SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
5 snips
Feb 18, 2025 • 5min

SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch

Dive into essential strategies for securing edge devices as vulnerabilities grow. Explore the PostgreSQL exploit and the alarming exploitation of Ivanti Connect Secure. The discussion also covers a recently patched WinZip buffer overflow threat that could be triggered by malicious files. Plus, learn about critical patches for Xerox printers that address vulnerabilities potentially allowing lateral movement. Stay informed and protect your network from emerging cyber threats!
undefined
5 snips
Feb 17, 2025 • 9min

SANS Stormcast Monday Feb 17th: Fake BSOD; Volatile IPs; Postgresql libpq SQL Injection; OAUTH Phishing

A malicious Python script is creating fake blue screens of death, possibly to trick users into calling support scams. The importance of managing volatile IP addresses is emphasized, as mismanagement can lead to serious security risks. A critical SQL injection vulnerability in PostgreSQL’s libpq functions is detailed, exposing systems to potential breaches. Finally, the podcast explores how Russian threat actors are exploiting OAuth device code authentication through phishing attacks, highlighting the need for increased user awareness and security measures.
undefined
Feb 14, 2025 • 6min

SANS Stormcast Feb 14th 2025: DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhone vs. Cisco; Crowdstrike Patch

Explore the fascinating world of honeypots with insights on new SIEM dashboards that summarize attack data. Discover the recently patched vulnerability in Palo Alto Networks' devices that could lead to authentication bypass. Learn how China's Volt Typhoon group exploits older Cisco vulnerabilities for telecom attacks. Plus, find out about the latest security patches from Crowdstrike for their Linux client. A deep dive into pressing cybersecurity topics that keep professionals on their toes.
undefined
5 snips
Feb 13, 2025 • 6min

SANS Stormcast Feb 13th 2025: Smart City Threats; Advanced Social Engineering Attacks; Wazuh Vulnerability; PAM Vulnerability; Ivanti Patches

The discussion dives into the complex security challenges posed by smart cities, emphasizing the need for standardized vocabularies. It highlights North Korean state actors' cunning social engineering tactics targeting South Korean administrators. Additionally, listeners learn about vulnerabilities in Wazuh and the PAM module for Linux, which could lead to serious breaches. Finally, critical updates from Ivanti address multiple security flaws, stressing the importance of proactive measures in cybersecurity.
undefined
8 snips
Feb 12, 2025 • 6min

SANS Stormcast Feb 12th 2025: MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS

This discussion dives into Microsoft's latest Patch Tuesday, unveiling fixes for 55 vulnerabilities, including critical issues with LDAP and Active Directory. Notably, some flaws are already exploited, urging immediate attention. Adobe also steps up with patches for seven products, with a focus on critical Adobe Commerce issues. Finally, Fortinet faces scrutiny as they acknowledge exploitation of a vulnerability in FortiOS, raising concerns about security protocols. It's a critical time for updates in the cybersecurity landscape!
undefined
9 snips
Feb 11, 2025 • 7min

SANS Stormcast Feb 11th 2025: 7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update

Explore the critical need for secure file extraction with 7-Zip updates that require the mark of the web. Apple rushes to patch a vulnerability that lets attackers bypass USB restrictions on devices. Meanwhile, a microcode exploit on AMD CPUs raises alarms, manipulating functions and random number generation. Trimble Cityworks falls victim to a newly exploited flaw, while the latest MageCart tactics involve stealthy JavaScript injections stealing credit card data through Google Tag Manager, highlighting the importance of cautious coding practices.
undefined
4 snips
Feb 10, 2025 • 7min

SANS Internet Stormcast Feb 10th 2025: Podcast Anniversary; SSL 2.0; Exposed Deepseek Installs; Crypto Scam costs

Celebrate 16 years of cybersecurity insights while discussing the age of SSL 2.0, which turns 30 but still has over 400k hosts exposed. Delve into alarming security flaws in the Chinese Deepseek AI model, highlighting various deficiencies. Learn about the intricacies of dual signature crypto scams, revealing that these wallets actually require financial investment to set up. Join in on a blend of nostalgia and critical reflections on current cybersecurity threats!
undefined
7 snips
Feb 7, 2025 • 6min

SANS Internet Stormcast Feb 7th 2025: Unbreakable Anti-Debugging;

Dive into advanced multilayer anti-debugging techniques crafted in Python. Discover alarming malware using OCR to steal information from both Google Play and the Apple App Store. Uncover how legitimate remote management tools like ScreenConnect are being exploited by threat actors. Stay updated on critical vulnerabilities affecting Cisco’s Identity Services Engine and authentication issues in F5’s TLS client certificates. This discussion rounds out with insights on securing remote tools against unauthorized misuse.
undefined
5 snips
Feb 6, 2025 • 7min

SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firefox CT Policy; Veeam and Netgear patches

Learn how scammers are exploiting com- prefix domains to launch convincing phishing attacks, targeting victims with toll fee scams. Microsoft updates pricing for Windows 10 Extended Security Updates, setting a fee for continued protection. Mozilla pushes for better internet security by enforcing certificate transparency measures. Additionally, discover serious vulnerabilities in Veeam's backup process and Netgear's WiFi routers, highlighting the need for rapid updates in cybersecurity.
undefined
4 snips
Feb 5, 2025 • 7min

SANS Internet Stormcast Feb 5th 2025: Feed Updates and Rosti; Resurrecting Dead S3 Buckets; Let's Encrypt Changes; Edge Device Security

Updates on data feeds highlight the introduction of the Rosti Feed, while concerns about reviving dead S3 buckets spark intriguing discussions. Let's Encrypt's move to stop sending expiration emails raises questions about certificate management. Meanwhile, new guidelines from CISA focus on fortifying edge devices like firewalls and VPN concentrators, emphasizing the need for vigilance in cybersecurity.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app