Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,350 episodes available.
April 21, 2026SANS Stormcast Tuesday, April 21st, 2026: CVE and EPSS; Windows Server 2025 OOB; QEMU Abuse; Handling the CVE Flood With EPSShttps://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914 Windows Server 2025 Out of Band Patchhttps://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835 QEMU abused to evade detection and enable ransomware deliveryhttps://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery...more6minPlay
April 20, 2026SANS Stormcast Monday, April 20th, 2026: Lumma Stealer and Sectop RAT; Windows 0-Day Exploited; NIST NVD Update; FortiSandbox PoC Lumma Stealer infection with Sectop RAT (ArechClient2)https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904 Three Recent Windows Defender Vulnerabilities Exploited (one 0-day)https://x.com/HuntressLabs/status/2044882115574091960 FortiSandbox PoC Exploit CVE-2026-39808https://github.com/samu-delucas/CVE-2026-39808?tab=readme-ov-file NIST Updates NVD Operations to Address Record CVE Growthhttps://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth...more7minPlay
April 17, 2026SANS Stormcast Friday, April 17th, 2026: DVRs Again; Cisco Again; Windows Defender Again; Sonatype Compromised DVRs and Finding Them in the Wildhttps://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886 Cisco ISE RCE Vulnerability and WebEx Auth Bypass CVE-2026-20184 CVE-2026-20180 CVE-2026-20186https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepvhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL Windows Defender 0-Day (RedSun)https://github.com/Nightmare-Eclipse/RedSun Sonatype Vulnerability CVE-2026-5189https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15...more6minPlay
April 16, 2026SANS Stormcast Thursday, April 16th, 2026: AI Credential Scans; Microsoft Update Issues; RDP Warnings; GitHub Action Vulns; Scanning for AI Modelshttps://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896 Microsoft Update Problemshttps://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update Microsoft RDP File Warningshttps://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings AI GitHub Action Vulnerabilitieshttps://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/ Wireguard Updatehttps://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html...more7minPlay
April 15, 2026SANS Stormcast Wednesday, April 15th, 2026: Microsoft, Adobe, Fortinet and others Patches Microsoft Patch Tuesday April 2026https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/ Adobe Patcheshttps://helpx.adobe.com/security/Home.html Fortinet Patcheshttps://fortiguard.fortinet.com/psirt...more9minPlay
April 14, 2026SANS Stormcast Tuesday, April 14th, 2026: EncystPHP Webshell; CPUID Compromise; OpenAI Mac Cert Issue; Axios Vulnerability Scans for EncystPHP Webshellhttps://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892 CPUID Compromisehttps://securelist.com/tr/cpu-z/119365/https://x.com/d0cTB/status/2042520961824559150 OpenAI Mac Application Update due to Axios Compromisehttps://openai.com/index/axios-developer-tool-compromise/ Axios Vulnerability CVE-2026-40175https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx...more7minPlay
April 13, 2026SANS Stormcast Monday, April 13th, 2026: Obfuscated JavaScript; Numbers in Passwords; Adobe Patches 0-Day; ClickFix Fix Bypass Obfuscated JavaScript or Nothinghttps://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884 Numbers in Passwordshttps://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866 Adobe 0-Day Patch CVE-2026-34621https://helpx.adobe.com/security/products/acrobat/apsb26-43.html ClickFix Bypass via ScriptEditorhttps://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/...more7minPlay
April 09, 2026SANS Stormcast Thursday, April 9th, 2026: Honeypot Fingerprinting; Microsoft Locks Developer Accounts; ActiveMQ Vuln; Honeypot Fingerprintinghttps://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878 Microsoft Locks Accounts for Privacy/Encryption Related Developershttps://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/ https://news.ycombinator.com/item?id=47687884 https://x.com/windscribecom/status/2041929519628443943https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/ Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/...more8minPlay
April 08, 2026SANS Stormcast Wednesday, April 8th, 2026: Pivoting for Webshells; WatchGuard Firebox Patch; Project Glasswing; Kubernetes Misconfigurations A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874 WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UIhttps://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009 Project Glasswinghttps://www.anthropic.com/glasswing Current Threats Against Kuberneteshttps://unit42.paloaltonetworks.com/modern-kubernetes-threats/...more7minPlay
April 07, 2026SANS Stormcast Tuesday, April 7th, 2026: Redirects in Phishing; Internet Bug Bounty Suspended; Bluehammer; Keycloak MFA Bypass How often are redirects used in phishing in 2026?https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870 Hackerone Suspends Internet Bug Bountyhttps://hackerone.com/ibb?type=teamhttps://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/ Bluehammer Windows 0-day Privilege Escalationhttps://github.com/Nightmare-Eclipse/BlueHammerhttps://deadeclipse666.blogspot.com/2026/04/public-disclosure.htmlhttps://deepwiki.com/Nightmare-Eclipse/BlueHammer Keycloak MFA Bypass CVE-2026-3429https://access.redhat.com/security/cve/cve-2026-3429...more7minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,350 episodes available.