Sinopsis
Daily update on current cyber security threats
Episodios
-
ISC StormCast for Wednesday, March 10th, 2021
10/03/2021 Duración: 07minMicrosoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+March+2021+Patch+Tuesday/27184/ Adobe Updates https://helpx.adobe.com/security.html Network Camera Breach https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams https://www.bleepingcomputer.com/news/security/hackers-access-surveillance-cameras-at-tesla-cloudflare-banks-more/ git vulnerability https://www.openwall.com/lists/oss-security/2021/03/09/3
-
ISC StormCast for Tuesday, March 9th, 2021
09/03/2021 Duración: 05minYARA and CyberChef https://isc.sans.edu/forums/diary/YARA+and+CyberChef/27180/ Apple Updates Everything https://support.apple.com/en-us/HT201222 Google Adds Port 554 to "Restricted Ports" https://chromium.googlesource.com/chromium/src.git/+/refs/heads/master/net/base/port_util.cc Yet Another Intel Side Channel Attack https://arxiv.org/pdf/2103.03443.pdf
-
ISC StormCast for Monday, March 8th, 2021
08/03/2021 Duración: 07minUpdate on Microsoft Exchange Vulnerability https://github.com/microsoft/CSS-Exchange/tree/main/Security https://github.com/nccgroup/Cyber-Defence/tree/master/Intelligence/Exchange https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b Microsoft Adding Excel 4.0 Macro Hooks to AMSI https://www.microsoft.com/security/blog/2021/03/03/xlm-amsi-new-runtime-defense-against-excel-4-0-macro-malware/ Apple Find My Device Leak https://arxiv.org/pdf/2103.02282.pdf
-
ISC StormCast for Friday, March 5th, 2021
05/03/2021 Duración: 06minFrom VBS, PowerShell, C Sharp, Process Hollowing to RAT https://isc.sans.edu/forums/diary/From+VBS+PowerShell+C+Sharp+Process+Hollowing+to+RAT/27168/ Cisco Patches Snort Related Vulnerabilities https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snort-ethernet-dos-HGXgJH8n VMWare View Planner Update https://www.vmware.com/security/advisories/VMSA-2021-0003.html Google's FLoC Algorithm https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-idea Supermicro Trickbot Patch https://www.supermicro.com/en/support/security/trickbot
-
ISC StormCast for Thursday, March 4th, 2021
04/03/2021 Duración: 04minMicrosoft Exchange Followup https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ Saltstack Vulnerability https://www.immersivelabs.com/resources/blog/why-so-salty-local-privilege-escalation-on-saltstack-minions/ GRUB2 Patches https://seclists.org/oss-sec/2021/q1/189 Dependency Confusion in the Wild https://threatpost.com/malicious-code-bombs-amazon-lyft-slack-zillow/164455/
-
ISC StormCast for Wednesday, March 3rd, 2021
03/03/2021 Duración: 07minQakbot Infection with Cobalt Strike https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike/27158/ Exchange Server 0-Day Exploits https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ Google Chrome 0-Day Exploits https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop.html
-
ISC StormCast for Tuesday, March 2nd, 2021
02/03/2021 Duración: 06minFun with DNS over TLS and https://isc.sans.edu/forums/diary/Fun+with+DNS+over+TLS+DoT/27150/ Gootloader Update https://news.sophos.com/en-us/2021/03/01/gootloader-expands-its-payload-delivery-options/ AOL Phishing https://www.bleepingcomputer.com/news/security/beware-aol-phishing-email-states-your-account-will-be-closed/ Spectre Exploit in the Wild https://dustri.org/b/spectre-exploits-in-the-wild.html
-
ISC StormCast for Monday, March 1st, 2021
01/03/2021 Duración: 05minPretending to be an Outlook Version Update https://isc.sans.edu/forums/diary/Pretending+to+be+an+Outlook+Version+Update/27144/ Geolocating Satori Botnet Scanning Port 26 https://isc.sans.edu/forums/diary/So+where+did+those+Satori+attacks+come+from/27140/ Alexa Skill Security https://www.ndss-symposium.org/wp-content/uploads/ndss2021_5A-1_23111_paper.pdf TMobile Data Breach / SIM Swapping https://beta.documentcloud.org/documents/20492859-t-mobile-feb-2021-bc-data-breach
-
ISC StormCast for Friday, February 26th, 2021
26/02/2021 Duración: 05minForensicating Azure VMs https://isc.sans.edu/forums/diary/Forensicating+Azure+VMs/27136/ FriarFox Browser Extension Targeting GMail Accounts https://www.proofpoint.com/us/blog/threat-insight/ta413-leverages-new-friarfox-browser-extension-target-gmail-accounts-global JSON Parser Inconsistencies https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities Apple MacOS Update https://www.reddit.com/r/macbook/comments/kge24m/dead_m1_mac_with_usbc_multiport_adapters/
-
ISC StormCast for Thursday, February 25th, 2021
25/02/2021 Duración: 05minMalspam Pushes GuLoader for Remcos RAT https://isc.sans.edu/forums/diary/Malspam+pushes+GuLoader+for+Remcos+RAT/27132/ vCenter Exploit / Vulnerability Details https://swarm.ptsecurity.com/unauth-rce-vmware/#more-2477 DNS CNAME Tracking https://blog.lukaszolejnik.com/large-scale-analysis-of-dns-based-tracking-evasion-broad-data-leaks-included/ Cisco MSO Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv
-
ISC StormCast for Wednesday, February 24th, 2021
24/02/2021 Duración: 06minQakbot In a Response to Full Disclosure Post https://isc.sans.edu/forums/diary/Qakbot+in+a+response+to+Full+Disclosure+post/27130/ Firefox Total Cookie Protection https://blog.mozilla.org/security/2021/02/23/total-cookie-protection/ VMWare ESXi / vCenter Server Update https://www.vmware.com/security/advisories/VMSA-2021-0002.html Replacing Content in Signed PDFs https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1B-4_24117_paper.pdf
-
ISC StormCast for Tuesday, February 23rd, 2021
23/02/2021 Duración: 05minUnprotecting Malicious Documents For Inspection https://isc.sans.edu/forums/diary/Unprotecting+Malicious+Documents+For+Inspection/27126/ Brave Browser DNS Leak https://www.theregister.com/2021/02/22/in_brief_security/ Telephony DoS https://www.ic3.gov/Media/Y2021/PSA210217
-
ISC StormCast for Monday, February 22nd, 2021
22/02/2021 Duración: 05minDynamic Data Exchange (DDE) is Back in the Wild https://isc.sans.edu/forums/diary/Dynamic+Data+Exchange+DDE+is+Back+in+the+Wild/27116/ https://isc.sans.edu/forums/diary/DDE+and+oledump/27122/ macOS Malware "Prototype" https://redcanary.com/blog/clipping-silver-sparrows-wings/ New Phishing Attack Identifed: Malformed URL Prefixes https://www.greathorn.com/blog-new-phishing-attack-identified-malformed-url-prefixes/ Sonicwall SMA 100 Firmware Update https://www.sonicwall.com/support/product-notification/additional-sma-100-series-10-x-and-9-x-firmware-updates-required-updated-feb-19-2-p-m-cst/210122173415410/
-
ISC StormCast for Friday, February 19th, 2021
19/02/2021 Duración: 05minMalspam Pushes Trickbot gtag rob13 https://isc.sans.edu/forums/diary/Malspam+pushing+Trickbot+gtag+rob13/27112/ AppleJeus https://us-cert.cisa.gov/ncas/alerts/aa21-048a Python 3 Buffer Overflow https://bugs.python.org/issue42938 Apple Platform Security Guide https://support.apple.com/guide/security/welcome/web
-
ISC StormCast for Thursday, February 18th, 2021
