ISC StormCast for Thursday, April 20th 2017

By Johannes B. Ullrich, Ph.D. Hunting and Analyzing Malicious Excel Files
https://isc.sans.edu/forums/diary/Hunting+for+Malicious+Excel+Sheets/22322/
Bose May Be Spying on Listeners
https://www.scribd.com/document/345620278/Bose-Privacy-Complaint
Microsoft No-Password Sign In
https://blogs.technet.microsoft.com/enterprisemobility/2017/04/18/no-password-phone-sign-in-for-microsoft-accounts/
Owncloud/Nextcloud Bug Reports Include Passwords
https://blog.hboeck.de/archives/885-Passwords-in-the-Bug-Reports-OwncloudNextcloud.html
Fuzzing Used to Find a Tcpdump Vulnerability
https://www.softscheck.com/en/identifying-security-vulnerabilities-with-cloud-fuzzing/
DNS Homograph Detection
https://github.com/dutchcoders/homographs
For Friday’s (and other upcoming webcasts), see
https://www.sans.org/webcasts
More Here