TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast: Webshells; Undocumented ESP32 Commands; Camera Used For Ransomware Distribution Mar 10, 2025
    Show notes
    Commonly Probed Webshell URLs
    Many attackers deploy web shells to gain a foothold on vulnerable web servers. These webshells can also be taken over by parasitic exploits.
    https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748
    Undocumented ESP32 Commands
    A recent conference presentation by Tarlogic revealed several "backdoors" or undocumented features in the commonly used ESP32 Chipsets. Tarlogic also released a toolkit to make it easier to audit chipsets and find these hiddent commands.
    https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/
    Camera Off: Akira deploys ransomware via Webcam
    The Akira ransomware group was recently observed infecting a network with Ransomware by taking advantage of a webcam.
    https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam

    SANS Stormcast Friday Mar 7th: Chrome vs Extensions; Kibana Update; PrePw0n3d Android TV Sticks; Identifying APTs (@sans_edu, Eric LeBlanc) Mar 07, 2025
    Show notes
    Latest Google Chrome Update Encourages UBlock Origin Removal
    The latest update to Google Chrome not only disabled the UBlock Origin ad blocker, but also guides users to uninstall the extension instead of re-enabling it.
    https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html
    https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/
    Critical Kibana Update
    Elastic published a critical Kibana update patching a prototype polution vulnerability that would allow arbitrary code execution for users with the "Viewer" role.
    https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441
    Certified PrePw0n3d Android TV Sticks
    Wired is reporting of over a million Android TV sticks that were found to be pre-infected with adware
    https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/
    SANS.edu Research Paper
    Advanced Persistent Threats (APTs) are among the most challenging to detect in enterprise environments, often mimicking authorized privileged access prior to their actions on objectives.
    https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/

    SANS Stormcast Thursday Mar 6th: DShield ELK Analysis; Jailbreaking AMD CPUs; VIM Vulnerability; Snail Mail Ransomware Mar 06, 2025
    Show notes
    DShield Traffic Analysis using ELK
    The "DShield SIEM" includes an ELK dashboard as part of the Honeypot. Learn how to find traffic of interest with this tool.
    https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742
    Zen and the Art of Microcode Hacking
    Google released details, including a proof of concept exploit, showing how to take advantage of the recently patched AMD microcode vulnerability
    https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking CVE-2024-56161
    VIM Vulnerability
    An attacker may execute arbitrary code by tricking a user to open a crafted tar file in VIM
    https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3
    Snil Mail Fake Ransom Note
    A copy cat group is impersonating ransomware actors. The group sends snail mail to company executives claiming to have stolen company data and threatening to leak it unless a payment is made.
    https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/

    SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal Scams; VMWare Escape Fix Mar 05, 2025
    Show notes
    Romanian Distillery Scanning for SMTP Credentials
    A particular attacker expanded the scope of their leaked credential file scans. In addition to the usual ".env" style files, it is not looking for specific SMTP related credential files.
    https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736
    Tool Updates: mac-robber.py
    This update of mac-robber.py fixes issues with symlinks.
    https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738
    CVE-2025-1723 Account takeover vulnerability in ADSelfService Plus
    CVE-2025-1723 describes a vulnerability caused by session mishandling in ADSelfService Plus that could allow unauthorized access to user enrollment data when MFA was not enabled for ADSelfService Plus login.
    https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html
    Android March Update
    Google released an update for Android addressing two already exploited vulnerabilities and several critical issues.
    https://source.android.com/docs/security/bulletin/2025-03-01
    PayPal's no-code-checkout Abuse
    Attackers are using PayPal's no-code-checkout feature is being abused by scammers to host PayPal tech support scam pages right within the PayPal.com domain.
    https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers
    Broadcom Fixes three VMWare VCenter Vulnerabilities
    https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004

    SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit Mar 04, 2025
    Show notes
    Mark of the Web: Some Technical Details
    Windows implements the "Mark of the Web" (MotW) as an alternate data stream that contains not just the "zoneid" of where the file came from, but may include other data like the exact URL and referrer.
    https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732
    Havoc Sharepoint with Microsoft Graph API
    A recent phishing attack observed by Fortinet uses a simple HTML email to trick a user into copy pasting powershell into their system to execute additional code. Most of the malware interaction uses a Sharepoint site via Microsoft's Graph API futher hiding the malicious traffic
    https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2
    Paragon Partition Manager Exploit
    A vulnerable Paragon Partition Manager has been user recently to escalate privileges for ransomware deployment. Even if you to not have PAragon installed: An attacker may just "bring the vulnerable driver" to your system.
    https://kb.cert.org/vuls/id/726882

    SANS Stormcast Monday Mar 3rd: AI Training Data Leaks; MITRE Caldera Vuln; modsecurity bypass Mar 03, 2025
    Show notes
    Common Crawl includes Common Leaks
    The "Common Crawl" dataset, a large dataset created by spidering website, contains as expected many API keys and other secrets. This data is often used to train large language models
    https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data
    Github Repositories Exposed by Copilot
    As it is well known, Github's Copilot is using data from public GitHub repositories to train it's model. However, it appears that repositories who were briefly left open and later made private have been included as well, allowing Copilot users to retrieve files from these repositories.
    https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot
    MITRE Caldera Framework Allows Unauthenticated Code Execution
    The MITRE Caldera adversary emulation framework allows for unauthenticted code execution by allowing attackers to specify compiler options
    https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e
    modsecurity Rule Bypass
    Attackers may bypass the modsecurity web application firewall by prepending encoded characters with 0.
    https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j

    SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware Feb 28, 2025
    Show notes
    Njrat Compaign Using Microsoft dev Tunnels:
    A recent version of the Njrat remote admin tool is taking advantage of Microsoft's developer tunnels (devtunnels.ms) as a command and control channel.
    https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724
    NrootTag Apple FindMy Abuse
    Malware could use a weakness in the keys used for Apple FindMy to abuse it to track victims. Updates were released with iOS 18.2, but to solve the issue the vast majority of Apple users must update.
    https://nroottag.github.io/
    360XSS: Mass Website Exploitation via Virtual Tour Framework
    The Krpano VR library which is often used to implement 3D virtual tours on real estate websites, is currently being abused to inject spam messages. The XSS vulnerabilty could allow attackers to inject even more malicious JavaScript.
    https://olegzay.com/360xss/
    SANS.edu Research: Proof is in the Pudding: EDR Configuration Versus Ransomware. Benjamin Powell
    https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/

    SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln; Feb 27, 2025
    Show notes
    Attacker of of Ephemeral Ports
    Attackers often use ephermeral ports to reach out to download additional resources or exfiltrate data. This can be used, with care, to detect possible compromises.
    https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710
    Compromised Visal Studio Code Extension downloaded by Millions
    Amit Assaraf identified a likely compromised Visual Studio Code theme that was installed by millions of potential victims. Amit did not disclose the exact malicious behaviour, but is asking for victims to contact them for details.
    https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26
    ByBit Theft Due to Compromised Developer Workstation
    ByBit and Safe{Wallet} disclosed that the record breaking ethereum theft was due to a compromised Safe{Wallet} developer workstation. A replaced JavaScript file targeted ByBit and altered a transaction signed by ByBit.
    https://x.com/benbybit/status/1894768736084885929
    https://x.com/safe/status/1894768522720350673
    PoC for NAKIVO Backup Replication Vulnerability
    This vulnerability allows the compromise of NAKIVO backup systems. The vulnerability was patched silently in November, and never disclosed by NAKIVO. Instead, WatchTowr now disloses details including a proof of concept exploit.
    https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/
    OpenH264 Vulnerability
    https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x
    rsync vulnerability exploited
    https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps Feb 26, 2025
    Show notes
    Massive Botnet Targets M365 with Password Spraying
    A large botnet is targeting service accounts in M365 with credentials stolen by infostealer malware.
    https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf
    Mixing up Public and Private Keys in OpenID
    The complex OpenID specificiation and the flexibility it supports enables careless administrators to publich private keys instead or in addition to public keys
    https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html
    Healthcare Malware Hunt Part 1:
    Medial images are often encoded in the DICOM format, an image format unique to medical imaging. Patients looking for viewers for DICOM images are tricked into downloading malware.
    https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/

    SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln Feb 25, 2025
    Show notes
    Unfurl Update Released
    Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs.
    https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716
    Google Confirms GMail To Ditch SMS Code Authentication
    Google no longer considers SMS authentication save enough for GMail. Instead, it pushes users to use Passkeys, or QR code based app authentication
    https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/
    Beware of Paypal New Address Feature Abuse
    Attackers are using "address change" e-mails to send links to phishing sites or trick users into calling fake tech support phone numbers. Attackers are just adding the malicious content as part of the address. The e-mail themselves are legitimate PayPal emails and will pass various spam and phishing filters.
    https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/
    Exim SQL Injection Vulnerability
    Exim, with sqlite support and ETRN enabled, is vulnerable to a simple SQL injection exploit. A PoC has been released
    https://www.exim.org/static/doc/security/CVE-2025-26794.txt
    https://github.com/OscarBataille/CVE-2025-26794?
    XMLlib patches
    https://gitlab.gnome.org/GNOME/libxml2/-/issues/847
    https://gitlab.gnome.org/GNOME/libxml2/-/issues/828
    0-Day in Parallels
    https://jhftss.github.io/Parallels-0-day/

    Previous 1 37 38 39 40 41 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights