Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,353 episodes available.
October 18, 2024ISC StormCast for Friday, October 18th, 2024Scanning Activity from Subnet 15.184.0.0/16.https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362 Gatekeeper Bypass /unit42.paloaltonetworks.com/gatekeeper-bypass-macos/ Oracle Critical Patch Updatehttps://www.oracle.com/security-alerts/cpuoct2024.html Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilitieshttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy SAP Vulnerabilityhttps://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/ Dept. of Commerce Sites Advertising Medicationhttps://x.com/tliston/status/1833542884047654984...more6minPlay
October 17, 2024ISC StormCast for Thursday, October 17th, 2024The Top 10 Not So Common SSH Usernames and Passwordshttps://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360 CISA Product Security Bad Practiceshttps://www.cisa.gov/resources-tools/resources/product-security-bad-practices Kubernetes Image Builder Vulnerability CVE-2024-9486 CVE-2024-9594https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119 Solarwinds Hardcoded Password Exploited CVE-2024-28987https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/ Bypassing noexec and executing arbitrary binarieshttps://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries Workshop Website:https://www.sansapi.com/https://www.sansapi.com/docs...more6minPlay
October 16, 2024ISC StormCast for Wednesday, October 16th, 2024Angular-base64-upload Demo Script Exploitedhttps://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354 Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf EDRSilencerhttps://github.com/netero1010/EDRSilencer Synchronizing Passkeyshttps://fidoalliance.org/specifications-credential-exchange-specifications/...more7minPlay
October 15, 2024ISC StormCast for Tuesday, October 15th, 2024Phishing Page Delivered Through a Blob URLhttps://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350 Fortinet Fortigate CVE 2024-23113 deep divehttps://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/ This New Supply Chain Attack Technique Can Trojanize All Your CLI Commandshttps://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/...more6minPlay
October 14, 2024ISC StormCast for Monday, October 14th, 2024Windows PPTP and L2TP Deprecationhttps://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956 BIG-IP LTM Systems Unencrypted Cookie Exploitationhttps://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookieshttps://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/...more6minPlay
October 11, 2024ISC StormCast for Friday, October 11th, 2024GPTHoney: A new class of honeypothttps://isc.sans.edu/diary/GPTHoney%3A%20A%20new%20class%20of%20honeypot%20%5BGuest%20Diary%5D/31342 Palo Alto Expedition: From N-Day to Full Compromisehttps://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/ Firefox 0-Dayhttps://www.mozilla.org/en-US/security/advisories/mfsa2024-51/ GitLab Vulnerabilities Patchedhttps://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/...more6minPlay
October 10, 2024ISC StormCast for Thursday, October 10th, 2024From Perfctl to InfoStealerhttps://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334 Wazuh Abused by Miner Campaignhttps://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/ USB Sticks Still Bridge Airgapshttps://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/ Fortigate Vulnerability now being exploitedhttps://nvd.nist.gov/vuln/detail/CVE-2024-23113...more6minPlay
October 09, 2024ISC StormCast for Wednesday, October 9th, 2024Microsoft Patch Tuesday - October 2024https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336 Adobe Patcheshttps://helpx.adobe.com/security/security-bulletin.html The Disappearance of an Internet Domainhttps://every.to/p/the-disappearance-of-an-internet-domain...more7minPlay
October 08, 2024ISC StormCast for Tuesday, October 8th, 2024macOS Sequoia: System/Network Admins, Hold On!https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330 Cisco Vulnerabilitieshttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms Apple iTunes PoChttps://github.com/mbog14/CVE-2024-44193 Attackers used ISP's Wiretap System to Spy on Usershttps://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/...more6minPlay
October 07, 2024ISC StormCast for Monday, October 7th, 2024Survey of CUPS exploit URLshttps://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326 Exposed LDAP Servershttps://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit Exploiting Visual Studio via Dump Fileshttps://ynwarcs.github.io/exploiting-vs-dump-files Apple Security Updateshttps://support.apple.com/en-us/100100 Free API Security Workshophttps://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/...more6minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,353 episodes available.