TopPodcast.com
Menu
  • Home
  • Top Charts
  • Top Networks
  • Top Apps
  • Top Independents
  • Top Podfluencers
  • Top Picks
    • Top Business Podcasts
    • Top True Crime Podcasts
    • Top Finance Podcasts
    • Top Comedy Podcasts
    • Top Music Podcasts
    • Top Womens Podcasts
    • Top Kids Podcasts
    • Top Sports Podcasts
    • Top News Podcasts
    • Top Tech Podcasts
    • Top Crypto Podcasts
    • Top Entrepreneurial Podcasts
    • Top Fantasy Sports Podcasts
    • Top Political Podcasts
    • Top Science Podcasts
    • Top Self Help Podcasts
    • Top Sports Betting Podcasts
    • Top Stocks Podcasts
  • Podcast News
  • About Us
  • Podcast Advertising
  • Contact
Not in our directory?
Add Show Here
Podcast Equipment
Center

toppodcastlogoOur TOPPODCAST Picks

  • Comedy
  • Crypto
  • Sports
  • News
  • Politics
  • True Crime
  • Business
  • Finance

Follow Us

toppodcastlogoStay Connected

    View Top 200 Chart
    Back to Rankings Page
    News

    SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

    A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

    Advertise

    Copyright: © (c) SANS Institute 2024 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

    • Apple Podcasts
    • Google Play
    • Spotify

    Latest Episodes:
    SANS ISC Stormcast, Jan 13, 2025: Defender Updates, Ivanti RCE, Apple USB-C Hack and more Jan 13, 2025
    Show notes

    In today's episode, we cover the latest updates in cybersecurity:
    Windows Defender Enhances Chrome Extension Detection
    Microsoft's Defender now catalogs Chrome extensions to identify malicious ones. Learn how this improves enterprise security.
    https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574
    Multi-OLE Analysis in Malicious Documents
    A look at how attackers embed OLE files in Office documents to evade detection and the tools to combat it.
    https://isc.sans.edu/diary/Multi-OLE/31580
    Ivanti Connect Secure RCE Vulnerability (CVE-2025-0282)
    Details of a critical vulnerability affecting Ivanti products and the patching timelines.
    https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/
    Apple USB-C Controller Compromised
    Researchers hacked Apple s ACE3 USB-C controller, highlighting hardware security challenges.
    https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/
    IRS Pushes for IP PIN Enrollment
    Protect yourself from tax-related identity theft by securing your IP PIN for the 2025 tax season.
    https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season


    SANS ISC Stormcast: Cryptomining Malware, Fake PoC Exploit, Malicious Browser Extensions, and Palo Alto Vulnerabilities. Jan 9th 2024 Jan 10, 2025
    Show notes

    In this episode, we explore the following stories:
    "Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics"
    Overview of Redtail's multi-architecture cryptomining malware exploiting vulnerabilities and deploying persistence techniques.
    URL: Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics
    "Information Stealer Masquerades as LDAPNightmare PoC Exploit"
    A malware disguised as a PoC exploit targets users seeking to test vulnerabilities like LDAPNightmare.
    URL: Information Stealer Masquerades as LDAPNightmare PoC Exploit
    "How Extensions Trick CWS Search"
    Research reveals how malicious browser extensions manipulate Chrome Web Store search to appear legitimate.
    URL: How Extensions Trick CWS Search
    "Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)"
    Multiple vulnerabilities in the deprecated Expedition tool can expose credentials and lead to unauthorized file and command execution.
    URL: Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)


    SANS ISC Stormcast, Jan 9, 2025: Critical Vulnerabilities in Ivanti, Aviatrix, and Hijacked Backdoors in Compromised Systems Jan 09, 2025
    Show notes

    In this episode, we discuss critical vulnerabilities in Ivanti Connect Secure and Policy Secure, command injection risks in Aviatrix Network Controllers, and the risks posed by hijacked abandoned backdoors.
    Episode Links and Topics:
    More Governments Backdoors in Your Backdoors
    https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/
    Researchers reveal how expired domains linked to abandoned backdoors can be hijacked, exposing systems to further compromise.
    Security Update: Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways
    https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways
    Ivanti addresses critical vulnerabilities (CVE-2025-0282, CVE-2025-0283) in their secure gateway products, with active exploitation in the wild.
    CVE-2024-50603: Aviatrix Network Controller Command Injection Vulnerability
    https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/
    A command injection vulnerability in Aviatrix Network Controllers allows unauthenticated code execution, posing severe risks to network environments.


    SANS ISC Stormcast, Jan 8, 2025: Critical Vulnerabilities in SonicWall, Moxa, and Windows BitLocker – Plus, Malware Targets PHP Servers and the Launch of U.S. Cyber Trust Mark Jan 08, 2025
    Show notes

    In this episode, we dive into active exploitation of a zero-day in SonicWall SSL-VPN, privilege escalation vulnerabilities in Moxa devices, and a BitLocker bypass in Windows 11. We also cover cryptocurrency mining malware hitting PHP servers and the White House's launch of the U.S. Cyber Trust Mark to secure connected devices.
    Episode Links and Topics:
    PacketCrypt Classic Cryptocurrency Miner on PHP Servers
    https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564
    Malware exploiting PHP servers to mine PacketCrypt Classic cryptocurrency.
    SonicOS Affected By Multiple Vulnerabilities
    https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003
    A zero-day vulnerability in SonicWall SSL-VPN devices is under active attack.
    Privilege Escalation and OS Command Injection Vulnerabilities in Moxa Devices
    https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo
    Critical vulnerabilities in Moxa routers and security appliances allow privilege escalation and OS command injection.
    White House Launches U.S. Cyber Trust Mark
    https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/
    A new cybersecurity labeling program for connected devices aims to help consumers choose secure products.
    Windows BitLocker: Screwed without a Screwdriver
    https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761
    (video in English)
    A two-year-old vulnerability in Windows 11 allows bypassing BitLocker encryption.


    ISC StormCast for Tuesday, January 7th, 2025 Jan 07, 2025
    Show notes

    In this episode of the SANS Internet Storm Center's Stormcast, we cover critical vulnerabilities affecting OpenSSH, BeyondTrust, and Nuclei, including the newly discovered "RegreSSHion" flaw and a bypass vulnerability in Nuclei. We also discuss how malware evasion techniques can impact analysis environments and highlight the dangers of fake exploits targeting researchers. Tune in for insights on patching, mitigation strategies, and staying ahead of emerging threats.
    Topics Covered:
    Make Malware Happy
    https://isc.sans.edu/diary/Make%20Malware%20Happy/31560
    A look at how malware adapts and detects analysis environments, and why replicating operational settings is critical during malware analysis.
    Nuclei Signature Verification Bypass (CVE-2024-43405)
    https://www.wiz.io/blog/nuclei-signature-verification-bypass
    A critical vulnerability in Nuclei allows malicious templates to bypass signature verification, risking arbitrary code execution.
    Critical Vulnerability in BeyondTrust (CVE-2024-12356)
    https://censys.com/cve-2024-12356/
    A high-risk flaw in BeyondTrust products allows unauthenticated OS command execution, posing a significant threat to privileged access systems.
    RegreSSHion Code Execution Vulnerability (CVE-2024-6387)
    https://cybersecuritynews.com/regresshion-code-execution-vulnerability/
    OpenSSH vulnerability "RegreSSHion" enables remote code execution, and fake exploits targeting security researchers are in circulation.


    ISC StormCast for Monday, January 6th, 2025 Jan 06, 2025
    Show notes

    In this episode of the SANS Internet Storm Center's Stormcast, we cover the latest cybersecurity threats and defenses, including Python-delivered malware, goodware hash sets, SSL/TLS protocol updates, and critical vulnerabilities in ASUS routers and Paessler PRTG. Stay informed and secure your systems!
    Full details and links to all stories:
    SwaetRAT via Python: https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554
    Goodware Hash Sets: https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556
    SSL/TLS Updates: https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550
    Cyberhaven Extension Compromise: https://secureannex.com/blog/cyberhaven-extension-compromise/
    PRTG Vulnerability: https://www.zerodayinitiative.com/advisories/ZDI-24-1736/
    ASUS Router Vulnerabilities: https://cybersecuritynews.com/asus-router-vulnerabilities/


    ISC StormCast for Friday, December 20th, 2024 Dec 20, 2024
    Show notes

    PHPUnit and Androxgh0st
    https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528
    Mirai Attacks Session Smart Routers
    https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US
    FortiWLM Unauthenticated limited file read vulnerability
    https://fortiguard.fortinet.com/psirt/FG-IR-23-144
    https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/
    Beyond Trust Security Advisory
    https://www.beyondtrust.com/trust-center/security-advisories/bt24-10
    BadBox Update
    https://www.bitsight.com/blog/badbox-botnet-back


    ISC StormCast for Thursday, December 19th, 2024 Dec 19, 2024
    Show notes

    A Deep Dive into TeamTNT and Spinning YARN
    https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530
    Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks
    https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html
    Okta Social Engineering Impersonation Report
    https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation
    US considers banning TP-Link routers over cybersecurity risks
    https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/
    CISA Releases Best Practice Guidance for Mobile Communications
    https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications


    ISC StormCast for Wednesday, December 18th, 2024 Dec 18, 2024
    Show notes

    Python Delivering AnyDesk Client as RAT
    https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/
    Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion
    https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html
    SS7 Attacks
    https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/
    CrushFTP Vulnerability
    https://crushftp.com/crush11wiki/Wiki.jsp?page=Update


    ISC StormCast for Tuesday, December 17th, 2024 Dec 17, 2024
    Show notes

    MUT-1244 Targeting Offensive Actors
    https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/
    Golang Crypto Vulnerability
    https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909
    Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows
    https://www.cadosecurity.com/blog/meeten-malware-threat


    Previous 1 41 42 43 44 45 253 Next

    Related Podcasts

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters

    1

    Inside Strategic Coach: Connecting Entrepreneurs With What Really Matters Business
    WSJ Your Money Briefing

    2

    WSJ Your Money Briefing Business
    FORTUNE Unfiltered with Aaron Task

    3

    FORTUNE Unfiltered with Aaron Task Business
    FORTUNE OnStage Presents: The Most Powerful Women

    4

    FORTUNE OnStage Presents: The Most Powerful Women Business
    Slate Money

    5

    Slate Money Business
    In The Dark – The New Yorker

    6

    In The Dark – The New Yorker Business News
    footer-logo

    Contact Us

    Toll Free: 844-670-7747

    Links

    • Home
    • Top Charts
    • Networks
    • Apps
    • Independents Podcasts
    • Podcast Advertising
    • Podcast News
    • Contact Us
    • About Us
    • Analytics & Insights

    Stay Connected

      Privacy, Terms of Use & Our Code of Ethics Protecting Content Creators Copyrights