SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
4.9(678)

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

by Johannes B. Ullrich

2502 episodesLatest 2 days agoEN-US
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Hosts

  • Johannes B. Ullrich, Ph.D.

(c) SANS Institute 2026 This work is licensed under a Creative Commons License - Attribution-NonCommercial-ShareAlike - https://creativecommons.org/licenses/by-nc-sa/4.0/

Episodes (2502)

  1. SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak

    Aug 21, 20267m#10062

    Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20

  2. SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers

    Aug 20, 20266m#10060

    Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory - August 2026 https://www.oracle.com/security-aler

  3. SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI

    Aug 19, 20268m#10058

    CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-

  4. SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM

    Aug 18, 20269m#10056

    Apple Patches or iOS and macOS https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Security https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantl

  5. SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;

    Aug 17, 20265m#10054

    macOS Screen Sharing Vulnerability Exploited https://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patch https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Comme

  6. SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion

    Aug 14, 20267m#10052

    Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242

  7. SANS Stormcast Thursday, August 13th, 2026: Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI regulation

    Aug 13, 20267m#10050

    Linux Kernel Process Accounting https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240 ShieldBreak - Windows Defender 0day vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/sr

  8. SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

    Aug 12, 20269m#10048

    Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236 Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 https://a.security/blog/asecurity-zoomsday Mozil

  9. SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch

    Aug 11, 20266m#10046

    Scans for Solana (Surfpool?) Endpoints https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230 Why AI-generated vulnerability patches still require expert human review https://1password.com/

  10. SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;

    Aug 10, 20268m#10044

    Linux Shell Forensic: Let s Dive Into Atuin! https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226 Apple Patches macOS Screen Sharing Vulnerability https://support.apple.com/en-us/148170 More N-Able

  11. SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu)

    Aug 7, 202616m#10042

    22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary] https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persist

  12. SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish

    Aug 6, 20268m#10040

    Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218 IP and DNS Leaks in WebKit Affectin

  13. SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys

    Aug 5, 20266m#10038

    Botnet Hunting for Vulnerabilities in Diagnostic Tools https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS https://ze

  14. SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey

    Aug 4, 20266m#10036

    AUR packages adoption disabled https://lists.archlinux.org/archives/list/[email protected]/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/ Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Docume

  15. SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability

    Aug 3, 20267m#10034

    zipdump.py Metadata Encoding https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/ Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208 Phishing

  16. SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats

    Jul 31, 20265m#10032

    Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%2

  17. SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch

    Jul 30, 20266m#10030

    Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://su

  18. SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit

    Jul 29, 20266m#10028

    AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising htt

  19. SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update

    Jul 28, 20265m#10026

    Java Spring Boot "heapdump" scans https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188 VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE https://ssd-disclosure.com/vbulletin-runtime-template-runma

  20. SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates

    Jul 27, 20267m#10024

    Scans for ESAFENET CDG 3 Document Management System Weak Logins https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184 DNS Poisoning Tactics Expand to Hospitali

  21. SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2

    Jul 24, 20266m#10022

    When the "Autonomous Attacker" Is Your Own AI Model https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180 Russian State-Supported Cyber Actors Conduct Phishing Campaign

  22. SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface

    Jul 23, 20266m#10020

    Rondo Meets Geoserver https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176 Oracle July Patch Update https://www.oracle.com/security-alerts/cpujul2026.html OpenAI and Hugging Face partner to address security inciden

  23. SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix

    Jul 22, 20265m#10018

    Captive Portal Detection https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172 Critical SolarWinds Serv-U Update https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_rel

  24. SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability

    Jul 21, 20268m#10016

    WordPress Exploitation Underway (CVE-2026-63030) https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168 HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Ch

  25. SANS Stormcast Monday, July 20th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE

    Jul 20, 20267m#10014

    Scans for Hikvision Intelligent Security API https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164 LG Monitor Spyware https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-ar