
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Latest episodes

Dec 12, 2023 • 6min
ISC StormCast for Tuesday, December 12th, 2023
Dive into the importance of sitemap.xml files for penetration testing, revealing how they can expose hidden website vulnerabilities. Learn about the latest critical security updates from Apple that patch various flaws. Discover alarming insights from Black Hat Europe, where researchers uncovered significant vulnerabilities in password managers, showing how malicious apps can compromise user credentials and highlighting the need for better safeguards.

Dec 11, 2023 • 6min
ISC StormCast for Monday, December 11th, 2023
Dive into the world of cybersecurity as unusual IPv6 notations are discussed, revealing their potential for obfuscation. The episode also highlights critical vulnerabilities in Bluetooth technology and the Syrus 4 IoT gateway, which could pose risks to thousands of vehicles. Microsoft Edge's recent security issue gets the spotlight too. Additionally, contributions from interns are acknowledged, showcasing the collaborative spirit in tackling emerging threats in the digital landscape.

Dec 8, 2023 • 6min
ISC StormCast for Friday, December 8th, 2023
Discover the hidden risks associated with 5G technologies and how they can lead to denial of service attacks. Learn about the security threats posed by QR codes and the importance of being vigilant. The discussion also highlights the end of support for Windows 10, urging users to transition to newer systems. Additionally, a critical vulnerability in Apache Struts is uncovered, emphasizing the need for immediate attention to safeguard against potential exploits.

Dec 7, 2023 • 6min
ISC StormCast for Thursday, December 7th, 2023
Delve into the implications of internet scanning, including a new RFC that may enhance attribution for probes. Explore a significant vulnerability in the MLflow machine learning framework, highlighting crucial security practices. The discussion also sheds light on monitoring AWS Secure Token Service usage and recent updates addressing vulnerabilities in Atlassian products. Plus, don’t miss the Holiday Hack Challenge for a fun twist on security awareness!

Dec 6, 2023 • 6min
ISC StormCast for Wednesday, December 6th, 2023
Discover the latest enhancements in Cobalt Strike analysis, particularly the ability to extract runtime configurations from memory. Learn about dangerous ColdFusion exploits and the urgent need for bolstered cybersecurity defenses. The discussion also highlights critical vulnerabilities in Atos Unify OpenScape, focusing on argument injection and privilege escalation risks. Additionally, explore emerging threats related to web shells and unauthorized modifications within communication systems, emphasizing proactive security measures.

Dec 5, 2023 • 6min
ISC StormCast for Tuesday, December 5th, 2023
Delve into the tactics employed by pro-Russian hacktivists, focusing on their exploitation of vulnerabilities in platforms like SharePoint. Discover ICANN's new system designed to notify domain owners of abuses. Plus, catch up on the latest security patches for Android and GitLab, ensuring your digital world remains resilient. This discussion covers critical updates that are shaping the cyber landscape.

Dec 4, 2023 • 6min
ISC StormCast for Monday, December 4th, 2023
Today’s discussion highlights alarming UEFI firmware vulnerabilities that could compromise systems at boot. A clever phishing scam targeting WordPress users is tricking individuals into installing a backdoor plugin. Additionally, Cactus Ransomware has exploited Qlik Sense, raising concerns about data security. The hosts also touched on the importance of patching vulnerabilities, including a recent fix from VMWare. Cybersecurity vigilance is emphasized as threats continue to evolve.

Dec 1, 2023 • 6min
ISC StormCast for Friday, December 1st, 2023
The latest security updates from Apple tackle critical WebKit vulnerabilities that could put devices at risk. An intriguing discussion unfolds around the expansion of the Mirai botnet, highlighted by a prophetic post from an intern. Vulnerabilities discovered in Zyxel's NAS products raise alarms, while recent developments involving SolarWinds invite further scrutiny. Tune in for essential insights into these pressing cybersecurity issues and their implications.

Nov 30, 2023 • 6min
ISC StormCast for Thursday, November 30th, 2023
Dive into the intriguing world of honeypots and their role in cybersecurity. Discover the latest statistics on attack patterns from DShield. Learn about critical vulnerabilities in Arcserve Unified Data Protection and Hikvision products. Uncover the risks posed by prompt injection in various custom GPTs. This discussion will keep you informed and vigilant in a landscape that's constantly evolving.

Nov 29, 2023 • 6min
ISC StormCast for Wednesday, November 29th, 2023
This episode dives into alarming vulnerabilities, including a critical flaw in Microsoft SharePoint that allows attackers to bypass authentication. Pro-Russian hackers are actively scanning for these weak points. The discussion also touches on Microsoft Defender's deprecation and a significant vulnerability affecting Synology devices. Additionally, there's a focus on an Apache Tomcat request smuggling issue, emphasizing the importance of staying updated on security measures.