Sans Internet Storm Center Daily Network/cyber Security And Information Security Podcast

Informações:

Sinopse

Daily update on current cyber security threats

Episódios

  • ISC StormCast for Wednesday, June 22nd 2016

    22/06/2016 Duração: 05min

    Apple Airport (and Time Capsule) Update https://support.apple.com/en-us/HT201222 StartCom Adding API For Free SSL Certificates https://support.apple.com/en-us/HT201222 BitCoin Phishing With Typo Squatting Domains http://blog.cyren.com/articles/2016-Q2_bitcoin-phishing-via-google-adwords.html Google Attempting to Simplify 2 Factor Authentication http://googleappsupdates.blogspot.co.uk/2016/06/new-settings-for-2-step-verification.html

  • ISC StormCast for Tuesday, June 21st 2016

    21/06/2016 Duração: 05min

    Fake SWIFT Payment Notices Used in Malicious E-Mail Campaign https://isc.sans.edu/forums/diary/Ongoing+Spam+Campaign+Related+to+Swift/21177/ RedHat Fixes Various OpenSSL Integer Overflows https://github.com/openssl/openssl/commit/a004e72b95835136d3f1ea90517f706c24c03da7 JavaScript Ransom Ware http://www.bleepingcomputer.com/news/security/the-new-raa-ransomware-is-created-entirely-using-javascript/ Triada/Horde Mobile Malware Updates http://blog.checkpoint.com/2016/06/17/in-the-wild-mobile-malware-implements-new-features/

  • ISC StormCast for Monday, June 20th 2016

    19/06/2016 Duração: 05min

    Avoiding Javascript Malware https://isc.sans.edu/forums/diary/Controlling+JavaScript+Malware+Before+it+Runs/21171/ LogMeIn Joining Other Sites in Proactively Resetting Passwords https://blog.logmeininc.com/password-reuse-issue-affecting-logmein-users/ Kaspersky Publishes Details Around Recent Flash Vulnerability https://securelist.com/blog/research/75100/operation-daybreak/ CSRF Vulnerability in Democratic Party Donation Platform http://rajk.me/actblue/#intro

  • ISC StormCast for Friday, June 17th 2016

    17/06/2016 Duração: 05min

    Adobe Patches Critiical Flash Vulnerability https://helpx.adobe.com/security/products/flash-player/apsb16-18.html Teamviewer Users May be Compromised by Trojaned Client http://blog.trendmicro.com/trendlabs-security-intelligence/unsupported-teamviewer-versions-exploited-backdoors-keylogging/ Siemens ICS Equipment Transmits Credentials Over the Network https://ics-cert.us-cert.gov/advisories/ICSA-16-161-02 GitHub Resets User Accounts Compromissed In 3rd Party Incident https://github.com/blog/2190-github-security-update-reused-password-attack HTTP Header Injection in Python urllib http://blog.blindspotsecurity.com/2016/06/advisory-http-header-injection-in.html

  • ISC StormCast for Thursday, June 16th 2016

    16/06/2016 Duração: 04min

    Group Policy Issues After Applying MS16-072 (KB3159398) https://social.technet.microsoft.com/Forums/en-US/e2ebead9-b30d-4789-a151-5c7783dbbe34/patch-tuesday-kb3159398?forum=winserverGP Apple Will Reject Apps Using HTTP https://developer.apple.com/videos/play/wwdc2016/706/ Rising AntiVirus Includes Malware (article only in german) http://www.heise.de/security/meldung/Virenscanner-infiziert-Systeme-mit-Sality-Virus-3237654.html SAP Patch https://erpscan.com/press-center/blog/sap-security-notes-june-2016/ Breached RDP Servers For Rent https://www.wired.com/2016/06/xdedic-server-trading-forum-kaspersky/

  • ISC StormCast for Wednesday, June 15th 2016

    15/06/2016 Duração: 07min

    Microsoft Updates https://isc.sans.edu/mspatchdays.html?viewday=2016-06-14 Adobe Updates (Incl. active exploitation of Flash Vuln.) https://helpx.adobe.com/security.html

  • ISC StormCast for Tuesday, June 14th 2016

    14/06/2016 Duração: 04min

    Flocker Ransomware Locks TVs http://blog.trendmicro.com/trendlabs-security-intelligence/flocker-ransomware-crosses-smart-tv/ Samsung Updates Software Update Software http://seclists.org/fulldisclosure/2016/Jun/21 Lets Encrypt Messes Up Notification E-mail, Leaks Addresses https://community.letsencrypt.org/t/email-address-disclosures-preliminary-report-june-11-2016/16867 ClamAV Fuzzing Finds Bugs in 7z Unpacking Code https://foxglovesecurity.com/2016/06/13/finding-pearls-fuzzing-clamav/

  • ISC StormCast for Monday, June 13th 2016

    13/06/2016 Duração: 05min

    DNS Sinkhole 2.0 Released https://isc.sans.edu/forums/diary/DNS+Sinkhole+ISO+Version+20/21153/ Visual C Telemetry Library https://www.reddit.com/r/cpp/comments/4ibauu/visual_studio_adding_telemetry_function_calls_to/ Crysis Ransomware http://www.eset.com/us/resources/detail/new-ransomware-threat-crysis-lays-claim-to-teslacrypt-s-former-turf/ Intel Releases ROP Attack Protection http://blogs.intel.com/evangelists/2016/06/09/intel-release-new-technology-specifications-protect-rop-attacks/ EMC Fixes Data Domain Session ID Disclosure Vulnerability https://auscert.org.au/render.html?it=35618

  • ISC StormCast for Friday, June 10th 2016

    10/06/2016 Duração: 05min

    Google Chrome PDF Viewer Remote Code Execution Vulnerability Patched http://blog.talosintel.com/2016/06/pdfium.html Google Continues to Remove SSLv3 Support http://googleappsupdates.blogspot.com.au/2016/06/gradually-disabling-support-for-sslv3.html Vibration Sensor Can Be Used As Microphone http://synrg.csl.illinois.edu/vibraphone/paperdocs/VibraPhone_nirupam.pdf Keypass Fixes Vulnerable Update Procedure http://keepass.info/help/kb/sec_issues.html#updsig

  • ISC StormCast for Thursday, June 9th 2016

    09/06/2016 Duração: 05min

    CryptXXX Switches From Angler to Neutrino EK https://isc.sans.edu/forums/diary/Neutrino+EK+and+CryptXXX/21141/ Android Flah Keyboard Uses Excessive Permissions https://regmedia.co.uk/2016/06/07/pentestflashkeybpardpaper.pdf Firefox 47 Released https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/#firefox47 D-Link Camera Vulnerable To Remote Exploit http://blog.senr.io/blog/home-secure-home BITS used to make malware more persistent https://www.secureworks.com/blog/malware-lingers-with-bits

  • ISC StormCast for Wednesday, June 8th 2016

    07/06/2016 Duração: 05min

    Various Internet Sites Flag Password Reuse http://krebsonsecurity.com/2016/06/password-re-user-get-to-get-busy/ Facebook Chat Vulnerability Patched https://www.helpnetsecurity.com/2016/06/07/facebook-vulnerability-chat-messenger/ DNS Cookies: Making DNS More Security https://www.rfc-editor.org/rfc/rfc7873.txt

  • ISC StormCast for Tuesday, June 7th 2016

    07/06/2016 Duração: 05min

    LinkedIn Data Used to Personalize Malicious E-Mail https://twitter.com/certbund/status/739824856011804676?ref_src=twsrc%5Etfw Android Patches https://source.android.com/security/bulletin/2016-06-01.html Mitsubishi Outlander Wifi Hack https://www.pentestpartners.com/blog/hacking-the-mitsubishi-outlander-phev-hybrid-suv/ Using NTP to Calibrate Time Stamps in PCAP https://isc.sans.edu/forums/diary/What+Time+Is+It+Using+NTP+Traffic+to+Calibrate+PCAP+Timestamps/21135/ BING Adds Malware Warning https://blogs.bing.com/webmaster/June-2016/Warning!-Bing-now-offers-enhanced-malware-warnings

  • ISC StormCast for Monday, June 6th 2016

    05/06/2016 Duração: 05min

    A Recent MySQL Honeypot Compromise https://isc.sans.edu/forums/diary/MySQL+is+YourSQL/21117/ Team Viewer Improves Security http://www.teamviewer.com/en/company/press/teamviewer-launches-trusted-devices-and-data-integrity/ Black Shades Ransomware http://www.bleepingcomputer.com/news/security/black-shades-ransomware-encrypts-your-pc-and-taunts-security-researchers/ NTP Update http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

  • ISC StormCast for Friday, June 3rd 2016

    03/06/2016 Duração: 05min

    Docker Containers Logging https://isc.sans.edu/forums/diary/Docker+Containers+Logging/21121/ Lenovo Suggests Uninstalling Accelerator Application https://support.lenovo.com/us/en/product_security/len_6718 Google Chrome Update http://googlechromereleases.blogspot.com/search/label/Stable%20updates MongoDB Injection http://blog.securelayer7.net/mongodb-security-injection-attacks-with-php/ Ouch! Newsletter https://securingthehuman.sans.org/resources/newsletters/ouch/2016#encryption Detecting DNS Tunneling With Splunk https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022 Android AV Vulnerabilities https://www.sit.fraunhofer.de/fileadmin/dokumente/Presse/teamsik_advisories_AV.pdf?_=1464692835

  • ISC StormCast for Thursday, June 2nd 2016

    02/06/2016 Duração: 05min

    KeePass Insecure Update https://bogner.sh/2016/03/mitm-attack-against-keepass-2s-update-check/ Possible TeamViewer Breach http://www.theregister.co.uk/2016/06/01/teamviewer_mass_breach_report/ Windows 10 Exploit Offered For Sale https://www.trustwave.com/Resources/SpiderLabs-Blog/Zero-Day-Auction-for-the-Masses/?page=1&year=0&month=0 Intrusion Detection in Depth Minneapolis (July 18-23rd) https://www.sans.org/event/minneapolis-2016/course/intrusion-detection-in-depth

  • ISC StormCast for Wednesday, June 1st 2016

    31/05/2016 Duração: 05min

    Increase in Telnet Scans https://isc.sans.edu/forums/diary/Increase+in+Port+23+telnet+scanning/21115/ Bloatware Introducing Security Flaws in Laptops https://duo.com/blog/out-of-box-exploitation-a-security-analysis-of-oem-updaters Exploit Released for Unpatchable SCADA Controller https://www.exploit-db.com/exploits/37154/ Fail2Ban Adding IPv6 Support https://www.slightfuture.com/security/fail2ban-ipv6 Critical LG Phone Security Flaws http://blog.checkpoint.com/2016/05/29/oems-have-flaws-too-exposing-two-new-lg-vulnerabilities/

  • ISC StormCast for Tuesday, May 31st 2016

    31/05/2016 Duração: 05min

    Hardcoded Password in Medical Software https://www.kb.cert.org/vuls/id/482135 Google Chorme Update http://googlechromereleases.blogspot.com.au/search/label/Stable%20updates PA DSS Update https://www.pcisecuritystandards.org/document_library JetPack WordPress Plugin XSS vulnerabilties https://jetpack.com/2016/05/27/jetpack-4-0-3-critical-security-update/ Tor Browser Fingerprinting Site https://tor.triop.se Anti-Pastejacking Browser Plugin https://github.com/rocketshipapps/hardenedpaste

  • ISC StormCast for Monday, May 30th 2016

    30/05/2016 Duração: 03min

    Analysis of a Distributed Denial of Service Attack https://isc.sans.edu/forums/diary/Analysis+of+a+Distributed+Denial+of+Service+DDoS/21109/ Bluecoat CA http://www.theregister.co.uk/2016/05/27/blue_coat_ca_certs/ Google Requires Symantec CAs to Comply With Certificate Transparency https://cabforum.org/pipermail/public/2016-May/007573.html

  • ISC StormCast for Friday, May 27th 2016

    27/05/2016 Duração: 05min

    Keeping an Eye on Tor Traffic https://isc.sans.edu/forums/diary/Keeping+an+Eye+on+Tor+Traffic/21103/ Next Generation Tor Passed First Test https://blog.torproject.org/blog/mission-montreal-building-next-generation-onion-services DDoS Prives Drop https://www.incapsula.com/blog/unmasking-ddos-for-hire-fiverr.html Older Microsoft Office Vulnerabilities Still Used by "APT" Actors https://securelist.com/analysis/publications/74828/cve-2015-2545-overview-of-current-threats/

  • ISC StormCast for Thursday, May 26th 2016

    26/05/2016 Duração: 05min

    DNS Covert Channel Used in Targeted Attacks http://researchcenter.paloaltonetworks.com/2016/05/unit42-new-wekby-attacks-use-dns-requests-as-command-and-control-mechanism/ Genius Web Annotation Serivce Is Removing Security Headers http://www.theverge.com/2016/5/25/11505454/news-genius-annotate-the-web-content-security-policy-vulnerability Canary Tokens For Windows Binaries http://blog.thinkst.com/2016/05/certified-canarytokens-alerts-from_25.html Cisco Patches IPv6 ND DoS Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6

página 96 de 98