Sinopsis
Daily update on current cyber security threats
Episodios
- 
								ISC StormCast for Tuesday, August 8th 201707/08/2017 Duración: 05minPHPMyAdmin Scans https://isc.sans.edu/forums/diary/Increase+of+phpMyAdmin+scans/22688/ Hotspot Shield Leakes Private User Data https://cdt.org/files/2017/08/FTC-CDT-VPN-complaint-8-7-17.pdf Debian Turning Off Support for TLS 1.0/1.1 https://lists.debian.org/debian-devel-announce/2017/08/msg00004.html Ongoing Phishing Attacks Against Google Chrome Plugin Developers https://www.bleepingcomputer.com/news/security/chrome-extension-developers-under-a-barrage-of-phishing-attacks/ 
- 
								ISC StormCast for Monday, August 7th 201707/08/2017 Duración: 06minOpengraph Used to Obfuscate Facebook Links https://isc.sans.edu/forums/diary/Use+of+the+Open+Graph+Protocol+to+Disguise+Malicious+Facebook+Links/22684/ Cerber Adding Bitcoin and Password Stealer to Crypto Ransomware http://blog.trendmicro.com/trendlabs-security-intelligence/cerber-ransomware-evolves-now-steals-bitcoin-wallets/ Symantec Selling Certificate Business To Digicert https://www.heise.de/security/meldung/Nachspiel-einer-fatalen-Panne-Symantec-verkauft-Zertifikatssparte-an-DigiCert-3793482.html Siemens Medical Imaging Systems Vulnerable to Old Windows Flaws https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-822184.pdf 
- 
								ISC StormCast for Friday, August 4th 201704/08/2017 Duración: 05minRaspberry Pi Honeypot https://github.com/DShield-ISC/dshield Troy Hunt Releases Password List https://haveibeenpwned.com/Passwords Typosquatting npm Packages http://blog.npmjs.org/post/163723642530/crossenv-malware-on-the-npm-registry SEC503: Intrusion Detection in Depth Berlin (Oct 23rd-28th) https://www.sans.org/event/berlin-2017/course/intrusion-detection-in-depth 
- 
								ISC StormCast for Thursday, August 3rd 201702/08/2017 Duración: 05minAttacking NoSQL Applications https://isc.sans.edu/forums/diary/Attacking+NoSQL+applications+part+2/22676/ Web Developer Chrome Toolbar Replaced with AdWare https://twitter.com/chrispederick Android Banking Trojans https://securelist.com/a-new-era-in-mobile-banking-trojans/79198/ Amazon Stops Selling Blu Smartphones http://www.zdnet.com/article/amazon-halts-blu-phone-sales-over-potential-security-issue/ 
- 
								ISC StormCast for Wednesday, August 2nd 201702/08/2017 Duración: 06minDetect SMB Versions with nmap https://isc.sans.edu/forums/diary/Rooting+Out+Hosts+that+Support+Older+Samba+Versions/22672/ CopyFish Google Chrome Extension Replaced by Adware https://a9t9.com/blog/chrome-extension-adware/ StartCom Applying to be Included in Mozilla SSL CAs again https://bugzilla.mozilla.org/show_bug.cgi?id=1311832#c12 McAffee Uses Mixed SSL/nonSSL Content For Online Malware Scan https://blogs.securiteam.com/index.php/archives/3350 Netflix Releases DoS Testing Tool https://medium.com/netflix-techblog/starting-the-avalanche-640e69b14a06 
- 
								ISC StormCast for Tuesday, August 1st 201701/08/2017 Duración: 05minMSFT Re-Releases June Outlook Update https://support.office.com/en-us/article/Outlook-known-issues-in-the-June-2017-security-updates-3f6dbffd-8505-492d-b19f-b3b89369ed9b?ui=en-US&rs=en-US&ad=US&fromAR=1 Iranian Hackers Use Social Media To Collect Data https://www.darkreading.com/attacks-breaches/iranian-hackers-ensnared-targets-via-phony-female-photographer/d/d-id/1329502?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple ShieldFS Self Healing Filesystem http://shieldfs.necst.it/continella-shieldfs-2016.pdf 
- 
								ISC StormCast for Monday, July 31st 201731/07/2017 Duración: 05minSMBloris DoS Attack Locks Up Windows https://twitter.com/jennamagius/status/891434286212984832 https://isc.sans.edu/forums/diary/SMBLoris+the+new+SMB+flaw/22662/ Text Banking Attacks https://isc.sans.edu/forums/diary/Text+Banking+Scams/22666/ Nissan Leaf WiFi Vulnerability https://github.com/HackingThings/Publications/blob/cdb72df7c3feffd02593a31d67a34ae353b09114/2017/DC25_Driving%20down%20the%20rabbit%20hole-Mickey_Jesse_Oleksander.pdf 
- 
								ISC StormCast for Friday, July 28th 201728/07/2017 Duración: 13minTargeting HTTP's Hidden Attack-Surface http://blog.portswigger.net/2017/07/cracking-lens-targeting-https-hidden.html Petya/Goldeneye Decrypter https://blog.malwarebytes.com/malwarebytes-news/2017/07/bye-bye-petya-decryptor-old-versions-released/ TinyPot, My Small Honeypot https://isc.sans.edu/forums/diary/TinyPot+My+Small+Honeypot/22654/ Shaun McCullough https://www.sans.org/reading-room/whitepapers/testing/docker-create-multi-container-environments-research-sharing-lateral-movement-37855 
- 
								ISC StormCast for Thursday, July 27th 201727/07/2017 Duración: 05minMalspam Pushing Emotet Malware https://isc.sans.edu/forums/diary/Malspam+pushing+Emotet+malware/22650/ Broadpwn Released http://blog.exodusintel.com/2017/07/26/broadpwn/ Microsoft Announces Windows 10 Bug Bounty https://blogs.technet.microsoft.com/msrc/2017/07/26/announcing-the-windows-bounty-program/ Custom Map Vulnearbilty in Valve Games https://oneupsecurity.com/research/remote-code-execution-in-source-games 
- 
								ISC StormCast for Wednesday, July 26th 201726/07/2017 Duración: 05minAdobe Announces End of Flash for 2020 https://blogs.adobe.com/conversations/2017/07/adobe-flash-update.html JA3 Hash To Fingerprint SSL/TLS Connections https://github.com/salesforce/ja3 https://engineering.salesforce.com/open-sourcing-ja3-92c9e53c3c41 New Wave of Apple iCloud Ransom Attacks https://www.heise.de/mac-and-i/meldung/Erneut-iCloud-Erpressungswelle-ueber-Meinen-Mac-suchen-und-Mein-iPhone-suchen-3782075.html 
- 
								ISC StormCast for Tuesday, July 25th 201725/07/2017 Duración: 07minUber Drivers Targeted in Social Engineering Scam https://isc.sans.edu/forums/diary/Uber+drivers+new+threat+the+passenger/22626/ Mac Malware FruitFly2 https://motherboard.vice.com/en_us/article/zmv79w/mysterious-mac-malware-has-infected-hundreds-of-victims-for-years Exploit Released for Critical Netscaler SD WAN 9.1.2 Vulnerability http://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-6316 
- 
								ISC StormCast for Monday, July 24th 201724/07/2017 Duración: 05minMalicious .iso Attachments https://isc.sans.edu/forums/diary/Malicious+iso+Attachments/22636/ Maldoc with .lnk File https://isc.sans.edu/forums/diary/Another+lnk+File/22640/ Large Ethereum Hack http://hackingdistributed.com/2017/07/22/deep-dive-parity-bug/ 
- 
								ISC StormCast for Friday, July 21st 201721/07/2017 Duración: 11minSymantec Sloppy Key Verification Leads To Revocation of Certificates https://blog.hboeck.de/archives/888-How-I-tricked-Symantec-with-a-Fake-Private-Key.html Gnome Thumbnailer Executes Code http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html 
- 
								ISC StormCast for Thursday, July 20th 201720/07/2017 Duración: 06minBots Searching for Keys and Config Files https://isc.sans.edu/forums/diary/Bots+Searching+for+Keys+Config+Files/22630/ Apple Updates Everything https://support.apple.com/en-us/HT201222 Trend Micro Sees SambaCry Exploits http://blog.trendmicro.com/trendlabs-security-intelligence/linux-users-urged-update-new-threat-exploits-sambacry/ Google Increases Developer Scrutiny https://developers.googleblog.com/2017/05/updating-developer-identity-guidelines.html 
