Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.
April 19, 2024ISC StormCast for Friday, April 19th, 2024Delinea Secret Server Authn Authz Bypasshttps://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3 Ivanti Avalanche Poc/Detailshttps://www.tenable.com/security/research/tra-2024-10 Advanced Phishing Campaignhttps://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit Hashicorp go-getter update CVE-2024-3817https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040 OfflRouter Virushttps://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/...more6minPlay
April 18, 2024ISC StormCast for Thursday, April 18th, 2024Malicious PDF File As Delivery Mechanismhttps://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848 Updated Palo Alto Networks GlobalProtect Guidancehttps://security.paloaltonetworks.com/CVE-2024-3400 Coordinated Social Engineering Takeovers of Open Source Projects;https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/ OpenMetaData Attackshttps://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/...more6minPlay
April 18, 2024ISC StormCast for Thursday, April 18th, 2024Malicious PDF File As Delivery Mechanismhttps://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848 Updated Palo Alto Networks GlobalProtect Guidancehttps://security.paloaltonetworks.com/CVE-2024-3400 Coordinated Social Engineering Takeovers of Open Source Projects;https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/ OpenMetaData Attackshttps://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/...more6minPlay
April 17, 2024ISC StormCast for Wednesday, April 17th, 2024Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/ Putty Private Key Recoveryhttps://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html Oracle Critical Patch Updatehttps://www.oracle.com/security-alerts/cpuapr2024.html Ivanti Avalanche MDM Patcheshttps://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US...more6minPlay
April 17, 2024ISC StormCast for Wednesday, April 17th, 2024Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/ Putty Private Key Recoveryhttps://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html Oracle Critical Patch Updatehttps://www.oracle.com/security-alerts/cpuapr2024.html Ivanti Avalanche MDM Patcheshttps://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US...more6minPlay
April 16, 2024ISC StormCast for Tuesday, April 16th, 2024Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400https://isc.sans.edu/diary/30838 Delinea patches critical vulnerability in secret managerhttps://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3 Lancom Windows Setup Assistant May Reset Passwordhttps://www.lancom-systems.com/service-support/general-security-information PHP Patcheshttps://seclists.org/oss-sec/2024/q2/113 Duo SMS and VoiP Logs Leakedhttps://app.securitymsp.cisco.com/e/es?e=2785&eid=opguvrs&elq=bd1c1886a59e40c09915b029a74be94e Lastpass Stops Deepfake Attackhttps://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee...more7minPlay
April 16, 2024ISC StormCast for Tuesday, April 16th, 2024Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400https://isc.sans.edu/diary/30838 Delinea patches critical vulnerability in secret managerhttps://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3 Lancom Windows Setup Assistant May Reset Passwordhttps://www.lancom-systems.com/service-support/general-security-information PHP Patcheshttps://seclists.org/oss-sec/2024/q2/113 Duo SMS and VoiP Logs Leakedhttps://app.securitymsp.cisco.com/e/es?e=2785&eid=opguvrs&elq=bd1c1886a59e40c09915b029a74be94e Lastpass Stops Deepfake Attackhttps://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee...more7minPlay
April 13, 2024ISC StormCast for Sunday, April 14th, 2024Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400https://security.paloaltonetworks.com/CVE-2024-3400https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise...more6minPlay
April 13, 2024ISC StormCast for Sunday, April 14th, 2024Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400https://security.paloaltonetworks.com/CVE-2024-3400https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise...more6minPlay
April 12, 2024ISC StormCast for Friday, April 12th, 2024BatBadBut: You can't securely execute commands on Windowshttps://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/ FortiClient Linux Remote Code Executionhttps://www.fortiguard.com/psirt/FG-IR-23-087 Apple Threat Notifications and Protecting Against Mercenary Spywarehttps://support.apple.com/en-us/102174 New Technique to Trick Developers Detected in an Open Source Supply Chain Attackhttps://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/...more7minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.