TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Monday, April 21st: MSFT Entra Lockouts; Erlang/OTP SSH Exploit; Sonicwall Exploit; bubble.io bug Apr 21, 2025
    Show notes
    Microsoft Entra User Lockout
    Multiple organizations reported widespread alerts and account lockouts this weekend from Microsoft Entra. The issue is caused by a new feature Microsoft enabled. This feature will lock accounts if Microsoft believes that the password for the account was compromised.
    https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/
    https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability
    Erlang/OTP SSH Exploit
    An exploit was published for the Erlang/OTP SSH vulnerability. The vulnerability is easy to exploit, and the exploit and a Metasploit module allow for easy remote code execution.
    https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb
    Sonicwall Exploited
    An older command injection vulnerability is now exploited on Sonicwall devices after initially gaining access by brute-forcing credentials.
    https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022
    Unpatched Vulnerability in Bubble.io
    An unpatched vulnerability in the no-code platform bubble.io can be used to access any project hosted on the site.
    https://github.com/demon-i386/pop_n_bubble

    SANS Stormcast Friday, April 18th: Remnux Cloud Environment; Erlang/OTP SSH Vuln; Brickstorm Backdoor Analysis; GPT 4.1 Safety Controversy Apr 18, 2025
    Show notes
    RedTail: Remnux and Malware Management
    A description showing how to set up a malware analysis in the cloud with Remnux and Kasm. RedTail is a sample to illustrate how the environment can be used.
    https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868
    Critical Erlang/OTP SSH Vulnerability
    Researchers identified a critical vulnerability in the Erlang/OTP SSH library. Due to this vulnerability, SSH servers written in Erlang/OTP allow arbitrary remote code execution without prior authentication
    https://www.openwall.com/lists/oss-security/2025/04/16/2
    Brickstorm Analysis
    An analysis of a recent instance of the Brickstorm backdoor. This backdoor used to be more known for infecting Linux systems, but now it also infects Windows.
    https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor
    https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf
    OpenAI GPT 4.1 Controversy
    OpenAI released its latest model, GPT 4.1, without a safety report and guardrails to prevent malware creation.
    https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report

    SANS Stormcast Thursday April 17th: Apple Updates; Oracle Updates; Google Chrome Updates; CVE News; Apr 17, 2025
    Show notes
    Apple Updates
    Apple released updates for iOS, iPadOS, macOS, and VisionOS. The updates fix two vulnerabilities which had already been exploited against iOS.
    https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866
    Oracle Updates
    Oracle released it quarterly critical patch update. The update addresses 378 security vulnerabilities. Many of the critical updates are already known vulnerabilities in open-source software like Apache and Nginx ingress.
    https://www.oracle.com/security-alerts/cpuapr2025.html
    Oracle Breach Guidance
    CISA released guidance for users affected by the recent Oracle cloud breach. The guidance focuses on the likely loss of passwords.
    https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise
    Google Chrome Update
    A Google Chrome update released today fixes two security vulnerabilities. One of the vulnerabilities is rated as critical.
    https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html
    CVE Updates
    CISA extended MITRE s funding to operate the CVE numbering scheme. However, a number of other organizations announced that they may start alternative vulnerability registers.
    https://euvd.enisa.europa.eu/
    https://gcve.eu/
    https://www.thecvefoundation.org/

    SANS Stormcast Wednesday Apr 16th: File Upload Service Abuse; OpenSSH 10.0 Released; Apache Roller Vuln; Possible CVE Changes Apr 16, 2025
    Show notes
    Online Services Again Abused to Exfiltrate Data
    Attackers like to abuse free online services that can be used to exfiltrate data. From the originals , like pastebin,
    to past favorites like anonfiles.com. The latest example is gofile.io. As a defender, it is important to track these services to detect exfiltration early
    https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862
    OpenSSH 10.0 Released
    OpenSSH 10.0 was released. This release adds quantum-safe ciphers and the separation of authentication services into a separate binary to reduce the authentication attack surface.
    https://www.openssh.com/releasenotes.html#10.0p1
    Apache Roller Vulnerability
    Apache Roller addressed a vulnerability. Its CVSS score of 10.0 appears inflated, but it is still a vulnerability you probably want to address.
    https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f
    CVE Funding Changes
    Mitre s government contract to operate the CVE system may run out tomorrow. This could lead to a temporary disruption of services, but the system is backed by a diverse board of directors representing many large companies. It is possible that non-government funding sources may keep the system afloat for now.
    https://www.cve.org/

    SANS Stormcast Tuesday April 15th: xorsearch Update; Short Lived Certificates; New USB Malware Apr 15, 2025
    Show notes
    xorsearch Update
    Diedier updated his "xorsearch" tool. It is now a python script, not a compiled binary, and supports Yara signatures. With Yara support also comes support for regular expressions.
    https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854
    Shorter Lived Certificates
    The CA/Brower Forum passed an update to reduce the maximum livetime of
    certificates. The reduction will be implemented over the next four years. EFF also released an update to certbot introducing profiles that can be used to request shorter lived certificates.
    https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs
    https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI
    New Malware Harvesting Data from USB drives and infecting them.
    Kaspersky is reporting that they identified new malware that not only harvests data from USB drives, but also spread via USB drives by replacing existing documents with malicious files.
    https://securelist.com/goffee-apt-new-attacks/116139/

    SANS Stormcast Monday April 14th: Langlow AI Attacks; Fortinet Attack Cleanup; MSFT Inetpub; Apr 14, 2025
    Show notes
    Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248)
    After spotting individaul attempts to exploit the recent Langflow vulnerability late last weeks, we now see more systematic internet wide scans attempting to verify the vulnerability.
    https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/
    Fortinet Analysis of Threat Actor Activity
    Fortinet oberved recent vulnerablities in its devices being used to add a symlink to ease future compromise. The symlink is not removed by prior patches, and Fortinet released additional updates to detect and remove this attack artifact.
    https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity
    MSFT Inetpub
    Microsoft clarrified that its April patches created the inetpub directory on purpose. Users should not remove it.
    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability
    SANSFIRE
    https://isc.sans.edu/j/sansfire

    SANS Stormcast Friday April 11th: Network Infraxploit; Windows Hello Broken; Dell Update; Langflow Exploit Apr 11, 2025
    Show notes
    Network Infraxploit
    Our undergraduate intern, Matthew Gorman, wrote up a walk through of
    CVE-2018-0171, an older Cisco vulnerability, that is still actively being
    exploited. For example, VOLT TYPHOON recently exploited this problem.
    https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844
    Windows Update Issues / Windows 10 Update
    Microsoft updated its "Release Health" notes with details regarding issues
    users experiences with Windows Hello, Citrix, and Roblox. Microsoft also released an emergency update for Office 2016 which has stability problems after applying the most recent update.
    https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb
    https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521
    https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5
    Dell Updates
    Dell releases critical updates for it's Powerscale One FS product. In particular, it fixes a default password problem.
    https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities
    Langflow Vulnerablity (possible exploit scans sighted) CVE-2025-3248
    Langflow addressed a critical vulnerability end of March. This writeup by Horizon3 demonstrates how the issue is possibly exploited. We have so far seen one "hit" in our honeypot logs for the vulnerable API endpoint URL.
    https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/

    SANS Stormcast ThursdayApril 10th: Getting Past PyArmor; CenterStack RCE; Android 0-Day Patch; VMware Tanzu Patches; Odd Win11 Directory; WhatsApp File Confusion; SANS AI Guide; Apr 10, 2025
    Show notes
    Getting Past PyArmor
    PyArmor is a python obfuscation tool used for malicious and non-malicious software. Xavier is taking a look at a sample to show what can be learned from these obfuscated samples with not too much work.
    https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840
    CenterStack RCE CVE-2025-30406
    Gladinet s CenterStack secure file-sharing software suffers from an inadequately protected machine key vulnerability that can be used to modify ViewState data. This vulnerability may lead to remote code execution, which is already exploited.
    https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf
    Google Patches two zero-day vulnerabilities CVE-2024-53150 CVE-2024-53197
    Google released its monthly patches for Android. Two of the patched vulnerabilities are already exploited. One of them was used by Serbian law enforcement.
    https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android
    Broadcom VMWare Tenzu Updates
    Broadcom released updates for VMWare Tenzu. Many vulnerabilities affect the backup component and allow for arbitrary command execution.
    https://support.broadcom.com/web/ecx/security-advisory?
    Windows 11 April Update ads inetpub directory
    The April Windows 11 update appears to create a new /inetpub directory. It is unclear why, and removing it appears to have no bad effects.
    https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/
    WhatsApp File Type Confusion/Spoofing
    WhatsApp patched a file type confusion vulnerability. A victim may be tricked into downloading n
    https://www.whatsapp.com/security/advisories/2025/
    SANS Critical AI Security Guidelines
    https://www.sans.org/mlp/critical-ai-security-guidelines

    SANS Stormcast Wednesday, April 10th: Microsoft Patch Tuesday; Adobe Patches; OpenSSL 3.5 with PQC; Fortinet Apr 09, 2025
    Show notes
    Microsoft Patch Tuesday
    Microsoft patched over 120 vulnerabilities this month. 11 of these were rated critical, and one vulnerability is already being exploited.
    https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838
    Adobe Updates
    Adobe released patches for 12 different products. In particular important are patches for Coldfusion addressing several remote code execution vulnerabilities. Adobe Commercse got patches as well, but none of the vulnerabilities are rated critical.
    https://helpx.adobe.com/security/security-bulletin.html
    OpenSSL 3.5 Released
    OpenSSL 3.5 was released with support to post quantum ciphers. This is a long term support release.
    https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA
    Fortiswitch Update
    Fortinet released an update for Fortiswitch addressing a vulnerability that may be used to reset a password without verification.
    https://fortiguard.fortinet.com/psirt/FG-IR-24-435

    SANS Stormcast Tuesday, April 8th: Apr 08, 2025
    Show notes
    XORsearch: Searching With Regexes
    Didier explains a workaround to use his tool XORsearch to search for regular expressions instead of simple strings.
    https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834
    MCP Security Notification: Tool Poisoning Attacks
    Invariant labs summarized a critical weakness in the Model Context Protocol (MCP) that allows for "Tool Poisoning Attacks." Many major providers such as Anthropic and OpenAI, workflow automation systems like Zapier, and MCP clients like Cursor are susceptible to this attack
    https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
    Making :visited more private
    Google Chrome changed how links are marked as visited . This new partitioning scheme was introduced to improve privacy. Instead of marking a link as visited on any page where it is displayed, it is only marked as visited if the user clicks on the link while visiting the particular site where the link is displayed.
    https://developer.chrome.com/blog/visited-links

    Previous 1 34 35 36 37 38 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights