
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Latest episodes

Sep 19, 2024 • 4min
ISC StormCast for Thursday, September 19th, 2024
Malware is evolving, with InfoStealer targeting crypto wallets and recent vulnerabilities in ServiceNow's access control system causing concern. The discussion covers critical patches released by GitLab and Aruba, emphasizing the importance of active patch management. Listeners learn how to stay ahead of security threats and the pressing need for improved cyber defenses in today's digital landscape.

Sep 18, 2024 • 5min
ISC StormCast for Wednesday, September 18th, 2024
Explore the latest cyber threats, including a keystroke-capturing script reminiscent of the notorious I love you virus. Delve into critical vulnerabilities in VMware vCenter and a critical zero-click exploit in macOS that could have serious implications. Plus, discover how Google is enhancing Chrome’s security with the latest post-quantum encryption standard. This podcast highlights the critical need for vigilance in our rapidly evolving digital landscape.

Sep 17, 2024 • 5min
ISC StormCast for Tuesday, September 17th, 2024
Explore the intriguing world of managing PE files with overlays, designed to dodge security tools. Learn about recent Apple updates and their associated vulnerabilities, stressing why timely updates matter. Dive into the critical vulnerabilities affecting DLink devices and understand the urgency of upgrading to the latest firmware. Plus, discover Microsoft's latest guidance to counter zero day exploits and strengthen your cybersecurity defenses.

Sep 16, 2024 • 6min
ISC StormCast for Monday, September 16th, 2024
Discover the intriguing world of honeypots as a machine learning tool uncovers data clusters and command similarities. Learn about a novel credential theft technique linked to the StiLC Malvers toolset. Recent vulnerabilities in Ivanti appliances raise concerns, along with crucial updates for Docker Desktop. Stay informed on the ever-evolving threats in cybersecurity!

Sep 13, 2024 • 5min
ISC StormCast for Friday, September 13th, 2024
A recent compromise of an old .mobi whois server sheds light on the cybersecurity risks tied to forgotten domains. The podcast discusses Microsoft's new security innovations, including the implementation of post-quantum cryptography to safeguard Windows customers. Additionally, a critical update for GitLab is highlighted, addressing a severe remote code execution vulnerability. The necessity for vigilant data validation and management post-expiration is emphasized, showcasing the importance of proactive security measures in today's digital landscape.

Sep 11, 2024 • 6min
ISC StormCast for Wednesday, September 11th, 2024
The hosts dive into urgent cybersecurity vulnerabilities impacting Microsoft, highlighting risks of remote code execution. A critical issue in ColdFusion also gets attention. The importance of timely patching is stressed, especially with notable updates from Microsoft, Adobe, and Ivanti. Listeners are advised on best practices for vulnerability management, considering upcoming changes to the podcast schedule.

Sep 10, 2024 • 4min
ISC StormCast for Tuesday, September 10th, 2024
Explore critical cybersecurity vulnerabilities, including a high-risk flaw in Loadmaster with a CVSS score of 10. Urgent patches for HAProxy and SonicWall SSL VPN are highlighted. The discussion dives into Akira ransomware targeting specific accounts and a severe Kibana deserialization vulnerability. Additionally, it examines how Stately Taurus abuses Visual Studio Code for espionage, shedding light on the complexity of these attacks that exploit legitimate software features.

Sep 9, 2024 • 6min
ISC StormCast for Monday, September 9th, 2024
Discover the shocking energy consumption of password cracking using Hashcat and how a new Python plugin enhances Notepad++. Dive into the murky waters of fake LinkedIn job ads used by North Korea to distribute malware. Learn about a sneaky new Android malware that strips crypto wallet passphrases right from your device. Plus, be wary of a sneaky sextortion scam that leverages victims' spouses' names as bait, highlighting the critical need for vigilance in online security.

Sep 6, 2024 • 6min
ISC StormCast for Friday, September 6th, 2024
Discover how enriching log data from honeypots can unveil malicious activities. Learn about critical vulnerabilities in Veeam's service provider console and the urgent need for updates. Delve into major security flaws in the OF Biz CRM suite, including a dangerous unauthenticated remote code execution issue. Plus, find out about essential patches for Cisco’s Smart License Manager that highlight the importance of keeping software up-to-date. These discussions shed light on protecting against evolving cyber threats.

Sep 5, 2024 • 7min
ISC StormCast for Thursday, September 5th, 2024
The talk dives into a recently identified vulnerability in the Moodle learning platform that has caught the attention of cybersecurity experts. Listeners learn about the alarming risks associated with the PyPi repository, where a technique has exposed around 22,000 packages. The discussion also highlights important updates regarding Android security patches and a new proof-of-concept exploit targeting MediaTek chipsets. It's a deep dive into current threats and protective measures in the digital landscape.