- 
								ISC StormCast for Wednesday, July 19th 201719/07/2017 Duración: 05minOracle Quarterly Critical Patch Update http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html Cisco WebEx Plugin Update https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170717-webex https://bugs.chromium.org/p/project-zero/issues/detail?id=1324&desc=2 Node.JS DoS Vulnerability https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/ Bitdefender Remote Stack Buffer Overflow https://landave.io/2017/07/bitdefender-remote-stack-buffer-overflow-via-7z-ppmd/ Coindash Hack https://twitter.com/coindashio/status/886936799695818752 https://www.coindash.io DowJones Leaks Customer Data via S3 Buckets https://www.upguard.com/breaches/cloud-leak-dow-jones 
- 
								ISC StormCast for Tuesday, July 18th 201718/07/2017 Duración: 05minSMS Phishing Asks Victims to Upload Picture of Token Card https://isc.sans.edu/forums/diary/SMS+Phishing+induces+victims+to+photograph+its+own+token+card/22616/ Critical FreeRADIUS Update https://guidovranken.wordpress.com/2017/07/17/11-remote-vulnerabilities-inc-2x-rce-in-freeradius-packet-parsers/ OS X Malware Installs Crypto Messenger Signal https://blog.checkpoint.com/2017/07/13/osxdok-refuses-go-away-money/ 
- 
								ISC StormCast for Monday, July 17th 201717/07/2017 Duración: 05minNemucodAES UPS Malspam https://isc.sans.edu/forums/diary/NemucodAES+and+the+malspam+that+distributes+it/22614/ Analyzing Malicious Office Document With LNK https://isc.sans.edu/forums/diary/Office+maldoc+lnk/22618/ Gandi Breach Leads to Domain Compromise https://news.gandi.net/en/2017/07/detailed-incident-report/ iSmart Alarm Vulnerabilities http://dojo.bullguard.com/blog/burglar-hacker-when-a-physical-security-is-compromised-by-iot-vulnerabilities/ 
- 
								ISC StormCast for Friday, July 14th 201713/07/2017 Duración: 14minMalware Loads ffmpeg For Video Recording Features https://blog.malwarebytes.com/threat-analysis/2017/07/malware-abusing-ffmpeg/ Password Managers and Cloud Storage https://discussions.agilebits.com/discussion/76956/can-i-still-buy-standalone-license-for-the-1password-no-longer-being-marketed/p8 SAP Point of Sales Express Patch https://erpscan.com/press-center/blog/sap-cyber-threat-intelligence-report-july-2017/ Roderick Currie: Car Hacking Developments https://www.sans.org/reading-room/whitepapers/internet/developments-car-hacking-36607 
- 
								ISC StormCast for Thursday, July 13th 201712/07/2017 Duración: 05minSimple File Integrity Monitoring With Backup Scripts https://isc.sans.edu/forums/diary/Backup+Scripts+the+FIM+of+the+Poor/22606/ Ethereum Wallet Services Targeted By Scammers http://www.ibtimes.co.uk/ethereum-under-siege-scammers-make-700000-6-days-slack-reddit-phishing-attacks-1629866 MongoDB Security Surprises For Shared Hosting https://medium.com/@alexbyk/mongodb-at-shared-hosting-security-surprises-c441ecb84b54 Trend Micro Vulnerabilities https://www.coresecurity.com/advisories/trend-micro-deep-discovery-director-multiple-vulnerabilities 
- 
								ISC StormCast for Wednesday, July 12th 201711/07/2017 Duración: 05minMicrosoft Patch Tuesday https://isc.sans.edu/diary//22602 AT&T Cell Phone Takeover https://carpeaqua.com/2017/07/07/hack-the-planet/ Systemd Invalid Username Bug To Be Fixed https://github.com/systemd/systemd/pull/6300 
 
												 
											 
									 
									 
									 
									 
									 
									 
									 
									 
									 
									 
             
					