
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Latest episodes

Nov 28, 2023 • 7min
ISC StormCast for Tuesday, November 28th, 2023
A critical vulnerability in the OwnCloud file sharing system could let attackers execute arbitrary code, prompting urgent protective measures. Meanwhile, security flaws in Windows Hello's fingerprint authentication system raise concerns, as manipulations of stored fingerprints could be exploited. Brands like Dell, Lenovo, and Microsoft are under scrutiny as research into these weaknesses expands, highlighting the need for improved security in biometric systems.

Nov 27, 2023 • 6min
ISC StormCast for Monday, November 27th, 2023
A celebration of DShield's birthday kicks off the discussion, highlighting community achievements. The dangers of the Mirai botnet are explored, including a new vulnerability that could expand its reach. Insights into router firmware vulnerabilities reveal alarming exploitation trends. The potential risks of exposing network video recorders are examined, along with tips for better patch management. Lastly, vulnerabilities in virtual machine files and a static code injection issue in OpenCart are dissected, with a call to action for the SANS holiday hack challenge!

Nov 17, 2023 • 15min
ISC StormCast for Friday, November 17th, 2023
Explore how to optimize tcpdump performance for faster data processing. Discover the alarming rise of a Zimbra 0-day exploit targeting governments. Delve into AI's role in cataloging cybersecurity vulnerabilities, and learn about a critical FortiSIEM command injection vulnerability. The challenges of managing vast cybersecurity data surface, along with innovative solutions for enhanced analytics. Finally, uncover strategies for efficient data onboarding while addressing storage costs, all with insights from the upcoming Thanksgiving holiday.

Nov 16, 2023 • 6min
ISC StormCast for Thursday, November 16th, 2023
Dive into the alarming world of malware as a new threat infiltrates systems through MSI packages, masquerading as harmless JPEGs. Uncover vulnerabilities in the ChatGPT code interpreter, revealing security flaws that could be exploited. The episode also highlights critical directory traversal vulnerabilities in Reactor Netty and discusses serious security concerns affecting Aruba networking products. Stay informed about these pressing cybersecurity issues to better protect your systems.

Nov 15, 2023 • 7min
ISC StormCast for Wednesday, November 15th, 2023
This episode dives into Microsoft and Adobe's recent security patches, addressing 64 vulnerabilities, including critical flaws in Chromium, Edge, and Microsoft Office. The discussion highlights the importance of timely updates to maintain security. Additionally, a spotlight is placed on Intel's microcode update designed to tackle processor vulnerabilities, showcasing the ongoing battle against cybersecurity threats.

Nov 14, 2023 • 5min
ISC StormCast for Tuesday, November 14th, 2023
Explore how DNS logs can reveal command and control channels used by attackers. Learn about serious vulnerabilities in SSH that could compromise security. Delve into the risks of faulty signatures in RSA algorithms and their effects on secret key protection. The importance of updating server secret keys and engaging clients in new security measures is also emphasized. Additionally, discover how recent Juniper vulnerabilities have been exploited, potentially leading to remote code execution.

Nov 13, 2023 • 6min
ISC StormCast for Monday, November 13th, 2023
Recent talks highlight the Gafgyt botnet targeting routers, stressing the importance of updated firmware and strong passwords. Healthcare systems are under attack, showcasing vulnerabilities linked to third-party vendors. Additionally, North Korea's Sapphire Sleet is on the prowl, using fake job portals to exploit developers. Insights into OpenVPN Access Server vulnerabilities remind us that staying informed is crucial in this ever-evolving cyber landscape.

Nov 10, 2023 • 5min
ISC StormCast for Friday, November 10th, 2023
Discover the dark world of code injection as experts reveal how vulnerabilities can be exploited in Windows systems. Learn about the alarming tactics of the CLOP ransomware gang, highlighting the urgent need for software updates. Stay informed with critical cybersecurity updates, including a significant fix for WS FTP and a warning about a malvertising campaign posing risks. Plus, don’t overlook the vulnerabilities linked to Apache Arrow involving the PyError Python module. It's a must-listen for anyone interested in cyber safety.

Nov 9, 2023 • 5min
ISC StormCast for Thursday, November 9th, 2023
Discover the chilling world of phishing campaigns, where attackers cleverly disguise their tactics to mimic legitimate marketing. Uncover the vulnerabilities in Azure Automation Services that allowed cryptocurrency miners to exploit systems through faulty Python script management. Also, learn about the latest security enhancements in Windows 11, including crucial updates to SMB and NTLM protocols, as well as a newly identified vulnerability that could jeopardize network security.

Nov 8, 2023 • 6min
ISC StormCast for Wednesday, November 8th, 2023
Discover the new world of DNS with designated resolvers and their implications for security and privacy. Learn about BlueNoroff, a malware targeting macOS users in cryptocurrency scams. Dive into Microsoft's advanced Authenticator features designed to enhance security by default. Join the conversation about the evolving landscape of cybersecurity and share your own experiences for a richer community interaction.