TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Wednesday, September 17th, 2025: Phishing Resistants; More npm Attacks; ChatGPT MCP abuse Sep 17, 2025
    Show notes
    Why You Need Phishing-Resistant Authentication NOW.
    The recent compromise of a number of high-profile npmjs.com accounts has yet again shown how dangerous a simple phishing email can be.
    https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290
    S1ngularity/nx Attackers Strike Again
    A second wave of attacks has hit over a hundred npm-related GitHub repositories. The updated payload implements a worm that propagates itself to other repositories.
    https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again
    ChatGPT s Calendar Integration Can Be Exploited to Steal Emails
    ChatGPT s new MCP integration can be used, via prompt injection, to affect software connected to ChatGPT via MCP.
    https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/

    SANS Stormcast Tuesday, September 16th, 2025: Apple Updates; Rust Phishing; Samsung 0-day Sep 16, 2025
    Show notes
    Apple Updates
    Apple released major updates for all of its operating systems. In addition to new features, these updates patch 33 different vulnerabilities.
    https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286
    Microsoft End of Life
    October 14th, support for Windows 10, Exchange 2016, and Exchange 2019 will end.
    https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011.
    https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605
    Phishing Targeting Rust Developers
    Rust developers are reporting similar phishing emails as the emails causing the major NPM compromise last week.
    https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064
    Samsung Patches 0-Day
    Samsung released its monthly updates for its flagship phones fixing, among other vulnerability, an already exploited 0-day.
    https://security.samsungmobile.com/securityUpdate.smsb

    SANS Stormcast Monday, September 15th, 2025: More Archives; Salesforce Attacks; White Cobra; BSides Augusta Sep 15, 2025
    Show notes
    Web Searches For Archives
    Didier observed additional file types being searched for as attackers continue to focus on archive files as they spider web pages
    https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282
    FBI Flash Alert: Salesforce Attacks
    The FBI is alerting users of Salesforce of two different threat actors targeting Salesforce. There are no new vulnerabilities disclosed, but the initial access usually takes advantage of social engineering or leaked data from the Salesdrift compromise.
    https://www.ic3.gov/CSA/2025/250912.pdf
    VSCode Cursor Extensions Malware
    Koe Security unmasked details about a recent malicious cursor extension campaign they call White Cobra.
    https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware
    BSides Augusta
    https://bsidesaugusta.org/

    SANS Stormcast Friday, September 12th, 2025: DShield SIEM Update; Another Sonicwall Warning; Website Keystroke Logging Sep 12, 2025
    Show notes
    DShield SIEM Docker Updates
    Guy updated the DShield SIEM which graphically summarizes what is happening inside your honeypot.
    https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276
    Again: Sonicwall SSL VPN Compromises
    The Australian Government s Signals Directorate noted an increase in compromised Sonicwall devices.
    https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia
    Website Keystroke Logging
    Many websites log every keystroke, not just data submitted in forms.
    https://arxiv.org/pdf/2508.19825

    SANS Stormcast Thursday, September 11th, 2025: BASE64 in DNS; Google Chrome, Ivantii and Sophos Patches; Apple Memory Integrity Feature Sep 11, 2025
    Show notes
    BASE64 Over DNS
    The base64 character set exceeds what is allowable in DNS. However, some implementations will work even with these invalid characters.
    https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274
    Google Chrome Update
    Google released an update for Google Chrome, addressing two vulnerabilities. One of the vulnerabilities is rated critical and may allow code execution.
    https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html
    Ivanti Updates
    Ivanti patched a number of vulnerabilities, several of them critical, across its product portfolio.
    https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs
    Sophos Patches
    Sophos resolved authentication bypass vulnerability in Sophos AP6 series wireless access point firmware (CVE-2025-10159)
    https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6
    Apple Introduces Memory Integrity Enforcement
    With the new hardware promoted in yesterday s event, Apple also introduced new memory integrity features based on this new hardware.
    https://security.apple.com/blog/memory-integrity-enforcement/

    SANS Stormcast Wednesday, September 10th, 2025: Microsoft Patch Tuesday; Sep 10, 2025
    Show notes
    Microsoft Patch Tuesday
    As part of its September patch Tuesday, Microsoft addressed 177 different vulnerabilities, 86 of which affect Microsoft products. None of the vulnerabilities has been exploited before today. Two of the vulnerabilities were already made public. Microsoft rates 13 of the vulnerabilities are critical.
    https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270
    Adobe Patches
    Adobe released patches for nine products, including Adobe Commerce, Coldfusion, and Acrobat.
    https://helpx.adobe.com/security/security-bulletin.html
    SAP Patches
    SAP patched vulnerabilities across its product portfolio. Particularly interesting are a few critical vulnerabilities in Netweaver, one of which scored a perfect 10.0 CVSS score.
    https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/

    SANS Stormcast Tuesday, September 9th, 2025: Major npm compromise; HTTP Request Signature Sep 09, 2025
    Show notes
    Major npm compromise
    A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week.
    https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y https://github.com/orgs/community/discussions/172738 https://github.com/chalk/chalk/issues/656#issuecomment-3266894253
    https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
    HTTP Request Signatures
    It looks like some search engines and AI bots are starting to use the HTTP request signature. This should make it easier to identify bot traffic.
    https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266

    SANS Stormcast Monday, September 8th, 2025: YARA to Debugger Offsets; SVG JavaScript Phishing; FreePBX Patches; Sep 08, 2025
    Show notes
    From YARA Offsets to Virtual Addresses
    Xavier explains how to convert offsets reported by YARA into offsets suitable for the use with debuggers.
    https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262
    Phishing via JavaScript in SVG Files
    Virustotal uncovered a Colombian phishing campaign that takes advantage of JavaScript in SVG files.
    https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html
    FreePBX Patches
    FreePBX released details regarding two vulnerabilities patched last week. One of these vulnerabilities was already actively exploited.
    https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf

    SANS Stormcast Friday, September 5th, 2025: Cloudflare Response to 1.1.1.1 Certificate; AI Modem Namespace Reuse; macOS Vulnerability Allowed Keychain Decryption Sep 05, 2025
    Show notes
    Unauthorized Issuance of Certificate for 1.1.1.1
    Cloudflare published a blog post with more details regarding the bad 1.1.1.1 certificate that was issued by Fina.
    https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/
    AI Model Namespace Reuse
    Deleted accounts on Huggingface can be taken over by other entities unrelated to the original owner.
    https://unit42.paloaltonetworks.com/model-namespace-reuse/
    macOS vulnerability allowed Keychain and iOS app decryption without a password
    Excessive entitlements for the gcore binary facilitated access to key material that was sufficient to access secrets stored in Apple s keychain.
    https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/

    SANS Stormcast Thursday, September 4th, 2025: Dassault DELMIA Apriso Exploit Attempts; Android Updates; 1.1.1.1 Certificate Issued Sep 04, 2025
    Show notes
    Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086
    Our honeypots detected attacks against the manufacturing management system DELMIA Apriso. The deserialization vulnerability was patched in June and is one of a few critical vulnerabilities patched in recent months.
    https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256
    Android Bulletin
    Google released its September update, fixing two already-exploited privilege escalation flaws and some remote code execution issues.
    https://source.android.com/docs/security/bulletin/2025-09-01
    Mis-issued Certificates for SAN iPAddress:1.1.1.1 by Fina RDC 2020
    Certificate authority Fina RDC issues a certificate for Cloudflare s IP address 1.1.1.1
    https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc

    Previous 1 24 25 26 27 28 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights