TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Wednesday, November 26th, 2025: Attacks Against Messaging; Passwords in Random Websites; Fluentbit Vuln; #thanksgiving Nov 26, 2025
    Show notes
    Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications
    Spyware attacks messaging applications in part by triggering vulnerabilities in messaging applications but also by deploying tools like keystroke loggers and screenshot applications.
    https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications
    Stop Putting Your Passwords Into Random Websites Yes. Just Stop!
    https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/
    Fluentbit Vulnerability
    https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover
    Happy Thanksgiving. Next podcast on Monday after Thanksgiving.

    SANS Stormcast Tuesday, November 25th, 2025: URL Mapping and Authentication; SHA1-Hulud; Hacklore Nov 25, 2025
    Show notes
    Conflicts between URL mapping and URL based access control.
    Mapping different URLs to the same script, and relying on URL based authentication at the same time, may lead to dangerous authentication and access control gaps.
    https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518
    Sha1-Hulud, The Second Coming
    A new, destructive variant of the Shai-Hulud worm is currently spreading through NPM/Github repos.
    https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised
    Hacklore: Cleaning up Outdated Security Advice
    A new website, hacklore.org, has published an open letter from former CISOs and other security leaders aimed at addressing some outdated security advice that is often repeated.
    https://www.hacklore.org

    SANS Stormcast Monday, November 24th, 2025: CSS Padding in Phishing; Oracle Identity Manager Scans Update; Nov 24, 2025
    Show notes
    Use of CSS stuffing as an obfuscation technique?
    Phishing sites stuff their HTML with benign CSS code. This is likely supposed to throw of simple detection engines
    https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510
    Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day
    Early exploit attempts for the vulnerability were part of Searchlight Cyber s research effort
    https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/
    ClamAV Cleaning Signature Database
    ClamAV will significantly clean up its signature database
    https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html

    SANS Stormcast Friday, November 21st, 2025: Oracle Idendity Manager Scans; SonicWall DoS Vuln; Adam Wilson (@sans_edu) reducing prompt injection. Nov 21, 2025
    Show notes
    Oracle Identity Manager Exploit Observation from September (CVE-2025-61757)
    We observed some exploit attempts in September against an Oracle Identity Manager vulnerability that was patched in October, indicating that exploitation may have occurred prior to the patch being released.
    https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506
    https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/
    DigitStealer: a JXA-based infostealer that leaves little footprint
    https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/
    SonicWall DoS Vulnerability
    Sonicwall patched a DoS vulnerability in SonicOS
    https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016
    Adam Wilson: Automating Generative AI Guidelines: Reducing Prompt Injection Risk with 'Shift-Left' MITRE ATLAS Mitigation Testing

    SANS Stormcast Thursday, November 20th, 2025: Unicode Issues; FortiWeb More Vulns; DLink DIR-878 Vuln; Operation WrtHug and ASUS Routers Nov 20, 2025
    Show notes
    Unicode: It is more than funny domain names.
    Unicode can cause a number of issues due to odd features like variance selectors and text direction issues.
    https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472
    FortiWeb Multiple OS command injection in API and CLI
    A second silently patched vulnerability in FortiWeb is already being exploited in the wild.
    https://fortiguard.fortinet.com/psirt/FG-IR-25-513
    DLink DIR-878 Vulnerability
    DLink disclosed four different vulnerabilities in its popular DIR-878 router. The router is end-of-life and DLink will not release patches
    https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475
    Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router
    A new report, Operation WrtHug, has uncovered a massive, coordinated effort that has compromised thousands of ASUS routers worldwide.
    https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/

    SANS Stormcast Wednesday, November 19th, 2025: Kong Tuke; Cloudflare Outage Nov 19, 2025
    Show notes
    KongTuke Activity
    This diary investigates how a recent Kong Tuke infections evolved all the way from starting with a ClickFix attack.
    https://isc.sans.edu/diary/KongTuke%20activity/32498
    Cloudflare Outage
    Cloudflare suffered a large outage today after an oversized configuration file was loaded into its bot protection service
    https://x.com/dok2001
    Google Patches Chrome 0-Day
    Google patched two vulnerabilities in Chrome. One of them is already being exploited.
    https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html

    SANS Stormcast Tuesday, November 18th, 2025: Binary Expression Decoding. Tea NPM Pollution; IBM AIX NIMSH Vulnerability Nov 18, 2025
    Show notes
    Decoding Binary Numeric Expressions
    Didier updated his number to hex script to support simple arithmetic operations in the text.
    https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490
    Tea Token NPM Pollution
    The NPM repository was hit with around 150,000 submissions that did not contain any useful contributions, but instead attempted to fake contributions to earn a new tea coin.
    https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/
    IBM AIX NIMSH Vulnerabilities
    IBM patched several critical vulnerablities in the NIMSH daemon
    https://www.ibm.com/support/pages/node/7251173

    SANS Stormcast Monday, November 17th, 2025: New(isch) Fortiweb Vulnerability; Finger and ClickFix Nov 17, 2025
    Show notes
    Fortiweb Vulnerability
    Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly.
    https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486
    https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/
    https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com
    Flnger.exe and ClickFix
    Attackers started to use the finger.exe binary to retrieve additional payload in ClickFix attacks
    https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492

    SANS Stormcast Friday, November 14th, 2025: SmartApeSG and ClickFix; Formbook Obfuscation Tricks; Sudo-rs Vulnerabilities; SANS Holiday Hack Challenge Nov 14, 2025
    Show notes
    SmartApeSG campaign uses ClickFix page to push NetSupport RAT
    A detailed analysis of a recent SamtApeSG campaign taking advantage of ClickFix
    https://isc.sans.edu/diary/32474
    Formbook Delivered Through Multiple Scripts
    An analysis of a recent version of Formbook showing how it takes advantage of multiple obfuscation tricks
    https://isc.sans.edu/diary/32480
    sudo-rs vulnerabilities
    Two vulnerabilities were patched in sudo-rs, the version of sudo written in Rust, showing that while Rust does have an advantage when it comes to memory safety, there are plenty of other vulnerabilities to worry about
    https://ubuntu.com/security/notices/USN-7867-1
    https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com
    SANS Holiday Hack Challenge
    https://sans.org/HolidayHack

    SANS Stormcast Thursday, November 13th, 2025: OWASP Top 10 Update; Cisco/Citrix Exploits; Test post quantum readiness Nov 13, 2025
    Show notes
    OWASP Top 10 2025 Release Candidate
    OWASP published a release candidate for the 2025 version of its Top 10 list
    https://owasp.org/Top10/2025/0x00_2025-Introduction/
    Citrix/Cisco Exploitation Details
    Amazon detailed how Citrix and Cisco vulnerabilities were used by advanced actors to upload webshells
    https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/
    Testing Quantum Readyness
    A website tests your services for post-quantum computing-resistant cryptographic algorithms
    https://qcready.com/

    Previous 1 19 20 21 22 23 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights