SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Apr 8, 2024 • 5min

ISC StormCast for Monday, April 8th, 2024

The podcast dives into the 10th anniversary of Heartbleed, reflecting on its impact on open-source security and the importance of funding bug bounties. It highlights recent vulnerabilities like the Magento XML backdoor and challenges in e-commerce security posed by malicious injections. Additionally, it addresses the ongoing threat of DNS cache poisoning and identifies a remote code execution vulnerability in Brocade Fabric OS. Stay tuned for updates on upcoming security talks in London!
undefined
Apr 5, 2024 • 15min

ISC StormCast for Friday, April 5th, 2024

Dan Mazzella, a researcher specializing in infostealers and malware techniques for automotive systems, joins the discussion to reveal alarming trends in automotive cybersecurity. He highlights the rising threat of information-stealing malware targeting car head units, shifting the focus from traditional safety vulnerabilities to data privacy concerns in IoT devices. Mazzella also explores the privacy implications of accessing sensitive information through infotainment systems and urges caution when connecting personal devices to unknown vehicles, emphasizing the need for heightened security awareness.
undefined
Apr 4, 2024 • 6min

ISC StormCast for Thursday, April 4th, 2024

Discover the intriguing world of SSH traffic and what it reveals about security threats. Google introduces a novel approach with Device Bound Session Credentials to combat cookie theft. The discussion also highlights four critical vulnerabilities in Ivanti software, including heap overflows and XML entity expansion issues. Additionally, there’s buzz around a Google Pixel zero-day vulnerability, shedding light on the ongoing challenges in mobile security.
undefined
Apr 3, 2024 • 6min

ISC StormCast for Wednesday, April 3rd, 2024

Unpack the latest privacy issues surrounding Google Chrome's incognito mode and a hefty settlement over data practices. Discover new email security protocols set to strengthen spam management in Gmail. Dive into critical vulnerabilities with Cisco updates and learn about the latest security fixes for Apache Pulsar and Flowmon. Stay informed on best practices for email compliance to keep your network safe. Tune in for a special segment with insights from industry expert Bojan Zdrnja.
undefined
Apr 2, 2024 • 7min

ISC StormCast for Tuesday, April 2nd, 2024

Explore the chilling details of a backdoor in xz-utils that poses serious security risks. Learn about infostealers threatening macOS users and the rise of malicious browser downloads disguised as Chrome. Discover a new tool for analyzing CSV files amid these cybersecurity threats. The podcast also highlights suspicious social media behaviors linked to compromised repositories.
undefined
Apr 1, 2024 • 8min

ISC StormCast for Monday, April 1st, 2024

A serious backdoor vulnerability has been discovered in the XC utils package, raising concerns for users of the x86-64 architecture. Experts dive deep into the technical details and potential impact of this flaw. They also discuss social engineering attempts to incorporate backdoors into software distributions, highlighting the importance of cybersecurity vigilance. The conversation emphasizes necessary precautions and the broader implications for software security in today’s landscape.
undefined
Mar 29, 2024 • 6min

ISC StormCast for Friday, March 29th, 2024

Dive into the intricate world of obfuscated malware, where JavaScript masks a remote access Trojan as an innocent invoice. Discover critical patches for TeamCity that safeguard against serious vulnerabilities. Learn about alarming exploits in Okta Verify for Windows, allowing arbitrary code execution. Explore the worrying rise of zero-day vulnerabilities that pose major threats to enterprise systems and a spotlight on the expanding risks from commercial surveillance vendors.
undefined
Mar 28, 2024 • 5min

ISC StormCast for Thursday, March 28th, 2024

The discussion delves into serious security vulnerabilities in Apache OFBiz, which could allow remote code execution by hackers. It also highlights flaws in the Unix 'wall' command that may enable unauthorized message disclosure. Additionally, the podcast addresses alarming trends in 'MFA Bombing' attacks targeting Apple users, shedding light on how these attacks exploit users' authentication fatigue. Security strategies to combat these threats are recommended, enhancing safeguarding measures.
undefined
Mar 27, 2024 • 6min

ISC StormCast for Wednesday, March 27th, 2024

A new tool simplifies forensic analysis on Linux systems, making investigations more efficient. There's a deep dive into a suspicious NuGet package that targets industrial systems. The podcast reveals alarming ShadowRay attacks on AI workloads currently exploited in the wild. Additionally, TheMoon malware is wreaking havoc by infecting thousands of ASUS routers for proxy services. Finally, the conversation covers vulnerabilities in the QUIC protocol and persistent malware threats in the cybersecurity landscape.
undefined
Mar 26, 2024 • 6min

ISC StormCast for Tuesday, March 26th, 2024

Discover the latest updates on cybersecurity tools that enhance network protection and process IP addresses efficiently. Apple rolls out urgent patches for critical vulnerabilities affecting macOS and iOS. A concerning hack targeting GitHub has affected around 150,000 developers, illustrating the importance of vigilance. Plus, hear about crucial fixes in OpenVPN that highlight the necessity of keeping software up to date. Stay informed and secure in the ever-evolving world of cybersecurity!

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app