TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Thursday, January 22nd, 2026: Visual Studio Code Scripts; Cisco Unified Comm and Zoom Vuln; Insufficient Fortinet Patch; SANS SOC Survey Jan 22, 2026
    Show notes
    Automatic Script Execution In Visual Studio Code
    Visual Studio Code will read configuration files within the source code that may lead to code execution.
    https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644
    Cisco Unified Communications Products Remote Code Execution Vulnerability A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b
    Zoom Vulnerability
    A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to execute remote code on the MMR via network access.
    https://www.zoom.com/en/trust/security-bulletin/zsb-26001/
    Possible new SSO Exploit (CVE-2025-59718) on 7.4.9
    https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/
    SANS SOC Survey
    The 2026 SOC Survey is open, and we need your input to create a meaningful report. Please share your experience so we can advocate for what actually works in the trenches.
    https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter

    SANS Stormcast Wednesday, January 21st, 2026: Punycode Hunting; telnetd vuln; 6 day Certs and IP Certs; Oracle Patches Jan 21, 2026
    Show notes
    Add Punycode to your Threat Hunting Routine
    Punycode patterns in DNS queries make excellent hunting opportunities.
    https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640
    GNU InetUtils Security Advisory: remote authentication by-pass intelnetd
    telnetd shipping with InetUtils suffers from a critical authentication by-pass vulnerability.
    https://www.openwall.com/lists/oss-security/2026/01/20/2
    6-day and IP Address Certificates are Generally Available
    Let s Encrypt will now offer 6-day certificates as an option. These short-lived certificates can be used for IP addresses.
    https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability
    Oracle Quarterly Critical Patch Update
    Oracle released its first quarterly patches for 2026, fixing 337 vulnerabilities
    https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW

    SANS Stormcast Tuesday, January 20th, 2026: Scans Against LLMs; NTLM Rainbow Table; OOB MSFT Patch Jan 20, 2026
    Show notes
    "How many states are there in the United States?"
    Attackers are actively scanning for LLMs, fingerprinting them using the query How many states are there in the United States? .
    https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618
    Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation
    Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol.
    https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables
    Out-of-band update to address issues observed with the January 2026 Windows security update
    Microsoft has identified issues upon installing the January 2026 Windows security update. To address these issues, an out-of-band (OOB) update was released today, January 17, 2026
    https://learn.microsoft.com/en-us/windows/release-health/windows-message-center

    SANS Stormcast Friday, January 16th, 2026: Cryptojacking Hidden Gifts; Bluetooth Vulnerability; Reprompt in MSFT Copilot Jan 16, 2026
    Show notes
    Battling Cryptojacking, Botnets, and IABs
    Cryptojacking often comes with less obvious addons, like SSH backdoors
    https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632
    Microsoft Copilot Reprompt Attacks
    Adding a query parameter to the URL may prefill a Copilot prompt, altering the meaning of the prompts that follow.
    https://www.varonis.com/blog/reprompt
    Hijacking Bluetooth Accessories Using Google Fast Pair
    Google s fast pair protocol is often not implemented correctly, allowing the Hijacking of Bluetooth accessories
    https://whisperpair.eu/#about

    SANS Stormcast Thursday, January 15th, 2026: Luma Streal Repeat Infection; ServiceNow Broken Auth; Starlink/GPS Jamming Jan 15, 2026
    Show notes
    Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain
    https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628
    BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow
    https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/
    Starlink Terminal GPS Spoofing/Jamming Detection in Iran
    https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md

    SANS Stormcast Wednesday, January 14th, 2026: Microsoft, Adobe and Fortinet Patches; ConsentFix Jan 14, 2026
    Show notes
    Microsoft Patch Tuesday January 2026
    Microsoft released patches for 113 vulnerabilities. This includes one already exploited vulnerability, one that was made public before today and eight critical vulnerabilities.
    https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624
    Adobe Patches
    Adobe released patches for five products. The code execution vulnerabilities in ColdFusion and Acrobat Reader deserve special attention.
    https://helpx.adobe.com/security.html
    Fortinet Patches
    Fortnet patched two products today, one suffering from an SSRF vulnerability.
    https://fortiguard.fortinet.com/psirt/FG-IR-25-783
    https://fortiguard.fortinet.com/psirt/FG-IR-25-084
    ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants
    Attackers are tricking victims to copy/paste OAUTH URLs, including credentials, to a fake CAPTCHA
    https://pushsecurity.com/blog/consentfix

    SANS Stormcast Tuesday, January 13th, 2026: n8n got npm’ed; Gogs exploit; telegram proxy links Jan 13, 2026
    Show notes
    n8n supply chain attack
    Malicious npm pagackages were used to attempt to obtain user OAUTH credentials for NPM.
    https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem
    Gogs 0-Day Exploited in the Wild
    An at the time unpachted flaw in Gogs was exploited to compromise git repos.
    https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
    Telegram Proxy Link Abuse
    Telegram proxy links have been abused to deanonymize users
    https://x.com/GangExposed_RU/status/2009961417781457129

    SANS Stormcast Monday, January 12th, 2026: PEB Manipulation; YARA Update; VideoLAND and Apache NimBLE Patches Jan 12, 2026
    Show notes
    Malicious Process Environment Block Manipulation
    The process environment block contains metadata about particular processes, but can be manipulated.
    https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/
    YARA-X 1.11.0 Release: Hash Function Warnings
    The latest version of YARA will warn users if a hash rule attempts to match an invalid hash.
    https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616
    VideoLAN Security Bulletin VLC 3.0.22 CVE-2025-51602
    VideoLAN fixed several vulnerabilities in its VLC software.
    https://www.videolan.org/security/sb-vlc3022.html
    Apache NimBLE Bluetooth vulnerabilities
    NimBLE is a Bluetooth stack popular in IoT devices. An update fixes some eavesdropping and pairing vulnerabilities.
    https://mynewt.apache.org/cve/

    SANS Stormcast Friday, January 9th, 2026: Gephi Analysis; zlib vuln; GnuPG Vulns; Cisco/Cloudflare DNS Issue Jan 09, 2026
    Show notes
    Analysis using Gephi with DShield Sensor Data
    Gephi is a neat tool to create interactive data visualizations. It can be applied to honeypot data to find data clusters.
    https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608
    zlib v1.3.1.2 Global Buffer Overflow in TGZfname() of zlib untgz Utility
    The untgz utility that is part of zlib suffers from a straightforward buffer overflow in the filename parameter
    https://seclists.org/fulldisclosure/2026/Jan/3
    GnuPG Vulnerabilities
    Several vulnerabilities in GnuPG were disclosed during a recent talk at the CCC congress.
    https://gpg.fail
    Cisco DNS Bug Reboot
    Last night, several Cisco users reported that their switches rebooted. The issue appears to be related to a change Cloudflare made in the order of CNAME records. Only users using 1.1.1.1 as a recursive resolver appear to be affected.
    https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com

    SANS Stormcast Thursday, January 8th, 2026: HTML QR Code Phishing; n8n vulnerability; Powerbank Feature Creep Jan 08, 2026
    Show notes
    A phishing campaign with QR codes rendered using an HTML table
    Phishing emails are bypassing filters by encoding QR codes as HTML tables.
    https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606
    n8n vulnerabilities
    In recent days, several new n8n vulnerabilities were disclosed. Ensure that you update any on-premises installations and carefully consider what to use n8n for.
    https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858
    https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg
    Power bank feature creep is out of control
    Simple power banks are increasingly equipped with advanced features, including networking, which may expose them to security risks.
    https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep

    Previous 1 16 17 18 19 20 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights