SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich
undefined
Aug 1, 2024 • 7min

ISC StormCast for Thursday, August 1st, 2024

The podcast dives into increased cyber threats related to the Apache OFBiz vulnerability. A significant certificate revocation incident by DigiCert raises alarms about trust in security certificates. They discuss a major Azure outage that affected services worldwide. Additionally, there's a spotlight on Google's innovative measures to bolster the security of Chrome cookies, underscoring the ever-evolving nature of cybersecurity.
undefined
Jul 31, 2024 • 5min

ISC StormCast for Wednesday, July 31st, 2024

A deep dive into Apple's latest updates reveals fixes for 64 vulnerabilities, including a critical exploit affecting kernel protections. The discussion also uncovers alarming details about a VMware vulnerability actively exploited by ransomware gangs. Additionally, concerns surrounding weak encryption in Voice Over Wi-Fi technology highlight the growing risks in modern communication. Security updates for Apache are brought to the forefront, emphasizing the necessity for robust protection against evolving cyber threats.
undefined
Jul 30, 2024 • 6min

ISC StormCast for Tuesday, July 30th, 2024

In this discussion, experts dive into a malicious Word document that targets a CrowdStrike vulnerability, showcasing the evolving nature of cyber threats. They also highlight a critical cross-site scripting flaw in Hotjar that jeopardizes OAuth security, putting over a million websites at risk. Additionally, the podcast examines a significant email spoofing campaign that exploits Proofpoint’s protection, detailing possible responses to enhance cybersecurity measures. Tune in for insight into these pressing security challenges!
undefined
Jul 29, 2024 • 6min

ISC StormCast for Monday, July 29th, 2024

Dive into the dark world of ExelaStealer, a new malware threat with Russian roots. Discover how to create your own BSOD with the quirky 'Not My Fault' tool for crash analysis. Unravel the PKFail vulnerability and its implications on security. The discussion also highlights major firmware vulnerabilities that could affect systems from brands like Lenovo and MSI, stressing the importance of trusted updates. Plus, learn about Microsoft’s efforts to improve the security landscape by tackling kernel driver usage in security software.
undefined
Jul 26, 2024 • 6min

ISC StormCast for Friday, July 26th, 2024

Explore the sinister world of X-Worm malware, cleverly using process hollowing for stealthy operations. Discover alarming revelations about how anyone can access deleted and private data on GitHub, raising serious security concerns. Plus, learn about Google's latest enhancement to Chrome that scans encrypted and password-protected files for potential threats. This discussion dives deep into the intersection of malware tactics and evolving cybersecurity measures.
undefined
Jul 25, 2024 • 6min

ISC StormCast for Thursday, July 25th, 2024

Dive into the world of cyber threats with a look at a malicious Python script that logs keystrokes and mouse movements. Explore a revealing incident report from CrowdStrike that highlights critical configuration management flaws. Additionally, uncover the intriguing story of a North Korean impersonating an IT worker to infiltrate organizations. These discussions shed light on modern cyber risks and the cunning tactics of attackers.
undefined
Jul 24, 2024 • 6min

ISC StormCast for Wednesday, July 24th, 2024

Explore the latest cyber threats targeting D-Link NAS devices and learn about vulnerabilities in Android applications disguising as videos on Telegram. Discover how attackers can bypass Windows Hello strong authentication measures, raising concerns for user security. Additionally, dive into Let's Encrypt's plan to replace OCSP with CRLs and Google's shift in managing third-party cookies, moving towards a privacy-focused approach.
undefined
Jul 23, 2024 • 5min

ISC StormCast for Tuesday, July 23rd, 2024

Discover the fallout from a major CrowdStrike incident that affected 8.5 million systems and learn about the daunting recovery efforts underway. The discussion explores the rising tide of phishing attacks and offers insights into effective strategies for managing recovery keys. Tune in for expert advice on navigating these challenges and safeguarding your systems!
undefined
Jul 22, 2024 • 9min

ISC StormCast for Monday, July 22nd, 2024

A significant flaw in a cybersecurity update has caused widespread crashes on Windows systems. The discussion offers insights into the aftermath of this technical mishap. Listeners will also learn about recovery strategies and confront common myths surrounding the issue. This informative talk sheds light on the intersection of technology and security, highlighting the importance of careful software updates.
undefined
Jul 19, 2024 • 6min

ISC StormCast for Friday, July 19th, 2024

Explore Oracle's critical patch update addressing 386 vulnerabilities, including a staggering CVSS score of 9.8. Discover Microsoft's latest advancements in email security with the new inbound SMTP DANE, enhancing protection. Learn how to improve your email reputation with DKIM and insights on upcoming SMTP features. Don't miss the analysis of recent VPN vulnerabilities and novel attack vectors that could jeopardize your connections. It's a treasure trove of information for anyone concerned about cyber security!

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app