SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
5 snips
Mar 10, 2025 • 7min

SANS Stormcast: Webshells; Undocumented ESP32 Commands; Camera Used For Ransomware Distribution

Discover the lurking dangers of web shells, which attackers use to infiltrate vulnerable servers while staying one step ahead. Learn about hidden backdoors in the popular ESP32 chipsets that could compromise IoT devices, thanks to recent findings from a conference presentation. Finally, be shocked by the Akira group's tactic of deploying ransomware through unsuspecting webcams, illustrating a new wave of innovative cyber threats. Enhance your security awareness with these intriguing insights!
undefined
Mar 7, 2025 • 14min

SANS Stormcast Friday Mar 7th: Chrome vs Extensions; Kibana Update; PrePw0n3d Android TV Sticks; Identifying APTs (@sans_edu, Eric LeBlanc)

Eric LeBlanc, a Senior cybersecurity engineer at the U.S. Strategic Petroleum Reserve, shares insights into the ever-evolving world of cybersecurity. He discusses the controversial Chrome update that disrupts ad blockers and the critical Kibana vulnerability posing security risks. LeBlanc also delves into the alarming discovery of pre-infected Android TV sticks filled with adware. His innovative meta detection strategies highlight the complexities of identifying Advanced Persistent Threats and managing log data effectively in federal environments.
undefined
Mar 6, 2025 • 7min

SANS Stormcast Thursday Mar 6th: DShield ELK Analysis; Jailbreaking AMD CPUs; VIM Vulnerability; Snail Mail Ransomware

Explore the world of cybersecurity with fascinating insights into the DShield SIEM's ELK dashboard for traffic analysis. Uncover the shocking details of a new AMD CPU microcode vulnerability revealed by Google, complete with a proof of concept. Dive into a VIM flaw that could let attackers execute arbitrary code through specially crafted files. And watch out for a peculiar snail mail scam, where fraudsters are impersonating ransomware groups to extort payments from executives. A mix of cautionary tales and technical discussions!
undefined
Mar 5, 2025 • 6min

SANS Stormcast Wednesday Mar 5th: SMTP Credential Hunt; mac-robber.py update; ADSelfService Plus Account Takeover; Android Patch Day; PayPal Scams; VMWare Escape Fix

A Romanian attacker expands their scanning tactics to hunt for SMTP credentials, complicating cybersecurity efforts. An update to mac-robber.py resolves symlink issues, enhancing security tool functionality. A serious vulnerability in ADSelfService Plus could allow unauthorized access without MFA. Google's March Android update tackles critical vulnerabilities, while PayPal's no-code-checkout feature faces exploitation by scammers. Broadcom addresses three VMware vulnerabilities to prevent potential virtual machine breaches.
undefined
Mar 4, 2025 • 6min

SANS Stormcast Tuesday Mar 4th: Mark of the Web Details; Sharepint and Click-Fix Phishing; Paragon Partionmanager BYOVD Exploit

Discover the nuances of the 'Mark of the Web' in Windows, revealing how it stores information like source URLs and referrers. Dive into a crafty phishing attack that exploits SharePoint via the Microsoft Graph API, luring users to execute harmful commands. Learn about a critical vulnerability in Paragon Partition Manager that enables attackers to escalate privileges for ransomware deployment, even without the software installed. Stay informed on these pressing cybersecurity threats!
undefined
4 snips
Mar 3, 2025 • 7min

SANS Stormcast Monday Mar 3rd: AI Training Data Leaks; MITRE Caldera Vuln; modsecurity bypass

The podcast dives into alarming AI training data leaks, revealing that the Common Crawl dataset harbors exposed API keys and secrets. It also discusses GitHub's Copilot inadvertently accessing sensitive data from previously private repositories. The MITRE Caldera framework is highlighted for its potential vulnerability, allowing unauthorized code execution. Lastly, it addresses a modsecurity rule bypass, emphasizing the critical importance of regular software updates to enhance cybersecurity defenses.
undefined
Feb 28, 2025 • 14min

SANS Stormcast Friday Feb 28th: Njrat devtunnels.ms; Apple FindMe Abuse; XSS Exploited; @sans_edu Ben Powell EDR vs. Ransomware

Join Ben Powell, a principal security engineer with 15 years in cybersecurity, as he dives into some pressing digital threats. He discusses the Njrat malware exploiting Microsoft's dev tunnels and highlights new vulnerabilities in Apple’s FindMy that could endanger users. The conversation also covers alarming trends in mass website exploitation through XSS vulnerabilities in virtual tour frameworks. Plus, learn about effective strategies against ransomware and the strengths and weaknesses of various cybersecurity solutions for small businesses.
undefined
Feb 27, 2025 • 7min

SANS Stormcast Thursday Feb 27th: High Exfil Ports; Malicious VS Code Theme; Developer Workstation Safety; NAKIVO PoC; OpenH264 and rsync vuln;

Discover the hidden risks of ephemeral ports as attackers use them to exfiltrate data, prompting the need for vigilant traffic monitoring. A compromised Visual Studio Code theme has alarmingly reached millions, with its exact malicious intent still under wraps. The shocking theft at ByBit reveals how a compromised developer workstation can lead to monumental losses. Additionally, a vulnerability in NAKIVO backup systems sparks concerns as a proof of concept exploit surfaces, catching the cyber world off guard.
undefined
Feb 26, 2025 • 6min

SANS Stormcast Wednesday Feb 26th: M365 Infostealer Botnet; Mixing OpenID Keys; Malicious Medical Image Apps

A massive botnet is targeting Microsoft 365 accounts using stolen credentials from infostealer malware, highlighting the urgency for better authentication methods. Misconfigurations in OpenID pose significant security risks, allowing private keys to accidentally be exposed. Additionally, patients downloading DICOM image viewers are tricked into installing malware, raising alarms about deceptive practices in the healthcare sector. These discussions emphasize the need for vigilance and improved security measures across digital platforms.
undefined
Feb 25, 2025 • 6min

SANS Stormcast Tuesday Feb 25th: Unfurl Updates; Google Ditches SMS; Paypal Phish; Exim, libXML, Parallels Vuln

Discover the latest Unfurl update that improves URL decoding and timestamp management. Learn how Google is phasing out SMS for GMail, opting for Passkeys instead. Beware of new PayPal phishing tactics that exploit legitimate emails. The podcast also covers vulnerabilities in mail servers, including a serious Exim SQL injection flaw and a newly discovered 0-day in Parallels. Stay informed about evolving cyber threats and enhance your security awareness!

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app