Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.
January 26, 2024ISC StormCast for Friday, January 26th, 2024Fecebook AdsManager Targeted by a Python Infostealerhttps://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590 Privacy Concerns about Apple Push Notificationshttps://twitter.com/mysk_co/status/1750502700112916504https://www.youtube.com/watch?v=4ZPTjGG9t7s Inside a Global Phone Spy Tool Monitoring Billionshttps://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/...more7minPlay
January 25, 2024ISC StormCast for Thursday, January 25th, 2024How Bad User Interfaces Make Security Tools Harmfulhttps://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586 Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Productionhttps://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/ Automotive Pwn2Ownhttps://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule Android Keystroke Injection Vulnerability Exploithttps://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/ CVE-2024-0769 D-Link DIR-859https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/ SANS.edu Dean's Listhttps://www.sans.edu/students/awards...more6minPlay
January 25, 2024ISC StormCast for Thursday, January 25th, 2024How Bad User Interfaces Make Security Tools Harmfulhttps://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586 Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Productionhttps://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/ Automotive Pwn2Ownhttps://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule Android Keystroke Injection Vulnerability Exploithttps://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/ CVE-2024-0769 D-Link DIR-859https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/ SANS.edu Dean's Listhttps://www.sans.edu/students/awards...more6minPlay
January 24, 2024ISC StormCast for Wednesday, January 24th, 2024Update on Atlassian Exploit Activityhttps://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/ POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/ Baracuda Web Application Firewallhttps://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/ GitGot: GitHub leveraged by cybercriminals to store stolen datahttps://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data...more6minPlay
January 24, 2024ISC StormCast for Wednesday, January 24th, 2024Update on Atlassian Exploit Activityhttps://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/ POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/ Baracuda Web Application Firewallhttps://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/ GitGot: GitHub leveraged by cybercriminals to store stolen datahttps://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data...more6minPlay
January 23, 2024ISC StormCast for Tuesday, January 23rd, 2024Apple Updates Everythinghttps://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/ Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/ Updated Ivanti Mitigation Advisehttps://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US Czech Republic Sets IPv4 Shutdown datehttps://konecipv4.cz/en/...more8minPlay
January 23, 2024ISC StormCast for Tuesday, January 23rd, 2024Apple Updates Everythinghttps://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/ Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/ Updated Ivanti Mitigation Advisehttps://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US Czech Republic Sets IPv6 Shutdown datehttps://konecipv4.cz/en/...more8minPlay
January 22, 2024ISC StormCast for Monday, January 22nd, 2024macOS Python Script Replacing Walling Applications with Rogue Appshttps://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572 Microsoft Breachhttps://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/ Juniper Vulnerabilitieshttps://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/ Brave Removing Strict Fingerprint Modehttps://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/...more7minPlay
January 22, 2024ISC StormCast for Monday, January 22nd, 2024macOS Python Script Replacing Walling Applications with Rogue Appshttps://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572 Microsoft Breachhttps://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/ Juniper Vulnerabilitieshttps://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/ Brave Removing Strict Fingerprint Modehttps://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/...more7minPlay
January 19, 2024ISC StormCast for Friday, January 19th, 2024More Scans for Ivanti Connect "Secure" VPN. Exploits Publichttps://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568 Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082https://www.cisa.gov/known-exploited-vulnerabilities-catalog Attacks against Exposed Databaseshttps://twitter.com/fasterthanlime/status/1741935393413402739 Outlook Vulnerability Discovery and New Ways to Leak NTLM Hasheshttps://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes...more7minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.