
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Latest episodes

8 snips
Feb 12, 2025 • 6min
SANS Stormcast Feb 12th 2025: MSFT Patch Tuesday; Adobe Patches; FortiNet Acknowledges Exploitation of FortiOS
This discussion dives into Microsoft's latest Patch Tuesday, unveiling fixes for 55 vulnerabilities, including critical issues with LDAP and Active Directory. Notably, some flaws are already exploited, urging immediate attention. Adobe also steps up with patches for seven products, with a focus on critical Adobe Commerce issues. Finally, Fortinet faces scrutiny as they acknowledge exploitation of a vulnerability in FortiOS, raising concerns about security protocols. It's a critical time for updates in the cybersecurity landscape!

9 snips
Feb 11, 2025 • 7min
SANS Stormcast Feb 11th 2025: 7zip and MoW; Apple 0-Day Fix; AMD Microcode Overwrite; Trimble CityWorks 0-Day; MageCart Update
Explore the critical need for secure file extraction with 7-Zip updates that require the mark of the web. Apple rushes to patch a vulnerability that lets attackers bypass USB restrictions on devices. Meanwhile, a microcode exploit on AMD CPUs raises alarms, manipulating functions and random number generation. Trimble Cityworks falls victim to a newly exploited flaw, while the latest MageCart tactics involve stealthy JavaScript injections stealing credit card data through Google Tag Manager, highlighting the importance of cautious coding practices.

4 snips
Feb 10, 2025 • 7min
SANS Internet Stormcast Feb 10th 2025: Podcast Anniversary; SSL 2.0; Exposed Deepseek Installs; Crypto Scam costs
Celebrate 16 years of cybersecurity insights while discussing the age of SSL 2.0, which turns 30 but still has over 400k hosts exposed. Delve into alarming security flaws in the Chinese Deepseek AI model, highlighting various deficiencies. Learn about the intricacies of dual signature crypto scams, revealing that these wallets actually require financial investment to set up. Join in on a blend of nostalgia and critical reflections on current cybersecurity threats!

7 snips
Feb 7, 2025 • 6min
SANS Internet Stormcast Feb 7th 2025: Unbreakable Anti-Debugging;
Dive into advanced multilayer anti-debugging techniques crafted in Python. Discover alarming malware using OCR to steal information from both Google Play and the Apple App Store. Uncover how legitimate remote management tools like ScreenConnect are being exploited by threat actors. Stay updated on critical vulnerabilities affecting Cisco’s Identity Services Engine and authentication issues in F5’s TLS client certificates. This discussion rounds out with insights on securing remote tools against unauthorized misuse.

5 snips
Feb 6, 2025 • 7min
SANS Internet Stormcast Feb 6th 2025: com- prefix domain phishing; Win 10 ESU pricing; Firefox CT Policy; Veeam and Netgear patches
Learn how scammers are exploiting com- prefix domains to launch convincing phishing attacks, targeting victims with toll fee scams. Microsoft updates pricing for Windows 10 Extended Security Updates, setting a fee for continued protection. Mozilla pushes for better internet security by enforcing certificate transparency measures. Additionally, discover serious vulnerabilities in Veeam's backup process and Netgear's WiFi routers, highlighting the need for rapid updates in cybersecurity.

4 snips
Feb 5, 2025 • 7min
SANS Internet Stormcast Feb 5th 2025: Feed Updates and Rosti; Resurrecting Dead S3 Buckets; Let's Encrypt Changes; Edge Device Security
Updates on data feeds highlight the introduction of the Rosti Feed, while concerns about reviving dead S3 buckets spark intriguing discussions. Let's Encrypt's move to stop sending expiration emails raises questions about certificate management. Meanwhile, new guidelines from CISA focus on fortifying edge devices like firewalls and VPN concentrators, emphasizing the need for vigilance in cybersecurity.

Feb 4, 2025 • 6min
SANS ISC Stormcast Feb 4th 2025: Crypto Scam; Mediatek and D-Link Patches; Microsoft ends VPN Service
Discover how a YouTube spam scam tricks users into losing money on crypto wallet fees, while their private keys remain safe. Learn about critical patches from Mediatek addressing serious vulnerabilities in WLAN products. D-Link faces challenges with older routers that will no longer receive updates, leaving users with the need to upgrade. Finally, Microsoft announces the discontinuation of its VPN service, prompting discussions about online security practices.

8 snips
Feb 3, 2025 • 6min
SANS ISC Stormcast Feb 3rd 2025: Automating Cyber Ranges; Deepseek Scams; PyPi Archived State; Medical Backdoors
Discover the intriguing world of automated cyber ranges and their creation processes. Learn how scammers are capitalizing on the Deepseek hype, leading to malware infections through deceptive sites. Delve into the newly archived status feature on PyPi, signaling the end of maintenance for certain projects. Finally, uncover concerns about a backdoor found in a medical monitoring device, raising alarms in cybersecurity for healthcare. Tune in for insights into modern threats and innovations!

7 snips
Jan 31, 2025 • 6min
SANS ISC Stormcast Jan 31st 2025: Old Netgear Vuln in Depth; Lightning AI RCE; Canon Printer RCE; Deepseek Leak;
Explore the alarming persistence of old vulnerabilities in Netgear routers, still a threat in 2025. Discover a risky remote code execution flaw in the AI platform Lightning AI that could be exploited with just a click. Delve into various vulnerabilities in Canon printers that could lead to significant security breaches. Lastly, learn about the exposure of the Deepseek ClickHouse database and why securing databases is more critical than ever.

6 snips
Jan 30, 2025 • 6min
SANS ISC Stormcast, Jan 30th 2025: Python vs. Powershell; Fortinet Exploits and Patch Policy; Voyager PHP Framework Vuln; Zyxel Targeted; VMWare AVI Patch
The discussion kicks off with a deep dive into devious Python malware that cleverly mimics PDF documents to steal data. A critical Fortinet vulnerability is making rounds on Russian forums, raising alarms over timely patches. The vulnerabilities in the Voyager PHP framework reveal risks like arbitrary file uploads. Active exploitation of unpatched Zyxel devices highlights the ever-present threat landscape. Finally, a VMware patch tackles a serious SQL injection flaw, underscoring the necessity for quick updates in cybersecurity.
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.