SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) cover image

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Latest episodes

undefined
Feb 27, 2025 • 7min

SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;

Discover the hidden risks of ephemeral ports as attackers use them to exfiltrate data, prompting the need for vigilant traffic monitoring. A compromised Visual Studio Code theme has alarmingly reached millions, with its exact malicious intent still under wraps. The shocking theft at ByBit reveals how a compromised developer workstation can lead to monumental losses. Additionally, a vulnerability in NAKIVO backup systems sparks concerns as a proof of concept exploit surfaces, catching the cyber world off guard.
undefined
Feb 26, 2025 • 6min

SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps

A massive botnet is targeting Microsoft 365 accounts using stolen credentials from infostealer malware, highlighting the urgency for better authentication methods. Misconfigurations in OpenID pose significant security risks, allowing private keys to accidentally be exposed. Additionally, patients downloading DICOM image viewers are tricked into installing malware, raising alarms about deceptive practices in the healthcare sector. These discussions emphasize the need for vigilance and improved security measures across digital platforms.
undefined
Feb 25, 2025 • 6min

SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln

Discover the latest Unfurl update that improves URL decoding and timestamp management. Learn how Google is phasing out SMS for GMail, opting for Passkeys instead. Beware of new PayPal phishing tactics that exploit legitimate emails. The podcast also covers vulnerabilities in mail servers, including a serious Exim SQL injection flaw and a newly discovered 0-day in Parallels. Stay informed about evolving cyber threats and enhance your security awareness!
undefined
4 snips
Feb 24, 2025 • 5min

SANS Stormcast Monday Feb 24th: sigs.py update; Google Introdusing Quantum Safe Sigs; MSFT Update Win 11 issues; LTE/5G Vulns;

Discover the latest advancements in cybersecurity tools, including the innovative sigs.py for hash verification. Google introduces quantum-safe digital signatures in its cloud key management, marking a significant shift in security. The conversation also delves into recent issues with Windows 11 updates affecting file usability. Finally, researchers raise alarms about numerous vulnerabilities in 5G and LTE networks, underlining the urgent need for enhanced security in our digital infrastructure.
undefined
8 snips
Feb 21, 2025 • 12min

SANS Stormcast Friday Feb 21st: Kibana Queries; Mongoose Injection; U-Boot Flaws; Unifi Protect Camera Vulnerabilities; Protecting Network Devices as Endpoint (Austin Clark @sans_edu)

Discover how to leverage ES|QL in Kibana for querying DShield honeypot logs effectively. Dive into the vulnerabilities of Mongoose leading to potential MongoDB exploits. Uncover the issues within the U-Boot open-source bootloader that could allow malicious code execution. Learn about key updates to Unifi Protect Cameras that address security risks. Lastly, explore innovative ways to treat network devices as endpoints, enhancing detection and privilege management to bolster cybersecurity.
undefined
4 snips
Feb 20, 2025 • 7min

SANS Stormcast Wednesday Feb 20th: XWorm Cocktail; Quantum Computing Breakthrough; Signal Phishing

Dive into the world of cybersecurity with a look at XWorm, a tricky malware disguised as anti-cheat software, packed with malicious PowerShell code. Discover Microsoft's revolutionary Majorana 1 chip, paving the way for stable, low-error quantum computing. Also, learn about the vulnerabilities in the popular Signal messaging app, where QR codes could compromise user accounts, and how Russian actors are exploiting this for phishing attacks. It's a cybersecurity rollercoaster you won't want to miss!
undefined
Feb 19, 2025 • 7min

SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability

Discover how ModelScan combats deserialization attacks on AI models, ensuring safety against malicious code. Learn about critical vulnerabilities in OpenSSH that could lead to server impersonation, emphasizing the importance of timely updates. Juniper fixes significant authentication bypass issues, while Dell addresses privilege escalation in BIOS across its product line. Each topic highlights the ongoing battle to secure our digital landscape.
undefined
5 snips
Feb 18, 2025 • 5min

SANS Stormcast: Securing the Edge; PostgreSQL Exploit; Ivanti Exploit; WinZip Vulnerablity; Xerox Patch

Dive into essential strategies for securing edge devices as vulnerabilities grow. Explore the PostgreSQL exploit and the alarming exploitation of Ivanti Connect Secure. The discussion also covers a recently patched WinZip buffer overflow threat that could be triggered by malicious files. Plus, learn about critical patches for Xerox printers that address vulnerabilities potentially allowing lateral movement. Stay informed and protect your network from emerging cyber threats!
undefined
5 snips
Feb 17, 2025 • 9min

SANS Stormcast Monday Feb 17th: Fake BSOD; Volatile IPs; Postgresql libpq SQL Injection; OAUTH Phishing

A malicious Python script is creating fake blue screens of death, possibly to trick users into calling support scams. The importance of managing volatile IP addresses is emphasized, as mismanagement can lead to serious security risks. A critical SQL injection vulnerability in PostgreSQL’s libpq functions is detailed, exposing systems to potential breaches. Finally, the podcast explores how Russian threat actors are exploiting OAuth device code authentication through phishing attacks, highlighting the need for increased user awareness and security measures.
undefined
Feb 14, 2025 • 6min

SANS Stormcast Feb 14th 2025: DShield Honeypot SIEM; PAN OS Auth Bypass; Salt Typhone vs. Cisco; Crowdstrike Patch

Explore the fascinating world of honeypots with insights on new SIEM dashboards that summarize attack data. Discover the recently patched vulnerability in Palo Alto Networks' devices that could lead to authentication bypass. Learn how China's Volt Typhoon group exploits older Cisco vulnerabilities for telecom attacks. Plus, find out about the latest security patches from Crowdstrike for their Linux client. A deep dive into pressing cybersecurity topics that keep professionals on their toes.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app