Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.
April 26, 2024ISC StormCast for Friday, April 26th, 2024Does it matter if iptables isn't running on my honeypot?https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/ Unplugging PlugX: Singholing the PlugX USB worm botnethttps://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/ pfSense Updateshttps://docs.netgate.com/advisories/index.html GitLab Updateshttps://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/ Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usagehttps://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/...more21minPlay
April 25, 2024ISC StormCast for Thursday, April 25th, 2024API Rug Pull - The NIST NVD Database and APIhttps://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868 Cisco Patches Vulnerabilities and Discovers Arcane Backdoorhttps://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/ Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppershttps://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/ MySQL2: Dangers of User-Defined Database Connectionshttps://blog.slonser.info/posts/mysql2-attacker-configuration/ Netgear Nighthawk Vulnerabilitieshttps://jvn.jp/en/vu/JVNVU91883072/...more7minPlay
April 25, 2024ISC StormCast for Thursday, April 25th, 2024API Rug Pull - The NIST NVD Database and APIhttps://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868 Cisco Patches Vulnerabilities and Discovers Arcane Backdoorhttps://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/ Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppershttps://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/ MySQL2: Dangers of User-Defined Database Connectionshttps://blog.slonser.info/posts/mysql2-attacker-configuration/ Netgear Nighthawk Vulnerabilitieshttps://jvn.jp/en/vu/JVNVU91883072/...more7minPlay
April 24, 2024ISC StormCast for Wednesday, April 24th, 2024Struts2 devmode Still a Problem Ten Years Laterhttps://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/ Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/ April 2024 Exchange Server Hotfix Updatehttps://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536 CVE-2024-2389: Command Injection Vulnerability in Progress Flowmonhttps://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/ GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mininghttps://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/...more7minPlay
April 24, 2024ISC StormCast for Wednesday, April 24th, 2024Struts2 devmode Still a Problem Ten Years Laterhttps://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/ Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/ April 2024 Exchange Server Hotfix Updatehttps://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536 CVE-2024-2389: Command Injection Vulnerability in Progress Flowmonhttps://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/ GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mininghttps://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/...more7minPlay
April 23, 2024ISC StormCast for Tuesday, April 23rd, 2024Number of Industrial Devices Accessible From Internet Up 30 Thousand over three yearshttps://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860 Evil XDR: Turning an XDR into an Offensive Toolhttps://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware GitLab Comment Bughttps://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/ SEC522 Demo: https://www.sans.org/ondemand/get-demo/316...more7minPlay
April 23, 2024ISC StormCast for Tuesday, April 23rd, 2024Number of Industrial Devices Accessible From Internet Up 30 Thousand over three yearshttps://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860 Evil XDR: Turning an XDR into an Offensive Toolhttps://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware GitLab Comment Bughttps://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/ SEC522 Demo: https://www.sans.org/ondemand/get-demo/316...more7minPlay
April 22, 2024ISC StormCast for Monday, April 22nd, 2024The CVE's They are A-Changinghttps://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850 CrushFTP 0-Day Vulnerabilityhttps://www.crushftp.com/crush11wiki/Wiki.jsp?page=Updatehttps://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/ GitHub Comment Bug Used to Distribute Malwarehttps://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/ YubiKey Manager Privilege Escalationhttps://www.yubico.com/support/security-advisories/ysa-2024-01/ Palo Alto Networks GlobalProtect Updatehttps://security.paloaltonetworks.com/CVE-2024-3400...more6minPlay
April 22, 2024ISC StormCast for Monday, April 22nd, 2024The CVE's They are A-Changinghttps://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850 CrushFTP 0-Day Vulnerabilityhttps://www.crushftp.com/crush11wiki/Wiki.jsp?page=Updatehttps://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/ GitHub Comment Bug Used to Distribute Malwarehttps://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/ YubiKey Manager Privilege Escalationhttps://www.yubico.com/support/security-advisories/ysa-2024-01/ Palo Alto Networks GlobalProtect Updatehttps://security.paloaltonetworks.com/CVE-2024-3400...more6minPlay
April 19, 2024ISC StormCast for Friday, April 19th, 2024Delinea Secret Server Authn Authz Bypasshttps://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3 Ivanti Avalanche Poc/Detailshttps://www.tenable.com/security/research/tra-2024-10 Advanced Phishing Campaignhttps://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit Hashicorp go-getter update CVE-2024-3817https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040 OfflRouter Virushttps://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/...more6minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.