TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Wednesday, October 1st, 2025: Cookie Auth Issues; Western Digtial Command Injection; sudo exploited; Oct 01, 2025
    Show notes
    Sometimes you don t even need to log in
    Applications using simple, predictable cookies to verify a user s identity are still exploited, and relatively recent vulnerabilities are still due to this very basic mistake.
    https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334
    Western Digital My Cloud Vulnerability
    Western Digital patched a critical vulnerability in its MyCloud device.
    https://nvd.nist.gov/vuln/detail/CVE-2025-30247
    sudo vulnerability exploited
    A recently patched vulnerability in sudo is now being exploited.
    https://www.sudo.ws/security/advisories/

    SANS Stormcast Tuesday, September 30th, 2025: Apple Patch; PAN Global Protect Scans; SSL.com signed malware Sep 30, 2025
    Show notes
    Apple Patches
    Apple released patches for iOS, macOS, and visionOS, fixing a single font parsing vulnerability
    https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330
    Increase in Scans for Palo Alto Global Protect Vulnerability (CVE-2024-3400).
    Our honeypots detected an increase in scans for a Palo Alto Global Protect vulnerability.
    https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328
    Nimbus Manticore / Charming Kitten Malware update
    Checkpoint released a report with details regarding a new Nimbus Manticore exploit kit. The malware in this case uses valid SSL.com-issued certificates.
    https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/

    SANS Stormcast Monday, September 29th, 2025: Convert Timestamps; Cisco Compromises; GitHub Notification Phishing Sep 29, 2025
    Show notes
    Converting Timestamps in .bash_history
    Unix shells offer the ability to add timestamps to commands in the .bash_history file. This is often done in the form of Unix timestamps. This new tool converts these timestamps into a more readable format.
    https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324
    Cisco ASA/FRD Compromises
    Exploitation of the vulnerabilities Cisco patched last week may have bone back about a year. Cisco and CISA have released advisories with help identifying affected devices.
    https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks
    https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
    Github Notification Phishing
    Github notifications are used to impersonate YCombinator and trick victims into installing a crypto drainer.
    https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/

    SANS Stormcast Friday, September 26th, 2025: Webshells in .well-known; Critical Cisco Vulns Exploited; XCSSET Update; GoAnywhere MFT Exploit Details Sep 26, 2025
    Show notes
    Webshells Hiding in .well-known Places
    Our honeypots registered an increase in scans for URLs in the .well-known directory, which appears to be looking for webshells.
    https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320
    Cisco Patches Critical Exploited Vulnerabilities
    Cisco released updates addressing already-exploited vulnerabilities in the VPN web server for the ASA and FTD appliances.
    https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW
    XCSSET Evolves Again
    Microsoft detected a new XCSSET variant, an infostealer infecting X-Code projects.
    https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/
    Exploitation of Fortra GoAnywhere MFT CVE-2025-10035
    watchTowr analyzed the latest GoAnywhere MFT vulnerability and exploits used against it.
    https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/

    SANS Stormcast Thursday, September 25th, 2025: Hikvision Exploits; Cisco Patches; Sonicawall Anit-Rootkit Patch; Windows 10 Support Sep 25, 2025
    Show notes
    Exploit Attempts Against Older Hikvision Camera Vulnerability
    Out honeypots observed an increase in attacks against some older Hikvision issues. A big part of the problem is weak passwords, and the ability to send credentials as part of the URL.
    https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316
    Cisco Patches Already Exploited SNMP Vulnerability
    Cisco patched a stack-based buffer overflow in the SNMP subsystem. It is already exploited in the wild, but requires
    admin privileges to achieve code execution.
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte
    SonicWall Anti-Rootkit Update
    SonicWall released a firmware update for its SMA100 devices specifically designed to eradicate a commonly deployed rootkit.
    https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015
    Extended Windows 10 Support
    Microsoft will extend free Windows 10 essential support for US and European customers.
    https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline

