

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 4, 2025 • 6min
SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit
Discover the nuances of the 'Mark of the Web' in Windows, revealing how it stores information like source URLs and referrers. Dive into a crafty phishing attack that exploits SharePoint via the Microsoft Graph API, luring users to execute harmful commands. Learn about a critical vulnerability in Paragon Partition Manager that enables attackers to escalate privileges for ransomware deployment, even without the software installed. Stay informed on these pressing cybersecurity threats!

4 snips
Mar 3, 2025 • 7min
SANS Stormcast Monday Mar 3rd: AI Training Data Leaks; MITRE Caldera Vuln; modsecurity bypass
The podcast dives into alarming AI training data leaks, revealing that the Common Crawl dataset harbors exposed API keys and secrets. It also discusses GitHub's Copilot inadvertently accessing sensitive data from previously private repositories. The MITRE Caldera framework is highlighted for its potential vulnerability, allowing unauthorized code execution. Lastly, it addresses a modsecurity rule bypass, emphasizing the critical importance of regular software updates to enhance cybersecurity defenses.

Feb 28, 2025 • 14min
SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware
Join Ben Powell, a principal security engineer with 15 years in cybersecurity, as he dives into some pressing digital threats. He discusses the Njrat malware exploiting Microsoft's dev tunnels and highlights new vulnerabilities in Apple’s FindMy that could endanger users. The conversation also covers alarming trends in mass website exploitation through XSS vulnerabilities in virtual tour frameworks. Plus, learn about effective strategies against ransomware and the strengths and weaknesses of various cybersecurity solutions for small businesses.

Feb 27, 2025 • 7min
SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;
Discover the hidden risks of ephemeral ports as attackers use them to exfiltrate data, prompting the need for vigilant traffic monitoring. A compromised Visual Studio Code theme has alarmingly reached millions, with its exact malicious intent still under wraps. The shocking theft at ByBit reveals how a compromised developer workstation can lead to monumental losses. Additionally, a vulnerability in NAKIVO backup systems sparks concerns as a proof of concept exploit surfaces, catching the cyber world off guard.

Feb 26, 2025 • 6min
SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps
A massive botnet is targeting Microsoft 365 accounts using stolen credentials from infostealer malware, highlighting the urgency for better authentication methods. Misconfigurations in OpenID pose significant security risks, allowing private keys to accidentally be exposed. Additionally, patients downloading DICOM image viewers are tricked into installing malware, raising alarms about deceptive practices in the healthcare sector. These discussions emphasize the need for vigilance and improved security measures across digital platforms.

Feb 25, 2025 • 6min
SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln
Discover the latest Unfurl update that improves URL decoding and timestamp management. Learn how Google is phasing out SMS for GMail, opting for Passkeys instead. Beware of new PayPal phishing tactics that exploit legitimate emails. The podcast also covers vulnerabilities in mail servers, including a serious Exim SQL injection flaw and a newly discovered 0-day in Parallels. Stay informed about evolving cyber threats and enhance your security awareness!

4 snips
Feb 24, 2025 • 5min
SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns;
Discover the latest advancements in cybersecurity tools, including the innovative sigs.py for hash verification. Google introduces quantum-safe digital signatures in its cloud key management, marking a significant shift in security. The conversation also delves into recent issues with Windows 11 updates affecting file usability. Finally, researchers raise alarms about numerous vulnerabilities in 5G and LTE networks, underlining the urgent need for enhanced security in our digital infrastructure.

8 snips
Feb 21, 2025 • 12min
SANS Stormcast Friday Feb 21st: Kibana Queries; Mongoose Injection; U-Boot Flaws; Unifi Protect Camera Vulnerabilities; Protecting Network Devices as Endpoint (Austin Clark @sans_edu)
Discover how to leverage ES|QL in Kibana for querying DShield honeypot logs effectively. Dive into the vulnerabilities of Mongoose leading to potential MongoDB exploits. Uncover the issues within the U-Boot open-source bootloader that could allow malicious code execution. Learn about key updates to Unifi Protect Cameras that address security risks. Lastly, explore innovative ways to treat network devices as endpoints, enhancing detection and privilege management to bolster cybersecurity.

4 snips
Feb 20, 2025 • 7min
SANS Stormcast Wednesday Feb 20th: XWorm Cocktail; Quantum Computing Breakthrough; Signal Phishing
Dive into the world of cybersecurity with a look at XWorm, a tricky malware disguised as anti-cheat software, packed with malicious PowerShell code. Discover Microsoft's revolutionary Majorana 1 chip, paving the way for stable, low-error quantum computing. Also, learn about the vulnerabilities in the popular Signal messaging app, where QR codes could compromise user accounts, and how Russian actors are exploiting this for phishing attacks. It's a cybersecurity rollercoaster you won't want to miss!

Feb 19, 2025 • 7min
SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability
Discover how ModelScan combats deserialization attacks on AI models, ensuring safety against malicious code. Learn about critical vulnerabilities in OpenSSH that could lead to server impersonation, emphasizing the importance of timely updates. Juniper fixes significant authentication bypass issues, while Dell addresses privilege escalation in BIOS across its product line. Each topic highlights the ongoing battle to secure our digital landscape.


