Sign up to save your podcastsEmail addressPasswordRegisterOrContinue with GoogleAlready have an account? Log in here.
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of cur... more
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.
January 04, 2024ISC StormCast for Thursday, January 4th, 2024Interesting large and small malspam attachments from 2023https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524 Orange Spain RIPE Account Compromisehttps://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/ Bitwarden Heisthttps://blog.redteam-pentesting.de/2024/bitwarden-heist/ Apple iOS PoC Exploitshttps://github.com/felix-pb/kfd/blob/main/writeups/smith.mdhttps://github.com/felix-pb/kfd/blob/main/writeups/landa.md...more7minPlay
January 03, 2024ISC StormCast for Wednesday, January 3rd, 2024Fingerprinting SSH Identification Stringshttps://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520 Google OAUTH2 Exploited by Malwarehttps://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking TsuKing DNS Amplificationhttps://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf...more9minPlay
January 03, 2024ISC StormCast for Wednesday, January 3rd, 2024Fingerprinting SSH Identification Stringshttps://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520 Google OAUTH2 Exploited by Malwarehttps://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking TsuKing DNS Amplificationhttps://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf...more9minPlay
January 02, 2024ISC StormCast for Tuesday, January 2nd, 2024Shall We Play a Gamehttps://isc.sans.edu/diary/Shall+We+Play+a+Game/30510 Mailtrap.io Exfiltrationhttps://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512 Pi Hole Dockerhttps://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/ Mirai Updatehttps://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514 Barracuda 0-Day Vulnerabilityhttps://www.barracuda.com/company/legal/esg-vulnerability Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/...more7minPlay
January 02, 2024ISC StormCast for Tuesday, January 2nd, 2024Shall We Play a Gamehttps://isc.sans.edu/diary/Shall+We+Play+a+Game/30510 Mailtrap.io Exfiltrationhttps://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512 Pi Hole Dockerhttps://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/ Mirai Updatehttps://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514 Barracuda 0-Day Vulnerabilityhttps://www.barracuda.com/company/legal/esg-vulnerability Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/...more7minPlay
December 22, 2023ISC StormCast for Friday, December 22nd, 2023Securing Web Servershttps://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504 Chrome 0-Day (last one for the year?)https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html Note that there will be no daily stormcast for the rest of the year. Returning January 2nd SANS Cloud Defender 2024https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/...more5minPlay
December 22, 2023ISC StormCast for Friday, December 22nd, 2023Securing Web Servershttps://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504 Chrome 0-Day (last one for the year?)https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html Note that there will be no daily stormcast for the rest of the year. Returning January 2nd SANS Cloud Defender 2024https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/...more5minPlay
December 21, 2023ISC StormCast for Thursday, December 21st, 2023Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502 Fake F5 BigIP Updatehttps://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/ Google OAUTH Problemshttps://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/ Remembering Adrien de Beauprehttps://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php...more8minPlay
December 21, 2023ISC StormCast for Thursday, December 21st, 2023Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502 Fake F5 BigIP Updatehttps://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/ Google OAUTH Problemshttps://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/ Remembering Adrien de Beauprehttps://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php...more8minPlay
December 20, 2023ISC StormCast for Wednesday, December 20th, 2023What are they looking for? Scans for OpenID Connect Configurationhttps://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498 Terrapin Attack Against SSHhttps://terrapin-attack.com/TerrapinAttack.pdf ALPHV/Blackcat Ransomware Disrupted and Decryptor Availablehttps://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant...more7minPlay
FAQs about SANS Stormcast: Daily Cyber Security News:How many episodes does SANS Stormcast: Daily Cyber Security News have?The podcast currently has 1,027 episodes available.