TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Tuesday, July 22nd, 2025: SharePoint Emergency Patches; How Long Does Patching Take; HPE Wifi Vuln; Zoho WorkDrive Abused Jul 22, 2025
    Show notes
    Microsoft Released Patches for SharePoint Vulnerability CVE-2025-53770 CVE-2025-53771
    Microsoft released a patch for the currently exploited SharePoint vulnerability. It also added a second CVE number identifying the authentication bypass vulnerability.
    https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
    How Quickly Are Systems Patched?
    Jan took Shodan data to check how quickly recent vulnerabilities were patched. The quick answer: Not fast enough.
    https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126
    HP Enterprise Instant On Access Points Vulnerability
    HPE patched two vulnerabilities in its Instant On access points (aka Aruba). One allows for authentication bypass, while the second one enables arbitrary code execution as admin.
    https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us
    Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy
    AppLocker sample policies suffer from a simple bug that may enable some rule bypass, but only if signatures are not enforced.
    While reviewing Microsoft s suggested configuration, Varonis Threat Labs noticed a subtle but important issue: the MaximumFileVersion field was set to 65355 instead of the expected 65535.
    https://www.varonis.com/blog/applocker-bypass-risks
    Ghost Crypt Malware Leverages Zoho WorkDrive
    The Ghost malware tricks users into downloading by sending links to Zoho WorkDrive locations.
    https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis

    SANS Stormcast Monday July 21st, 2025: Sharepoint Exploited; Veeam Fake Voicemail Phish; Passkey Phishing Attack Jul 21, 2025
    Show notes
    SharePoint Servers Exploited via 0-day CVE-2025-53770
    Late last week, CodeWhite found a new remote code execution exploit against SharePoint. This vulnerability is now actively exploited.
    https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/
    Veeam Voicemail Phishing
    Attackers appear to impersonate VEEAM in recent voicemail-themed phishing attempts.
    https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120
    Passkey Phishing Attack
    A currently active phishing attack takes advantage of the ability to use QR codes to complete the Passkey login procedure
    https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/

    SANS Stormcast Friday, July 18th, 2025: Extended File Attributes; Critical Cisco ISE Patch; VMWare Patches; Quarterly Oracle Patches Jul 18, 2025
    Show notes
    Hiding Payloads in Linux Extended File Attributes
    Xavier today looked at ways to hide payloads on Linux, similar to how alternate data streams are used on Windows. Turns out that extended file attributes do the trick, and he presents some scripts to either hide data or find hidden data.
    https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116
    Cisco Patches Critical Identity Services Engine Flaw CVE-2025-20281, CVE-2025-20337, CVE-2025-20282
    An unauthenticated user may execute arbitrary code as root across the network due to improperly validated data in Cisco s Identity Services Engine.
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6
    Oracle Critical Patch Update
    Oracle patched 309 flaws across 111 products. 9 of these vulnerabilities have a critical CVSS score of 9.0 or higher.
    https://www.oracle.com/security-alerts/cpujul2025.html
    Broadcom releases VMware Updates
    Broadcom fixed a number of vulnerabilities for ESXi, Workstation, Fusion, and Tools.
    https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877

    SANS Stormcast Thursday, July 17th, 2025: catbox.moe abuse; Sonicwall Attacks; Rendering Issues Jul 17, 2025
    Show notes
    More Free File Sharing Services Abuse
    The free file-sharing service catbox.moe is abused by malware. While it officially claims not to allow hosting of executables, it only checks extensions and is easily abused
    https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112
    Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor
    A group Google identifies as UNC6148 is exploiting the Sonicwall SMA 100 series appliance. The devices are end of life, but even fully patched devices are exploited. Google assumes that these devices are compromised because credentials were leaked during prior attacks. The attacker installs the OVERSTEP backdoor after compromising the device.
    https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor
    Weaponizing Trust in File Rendering Pipelines
    RenderShock is a comprehensive zero-click attack strategy that targets passive file preview, indexing, and automation behaviours in modern operating systems and enterprise environments. It leverages built-in trust mechanisms and background processing in file systems, email clients, antivirus tools, and graphical user interfaces to deliver payloads without requiring any user interaction.
    https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/

    SANS Stormcast Wednesday, July 16th, 2025: ADS Keystroke Logger; Fake Homebrew; Broadcom Altiris RCE; Malicious Cursor AI Extensions Jul 16, 2025
    Show notes
    Keylogger Data Stored in an ADS
    Xavier came across a keystroke logger that stores data in alternate data streams. The data includes keystroke logs as well as clipboard data
    https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108
    Malvertising Homebrew
    An attacker has been attempting to trick users into installing a malicious version of Homebrew. The fake software is advertised via paid Google ads and directs users to the attacker s GitHub repo.
    https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc
    CVE-2025-5333: Remote Code Execution in Broadcom Altiris IRM
    LRQA have discovered a critical unauthenticated remote code execution (RCE) vulnerability in the Broadcom Symantec Altiris Inventory Rule Management (IRM) component of Symantec Endpoint Management.
    https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/
    Code highlighting with Cursor AI for $500,000
    A syntax highlighting extension for Cursor AI was used to compromise a developer s workstation and steal $500,000 in cryptocurrency.
    https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/

    SANS Stormcast Monday, July 14th, 2025: Web Honeypot Log Volume; Browser Extension Malware; RDP Forensics Jul 15, 2025
    Show notes
    DShield Honeypot Log Volume Increase
    Within the last few months, there has been a dramatic increase in honeypot log volumes and how often these high volumes are seen. This has not just been from Jesse s residential honeypot, which has historically seen higher log volumes, but from all of the honeypots that Jesse runs.
    https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100
    Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware.
    Koi Security s investigation of a single verified color picker exposed a coordinated campaign of 18 malicious extensions that infected a massive 2.3 million users across Chrome and Edge.
    https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5
    RDP Forensics
    Comprehensive overview of Windows RDP Forensics
    https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec

    SANS Stormcast Monday, July 14th, 2025: Suspect Domain Feed; Wing FTP Exploited; FortiWeb Exploited; NVIDIA GPU Rowhammer Jul 14, 2025
    Show notes
    Experimental Suspicious Domain Feed
    Our new experimental suspicious domain feed uses various criteria to identify domains that may be used for phishing or other malicious purposes.
    https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102
    Wing FTP Server RCE Vulnerability Exploited CVE-2025-47812
    Huntress saw active exploitation of Wing FTP Server remote code execution (CVE-2025-47812) on a customer on July 1, 2025. Organizations running Wing FTP Server should update to the fixed version, version 7.4.4, as soon as possible.
    https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild
    https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/
    FortiWeb Pre-Auth RCE (CVE-2025-25257)
    An exploit for the FortiWeb RCE Vulnerability is now available and is being used in the wild.
    https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce
    NVIDIA Vulnerable to Rowhammer
    NVIDIA has received new research related to the industry-wide DRAM issue known as Rowhammer . The research demonstrates a potential Rowhammer attack against an NVIDIA A6000 GPU with GDDR6 Memory. The purpose of this notice is to reinforce already known mitigations to Rowhammer attacks.
    https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025

    SANS Stormcast Friday, July 11th, 2025: SSH Tunnel; FortiWeb SQL Injection; Ruckus Unpatched Vuln; Missing Motherboard Patches; Jul 11, 2025
    Show notes
    SSH Tunneling in Action: direct-tcp requests
    Attackers are compromising ssh servers to abuse them as relays. The attacker will configure port forwarding direct-tcp connections to forward traffic to a victim. In this particular case, the Yandex mail server was the primary victim of these attacks.
    https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094
    Fortiguard FortiWeb Unauthenticated SQL injection in GUI (CVE-2025-25257)
    An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
    https://www.fortiguard.com/psirt/FG-IR-25-151
    Ruckus Virtual SmartZone (vSZ) and Ruckus Network Director (RND) contain multiple vulnerabilities
    Ruckus products suffer from a number of critical vulnerabilities. There is no patch available, and users are advised to restrict access to the vulnerable admin interface.
    https://kb.cert.org/vuls/id/613753

    SANS Stormcast Thursday, July 10th, 2025: Internal CA with ACME; TapJacking on Android; Adobe Patches; Jul 10, 2025
    Show notes
    Setting up Your Own Certificate Authority for Development: Why and How.
    Some tips on setting up your own internal certificate authority using the smallstep CA.
    https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092
    Animation-Driven Tapjacking on Android
    Attackers can use a click-jacking like trick to trick victims into clicking on animated transparent dialogs opened from other applications.
    https://taptrap.click/usenix25_taptrap_paper.pdf
    Adobe Patches
    Adobe patched 13 different products yesterday. Most concerning are vulnerabilities in Coldfusion that include code execution and arbitrary file disclosure vulnerabilities.
    https://helpx.adobe.com/security/security-bulletin.html

    SANS Stormcast Wednesday, July 9th, 2025: Microsoft Patches; Opposum Attack; Jul 09, 2025
    Show notes
    Microsoft Patch Tuesday, July 2025
    Today, Microsoft released patches for 130 Microsoft vulnerabilities and 9 additional vulnerabilities not part of Microsoft's portfolio but distributed by Microsoft. 14 of these are rated critical. Only one of the vulnerabilities was disclosed before being patched, and none of the vulnerabilities have so far been exploited.
    https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088
    Opposum Attack
    If a TLS server is configured to allow switching from HTTP to HTTPS on a specific port, an attacker may be able to inject a request into the data stream.
    https://opossum-attack.com/
    Ivanti Security Updates
    Ivanty fixed vulnerabilities in Ivanty Connect Secure, EPMM, and EPM. In particular the password decryption vulnerabliity may be interesting.
    https://www.ivanti.com/blog/july-security-update-2025

    Previous 1 28 29 30 31 32 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights