TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Tuesday, June 3rd, 2025: Windows SSH C2; Google Removes CAs from trusted list; MSFT issues Emergency Patch to fix Crash issue; Qualcom Adreno GPU 0-day Jun 03, 2025
    Show notes
    Simple SSH Backdoor
    Xavier came across a simple SSH backdoor taking advantage of the ssh client preinstalled on recent Windows systems. The backdoor is implemented via an SSH configuration file that instructs the SSH client to connect to a remote system and forward a shell on a random port. This will make the shell accessible to anybody able to connect to the C2 host.
    https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000
    Google Chrome to Distrust CAs
    Google Chrome will remove the Chunghwa Telecom and Netlock certificate authorities from its list of trusted CAs. Any certificates issued after July 31st will not be trusted. Certificates issued before the deadline will be trusted until they expire.
    https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html
    Microsoft Emergency Update to Fix Crashes Caused by May Patch
    Microsoft released an emergency update for a bug caused by one of the patches released in May. Due to the bug, systems may not restart after the patch is applied. This affects, first of all, virtual systems running in Azure and HyperV but apparently has also affected some physical systems.
    https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys
    Qualcomm Adreno Graphics Processing Unit Patch (Exploited!)
    Qualcomm released an update for the driver for its Adreno GPU. The patched vulnerability is already being exploited against Android devices.
    https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html

    SANS Stormcast Monday, June 2nd, 2025: PNG with RAT; Cisco IOS XE WLC Exploit; vBulletin Exploit Jun 02, 2025
    Show notes
    A PNG Image With an Embedded Gift
    Xavier shows how Python code attached to a PNG image can be used to implement a command and control channel or a complete remote admin kit.
    https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998
    Cisco IOS XE WLC Arbitrary File Upload Vulnerability (CVE-2025-20188) Analysis
    Horizon3 analyzed a recently patched flaw in Cisco Wireless Controllers. This arbitrary file upload flaw can easily be used to execute arbitrary code.
    https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/
    Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE
    A change in PHP 8.1 can expose methods previously expected to be safe . vBulletin fixed a related flaw about a year ago without explicitly highlighting the security impact of the fix. A blog post now exposed the flaw and provided exploit examples. We have seen exploit attempts against honeypots starting May 25th, two days after the blog was published.
    https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce

    SANS Stormcast Friday, May 30th 2025: Alternate Data Streams; Connectwise Breach; Google Calendar C2; May 30, 2025
    Show notes
    Alternate Data Streams: Adversary Defense Evasion and Detection
    Good Primer of alternate data streams and how they are abused, as well as how to detect and defend against ADS abuse.
    https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990
    Connectwise Breach Affects ScreenConnect Customers
    Connectwise s ScreenConnect solution was compromised, leading to attacks against a small number of customers. This is yet another example of how attackers are taking advantage of remote access solutions.
    https://www.connectwise.com/company/trust/advisories
    Mark Your Calendar: APT41 Innovative Tactics
    Google detected attacks leveraging Google s calendar solution as a command and control channel.
    https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics
    Webs of Deception: Using the SANS ICS Kill Chain to Flip the Advantage to the Defender
    Defending a small Industrial Control System (ICS) against sophisticated threats can seem futile. The resource disparity between small ICS defenders and sophisticated attackers poses a significant security challenge.
    https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/

    SANS Stormcast Thursday May 29th 2025: LLM Assisted Analysis; MSP Ransomware; Everetz Vulnerability May 29, 2025
    Show notes
    Exploring a Use Case of Artificial Intelligence Assistance with Understanding an Attack
    Jennifer Wilson took a weird string found in a recent honeypot sample and worked with ChatGPT to figure out what it is all about.
    https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980
    Ransomware Deployed via SimpleHelp Vulnerabilities
    Ransomware actors are using vulnerabilities in SimpleHelp to gain access to victim s networks via MSPs. The exploited vulnerabilities were patched in January.
    https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/
    OS Command Injection in Everetz Equipment
    Broadcast equipment manufactured by Everetz is susceptible to an OS command injection vulnerability. Everetz has not responded to researchers reporting the vulnerability so far and there is no patch available.
    https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009

    SANS Stormcast Wednesday May 28th 2025: Securing authorized_keys; ADAuditPlus SQL Injection; Dero Miner vs Docker API May 28, 2025
    Show notes
    SSH authorized_keys File
    One of the most common techniques used by many bots is to add rogue keys to the authorized_keys file, implementing an SSH backdoor. Managing these files and detecting unauthorized changes is not hard and should be done if you operate Unix systems.
    https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986
    REMOTE COMMAND EXECUTION ON SMARTBEDDED METEOBRIDGE (CVE-2025-4008)
    Weatherstation software Meteobridge suffers from an easily exploitable unauthenticated remote code execution vulnerability
    https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008
    https://forum.meteohub.de/viewtopic.php?t=18687
    Manageengine ADAuditPlus SQL Injection
    Zoho patched two SQL Injection vulnerabilities in its ManageEngine ADAuditPlus product
    https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html
    https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html
    Dero Miner Infects Containers through Docker API
    Kaspersky found yet another botnet infecting docker containers to spread crypto coin miners. The initial access happens via exposed docker APIs.
    https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/

    SANS Stormcast Tuesday, May 27th 2025: SVG Steganography; Fortinet PoC; GitLab Duo Prompt Injection May 27, 2025
    Show notes
    SVG Steganography
    Steganography is not only limited to pixel-based images but can be used to embed messages into vector-based formats like SVG.
    https://isc.sans.edu/diary/SVG%20Steganography/31978
    Fortinet Vulnerability Details CVE-2025-32756
    Horizon3.ai shows how it was able to find the vulnerability in Fortinet s products, and how to possibly exploit this issue. The vulnerability is already being exploited in the wild and was patched May 13th
    https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/
    Remote Prompt Injection in GitLab Duo Leads to Source Code Theft
    An attacker may leave instructions (prompts) for GitLab Duo embedded in the source code. This could be used to exfiltrate source code and secrets or to inject malicious code into an application.
    https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo

    SANS Stormcast Friday, May 23rd 2025: Backup Connectivity; Windows 2025 dMSA Abuse; Samlify Vulnerability May 23, 2025
    Show notes
    Resilient Secure Backup Connectivity for SMB/Home Users
    Establishing resilient access to a home network via a second ISP may lead to unintended backdoors. Secure the access and make sure you have the visibility needed to detect abuse.
    https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972
    BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
    An attacker with the ability to create service accounts may be able to manipulate these accounts to mark them as migrated accounts, inheriting all privileges the original account had access to.
    https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory
    Flaw in samlify That Opens Door to SAML Single Sign-On Bypass CVE-2025-47949
    The samlify Node.js library does not verify SAML assertions correctly. It will consider the entire assertion valid, not just the original one. An attacker may use this to obtain additional privileges or authenticate as a different user
    https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass

    SANS Stormcast Thursday, May 22nd 2025: Crypto Confidence Scams; Extension Mayhem for VS Code and Chrome May 22, 2025
    Show notes
    New Variant of Crypto Confidence Scam
    Scammers are offering login credentials for what appears to be high value crypto coin accounts. However, the goal is to trick users into paying for expensive VIP memberships to withdraw the money.
    https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968
    Malicious Chrome Extensions
    Malicious Chrome extensions mimick popular services like VPNs to trick users into installing them. Once installed, the extensions will exfiltrate browser secrets
    https://dti.domaintools.com/dual-function-malware-chrome-extensions/
    Malicious VS Code Extensions
    Malicious Visual Studio Code extensions target crypto developers to trick them into installing them to exfiltrate developer secrets.
    https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise

    SANS Stormcast Wednesday, May 21st 2025: Researchers Scanning the Internet; Forgotten DNS Records; openpgp.js Vulneraiblity May 21, 2025
    Show notes
    Researchers Scanning the Internet
    A newish RFC, RFC 9511, suggests researchers identify themselves by adding strings to the traffic they send, or by operating web servers on machines from which the scan originates. We do offer lists of researchers and just added three new groups today
    https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964
    Cloudy with a change of Hijacking: Forgotten DNS Records
    Organizations do not always remove unused CNAME records. An attacker may take advantage of this if an attacker is able to take possession of the now unused public cloud resource the name pointed to.
    https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/
    Message signature verification can be spoofed CVE-2025-47934
    A vulnerability in openpgp.js may be used to spoof message signatures. openpgp.js is a popular library in systems implementing end-to-end encrypted browser applications.
    https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8

    SANS Stormcast Tuesday, May 20th 2025: AutoIT Code RAT; Fake Keepass Download; Procolored Printer Software Compromise May 20, 2025
    Show notes
    RAT Dropped By Two Layers of AutoIT Code
    Xavier explains how AutoIT was used to install a remote admin tool (RAT) and how to analyse such a tool
    https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960
    RVTools compromise confirmed
    Robware.net, the site behind the popular tool RVTools now confirmed that it was compromised. The site is currently offline.
    https://www.robware.net/readMore
    Trojaned Version of Keepass used to install info stealer and Cobalt Strike beacon
    A backdoored version of KeePass was used to trick victims into installing Cobalt Strike and other malware. In this case, Keepass itself was not compromised and the malicious version was advertised via search engine optimization tricks
    https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign
    Procolored UV Printer Software Compromised
    The official software offered by the makers of the Procolored UV printer has been compromised, and versions with malware were distributed for about half a year.
    https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3
    https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads

    Previous 1 31 32 33 34 35 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights