Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.
May 03, 2024ISC StormCast for Friday, May 3rd, 2024https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890 Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796 Buffer Overflow Vulnerabilities in ArubaOShttps://www.arubanetworks.com/support-services/security-bulletins/ The Cuttlefish Malwarehttps://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/...more6minPlay
May 02, 2024ISC StormCast for Thursday, May 2nd, 2024Linux Trojan - Xorddos with Filename eyshcjdmzghttps://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880 AWS S3 Denial of Wallet Amplification Attackhttps://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d EU iOS Safari Allows User Trackinghttps://www.mysk.blog/2024/04/28/safari-tracking/ BentoML Critical Deserialization Vuln CVE-2024-2912https://nvd.nist.gov/vuln/detail/CVE-2024-2912...more7minPlay
May 02, 2024ISC StormCast for Thursday, May 2nd, 2024Linux Trojan - Xorddos with Filename eyshcjdmzghttps://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880 AWS S3 Denial of Wallet Amplification Attackhttps://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d EU iOS Safari Allows User Trackinghttps://www.mysk.blog/2024/04/28/safari-tracking/ BentoML Critical Deserialization Vuln CVE-2024-2912https://nvd.nist.gov/vuln/detail/CVE-2024-2912...more7minPlay
May 01, 2024ISC StormCast for Wednesday, May 1st, 2024Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884 R-Bitrary Code Execution: Vulnearbility in R's Deserializationhttps://hiddenlayer.com/research/r-bitrary-code-execution/ Coordinated Docker Hub Attacks using Malicious Repositorieshttps://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/ NVMe-oF/TCP Vulnerabilitieshttps://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller...more7minPlay
May 01, 2024ISC StormCast for Wednesday, May 1st, 2024Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884 R-Bitrary Code Execution: Vulnearbility in R's Deserializationhttps://hiddenlayer.com/research/r-bitrary-code-execution/ Coordinated Docker Hub Attacks using Malicious Repositorieshttps://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/ NVMe-oF/TCP Vulnerabilitieshttps://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller...more7minPlay
April 30, 2024ISC StormCast for Tuesday, April 30th, 2024DLink NAS Exploit Variationhttps://www.qnap.com/en/security-advisory/qsa-24-09 Muddling Meerkat DNS Abusehttps://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/ Android TV Data Leakagehttps://www.youtube.com/watch?v=QiyBXXO8QpAhttps://www.404media.co/android-tvs-can-expose-user-email-inboxes/ SEC522: SANSFIREhttps://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/ SEC522 Demo (requires free account):https://www.sans.org/ondemand/get-demo/316...more7minPlay
April 30, 2024ISC StormCast for Tuesday, April 30th, 2024DLink NAS Exploit Variationhttps://www.qnap.com/en/security-advisory/qsa-24-09 Muddling Meerkat DNS Abusehttps://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/ Android TV Data Leakagehttps://www.youtube.com/watch?v=QiyBXXO8QpAhttps://www.404media.co/android-tvs-can-expose-user-email-inboxes/ SEC522: SANSFIREhttps://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/ SEC522 Demo (requires free account):https://www.sans.org/ondemand/get-demo/316...more7minPlay
April 29, 2024ISC StormCast for Monday, April 29th, 2024Okta warns of increase in credential stuffinghttps://sec.okta.com/blockanonymizers Fake payment cards used by Police in Japanhttps://twitter.com/vxunderground/status/1783522097425211887 Phishing Campaigns Targeting USPShttps://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic Chrome 124 Breaks TLS Handshakehttps://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/...more7minPlay
April 29, 2024ISC StormCast for Monday, April 29th, 2024Okta warns of increase in credential stuffinghttps://sec.okta.com/blockanonymizers Fake payment cards used by Police in Japanhttps://twitter.com/vxunderground/status/1783522097425211887 Phishing Campaigns Targeting USPShttps://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic Chrome 124 Breaks TLS Handshakehttps://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/...more7minPlay
April 26, 2024ISC StormCast for Friday, April 26th, 2024Does it matter if iptables isn't running on my honeypot?https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/ Unplugging PlugX: Singholing the PlugX USB worm botnethttps://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/ pfSense Updateshttps://docs.netgate.com/advisories/index.html GitLab Updateshttps://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/ Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usagehttps://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/...more21minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.