TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Wednesday, September 3rd, 2025: Sextortiion Analysis; Covert Channel DNS/ICMP; Azure AD Secret Theft; Official FreePBX Patches Sep 03, 2025
    Show notes
    A Quick Look at Sextortion at Scale
    Jan analyzed 1900 different sextortion messages using 205 different Bitcoin addresses to look at the success rate, lifetime, and other metrics defining these campaigns.
    https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252
    Azure AD Client Secret Leak
    Attackers are stealing Azure AD client secrets from websites that are leaving them exposed.
    https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud
    Covert Channel via ICMP and DNS
    A new bot combines ICMP and DNS in new ways for covert communication. The DNS requests use domains with a fixed prefix followed by a base64 encoded command, and the ICMP echo request packets include commands as a payload.
    https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/
    Official Release of Critical FreePBX Patch
    Sangoma has announced that the experimental patch released for the exploited FreePBX vulnerability is now considered stable, and users should update to apply it.
    https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203

    SANS Stormcast Tuesday, September 2nd, 2025: pdf-parser Patch; Salesloft Compromise; Velociraptor Abuse; NeuVector Default Password Sep 02, 2025
    Show notes
    pdf-parser: All Streams
    Didier released a new version of pdf-parser.py. This version fixes a problem with dumping all filtered streams.
    https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248
    Salesloft Drift Putting OAuth Tokens at Risk
    OAuth tokens used by Salesloft Drift users to provide access to integrations with Salesforce, Google Workspace, and others have been compromised and heavily abused for additional compromise and large-scale data exfiltration from exposed services.
    https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift
    Velociraptor incident response tool abused for remote access
    Attackers are using the open source incident response tool Velociraptor to access remote systems in breached networks. Tools like Velocitraptor are ideal for attackers to perform lateral movement.
    https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/
    Default Password in NeuVector (Rancher Desktop)
    SuSE fixed a default password vulnerability in NeuVector, a security tool included in Rancher Desktop.
    https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56

    SANS Stormcast Friday, August 29th, 2025: Scans for ZIP Files; FreePBX 0-Day; Passwordstate Patch Aug 29, 2025
    Show notes
    Increasing Searches for ZIP Files
    Attackers are scanning our honeypots more and more for .zip files. They are looking for backups of credential files and the like left behind by careless administrators and developers.
    https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242
    FreePBX Vulnerability
    An upatched vulnerability in FreePBX is currently being exploited. FreePBX offers mitigation advice and has also just released a beta patch.
    https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203
    Passwordstate Vulnerability
    Clickstudios patched an authentication bypass vulnerability in its password manager, Passwordstate. The vulnerability can be used to access the emergency password page.
    https://www.clickstudios.com.au/passwordstate-changelog.aspx

    SANS Stormcast Thursday, August 28th, 2025: Launching Shellcode; NX Compromise; Volt Typhoon Report Aug 28, 2025
    Show notes
    Interesting Technique to Launch a Shellcode
    Xavier came across malware that PowerShell and the CallWindowProcA() API to launch code.
    https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238
    NX Compromised to Steal Wallets and Credentials
    The popular open source NX build package was compromised. Code was added that uses the help of AI tools like Claude and Gemini to steal credentials from affected systems
    https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/
    Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed the Global Espionage System
    Several law enforcement and cybersecurity agencies worldwide collaborated to release a detailed report on the recent Volt Typhoon incident.
    https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a

    SANS Stormcast Wednesday, August 27th, 2025: Analyzing IDNs; Netscaler 0-Day Vuln; Git Vuln Exploited; Aug 27, 2025
    Show notes
    Getting a Better Handle on International Domain Names and Punycode
    International Domain names can be used for phishing and other attacks. One way to identify suspect names is to look for mixed script use.
    https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234
    Citrix Netscaler Vulnerabilities CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424
    Citrix patched three vulnerabilities in Netscaler. One is already being exploited
    https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424
    git vulnerability exploited (CVE-2025-48384)
    A git vulnerability patched in early July is now being exploited
    https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9

    SANS Stormcast Tuesday, August 26th, 2025: Decoding Word Reading Location; Image Downscaling AI Vulnerability; IBM Jazz Team Server Vuln Aug 26, 2025
    Show notes
    Reading Location Position Value in Microsoft Word Documents
    Jessy investigated how Word documents store the last visited document location in the registry.
    https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224
    Weaponizing image scaling against production AI systems
    AI systems often downscale images before processing them. An attacker can create a harmless looking image that would reveal text after downscaling leading to prompt injection
    https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/
    IBM Jazz Team Server Vulnerability CVE-2025-36157
    IBM patched a critical vulnerability in its Jazz Team Server
    https://www.ibm.com/support/pages/node/7242925

    SANS Stormcast Monday, August 25th, 2025: IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions Aug 25, 2025
    Show notes
    The end of an era: Properly formatted IP addresses in all of our data.
    When initiall designing DShield, addresses were zero padded , an unfortunate choice. As of this week, datafeeds should no longer be zero padded .
    https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228
    .desktop files used in an attack against Linux Desktops
    Pakistani attackers are using .desktop files to target Indian Linux desktops.
    https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/
    Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
    A go module advertising its ability to quickly brute force passwords against random IP addresses, has been used to exfiltrate credentials from the person running the module.
    https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials
    Limiting Onmicrosoft Domain Usage for Sending Emails
    Microsoft is limiting how many emails can be sent by Microsoft 365 users using the onmicrosoft.com domain.
    https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167

    SANS Stormcast Friday, August 22nd, 2025: The -n switch; Commvault Exploit; Docker Desktop Escape Vuln; Aug 22, 2025
    Show notes
    Don't Forget The "-n" Command Line Switch
    Disabling reverse DNS lookups for IP addresses is important not just for performance, but also for opsec. Xavier is explaining some of the risks.
    https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220
    watchTowr releases details about recent Commvault flaws
    Users of the Commvault enterprise backup solution must patch now after watchTowr released details about recent vulnerabilities
    https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123
    Docker Desktop Vulnerability CVE-2025-9074
    A vulnerability in Docker Desktop allows attackers to escape from containers to attack the host.
    https://docs.docker.com/desktop/release-notes/#4443

    SANS Stormcast Thursday, August 21st, 2025: Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking Aug 21, 2025
    Show notes
    Airtel Router Scans and Mislabeled Usernames
    A quick summary of some odd usernames that show up in our honeypot logs
    https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216
    Apple Patches 0-Day CVE-2025-43300
    Apple released an update for iOS, iPadOS and MacOS today patching a single, already exploited, vulnerability in ImageIO.
    https://support.apple.com/en-us/124925
    Microsoft Copilot Audit Logs
    A user retrieving data via copilot obscures the fact that the user may have had access to data in a specific file
    https://pistachioapp.com/blog/copilot-broke-your-audit-log
    Password Managers Susceptible to Clickjacking
    Many password managers are susceptible to clickjacking, and only few have fixed the problem so far
    https://marektoth.com/blog/dom-based-extension-clickjacking/

    SANS Stormcast Wednesday, August 20th, 2025: Increased Elasticsearch Scans; MSFT Patch Issues Aug 20, 2025
    Show notes
    Increased Elasticsearch Recognizance Scans
    Our honeypots noted an increase in reconnaissance scans for Elasticsearch. In particular, the endpoint /_cluster/settings is hit hard.
    https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212
    Microsoft Patch Tuesday Issues
    Microsoft noted some issues deploying the most recent patches with WSUS. There are also issues with certain SSDs if larger files are transferred.
    https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc
    https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot
    SAP Vulnerabilities Exploited CVE-2025-31324, CVE-2025-42999
    Details explaining how to take advantage of two SAP vulnerabilities were made public
    https://onapsis.com/blog/new-exploit-for-cve-2025-31324/

    Previous 1 25 26 27 28 29 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights