Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,063 episodes available.
November 04, 2024ISC StormCast for Monday, November 4th, 2024October Activity with Username chenzilonghttps://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400 qpdf Extracting PDF Streamshttps://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406 Okta bcrypt issuehttps://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5 Synology Vulnerabilitieshttps://www.synology.com/de-de/security/advisory/Synology_SA_24_19https://www.synology.com/de-de/security/advisory/Synology_SA_24_18 Lastpass Fake Reviewshttps://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data...more6minPlay
October 31, 2024ISC StormCast for Thursday, October 31st, 2024Scans for RDP Gatewayshttps://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398 CyberPanel Exploitedhttps://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/ Windows Themes Files Spoofing CVE-2024-38030https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html QNAP Patches CVE-2024-50388, CVE-2024-50387https://www.qnap.com/en/security-advisory/qsa-24-41 Facebook Malvertisinghttps://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/...more6minPlay
October 30, 2024ISC StormCast for Wednesday, October 30th, 2024Critical RCE Vulnerabilty in Cyberpanelhttps://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce Spring WebFlux Vulnerabilityhttps://access.redhat.com/security/cve/cve-2024-38821https://spring.io/security/cve-2024-38821 Inbound SMTP DANE with DNSSEC for Exchange Onlinehttps://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292 HeptaX: Unauthorized RDP Connections for Cyberespionage Operationshttps://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/...more7minPlay
October 29, 2024ISC StormCast for Tuesday, October 29th, 2024Apple Update Everythinghttps://isc.sans.edu/diary/Apple%20Updates%20Everything/31390 Selfcontained HTML Phishing Attachment Using Telegram to Exfiltrate Credentialshttps://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/ ChatGPT-4o Guardrail Jailbreak: Hex Encoding for Writing CVE Exploitshttps://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits...more6minPlay
October 28, 2024ISC StormCast for Monday, October 28th, 2024Two currently (old) exploited Ivanti vulnerabilitieshttps://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384 Arcadyan FMIMG51AX000J (WiFi Alliance) RCE CVE-2024-41992https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/ Okta iOS App Vulnerability CVE-2024-10327https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/ Threat Alert TeamTNT's docker gatling gun campaignhttps://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/...more6minPlay
October 25, 2024ISC StormCast for Friday, October 25th, 2024Development Features Enabled in Productionhttps://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380 Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentialshttps://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/ Cisco Secure Firewall Management Center Software Command Injection Vulnerabilityhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7 Exposing the Danger Within: Hardcoded Cloud Credentials in Popular Mobile Appshttps://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps...more6minPlay
October 24, 2024ISC StormCast for Thursday, October 24th, 2024Everybody Loves Bash Scripts Including Attackershttps://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376 Fortimanager Exploited Vulnerabilityhttps://www.fortiguard.com/psirt/FG-IR-24-423 Sharepoint Exploithttps://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-cataloghttps://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC OpenSSL Vulnerabilityhttps://openssl-library.org/news/secadv/20241016.txt Reduced Certificate Lifetimehttps://github.com/cabforum/servercert/pull/553...more7minPlay
October 23, 2024ISC StormCast for Wednesday, October 23rd, 2024How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372 VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968 Unifi Security Advisory Bulletin 043https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7 Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability.https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability Atlassian Security Bulletin - October 15 2024https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html OneDev Arbitrary file reading for unauthenticated userhttps://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489...more6minPlay
October 22, 2024ISC StormCast for Tuesday, October 22nd, 2024A Network Nerd's Take on Emergency Preparednesshttps://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356 HM Surf Vulnerability Access to Camera Exploited CVE-2024-44133https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/ Fortinet releases patches for undisclosed critical FortiManager vulnerabilityhttps://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/ ScienceLogic Vulnerabilityhttps://rackspace.service-now.com/system_status?id=detailed_status&service=4dafca5a87f41610568b206f8bbb35a6https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm...more7minPlay
October 21, 2024ISC StormCast for Monday, October 21st, 2024Microsoft 365: Partially incomplete log data due to monitoring agent issuehttps://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/ End-to-End Encrytped Cloud Storage in the Wild: A Broken Ecosystemhttps://brokencloudstorage.info/paper.pdf ESET Branded Malwarehttps://x.com/ESETresearch/status/1847192384448172387 Synology Updatehttps://www.synology.com/en-us/security/advisory/Synology_SA_24_17 Spring Framework Update CVe-2024-38819 CVE-2024-38820https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published Grafana Security Release CVE-2024-9264https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/...more6minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,063 episodes available.