Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,243 episodes available.
April 09, 2026SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln; Honeypot Fingerprintinghttps://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878 Microsoft Locks Accounts for Privacy/Encryption Related Developershttps://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/ https://news.ycombinator.com/item?id=47687884 https://x.com/windscribecom/status/2041929519628443943https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/ Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/...more8minPlay
April 08, 2026SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874 WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UIhttps://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009 Project Glasswinghttps://www.anthropic.com/glasswing Current Threats Against Kuberneteshttps://unit42.paloaltonetworks.com/modern-kubernetes-threats/...more7minPlay
April 07, 2026SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass How often are redirects used in phishing in 2026?https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870 Hackerone Suspends Internet Bug Bountyhttps://hackerone.com/ibb?type=teamhttps://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/ Bluehammer Windows 0-day Privilege Escalationhttps://github.com/Nightmare-Eclipse/BlueHammerhttps://deadeclipse666.blogspot.com/2026/04/public-disclosure.htmlhttps://deepwiki.com/Nightmare-Eclipse/BlueHammer Keycloak MFA Bypass CVE-2026-3429https://access.redhat.com/security/cve/cve-2026-3429...more7minPlay
April 06, 2026SANS Stormcast Monday, April 6th, 2026: TeamPCP Update and Axio Post Mortem; Fortinet 0-Day Team PCP Update and Axios Post Mortemhttps://isc.sans.edu/diary/32864https://github.com/axios/axios/issues/10636 Strapi NPM Packages Compromisedhttps://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/ Fortinet CVE-2026-35616 exctively exploitedhttps://fortiguard.fortinet.com/psirt/FG-IR-26-099...more7minPlay
April 03, 2026SANS Stormcast Friday, April 3rd, 2026: Vite Exploits; OpenSSH 10.3; Claude Code Vuln Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860 OpenSSH 10.3 Releasehttps://seclists.org/oss-sec/2026/q2/7 Claude Code Vulnerabilityhttps://adversa.ai/claude-code-security-bypass-deny-rules-disabled/...more6minPlay
April 02, 2026SANS Stormcast Thursday, April 2nd, 2026: Script Removing ADS/MotW; Google Chrome 0-Day; iOS/iPadOS 18 Update; Malicious Script That Gets Rid of ADShttps://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854 Google Chrome Update fixes 21 Vulnerabilities and 0-Dayhttps://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html Apple Addresses Darksword Vulnerabilities for older deviceshttps://support.apple.com/en-us/126793...more5minPlay
April 01, 2026SANS Stormcast Wednesday, April 1st, 2026: Application Control Bypass; Axios NPM Module Compromise; TeamPCP vs Cloud Application Control Bypass for Data Exfiltrationhttps://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850 Axios NPM Module Supply Chain Compromisehttps://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojanhttps://www.linkedin.com/events/7444763050819092480/ TeamPCP vs. Cloud Resourceshttps://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild...more7minPlay
March 31, 2026SANS Stormcast Tuesday, March 31st, 2026: Honeypot Session Lifetime; Let’s Encrypt Tests Mass Revocation; F5 RCE Exploited Honeypot Session Lifetimehttps://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840 Let s Encrypt Tests Mass Revocationhttps://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960https://www.certkit.io/blog/ari-solves-mass-certificate-revocationhttps://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation F5 Vulnerability Re-Classified (and already exploited) as RCEhttps://my.f5.com/manage/s/article/K000156741...more6minPlay
March 30, 2026SANS Stormcast Monday, March 30th, 2026: More TeamPCP: telnyx; Netscaler Exploit; macOS ClickFix Fix; Windows Smart Install TeamPCP Update #2: Telnyx PyPi Compromisehttps://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838 Citrix Netscaler Vulnerability Detailshttps://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/ macOS Clickfix Warninghttps://x.com/ClassicII_MrMac/status/2036797948911141129 Windows Smart Installhttps://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/...more9minPlay
March 27, 2026SANS Stormcast Friday, March 27th, 2026: TeamPCP Update; DarkSword vs Patches; LangFlow Exploited TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Availablehttps://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834 DarkSword and This Weeks iOS Updateshttps://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain LangFlow Exploitedhttps://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog...more7minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,243 episodes available.