Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,063 episodes available.
November 20, 2024ISC StormCast for Wednesday, November 20th, 2024Detecting the Presence of a Debugger in Linuxhttps://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450 Palo Alto Patcheshttps://security.paloaltonetworks.com/CVE-2024-0012https://security.paloaltonetworks.com/CVE-2024-9474 VMware vCenter Server Attackshttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e Veritas Enterprise Vault Vulnerabilityhttps://www.veritas.com/support/en_US/security/VTS24-014...more7minPlay
November 19, 2024ISC StormCast for Tuesday, November 19th, 2024Exploit attempts for unpatched Citrix vulnerability CVE-2024-8068/CVE-2024-8069https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US Microsoft Power Pages: Data Exposure Reviewedhttps://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/ Zohocorp ManageEngine ADAudit Plus Vulnerable To SQL Injection Attacks CVE-2024-49574https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html...more6minPlay
November 18, 2024ISC StormCast for Monday, November 18th, 2024Ancient TP-Link Backdoor Discovered by Attackershttps://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442 GitHub Projects Targeted with Malicious Commits To Frame Researchershttps://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/ PaloAlto and Fortinet Vulnerabilitieshttps://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/https://security.paloaltonetworks.com/PAN-SA-2024-0015https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/...more7minPlay
November 13, 2024ISC StormCast for Wednesday, November 13th, 2024Microsoft November 2024 Patch Tuesdayhttps://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438 CISA Top Routinely Exploited Vulnerabilitieshttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a APT Actors Embed Malware within macOS Flutter Applicationshttps://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/...more6minPlay
November 12, 2024ISC StormCast for Tuesday, November 12th, 2024PDF Object Streamshttps://isc.sans.edu/diary/PDF%20Object%20Streams/31430 Mazda Infotainment Vulnerabilitieshttps://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sighthttps://workos.com/blog/ruby-saml-cve-2024-45409 Veeam Backup Enterprise Manager Vulnerabilityhttps://www.veeam.com/kb4682 Security Update for Dell Enterprise SONiC Distribution Vulnerabilitieshttps://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities Easy Access to Information for Conducting Fraudulent Emergency Data Requests Impacts US-Based Companies and Law Enforcement Agencieshttps://www.ic3.gov/CSA/2024/241104.pdf...more7minPlay
November 11, 2024ISC StormCast for Monday, November 11th, 2024zipdump and pkzip recordshttps://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428 Am I Isolatedhttps://github.com/edera-dev/am-i-isolated Locked iPhones Reboothttps://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/https://x.com/naehrdine/status/1854896392797360484 Palo Alto Networks Bulletinhttps://security.paloaltonetworks.com/PAN-SA-2024-0015 D-Link Vulnerabilityhttps://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07...more6minPlay
November 08, 2024ISC StormCast for Friday, November 8th, 2024Steam Account Checker Poisoned with Infostealerhttps://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420 Cisco Ultra Reliable Wireless Backhaul Vulnerabilityhttps://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html Breaking Down Multipart Parsers: File upload validation bypasshttps://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/ Evasive ZIP Concatenation: Trojan Targets Windows Usershttps://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/ Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)https://www.veeam.com/kb4682 SANS Holiday Hack Challengehttps://www.sans.org/mlp/holiday-hack-challenge-2024...more6minPlay
November 07, 2024ISC StormCast for Thursday, November 7th, 2024Insights from August Web Traffic Surgehttps://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/ Talkative Air Fryerhttps://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c Pygmy Goat Malware Reporthttps://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports Apple CVE-2024-44258 PoC Exploithttps://github.com/ifpdz/CVE-2024-44258 HPE Arruba vulnerabilitieshttps://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US...more5minPlay
November 06, 2024ISC StormCast for Wednesday, November 6th, 2024Python RAT with a Nice Screensharing Featurehttps://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414 Android Security Bulletin November 2024https://source.android.com/docs/security/bulletin/2024-11-01 Malware Delivered as Virtual Machinehttps://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/ Fake Docusign Invoiceshttps://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/...more6minPlay
November 05, 2024ISC StormCast for Tuesday, November 5th, 2024Analyzing an Encrypted Phishing PDFhttps://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404 Okta Verify Desktop MFA For Windows Password Less Login CVE-2024-9191https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/ QNAP QuRouter Vulnerability and Patchhttps://www.qnap.com/en/security-advisory/qsa-24-45 From Naptime to Big Sleephttps://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html Authenticated SQL injection vulnerability - ManageEngine ADManager Plus CVE-2024-48878https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html...more5minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,063 episodes available.