TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Monday Mar 24th: Critical Next.js Vulnerability; Microsoft Trust Signing Platform Abuse Mar 24, 2025
    Show notes
    Critical Next.js Vulnerability CVE-2025-29927
    A critical vulnerability in how the x-middleware-subrequest header is verified may lead to bypassing authorization in Next.js applications.
    https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware
    https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw
    https://www.runzero.com/blog/next-js/
    Microsoft Trust Signing Service Abused
    Attackers abut the Microsoft Trust Signing Service, a service meant to help developers create signed software, to obtain short lived signatures for malware.
    https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/

    SANS Stormcast Friday Mar 21st: New Data Feeds; SEO Spam; Veeam Deserialization; IBM AIX RCE; Mar 21, 2025
    Show notes
    Some New Data Feeds and Little Incident
    We started offering additional data feeds, and an SEO spamer attempted to make us change a link from an old podcast episode.
    https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786
    Veeam Deserialization Vulnerability
    Veeam released details regarding the latest vulnerablity in Veeam, pointing out the insufficient patch applied to a prior deserialization vulnerability.
    https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/
    IBM AIX Vulnerablity
    The AIX NIM service is vulnerable to an unauthenticated remote code execution vulnerability
    https://www.ibm.com/support/pages/node/7186621
    thanks Chris Mosby for Spotify comment

    SANS Stormcast Thursday Mar 20th: Cisco Smart Licensing Attacks; Vulnerable Drivers again; Synology Advisories Updated Mar 20, 2025
    Show notes
    Exploit Attempts for Cisco Smart Licensing Utility CVE-2024-20439 CVE-2024-20440
    Attackers added last September's Cisco Smart Licensing Utility vulnerability to their toolset. These attacks orginate most likely from botnets and the same attackers are scanning for a wide range of additional vulnerabilities. The vulnerability is a static credential issue and trivial to exploit after the credentials were published last fall.
    https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782
    Legacy Driver Exploitation Through Bypassing Certificate Verification
    Ahnlab documented a new type of "bring your own vulnerable driver" vulnerability. In this case, an old driver used by an anit-malware and anti-rootkit system can be used to shut down arbitrary processeses, including security related processeses.
    https://asec.ahnlab.com/en/86881/
    Synology Vulnerability Updates
    Synology updates some security advisories it release last year adding addition details and vulnerable systems.
    https://www.synology.com/en-global/security/advisory/Synology_SA_24_20
    https://www.synology.com/en-global/security/advisory/Synology_SA_24_24

    SANS Stormcast Wednesday Mar 19th 2025: Python DLL Side Loading; Tomcast RCE Correction; SAML Roulette; Windows Shortcut 0-Day Mar 19, 2025
    Show notes
    Python Bot Delivered Through DLL Side-Loading
    A "normal", but vulnerable to DLL side-loading PDF reader may be used to launch additional exploit code
    https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778
    Tomcat RCE Correction
    To exploit the Tomcat RCE I mentioned yesterday, two non-default configuration options must be selected by the victim.
    https://x.com/dkx02668274/status/1901893656316969308
    SAML Roulette: The Hacker Always Wins
    This Portswigger blog explains in detail how to exploit the ruby-saml vulnerablity against GitLab.
    https://portswigger.net/research/saml-roulette-the-hacker-always-wins
    Windows Shortcut Zero Day Exploit
    Attackers are currently taking advantage of an unpatched vulnerability in how Windows displays Shortcut (.lnk file) details. Trendmicro explains how the attack works and provides PoC code. Microsoft is not planning to fix this issue
    https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html

    SANS Stormcast Tuesday Mar 18th 2025: Analyzing GUID Encoded Shellcode; Node.js SAML Vuln; Tomcat RCE in the Wild; CSS e-mail obfuscation Mar 18, 2025
    Show notes
    Static Analysis of GUID Encoded Shellcode
    Didier explains how to decode shell code embeded as GUIDs in malware, and how to feed the result to his tool 1768.py which will extract Cobal Strike configuration information from the code.
    https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774
    SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries
    xml-crypto, a library use in Node.js applications to decode XML and support SAML, has found to parse comments incorrectly leading to several SAML vulnerabilities.
    https://workos.com/blog/samlstorm
    One PUT Request to Own Tomcat: CVE-2025-24813 RCE is in the Wild
    A just made public deserialization vulnerablity in Tomcat is already being exploited. Contributing to the rapid exploit release is the similarity of this vulnerability to other Java deserializtion vulnerabilities.
    https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/ CVE-2025-24813
    CSS Abuse for Evasion and Tracking
    Attackers are using cascading stylesheets to evade detection and enable more stealthy tracking of users
    https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/

    SANS Stormcast Monday March 17th: Mirai Makes Mistakes; Compromised Github Action; ruby-saml vulnerability; Fake GitHub Security Alert Phishing Mar 17, 2025
    Show notes
    Mirai Bot Now Incorporating Malformed DrayTek Vigor Router Exploits
    One of the many versions of the Mirai botnet added some new exploit strings attempting to take advantage of an old DrayTek Vigor Router vulnerability, but they got the URL wrong.
    https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770
    Compromised GitHub Action
    The popular GitHub action tj-actions/changed-files was compromised and leaks credentials via the action logs
    https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
    ruby-saml authentication bypass
    A confusion in how to parse SAML messages between two XML parsers used by Ruby leads to an authentication bypass in saml-ruby.
    https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/
    GitHub Fake Security Alerts
    Fake GitHub security alerts are used to trick package maintainers into adding OAUTH privileges to malicious apps.
    https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/

    SANS Stormcast: File Hashes in MSFT BI; Apache Camel Vuln; Juniper Fixes Exploited Vuln; AMI Patches 10.0 Redfish BMC Vuln Mar 14, 2025
    Show notes
    File Hashes Analysis with Power BI
    Guy explains in this diary how to analyze Cowrie honeypot file hashes using Microsoft's BI tool and what you may be able to discover using this tool.
    https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764
    Apache Camel Vulnerability
    Apache released two patches for Camel in close succession. Initially, the vulnerability was only addressed for headers, but as Akamai discovered, it can also be exploited via query parameters. This vulnerability is trivial to exploit and leads to arbitrary code execution.
    https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations
    Juniper Patches Junos Vulnerability
    Juniper patches an already exploited vulnerability in JunOS. However, to exploit the vulnerability, and attacker already needs privileged access. By exploiting the vulnerability, an attacker may completely compromised the device.
    https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US
    AMI Security Advisory
    AMI patched three vulnerabilities. One of the, an authentication bypass in Redfish, allows for a complete system compromise without authentication and is rated with a CVSS score of 10.0.
    https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf

    SANS Stormcast Thursday Mar 13th: Exploiting Login Pages with Log4j; Patch Tuesday Fallout; Adobe Patches; Medusa Ransomware; Zoom and Font Library Updates; Mar 13, 2025
    Show notes
    Log4J Scans for VMWare Hyhbrid Cloud Extensions
    An attacker is scanning various login pages, including the authentication feature in the VMWare HCX REST API for Log4j vulnerabilities. The attack submits the exploit string as username, hoping to trigger the vulnerability as Log4j logs the username
    https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762
    Patch Tuesday Fallout
    Yesterday's Apple patch may re-activate Apple Intelligence for users who earlier disabled it. Microsoft is offering support for users whos USB printers started printing giberish after a January patch was applies.
    https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/
    https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update
    Adobe Updates
    Adobe updated seven different products, including Adobe Acrobat. The Acrobat vulnerability may lead to remote code execution and Adobe considers the vulnerablities critical.
    https://helpx.adobe.com/security/security-bulletin.html
    Medusa Ransomware
    CISA and partner agencies released details about the Medusa Ransomware. The document includes many details useful to defenders.
    https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
    Zoom Update
    Zoom released a critical update fixing a number of remote code execution vulnerabilities.
    https://www.zoom.com/en/trust/security-bulletin/
    FreeType Library Vulnerability
    https://www.facebook.com/security/advisories/cve-2025-27363

    SANS Stormcast Wednesday Mar 12th: Microsoft Patch Tuesday; Apple Patch; Espressif ESP32 Statement Mar 12, 2025
    Show notes
    Microsoft Patch Tuesday
    Microsoft Patched six already exploited vulnerabilities today. In addition, the patches included a critical patch for Microsoft's DNS server and about 50 additional patches.
    https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756
    Apple Updates iOS/macOS
    Apple released an update to address a single, already exploited, vulnerability in WebKit. This vulnerability affects iOS, macOS and VisionOS.
    https://support.apple.com/en-us/100100
    Expressif Response to ESP32 Debug Commands
    Expressif released a statement commenting on the recent release of a paper alledging "Backdoors" in ESP32 chipsets. According to Expressif, these commands are debug commands and not reachable directly via Bluetooth.
    https://www.espressif.com/en/news/Response_ESP32_Bluetooth

    SANS Stormcast Tuesday Mar 11th: Shellcode as UUIDs; Moxe Switch Vuln Updates; Opentext Vuln; Livewire Volt Vuln; Mar 11, 2025
    Show notes
    Shellcode Encoded in UUIDs
    Attackers are using UUIDs to encode Shellcode. The 128 Bit (or 16 Bytes) encoded in each UUID are converted to shell code to implement a cobalt strike beacon
    https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752
    Moxa CVE-2024-12297 Expanded to PT Switches
    Moxa in January first releast an update to address a fronted authorizaation logic disclosure vulnerability. It now updated the advisory and included the PT series switches as vulenrable.
    https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches
    Opentext Insufficently Protected Credentials
    https://portal.microfocus.com/s/article/KM000037455?language=en_US
    Livewire Volt API vulnerability
    https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv

    Previous 1 36 37 38 39 40 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights