

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Aug 20, 2025 • 6min
SANS Stormcast Wednesday, August 20th, 2025: Increased Elasticsearch Scans; MSFT Patch Issues
There's been a spike in reconnaissance scans targeting Elasticsearch, particularly towards the /_cluster/settings endpoint. Meanwhile, Microsoft is facing challenges with recent patches, causing issues with WSUS and transferring large files on certain SSDs. Additionally, details have emerged about two SAP vulnerabilities that can be exploited, shedding light on the ongoing security landscape and its implications for users.

Aug 19, 2025 • 5min
SANS Stormcast Tuesday, August 19th, 2025: MFA Bombing; Cisco Firewall Management Vuln; F5 Access for Android Vuln;
Learn about the alarming rise of MFA bombing attacks, where users are overwhelmed with authentication requests to crack security. Discover critical vulnerabilities in Cisco's Secure Firewall Management Center software that could allow remote code execution. Also discussed is a significant flaw in F5 Access for Android, where attackers can intercept sensitive data. The podcast emphasizes the importance of recognizing these threats and applying timely patches to enhance cybersecurity.

Aug 18, 2025 • 6min
SANS Stormcast Monday, August 18th, 2025: 5G Attack Framework; Plex Vulnerability; Fortiweb Exploit; Flowise Vuln
A new tool allows passive interception of 5G traffic, raising concerns about security and potential attacks. Plex has patched a vulnerability in its media server, urging users to update. Details of a critical exploit for FortiWeb have emerged, showcasing a complete authentication bypass. Additionally, new vulnerabilities in AI tools highlight risks associated with untrusted data, making cybersecurity more crucial than ever.

4 snips
Aug 15, 2025 • 15min
SANS Stormcast Friday, August 15th, 2025: Analysing Attack with AI; Proxyware via YouTube; Xerox FreeFlow Vuln; Evaluating Zero Trust @SANS_edu
Darren Carstensen, an MSISE graduate and security expert, dives into the realm of AI and its role in speeding up cybersecurity incident analysis. He reveals alarming trends, including proxyware malware distributed via popular YouTube download sites. Carstensen discusses critical vulnerabilities in Xerox's FreeFlow Core, enabling easy exploitation for remote code execution. The discussion also covers the complexities of implementing Zero Trust security, highlighting essential factors for successful adoption and the importance of robust multi-factor authentication.

Aug 14, 2025 • 7min
SANS Stormcast Thursday, August 14th, 2025: Equation Editor; Kerberos Patch; XZ-Utils Backdoor; ForitSIEM/FortiWeb patches
Old vulnerabilities are still posing serious threats, with a 2017 Excel exploit actively targeting users to steal passwords. Microsoft recently patched a critical Kerberos privilege escalation flaw impacting Exchange servers. There's a lurking backdoor in outdated Debian Docker images stirring concerns about software safety. Plus, Fortinet is addressing exploited vulnerabilities in their security products. These discussions highlight the ongoing challenges in cyber security and the importance of staying vigilant against both old and new threats.

7 snips
Aug 13, 2025 • 9min
SANS Stormcast Wednesday, August 13th, 2025: Microsoft Patch Tuesday; libarchive vulnerability upgrade; Adobe Patches
Discover the latest on Microsoft’s massive Patch Tuesday, addressing 111 vulnerabilities, including critical Azure issues. Learn about the chilling upgrade of a libarchive vulnerability from low to critical, impacting compression software across many platforms. Don’t miss the spotlight on Adobe's extensive patch rollout for 13 products, highlighting serious authentication concerns. Stay informed on these vital security updates that could affect your systems!

Aug 12, 2025 • 7min
SANS Stormcast Tuesday, August 12th, 2025: Erlang OTP SSH Exploits (Palo Alto Networks); Winrar Exploits; Netscaler Exploits; OpenSSH Pushing PQ Crypto;
Discover the latest cyber vulnerabilities that are causing a stir in the security world, including a critical exploit in Erlang/OTP SSH and active attacks on WinRAR. Learn how threat actors are capitalizing on Citrix Netscaler vulnerabilities and what patches are necessary to protect against them. Also, dive into OpenSSH's forward-thinking approach to quantum-safe encryption, signaling a significant leap in future cybersecurity measures. Stay informed and secure in an evolving threat landscape!

Aug 11, 2025 • 7min
SANS Stormcast Monday, August 11th, 2025: Fake Tesla Preorders; Bad USB Cameras; Win-DoS Epidemic
Beware of fake Tesla websites tricking users into sharing credit card information for nonexistent preorders. In a shocking twist, compromised USB devices can act like keyboards to inject malicious commands. Additionally, learn about a concerning epidemic where internet-exposed domain controllers are exploited for powerful denial of service attacks, emphasizing the need for strong security measures. Stay informed and protect yourself from these modern cyber threats!

Aug 8, 2025 • 24min
SANS Stormcast Friday, August 8th, 2025:: ASN43350 Mass Scans; HTTP1.1 Must Die; Hyprid Exchange Vuln; Sonicwall Update; SANS.edu Research: OSS Security and Shifting Left
Wellington Rampazo, an information security expert with two decades in the field and recent master’s grad, enlightens listeners with crucial cybersecurity insights. He discusses the alarming rise of mass scanning from ASN 43350 and how organizations can defend against it. The conversation also dives into critical vulnerabilities in HTTP/1.1 and Microsoft Exchange Servers, emphasizing the need for swift updates. Finally, Rampazo shares vital research on improving open-source software security, advocating for developers to shift their awareness and practices to mitigate risks.

4 snips
Aug 7, 2025 • 5min
SANS Stormcast Thursday, August 7th, 2025: Sextortion Update; Adobe and Trend Micro release emergency patches
Sextortion scams are making a disturbing comeback in 2025, with some crypto addresses still receiving deposits. The Akira ransomware group is leveraging legitimate drivers for privilege escalation, raising alarms about this tactic. Emergency patches have been issued by Adobe for a critical vulnerability in Experience Manager after a proof-of-concept exploit surfaced. Similarly, Trend Micro has responded to an actively exploited vulnerability in their Apex One management console. Cybersecurity vigilance is more crucial than ever!