

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Feb 4, 2025 • 6min
SANS ISC Stormcast Feb 4th 2025: Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service
Discover how a YouTube spam scam tricks users into losing money on crypto wallet fees, while their private keys remain safe. Learn about critical patches from Mediatek addressing serious vulnerabilities in WLAN products. D-Link faces challenges with older routers that will no longer receive updates, leaving users with the need to upgrade. Finally, Microsoft announces the discontinuation of its VPN service, prompting discussions about online security practices.

8 snips
Feb 3, 2025 • 6min
SANS ISC Stormcast Feb 3rd 2025: Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors
Discover the intriguing world of automated cyber ranges and their creation processes. Learn how scammers are capitalizing on the Deepseek hype, leading to malware infections through deceptive sites. Delve into the newly archived status feature on PyPi, signaling the end of maintenance for certain projects. Finally, uncover concerns about a backdoor found in a medical monitoring device, raising alarms in cybersecurity for healthcare. Tune in for insights into modern threats and innovations!

7 snips
Jan 31, 2025 • 6min
SANS ISC Stormcast Jan 31st 2025: Old Netgear Vuln in Depth; Lightning AI RCE; Canon Printer RCE; Deepseek Leak;
Explore the alarming persistence of old vulnerabilities in Netgear routers, still a threat in 2025. Discover a risky remote code execution flaw in the AI platform Lightning AI that could be exploited with just a click. Delve into various vulnerabilities in Canon printers that could lead to significant security breaches. Lastly, learn about the exposure of the Deepseek ClickHouse database and why securing databases is more critical than ever.

6 snips
Jan 30, 2025 • 6min
SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch
The discussion kicks off with a deep dive into devious Python malware that cleverly mimics PDF documents to steal data. A critical Fortinet vulnerability is making rounds on Russian forums, raising alarms over timely patches. The vulnerabilities in the Voyager PHP framework reveal risks like arbitrary file uploads. Active exploitation of unpatched Zyxel devices highlights the ever-present threat landscape. Finally, a VMware patch tackles a serious SQL injection flaw, underscoring the necessity for quick updates in cybersecurity.

5 snips
Jan 29, 2025 • 6min
SANS ISC Stormcast, Jan 29th 2025: Python Crypto Stealer; SimpleHelp Exploited; Apple Silicon Vuln; Teamviewer Vuln; Odd QR Code
Delve into the world of cybersecurity with discussions on a Python script targeting Exodus wallets, swiftly stealing crypto without saving data. Hear about the exploitation of vulnerabilities in SimpleHelp software, raising alarm for initial network breaches. Explore new side-channel attacks affecting Apple Silicon processors, enabling unauthorized access to sensitive data. The podcast also highlights privilege escalation vulnerabilities in TeamViewer and examines the strange misuse of QR codes in cyber threats.

15 snips
Jan 28, 2025 • 6min
SANS ISC Stormcast, Jan 28th 2025: Z-Shy Phishing; Apple Patches 0-Day; Fortinet Exploit Details; Github and Apache Solr Patches
Discover how cybercriminals are using the 'shy' HTML entity to bypass phishing filters in a cunning new tactic. Apple has rolled out vital patches that address a 0-day vulnerability, bolstering user security. Learn about a serious vulnerability in Fortinet's systems that could be exploited. Plus, hear the latest updates on vulnerabilities in GitHub Desktop and Apache Solr, ensuring you're informed about necessary patches and security measures in the ever-evolving landscape of cybersecurity.

5 snips
Jan 27, 2025 • 6min
SANS ISC Stormcast, Jan 27, 2025: Access Brokers; Llama Stack Vuln; ESXi SSH Tunnels; Zyxel Boot Loops; Subary StarLeak
Cybercriminals are using access brokers to maintain a persistent grip on compromised networks, raising significant security concerns. A critical vulnerability in Meta's Llama Stack highlights the need for robust mitigation strategies. The discussion also covers how to defend against ESXi ransomware and the importance of SSH tunneling. Additionally, a flaw in Subaru's Starlink system puts vehicles at risk of remote hacking, prompting urgent resolution measures. Tune in for insights on these pressing cybersecurity issues!

7 snips
Jan 24, 2025 • 15min
SANS ISC Stormcast, Jan 24, 2025: XSS in Email, SonicWall Exploited; Cisco Vulnerablities; AI and SOAR (@sans_edu research paper by Anthony Russo)
In this discussion, Anthony Russo, U.S. team lead for security operations at Atlassian, shares insights on using AI for SOAR platforms. He highlights recent XSS attacks targeting webmail and the essential patches from SonicWall and Cisco to address critical vulnerabilities. Russo also delves into the integration of AI in automating security operations and the potential of large language models like ChatGPT in enhancing cybersecurity. However, he stresses the importance of understanding AI limitations and ensuring effective automation.

5 snips
Jan 22, 2025 • 8min
SANS ISC Stormcast, Jan 23, 2025: PFSync Protocol; Oracle CPU; Korean VPN Supply Chain Attack; Ivanti Guidance
Discover the intricacies of the PFSync protocol, crucial for synchronizing firewall states during failover scenarios. Delve into Oracle's latest critical patch release that targets multiple vulnerabilities. Uncover a sophisticated supply chain attack on a Korean VPN service, revealing significant security implications. Explore the challenges of VPN configuration and the urgent need for enhanced security measures regarding Ivanti. Stay informed with effective strategies to protect critical infrastructure from emerging threats.

4 snips
Jan 22, 2025 • 9min
SANS ISC Stormcast, Jan 22, 2025: Geolocation via Starlink and Cloudflare; AI Prompt Risks; Homebrew Phishing
Explore the unsettling geolocation risks for Starlink users, revealing how satellite internet could expose sensitive data. Learn about Cloudflare's role in potentially deanonymizing individuals by tracking cached content. Delve into alarming incidents where AI assistants leak confidential customer information due to careless prompts. Finally, discover the rising threat of phishing attacks targeting Mac users, underscoring the urgent need for better data protection and user training.


