SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Mar 25, 2024 • 6min

ISC StormCast for Monday, March 25th, 2024

Discover enhancements in Cobalt Strike beacons that boost incident response capabilities. Dive into a novel UDP-based attack affecting application layers, causing endless response loops. Uncover vulnerabilities in network protocols tied to DNS error messages that can create infinite loops. Learn how these issues impact major vendors like Cisco and Microsoft, alongside key security patches aimed at fixing memory leaks in Windows servers.
undefined
Mar 22, 2024 • 6min

ISC StormCast for Friday, March 22nd, 2024

Delve into the world of geolocation data and the significance of Geofeed in WHOIS records. Discover Apple's latest security updates and a new bug that could affect users. Explore GitHub's innovative AutoFix feature, powered by AI, designed to streamline code corrections. Lastly, get the scoop on vulnerabilities found in Fortinet and Ivanti products, detailing potential risks and necessary precautions. This episode is a must-listen for anyone interested in the latest in cybersecurity!
undefined
Mar 21, 2024 • 6min

ISC StormCast for Thursday, March 21st, 2024

Discover the details of a new buffer overflow vulnerability in Fortinet devices that's making waves in the cyber world. As tax season approaches, find out how scammers are ramping up phishing attacks, particularly targeting unsuspecting users. The discussion also sheds light on the exploitation risks linked to DHCP server configurations, raising awareness about potential privilege escalation in Windows domains. Stay informed and prepared to tackle these pressing cybersecurity challenges!
undefined
Mar 20, 2024 • 5min

ISC StormCast for Wednesday, March 20th, 2024

Delve into the alarming tactics of attackers targeting firewall vulnerabilities and the evolving cybersecurity landscape. Discover a newly uncovered exploit that raises concerns, paralleled by a surge in crypto scams highlighted by the FBI. Also discussed are the compatibility issues and software troubles following the recent macOS 14.4 update. Stay informed about these pressing cybersecurity challenges!
undefined
Mar 19, 2024 • 5min

ISC StormCast for Tuesday, March 19th, 2024

Microsoft's plan to phase out 1024-bit RSA keys sparks a discussion on online security standards. Google enhances its Chrome browser with real-time safe browsing, raising privacy concerns. The spotlight shifts to critical vulnerabilities, like those in Fortra's FileCatalyst and Spring Security, emphasizing the need for immediate patching. Additionally, TrendNet routers face their own security issues, prompting a call for vigilance in cybersecurity practices.
undefined
Mar 18, 2024 • 7min

ISC StormCast for Monday, March 18th, 2024

The discussion highlights a revisitation of the 5G Huler vulnerabilities, exposing ongoing risks from outdated Android firmware. It dives into OAuth issues linked to ChatGPT plugins, showcasing how they can compromise account security. The latest threat detection report from RedCanary unveils emerging IT threats. Additionally, new guidelines on certificate revocation bring critical updates for cybersecurity professionals. This blend of insights helps listeners stay informed about vital trends and vulnerabilities in the digital landscape.
undefined
Mar 15, 2024 • 21min

ISC StormCast for Friday, March 15th, 2024

There's a surge in phishing attacks targeting IPFS and R2 buckets, making traditional blocking methods less effective. Critical vulnerabilities in Fortinet and Arcserve are highlighted, urging prompt security updates. A student shares insights on monitoring PLCs for industrial control systems, revealing the complexities in their operational modes and security risks. The discussion extends to the challenges of firmware updates in essential networks and the potential of AI tools for improving incident detection and managing code vulnerabilities.
undefined
Mar 14, 2024 • 5min

ISC StormCast for Thursday, March 14th, 2024

Discover how ChatGPT can help deobfuscate malicious scripts, enhancing cybersecurity defenses. Dive into critical vulnerabilities affecting Fortinet and Adobe, highlighting the need for stronger authentication methods. Learn about a troubling command injection vulnerability in Kubernetes that could give attackers system privileges. It's a blend of AI innovation and pressing security concerns that no tech enthusiast should miss!
undefined
Mar 13, 2024 • 6min

ISC StormCast for Wednesday, March 13th, 2024

Microsoft's latest Patch Tuesday tackles 60 vulnerabilities, with critical updates that could affect Hyper-V. The discussion also touches on the potential decline of the National Vulnerability Database. Notably, there’s a serious unrestricted file upload vulnerability in ManageEngine Desktop Central. Additionally, recent updates to Siemens fire protection systems are highlighted, showcasing the importance of staying on top of cybersecurity threats.
undefined
Mar 12, 2024 • 6min

ISC StormCast for Tuesday, March 12th, 2024

Leaking AWS API keys can lead to rapid exploitation, highlighting the critical need for vigilance in securing sensitive information. The rise of crypto imposters using Calendly to spread malware on Macs is a concerning trend. Misconfigurations in tools like Microsoft Configuration Manager are also addressed, showcasing the importance of proper security practices. The discussion underscores the urgency for both individuals and organizations to stay informed about these threats to maintain their cybersecurity.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app