><![CDATA[WordPress RCE Via Fake Updates<br/>
 <a href="http://www.openwall.com/lists/oss-security/2016/11/21/3">http://www.openwall.com/lists/oss-security/2016/11/21/3</a><br/>
Turning Speakers into Microphones<br/>
 <a href="http://cyber.bgu.ac.il/advanced-cyber/system/files/SPEAKEaR.pdf">http://cyber.bgu.ac.il/advanced-cyber/system/files/SPEAKEaR.pdf</a><br/>
5 Second Video iOS Crash<br/>
 <a href="http://www.cultofmac.com/455215/455215/">http://www.cultofmac.com/455215/455215/</a><br/>
"Stubby" Implements Encrypted DNS<br/>
 <a href="http://www.theregister.co.uk/2016/11/22/dns_boffins_offer_up_privacy_test/">http://www.theregister.co.uk/2016/11/22/dns_boffins_offer_up_privacy_test/</a><br/>
]]></description>
<itunes:duration>6:43
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5265" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 22nd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5263</itunes:episode>
<itunes:subtitle>Encrypted ZIP File With Comments; Siemens Camera Default Password
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Encrypted ZIP File With Comments; Siemens Camera Default Password
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5263.mp3" length="4497268" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5263.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5263</link>
<pubDate>Mon, 21 Nov 2016 23:45:02 GMT</pubDate>
<description><![CDATA[Encrypted ZIP File With Comments<br/>
 <a href="https://isc.sans.edu/forums/diary/ZIP+With+Comment/21737/">https://isc.sans.edu/forums/diary/ZIP+With+Comment/21737/</a><br/>
Siemens Surveilance Cameras Use Static Default Password<br/>
 <a href="https://ics-cert.us-cert.gov/advisories/ICSA-16-322-01">https://ics-cert.us-cert.gov/advisories/ICSA-16-322-01</a><br/>
NTP Single Packet DoS Vulnerablity<br/>
 <a href="http://dumpco.re/cve-2016-7434/">http://dumpco.re/cve-2016-7434/</a><br/>
Windows 10 Does Not Provide the Same Protections as EMET<br/>
 <a href="https://insights.sei.cmu.edu/cert/2016/11/windows-10-cannot-protect-insecure-applications-like-emet-can.html">https://insights.sei.cmu.edu/cert/2016/11/windows-10-cannot-protect-insecure-applications-like-emet-can.html</a><br/>
]]></description>
<itunes:duration>5:20
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5263" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 21st 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5261</itunes:episode>
<itunes:subtitle>Converting Timestamps; SIP Dispabled Macbook Pros; Spoofing Microsoft E-Mails With Outlook 365</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Converting Timestamps; SIP Dispabled Macbook Pros; Spoofing Microsoft E-Mails With Outlook 365</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5261.mp3" length="5047030" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5261.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5261</link>
<pubDate>Mon, 21 Nov 2016 00:40:03 GMT</pubDate>
<description><![CDATA[Converting Timestamps with Epocalypse<br/>
 <a href="https://isc.sans.edu/forums/diary/How+many+Epoch+times+Epocalypsepy+timestamp+converter/21733/">https://isc.sans.edu/forums/diary/How+many+Epoch+times+Epocalypsepy+timestamp+converter/21733/</a><br/>
SIP Disabled on Some Macbook Pros<br/>
 <a href="http://www.macrumors.com/2016/11/17/system-integrity-protection-disabled-macbook-pro/">http://www.macrumors.com/2016/11/17/system-integrity-protection-disabled-macbook-pro/</a><br/>
Spoofing Microsoft.com E-Mails with Outlook.com<br/>
 <a href="https://www.utkusen.com/blog/sending-valid-phishing-emails-from-microsoftcom.html">https://www.utkusen.com/blog/sending-valid-phishing-emails-from-microsoftcom.html</a><br/>
Various High Profile Twitter Accounts Hijacked By Spammers<br/>
 <a href="https://www.engadget.com/2016/11/19/spammers-compromised-twitter-accounts-for-playstation-and-other/">https://www.engadget.com/2016/11/19/spammers-compromised-twitter-accounts-for-playstation-and-other/</a><br/>
Dyn Attack Caused by Single Angry Playstation User<br/>
 <a href="http://www.wsj.com/articles/october-internet-attack-targeted-playstation-network-researchers-say-1479250847">http://www.wsj.com/articles/october-internet-attack-targeted-playstation-network-researchers-say-1479250847</a>]]></description>
<itunes:duration>5:59
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5261" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 18th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5259</itunes:episode>
<itunes:subtitle>Anti-Research Countermeasures; #Fedora/#Chrome Driveby Exploit; #Volutility
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Anti-Research Countermeasures; #Fedora/#Chrome Driveby Exploit; #Volutility
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5259.mp3" length="4840035" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5259.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5259</link>
<pubDate>Fri, 18 Nov 2016 01:20:01 GMT</pubDate>
<description><![CDATA[Phishers Protect Phishing Sites from Security Researchers<br/>
 <a href="https://isc.sans.edu/forums/diary/Example+of+Getting+Analysts+Researchers+Away/21721/">https://isc.sans.edu/forums/diary/Example+of+Getting+Analysts+Researchers+Away/21721/</a><br/>
Fedora / Chrome Automatic Downloads and Code Execution<br/>
 <a href="https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html">https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html</a><br/>
Volutility Version 1.0 Released<br/>
 <a href="https://techanarchy.net/2016/11/volutility-version-1-0-release/">https://techanarchy.net/2016/11/volutility-version-1-0-release/</a><br/>
iOS Synchronizing Call Logs via iCloud<br/>
 <a href="http://www.forbes.com/sites/thomasbrewster/2016/11/17/iphone-call-logs-in-icloud-warns-elcomsoft-hackers/#5d96b21c2936">http://www.forbes.com/sites/thomasbrewster/2016/11/17/iphone-call-logs-in-icloud-warns-elcomsoft-hackers/#5d96b21c2936</a><br/>
]]></description>
<itunes:duration>5:44
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5259" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 17th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5257</itunes:episode>
<itunes:subtitle>Troldesh #Ransomware; #Poisontap; #Symantec DLL Patch; #VMWare Patch;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Troldesh #Ransomware; #Poisontap; #Symantec DLL Patch; #VMWare Patch;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5257.mp3" length="5087726" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5257.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5257</link>
<pubDate>Thu, 17 Nov 2016 00:38:25 GMT</pubDate>
<description><![CDATA[Russian Malspam Distributing Troldesh Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+distributing+Troldesh+ransomware/21717/">https://isc.sans.edu/forums/diary/Malspam+distributing+Troldesh+ransomware/21717/</a><br/>
Poisontap Exploits USB Ethernet Adapters<br/>
 <a href="https://samy.pl/poisontap/">https://samy.pl/poisontap/</a><br/>
Symantec Patches Untrusted DLL Loading Vulnerability<br/>
 <a href="https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20161115_00">https://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20161115_00</a><br/>
VMWare Patches VM Escape Vulnerablity<br/>
 <a href="http://www.vmware.com/security/advisories/VMSA-2016-0019.html">http://www.vmware.com/security/advisories/VMSA-2016-0019.html</a><br/>
Some Android Phones Leak Data To China<br/>
 <a href="http://www.prnewswire.com/news-releases/kryptowire-discovered-mobile-phone-firmware-that-transmitted-personally-identifiable-information-pii-without-user-consent-or-disclosure-300362844.html">http://www.prnewswire.com/news-releases/kryptowire-discovered-mobile-phone-firmware-that-transmitted-personally-identifiable-information-pii-without-user-consent-or-disclosure-300362844.html</a><br/>
Jacksonville ISC2 Meeting<br/>
 <a href="https://www.eventbrite.com/e/isc2-ne-florida-chapter-meeting-november-2016-tickets-29050701430">https://www.eventbrite.com/e/isc2-ne-florida-chapter-meeting-november-2016-tickets-29050701430</a><br/>
]]></description>
<itunes:duration>6:02
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5257" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 16th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5255</itunes:episode>
<itunes:subtitle>#LUKS Vulnerability; #Shazam Privacy Concerns; #Debian/#nginx Priv Esc Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#LUKS Vulnerability; #Shazam Privacy Concerns; #Debian/#nginx Priv Esc Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5255.mp3" length="4497536" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5255.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5255</link>
<pubDate>Wed, 16 Nov 2016 01:05:02 GMT</pubDate>
<description><![CDATA[Vulnerability in LUKS Can Be used to Boot Encrypted Linux Systems<br/>
 <a href="http://betanews.com/2016/11/15/linux-security-bug-cryptsetup-luks/">http://betanews.com/2016/11/15/linux-security-bug-cryptsetup-luks/</a><br/>
Shazam Keeps Microphone Turned on Even While not "Listening"<br/>
 <a href="https://objective-see.com/blog/blog_0x13.html">https://objective-see.com/blog/blog_0x13.html</a><br/>
nginx Privilege Escalation Vulnerability (Debian Only)<br/>
 <a href="http://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html">http://legalhackers.com/advisories/Nginx-Exploit-Deb-Root-PrivEsc-CVE-2016-1247.html</a><br/>
]]></description>
<itunes:duration>5:52
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5255" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 15th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5253</itunes:episode>
<itunes:subtitle>#FIFA Coins Indictment; Crysis #Ransomware Decrypt; #Lightbulb #WAF Auditing Framework
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#FIFA Coins Indictment; Crysis #Ransomware Decrypt; #Lightbulb #WAF Auditing Framework
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5253.mp3" length="4089984" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5253.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5253</link>
<pubDate>Tue, 15 Nov 2016 00:05:02 GMT</pubDate>
<description><![CDATA[Indictment for the theft of FIFA Game Coins<br/>
 <a href="https://regmedia.co.uk/2016/11/14/fifafraudindictment.pdf">https://regmedia.co.uk/2016/11/14/fifafraudindictment.pdf</a><br/>
Crysis Ransomware Master Encryption Key Released<br/>
 <a href="http://www.bleepingcomputer.com/news/security/master-decryption-keys-and-decryptor-for-the-crysis-ransomware-released-/">http://www.bleepingcomputer.com/news/security/master-decryption-keys-and-decryptor-for-the-crysis-ransomware-released-/</a><br/>
Adult Friend Finder Breached<br/>
 <a href="https://www.leakedsource.com/blog/friendfinder">https://www.leakedsource.com/blog/friendfinder</a><br/>
Lightbulb Web Application Firewall Auditing Framework<br/>
 <a href="http://seclist.us/lightbulb-is-an-open-source-python-framework-for-auditing-web-applications-firewalls.html">http://seclist.us/lightbulb-is-an-open-source-python-framework-for-auditing-web-applications-firewalls.html</a><br/>
]]></description>
<itunes:duration>5:20
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5253" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 14th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5251</itunes:episode>
<itunes:subtitle>#VBA Shellcode and #EMET; #Bitcoin Miner FTP Uploads; #Russian Bank #DDoS
