Sans Internet Storm Center Daily Network/cyber Security And Information Security Podcast

  • Autor: Vários
  • Narrador: Vários
  • Editor: Podcast
  • Duración: 260:18:49
  • Mas informaciones

Informações:

Sinopsis

Daily update on current cyber security threats

Episodios

  • ISC StormCast for Thursday, January 9th 2020

    09/01/2020 Duración: 05min

    Critical Firefox Update Fixing Exploited Bug https://www.mozilla.org/en-US/security/advisories/mfsa2020-03/ 3 Google Play Store Apps Exploit Android Zero-Day https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/ Tails 4.2 https://tails.boum.org/news/version_4.2/index.en.html TikTok Vulnerablities https://research.checkpoint.com/2020/tik-or-tok-is-tiktok-secure-enough/

  • ISC StormCast for Wednesday, January 8th 2020

    08/01/2020 Duración: 05min

    Citrix ADC Update https://isc.sans.edu/forums/diary/A+Quick+Update+on+Scanning+for+CVE201919781+Citrix+ADC+Gateway+Vulnerability/25686/ Pulse Secure SSLVPN Exploited https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/ https://www.darkreading.com/attacks-breaches/widely-known-flaw-in-pulse-secure-vpn-being-used-in-ransomware-attacks/d/d-id/1336729 Google Project Zero Changing Disclosure Policy https://googleprojectzero.blogspot.com/2020/01/policy-and-disclosure-2020-edition.html Google Updates Android https://source.android.com/security/bulletin/2020-01-01

  • ISC StormCast for Tuesday, January 7th 2020

    07/01/2020 Duración: 05min

    Spoofed Scans from 103/8 https://isc.sans.edu/forums/diary/Increase+in+Number+of+Sources+January+3rd+and+4th+spoofed/25678/ Iran Terror Threat https://www.dhs.gov/sites/default/files/ntas/alerts/20_0104_ntas_bulletin.pdf BusKill Laptop Kill Cord https://tech.michaelaltfield.net/2020/01/02/buskill-laptop-kill-cord-dead-man-switch/

  • ISC StormCast for Monday, January 6th 2020

    06/01/2020 Duración: 04min

    Quick Summary of the California Conumser Privacy Act https://isc.sans.edu/forums/diary/CCPA+Quick+Overview/25668/ Cisco Vulnerabilities https://tools.cisco.com/security/center/publicationListing.x XiaoMi Camera Cache Bug https://www.reddit.com/r/googlehome/comments/eine1m/when_i_load_the_xiaomi_camera_in_my_google_home/

  • ISC StormCast for Friday, January 3rd 2020

    03/01/2020 Duración: 08min

    Ransomware written in JavaScript using Node.js https://isc.sans.edu/forums/diary/Ransomware+in+Nodejs/25664/ Landry Restaurant PoS Breach https://www.landrysinc.com/CreditNotice/CANotice.asp Holiday Hack Challenge https://www.holidayhackchallenge.com Citrix/NetScaler Vulnerability Special Webcast Recording https://i5c.us/citrix

  • ISC StormCast for Tuesday, December 31st 2019

    31/12/2019 Duración: 06min

    ISC API Update https://isc.sans.edu/api https://isc.sans.edu/forums/diary/Miscellaneous+Updates+to+our+Threatfeed+API/25654/ CCC Conference https://fahrplan.events.ccc.de/congress/2019/Fahrplan/ https://events.ccc.de/congress/2019/wiki/index.php/Main_Page

  • ISC StormCast for Monday, December 30th 2019

    30/12/2019 Duración: 05min

    Breaking 2FA Soft Tokens https://resources.fox-it.com/rs/170-CAK-271/images/201912_Report_Operation_Wocao.pdf PiHole Dashboard https://isc.sans.edu/forums/diary/ELK+Dashboard+for+Pihole+Logs/25652/ Corrupt Office Documents https://isc.sans.edu/forums/diary/Corrupt+Office+Documents/25650/ Enumerating Office 365 Users https://isc.sans.edu/forums/diary/Enumerating+office365+users/25648/

  • ISC StormCast for Friday, December 27th 2019

    27/12/2019 Duración: 03min

    Citrix Application Delivery Controller (Netscaler ADC) Critical Vulnerability https://www.ptsecurity.com/ww-en/about/news/citrix-vulnerability-allows-criminals-to-hack-networks-of-80000-companies/ https://support.citrix.com/article/CTX267027

  • ISC StormCast for Monday, December 23rd 2019

    23/12/2019 Duración: 04min

    Extracting VBA Macros From .DWG Files https://isc.sans.edu/forums/diary/Extracting+VBA+Macros+From+DWG+Files/25634/ Cisco PKI Self-Signed Certificate Expiration https://www.cisco.com/c/en/us/support/docs/field-notices/704/fn70489.html AFRINIC IP Address Space Misappropriated By Insider https://mybroadband.co.za/news/internet/330379-how-internet-resources-worth-r800-million-were-stolen-and-sold-on-the-black-market.html

  • ISC StormCast for Friday, December 20th 2019

    20/12/2019 Duración: 05min

    More DNS over HTTPS Details https://isc.sans.edu/forums/diary/More+DNS+over+HTTPS+Become+One+With+the+Packet+Be+the+Query+See+the+Query/25628/ Ransomware Outing Victims https://krebsonsecurity.com/2019/12/ransomware-gangs-now-outing-victim-businesses-that-dont-pay-up/ Google Chrome Update https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop_17.html

  • ISC StormCast for Thursday, December 19th 2019

    19/12/2019 Duración: 03min

    An Emotet Update https://isc.sans.edu/forums/diary/Emotet+infection+with+spambot+activity/25622/ Emotet Used to Spread Malware From German Federal Agency Accounts (german) https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2019/Spam-Bundesbehoerden_181219.html Joomla Patches SQL Injection https://developer.joomla.org/security-centre.html Unicode Mapping Problems https://eng.getwisdom.io/hacking-github-with-unicode-dotless-i/

