

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Episodes
Mentioned books

Dec 5, 2025 • 5min
SANS Stormcast Friday, December 5th, 2025: Compromised Govt System; React Vuln Update; Array Networks VPN Attacks
A honeypot capture reveals an SSH scan from an IP linked to the Indonesian government, raising questions of whether it's a nation-state attack or a compromised system. Recent updates disclose that exploits for a serious React vulnerability exist, urging vigilance. Additionally, there's an active threat against Array Networks VPN gateways, emphasizing the importance of patching and verifying updates from VPN vendors, even smaller ones. Tune in for crucial insights into these pressing cybersecurity issues!

7 snips
Dec 4, 2025 • 7min
SANS Stormcast Thursday, December 4th, 2025: CDN Headers; React Vulnerabiity; PickleScan Patch
Honeypots reveal scans with CDN headers, highlighting attempts by attackers to bypass these defenses. A critical vulnerability in React server components has been patched, but exploitation may occur soon. Additionally, PickleScan, a tool for AI model security, has addressed three significant vulnerabilities, ensuring safer PyTorch models. The discussion dives into the implications of these security issues, making the stakes clearer for developers and cybersecurity professionals.

4 snips
Dec 3, 2025 • 6min
SANS Stormcast Wednesday, December 3rd, 2025: SmartTube Compromise; NPM Malware Prompt Injection Attempt; Angular XSS Vulnerability
The compromise of the SmartTube Android app reveals how a developer's key was exploited, leading to the release of a malicious version. In another intriguing discussion, a rogue NPM package cleverly disguised itself through prompt injection to avoid detection, exfiltrating sensitive data for two years. Additionally, Angular addressed a critical stored XSS vulnerability linked to SVG and MathML, highlighting ongoing security challenges in web applications. Tune in for insights on the evolving landscape of cyber threats!

6 snips
Dec 2, 2025 • 6min
SANS Stormcast Tuesday, December 2nd, 2025: Analyzing ToolShell from Packdets; Android Update; Long Game Malicious Browser Ext.
Dive into the world of cyber security with an intriguing analysis of ToolShell payloads, exploring how to decode embedded PowerShell commands. Discover Google's December Android update, which fixes critical vulnerabilities already exploited. Uncover the shocking story of the ShadyPanda malware campaign, where innocent browser extensions turned malicious after years of being safe. The episode also highlights the shift to spyware behaviors and offers insights on defensive strategies amid uncertainties in attribution.

Dec 1, 2025 • 6min
SANS Stormcast Monday, December 1st, 2025: More ClickFix; Teams Guest Access; Geoserver XXE Vulnerablity
A new variant of ClickFix tricks users with a fake Blue Screen of Death to steal information. There's a concerning phishing risk connected to Teams guest access, where attackers can invite users into unprotected environments. Additionally, a recently patched Geoserver vulnerability (CVE-2025-58360) highlights the dangers of exposing XML entities publicly. These insights reveal the evolving landscape of cyber threats and the importance of vigilance.

4 snips
Nov 26, 2025 • 6min
SANS Stormcast Wednesday, November 26th, 2025: Attacks Against Messaging; Passwords in Random Websites; Fluentbit Vuln; #thanksgiving
Spyware is exploiting vulnerabilities in messaging apps, using tools like keystroke loggers to invade users' privacy. A warning against inputting passwords into random websites highlights the danger of careless online behavior. The critical vulnerabilities in Fluent Bit that could allow remote takeovers are discussed, urging rapid patching for affected users. As Thanksgiving approaches, the focus turns to being safe online and the importance of trusting cloud security.

Nov 25, 2025 • 6min
SANS Stormcast Tuesday, November 25th, 2025: URL Mapping and Authentication; SHA1-Hulud; Hacklore
Conflicts between URL mapping and access control could create serious security gaps. A new destructive worm called Sha1-Hulud is wreaking havoc on NPM and GitHub, stealing credentials and even deleting home directories. Meanwhile, Hacklore.org is tackling outdated security tips, with an open letter from former CISOs addressing common myths about public Wi-Fi and password changes. This dialogue highlights the critical need for updated security advice in a rapidly evolving digital landscape.

Nov 24, 2025 • 5min
SANS Stormcast Monday, November 24th, 2025: CSS Padding in Phishing; Oracle Identity Manager Scans Update;
Discover how phishing sites are using CSS stuffing to confuse detection engines with harmless code. Explore the alarming news about a critical vulnerability in Oracle Identity Manager that could be exploited as a zero-day attack. Plus, learn about ClamAV's efforts to clean up and streamline its signature database to improve security efforts. This discussion highlights the ever-evolving landscape of cyber threats and the innovative methods attackers employ.

8 snips
Nov 21, 2025 • 14min
SANS Stormcast Friday, November 21st, 2025: Oracle Idendity Manager Scans; SonicWall DoS Vuln; Adam Wilson (@sans_edu) reducing prompt injection.
Adam Wilson, a Senior Manager in DevSecOps and application security expert, discusses the automation of generative AI guidelines to mitigate prompt injection risks. He introduces MITRE ATLAS, detailing how it enhances ATT&CK by specifying AI-related threats and their defenses. Adam highlights four main mitigations, emphasizing the value of layered defenses and automation in DevOps environments. Additionally, he shares insights on conducting experiments with different AI defense techniques and underscores the need for ongoing research to bolster security measures.

4 snips
Nov 20, 2025 • 7min
SANS Stormcast Thursday, November 20th, 2025: Unicode Issues; FortiWeb More Vulns; DLink DIR-878 Vuln; Operation WrtHug and ASUS Routers
Dive into the complexities of Unicode, where seemingly funny domain names hide serious vulnerabilities. Discover multiple vulnerabilities in the FortiWeb API and CLI, exacerbated by active exploits. Learn about the troubling DLink DIR-878 router issues, which won't receive patches due to its end-of-life status. Uncover the alarming Operation WrtHug, exposing how thousands of ASUS routers have fallen victim to a global espionage campaign. Tune in for insights on mitigating these threats with better admin controls!


