Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,018 episodes available.
November 11, 2024ISC StormCast for Monday, November 11th, 2024zipdump and pkzip recordshttps://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428 Am I Isolatedhttps://github.com/edera-dev/am-i-isolated Locked iPhones Reboothttps://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/https://x.com/naehrdine/status/1854896392797360484 Palo Alto Networks Bulletinhttps://security.paloaltonetworks.com/PAN-SA-2024-0015 D-Link Vulnerabilityhttps://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07...more6minPlay
November 08, 2024ISC StormCast for Friday, November 8th, 2024Steam Account Checker Poisoned with Infostealerhttps://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420 Cisco Ultra Reliable Wireless Backhaul Vulnerabilityhttps://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html Breaking Down Multipart Parsers: File upload validation bypasshttps://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/ Evasive ZIP Concatenation: Trojan Targets Windows Usershttps://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/ Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)https://www.veeam.com/kb4682 SANS Holiday Hack Challengehttps://www.sans.org/mlp/holiday-hack-challenge-2024...more6minPlay
November 07, 2024ISC StormCast for Thursday, November 7th, 2024Insights from August Web Traffic Surgehttps://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/ Talkative Air Fryerhttps://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c Pygmy Goat Malware Reporthttps://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports Apple CVE-2024-44258 PoC Exploithttps://github.com/ifpdz/CVE-2024-44258 HPE Arruba vulnerabilitieshttps://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US...more5minPlay
November 06, 2024ISC StormCast for Wednesday, November 6th, 2024Python RAT with a Nice Screensharing Featurehttps://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414 Android Security Bulletin November 2024https://source.android.com/docs/security/bulletin/2024-11-01 Malware Delivered as Virtual Machinehttps://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/ Fake Docusign Invoiceshttps://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/...more6minPlay
November 05, 2024ISC StormCast for Tuesday, November 5th, 2024Analyzing an Encrypted Phishing PDFhttps://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404 Okta Verify Desktop MFA For Windows Password Less Login CVE-2024-9191https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/ QNAP QuRouter Vulnerability and Patchhttps://www.qnap.com/en/security-advisory/qsa-24-45 From Naptime to Big Sleephttps://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html Authenticated SQL injection vulnerability - ManageEngine ADManager Plus CVE-2024-48878https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html...more5minPlay
November 04, 2024ISC StormCast for Monday, November 4th, 2024October Activity with Username chenzilonghttps://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400 qpdf Extracting PDF Streamshttps://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406 Okta bcrypt issuehttps://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5 Synology Vulnerabilitieshttps://www.synology.com/de-de/security/advisory/Synology_SA_24_19https://www.synology.com/de-de/security/advisory/Synology_SA_24_18 Lastpass Fake Reviewshttps://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data...more6minPlay
October 31, 2024ISC StormCast for Thursday, October 31st, 2024Scans for RDP Gatewayshttps://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398 CyberPanel Exploitedhttps://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/ Windows Themes Files Spoofing CVE-2024-38030https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html QNAP Patches CVE-2024-50388, CVE-2024-50387https://www.qnap.com/en/security-advisory/qsa-24-41 Facebook Malvertisinghttps://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/...more6minPlay
October 30, 2024ISC StormCast for Wednesday, October 30th, 2024Critical RCE Vulnerabilty in Cyberpanelhttps://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce Spring WebFlux Vulnerabilityhttps://access.redhat.com/security/cve/cve-2024-38821https://spring.io/security/cve-2024-38821 Inbound SMTP DANE with DNSSEC for Exchange Onlinehttps://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292 HeptaX: Unauthorized RDP Connections for Cyberespionage Operationshttps://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/...more7minPlay
October 29, 2024ISC StormCast for Tuesday, October 29th, 2024Apple Update Everythinghttps://isc.sans.edu/diary/Apple%20Updates%20Everything/31390 Selfcontained HTML Phishing Attachment Using Telegram to Exfiltrate Credentialshttps://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/ ChatGPT-4o Guardrail Jailbreak: Hex Encoding for Writing CVE Exploitshttps://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits...more6minPlay
October 28, 2024ISC StormCast for Monday, October 28th, 2024Two currently (old) exploited Ivanti vulnerabilitieshttps://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384 Arcadyan FMIMG51AX000J (WiFi Alliance) RCE CVE-2024-41992https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/ Okta iOS App Vulnerability CVE-2024-10327https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/ Threat Alert TeamTNT's docker gatling gun campaignhttps://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/...more6minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,018 episodes available.