18/02/2021 Duración: 05minThe new "LinkedInSecureMessage" Phish https://isc.sans.edu/forums/diary/The+new+LinkedInSecureMessage/27110/ Apple M1 Optimized Malware https://objective-see.com/blog/blog_0x62.html QNAP Surveilance Station Vulnerability https://www.qnap.com/en/security-advisory/qsa-21-07 Masslogger Exfiltrates User Credentials https://blog.talosintelligence.com/2021/02/masslogger-cred-exfil.html
-
ISC StormCast for Wednesday, February 17th, 2021
17/02/2021 Duración: 05minMore Weirdness on TCP Port 26 https://isc.sans.edu/forums/diary/More+weirdness+on+TCP+port+26/27106/ Microsoft Pulls Servicing Stack Update https://threatpost.com/microsoft-windows-update-patch-tuesday/163981/ Network Monitoring Company Centreon Compromised https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-005.pdf SHAREit Flaw Could Lead to Remote Code Execution https://www.trendmicro.com/en_us/research/21/b/shareit-flaw-could-lead-to-remote-code-execution.html VSCode NPM Extension RCE https://github.com/jackadamson/CVE-2021-26700
-
ISC StormCast for Tuesday, February 16th, 2021
16/02/2021 Duración: 06minSecuring and Optimizing Networks Using pfSense Traffic Shaper to Combat Bufferbloat https://isc.sans.edu/forums/diary/Securing+and+Optimizing+Networks+Using+pfSense+Traffic+Shaper+Limiters+to+Combat+Bufferbloat/27102/ Apple to Proxy Safe Browsing Requests https://twitter.com/othermaciej/status/1359736220809531393 Power Outages and Some Network Outages as a Result https://downdetector.com Phone Scam Success Rates https://www.helpnetsecurity.com/2021/02/15/lost-money-to-phone-scams/ https://nakedsecurity.sophos.com/2021/02/12/sms-tax-scam-unmasked-bogus-but-believable-dont-fall-for-it/
-
ISC StormCast for Monday, February 15th, 2021
15/02/2021 Duración: 07minAgentTesla Dropped Through Automatic Click in Microsoft Help File https://isc.sans.edu/forums/diary/AgentTesla+Dropped+Through+Automatic+Click+in+Microsoft+Help+File/27092/ Telegram used to Defraud Delivery Serivces https://thefintechtimes.com/sift-finds-new-telegram-fraud-exploiting-increasing-use-of-food-delivery-services/ Singtel Suffers Zero-DAy Cyberattack https://threatpost.com/singtel-zero-day-cyberattack/163938/ Vulnerabilities in Mobile Health Apps https://approov.io/download/all-that-we-let-in_hacking-mhealth-apps-and-apis.pdf Bloomberg Supermicro Story https://www.bloomberg.com/features/2021-supermicro/ https://www.theregister.com/2021/02/12/supermicro_bloomberg_spying/
-
ISC StormCast for Friday, February 12th, 2021
12/02/2021 Duración: 05minAgent Tesla Hidden in Historical Anti-Malware Tool https://isc.sans.edu/forums/diary/Agent+Tesla+hidden+in+a+historical+antimalware+tool/27088/ McAfee Total Protection Vulnerabilities https://service.mcafee.com/webcenter/portal/oracle/webcenter/page/scopedMD/s55728c97_466d_4ddb_952d_05484ea932c6/Page29.jspx Intel Patches https://blogs.intel.com/technology/2021/02/ipas-security-advisories-for-february-2021 Discord Used to Distribute Malware https://www.zscaler.com/blogs/security-research/discord-cdn-popular-choice-hosting-malicious-payloads
-
ISC StormCast for Thursday, February 11th, 2021
11/02/2021 Duración: 05minPhishing Message to the ISC Handlers E-Mail Distro https://isc.sans.edu/forums/diary/Phishing+message+to+the+ISC+handlers+email+distro/27082/ Google Phishing Statistics https://cloud.google.com/blog/products/workspace/how-gmail-helps-users-avoid-email-scams Adobe Security Updates https://helpx.adobe.com/security/products/acrobat/apsb21-09.html Apple Sudo Patch https://support.apple.com/en-us/HT212177 Number:Jack ISN Generation Weaknesses https://www.forescout.com/company/resources/numberjack-weak-isn-generation-in-embedded-tcpip-stacks/