TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Wednesday, October 29th, 2025: Invisible Subject Character Phishing; Tomcat PUT Vuln; BIND9 Spoofing Vuln PoC Oct 29, 2025
    Show notes
    Phishing with Invisible Characters in the Subject Line
    Phishing emails use invisible UTF-8 encoded characters to break up keywords used to detect phishing (or spam). This is aided by mail clients not rendering some characters that should be rendered.
    https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428
    Apache Tomcat PUT Directory Traversal
    Apache released an update to Tomcat fixing a directory traversal vulnerability in how the PUT method is used. Exploits could upload arbitrary files, leading to remote code execution.
    https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog
    BIND9 DNS Spoofing Vulnerability
    A PoC exploit is now available for the recently patched BIND9 spoofing vulnerability
    https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918

    SANS Stormcast Tuesday, October 28th, 2025: Bytes over DNS; Unifi Access Vuln; OpenAI Atlas Prompt Injection Oct 28, 2025
    Show notes
    Bytes over DNS
    Didiear investigated which bytes may be transmitted as part of a hostname in DNS packets, depending on the client resolver and recursive resolver constraints
    https://isc.sans.edu/diary/Bytes%20over%20DNS/32420
    Unifi Access Vulnerability
    Unifi fixed a critical vulnerability in it s Access product
    https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191
    OpenAI Atlas Omnibox Prompt Injection
    OpenAI s latest browser can be jailbroken by inserting prompts in URLs
    https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection

    SANS Stormcast Monday, October 27th, 2025: Bilingual Phishing; Kaitai Struct WebIDE Oct 27, 2025
    Show notes
    Bilingual Phishing for Cloud Credentials
    Guy observed identical phishing messages in French and English attempting to phish cloud credentials
    https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416
    Kaitai Struct WebIDE
    The binary file analysis tool Kaitai Struct is now available in a web only version
    https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422
    WSUS Emergency Update
    Microsoft released an emergency patch for WSUS to fix a currently exploited critical vulnerability
    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287
    Network Security Devices Endanger Orgs with 90s-era Flaws
    Attackers increasingly use simple-to-exploit network security device vulnerabilities to compromise organizations.
    https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html

    SANS Stormcast Friday, October 24th, 2025: Android Infostealer; SessionReaper Exploited; BIND/unbound DNS Spoofing fix; WSUS Exploit Oct 24, 2025
    Show notes
    Infostealer Targeting Android Devices
    This infostealer, written in Python, specifically targets Android phones. It takes advantage of Termux to gain access to data and exfiltrates it via Telegram.
    https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414
    Attackers exploit recently patched Adobe Commerce Vulnerability CVE-2025-54236
    Six weeks after Adobe's emergency patch, SessionReaper (CVE-2025-54236) has entered active exploitation. E-Commerce security company SanSec has detected multiple exploit attempts.
    https://sansec.io/research/sessionreaper-exploitation
    Patch for BIND and unbound nameservers CVE-2025-40780
    The Internet Systems Consortium (ISC.org), as well as the Unbound project, patched a flaw that may allow for DNS spoofing due to a weak random number generator.
    https://kb.isc.org/docs/cve-2025-40780
    WSUS Exploit Released CVE-2025-59287
    Hawktrace released a walk through showing how to exploit the recently patched WSUS vulnerability
    https://hawktrace.com/blog/CVE-2025-59287

    SANS Stormcast Thursday, October 23rd, 2025: Blue Angle Software Exploit; Oracle CPU; Rust tar library vulnerability. Oct 23, 2025
    Show notes
    webctrl.cgi/Blue Angel Software Suite Exploit Attempts. Maybe CVE-2025-34033 Variant?
    Our honeypots detected attacks that appear to exploit CVE-2025-34033 or a similar vulnerability in the Blue Angle Software Suite.
    https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410
    Oracle Critical Patch Update
    Oracle released its quarterly critical patch update. The update includes patches for 374 vulnerabilities across all of Oracle s products. There are nine more patches for Oracle s e-Business Suite.
    https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS
    Rust TAR Library Vulnerability
    A vulnerability in the popular, but no longer maintained, async-tar vulnerability could lead to arbitrary code execution
    https://edera.dev/stories/tarmageddon

