TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Thursday, February 5th, 2026: Malicious Scripts; Synectix Vuln; Google Chrome; Google Looker; Feb 05, 2026
    Show notes
    Malicious Script Delivering More Maliciousness
    https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682
    Synectix LAN 232 TRIO Unauthenticated Web Admin CVE-2026-1633
    https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04
    Google Chrome Patches
    https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html
    LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem)
    https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout

    SANS Stormcast Wednesday, February 4th, 2026: Detecting OpenClaw; Synology telnetd Patch; More GlassWorm Feb 04, 2026
    Show notes
    Detecting and Monitoring OpenClaw (clawdbot, moltbot)
    https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment
    Synology telnetd Patch
    https://www.synology.com/en-us/releaseNote/DSM
    GlassWorm Loader Hits Open VSX via Developer Account Compromise
    https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise

    SANS Stormcast Tuesday, February 3rd, 2026: Scanning for AI; Notepad++ Compromise; OpenClaw Vulnerabilities Feb 03, 2026
    Show notes
    Scanning for exposed Anthropic Models https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674
    Notepad++ Hijacked by State-Sponsored Hackers https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
    https://notepad-plus-plus.org/news/hijacked-incident-info-update/
    Insecure Websockets in OpenClaw
    https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability
    Malicious OpenClaw Skills
    https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting
    Exposed OpenClaw Instances
    https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant

    SANS Stormcast Monday, February 2nd, 2026: Google Presentation Abuse; Ivanti Vuln Exploited; Microsoft NTLM Strategy Feb 02, 2026
    Show notes
    Google Presentation Abuse
    https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/
    Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 & CVE-2026-1340)
    https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US
    Microsoft NTLM Strategy
    https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526

    SANS Stormcast Friday, January 30th, 2026: Residential Proxy Networks; Clowdbot/Moltbot Themed Malware; eScan Malicious Updates Jan 30, 2026
    Show notes
    No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network
    Google dismantled the IPIDEA network that used residential proxies to route malicious traffic.
    https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network
    Fake Clawdbot VS Code Extension Installs ScreenConnect RAT
    The news about Clawdbot (now Moltbot) is used to distribute malware, in particular malicious VS Code extensions.
    https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware
    Threat Bulletin: Critical eScan Supply Chain Compromise
    Anti-virus vendor eScan was compromised, and its update servers were used to install malware on some customer systems.
    https://www.morphisec.com/blog/critical-escan-threat-bulletin/

    SANS Stormcast Thursday, January 29th, 2026: WebLogic AI Slop; Fortinet Patches; WebLogic AI Slop; Fortinet Patches Jan 29, 2026
    Show notes
    Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?
    We are seeing attempts to attack CVE-2026-21962, a recent weblog vulnerability, using a non-working AI slop exploit
    https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662
    Fortinet Patches are Rolling Out
    Fortinet is starting to roll out patches for the recent SSO vulnerability
    https://fortiguard.fortinet.com/psirt/FG-IR-26-060
    SolarWinds Web Helpdesk Vulnerability
    Another set of vulnerabilities in SolarWinds Web Helpdesk may result in unauthenticated system access
    https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/

    SANS Stormcast Wednesday, January 28th, 2026: Romance Scams; DoS Vuln in React Server Components; OpenSSL Patch; Kubernetes Priv Confusion Jan 28, 2026
    Show notes
    Initial Stages of Romance Scams [Guest Diary]
    Romance scams often start with random text messages that appear to be misrouted . This guest diary by Faris Azhari is following some of the initial stages of such a scam.
    https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650
    Denial of Service Vulnerabilities in React Server Components
    Another folowup fix for the severe React vulnerability from last year, but now only fixing a DoS condition.
    https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg
    OpenSSL Updates
    OpenSSL released its monthly updates, fixing a potential RCE.
    https://openssl-library.org/news/vulnerabilities/
    Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission
    Many Kubernetes Helm Charts are vulnerable to possible remote code executions due to unclear defined access controls.
    https://grahamhelton.com/blog/nodes-proxy-rce

    SANS Stormcast Tuesday, January 27th, 2026: PWD scanning; MSFT Office OOB Patch; Exposed Clawdbot Jan 27, 2026
    Show notes
    Scanning Webserver with pwd as a Starting Path
    Attackers are adding the output of the pwd command to their web scans.
    https://isc.sans.edu/diary/x/32654
    Microsoft Office Security Feature Bypass Vulnerability CVE-2026-21509
    Microsoft released an out-of-band patch for Office fixing a currently exploited vulnerability.
    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
    Exposed Clawdbot Instances
    Many users of the AI tool clawdbot expose instances without access control.
    https://x.com/theonejvo/status/2015485025266098536

    SANS Stormcast Monday, January 26th, 2026: FortiOS SSO Vuln Updates; Outlook OOB Update; VMware vCenter Exploited Jan 26, 2026
    Show notes
    Analysis of Single Sign-On Abuse on FortiOS
    Fortinet released an advisory. FortiOS devices are vulnerable if configured with any SAML integration, not just FortiCloud
    https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios
    Outlook OOB Update
    Microsoft released a non-security OOB Update for Outlook, fixing an issue introduced with this months security patches.
    https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491
    VMware vCenter Server Vulnerabilities Exploited (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081)
    A VMWare vCenter vulnerability patched last June is now actively exploited.
    https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453

    SANS Stormcast Friday, January 23rd, 2026: Scanning AI Code; FortiGate Update; ISC BIND DoS; Trivial SmaterMail Vulnerability Jan 23, 2026
    Show notes
    Is AI-Generated Code Secure?
    Xavier used the free static code analysis tool Bandit to review code he wrote with heavy AI support.
    https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648
    Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts
    Arctic Wolf summarized some of the attacks it is seeing against FortiGate devices via the insufficiently patched SSL vulnerability.
    https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/
    ISC BIND DoS vulnerability in Drone ID Records
    HHIT and BRID records, which are used as part of Drone ID, can be used to crash named if their length is 3 bytes.
    https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/
    SmarterTools SmarterMail Password Reset Vulnerability
    SmarterTools recently patched a trivial vulnerability in SmarterMail that would allow anybody without authentication to reset administrator passwords.
    https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/

    Previous 1 15 16 17 18 19 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights