

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

4 snips
Sep 4, 2025 • 6min
SANS Stormcast Thursday, September 4th, 2025: Dassault DELMIA Apriso Exploit Attempts; Android Updates; 1.1.1.1 Certificate Issued
Recent cyber attack attempts target Dassault's DELMIA Apriso software due to a patched deserialization vulnerability. The discussion also covers Google's September Android updates, addressing exploited privilege escalation flaws. Additionally, the podcast highlights a certificate issued for Cloudflare's DNS service, raising concerns about network vulnerabilities and security flaws. Proactive measures are emphasized to combat these evolving cyber threats.

5 snips
Sep 3, 2025 • 5min
SANS Stormcast Wednesday, September 3rd, 2025: Sextortiion Analysis; Covert Channel DNS/ICMP; Azure AD Secret Theft; Official FreePBX Patches
Dive into the dark world of sextortion as experts analyze 1,900 scam messages and their effectiveness over four years. Discover alarming insights into Azure AD client secret theft, revealing how attackers exploit exposed credentials. Learn about a new bot that cleverly uses ICMP and DNS for covert communications, combining two protocols for stealthy command execution. Lastly, find out about the critical updates for FreePBX and the importance of staying secure amidst these rising cybersecurity threats.

Sep 2, 2025 • 6min
SANS Stormcast Tuesday, September 2nd, 2025: pdf-parser Patch; Salesloft Compromise; Velociraptor Abuse; NeuVector Default Password
A new update for pdf-parser fixes critical streaming issues, enhancing security measures. In a troubling development, compromised OAuth tokens from Salesloft Drift have led to significant data breaches. The podcast also reveals how attackers are misusing the Velociraptor tool, typically for incident response, to gain remote access within breached networks. Finally, a default password vulnerability in NeuVector has been patched, emphasizing the need for security in software installations. Stay alert and informed!

7 snips
Aug 29, 2025 • 6min
SANS Stormcast Friday, August 29th, 2025: Scans for ZIP Files; FreePBX 0-Day; Passwordstate Patch
In this installment, experts highlight an alarming rise in attacks targeting .zip files, as attackers seek out careless backups. They delve into a critical vulnerability in FreePBX that's currently being exploited, along with new mitigations and a beta patch. Additionally, the discussion covers a recently patched authentication bypass vulnerability in Passwordstate, which could expose emergency passwords. Tune in for essential insights into these pressing cyber security issues!

Aug 28, 2025 • 7min
SANS Stormcast Thursday, August 28th, 2025: Launching Shellcode; NX Compromise; Volt Typhoon Report
Discover an intriguing malware technique that uses PowerShell to launch shellcode, evading security protocols. Learn about the NX build package compromise that leveraged AI to pilfer credentials. The discussion also highlights a global report on the 'Volt Typhoon' cyber threat, revealing the extensive impact of state-sponsored espionage. Stay informed about these critical cyber risks and how they may affect systems worldwide.

Aug 27, 2025 • 6min
SANS Stormcast Wednesday, August 27th, 2025: Analyzing IDNs; Netscaler 0-Day Vuln; Git Vuln Exploited;
The discussion dives into the risks associated with International Domain Names (IDNs) and how mixed scripts can signal phishing attempts. A Python script is introduced to analyze these names for security flaws. The hosts also spotlight critical vulnerabilities in Citrix Netscaler, one of which is already actively being exploited. Additionally, they cover a Git vulnerability that has been exploited post-patch, emphasizing the urgency of keeping systems updated to fend off potential threats.

6 snips
Aug 26, 2025 • 5min
SANS Stormcast Tuesday, August 26th, 2025: Decoding Word Reading Location; Image Downscaling AI Vulnerability; IBM Jazz Team Server Vuln
Uncover the secrets of Microsoft Word as experts reveal how it tracks document interactions. Delve into the risks posed by AI image downscaling, where seemingly innocent photos can unleash harmful text. The discussion doesn't stop there; learn about a critical vulnerability in the IBM Jazz Team Server that poses serious security threats. Discover advancements in understanding document security and how to safeguard against these emerging cyber risks!

Aug 25, 2025 • 6min
SANS Stormcast Monday, August 25th, 2025: IP Cleanup; Linux Desktop Attacks; Malicious Go SSH Brute Forcer; Onmicrosoft Domain Restrictions
A significant update on IP address formatting has kicked off the discussion, marking the end of zero-padded addresses. Attacks targeting Indian Linux desktops using .desktop files are on the rise, showcasing the creative tactics of Pakistani attackers. Meanwhile, a malicious Go module is exposing credentials through clever disguises as an SSH brute forcer. Lastly, Microsoft is tightening restrictions on email sending from its onmicrosoft.com domain, aiming to enhance security for its users.

Aug 22, 2025 • 7min
SANS Stormcast Friday, August 22nd, 2025: The -n switch; Commvault Exploit; Docker Desktop Escape Vuln;
The importance of using the '-n' command line switch is highlighted, focusing on how it can enhance operational security by disabling reverse DNS lookups. Recent vulnerabilities in Commvault's enterprise backup solution are discussed, urging immediate patches for users. Additionally, a concerning Docker Desktop vulnerability is unveiled, revealing how attackers could escape from containers to compromise the host system. The insights stress the need for developers to prioritize security in their software.

Aug 21, 2025 • 7min
SANS Stormcast Thursday, August 21st, 2025: Airtel Scans; Apple Patch; Microsoft Copilot Audit Log Issue; Password Manager Clickjacking
Discover the strange usernames popping up in honeypot logs related to Airtel routers. Apple swiftly addresses a 0-day vulnerability in their systems with crucial updates. Uncover the complexities of Microsoft Copilot’s audit logs and its implications for data access. Finally, learn about alarming clickjacking vulnerabilities plaguing many password managers, highlighting the essential need for prompt security enhancements.