TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns; Feb 24, 2025
    Show notes
    Tool Update: Sigs.py
    Jim updates sigs.py. The tool verifies hashes for files and automatically recognizes what hash is used.
    https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706
    Google Announcing Quantum Safe Digital Signatures in Cloud KMS
    Google announced the option to use quantum safe digital signatures for its
    cloud key management system.
    https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms
    Windows 11 Patch issues
    The February Patch Tuesday appears to have caused issues with a number of Windows 11 systems. In particular the usability of the file manager appears to be affected.
    https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/
    LTE/5G Vulnerabilities
    Researchers at the university of Florida have identified a large number of vulnerabilities in 5G and LTE networks.
    https://nathanielbennett.com/publications/ransacked.pdf

    SANS Stormcast Friday Feb 21st: Kibana Queries; Mongoose Injection; U-Boot Flaws; Unifi Protect Camera Vulnerabilities; Protecting Network Devices as Endpoint (Austin Clark @sans_edu) Feb 21, 2025
    Show notes
    Using ES|QL In Kibana to Query DShield Honeypot Logs
    Using the "Elastic Search Piped Query Language" to query DShield honeypot logs
    https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704
    Mongoose Flaws Put MongoDB at risk
    The Object Direct Mapping library Mongoose suffers from an injection vulnerability leading to the potenitial of remote code exeuction in MongoDB
    https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/
    U-Boot Vulnerabilities
    The open source boot loader U-Boot does suffer from a number of issues allowing the bypass of its integrity checks. This may lead to the execution of malicious code on boot.
    https://www.openwall.com/lists/oss-security/2025/02/17/2
    Unifi Protect Camera Update
    https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f

    SANS Stormcast Wednesday Feb 20th: XWorm Cocktail; Quantum Computing Breakthrough; Signal Phishing Feb 20, 2025
    Show notes
    XWorm Cocktail: A Mix of PE data with PowerShell Code
    Quick analysis of an interesting XWrom sample with powershell code embedded inside an executable
    https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700
    Microsoft's Majorana 1 Chip Carves New Path for Quantum Computing
    Microsoft announced a breack through in Quantum computing. Its new prototype Majorana 1 chip takes advantage of exotic majorana particles to implement a scalable low error rate solution to building quantum computers
    https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/
    Russia Targeting Signal Messenger
    Signal is well regarded as a secure end to end encrypted messaging platform. However, a user may be tricked into providing access to their account by scanning a QR code masquerading as a group channel invitation.
    https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/

    SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability Feb 19, 2025
    Show notes
    ModelScan: Protection Against Model Serialization Attacks
    ModelScan is a tool to inspect AI models for deserialization attacks. The tool will detect suspect commands and warn the user.
    https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692
    OpenSSH MitM and DoS Vulnerabilities
    OpenSSH Patched two vulnerabilities discovered by Qualys. One may be used for MitM attack in specfic configurations of OpenSSH.
    https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt
    Juniper Authentication Bypass
    Juniper fixed an authentication bypass vulnerability that affects several prodcuts. The patch was released outside the normal patch schedule.
    https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US
    DELL BIOS Patches
    DELL released BIOS updates fixing a privilege escalation issue. The update affects a large part of Dell's portfolio
    https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021

    SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch Feb 18, 2025
    Show notes
    My Very Personal Guidance and Strategies to Protect Network Edge Devices
    A quick summary to help you secure edge devices. This may be a bit opinionated, but these are the strategies that I find work and are actionable.
    https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660
    PostgreSQL SQL Injection
    A followup to yesterday's segment about the PostgreSQL vulnerability. Rapid7 released a Metasploit module to exploit the vulnerability.
    https://github.com/rapid7/metasploit-framework/pull/19877
    Ivanti Connect Secure Exploited
    The Japanese CERT observed exploitation of January's Connect Secure vulnerability
    https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html
    WinZip Vulnerability
    WinZip patched a buffer overflow vulenrability that may be triggered by malicious 7Z files
    https://www.zerodayinitiative.com/advisories/ZDI-25-047/
    Xerox Printer Patch
    Xerox patched two vulnerabililites in its enterprise multifunction printers that may be exploited for lateral movement.
    https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf

    SANS Stormcast Monday Feb 17th: Fake BSOD; Volatile IPs; Postgresql libpq SQL Injection; OAUTH Phishing Feb 17, 2025
    Show notes
    Fake BSOD Delivered by Malicious Python Script
    Xavier found an odd malicious Python script that displays a blue screen of
    death to users. The purpose isn't quite clear. It could be a teach support scam
    tricking users into calling the 800 number displayed, or a simple
    anti-reversing trick
    https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686
    The Danger of IP Volatility
    Accounting for IP addresses is important, and if not done properly, may
    lead to resources being exposed after IP addresses are released.
    https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688
    PostgreSQL SQL Injection
    Functions in PostgreSQL's libpq do not properly escape parameters which may
    lead to SQL injection issues if the functions are used to create input for pqsql.
    https://www.postgresql.org/support/security/CVE-2025-1094/
    Multiple Russian Threat Actors Targeting Microsoft Device Code Auth
    The OAUTH device code flow is used to attach devices with limited input capability to a user's account. However, this can be abused via phishing attacks.
    https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/

    SANS Stormcast Feb 14th 2025: DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhone vs. Cisco; Crowdstrike Patch Feb 14, 2025
    Show notes
    DShield SIEM Docker Updates
    Interested in learning more about the attacks hitting your honeypot?
    Guy assembled a neat SIEM to create dashboards summarizing the attacks.
    https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680
    PANOS Path Confusion Auth Bypass
    Palo Alto Networks fixed a path confusion vulnerability introduced by the
    overly complex midle box chain in PANOS.
    https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/
    https://www.theregister.com/2025/02/13/palo_alto_firewall/
    China's Volt Typhoon Continues to use Cisco Vulns
    Recorded Future wrote up some recent attacks of the Red Mike / Volt Typhoon groups going after telecom providers by compromissing Cisco systems via an older vulnerabilty
    https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/
    Crowdstrike Patches Linux Client
    https://www.crowdstrike.com/security-advisories/cve-2025-1146/

    SANS Stormcast Feb 13th 2025: Smart City Threats; Advanced Social Engineering Attacks; Wazuh Vulnerability; PAM Vulnerability; Ivanti Patches Feb 13, 2025
    Show notes
    An Ontology for Threats: Cybercrime and Digital Forensic Investigation on Smart City Infrastructure
    Smart cities is a big topic for many local governments. With building these complex systems, attacks will follow.
    https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676
    North Korean state actor tricking admins into executing PowerShell
    North Korean state actors are spending quite a bit of effort setting up relationships with South Korean system administrators, culminating in them getting tricked into executing malicious PowerShell scripts.
    https://x.com/MsftSecIntel/status/1889407814604296490
    Wazuh Vulnerability
    A deserialization vulnerability in Wazuh may lead to an unauthenticated remote code execution vulnerability
    https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh
    PAM PKCS11 Vulnerablity
    Several vulnerabilities in the Linux PAM module processing smart card authentication can be used to bypass authentication
    https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13
    Ivanti Patches
    Ivanti released its monhtly update, fixing a number of critical vulnerabilities in Connect Secure and other prodcuts
    https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US

    SANS Stormcast Feb 12th 2025: MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS Feb 12, 2025
    Show notes
    Microsoft Patch Tuesday
    Microsoft released patches for 55 vulnerabilities. Three of them are actagorized as critical, two are already exploited and another two have been publicly disclosed. The LDAP server vulnerability could become a huge deal, but it is not clear if an exploit will appear.
    https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674
    Adobe Patches
    Adobe released patches for seven products. Watch out in particular for the Adobe Commerce issues
    https://helpx.adobe.com/security/security-bulletin.html
    Fortinet Acknowledges Exploitation of Vulnerability
    https://fortiguard.fortinet.com/psirt/FG-IR-24-535

    SANS Stormcast Feb 11th 2025: 7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update Feb 11, 2025
    Show notes
    Reminder: 7-Zip MoW
    The MoW must be added to any files extracted from ZIP or other compound file formats. 7-Zip does not do so by default unless you alter the default configuration.
    https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668
    Apple Fixes 0-Day
    Apple released updates to iOS and iPadOS fixing a bypass for USB Restricted Mode. The vulnerability is already being exploited.
    https://support.apple.com/en-us/122174
    AMD ZEN CPU Microcode Update
    An attacker is able to replace microcode on some AMD CPUs. This may alter how the CPUs function and Google released a PoC showing how it can be used to manipulate the random number generator.
    https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w
    Trimble Cityworks Exploited
    CISA added a recent Trimble Cityworks vulnerabliity to its list of exploited vulnerabilities.
    https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?
    Google Tag Manager Skimmer Steals Credit Card Info
    Sucuri released a blog post with updates to the mage cart campaign. The latest version is injecting malicious code as part of the google tag manager / analytics code.
    https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html

    Previous 1 38 39 40 41 42 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights