
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Latest episodes

May 21, 2024 • 6min
ISC StormCast for Tuesday, May 21st, 2024
This discussion dives into analyzing MSG files with the innovative tool OliDump. A critical vulnerability in Fluent Bit alerts listeners to serious cloud service risks. The urgency of patching a significant integer input vulnerability affecting multiple services is emphasized. Insights include deep dives into recent vulnerabilities like Fortinet's command injection and Google's Chrome flaw, making clear the necessity for proactive cybersecurity measures.

May 20, 2024 • 6min
ISC StormCast for Monday, May 20th, 2024
Discover the intriguing world of PDF streams as experts explain how to extract JPEGs. Dive into the vulnerabilities haunting QNAP QTS and the critical buffer overflow risks involved. The discussion also highlights pressing issues with Windows 2019 security updates. Learn about the newly identified Dlink vulnerabilities that are being actively exploited and the PoC exploit for Ivanti's CVE 2024-22026, showcasing the need for vigilant patch management in cybersecurity.

May 17, 2024 • 5min
ISC StormCast for Friday, May 17th, 2024
Dive into the world of XML with YQ, a powerful tool making JSON parsing easier. Discover the alarming misuse of Microsoft's Quick Assist in social engineering attacks leading to ransomware. Uncover recent vulnerabilities in Google Chrome that highlight the urgency of software updates. On the security front, learn about an innovative Android feature detecting theft through unique motion patterns. Lastly, a critical Git update addresses serious vulnerabilities, underscoring the risks of untrusted repositories.

May 16, 2024 • 6min
ISC StormCast for Thursday, May 16th, 2024
Dive into the crucial world of cyber security! Discover why multi-factor authentication is a must-have to protect against brute force attacks. Learn about a new vulnerability called SSID confusion that misleads Wi-Fi clients into connecting to the wrong network. The discussion also highlights alarming concerns regarding man-in-the-middle attacks that can compromise FIDO2 security. Secure configurations and unique credentials are emphasized as vital defenses against these emerging threats!

May 15, 2024 • 8min
ISC StormCast for Wednesday, May 15th, 2024
Microsoft's recent updates patch 60 vulnerabilities, including serious security issues. A partnership between tech giants aims to standardize the detection of Bluetooth trackers for enhanced user privacy. Critical vulnerabilities in VMware and updates from Adobe are also discussed, particularly concerning the Black Lotus threat. The podcast highlights the perils of expired security certificates and emphasizes the need for timely updates to ensure secure boot functionality, while detailing specific challenges faced by HP systems.

May 14, 2024 • 6min
ISC StormCast for Tuesday, May 14th, 2024
Exciting discussions include Apple's sweeping updates to macOS and iOS, addressing numerous vulnerabilities, including a significant exploit in older versions. Juniper's insights into their OpenSSH vulnerabilities highlight critical security measures. Additionally, listeners learn about a malicious binary hidden in a Python package that poses a serious risk, making it crucial for developers to stay informed. Tune in for the latest trends and tips in cybersecurity!

May 13, 2024 • 6min
ISC StormCast for Monday, May 13th, 2024
Dive into the vital role of DNS configurations, including a key focus on the importance of the trailing dot. Discover alarming insights about the Black Basta ransomware threat and the necessity of multi-factor authentication. The discussion also unveils recent vulnerabilities impacting healthcare systems, especially concerning ArcServe. Keep up with the latest Chrome patches for zero-day exploits and learn about critical updates for SolarWinds products. Tune in for essential tips to defend against these emerging cybersecurity threats!

May 10, 2024 • 6min
ISC StormCast for Friday, May 10th, 2024
Discover cutting-edge advancements in PDF analysis that streamline data extraction into JSON format. Learn about critical vulnerabilities in F5's Next Central Manager, particularly SQL injection risks. The discussion highlights essential updates from Veeam, stressing the importance of keeping software current to mitigate exploitation risks. Additionally, the removal of vulnerable versions of PuTTY from Citrix's XEN Center raises red flags for cybersecurity professionals. Stay informed about these pressing security developments!

May 9, 2024 • 6min
ISC StormCast for Thursday, May 9th, 2024
Dive into disk vulnerabilities with a focus on Synology NAS systems, emphasizing forensic techniques and data recovery. Gain insights from an RSA panel on the latest AI threats facing election security. Discover the realities of technical debt in security devices, and learn about the growing risks of sextortion. The discussion also highlights the complexities of maintaining a secure online identity in today's increasingly hostile cyber landscape.

May 8, 2024 • 8min
ISC StormCast for Wednesday, May 8th, 2024
Explore the intriguing world of DNS spoofing, particularly involving Comcast, and discover techniques to detect and address these issues. The discussion also delves into recent vulnerabilities in WebLogic and PDF.js, emphasizing the critical need for timely security patches. Tune in for insights that could help safeguard your digital environment!