SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Jun 13, 2025 • 6min

SANS Stormcast Friday, June 13th, 2025: Honeypot Scripts; EchoLeak MSFT Copilot Vuln; Thunderbolt mailbox URL Vuln;

Dive into the world of cybersecurity with an intriguing discussion on honeypot scripts and automated tools for DShield investigations. Discover the alarming EchoLeak vulnerability in Microsoft 365 Copilot that allowed zero-click data leaks. The podcast also unpacks a Thunderbolt vulnerability where unsuspecting users could be tricked into downloading malicious files via deceptive email links. This episode highlights the urgency of user awareness and the importance of keeping software updated to fend off these threats.
undefined
5 snips
Jun 12, 2025 • 6min

SANS Stormcast Thursday, June 12th, 2025: Quasar RAT; Windows 11 24H2 Delay; SMB Client Vuln PoC; Connectwise Signing Keys; KDE Telnet code exec

Discover the sneaky Quasar RAT that can be installed via bat files, hidden within PNG images. Microsoft is delaying the Windows 11 24H2 rollout due to unexpected issues from the latest updates. An exploration of a newly patched SMB client vulnerability reveals its exploitation potential. Connectwise is taking security seriously by rotating signing certificates after a compromise. Lastly, the KDE terminal presents a concerning vulnerability that may allow arbitrary code execution through telnet URLs. Stay informed and secure!
undefined
6 snips
Jun 11, 2025 • 7min

SANS Stormcast Wednesday, June 11th, 2025: Microsoft Patch Tuesday; Acrobat Patches

A deep dive reveals Microsoft patched a staggering 67 vulnerabilities, with 10 critically urgent. One issue is already under attack, highlighting the need for swift updates. Turning to Adobe, the team discusses patches for 7 applications, including crucial updates for Adobe Commerce and Acrobat Reader. The latter's flaws could allow code execution through deceptive PDFs. Cybersecurity is more crucial than ever as these discussions underscore the importance of timely software updates.
undefined
8 snips
Jun 10, 2025 • 6min

SANS Stormcast June, Tuesday, June 10th, 2025: Octosql; Mirai vs. Wazuh DNS4EU; Wordpress Fair Package Manager

Discover the power of OctoSQL, a tool that lets you query vulnerability data in various formats using SQL. Learn how the Mirai botnet is back in action, exploiting weaknesses in the Wazuh tool. The EU is making strides with its new public recursive resolver, enhancing privacy compliance. Plus, find out about the challenges WordPress faces with plugin management and the Linux Foundation's FAIR Package Manager, aimed at simplifying plugin updates and addressing security concerns.
undefined
10 snips
Jun 9, 2025 • 6min

SANS Stormcast June, June 9th, 2025: Extracting PNG Data; GlueStack Packages Backdoor; MacOS targeted by Clickfix; INETPUB restore script

Learn how a powerful script, pngdump.py, is now able to extract hidden data from PNG files. Delve into the alarming discovery of 16 backdoored npm packages that could threaten thousands of users. MacOS faces a new challenge as fake captcha schemes lure users into malware traps. Plus, find out about Microsoft's handy PowerShell script to recover mistakenly deleted inetpub folders. Stay informed about these evolving threats and the creative strategies being developed to counter them!
undefined
Jun 6, 2025 • 5min

SANS Stormcast Friday, June 6th, 2025: Fake Zoom Clients; Python tarfile vulnerability; HPE Insight Remote Support Patch

Beware of fake Zoom client downloads! Scammers are sending deceptive invites that lead to malicious updates. The Python tarfile module has a vulnerability that needs attention, as its new filter isn't functioning as intended. Additionally, HP has addressed a critical remote code execution flaw in their Insight Remote Support software. Stay informed and cautious in the digital landscape!
undefined
Jun 5, 2025 • 5min

SANS Stormcast Thursday, June 5th, 2025: Phishing Comment Trick; AWS default logging mode change; Cisco Backdoor Fixed; Infoblox Vulnerability Details Released

A cunning phishing tactic is discussed, where malicious links are cleverly hidden from Outlook users using HTML comments. Amazon's shift to non-blocking logging raises concerns about potential log loss while enhancing application stability. Critical security updates from Cisco, including the removal of a backdoor vulnerability, are highlighted. Infoblox vulnerabilities are also detailed, prompting a reminder of the importance of keeping software up to date. This conversation is essential for anyone interested in cybersecurity.
undefined
15 snips
Jun 4, 2025 • 7min

SANS Stormcast Wednesday, June 4th, 2025: vBulletin Exploited; Chrome 0-Day Patch; Roundcube RCE Patch; Multiple HP StoreOnce Vulns Patched

Delve into the cybersecurity landscape as recent exploits in vBulletin create concern, especially for PHP 8.1 users. Google Chrome receives urgent patches for flaws, one of which is actively exploited. Roundcube's vulnerability allows any logged-in user to execute code, highlighting serious webmail risks. Additionally, HP’s StoreOnce faces vulnerabilities that could enable remote code execution. The discussion emphasizes the critical importance of timely updates and hints at exciting upcoming events at the SANS Fire conference.
undefined
4 snips
Jun 3, 2025 • 6min

SANS Stormcast Tuesday, June 3rd, 2025: Windows SSH C2; Google Removes CAs from trusted list; MSFT issues Emergency Patch to fix Crash issue; Qualcom Adreno GPU 0-day

A simple SSH backdoor exploits Windows clients, offering unauthorized access through a sneaky configuration. Google Chrome shakes things up by distrustful of certain certificate authorities, impacting digital certificates. Microsoft rushes an emergency fix for a bug that halts system restarts after a patch, affecting both virtual and physical machines. Meanwhile, Qualcomm scrambles to address a vulnerability in its Adreno GPU, already under exploitation, highlighting the urgent need for security updates.
undefined
Jun 2, 2025 • 6min

SANS Stormcast Monday, June 2nd, 2025: PNG with RAT; Cisco IOS XE WLC Exploit; vBulletin Exploit

Discover how a PNG image can hide malware through clever Python coding, raising alarms about current detection methods. Delve into the critical vulnerabilities in Cisco Wireless Controllers that allow for arbitrary code execution. Unpack the implications of changes to PHP that exposed once-protected methods in vBulletin, leading to a surge in exploit attempts. This discussion emphasizes the need for advanced security measures as attackers adapt to new technologies.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app