    SANS Stormcast Wednesday, October 22nd, 2025: NTP Pool; Xubuntu Compromise; Squid Vulnerability; Lanscope Vuln; Oct 22, 2025
    Show notes
    What time is it? Accuracy of pool.ntp.org.
    How accurate and reliable is pool.ntp.org? Turns out it is very good!
    https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390
    Xubuntu Compromise
    The Xubuntu website was compromised last weekend and served malware
    https://floss.social/@bluesabre/115401767635718361
    Squid Proxy Vulnerability
    The Squid team fixed an information disclosure vulnerabilty that may leak authentication credentials.
    https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr
    Lanscope Endpoint Manager Vulnerablity
    https://jvn.jp/en/jp/JVN86318557/index.html

    SANS Stormcast Tuesday, October 21st, 2025: Syscall() Obfuscation; AWS down; Beijing Time Attack Oct 20, 2025
    Show notes
    Using Syscall() for Obfuscation/Fileless Activity
    Fileless malware written in Python can uses syscall() to create file descriptors in memory, evading signatures.
    https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384
    AWS Outages
    AWS has had issues most of the day on Monday, affecting numerous services.
    https://health.aws.amazon.com/health/status
    Time Server Hack
    China reports a compromise of its time standard servers.
    https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html

    SANS Stormcast Monday, October 20th, 2025: Malicious Tiktok; More Google Ad Problems; Satellite Insecurity Oct 19, 2025
    Show notes
    TikTok Videos Promoting Malware InstallationTikTok Videos Promoting Malware Installation
    Tiktok videos advertising ways to obtain software like Photoshop for free will instead trick users into downloading
    https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380
    Google Ads Advertise Malware Targeting MacOS Developers
    Hunt.io discovered Google ads that pretend to advertise tools like Homebrew and password managers to spread malware
    https://hunt.io/blog/macos-odyssey-amos-malware-campaign
    Satellite Transmissions are often unencrypted
    A large amount of satellite traffic is unencrypted and easily accessible to eavesdropping
    https://satcom.sysnet.ucsd.edu

    SANS Stormcast Friday, October 17th, 2025: New Slack Workspace; Cisco SNMP Exploited; BIOS Backdoor; @sans_edu reseach: Active Defense Oct 17, 2025
    Show notes

    New DShield Support Slack Workspace
    Due to an error on Salesforce s side, we had to create a new Slack Workspace for DShield support.
    https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376
    Attackers Exploiting Recently Patched Cisco SNMP Flaw (CVE-2025-20352)
    Trend Micro published details explaining how attackers took advantage of a recently patched Cisco SNMP Vulnerability
    https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte
    Framework BIOS Backdoor
    The mm command implemented in Framework BIOS shells can be used to compromise a device pre-boot.
    https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/
    SANS.edu Research: Mark Stephens, Validating the Effectiveness of MITRE Engage and Active Defense
    https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/


    SANS Stormcast Thursday, October 16th, 2025: Clipboard Image Stealer; F5 Compromise; Adobe Updates; SAP Patchday Oct 15, 2025
    Show notes

    Clipboard Image Stealer
    Xavier presents an infostealer in Python that steals images from the clipboard.
    https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372
    F5 Compromise
    F5 announced a wide-ranging compromise today. Source code and information about unpatched vulnerabilities were stolen.
    https://my.f5.com/manage/s/article/K000157005
    https://my.f5.com/manage/s/article/K000156572
    https://my.f5.com/manage/s/article/K000154696
    Adobe Updates
    Adobe updated 12 different products yesterday.
    https://helpx.adobe.com/security.html
    SAP Patchday
    Among the critical vulnerabilities patched in SAP s products are two deserialization vulnerabilities with a CVSS score of 10.0
    https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html
    https://onapsis.com/blog/sap-security-patch-day-october-2025/


    Previous 1 21 22 23 24 25 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights