

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jul 15, 2025 • 6min
SANS Stormcast Monday, July 14th, 2025: Web Honeypot Log Volume; Browser Extension Malware; RDP Forensics
Honeypot log volumes have surged dramatically, indicating a robust botnet targeting systems like SonicWall. Discover a shocking investigation revealing 18 malicious browser extensions that deceived millions into downloading malware. The discussion also dives into RDP forensics, providing essential techniques for preventing lateral movement and ensuring better incident response. Tune in to learn about the evolving landscape of cyber threats and the vital safeguards that can keep users secure.

Jul 14, 2025 • 7min
SANS Stormcast Monday, July 14th, 2025: Suspect Domain Feed; Wing FTP Exploited; FortiWeb Exploited; NVIDIA GPU Rowhammer
Discover a groundbreaking domain feed aimed at identifying potential phishing threats through innovative data aggregation. Learn about recent vulnerabilities in Wing FTP Server and FortiWeb that are actively being exploited, emphasizing the urgent need for updates. Dive into the alarming Rowhammer vulnerability affecting NVIDIA GPUs, showcasing industry-wide risks. This discussion not only illuminates current cybersecurity challenges but also reinforces the importance of vigilance among web developers and organizations.

Jul 11, 2025 • 6min
SANS Stormcast Friday, July 11th, 2025: SSH Tunnel; FortiWeb SQL Injection; Ruckus Unpatched Vuln; Missing Motherboard Patches;
Dive into the world of cyber security vulnerabilities, where SSH tunneling is exploited by attackers to relay traffic through compromised servers, targeting services like Yandex email. Discover the alarming risk posed by an unauthenticated SQL injection vulnerability in FortiWeb, potentially allowing unauthorized code execution. Plus, learn about critical flaws in Ruckus products, where multiple vulnerabilities remain unpatched, highlighting the necessity for restrictive access. Cyber risks are evolving; stay informed!

Jul 10, 2025 • 5min
SANS Stormcast Thursday, July 10th, 2025: Internal CA with ACME; TapJacking on Android; Adobe Patches;
Learn how to set up your own internal certificate authority for development with practical tips. Discover the dangerous animation-driven tapjacking technique on Android, which can trick users into unwanted actions. The discussion highlights concerning vulnerabilities in more than a dozen Adobe products, notably in ColdFusion, where code execution risks loom large. Delve into the significance of robust mobile application security and the alarming lack of protection in many popular apps.

Jul 9, 2025 • 8min
SANS Stormcast Wednesday, July 9th, 2025: Microsoft Patches; Opposum Attack;
A major patch day for Microsoft sees 139 vulnerabilities addressed, with 14 rated as critical. The discussion also highlights a new TLS vulnerability known as the 'opossum attack,' which lets attackers inject requests in specific configurations. Additionally, Ivanti has rolled out updates to tackle significant issues in their products, including a concerning password decryption flaw. Tune in for insights on these emerging threats and essential fixes in the cybersecurity landscape!

4 snips
Jul 8, 2025 • 5min
SANS Stormcast Tuesday, July 8th, 2025: Detecting Filename (Windows); Atomic Stealer now with Backdoor; SEO Scams
Discover how malware can cleverly detect its environment through filename tricks, making analysis difficult. A new version of the Atomic macOS info-stealer, equipped with a backdoor, enables attackers to maintain persistent access to compromised systems. The podcast also dives into alarming SEO scams promoting trojaned versions of popular tools, showcasing the dangers of malvertising. Learn about vulnerabilities exploited by attackers that could lead to remote code execution on cloud services.

Jul 7, 2025 • 6min
SANS Stormcast Monday, July 7th, 2025: interesting usernames; More sudo issues; CitrixBleed2 PoC; Short Lived Certs
Dive into intriguing usernames found in honeypots that could reveal security risks. Discover how the sudo command can be exploited to gain unauthorized access. Learn about the newly documented CitrixBleed2 vulnerability and its proof of concept. Plus, find out why Instagram has opted for six-day TLS certificates to boost security. Each topic highlights essential insights into current cybersecurity challenges.

Jul 3, 2025 • 5min
SANS Stormcast Thursday July 3rd, 2025: sudo problems; polymorphic zip files; cisco vulnerablity
Local users can exploit a vulnerability in the Linux sudo command to gain root access, raising significant security concerns. The podcast also delves into polymorphic zip files, which can yield different data during extraction, depending on the tool used. Additionally, there's a critical flaw in Cisco's Unified Communications Manager that allows attackers to access devices using unchangeable default credentials. These discussions emphasize the importance of patching and understanding security vulnerabilities in modern software.

6 snips
Jun 30, 2025 • 7min
SANS Stormcast Monday June 30th, 2025: Scattered Spider; AMI BIOS Exploited; Secure Boot Certs Expiring; Microsoft Resliliency Initiative
The podcast dives into the latest from the hacking group Scattered Spider, focusing on their dangerous social engineering tactics targeting airlines. A serious vulnerability in AMI BIOS is also highlighted, as it's currently being exploited. Listeners are reminded of the impending expiration of Secure Boot certificates, which is crucial for operating system security. Finally, Microsoft unveils its Resiliency Initiative, emphasizing enhanced security while introducing changes that could affect security tool functionality.

Jun 27, 2025 • 7min
SANS Stormcast Friday, June 27th, 2025: Open-VSX Flaw; Airoha Bluetooth Vulnerablity; Critical Cisco Identity Service Engine Vuln;
Developers beware: a flaw in the Open-VSX extension marketplace could jeopardize every extension available. Bluetooth vulnerabilities in the Airoha chipset may allow eavesdropping on personal devices, raising alarms about privacy. Additionally, critical weaknesses in Cisco's Identity Services Engine could enable remote attackers to gain root access. Learn about the growing threat landscape and upcoming events aimed at boosting cybersecurity awareness!


