Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,345 episodes available.
August 27, 2026SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware Who Has Admin Rights in your Entra ID Directory?https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patcheshttps://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerabilityhttps://github.com/joanbono/log4j2-4255-exploithttps://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malwarehttps://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more8minPlay
August 26, 2026SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2; Obfuscating IP Addresses as Hostnameshttps://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280 Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Imageshttps://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/ FTP Banners The New Dead Drop Resolver Delivering Novel RATshttps://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more6minPlay
August 25, 2026SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car DOUBLECUP's PNG Payloadhttps://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274 AliExpress WebAudio fingerprintinghttps://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Expired DMARC Reporting Domain Exposed 86 Domainshttps://www.sh.consulting/blog/abandoned-dmarc-reporting-domain Android Car Malwarehttps://securelist.com/android-head-unit-malware/121106/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more8minPlay
August 24, 2026SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprayshttps://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malwarehttps://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more6minPlay
August 21, 2026SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Le Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenseshttps://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264 Using Microsoft Graph and Powershell - Risk Detection Commandshttps://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266 Keycloak Vulnerabilityhttps://github.com/keycloak/keycloak/issues/51833 https://www.keycloak.org/2026/08/keycloak-2672-released CRYPTOGRAPHIC CONTEXT INJECTION ATTACKhttps://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/ N-able password managerhttps://amibeingpwned.com/blog/solar-winds-part-2-avoided?_sp=75fd154a-e34f-41d0-8624-7c285776c13d.1787263544340 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more8minPlay
August 20, 2026SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers Simple Scans for Cloud Metadata Servicehttps://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuershttps://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more7minPlay
August 19, 2026SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI CoSnitch: When Your AI Assistant Becomes Its Own Whistleblowerhttps://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its websitehttps://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Updatehttps://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryptionhttps://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more9minPlay
August 18, 2026SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM Apple Patches or iOS and macOShttps://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Securityhttps://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memoryhttps://www.usenix.org/system/files/usenixsecurity26-collins.pdf My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more10minPlay
August 17, 2026SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited; macOS Screen Sharing Vulnerability Exploitedhttps://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patchhttps://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Commerce Cloud Vuln Exploitedhttps://x.com/DefusedCyber/status/2088240809355153647 ChainDrop npm Wormhttps://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more6minPlay
August 14, 2026SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AIhttps://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242 CPU Privilege Escalationhttps://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiiihttps://github.com/xoreaxeaxeax/skitter-creek-bath-salts GeoServer Vulnerabilityhttps://x.com/q1uf3ng/status/2087490992723407096 Windows USB Driver Vulnerabilityhttps://x.com/0xedh/status/2085842285481062887 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich...more8minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,345 episodes available.