

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Jun 27, 2024 • 6min
ISC StormCast for Thursday, June 27th, 2024
A critical vulnerability in MoveIt software is making waves, allowing unauthorized server access that organizations must address immediately. There's a deep dive into a supply chain attack targeting Polyfill.io, affecting over 100,000 websites. The risks don't stop there; a JavaScript library flaw threatens former clients with ransomware reinfection. Plus, the spotlight is on Apple AirPods, reminding users of the importance of firmware updates to stay secure. Stay informed on these pressing cybersecurity matters!

Jun 26, 2024 • 6min
ISC StormCast for Wednesday, June 26th, 2024
Discover a fascinating study revealing how latency changes in network traffic can infer website visits, even without direct data access. Dive into new cybersecurity techniques that leverage Management Safe Console files for code execution. Uncover vulnerabilities in Wyze cameras and Realtek Wi-Fi drivers that could leave users exposed. The implications of these findings and techniques raise important questions about online privacy and security. Don’t miss the intriguing insights into the evolving landscape of cybersecurity threats!

Jun 25, 2024 • 5min
ISC StormCast for Tuesday, June 25th, 2024
The podcast dives into the emerging threat landscape, focusing on scanners targeting cloud configuration files. It discusses critical vulnerabilities in Java Spring and an urgent SQL Server update from Microsoft. There's also an in-depth look at the latest updates for Juniper Secure Analytics, which tackle over 200 vulnerabilities. Lastly, it highlights a concerning buffer overflow exploit affecting Apple's macOS and iOS, stressing the importance of regular system updates to mitigate risks.

Jun 24, 2024 • 7min
ISC StormCast for Monday, June 24th, 2024
The latest cybersecurity developments unveil Sysinternals Process Monitor 4.01, packed with new features. Concerns arise over potential US sanctions against Kaspersky. A critical buffer overflow in Phoenix UEFI firmware could impact numerous Intel devices, raising alarm bells in the digital supply chain. Important updates for GhostScript and JS2py vulnerabilities are discussed, emphasizing the risks of running untrusted code. Stay informed about these vital security updates!

Jun 21, 2024 • 5min
ISC StormCast for Friday, June 21st, 2024
Discover essential free tools to bolster authentication security on Ubuntu systems. Explore the latest vulnerabilities in Atlassian Confluence and how they can impact your projects. Dive into the complexities of email address formatting and the security risks of poor validation practices. Additionally, learn about important updates from Broadcom to patch various vulnerabilities in VMWare's vCenter server software. Stay informed and secure in the ever-evolving landscape of cybersecurity.

Jun 18, 2024 • 5min
ISC StormCast for Tuesday, June 18th, 2024
Discover the alarming vulnerabilities linked to the compromised NetSupport remote access tool and the unprotected backdoor in D-Link routers. Learn about the critical security updates for iTerm2, spotlighting issues related to tmux integration. The urgency of patching high-risk vulnerabilities in Nextcloud is also tackled, as these flaws could severely jeopardize multi-factor authentication systems. Stay informed and secure in the ever-evolving landscape of cyber threats.

Jun 17, 2024 • 5min
ISC StormCast for Monday, June 17th, 2024
This discussion highlights tools for managing JSON data and dives into Python's 'sleepy pickle' vulnerability. The challenges of detecting headless Chrome are examined, alongside a new tool for evaluating browser extension safety. Additionally, critical security updates for Asus routers are revealed, emphasizing the importance of addressing vulnerabilities in network devices.

Jun 14, 2024 • 6min
ISC StormCast for Friday, June 14th, 2024
Discover the fascinating world of jq, a powerful command line tool for JSON parsing. Dive into critical vulnerabilities in Microsoft Outlook and learn how these flaws could impact users. Explore the emerging threat of pickle file attacks on machine learning models, revealing the risks associated with this technology. Get insights on how to safeguard personal email accounts in light of these vulnerabilities. Plus, stay tuned for exciting updates on future podcast events!

Jun 13, 2024 • 5min
ISC StormCast for Thursday, June 13th, 2024
Discover how reconnaissance activities reveal intriguing patterns in Microsoft Message Queue traffic. Learn about Adobe's critical updates addressing vulnerabilities in its products, including Commerce and Cold Fusion. Delve into the alarming exploitation of a privilege escalation flaw by Black Basta ransomware. The discussion also highlights the complexities of forensic analysis in these incidents and reviews essential Android updates that patch critical vulnerabilities.

Jun 12, 2024 • 6min
ISC StormCast for Wednesday, June 12th, 2024
Get ready for a deep dive into the latest security landscape! This discussion covers crucial June patches from Microsoft, highlighting 58 vulnerabilities, including a major flaw in the Message Queuing Service. The podcast also reveals a worrying vulnerability in JetBrains' GitHub plugin and addresses risks in Veeam Recovery Orchestrator. Plus, an intriguing insight into a potential threat posed by internet-connected treadmills adds an unexpected twist!