  • ISC StormCast for Wednesday, December 18th 2019

    18/12/2019 Duración: 06min

    Discovering DNS over HTTPS https://isc.sans.edu/forums/diary/Is+it+Possible+to+Identify+DNS+over+HTTPs+Without+Decrypting+TLS/25616/ Ring Camera Weaknesses https://www.vice.com/en_us/article/epg4xm/amazon-ring-camera-security WhatsApp DoS Bug https://research.checkpoint.com/2019/breakingapp-whatsapp-crash-data-loss-bug/

  • ISC StormCast for Tuesday, December 17th 2019

    17/12/2019 Duración: 06min

    Slack "Unshare" Not Working As Expected https://www.theregister.co.uk/2019/12/16/slack_filesharing_vulnerability_post_sharing/ Google Making OAUTH Mandatory for GSuite https://gsuiteupdates.googleblog.com/2019/12/less-secure-apps-oauth-google-username-password-incorrect.html TPLink Authentication Bypass https://securityintelligence.com/posts/tp-link-archer-router-vulnerability-voids-admin-password-can-allow-remote-takeover/ Factoring IoT RSA Keys https://info.keyfactor.com/factoring-rsa-keys-in-the-iot-era

  • ISC StormCast for Monday, December 16th 2019

    16/12/2019 Duración: 05min

    VBA Macros in Autocad https://isc.sans.edu/forums/diary/Malicious+DWG+Files/25612/ OpenBSD Privilege Escalation Vulnerability https://www.qualys.com/2019/12/11/cve-2019-19726/local-privilege-escalation-openbsd-dynamic-loader.txt NPM Fixes Critical Security Vulnerability https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli

  • ISC StormCast for Friday, December 13th 2019

    13/12/2019 Duración: 14min

    Malware Information Sharing https://isc.sans.edu/forums/diary/Code+Data+Reuse+in+the+Malware+Ecosystem/25598/ Apple Improves Tracking Prevention Tracking in WebKit https://webkit.org/blog/9661/preventing-tracking-prevention-tracking/ Google Verified SMS Messages https://www.blog.google/products/messages/safer-conversations-messages-verified-sms-and-spam-protection/ Echobot Keeps Adding More Exploits https://www.bleepingcomputer.com/news/security/new-echobot-variant-exploits-77-remote-code-execution-flaws/ STI Research Paper: Caleb Baker DNS Monitoring https://www.sans.org/reading-room/whitepapers/dns/challenges-effective-dns-query-monitoring-39215

  • ISC StormCast for Thursday, December 12th 2019

    12/12/2019 Duración: 05min

    German Malspam Installs Trickbot https://isc.sans.edu/forums/diary/German+language+malspam+pushes+yet+another+wave+of+Trickbot/25594/ Vulnerable KeyWe Smart Lock https://labs.f-secure.com/advisories/keywe-smart-lock-unauthorized-access-traffic-interception Google Chrome Update https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html iOS Spam Feature https://support.apple.com/en-us/HT210756 https://kishanbagaria.com/airdos/

  • ISC StormCast for Wednesday, December 11th 2019

    11/12/2019 Duración: 06min

    Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+December+2019+Patch+Tuesday/25592/ https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/ Adobe Patch Tuesday https://helpx.adobe.com/security.html Apple Security Updates https://support.apple.com/en-us/HT201222 Intel Plundervolt Update https://blogs.intel.com/technology/2019/12/ipas-security-advisories-for-december-2019/

  • ISC StormCast for Tuesday, December 10th 2019

    10/12/2019 Duración: 07min

    Another Word Maldoc https://isc.sans.edu/forums/diary/Lazy+Sunday+Maldoc+Analysis/25586/ Snatch Ransomware Reboots System Into Safe Mode To Disable Anti Virus https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/ Ryuk Ransomware Decryptor May No Longer Work / Corrupt Documents https://blog.emsisoft.com/en/35023/bug-in-latest-ryuk-decryptor-may-cause-data-loss/ Extending Windows 7 Security Updates https://www.ghacks.net/2019/12/07/someone-found-a-way-to-bypass-windows-7-extended-security-updates-checks/ Swift on Security Updates Sysmon Rules https://github.com/SwiftOnSecurity/sysmon-config RSA Webcast https://www.rsaconference.com/industry-topics/webcast/36-five-most-dangerous-attacks-evolving

  • ISC StormCast for Monday, December 9th 2019

    09/12/2019 Duración: 06min

    E-Mail Includes Entire HTML/Javascript Phishing Kit https://isc.sans.edu/forums/diary/Phishing+with+a+selfcontained+credentialsstealing+webpage/25580/ Great Canon / Red Canon Activated to Silence Pro Hongkong Forum https://cybersecurity.att.com/blogs/labs-research/the-great-cannon-has-been-deployed-again

  • ISC StormCast for Friday, December 6th 2019

    06/12/2019 Duración: 14min

    OpenBSD Authentication Bypass and Privilege Escalation Vulnerability https://www.qualys.com/2019/12/04/cve-2019-19521/authentication-vulnerabilities-openbsd.txt?_ga=2.58244398.587934852.1575530822-682141427.1570559125 Hijacking Linux (and BSD) VPN Connections https://seclists.org/oss-sec/2019/q4/122 RASP vs. WAF: Alexander Fry Research Paper https://www.sans.org/reading-room/whitepapers/application/runtime-application-self-protection-rasp-investigation-effectiveness-rasp-solution-protecting-vulnerable-target-applications-38950

página 73 de 117