

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Aug 22, 2025 • 7min
SANS Stormcast Friday, August 22nd, 2025: The -n switch; Commvault Exploit; Docker Desktop Escape Vuln;
The importance of using the '-n' command line switch is highlighted, focusing on how it can enhance operational security by disabling reverse DNS lookups. Recent vulnerabilities in Commvault's enterprise backup solution are discussed, urging immediate patches for users. Additionally, a concerning Docker Desktop vulnerability is unveiled, revealing how attackers could escape from containers to compromise the host system. The insights stress the need for developers to prioritize security in their software.

Aug 21, 2025 • 7min
SANS Stormcast Thursday, August 21st, 2025: Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking
Discover the strange usernames popping up in honeypot logs related to Airtel routers. Apple swiftly addresses a 0-day vulnerability in their systems with crucial updates. Uncover the complexities of Microsoft Copilot’s audit logs and its implications for data access. Finally, learn about alarming clickjacking vulnerabilities plaguing many password managers, highlighting the essential need for prompt security enhancements.

Aug 20, 2025 • 6min
SANS Stormcast Wednesday, August 20th, 2025: Increased Elasticsearch Scans; MSFT Patch Issues
There's been a spike in reconnaissance scans targeting Elasticsearch, particularly towards the /_cluster/settings endpoint. Meanwhile, Microsoft is facing challenges with recent patches, causing issues with WSUS and transferring large files on certain SSDs. Additionally, details have emerged about two SAP vulnerabilities that can be exploited, shedding light on the ongoing security landscape and its implications for users.

Aug 19, 2025 • 5min
SANS Stormcast Tuesday, August 19th, 2025: MFA Bombing; Cisco Firewall Management Vuln; F5 Access for Android Vuln;
Learn about the alarming rise of MFA bombing attacks, where users are overwhelmed with authentication requests to crack security. Discover critical vulnerabilities in Cisco's Secure Firewall Management Center software that could allow remote code execution. Also discussed is a significant flaw in F5 Access for Android, where attackers can intercept sensitive data. The podcast emphasizes the importance of recognizing these threats and applying timely patches to enhance cybersecurity.

Aug 18, 2025 • 6min
SANS Stormcast Monday, August 18th, 2025: 5G Attack Framework; Plex Vulnerability; Fortiweb Exploit; Flowise Vuln
A new tool allows passive interception of 5G traffic, raising concerns about security and potential attacks. Plex has patched a vulnerability in its media server, urging users to update. Details of a critical exploit for FortiWeb have emerged, showcasing a complete authentication bypass. Additionally, new vulnerabilities in AI tools highlight risks associated with untrusted data, making cybersecurity more crucial than ever.

4 snips
Aug 15, 2025 • 15min
SANS Stormcast Friday, August 15th, 2025: Analysing Attack with AI; Proxyware via YouTube; Xerox FreeFlow Vuln; Evaluating Zero Trust @SANS_edu
Darren Carstensen, an MSISE graduate and security expert, dives into the realm of AI and its role in speeding up cybersecurity incident analysis. He reveals alarming trends, including proxyware malware distributed via popular YouTube download sites. Carstensen discusses critical vulnerabilities in Xerox's FreeFlow Core, enabling easy exploitation for remote code execution. The discussion also covers the complexities of implementing Zero Trust security, highlighting essential factors for successful adoption and the importance of robust multi-factor authentication.

Aug 14, 2025 • 7min
SANS Stormcast Thursday, August 14th, 2025: Equation Editor; Kerberos Patch; XZ-Utils Backdoor; ForitSIEM/FortiWeb patches
Old vulnerabilities are still posing serious threats, with a 2017 Excel exploit actively targeting users to steal passwords. Microsoft recently patched a critical Kerberos privilege escalation flaw impacting Exchange servers. There's a lurking backdoor in outdated Debian Docker images stirring concerns about software safety. Plus, Fortinet is addressing exploited vulnerabilities in their security products. These discussions highlight the ongoing challenges in cyber security and the importance of staying vigilant against both old and new threats.

7 snips
Aug 13, 2025 • 9min
SANS Stormcast Wednesday, August 13th, 2025: Microsoft Patch Tuesday; libarchive vulnerability upgrade; Adobe Patches
Discover the latest on Microsoft’s massive Patch Tuesday, addressing 111 vulnerabilities, including critical Azure issues. Learn about the chilling upgrade of a libarchive vulnerability from low to critical, impacting compression software across many platforms. Don’t miss the spotlight on Adobe's extensive patch rollout for 13 products, highlighting serious authentication concerns. Stay informed on these vital security updates that could affect your systems!

Aug 12, 2025 • 7min
SANS Stormcast Tuesday, August 12th, 2025: Erlang OTP SSH Exploits (Palo Alto Networks); Winrar Exploits; Netscaler Exploits; OpenSSH Pushing PQ Crypto;
Discover the latest cyber vulnerabilities that are causing a stir in the security world, including a critical exploit in Erlang/OTP SSH and active attacks on WinRAR. Learn how threat actors are capitalizing on Citrix Netscaler vulnerabilities and what patches are necessary to protect against them. Also, dive into OpenSSH's forward-thinking approach to quantum-safe encryption, signaling a significant leap in future cybersecurity measures. Stay informed and secure in an evolving threat landscape!

Aug 11, 2025 • 7min
SANS Stormcast Monday, August 11th, 2025: Fake Tesla Preorders; Bad USB Cameras; Win-DoS Epidemic
Beware of fake Tesla websites tricking users into sharing credit card information for nonexistent preorders. In a shocking twist, compromised USB devices can act like keyboards to inject malicious commands. Additionally, learn about a concerning epidemic where internet-exposed domain controllers are exploited for powerful denial of service attacks, emphasizing the need for strong security measures. Stay informed and protect yourself from these modern cyber threats!