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#VBA Shellcode and #EMET; #Bitcoin Miner FTP Uploads; #Russian Bank #DDoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5251.mp3" length="4278400" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5251.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5251</link>
<pubDate>Mon, 14 Nov 2016 02:10:02 GMT</pubDate>
<description><![CDATA[EMET Will Defeat Shell Code Executing Inside Word<br/>
 <a href="https://isc.sans.edu/forums/diary/VBA+Shellcode+and+EMET/21705/">https://isc.sans.edu/forums/diary/VBA+Shellcode+and+EMET/21705/</a><br/>
Bitcoin Miners Distributed via FTP Exploits<br/>
 <a href="https://isc.sans.edu/forums/diary/Bitcoin+Miner+File+Upload+via+FTP/21707/">https://isc.sans.edu/forums/diary/Bitcoin+Miner+File+Upload+via+FTP/21707/</a><br/>
5 Russian Banks Suffer DoS Attack<br/>
 <a href="https://www.rt.com/news/366172-russian-banks-ddos-attack/">https://www.rt.com/news/366172-russian-banks-ddos-attack/</a><br/>
Wifi May Reveal Mobile Phone Passwords<br/>
 <a href="http://dl.acm.org/citation.cfm?id=2978397">http://dl.acm.org/citation.cfm?id=2978397</a><br/>
]]></description>
<itunes:duration>5:29
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5251" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 11th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5249</itunes:episode>
<itunes:subtitle>#ICMP DoS Attacks; OpenSSL Patch; #OWASP CRS 3.0.0
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#ICMP DoS Attacks; OpenSSL Patch; #OWASP CRS 3.0.0
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5249.mp3" length="4788352" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5249.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5249</link>
<pubDate>Fri, 11 Nov 2016 00:05:02 GMT</pubDate>
<description><![CDATA[ICMP Unreachable DoS Attacks <br/>
 <a href="https://isc.sans.edu/forums/diary/ICMP+Unreachable+DoS+Attacks+aka+Black+Nurse/21699/">https://isc.sans.edu/forums/diary/ICMP+Unreachable+DoS+Attacks+aka+Black+Nurse/21699/</a><br/>
OpenSSL 1.1.0 Patch<br/>
 <a href="https://www.openssl.org/news/secadv/20161110.txt">https://www.openssl.org/news/secadv/20161110.txt</a><br/>
OWASP ModSecurity Core Rule Set Version 3.0.0 Release<br/>
 <a href="https://lists.owasp.org/pipermail/owasp-modsecurity-core-rule-set/2016-November/002265.html">https://lists.owasp.org/pipermail/owasp-modsecurity-core-rule-set/2016-November/002265.html</a><br/>
]]></description>
<itunes:duration>6:11
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5249" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 10th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5247</itunes:episode>
<itunes:subtitle>DoS Turns of Heat to Finish Appartments; #DLink HNAP Vuln; 2 MSFT Bug PoCs 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
DoS Turns of Heat to Finish Appartments; #DLink HNAP Vuln; 2 MSFT Bug PoCs 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5247.mp3" length="4225152" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5247.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5247</link>
<pubDate>Wed, 09 Nov 2016 23:35:01 GMT</pubDate>
<description><![CDATA[DoS Attack Turns off Heat for More then a Week<br/>
 <a href="http://www.hs.fi/kotimaa/a1478495966653">http://www.hs.fi/kotimaa/a1478495966653</a> (finish only)<br/>
DLink HNAP Vulnerability<br/>
 <a href="https://raw.githubusercontent.com/pedrib/PoC/master/advisories/dlink-hnap-login.txt">https://raw.githubusercontent.com/pedrib/PoC/master/advisories/dlink-hnap-login.txt</a><br/>
PoC Exploits Available for Two MSFT Vulnerabilities<br/>
 <a href="https://github.com/tinysec/public/tree/master/CVE-2016-7255">https://github.com/tinysec/public/tree/master/CVE-2016-7255</a><br/>
 <a href="https://g-laurent.blogspot.com/2016/11/ms16-137-lsass-remote-memory-corruption.html">https://g-laurent.blogspot.com/2016/11/ms16-137-lsass-remote-memory-corruption.html</a><br/>
OpenSSL Patch Pre-Announced<br/>
 <a href="https://mta.openssl.org/pipermail/openssl-announce/2016-November/000085.html">https://mta.openssl.org/pipermail/openssl-announce/2016-November/000085.html</a><br/>
Hue Lightbulb Exploit/Worm<br/>
 <a href="http://iotworm.eyalro.net">http://iotworm.eyalro.net</a> (Sophos labels this link as "Spam", but appears to be harmless)<br/>
]]></description>
<itunes:duration>5:27
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5247" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 9th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5245</itunes:episode>
<itunes:subtitle>Microsoft Patch Tuesday; Adobe Updates (Flash and Connect);
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Microsoft Patch Tuesday; Adobe Updates (Flash and Connect);
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5245.mp3" length="5726336" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5245.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5245</link>
<pubDate>Tue, 08 Nov 2016 23:55:02 GMT</pubDate>
<description><![CDATA[Microsoft Patch Tuesday<br/>
 <a href="https://isc.sans.edu/forums/diary/November+2016+Microsoft+Patch+Day/21689/">https://isc.sans.edu/forums/diary/November+2016+Microsoft+Patch+Day/21689/</a><br/>
Adobe Updates<br/>
 <a href="https://helpx.adobe.com/security/products/connect/apsb16-35.html">https://helpx.adobe.com/security/products/connect/apsb16-35.html</a><br/>
 <a href="https://helpx.adobe.com/security/products/flash-player/apsb16-37.html">https://helpx.adobe.com/security/products/flash-player/apsb16-37.html</a><br/>
]]></description>
<itunes:duration>7:29
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5245" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 8th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5243</itunes:episode>
<itunes:subtitle>#TESCO Bank Limits Online Banking; Attacking Mobile Devices via #IoT; Fake Apple iOS Apps
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#TESCO Bank Limits Online Banking; Attacking Mobile Devices via #IoT; Fake Apple iOS Apps
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5243.mp3" length="4878464" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5243.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5243</link>
<pubDate>Tue, 08 Nov 2016 00:55:02 GMT</pubDate>
<description><![CDATA[Tesco Bank Limits Online Banking After Online Criminal Activity<br/>
 <a href="https://yourcommunity.tescobank.com/t5/News/Message-for-Current-Account-customers/td-p/6599">https://yourcommunity.tescobank.com/t5/News/Message-for-Current-Account-customers/td-p/6599</a><br/>
Belkin WeMo Devices Used To Attack Mobile Devices<br/>
 <a href="https://www.blackhat.com/eu-16/briefings/schedule/index.html#breaking-bhad-abusing-belkin-home-automation-devices-4640">https://www.blackhat.com/eu-16/briefings/schedule/index.html#breaking-bhad-abusing-belkin-home-automation-devices-4640</a><br/>
Fake Retail Apps Flooding Apple App Store<br/>
 <a href="http://www.nytimes.com/2016/11/07/technology/more-iphone-fake-retail-apps-before-holidays.html?_r=0">http://www.nytimes.com/2016/11/07/technology/more-iphone-fake-retail-apps-before-holidays.html?_r=0</a><br/>
Netflix Password Recovery via Phone Call Vulnerability<br/>
 <a href="https://slashcrypto.org/2016/11/07/Netflix/">https://slashcrypto.org/2016/11/07/Netflix/</a><br/>
Webcast: 8 Ways To Watch The Invisible: Analyzing Encrypted Network Traffic<br/>
 <a href="https://www.sans.org/webcasts/8-ways-watch-invisible-analyzing-encrypted-network-traffic-103277">https://www.sans.org/webcasts/8-ways-watch-invisible-analyzing-encrypted-network-traffic-103277</a><br/>
]]></description>
<itunes:duration>6:18
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5243" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, November 7th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5241</itunes:episode>
<itunes:subtitle>Hancitor Maldoc Whitelisting Bypass; EMET Support Extended; IMSI Catcher Via WiFi
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Hancitor Maldoc Whitelisting Bypass; EMET Support Extended; IMSI Catcher Via WiFi
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5241.mp3" length="4452480" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5241.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5241</link>
<pubDate>Mon, 07 Nov 2016 00:25:02 GMT</pubDate>
<description><![CDATA[Hancitor Maldoc Bypasses Application Whitelisting<br/>
 <a href="https://isc.sans.edu/forums/diary/Hancitor+Maldoc+Bypasses+Application+Whitelisting/21683/">https://isc.sans.edu/forums/diary/Hancitor+Maldoc+Bypasses+Application+Whitelisting/21683/</a><br/>
Microsoft Extends EMET Support Deadline<br/>
 <a href="https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/">https://blogs.technet.microsoft.com/srd/2016/11/03/beyond-emet/</a><br/>
Wifi Based IMSI Catcher<br/>
 <a href="https://www.blackhat.com/docs/eu-16/materials/eu-16-OHanlon-WiFi-IMSI-Catcher.pdf">https://www.blackhat.com/docs/eu-16/materials/eu-16-OHanlon-WiFi-IMSI-Catcher.pdf</a><br/>
]]></description>
<itunes:duration>5:44
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5241" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, November 4th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5239</itunes:episode>
<itunes:subtitle>Reconstruct Binaries Sent via Telnet; Wix.com DOM Based XSS; WoT Leaked/Sold User Data
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Reconstruct Binaries Sent via Telnet; Wix.com DOM Based XSS; WoT Leaked/Sold User Data
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5239.mp3" length="5388416" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5239.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5239</link>
<pubDate>Thu, 03 Nov 2016 23:20:01 GMT</pubDate>
<description><![CDATA[Reconstruct Binaries Sent via Telnet<br/>
 <a href="https://isc.sans.edu/forums/diary/Extracting+Malware+Transmitted+Via+Telnet/21673/">https://isc.sans.edu/forums/diary/Extracting+Malware+Transmitted+Via+Telnet/21673/</a><br/>
Wix.com DOM Based XSS<br/>
 <a href="https://www.contrastsecurity.com/security-influencers/dom-xss-in-wix.com">https://www.contrastsecurity.com/security-influencers/dom-xss-in-wix.com</a><br/>
DNS Based Mail Security<br/>
 <a href="https://nccoe.nist.gov/projects/building_blocks/secured_email">https://nccoe.nist.gov/projects/building_blocks/secured_email</a><br/>
Web of Trust Plugin Released Anonymized User Data <br/>
 <a href="https://www.mywot.com/en/forum/70396--virus-spyware-do-not-install-uninstall-as-soon-as-possible">https://www.mywot.com/en/forum/70396--virus-spyware-do-not-install-uninstall-as-soon-as-possible</a><br/>
]]></description>
<itunes:duration>6:53
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5239" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, November 3rd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5237</itunes:episode>
<itunes:subtitle>#OWA Two Factor Bypass; #Baraccuda DoS; #Targobank loses track of accounts 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#OWA Two Factor Bypass; #Baraccuda DoS; #Targobank loses track of accounts 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5237.mp3" length="4532352" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5237.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5237</link>
<pubDate>Thu, 03 Nov 2016 00:00:01 GMT</pubDate>
<description><![CDATA[Exchange Web Service Two-Factor Authentication Bypass<br/>
 <a href="http://www.blackhillsinfosec.com/?p=5396">http://www.blackhillsinfosec.com/?p=5396</a><br/>
Barracuda DoS Disrupts Mail Delivery<br/>
 <a href="http://status.barracuda.com">http://status.barracuda.com</a><br/>
Targobank Looses Account Data After Maintenance<br/>
 <a href="http://www.spiegel.de/wirtschaft/service/targobank-kunden-fehlt-geld-auf-dem-konto-it-probleme-a-1119434.html">http://www.spiegel.de/wirtschaft/service/targobank-kunden-fehlt-geld-auf-dem-konto-it-probleme-a-1119434.html</a> (german only)<br/>
Ouch! Security Awareness Newsletter<br/>
 <a href="http://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201611_en.pdf">http://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201611_en.pdf</a><br/>
]]></description>
<itunes:duration>5:48
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5237" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, November 2nd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5235</itunes:episode>
<itunes:subtitle>Google Ads On Google Pushing Malware to macOS Users; Memcached Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Google Ads On Google Pushing Malware to macOS Users; Memcached Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5235.mp3" length="4563072" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5235.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5235</link>
<pubDate>Wed, 02 Nov 2016 01:10:02 GMT</pubDate>
<description><![CDATA[Malvertising On Google AdWords Targeting macOS Users<br/>
<a href="http://blog.cylance.com/malvertising-on-google-adwords-targeting-macos-users">http://blog.cylance.com/malvertising-on-google-adwords-targeting-macos-users</a><br/>
Microsoft Response to Google Privilege Escalation Disclosure<br/>
 <a href="https://blogs.technet.microsoft.com/mmpc/2016/11/01/our-commitment-to-our-customers-security/">https://blogs.technet.microsoft.com/mmpc/2016/11/01/our-commitment-to-our-customers-security/</a><br/>
Memcached Remote Code Execution Vulnerabilities<br/>
 <a href="http://blog.talosintel.com/2016/10/memcached-vulnerabilities.html">http://blog.talosintel.com/2016/10/memcached-vulnerabilities.html</a><br/>
SAP Vulnerability Details Released<br/>
 <a href="https://erpscan.com/press-center/blog/0-day-sap-vulnerability-published-heres-can/">https://erpscan.com/press-center/blog/0-day-sap-vulnerability-published-heres-can/</a><br/>
]]></description>
<itunes:duration>5:50
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5235" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, November 1st 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5233</itunes:episode>
<itunes:subtitle>snapshot.ps1; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
snapshot.ps1; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5233.mp3" length="4640896" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5233.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5233</link>
<pubDate>Tue, 01 Nov 2016 01:45:01 GMT</pubDate>
<description><![CDATA[snapshot.ps1 DFIR Capture<br/>
 <a href="https://isc.sans.edu/forums/diary/SEC505+DFIR+capture+script+snapshotps1/21659/">https://isc.sans.edu/forums/diary/SEC505+DFIR+capture+script+snapshotps1/21659/</a><br/>
Predicting Domain Reputation<br/>
 <a href="http://www.icir.org/vern/papers/predator-ccs16.pdf">http://www.icir.org/vern/papers/predator-ccs16.pdf</a><br/>
Mozilla Removing Battery Status API For Privacy Reasons<br/>
 <a href="https://www.fxsitecompat.com/en-CA/docs/2016/battery-status-api-has-been-removed/">https://www.fxsitecompat.com/en-CA/docs/2016/battery-status-api-has-been-removed/</a><br/>
Windows Privilege Escalation 0-day Actively Exploited<br/>
 <a href="https://security.googleblog.com/2016/10/disclosing-vulnerabilities-to-protect.html">https://security.googleblog.com/2016/10/disclosing-vulnerabilities-to-protect.html</a><br/>
]]></description>
<itunes:duration>5:56
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5233" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 31st 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5231</itunes:episode>
<itunes:subtitle>Volatility Bot; E911 DoS; Mirai Vuln; iOS/macOS task_t Vuln;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Volatility Bot; E911 DoS; Mirai Vuln; iOS/macOS task_t Vuln;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5231.mp3" length="5210240" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5231.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5231</link>
<pubDate>Mon, 31 Oct 2016 01:15:02 GMT</pubDate>
<description><![CDATA[Volatility Bot: Automated Memory Analysis<br/>
 <a href="https://isc.sans.edu/forums/diary/Volatility+Bot+Automated+Memory+Analysis/21655/">https://isc.sans.edu/forums/diary/Volatility+Bot+Automated+Memory+Analysis/21655/</a><br/>
911 System Fragility Exposed in Accidental DoS Attacks<br/>
 <a href="https://staging.mcso.org/Multimedia/PressRelease/911%20Cyber%20Attack.pdf">https://staging.mcso.org/Multimedia/PressRelease/911%20Cyber%20Attack.pdf</a><br/>
Vulnerability in Mirai Botnet<br/>
 <a href="https://www.invincealabs.com/blog/2016/10/killing-mirai/">https://www.invincealabs.com/blog/2016/10/killing-mirai/</a><br/>
XNU Kernel (iOS/macOS) task_t Privildge Escalation<br/>
 <a href="https://googleprojectzero.blogspot.de/2016/10/taskt-considered-harmful.html">https://googleprojectzero.blogspot.de/2016/10/taskt-considered-harmful.html</a><br/>
]]></description>
<itunes:duration>6:44
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5231" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 28th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5229</itunes:episode>
<itunes:subtitle>Small Changes to Ransomware E-Mails;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Small Changes to Ransomware E-Mails;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5229.mp3" length="5025792" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5229.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5229</link>
<pubDate>Thu, 27 Oct 2016 23:45:02 GMT</pubDate>
<description><![CDATA[Small Changes to Ransomware E-Mails May Fool Some Mail Filters<br/>
 <a href="https://isc.sans.edu/forums/diary/Your+Bill+Is+Not+Overdue+today/21647/">https://isc.sans.edu/forums/diary/Your+Bill+Is+Not+Overdue+today/21647/</a><br/>
Microsoft / Google Release Browser Updates to Address Flash Vulnerablity<br/>
 <a href="https://technet.microsoft.com/en-us/library/security/ms16-128.aspx">https://technet.microsoft.com/en-us/library/security/ms16-128.aspx</a><br/>
 <a href="https://googlechromereleases.blogspot.com">https://googlechromereleases.blogspot.com</a><br/>
Social Media "Support" Phishing<br/>
 <a href="https://www.proofpoint.com/us/corporate-blog/post/cybercriminals-spoof-every-major-bank-masquerade-branded-customer-service-twitter-accounts">https://www.proofpoint.com/us/corporate-blog/post/cybercriminals-spoof-every-major-bank-masquerade-branded-customer-service-twitter-accounts</a><br/>
Path Traversal Vulnerablity in gnu tar<br/>
 <a href="https://sintonen.fi/advisories/tar-extract-pathname-bypass.proper.txt">https://sintonen.fi/advisories/tar-extract-pathname-bypass.proper.txt</a><br/>
Podcast Survey<br/>
 <a href="https://dshield.typeform.com/to/lVgHr5">https://dshield.typeform.com/to/lVgHr5</a><br/>
]]></description>
<itunes:duration>6:35
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5229" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 27th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5227</itunes:episode>
<itunes:subtitle>#Adobe Flash Patch; #Pwn2Own; #Startcom/#Wosign Update; #Joomla #Exploit; #Google #CSRF;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Adobe Flash Patch; #Pwn2Own; #Startcom/#Wosign Update; #Joomla #Exploit; #Google #CSRF;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5227.mp3" length="4690048" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5227.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5227</link>
<pubDate>Wed, 26 Oct 2016 23:55:02 GMT</pubDate>
<description><![CDATA[Adobe Releases Emergency Patch For Flash<br/>
 <a href="https://isc.sans.edu/forums/diary/Critical+Flash+Player+Update+APSB1636/21643/">https://isc.sans.edu/forums/diary/Critical+Flash+Player+Update+APSB1636/21643/</a><br/>
Mobile Pwn2Own Writeup<br/>
 <a href="http://blog.trendmicro.com/results-mobile-pwn2own-2016/">http://blog.trendmicro.com/results-mobile-pwn2own-2016/</a><br/>
Mozilla Will Stick With Blacklisting Startcom/WoSign<br/>
 <a href="https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/">https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/</a><br/>
Joomla Exploit Released<br/>
 <a href="https://medium.com/@showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.b8gks1jar">https://medium.com/@showthread/joomla-3-6-4-account-creation-elevated-privileges-write-up-and-exploit-965d8fb46fa2#.b8gks1jar</a><br/>
Google Spreadsheet Vulnerability<br/>
 <a href="https://www.rodneybeede.com/Google_Spreadsheet_Vuln_-_CSRF_and_JSON_Hijacking_allows_data_theft.html">https://www.rodneybeede.com/Google_Spreadsheet_Vuln_-_CSRF_and_JSON_Hijacking_allows_data_theft.html</a><br/>
]]></description>
<itunes:duration>6:02
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5227" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 26th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5225</itunes:episode>
<itunes:subtitle>Patch #Joomla Now; Letsencrypt Persistent Domain Validation; New Locky Variant
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Patch #Joomla Now; Letsencrypt Persistent Domain Validation; New Locky Variant
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5225.mp3" length="4092032" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5225.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5225</link>
<pubDate>Wed, 26 Oct 2016 01:25:02 GMT</pubDate>
<description><![CDATA[Joomla Fixes Two Critical Vulnerablities;<br/>
 <a href="https://www.joomla.org/announcements/release-news/5678-joomla-3-6-4-released.html">https://www.joomla.org/announcements/release-news/5678-joomla-3-6-4-released.html</a><br/>
Letsencrypt Domain Verification Problem<br/>
 <a href="https://dan.enigmabridge.com/lets-encrypts-vulnerability-as-a-feature-authz-reuse-and-eternal-account-key/">https://dan.enigmabridge.com/lets-encrypts-vulnerability-as-a-feature-authz-reuse-and-eternal-account-key/</a><br/>
New Locky Variants: Pumpkin Locky<br/>
 <a href="http://blog.talosintel.com/2016/10/pumpkin-locky.html">http://blog.talosintel.com/2016/10/pumpkin-locky.html</a><br/>
Pagers still in use for Critical Infrastructure<br/>
 <a href="http://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/industrial-plant-beepers-leaking-secrets">http://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/industrial-plant-beepers-leaking-secrets</a><br/>
]]></description>
<itunes:duration>5:16
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5225" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 25th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5223</itunes:episode>
<itunes:subtitle>#MacOS #iOS Updates; LTE MitM Exploit; Rowhammer Exploited Against Android
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#MacOS #iOS Updates; LTE MitM Exploit; Rowhammer Exploited Against Android
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5223.mp3" length="5179520" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5223.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5223</link>
<pubDate>Tue, 25 Oct 2016 00:50:02 GMT</pubDate>
<description><![CDATA[Updates For iOS, MacOS, Safari<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
LTE Intercept Vulnerability <br/>
 <a href="http://www.theregister.co.uk/2016/10/23/every_lte_call_text_can_be_intercepted_blacked_out_hacker_finds/">http://www.theregister.co.uk/2016/10/23/every_lte_call_text_can_be_intercepted_blacked_out_hacker_finds/</a><br/>
Rowhammer Exploit Demonstrated Against Android<br/>
 <a href="https://www.vusec.net/projects/drammer/">https://www.vusec.net/projects/drammer/</a><br/>
]]></description>
<itunes:duration>6:36
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5223" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 24th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5221</itunes:episode>
<itunes:subtitle>#Dyn DNS DDoS Attack;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Dyn DNS DDoS Attack;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5221.mp3" length="5759104" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5221.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5221</link>
<pubDate>Sun, 23 Oct 2016 22:10:02 GMT</pubDate>
<description><![CDATA[ISC Briefing: Large DDoS Attack Against Dyn<br/>
 <a href="https://isc.sans.edu/forums/diary/ISC+Briefing+Large+DDoS+Attack+Against+Dyn/21627/">https://isc.sans.edu/forums/diary/ISC+Briefing+Large+DDoS+Attack+Against+Dyn/21627/</a><br/>
TCP Port 4786: Cisco Memory Leak Vulnerability <br/>
 <a href="https://isc.sans.edu/forums/diary/Request+for+Packets+TCP+4786+CVE20166385/21625/">https://isc.sans.edu/forums/diary/Request+for+Packets+TCP+4786+CVE20166385/21625/</a><br/>
Dirty Cow PoC Exploits Available<br/>
 <a href="https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs">https://github.com/dirtycow/dirtycow.github.io/wiki/PoCs</a><br/>
To register for today's SANS Technology Institute's Professional Lecture Series, pleaes e-mail info@sans.edu<br/>
]]></description>
<itunes:duration>7:22
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5221" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 21st 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5219</itunes:episode>
<itunes:subtitle>#NanoCore RAT; #DirtyCow Priv Escalation Flaw;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#NanoCore RAT; #DirtyCow Priv Escalation Flaw;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5219.mp3" length="4796544" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5219.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5219</link>
<pubDate>Thu, 20 Oct 2016 23:35:02 GMT</pubDate>
<description><![CDATA[NanoCore RAT Malspam Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Malspam+delivers+NanoCore+RAT/21615/">https://isc.sans.edu/forums/diary/Malspam+delivers+NanoCore+RAT/21615/</a><br/>
Dirty Cow Privilege Escalation Flaw<br/>
 <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1384344#c13">https://bugzilla.redhat.com/show_bug.cgi?id=1384344#c13</a><br/>
Lexmark Markvision Enterprise Application Vulnerability<br/>
 <a href="https://www.digitaldefense.com/blog-zero-day-lexmark-markvision/">https://www.digitaldefense.com/blog-zero-day-lexmark-markvision/</a><br/>
WebRTC Security Overview<br/>
 <a href="https://webrtc-security.github.io">https://webrtc-security.github.io</a><br/>
UPnP Scanner<br/>
 <a href="https://www.tenable.com/blog/do-you-know-where-your-upnp-is">https://www.tenable.com/blog/do-you-know-where-your-upnp-is</a><br/>
]]></description>
<itunes:duration>6:05
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5219" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 20th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5217</itunes:episode>
<itunes:subtitle>#ICS Files Used to "Amplify" spam; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#ICS Files Used to "Amplify" spam; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5217.mp3" length="4399232" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5217.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5217</link>
<pubDate>Wed, 19 Oct 2016 23:30:01 GMT</pubDate>
<description><![CDATA[Spam Delivered Via .ICS Files<br/>
<a href="https://isc.sans.edu/forums/diary/Spam+Delivered+via+ICS+Files/21611/">https://isc.sans.edu/forums/diary/Spam+Delivered+via+ICS+Files/21611/</a><br/>
Comodo OCR Errors Leads to SSL Certificate Verification Issues<br/>
 <a href="https://heise.de/-3354229">https://heise.de/-3354229</a> (german only)<br/>
Oracle Quarterly Critical Patch Update<br/>
 <a href="http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html">http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html</a><br/>
Images Used to Exfiltrate CC Numbers From Web Stores<br/>
 <a href="https://blog.sucuri.net/2016/10/magento-credit-card-swiper-exports-image.html">https://blog.sucuri.net/2016/10/magento-credit-card-swiper-exports-image.html</a><br/>
]]></description>
<itunes:duration>5:45
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5217" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 19th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5215</itunes:episode>
<itunes:subtitle>#SSL/#SSH Confusion; #Dyre is Back; How Stolen iPhones are Unlocked;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#SSL/#SSH Confusion; #Dyre is Back; How Stolen iPhones are Unlocked;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5215.mp3" length="5195904" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5215.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5215</link>
<pubDate>Wed, 19 Oct 2016 00:55:02 GMT</pubDate>
<description><![CDATA[SSL Client Hellos Soliciting SSH Banners from HAProxy<br/>
 <a href="https://isc.sans.edu/forums/diary/OpenSSH+Protocol+Mismatch+In+Response+to+SSL+Client+Hello/21609/">https://isc.sans.edu/forums/diary/OpenSSH+Protocol+Mismatch+In+Response+to+SSL+Client+Hello/21609/</a><br/>
Dyre is Back as Trickbot<br/>
 <a href="http://www.threatgeek.com/2016/10/trickbot-the-dyre-connection.html">http://www.threatgeek.com/2016/10/trickbot-the-dyre-connection.html</a><br/>
How Stolen iPhones Are Unlocked<br/>
 <a href="https://www.linkedin.com/pulse/sin-card-how-criminals-unlocked-stolen-iphone-6s-renato-marinho?trk=pulse_spock-articles">https://www.linkedin.com/pulse/sin-card-how-criminals-unlocked-stolen-iphone-6s-renato-marinho?trk=pulse_spock-articles</a><br/>
]]></description>
<itunes:duration>6:48
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5215" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 18th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5213</itunes:episode>
<itunes:subtitle>Mozilla Users Reach 50% HTTPs; Yahoo! Mail MITM; LastPass Memory Forensics
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Mozilla Users Reach 50% HTTPs; Yahoo! Mail MITM; LastPass Memory Forensics
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5213.mp3" length="4046976" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5213.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5213</link>
<pubDate>Mon, 17 Oct 2016 23:50:01 GMT</pubDate>
<description><![CDATA[Mozilla Users Reach 50% Https<br/>
 <a href="https://twitter.com/0xjosh/status/786971412959420424/photo/1">https://twitter.com/0xjosh/status/786971412959420424/photo/1</a><br/>
Retrieving LastPass Passwords From Memory<br/>
 <a href="https://techanarchy.net/2016/10/extracting-lastpass-site-credentials-from-memory/">https://techanarchy.net/2016/10/extracting-lastpass-site-credentials-from-memory/</a><br/>
Yahoo MITM Due To Weak Crossdomain.xml Configuration<br/>
 <a href="https://github.com/JordanMilne/YMail-Pineapple">https://github.com/JordanMilne/YMail-Pineapple</a><br/>
]]></description>
<itunes:duration>5:20
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5213" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 17th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5211</itunes:episode>
<itunes:subtitle>pseudoDarkleach Switches Payload; Decoding VBA; Auditing SSH;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
pseudoDarkleach Switches Payload; Decoding VBA; Auditing SSH;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5211.mp3" length="4194432" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5211.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5211</link>
<pubDate>Sun, 16 Oct 2016 23:55:02 GMT</pubDate>
<description><![CDATA[PseudoDakrleech Uses Rig Exploit Kit to Spread Cerber<br/>
 <a href="https://isc.sans.edu/forums/diary/pseudoDarkleech+Rig+EK/21595/">https://isc.sans.edu/forums/diary/pseudoDarkleech+Rig+EK/21595/</a><br/>
Decoder.xls to Decode Word Malicious Macro<br/>
 <a href="https://isc.sans.edu/forums/diary/Analyzing+Office+Maldocs+With+Decoderxls/21601/">https://isc.sans.edu/forums/diary/Analyzing+Office+Maldocs+With+Decoderxls/21601/</a><br/>
Auditing SSH Servers<br/>
 <a href="https://github.com/arthepsy/ssh-audit">https://github.com/arthepsy/ssh-audit</a><br/>
How Not To User HTML Purifier<br/>
 <a href="https://devwerks.net/blog/16/how-not-to-use-html-purifier/">https://devwerks.net/blog/16/how-not-to-use-html-purifier/</a><br/>
]]></description>
<itunes:duration>5:31
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5211" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 14th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5209</itunes:episode>
<itunes:subtitle>Mount Docker Filesystems; Globalsign Messes Up CA; DXXD Ransomware; LockyDump
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Mount Docker Filesystems; Globalsign Messes Up CA; DXXD Ransomware; LockyDump
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5209.mp3" length="4206720" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5209.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5209</link>
<pubDate>Fri, 14 Oct 2016 00:50:02 GMT</pubDate>
<description><![CDATA[Mount Docker Filesystems with docker-mount.py<br/>
 <a href="https://isc.sans.edu/forums/diary/New+tool+dockermountpy/21589/">https://isc.sans.edu/forums/diary/New+tool+dockermountpy/21589/</a><br/>
Global Sign OCSP Mess Up Invalidates Countless Certs<br/>
 <a href="https://downloads.globalsign.com/acton/fs/blocks/showLandingPage/a/2674/p/p-008f/t/page/fm/0">https://downloads.globalsign.com/acton/fs/blocks/showLandingPage/a/2674/p/p-008f/t/page/fm/0</a><br/>
Cisco Releases LockyDump<br/>
 <a href="http://blog.talosintel.com/2016/10/lockydump.html">http://blog.talosintel.com/2016/10/lockydump.html</a><br/>
Google Updates Chrome<br/>
 <a href="https://googlechromereleases.blogspot.com/2016/10/stable-channel-update-for-desktop.html">https://googlechromereleases.blogspot.com/2016/10/stable-channel-update-for-desktop.html</a><br/>
DXXD Ransomware Infected un-mapped Shares<br/>
 <a href="http://www.bleepingcomputer.com/news/security/the-dxxd-ransomware-displays-legal-notice-before-users-login/">http://www.bleepingcomputer.com/news/security/the-dxxd-ransomware-displays-legal-notice-before-users-login/</a><br/>
]]></description>
<itunes:duration>5:30
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5209" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 13th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5207</itunes:episode>
<itunes:subtitle>Wifi Dangers; AVTECH IP Camera Vulns; SAP Patches; 1024 Bit Keys Factored;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Wifi Dangers; AVTECH IP Camera Vulns; SAP Patches; 1024 Bit Keys Factored;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5207.mp3" length="4706432" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5207.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5207</link>
<pubDate>Wed, 12 Oct 2016 22:50:02 GMT</pubDate>
<description><![CDATA[WiFi Still Remains a Good Attack Vector<br/>
 <a href="https://isc.sans.edu/forums/diary/WiFi+Still+Remains+a+Good+Attack+Vector/21583/">https://isc.sans.edu/forums/diary/WiFi+Still+Remains+a+Good+Attack+Vector/21583/</a><br/>
AVTECH IP Camera Vulnerabilities<br/>
 <a href="http://seclists.org/bugtraq/2016/Oct/26">http://seclists.org/bugtraq/2016/Oct/26</a><br/>
SAP Patches 3 Year Old Bug in P4<br/>
 <a href="https://erpscan.com/press-center/blog/sap-cyber-threat-intelligence-report-october-2016/">https://erpscan.com/press-center/blog/sap-cyber-threat-intelligence-report-october-2016/</a><br/>
1024 bit DSA Keys Factored <br/>
 <a href="https://eprint.iacr.org/2016/961.pdf">https://eprint.iacr.org/2016/961.pdf</a><br/>
]]></description>
<itunes:duration>6:13
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5207" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 12th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5205</itunes:episode>
<itunes:subtitle>#MSFT, #Adobe Patches, badssl.com summary, More Swift Attacks
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#MSFT, #Adobe Patches, badssl.com summary, More Swift Attacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5205.mp3" length="4642944" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5205.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5205</link>
<pubDate>Tue, 11 Oct 2016 22:35:02 GMT</pubDate>
<description><![CDATA[Microsoft and Adobe Patches<br/>
<a href="https://isc.sans.edu/mspatchdays.html?viewday=2016-10-11">https://isc.sans.edu/mspatchdays.html?viewday=2016-10-11</a><br/>
<a href="https://helpx.adobe.com/security/products/acrobat/apsb16-33.html">https://helpx.adobe.com/security/products/acrobat/apsb16-33.html</a><br/>
<a href="http://www.minixforum.com/threads/neo-z64w-doesnt-start-anymore-after-windows-10-update-help.14122/">http://www.minixforum.com/threads/neo-z64w-doesnt-start-anymore-after-windows-10-update-help.14122/</a><br/>
Review of Browsers SSL Failures<br/>
 <a href="https://docs.google.com/document/d/1b7lenmn5XO06QohaJzVffnJxjXjY1rD70wg34gfuxRo/edit#heading=h.w6vk76mv9e6n">https://docs.google.com/document/d/1b7lenmn5XO06QohaJzVffnJxjXjY1rD70wg34gfuxRo/edit#heading=h.w6vk76mv9e6n</a><br/>
New Malware Targeting SWIFT Users<br/>
 <a href="http://www.symantec.com/connect/blogs/odinaff-new-trojan-used-high-level-financial-attacks">http://www.symantec.com/connect/blogs/odinaff-new-trojan-used-high-level-financial-attacks</a><br/>
]]></description>
<itunes:duration>5:58
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5205" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 11th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5203</itunes:episode>
<itunes:subtitle>#rehash calc entropy
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#rehash calc entropy
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5203.mp3" length="2670720" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5203.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5203</link>
<pubDate>Tue, 11 Oct 2016 02:55:02 GMT</pubDate>
<description><![CDATA[Radare's Rehash Utility CAn calculate File Entropy <br/>
 <a href="https://isc.sans.edu/forums/diary/Radare2+rahash2/21577/">https://isc.sans.edu/forums/diary/Radare2+rahash2/21577/</a><br/>
Spoofing IPs Still works<br/>
 <a href="https://idea.popcount.org/2016-09-20-strange-loop---ip-spoofing/">https://idea.popcount.org/2016-09-20-strange-loop---ip-spoofing/</a><br/>
EU Commission Plants IoT Labeling<br/>
 <a href="http://www.euractiv.com/section/innovation-industry/news/commission-plans-cybersecurity-rules-for-internet-connected-machines/">http://www.euractiv.com/section/innovation-industry/news/commission-plans-cybersecurity-rules-for-internet-connected-machines/</a><br/>
]]></description>
<itunes:duration>3:29
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5203" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 10th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5201</itunes:episode>
<itunes:subtitle>Hurricane Matthew Phish; KNOXOut Vulnerability; Win 10 Improves XSS Protection
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Hurricane Matthew Phish; KNOXOut Vulnerability; Win 10 Improves XSS Protection
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5201.mp3" length="3973248" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5201.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5201</link>
<pubDate>Sun, 09 Oct 2016 23:45:02 GMT</pubDate>
<description><![CDATA[First Hurricane Matthew Phish Impersonating Stripe<br/>
 <a href="https://isc.sans.edu/forums/diary/First+Hurricane+Matthew+related+Phish/21571/">https://isc.sans.edu/forums/diary/First+Hurricane+Matthew+related+Phish/21571/</a><br/>
Samsung Galaxy S6 "KNOXOut" Vulnerability<br/>
 <a href="http://media.wix.com/ugd/4e84e6_668d564cc447434a9a8fda3c13a63f6a.pdf">http://media.wix.com/ugd/4e84e6_668d564cc447434a9a8fda3c13a63f6a.pdf</a><br/>
Windows 10 Anniversary Edition Improves IE 10 XSS Protection<br/>
 <a href="http://mksben.l0.cm/2016/10/xss-via-referrer.html">http://mksben.l0.cm/2016/10/xss-via-referrer.html</a><br/>
]]></description>
<itunes:duration>5:09
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5201" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, October 7th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5199</itunes:episode>
<itunes:subtitle>Honeypot Fun; OS X Webcam; iOS Privacy; Steam Chat Hacks
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Honeypot Fun; OS X Webcam; iOS Privacy; Steam Chat Hacks
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5199.mp3" length="4485248" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5199.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5199</link>
<pubDate>Fri, 07 Oct 2016 03:25:01 GMT</pubDate>
<description><![CDATA[More Honeypot Fun<br/>
 <a href="https://isc.sans.edu/forums/diary/Checking+my+honeypot+day/21561/">https://isc.sans.edu/forums/diary/Checking+my+honeypot+day/21561/</a><br/>
OS X Webcam Exploit <br/>
 <a href="https://objective-see.com/products/oversight.html">https://objective-see.com/products/oversight.html</a><br/>
iOS 10 Private Browsing<br/>
 <a href="https://www.intaforensics.com/2016/09/30/ios-10-private-browsing-how-private-is-it/">https://www.intaforensics.com/2016/09/30/ios-10-private-browsing-how-private-is-it/</a><br/>
Hacked Steam Accounts Used to Spread Malware<br/>
 <a href="http://www.bleepingcomputer.com/news/security/hacked-steam-accounts-spreading-remote-access-trojan/">http://www.bleepingcomputer.com/news/security/hacked-steam-accounts-spreading-remote-access-trojan/</a><br/>
Please Report Any Hurricane Matthew Related Malware/Scams<br/>
 <a href="https://isc.sans.edu/contact.html">https://isc.sans.edu/contact.html</a><br/>
]]></description>
<itunes:duration>5:41
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5199" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, October 6th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5197</itunes:episode>
<itunes:subtitle>Ouch Newsletter; Security Fatigue; Selfi Pay; MarsJoke Decrypter
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Ouch Newsletter; Security Fatigue; Selfi Pay; MarsJoke Decrypter
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5197.mp3" length="4442240" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5197.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5197</link>
<pubDate>Thu, 06 Oct 2016 04:20:02 GMT</pubDate>
<description><![CDATA[Securing the Human Newsletter<br/>
 <a href="https://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201610_en.pdf">https://securingthehuman.sans.org/newsletters/ouch/issues/OUCH-201610_en.pdf</a><br/>
"Security Fatigue" <br/>
 <a href="https://www.nist.gov/news-events/news/2016/10/security-fatigue-can-cause-computer-users-feel-hopeless-and-act-recklessly">https://www.nist.gov/news-events/news/2016/10/security-fatigue-can-cause-computer-users-feel-hopeless-and-act-recklessly</a><br/>
"Selfi Pay" Facial Recognition<br/>
 <a href="http://www.theregister.co.uk/2016/10/05/mastercard_selfie_pay/">http://www.theregister.co.uk/2016/10/05/mastercard_selfie_pay/</a><br/>
"MarsJoke" Ransomware Decrypted<br/>
 <a href="https://threatpost.com/researchers-break-marsjoke-ransomware-encryption/121022/">https://threatpost.com/researchers-break-marsjoke-ransomware-encryption/121022/</a><br/>
]]></description>
<itunes:duration>5:40
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5197" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, October 5th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5195</itunes:episode>
<itunes:subtitle>Misguided SSL Requests; Insulin Pump Flaws; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Misguided SSL Requests; Insulin Pump Flaws; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5195.mp3" length="4282496" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5195.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5195</link>
<pubDate>Wed, 05 Oct 2016 03:15:02 GMT</pubDate>
<description><![CDATA[SSL Requests to Non-SSL Web Servers<br/>
 <a href="https://isc.sans.edu/forums/diary/SSL+Requests+to+nonSSL+HTTP+Servers/21551/">https://isc.sans.edu/forums/diary/SSL+Requests+to+nonSSL+HTTP+Servers/21551/</a><br/>
Insulin Pump Vulnerablities<br/>
 <a href="https://community.rapid7.com/community/infosec/blog/2016/10/04/r7-2016-07-multiple-vulnerabilities-in-animas-onetouch-ping-insulin-pump">https://community.rapid7.com/community/infosec/blog/2016/10/04/r7-2016-07-multiple-vulnerabilities-in-animas-onetouch-ping-insulin-pump</a><br/>
SSH Konami Codes<br/>
 <a href="http://pen-testing.sans.org/blog/2015/11/10/protected-using-the-ssh-konami-code-ssh-control-sequences">http://pen-testing.sans.org/blog/2015/11/10/protected-using-the-ssh-konami-code-ssh-control-sequences</a><br/>
Cyber Security Awareness Month<br/>
 <a href="https://securingthehuman.sans.org/blog/2016/10/02/week01-kicking-off-ncsam/">https://securingthehuman.sans.org/blog/2016/10/02/week01-kicking-off-ncsam/</a><br/>
OpenJPEG Flaw<br/>
 <a href="http://blog.talosintel.com/2016/09/vulnerability-spotlight-jpeg2000.html">http://blog.talosintel.com/2016/09/vulnerability-spotlight-jpeg2000.html</a><br/>
]]></description>
<itunes:duration>5:32
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5195" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, October 4th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5193</itunes:episode>
<itunes:subtitle>Password Buddy; iMessage Info Leak; Exploiting Kiosks 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Password Buddy; iMessage Info Leak; Exploiting Kiosks 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5193.mp3" length="4386944" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5193.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5193</link>
<pubDate>Tue, 04 Oct 2016 05:00:02 GMT</pubDate>
<description><![CDATA[Password Buddies<br/>
<a href="https://isc.sans.edu/forums/diary/Password+Buddies+A+Better+Way+To+Reset+Passwords/21547/">https://isc.sans.edu/forums/diary/Password+Buddies+A+Better+Way+To+Reset+Passwords/21547/</a><br/>
iMessage Data Leakage<br/>
<a href="http://rsmck.co.uk/blog/imessage-preview/">http://rsmck.co.uk/blog/imessage-preview/</a><br/>
Exploiting HP Thin Client<br/>
<a href="http://blog.malerisch.net/2016/10/pwning-thin-client-in-less-two-minutes2-cve2016-2246.html">http://blog.malerisch.net/2016/10/pwning-thin-client-in-less-two-minutes2-cve2016-2246.html</a><br/>
]]></description>
<itunes:duration>5:43
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5193" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, October 3rd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5191</itunes:episode>
<itunes:subtitle>DVR Exploit Analysis; Odd User-Agent From Word Exploit;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
DVR Exploit Analysis; Odd User-Agent From Word Exploit;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5191.mp3" length="4634752" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5191.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5191</link>
<pubDate>Mon, 03 Oct 2016 04:35:02 GMT</pubDate>
<description><![CDATA[The Short Life of a Vulnerable DVR Connected to the Internet<br/>
 <a href="https://isc.sans.edu/forums/diary/The+Short+Life+of+a+Vulnerable+DVR+Connected+to+the+Internet/21543/">https://isc.sans.edu/forums/diary/The+Short+Life+of+a+Vulnerable+DVR+Connected+to+the+Internet/21543/</a><br/>
Another Day, Another Malicious Behaviour<br/>
 <a href="https://isc.sans.edu/forums/diary/Another+Day+Another+Malicious+Behaviour/21539/">https://isc.sans.edu/forums/diary/Another+Day+Another+Malicious+Behaviour/21539/</a><br/>
Capcom's Streetfighter V Anti Cheat Tool Allows Privilege Escalation<br/>
 <a href="https://twitter.com/TheWack0lian/status/779397840762245124/photo/1?ref_src=twsrc%5Etfw">https://twitter.com/TheWack0lian/status/779397840762245124/photo/1?ref_src=twsrc%5Etfw</a><br/>
Apple Joins Mozilla In Distrusting WoSign<br/>
 <a href="https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/lWJ1zdUJPLI">https://groups.google.com/forum/#!topic/mozilla.dev.security.policy/lWJ1zdUJPLI</a><br/>
"Footprints" Browser Extension Demonstrate Unmasking User's Idendity<br/>
 <a href="https://footprints.stanford.edu">https://footprints.stanford.edu</a><br/>
]]></description>
<itunes:duration>6:02
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5191" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 30th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5189</itunes:episode>
<itunes:subtitle>#SNMP Pw0n3ge; Yahoo! Answers For Bots; Unpatched DLink Router Vuln
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#SNMP Pw0n3ge; Yahoo! Answers For Bots; Unpatched DLink Router Vuln
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5189.mp3" length="4167680" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5189.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5189</link>
<pubDate>Fri, 30 Sep 2016 01:35:02 GMT</pubDate>
<description><![CDATA[Turning the lights off with SNMP<br/>
 <a href="https://isc.sans.edu/forums/diary/SNMP+Pwn3ge/21533/">https://isc.sans.edu/forums/diary/SNMP+Pwn3ge/21533/</a><br/>
Yahoo! Anwers Used in Command and Control Networks<br/>
 <a href="http://researchcenter.paloaltonetworks.com/2016/09/unit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites/">http://researchcenter.paloaltonetworks.com/2016/09/unit42-confucius-says-malware-families-get-further-by-abusing-legitimate-websites/</a><br/>
Dlink Router Includes Stupid Simple UDP Backdoor<br/>
 <a href="https://pierrekim.github.io/blog/2016-09-28-dlink-dwr-932b-lte-routers-vulnerabilities.html">https://pierrekim.github.io/blog/2016-09-28-dlink-dwr-932b-lte-routers-vulnerabilities.html</a><br/>
Hikvision XXE Vulnerability<br/>
 <a href="https://medium.com/@iraklis/an-unlikely-xxe-in-hikvisions-remote-access-camera-cloud-d57faf99620f#.qukzihoew">https://medium.com/@iraklis/an-unlikely-xxe-in-hikvisions-remote-access-camera-cloud-d57faf99620f#.qukzihoew</a><br/>
]]></description>
<itunes:duration>5:23
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5189" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 29th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5187</itunes:episode>
<itunes:subtitle>Rig Exploit Kit; osquery for Windows; Update Cowrie; BIND&amp;Cisco DoS
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Rig Exploit Kit; osquery for Windows; Update Cowrie; BIND&amp;Cisco DoS
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5187.mp3" length="3917952" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5187.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5187</link>
<pubDate>Wed, 28 Sep 2016 23:45:02 GMT</pubDate>
<description><![CDATA[Rig Exploit Kit Used to Spread Locky Ransomware<br/>
 <a href="https://isc.sans.edu/forums/diary/Rig+Exploit+Kit+from+the+Afraidgate+Campaign/21531/">https://isc.sans.edu/forums/diary/Rig+Exploit+Kit+from+the+Afraidgate+Campaign/21531/</a><br/>
Facebook Releases osquery for Windows<br/>
 <a href="https://blog.trailofbits.com/2016/09/27/windows-network-security-now-easier-with-osquery/">https://blog.trailofbits.com/2016/09/27/windows-network-security-now-easier-with-osquery/</a><br/>
Update Cowrie and "New" Default Password used in Internet Wide Scans<br/>
 <a href="https://isc.sans.edu/ssh.html?pw=xc3511">https://isc.sans.edu/ssh.html?pw=xc3511</a><br/>
BIND Name Server Update<br/>
 <a href="https://kb.isc.org/article/AA-01393/74/CVE-2016-2775%3A-A-query-name-which-is-too-long-can-cause-a-segmentation-fault-in-lwresd.html">https://kb.isc.org/article/AA-01393/74/CVE-2016-2775%3A-A-query-name-which-is-too-long-can-cause-a-segmentation-fault-in-lwresd.html</a><br/>
Various Cisco DoS Vulnerabilities<br/>
 <a href="https://tools.cisco.com/security/center/publicationListing.x?product=NonCisco#~Vulnerabilities">https://tools.cisco.com/security/center/publicationListing.x?product=NonCisco#~Vulnerabilities</a><br/>
]]></description>
<itunes:duration>5:07
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5187" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 28th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5185</itunes:episode>
<itunes:subtitle>Memory #Forensics Tricks; #IoT #DDoS; Google #CSP Tools; #Microsoft Cloud Fuzzer
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Memory #Forensics Tricks; #IoT #DDoS; Google #CSP Tools; #Microsoft Cloud Fuzzer
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5185.mp3" length="3991680" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5185.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5185</link>
<pubDate>Wed, 28 Sep 2016 01:20:01 GMT</pubDate>
<description><![CDATA[Back in Time Memory Forensics<br/>
 <a href="https://isc.sans.edu/forums/diary/Back+in+Time+Memory+Forensics/21527/">https://isc.sans.edu/forums/diary/Back+in+Time+Memory+Forensics/21527/</a><br/>
Cameras Responsible For Large DDoS Attacks<br/>
 <a href="https://twitter.com/olesovhcom/status/779297257199964160">https://twitter.com/olesovhcom/status/779297257199964160</a><br/>
Google Releases CSP Support Tools<br/>
 <a href="https://csp-evaluator.withgoogle.com">https://csp-evaluator.withgoogle.com</a><br/>
 <a href="https://chrome.google.com/webstore/detail/csp-mitigator">https://chrome.google.com/webstore/detail/csp-mitigator</a><br/>
Microsoft Launches "fuzzing-as-a-service" <br/>
 <a href="https://www.microsoft.com/en-us/springfield/">https://www.microsoft.com/en-us/springfield/</a><br/>
]]></description>
<itunes:duration>5:08
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5185" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 27th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5183</itunes:episode>
<itunes:subtitle>Decompiling PCode; #StartCom/#Wosign CAs in Trouble;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Decompiling PCode; #StartCom/#Wosign CAs in Trouble;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5183.mp3" length="4655232" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5183.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5183</link>
<pubDate>Mon, 26 Sep 2016 22:15:02 GMT</pubDate>
<description><![CDATA[Decompiling P-Code<br/>
 <a href="https://isc.sans.edu/forums/diary/VBA+and+Pcode/21521/">https://isc.sans.edu/forums/diary/VBA+and+Pcode/21521/</a><br/>
Lenovo To Add FIDO Compliant Fingerprint Reader<br/>
 <a href="http://www.theregister.co.uk/2016/09/26/intel_and_lenovo_give_the_finger_to_passwords_with_fido/">http://www.theregister.co.uk/2016/09/26/intel_and_lenovo_give_the_finger_to_passwords_with_fido/</a><br/>
More Details On Simpler Password Hasing in iOS 10<br/>
 <a href="https://twitter.com/thorsheim/status/779207177416351744">https://twitter.com/thorsheim/status/779207177416351744</a><br/>
Mozilla to Remove WoSign and StartCom From Trusted List<br/>
 <a href="https://docs.google.com/document/d/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ/preview">https://docs.google.com/document/d/1C6BlmbeQfn4a9zydVi2UvjBGv6szuSB4sMYUcVrR8vQ/preview</a><br/>
]]></description>
<itunes:duration>6:07
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5183" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 26th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5181</itunes:episode>
<itunes:subtitle>Analyzing Malicious .PUB Files;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Analyzing Malicious .PUB Files;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5181.mp3" length="4364416" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5181.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5181</link>
<pubDate>Mon, 26 Sep 2016 11:55:02 GMT</pubDate>
<description><![CDATA[Analyzing Malicious .PUB files<br/>
 <a href="https://isc.sans.edu/forums/diary/PUB+Analysis/21517/">https://isc.sans.edu/forums/diary/PUB+Analysis/21517/</a><br/>
iOS 10 Backup Passwords Easier to Crack <br/>
 <a href="http://blog.elcomsoft.com/2016/09/ios-10-security-weakness-discovered-backup-passwords-much-easier-to-break/">http://blog.elcomsoft.com/2016/09/ios-10-security-weakness-discovered-backup-passwords-much-easier-to-break/</a><br/>
Windows 10 Certificate Pinning of Microsoft Domains<br/>
 <a href="http://hexatomium.github.io/2016/09/24/hidden-w10-pins/">http://hexatomium.github.io/2016/09/24/hidden-w10-pins/</a><br/>
IBM Geoblocking Fail For Australian Census<br/>
 <a href="http://www.aph.gov.au/DocumentStore.ashx?id=124f22ba-caaa-46ff-899d-7d96851fee3e&subId=414127">http://www.aph.gov.au/DocumentStore.ashx?id=124f22ba-caaa-46ff-899d-7d96851fee3e&subId=414127</a><br/>
97% Of Fortune 1000 Companies Have Leaked Credentials<br/>
 <a href="http://info.digitalshadows.com/rs/457-XEY-671/images/CompromisedCredentials-LearnFromtheExposureoftheWorlds1000BiggestCompanies-Download.pdf">http://info.digitalshadows.com/rs/457-XEY-671/images/CompromisedCredentials-LearnFromtheExposureoftheWorlds1000BiggestCompanies-Download.pdf</a><br/>
]]></description>
<itunes:duration>5:42
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5181" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 23rd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5179</itunes:episode>
<itunes:subtitle>#openssl update; Biometric ATM Skimmer Prototypes; #Yahoo!
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#openssl update; Biometric ATM Skimmer Prototypes; #Yahoo!
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5179.mp3" length="4190336" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5179.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5179</link>
<pubDate>Thu, 22 Sep 2016 23:55:01 GMT</pubDate>
<description><![CDATA[OpenSSL Security Update<br/>
 <a href="https://isc.sans.edu/forums/diary/OpenSSL+Update+Released/21509/">https://isc.sans.edu/forums/diary/OpenSSL+Update+Released/21509/</a><br/>
ATM Skimmer Prototypes To Collect Fingerprints<br/>
 <a href="https://securelist.com/files/2016/09/16_09_en.pdf">https://securelist.com/files/2016/09/16_09_en.pdf</a><br/>
Yahoo! Breach Leaks 500M User's Data<br/>
 <a href="https://yahoo.tumblr.com/post/150781911849/an-important-message-about-yahoo-user-security">https://yahoo.tumblr.com/post/150781911849/an-important-message-about-yahoo-user-security</a><br/>
]]></description>
<itunes:duration>5:25
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5179" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 22nd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5177</itunes:episode>
<itunes:subtitle>#Locky Update; #ASMI bypass; #Cloudflare #SSL Rewrite
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Locky Update; #ASMI bypass; #Cloudflare #SSL Rewrite
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5177.mp3" length="4624512" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5177.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5177</link>
<pubDate>Wed, 21 Sep 2016 22:25:01 GMT</pubDate>
<description><![CDATA[Those never-ending waves of Locky Malspam<br/>
 <a href="https://isc.sans.edu/forums/diary/Those+neverending+waves+of+Locky+malspam/21505/">https://isc.sans.edu/forums/diary/Those+neverending+waves+of+Locky+malspam/21505/</a><br/>
Windows Anti Malware Scan Interface (AMSI)<br/>
 <a href="http://www.labofapenetrationtester.com/2016/09/amsi.html">http://www.labofapenetrationtester.com/2016/09/amsi.html</a><br/>
Cloudflare Intorducing SSL Re-Write<br/>
 <a href="https://blog.cloudflare.com/opportunistic-encryption-bringing-http-2-to-the-unencrypted-web/">https://blog.cloudflare.com/opportunistic-encryption-bringing-http-2-to-the-unencrypted-web/</a><br/>
Australian Police Warns of Malicious USB Sticks<br/>
 <a href="https://www.vicpolicenews.com.au/news/harmful-usb-drives-found-in-letterboxes">https://www.vicpolicenews.com.au/news/harmful-usb-drives-found-in-letterboxes</a><br/>
]]></description>
<itunes:duration>5:54
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5177" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 21st 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5175</itunes:episode>
<itunes:subtitle>#macos Siera Released; BackConnect BGP Hijacks;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#macos Siera Released; BackConnect BGP Hijacks;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5175.mp3" length="3854464" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5175.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5175</link>
<pubDate>Wed, 21 Sep 2016 00:15:02 GMT</pubDate>
<description><![CDATA[MacOS Sierra and Safari 10 Released<br/>
 <a href="https://isc.sans.edu/forums/diary/Getting+Ready+for+macOS+Sierra+Upgrade+Securely/21465/">https://isc.sans.edu/forums/diary/Getting+Ready+for+macOS+Sierra+Upgrade+Securely/21465/</a><br/>
 <br/>
BackConnect BGP Hijacks<br/>
 <a href="http://research.dyn.com/2016/09/backconnects-suspicious-bgp-hijacks/">http://research.dyn.com/2016/09/backconnects-suspicious-bgp-hijacks/</a><br/>
Metasploit Vulnerablity<br/>
 <a href="https://github.com/justinsteven/advisories/blob/master/2016_metasploit_rce_static_key_deserialization.md">https://github.com/justinsteven/advisories/blob/master/2016_metasploit_rce_static_key_deserialization.md</a><br/>
]]></description>
<itunes:duration>4:57
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5175" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 20th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5173</itunes:episode>
<itunes:subtitle>Taking Over Facebook Pages;
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Taking Over Facebook Pages;
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5173.mp3" length="4386944" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5173.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5173</link>
<pubDate>Tue, 20 Sep 2016 01:10:02 GMT</pubDate>
<description><![CDATA[Taking Over Facebook Pages<br/>
 <a href="http://arunsureshkumar.me/index.php/2016/09/16/facebook-page-takeover-zero-day-vulnerability/">http://arunsureshkumar.me/index.php/2016/09/16/facebook-page-takeover-zero-day-vulnerability/</a><br/>
Exchange Auto-Discovery Vulnerability<br/>
 <a href="http://www.theregister.co.uk/2016/09/19/ms_exchange_alleged_bug/">http://www.theregister.co.uk/2016/09/19/ms_exchange_alleged_bug/</a><br/>
Spyware Apps Targeting Travelers Removed From Goolge App Store<br/>
 <a href="https://blog.lookout.com/blog/2016/09/16/embassy-spyware-google-play/">https://blog.lookout.com/blog/2016/09/16/embassy-spyware-google-play/</a><br/>
Firefox Will Patch HSTS Vulnerability<br/>
 <a href="https://threatpost.com/mozilla-patching-firefox-certificate-pinning-vulnerability/120694/">https://threatpost.com/mozilla-patching-firefox-certificate-pinning-vulnerability/120694/</a><br/>
OpenSSL Patch Pre-Announcement<br/>
 <a href="https://mta.openssl.org/pipermail/openssl-announce/2016-September/000076.html">https://mta.openssl.org/pipermail/openssl-announce/2016-September/000076.html</a><br/>
]]></description>
<itunes:duration>5:39
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5173" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 19th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5171</itunes:episode>
<itunes:subtitle>Cisco IKEv1 Advisory; 64Bit Conversion Woes; Intercepting OS X Passwords; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Cisco IKEv1 Advisory; 64Bit Conversion Woes; Intercepting OS X Passwords; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5171.mp3" length="5552256" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5171.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5171</link>
<pubDate>Mon, 19 Sep 2016 01:45:02 GMT</pubDate>
<description><![CDATA[Cisco Issues Advisories for IKEv1 "heartbleed like" Vulnerability<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160916-ikev1</a><br/>
Intercepting OS X Passwords<br/>
 <a href="https://www.scriptjunkie.us/2016/09/intercepting-passwords-to-escalate-privileges-on-os-x/">https://www.scriptjunkie.us/2016/09/intercepting-passwords-to-escalate-privileges-on-os-x/</a><br/>
Vulnerabilities Introduced By Converting 32 Bit to 64 Bit<br/>
 <a href="https://www.tu-braunschweig.de/Medien-DB/sec/pubs/2016-ccs.pdf">https://www.tu-braunschweig.de/Medien-DB/sec/pubs/2016-ccs.pdf</a><br/>
HSTS Preload Database and Webservices<br/>
 <a href="https://hstspreload.com">https://hstspreload.com</a><br/>
]]></description>
<itunes:duration>7:16
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5171" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 16th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5169</itunes:episode>
<itunes:subtitle>Misc Locky Updates; WebEx Update; Windows Malware Attacking iOS/Android
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Misc Locky Updates; WebEx Update; Windows Malware Attacking iOS/Android
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5169.mp3" length="4591744" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5169.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5169</link>
<pubDate>Fri, 16 Sep 2016 03:00:02 GMT</pubDate>
<description><![CDATA[Locky Ransomware Updates<br/>
 <a href="https://blog.avira.com/locky-ransomware-goes-autopilot/">https://blog.avira.com/locky-ransomware-goes-autopilot/</a><br/>
 <a href="https://blogs.forcepoint.com/security-labs/locky-distributor-uses-newly-released-quant-loader-sold-russian-underground">https://blogs.forcepoint.com/security-labs/locky-distributor-uses-newly-released-quant-loader-sold-russian-underground</a><br/>
 <a href="https://isc.sans.edu/forums/diary/Is+2+out+of+3+good+enough+for+AntiMalware/21485/">https://isc.sans.edu/forums/diary/Is+2+out+of+3+good+enough+for+AntiMalware/21485/</a><br/>
Critical Update For Cisco WebEx Server<br/>
 <a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160914-wem">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160914-wem</a><br/>
Dualtoy Malware Attacks iOS and Android<br/>
 <a href="http://researchcenter.paloaltonetworks.com/2016/09/dualtoy-new-windows-trojan-sideloads-risky-apps-to-android-and-ios-devices/">http://researchcenter.paloaltonetworks.com/2016/09/dualtoy-new-windows-trojan-sideloads-risky-apps-to-android-and-ios-devices/</a><br/>
Certificate Pinning Issue in Firefox/Tor Browser<br/>
 <a href="https://hackernoon.com/tor-browser-exposed-anti-privacy-implantation-at-mass-scale-bd68e9eb1e95#.9jnte0u52">https://hackernoon.com/tor-browser-exposed-anti-privacy-implantation-at-mass-scale-bd68e9eb1e95#.9jnte0u52</a><br/>
]]></description>
<itunes:duration>5:50
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5169" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 15th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5167</itunes:episode>
<itunes:subtitle>Drupal RESTWS Scans; Google.fr #XSS; #VMWare Updates
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Drupal RESTWS Scans; Google.fr #XSS; #VMWare Updates
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5167.mp3" length="4075648" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5167.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5167</link>
<pubDate>Thu, 15 Sep 2016 01:00:01 GMT</pubDate>
<description><![CDATA[Exploit Attempts for Drupal RESTWS Module Vulnerablity<br/>
 <a href="https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Drupal+RESTWS+x+Module+Vulnerability/21481/">https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Drupal+RESTWS+x+Module+Vulnerability/21481/</a><br/>
Google France XSS Vulnerability<br/>
 <a href="https://sysdream.com/news/lab/2016-09-12-cross-site-scripting-vulnerability-found-on-www-google-fr/">https://sysdream.com/news/lab/2016-09-12-cross-site-scripting-vulnerability-found-on-www-google-fr/</a><br/>
Pokemon Go Continues to Lead to Malware<br/>
 <a href="https://securelist.com/blog/mobile/76081/rooting-pokemons-in-google-play-store/">https://securelist.com/blog/mobile/76081/rooting-pokemons-in-google-play-store/</a><br/>
VMWare Update Fixes Escape Vulnerablity<br/>
 <a href="https://www.vmware.com/security/advisories/VMSA-2016-0014.html">https://www.vmware.com/security/advisories/VMSA-2016-0014.html</a><br/>
]]></description>
<itunes:duration>5:11
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5167" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 14th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5165</itunes:episode>
<itunes:subtitle>Super Patch Tuesday: Microsoft, Adobe, Apple
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Super Patch Tuesday: Microsoft, Adobe, Apple
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5165.mp3" length="7303296" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5165.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5165</link>
<pubDate>Wed, 14 Sep 2016 04:10:02 GMT</pubDate>
<description><![CDATA[Microsoft Patches<br/>
 <a href="https://isc.sans.edu/mspatchdays.html?viewday=2016-09-13">https://isc.sans.edu/mspatchdays.html?viewday=2016-09-13</a><br/>
Adobe Air Patches<br/>
 <a href="https://helpx.adobe.com/security/products/air/apsb16-31.html">https://helpx.adobe.com/security/products/air/apsb16-31.html</a><br/>
iOS 10 Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Apple+iOS+10+and+1001+Released/21473/">https://isc.sans.edu/forums/diary/Apple+iOS+10+and+1001+Released/21473/</a><br/>
]]></description>
<itunes:duration>9:21
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5165" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 13th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5163</itunes:episode>
<itunes:subtitle>Free Document Converters Add Malware; check my.cnf ownership; FDE Ransomware
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Free Document Converters Add Malware; check my.cnf ownership; FDE Ransomware
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5163.mp3" length="4868224" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5163.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5163</link>
<pubDate>Tue, 13 Sep 2016 03:45:02 GMT</pubDate>
<description><![CDATA[If it's Free, YOU are the Product<br/>
 <a href="https://isc.sans.edu/forums/diary/If+its+Free+YOU+are+the+Product/21469/">https://isc.sans.edu/forums/diary/If+its+Free+YOU+are+the+Product/21469/</a><br/>
Weak MySQL Configurations Can Lead To Privilege Escalation<br/>
 <a href="http://legalhackers.com/advisories/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.html">http://legalhackers.com/advisories/MySQL-Exploit-Remote-Root-Code-Execution-Privesc-CVE-2016-6662.html</a><br/>
Full Disk Encryption Ransomware<br/>
 <a href="https://www.linkedin.com/pulse/mamba-new-full-disk-encryption-ransomware-family-member-marinho?trk=prof-post">https://www.linkedin.com/pulse/mamba-new-full-disk-encryption-ransomware-family-member-marinho?trk=prof-post</a><br/>
]]></description>
<itunes:duration>6:15
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5163" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Monday, September 12th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5161</itunes:episode>
<itunes:subtitle>Upgrade to MacOS Sierra Security; PCI PTS POI 5.0 Standard; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Upgrade to MacOS Sierra Security; PCI PTS POI 5.0 Standard; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5161.mp3" length="4792448" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5161.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5161</link>
<pubDate>Mon, 12 Sep 2016 04:30:02 GMT</pubDate>
<description><![CDATA[Upgrading Security to MacOS Sierra<br/>
 <a href="https://isc.sans.edu/forums/diary/Getting+Ready+for+macOS+Sierra+Upgrade+Securely/21465/">https://isc.sans.edu/forums/diary/Getting+Ready+for+macOS+Sierra+Upgrade+Securely/21465/</a><br/>
PCI PIN Transation Security / Point of Interaction Update<br/>
 <a href="https://www.pcisecuritystandards.org/documents/PCI_PTS_POI_SRs_v5.pdf">https://www.pcisecuritystandards.org/documents/PCI_PTS_POI_SRs_v5.pdf</a><br/>
IMAPS Scans<br/>
 <a href="https://isc.sans.edu/forums/diary/Ongoing+IMAP+Scan+Anyone+Else/21463/">https://isc.sans.edu/forums/diary/Ongoing+IMAP+Scan+Anyone+Else/21463/</a><br/>
]]></description>
<itunes:duration>6:21
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5161" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 9th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5159</itunes:episode>
<itunes:subtitle>Looking for #SNMP pcaps; #XEN Vulnerabilities; Old Bugs Still Work
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Looking for #SNMP pcaps; #XEN Vulnerabilities; Old Bugs Still Work
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5159.mp3" length="5318784" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5159.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5159</link>
<pubDate>Thu, 08 Sep 2016 23:35:02 GMT</pubDate>
<description><![CDATA[Spikes in SNMP Traffic: Looking for PCAPs<br/>
 <a href="https://isc.sans.edu/forums/diary/Curious+SNMP+Traffic+Spike/21457/">https://isc.sans.edu/forums/diary/Curious+SNMP+Traffic+Spike/21457/</a><br/>
New Version of Wireshark Released<br/>
 <a href="https://www.wireshark.org/docs/relnotes/wireshark-2.2.0.html">https://www.wireshark.org/docs/relnotes/wireshark-2.2.0.html</a><br/>
XEN Hypervisor Vulnerabilities<br/>
 <a href="https://xenbits.xen.org/xsa/">https://xenbits.xen.org/xsa/</a><br/>
Google Moving Ahead With HTTP Phaseout<br/>
 <a href="https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html">https://security.googleblog.com/2016/09/moving-towards-more-secure-web.html</a><br/>
Old Windows Media Player DRM Feature Still Used To Install Malware<br/>
 <a href="http://blog.cyren.com/articles/windows-media-player-drm-feature-used-for-malware-delivery-again.html">http://blog.cyren.com/articles/windows-media-player-drm-feature-used-for-malware-delivery-again.html</a><br/>
SEC503 Intrusion Detection in Depth Online Training<br/>
 <a href="https://www.sans.org/vlive/details/sec503-19sep2016-johannes-ullrich-phd">https://www.sans.org/vlive/details/sec503-19sep2016-johannes-ullrich-phd</a><br/>
]]></description>
<itunes:duration>7:04
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5159" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Thursday, September 8th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5157</itunes:episode>
<itunes:subtitle>Fortinet Unpatched Priv Esc Flaws; NSM Vulnerabilities
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Fortinet Unpatched Priv Esc Flaws; NSM Vulnerabilities
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5157.mp3" length="4223104" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5157.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5157</link>
<pubDate>Thu, 08 Sep 2016 00:50:02 GMT</pubDate>
<description><![CDATA[DShield Blocklist Update<br/>
 <a href="https://isc.sans.edu/forums/diary/Updated+DShield+Blocklist/21453/">https://isc.sans.edu/forums/diary/Updated+DShield+Blocklist/21453/</a><br/>
Fortinet FortiWAN Load Balancer Mulitple Unpatched Vulnerabilities<br/>
 <a href="http://www.kb.cert.org/vuls/id/724487">http://www.kb.cert.org/vuls/id/724487</a><br/>
Rapid7 Published NSM Vulnerabilities <br/>
 <a href="http://www.theregister.co.uk/2016/09/07/natwork_magement_vulns/">http://www.theregister.co.uk/2016/09/07/natwork_magement_vulns/</a><br/>
OPM Breached by Two Different Attackers<br/>
 <a href="https://oversight.house.gov/wp-content/uploads/2016/09/The-OPM-Data-Breach-How-the-Government-Jeopardized-Our-National-Security-for-More-than-a-Generation.pdf">https://oversight.house.gov/wp-content/uploads/2016/09/The-OPM-Data-Breach-How-the-Government-Jeopardized-Our-National-Security-for-More-than-a-Generation.pdf</a><br/>
]]></description>
<itunes:duration>5:32
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5157" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Wednesday, September 7th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5155</itunes:episode>
<itunes:subtitle>Google Releases Android Security Update; More Default Keys Then Ever
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Google Releases Android Security Update; More Default Keys Then Ever
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5155.mp3" length="4391040" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5155.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5155</link>
<pubDate>Tue, 06 Sep 2016 23:40:01 GMT</pubDate>
<description><![CDATA[Google September Android Security Update<br/>
 <a href="https://source.android.com/security/bulletin/2016-09-01.html">https://source.android.com/security/bulletin/2016-09-01.html</a><br/>
Hard Coded Password / Key Issue Gets Worse<br/>
 <a href="http://blog.sec-consult.com/2016/09/house-of-keys-9-months-later-40-worse.html">http://blog.sec-consult.com/2016/09/house-of-keys-9-months-later-40-worse.html</a><br/>
Snagging Credentials From Locked Machines (Windows and OS X)<br/>
 <a href="https://room362.com/post/2016/snagging-creds-from-locked-machines/">https://room362.com/post/2016/snagging-creds-from-locked-machines/</a><br/>
]]></description>
<itunes:duration>5:51
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5155" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Tuesday, September 6th 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5153</itunes:episode>
<itunes:subtitle>#Trident / #Pegasus Patch for OS X; 
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
#Trident / #Pegasus Patch for OS X; 
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5153.mp3" length="3924096" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5153.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5153</link>
<pubDate>Tue, 06 Sep 2016 00:20:01 GMT</pubDate>
<description><![CDATA[Apple Patches OS X and Safari for Trident/Pegasus Vulnerabilities<br/>
 <a href="https://support.apple.com/en-us/HT201222">https://support.apple.com/en-us/HT201222</a><br/>
Malware Delivered via ".pub" Files<br/>
 <a href="https://isc.sans.edu/forums/diary/Malware+Delivered+via+pub+Files/21443/">https://isc.sans.edu/forums/diary/Malware+Delivered+via+pub+Files/21443/</a><br/>
Sophos Anti Virus False Positive Causes Blue Screen of Death<br/>
 <a href="https://community.sophos.com/kb/en-us/125000">https://community.sophos.com/kb/en-us/125000</a><br/>
Adobe Reviving Flash for Linux<br/>
 <a href="https://blogs.adobe.com/flashplayer/2016/08/beta-news-flash-player-npapi-for-linux.html">https://blogs.adobe.com/flashplayer/2016/08/beta-news-flash-player-npapi-for-linux.html</a><br/>
Google Patches Nexuse 5X Vulnerability<br/>
 <a href="https://securityintelligence.com/undocumented-patched-vulnerability-in-nexus-5x-allowed-for-memory-dumping-via-usb/">https://securityintelligence.com/undocumented-patched-vulnerability-in-nexus-5x-allowed-for-memory-dumping-via-usb/</a> <br/>
]]></description>
<itunes:duration>5:13
</itunes:duration>
<podcast:transcript url="https://isc.sans.edu/podcasttranscript.html?id=5153" type="text/plain" language="en" />
<itunes:keywords>Security, Network, Technology, Windows, Linux, Apple, iOS, Android, Firewall, cyber, business, cybersecurity, hacking, infosec, it, news, daily, network, security, computer, internet</itunes:keywords>
</item>

<item>
<title>ISC StormCast for Friday, September 2nd 2016</title>
<itunes:author>Johannes B. Ullrich, Ph.D.</itunes:author>
<itunes:episodeType>full</itunes:episodeType>
<itunes:episode>5151</itunes:episode>
<itunes:subtitle>Malware Using MaxMind For Host ID/GeoLoc.
</itunes:subtitle>
<itunes:summary>Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. 
Malware Using MaxMind For Host ID/GeoLoc.
</itunes:summary>
<enclosure url="https://traffic.libsyn.com/securitypodcast/5151.mp3" length="3684480" type="audio/mpeg" />
<guid>https://traffic.libsyn.com/securitypodcast/5151.mp3</guid>
<link>https://isc.sans.edu/podcastdetail/5151</link>
<pubDate>Thu, 01 Sep 2016 22:40:02 GMT</pubDate>
<description><![CDATA[Malware Using Maxmind For Geolocation<br/>
 <a href="https://isc.sans.edu/forums/diary/Maxmindcom+Abused+As+AntiAnalysis+Technique/21435/">https://isc.sans.edu/forums/diary/Maxmindcom+Abused+As+AntiAnalysis+Technique/21435/</a><br/>
Content Security Policy of Limited Use in Real World<br/>
 <a href="https://research.google.com/pubs/pub45542.html">https://research.google.com/pubs/pub45542.html</a><br/>
CryptWare Bitlocker Enhancement Vulnerability<br/>
 <a href="https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20160831-0_CryptWare_CryptoPro_Manipulation_of_pre-boot_authentication_v10.txt">https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20160831-0_CryptWare_CryptoPro_Manipulation_of_pre-boot_authentication_v10.txt</a><br/>
Google Releases Chrome 53 <br/>
 <a href="http://googlechromereleases.blogspot.com/2016/08/stable-channel-u