TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS Internet Stormcast Feb 10th 2025: Podcast Anniversary; SSL 2.0; Exposed Deepseek Installs; Crypto Scam costs Feb 10, 2025
    Show notes
    SSL 2.0 Turns 30 This Sunday
    SSL was created in February 1995. However, back in 2005, only a year later, SSL 3.0 was released, and as of 2011, SSL 2.0 was deprecated, and support was removed from many crypto libraries. However, over 400k hosts are still exposed via SSL 2.0.
    https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664
    Deepseek News
    Many articles cover various security shortcomings in the Chinese Deepseek AI model. Remember that some of these issues are not unique to Deepseek.
    https://www.upguard.com/blog/deepseek-adoption
    https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face
    https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak
    https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/
    Crypto Wallet Scam Not For Free
    Didier looked closer at the recent dual signature crypto scams. These wallets are not free; attackers must spend money to set them up.
    https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666

    SANS Internet Stormcast Feb 7th 2025: Unbreakable Anti-Debugging; Feb 07, 2025
    Show notes
    The Unbreakable Multi-Layer Anti-Debugging System
    Xavier found a nice Python script that included what it calls the "Unbreakable Multi-Layer Anti-Debugging System". Leave it up to Xavier to tear it appart for you.
    https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658
    Take my money: OCR crypto stealers in Google Play and App Store
    Malware using OCR on screen shots was available not just via Google Play, but also the Apple App Store.
    https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/
    Threat Actors Still Leveraging Legit RMM Tool ScreenConnect
    Unsurprisingly, threat actors still like to use legit remote admin tools, like ScreenConnect, as a command and control channel. Silent Push outlines the latest trends and IoCs they found
    https://www.silentpush.com/blog/screenconnect/
    Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
    Java deserializing strikes again to allow arbitrary code execution. Cisco fixed this vulnerability and a authorization bypass issue in its Identity Services Engine
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF
    F5 Update
    F5 fixes an interesting authentication bypass problem affecting TLS client certificates
    https://my.f5.com/manage/s/article/K000149173

    SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firefox CT Policy; Veeam and Netgear patches Feb 06, 2025
    Show notes
    Phishing via com- prefix domains
    Every day, attackers are registering a few hunder domain names starting with com-. These are used in phishing e-mails, like for example "toll fee scams", to create more convincing phishing links.
    https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654
    Microsoft Windows 10 Extended Security Updates
    Microsoft released pricing and additional details for the Windows 10 extended security updates. For the first year after official free updates stopped, security updates will be available for $61 for the first year.
    https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates
    Mozilla Enforcing Certificate Transparency
    Mozilla is following the lead from other browsers, and will require certificates to include a certificate signature timestamp as proof of compliance with certificate transparency requirements.
    https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ
    https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies
    Veeam Update
    Veeam's internal backup process may be used to execute arbitrary code by an attacker with a machine in the middle position.
    https://www.veeam.com/kb4712
    Netgear Unauthenticated RCE
    https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039

    SANS Internet Stormcast Feb 5th 2025: Feed Updates and Rosti; Resurrecting Dead S3 Buckets; Let's Encrypt Changes; Edge Device Security Feb 05, 2025
    Show notes
    Some Updates to Our Data Feeds
    We made some updates to the documentation for our data feeds, and added the neat Rosti Feed to our list as well as to our ipinfo page.
    https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650
    8 Million Request Later We Meade the Solarwindws Supply Chain Attack Look Amateur
    While the title is a bit of watchTowr hyperbole, the problem of resurrecting dead S3 buckets back to live is real and needs to be addressed. Boring solutions will help not becoming an exciting headline.
    https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/
    Let's Encrypt Ending Expiration Emails
    Let's Encrypt will no longer send emails for expiring certificates. They suggest other free services to send these emails for you
    https://letsencrypt.org/2025/01/22/ending-expiration-emails/
    Guidance and Strategies Protect Network Edge Edvices
    CISA and other agencies created a guidance document outlining how to protect edge devices like firewalls, vpn concentrators and other similar devices.
    https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices

    SANS ISC Stormcast Feb 4th 2025: Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service Feb 04, 2025
    Show notes
    Crypto Wallet Scam
    YouTube spam messages leak private keys to crypto wallets. However, these keys can not be used to withdraw funds. Victims are scammed into depositing "gas fees" which are then collected by the scammer.
    https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646
    Mediatek Patches
    Mediatek patched numerous vulnerabilities in its WLAN products. Some allow for unauthenticated arbitrary code execution
    https://corp.mediatek.com/product-security-bulletin/February-2025
    D-Link Vulnerability
    D-Link disclosed a vulnerability in older routers that as of May no longer receive any updates. Your only option is to upgrade hardare.
    https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415
    Microsoft Discontinues VPN Service
    Microsoft is shutting down the VPN service that was included as part of Microsoft Defender
    https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a

    SANS ISC Stormcast Feb 3rd 2025: Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors Feb 03, 2025
    Show notes
    To Simulate or Replicate: Crafting Cyber Ranges
    Automating the creation of cyber ranges. This will be a multi part series and this part covers creating the DNS configuration in Windows
    https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642
    Scammers Exploiting Deepseek Hype
    Scammers are using the hype around Deepseek, and some of the confusion caused by it's site not being reachable, to scam users into installing malware. I am also including a link to a "jailbreak" of Deepseek (this part was not covered in the podcast).
    https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/
    https://lab.wallarm.com/jailbreaking-generative-ai/
    PyPi Archived Status
    PyPi introduced a new feature to mark repositories as archived. This implies that the author is no longer maintaining the particular package
    https://blog.pypi.org/posts/2025-01-30-archival/
    ICS Mecial Advisory: Comtec Patient Monitor Backdoor
    And interested backdoor was found in a Comtech Patient Monitor.
    https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01

    SANS ISC Stormcast Jan 31st 2025: Old Netgear Vuln in Depth; Lightning AI RCE; Canon Printer RCE; Deepseek Leak; Jan 31, 2025
    Show notes
    PCAPs or It Didn't Happen: Exposing an Old Netgear Vulnerability Still Active in 2025 [Guest Diary]
    https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638
    RCE Vulnerablity in AI Development Platform Lightning AI
    Noma Security discovered a neat remote code execution vulnerability in Lightning AI. This vulnerability is exploitable by tricking a logged in user into clicking a simple link.
    https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/
    Canon Laser Printers and Small Office Multifunctional Printer Vulnerabilities
    Canon fixed three different vulnerablities affecting various laser and small office multifunctional printers. These vulnerabilities may lead to remote code execution, and there are some interesting exploit opportunities
    https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers
    Deepseek ClickHouse Database Leak
    https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak

    SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch Jan 30, 2025
    Show notes
    From PowerShell to a Python Obfuscation Race!
    This information stealer not only emulates a PDF document convincingly, but also includes its own Python environment for Windows
    https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634
    Alleged Active Exploit Sale of CVE-2024-55591 on Fortinet Devices
    An exploit for this week's Fortinet vulnerability is for sale on russian forums. Fortinet also requires patching of devices without cloud license within seven days of patch release
    https://x.com/MonThreat/status/1884577840185643345
    https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376
    The Tainted Voyage: Uncovering Voyager's Vulnerabilities
    Sonarcube identified vulnerabilities in the popular PHP package Voyager. One of them allows arbitrary file uploads.
    https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/
    Hackers exploit critical unpatched flaw in Zyxel CPE devices
    A currently unpatches vulnerablity in Zyxel devices is actively exploited.
    https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/
    VMSA-2025-0002: VMware Avi Load Balancer addresses an unauthenticated blind SQL Injection vulnerability (CVE-2025-22217)
    VMWare released a patch for the AVI Load Balancer addressing an unauthenticated blink SQL injection vulnerability.
    https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346

    SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code Jan 29, 2025
    Show notes
    Learn about fileless crypto stealers written in Python, the ongoing exploitation of recent SimpleHelp vulnerablities, new Apple Silicon Sidechannel attacks a Team Viewer Vulnerablity and an odd QR Code
    Fileless Python InfoStealer Targeting Exodus
    This Python script targets Exodus crypto wallet and password managers to steal crypto currencies. It does not save exfiltrated data in files, but keeps it in memory for exfiltration
    https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630
    Campaign Exploiting SimpleHelp Vulnerablity
    Arcticwolf observed attacks exploiting SimpleHelp for initial access to networks. It has not been verified, but is assumed that vulnerabilities made public about a week ago are being exploited.
    https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/
    Two new Side Channel Vulnerabilities in Apple Silicon
    SLAP (Data Speculation Attacks via Load Address Prediction): This attack exploits the Load Address Predictor in Apple CPUs starting with the M2/A15, allowing unauthorized access to sensitive data by mispredicting memory addresses. FLOP (Breaking the Apple M3 CPU via False Load Output Predictions): This attack targets the Load Value Predictor in Apple's M3/A17 CPUs, enabling attackers to execute arbitrary computations on incorrect data, potentially leaking sensitive information.
    https://predictors.fail/
    Teamviewer Security Bulletin
    Teamviewer patched a privilege escalation vulnerability CVE-2025-0065
    https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/
    Odd QR Code
    A QR code may resolve to a different URL if looked at at an angle.
    https://mstdn.social/@isziaui/113874436953157913
    Limited Discount for SANS Baltimore
    https://sans.org/u/1zQd

    SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches Jan 28, 2025
    Show notes
    This episode shows how attackers are bypassing phishing filter by abusing the "shy" softhyphen HTML entitiy. We got an update from Apple fixing a 0-day vulnerability in addition to a number of other issues. watchTowr show how to exploit an interesting FortiOS vulnerability and we have patches for Github Desktop and Apache Solr
    An unusal shy z-wasp phish
    https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626
    How the soft hyphen "shy" HTML entity can be abused to bypass e-mail filters
    Apple Patches
    https://support.apple.com/en-us/100100
    Apple released patches for all of its operating systems, fixing a 0-day vulnerability among many others issues
    Get Fortirekt I am the Super_admin now
    https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/
    Details about a recent FortiOS Vulnerability
    GitHub Desktop Vulnerability
    https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html
    Apache Solr Vulnerability
    https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access

    Previous 1 39 40 41 42 43 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights