Sinopsis
Daily update on current cyber security threats
Episodios
-
ISC StormCast for Wednesday, May 15th 2019
15/05/2019 Duración: 06minNew Intel CPU Vulnerabilities https://cpu.fail/ Microsoft Patch Tuesday https://isc.sans.edu/forums/diary/Microsoft+May+2019+Patch+Tuesday/24934/ Apple Updates https://support.apple.com/en-us/HT201222 Broken Trustseal https://twitter.com/gwillem/status/1127890329175244800 https://twitter.com/bestoftheweb/status/1128036593208524800
-
ISC StormCast for Tuesday, May 14th 2019
14/05/2019 Duración: 05minLinux Remote Code Execution When Closing TCP Sockets https://github.com/torvalds/linux/commit/cb66ddd156203daefb8d71158036b27b0e2caf63 WhatsApp Buffer Overflow Exploited to Install Spyware https://www.facebook.com/security/advisories/cve-2019-3568 Cisco Vulnerabilities Lead to Trust Anchor Module Exploit https://thrangrycat.com/ Linksys Unauthenticated Information Leak https://badpackets.net/over-25000-linksys-smart-wi-fi-routers-vulnerable-to-sensitive-information-disclosure-flaw/
-
ISC StormCast for Monday, May 13th 2019
13/05/2019 Duración: 05minDSSuite - A Docker Container with Didier's Tools https://isc.sans.edu/forums/diary/DSSuite+A+Docker+Container+with+Didiers+Tools/24926/ Sqlite3 Vulnerability https://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0777 NVidia Updates https://nvidia.custhelp.com/app/answers/detail/a_id/4797 Windows 10 FIDO2 Certified https://fidoalliance.org/microsoft-achieves-fido2-certification-for-windows-hello/ Google May Remove ADB Backup/Restore from Future Android Versions https://www.xda-developers.com/adb-backup-and-restore-depreciated/
-
ISC StormCast for Friday, May 10th 2019
10/05/2019 Duración: 05minUS DHS Warns of North Korean ELECTRICFISH Malware https://www.us-cert.gov/ncas/analysis-reports/AR19-129A Fake KeePass Site Spreading Malware https://twitter.com/berkcgoksel/status/1125727590440931329 Google Android Security Bulletin https://source.android.com/security/bulletin/2019-05-01 Three Anti-Virus Companies Breached https://www.advanced-intel.com/blog/top-tier-russian-hacking-collective-claims-breaches-of-three-major-anti-virus-companies
-
ISC StormCast for Thursday, May 9th 2019
09/05/2019 Duración: 05minEMail Roulette May 2019 https://isc.sans.edu/forums/diary/Email+roulette+May+2019/24918/ Turla Lightneuron https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf Alpine Linux Docker Image root User Hard Coded Credentials https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782 Worpress 5.2 Adds Digitially Signed Updates https://wordpress.org/support/wordpress-version/version-5-2/
-
ISC StormCast for Wednesday, May 8th 2019
08/05/2019 Duración: 04minJenkins Exploit Mines Cryptocurrencies https://isc.sans.edu/forums/diary/Vulnerable+Apache+Jenkins+exploited+in+the+wild/24916/ Confluence Vulnerablity Exploited to Delivery Cryptocurrency Miner with Rootkit https://blog.trendmicro.com/trendlabs-security-intelligence/cve-2019-3396-redux-confluence-vulnerability-exploited-to-deliver-cryptocurrency-miner-with-rootkit/ Cisco Elastic Services Controller REST API Authentication Bypass https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190507-esc-authbypass Google Chrome History Manipulation Prevention https://groups.google.com/a/chromium.org/forum/?#!msg/blink-dev/T8d4_BRb2xQ/WSdOiOFcBAAJ
-
ISC StormCast for Tuesday, May 7th 2019
07/05/2019 Duración: 06minDecoding UTF-16 in UDF Files https://isc.sans.edu/forums/diary/Text+and+TNULeNULxNULtNUL/24912/ VMWare Fusion 11 Guest VM RCE https://theevilbit.github.io/posts/vmware_fusion_11_guest_vm_rce_cve-2019-5514/ Hackers Are Using Bad Passwords Too https://www.ankitanubhav.info/post/c2bruting Amazon S3 Discontinues Path Style Access https://www.bleepingcomputer.com/news/security/amazon-to-disable-s3-path-style-access-used-to-bypass-censorship/
-
ISC StormCast for Monday, May 6th 2019
05/05/2019 Duración: 06minGit Ransomware https://www.theregister.co.uk/2019/05/03/git_ransomware_bitcoin/ DLink Ransomware Patch https://eu.dlink.com/de/de/support/support-news/2019/february/28/dns320_trojan_cr1pttor Jenkins Plugin Vulnerabilities https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2019/may/story-of-a-hundred-vulnerable-jenkins-plugins/ Malicious WPAD Domains https://blog.redteam.pl/2019/05/badwpad-and-wpad-pl-wpadblocking-com.html
-
ISC StormCast for Friday, May 3rd 2019
03/05/2019 Duración: 06minNew SAP Exploits Used to Target Exposed https://www.onapsis.com/10kblaze Cisco Patches SSH Default Credential Vulnerability in Nexus 9000 Switches https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey Current State of JavaScript Crypto Jacking https://blog.malwarebytes.com/cybercrime/2019/05/cryptojacking-in-the-post-coinhive-era/ D-Link Camera Vulnerabilities https://www.welivesecurity.com/2019/05/02/d-link-camera-vulnerability-video-stream/ Securepairs Promotes "Right to Repair" https://securepairs.org/
-
ISC StormCast for Thursday, May 2nd 2019
02/05/2019 Duración: 05minRCE Vulnerability in Dell Support Assist https://d4stiny.github.io/Remote-Code-Execution-on-most-Dell-computers/ Creston Multiple Vulnerabilities https://www.crestron.com/en-US/Security/Security_Advisories Polymorphic Skimmer Targeting 57 different Payment Gateways https://labs.sansec.io/2019/04/29/polymorphic-skimmer-57-payment-gateways/ More Attacks Against S/Mime and PGP Signed Email https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf
-
ISC StormCast for Wednesday, May 1st 2019
01/05/2019 Duración: 05minSodinokibi Ransomware Exploits WebLogic Server Vulnerability https://blog.talosintelligence.com/2019/04/sodinokibi-ransomware-exploits-weblogic.html Facebook Leaking Sellers Exact Locations https://www.7elements.co.uk/resources/blog/facebooks-burglary-shopping-list/ Revive Adserver Deserialization Vulnerability https://www.revive-adserver.com/security/revive-sa-2019-001/ AutoMacTC: Automating Mac Forensics Triage https://www.crowdstrike.com/blog/automating-mac-forensic-triage/ Kroll Artifact Parser And Extractor (KAPE) https://learn.duffandphelps.com/kape
-
ISC StormCast for Tuesday, April 30th 2019
30/04/2019 Duración: 05miniLnkP2P Allows Access To Millions of Security Cameras https://hacked.camera Windows 10 Users Not Applying October Update https://reports.adduplex.com/#/r/2019-04 iFrame "Ransom Support" Attacks https://blog.trendmicro.com/trendlabs-security-intelligence/tech-support-scam-employs-new-trick-by-using-iframe-to-freeze-browsers/
-
ISC StormCast for Monday, April 29th 2019
29/04/2019 Duración: 05minWebLogic Update https://isc.sans.edu/diary.html?storyid=24890 Docker Hub Breach https://success.docker.com/article/docker-hub-user-notification
-
ISC StormCast for Friday, April 26th 2019
26/04/2019 Duración: 05minUnpatched Vulnerablity in WebLogic Exploited https://isc.sans.edu/forums/diary/Unpatched+Vulnerability+Alert+WebLogic+Zero+Day/24880/ Collecting Windows Service Accounts https://isc.sans.edu/forums/diary/Service+Accounts+Redux+Collecting+Service+Accounts+with+PowerShell/24882/ Confluence Vulnerablity Exploited by GandGrab https://blog.alertlogic.com/active-exploitation-of-confluence-vulnerability-cve-2019-3396-dropping-gandcrab-ransomware/ New Micrsoft Security Baseline for Windows 10 / Windows Server https://blogs.technet.microsoft.com/secguide/2019/04/24/security-baseline-draft-for-windows-10-v1903-and-windows-server-v1903/
-
ISC StormCast for Thursday, April 25th 2019
25/04/2019 Duración: 07minRooting Out Unwanted Domain Admins With Powershell https://isc.sans.edu/forums/diary/Where+have+all+the+Domain+Admins+gone+Rooting+out+Unwanted+Domain+Administrators/24874/ Mac OS X-Protect Now Covering Windows Malware https://twitter.com/patrickwardle/status/1120771284286103552 Wifi Finder Leaks Hotspot Passwords https://techcrunch.com/2019/04/22/hotspot-password-leak/ Github Hosting Phishing Pages https://www.proofpoint.com/us/threat-insight/post/threat-actors-abuse-github-service-host-variety-phishing-kits RSA Webinar: The Five Most Dangerous New Attack Techniques and How to Counter Them https://www.rsaconference.com/videos/rsac-2019-the-five-most-dangerous-new-attack-techniques-and-how-to-counter-them-continued
-
ISC StormCast for Wednesday, April 24th 2019
24/04/2019 Duración: 05minDecoding Malicious VBA Office Document Without Source Code https://isc.sans.edu/forums/diary/Malicious+VBA+Office+Document+Without+Source+Code/24870/ More Updates on "ShadowHammer" Supply Chain Attack https://securelist.com/operation-shadowhammer-a-high-profile-supply-chain-attack/90380/ A Malicious Sight in Google Sites https://www.netskope.com/blog/malicious-google-sites
-
ISC StormCast for Tuesday, April 23rd 2019
22/04/2019 Duración: 05min.rar Files Exploiting ACE Vulneraiblity CVE-2018-20250 https://isc.sans.edu/forums/diary/rar+Files+and+ACE+Exploit+CVE201820250/24864/ Malware Senders Become Younger and Less Sophisticated (in German) https://www.heise.de/security/meldung/Malware-Verteiler-werden-immer-juenger-infizieren-sich-oft-selbst-4403823.html McAfee Antivirus Affected by April Windows Update Crashes http://kc.mcafee.com/corporate/index?page=content&id=KB91465 Rules to Protect Against Azure Blog Phishing in Outlook 365 https://malware-research.org/simple-rule-to-protect-against-spoofed-windows-net-phishing-attacks/ Windows 7 End of Support Messages https://www.windowslatest.com/2019/04/20/windows-7-users-are-now-receiving-the-end-of-support-notifications/
-
ISC StormCast for Monday, April 22nd 2019
22/04/2019 Duración: 06minAnalyzing UDF Files Using Python https://isc.sans.edu/forums/diary/Analyzing+UDF+Files+with+Python/24860/ HTML Ping To Be Adopted By All Major Browsers https://webkit.org/blog/8821/link-click-analytics-and-privacy/ Microsoft to Modify Edge User Agent for Some Sites https://www.onmsft.com/news/new-edge-insider-browser-can-change-user-agent-strings-based-on-what-website-youre-visiting French Government Chat System Used Weak User Management https://m.heise.de/security/meldung/Tchap-Frankreichs-nicht-so-exklusiver-Regierungschat-4403961.html
-
ISC StormCast for Friday, April 19th 2019
19/04/2019 Duración: 06minMalware Delivered As a UDF .img file https://isc.sans.edu/forums/diary/Malware+Sample+Delivered+Through+UDF+Image/24854/ Facebook Stored Passwords in Plain Text https://newsroom.fb.com/news/2019/03/keeping-passwords-secure/ Iranian Statesponsored Malware and Data Leaked https://misterch0c.blogspot.com/2019/04/apt34-oilrig-leak.html Windows 8 Live Tiles Domain Takeover https://www.golem.de/news/subdomain-takeover-microsoft-verliert-kontrolle-ueber-windows-kacheln-1904-140709.html
-
ISC StormCast for Thursday, April 18th 2019
18/04/2019 Duración: 05minDNS Hijacking by Sea Turtle https://blog.talosintelligence.com/2019/04/seaturtle.html Broadcom Wifi Driver Vulnerabilities https://www.kb.cert.org/vuls/id/166939/ NamPoHyu Virus Infects Samba Servers https://www.bleepingcomputer.com/news/security/nampohyu-virus-ransomware-targets-remote-samba-servers/ Increased Attacks on Confluence https://twitter.com/DFNCERT/status/1118468599230943233