

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Mar 19, 2024 • 5min
ISC StormCast for Tuesday, March 19th, 2024
Microsoft's plan to phase out 1024-bit RSA keys sparks a discussion on online security standards. Google enhances its Chrome browser with real-time safe browsing, raising privacy concerns. The spotlight shifts to critical vulnerabilities, like those in Fortra's FileCatalyst and Spring Security, emphasizing the need for immediate patching. Additionally, TrendNet routers face their own security issues, prompting a call for vigilance in cybersecurity practices.

Mar 18, 2024 • 7min
ISC StormCast for Monday, March 18th, 2024
The discussion highlights a revisitation of the 5G Huler vulnerabilities, exposing ongoing risks from outdated Android firmware. It dives into OAuth issues linked to ChatGPT plugins, showcasing how they can compromise account security. The latest threat detection report from RedCanary unveils emerging IT threats. Additionally, new guidelines on certificate revocation bring critical updates for cybersecurity professionals. This blend of insights helps listeners stay informed about vital trends and vulnerabilities in the digital landscape.

Mar 15, 2024 • 21min
ISC StormCast for Friday, March 15th, 2024
There's a surge in phishing attacks targeting IPFS and R2 buckets, making traditional blocking methods less effective. Critical vulnerabilities in Fortinet and Arcserve are highlighted, urging prompt security updates. A student shares insights on monitoring PLCs for industrial control systems, revealing the complexities in their operational modes and security risks. The discussion extends to the challenges of firmware updates in essential networks and the potential of AI tools for improving incident detection and managing code vulnerabilities.

Mar 14, 2024 • 5min
ISC StormCast for Thursday, March 14th, 2024
Discover how ChatGPT can help deobfuscate malicious scripts, enhancing cybersecurity defenses. Dive into critical vulnerabilities affecting Fortinet and Adobe, highlighting the need for stronger authentication methods. Learn about a troubling command injection vulnerability in Kubernetes that could give attackers system privileges. It's a blend of AI innovation and pressing security concerns that no tech enthusiast should miss!

Mar 13, 2024 • 6min
ISC StormCast for Wednesday, March 13th, 2024
Microsoft's latest Patch Tuesday tackles 60 vulnerabilities, with critical updates that could affect Hyper-V. The discussion also touches on the potential decline of the National Vulnerability Database. Notably, there’s a serious unrestricted file upload vulnerability in ManageEngine Desktop Central. Additionally, recent updates to Siemens fire protection systems are highlighted, showcasing the importance of staying on top of cybersecurity threats.

Mar 12, 2024 • 6min
ISC StormCast for Tuesday, March 12th, 2024
Leaking AWS API keys can lead to rapid exploitation, highlighting the critical need for vigilance in securing sensitive information. The rise of crypto imposters using Calendly to spread malware on Macs is a concerning trend. Misconfigurations in tools like Microsoft Configuration Manager are also addressed, showcasing the importance of proper security practices. The discussion underscores the urgency for both individuals and organizations to stay informed about these threats to maintain their cybersecurity.

Mar 11, 2024 • 7min
ISC StormCast for Monday, March 11th, 2024
A new attack has turned thousands of web users into a password-cracking botnet, highlighting the evolving landscape of cyber threats. Critical vulnerabilities in Cisco VPN clients expose severe risks to user authentication, raising alarms on patching practices. Additionally, font parsing libraries reveal potential for arbitrary code execution, stressing the importance of keeping security tools updated. Plus, urgent QNAP flaws open doors for hackers, emphasizing the necessity for robust protective measures across various platforms.

Mar 8, 2024 • 5min
ISC StormCast for Friday, March 8th, 2024
Explore the rising targeting of AWS deployments, as attackers exploit uploaded credentials, revealed through honeypot insights. Discover how Apple’s latest security update tackles over 70 vulnerabilities across its operating systems. Additionally, uncover recent WebKit issues affecting Safari users and gain knowledge from essential secure cloud practices as outlined by NSA and CISA guides. The tech world is buzzing with both risks and solutions!

Mar 7, 2024 • 6min
ISC StormCast for Thursday, March 7th, 2024
Dive into the QUIC protocol, which enhances performance but raises security concerns. Discover the challenges of scanning QUIC services and its implications for popular applications. A crucial update from Google Chrome is also discussed, ensuring users are aware of necessary protections. Finally, learn about a new Linux malware campaign targeting Docker and other platforms, highlighting the dynamic landscape of cybersecurity threats.

Mar 6, 2024 • 7min
ISC StormCast for Wednesday, March 6th, 2024
Recent iOS and iPadOS updates tackle urgent zero-day vulnerabilities currently under attack. The discussion highlights the risks posed by poorly understood firewalls and their potential consequences. Insights into QEMU tunneling reveal new networking techniques, while VMware patches address critical security flaws. Together, these topics underscore the evolving landscape of cyber threats and the importance of vigilance in cybersecurity.