    SANS Stormcast Wednesday, September 24th, 2025: DoS against the Analyst; GitHub Improvements; Solarwinds and Supermicro BMC vulnerabilities Sep 24, 2025
    Show notes
    Distracting the Analyst for Fun and Profit
    Our undergraduate intern, Tyler House analyzed what may have been a small DoS attack that was likely more meant to distract than to actually cause a denial of service
    https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308
    GitHub s plan for a more secure npm supply chain
    GitHub outlined its plan to harden the supply chain, in particular in light of the recent attack against npm packages
    https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/
    SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-26399)
    SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
    https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399
    Vulnerabilities in Supermicro BMC Firmware CVE-2025-7937 CVE-2025-6198
    Supermicro fixed two vulnerabilities that could allow an attacker to compromise the BMC with rogue firmware.
    https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025

    SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation Sep 23, 2025
    Show notes
    CISA Reports Ivanti EPMM Exploit Sightings
    Two different organizations submitted backdoors to CISA, which are believed to have been installed using Ivanti vulnerabilities patched in May.
    https://www.cisa.gov/news-events/analysis-reports/ar25-261a
    Lastpass Observes Impersonation on GitHub
    Lastpass noted a number of companies being impersonated via fake GitHub repositories in order to trick victims to download Mac malware.
    https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages
    Oracle Scheduler Ransomware
    Ransomware has been discovered that gained access to systems via an exposed Oracle Database Scheduler service.
    https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/

    SANS Stormcast Monday, September 22nd, 2025: Odd HTTP Reuqest; GoAnywhere MFT Bug; EDR Freeze Sep 22, 2025
    Show notes
    Help Wanted: What are these odd requests about?
    An odd request is hitting a number of our honeypots with a somewhat unusual HTTP request
    header. Please let me know if you no what the request is about.
    https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/
    Forta GoAnywhere MFT Vulnerability
    Forta s GoAnywhere MFT product suffers from a critical deserialization vulnerability. Forta released
    an advisory disclosing the vulnerability on Thursday.
    https://www.fortra.com/security/advisories/product-security/fi-2025-012
    EDR Freeze
    A new tool, EDR Freeze, allows regular users to suspend EDR processes.
    https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html

    SANS Stormcast Friday, September 19th, 2025: Honeypot File Analysis (@sans_edu); SonicWall Breach; DeepSeek Bias; Chrome 0-day Sep 19, 2025
    Show notes
    Exploring Uploads in a Dshield Honeypot Environment
    This guest diary by one of our SANS.edu undergraduate interns shows how to analyze files uploaded to Cowrie
    https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296
    Sonicwall Breach
    SonicWall MySonicWall accounts were breached via credential brute forcing
    https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330
    DeepSeek Bias
    Cloudflare found significant biases in code created by the Chinese AI engine DeepSeek. Code for organizations not aligned with China s politics contained significantly more bugs
    https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/
    Google Chrome 0-day
    Google fixed an already-exploited vulnerability in Google Chrome
    https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html

    SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches Sep 18, 2025
    Show notes
    CTRL-Z DLL Hooking
    Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries.
    https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294
    Global Admin in every Entra ID tenant via Actor tokens
    As part of September s patch Tuesday, Microsoft patched CVE-2025-55241. The discoverer of the vulnerability,
    Dirk-jan Mollema has published a blog post showing how this vulnerability could have been exploited.
    https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
    WatchGuard Firebox iked Out of Bounds Write Vulnerability CVE-2025-9242
    WatchGuard patched an out-of-bounds write vulnerability, which could allow an unauthenticated attacker to compromise the devices.
    https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015
    NVidia Triton Inference Server
    NVIDIA patched critical vulnerabilities in its Triton Inference Server.
    https://nvidia.custhelp.com/app/answers/detail/a_id/5691

    Previous 1 23 24 25 26 27 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights