SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
4.9(678)

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

by Johannes B. Ullrich

2494 episodesLatest todayEN-US
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Hosts

  • Johannes B. Ullrich, Ph.D.

(c) SANS Institute 2026 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

Episodes (2494)

  1. SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch

    Aug 11, 20266m#10046

    Scans for Solana (Surfpool?) Endpoints https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230 Why AI-generated vulnerability patches still require expert human review https://1password.com/

  2. SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;

    Aug 10, 20268m#10044

    Linux Shell Forensic: Let s Dive Into Atuin! https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226 Apple Patches macOS Screen Sharing Vulnerability https://support.apple.com/en-us/148170 More N-Able

  3. SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu)

    Aug 7, 202616m#10042

    22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary] https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persist

  4. SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish

    Aug 6, 20268m#10040

    Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218 IP and DNS Leaks in WebKit Affectin

  5. SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys

    Aug 5, 20266m#10038

    Botnet Hunting for Vulnerabilities in Diagnostic Tools https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS https://ze

  6. SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey

    Aug 4, 20266m#10036

    AUR packages adoption disabled https://lists.archlinux.org/archives/list/[email protected]/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/ Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Docume

  7. SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability

    Aug 3, 20267m#10034

    zipdump.py Metadata Encoding https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/ Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208 Phishing

  8. SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats

    Jul 31, 20265m#10032

    Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%2

  9. SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch

    Jul 30, 20266m#10030

    Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://su

  10. SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit

    Jul 29, 20266m#10028

    AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising htt

  11. SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update

    Jul 28, 20265m#10026

    Java Spring Boot "heapdump" scans https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188 VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE https://ssd-disclosure.com/vbulletin-runtime-template-runma

  12. SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates

    Jul 27, 20267m#10024

    Scans for ESAFENET CDG 3 Document Management System Weak Logins https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184 DNS Poisoning Tactics Expand to Hospitali

  13. SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2

    Jul 24, 20266m#10022

    When the "Autonomous Attacker" Is Your Own AI Model https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180 Russian State-Supported Cyber Actors Conduct Phishing Campaign

  14. SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface

    Jul 23, 20266m#10020

    Rondo Meets Geoserver https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176 Oracle July Patch Update https://www.oracle.com/security-alerts/cpujul2026.html OpenAI and Hugging Face partner to address security inciden

  15. SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix

    Jul 22, 20265m#10018

    Captive Portal Detection https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172 Critical SolarWinds Serv-U Update https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_rel

  16. SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability

    Jul 21, 20268m#10016

    WordPress Exploitation Underway (CVE-2026-63030) https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168 HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Ch

  17. SANS Stormcast Monday, July 20th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE

    Jul 20, 20267m#10014

    Scans for Hikvision Intelligent Security API https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164 LG Monitor Spyware https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-ar

  18. SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln

    Jul 17, 20265m#10012

    German Federal Information Security Office Analyzes Windows Hello for Business https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html https://www.bsi.bund.de/Shar

  19. SANS Stormcast Thursday, July 16th, 2026: DShield SIEM Update; MSFT Patches vs. Intel IPF; Zoom Patch; Forgotten UEFI Shims

    Jul 16, 20264m#10010

    DShield SIEM Update https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156 Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers https://support.microsoft.com/en-us/servicing/os/wi

  20. SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration

    Jul 15, 20266m#10008

    Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154 LegacyHive : Windows user profile servic

  21. SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln;

    Jul 14, 20267m#10006

    Someone Is Scanning for Your MCP Servers and AI Assistant Credentials https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150 Improve Router Hygiene to P

  22. SANS Stormcast Monday, July 13th, 2026: Progress Sharefile Shutdown; U-Boot Vuln; More Nightmare Eclipse; Cisco AI Response

    Jul 13, 20265m#10004

    Progress Sharefile Emergency Shutdown Notice https://status.sharefile.com https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/ https://www.bleepingcomputer.com/news/security/progre

  23. SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch

    Jul 10, 20266m#10002

    _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary] https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28 h

  24. SANS Stormcast Thursday, July 9th, 2026: Stack Simulator; RootAsRole; Hoymiles; Git Hash Malleability

    Jul 9, 20264m#10000

    My Stack Simulator https://isc.sans.edu/diary/My%20Stack%20Simulator/33138 RootAsRole https://github.com/LeChatP/RootAsRole Hoymiles Inverter Vulnerability https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln

  25. SANS Stormcast Wednesday, July 8th, 2026: Odd DNS; AnyDesk Phishing; Tenda Backdoor; GitLost

    Jul 8, 20267m#9998

    More Odd DNS Records: NIMLOC https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128 From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations https://www.seqrite.c