Good podcast

Top 100 most popular podcasts

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Subscribe

iTunes / Overcast / RSS

Website

isc.sans.edu/podcast.html#stormcast

Episodes

ISC StormCast for Thursday, December 19th, 2024

ISC StormCast for Wednesday, December 18th, 2024

ISC StormCast for Tuesday, December 17th, 2024

MUT-1244 Targeting Offensive Actors
https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/
Golang Crypto Vulnerability
https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909
Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows
https://www.cadosecurity.com/blog/meeten-malware-threat
2024-12-17
Link to episode

ISC StormCast for Thursday, December 12th, 2024

ISC StormCast for Tuesday, December 10th, 2024

ISC StormCast for Monday, December 9th, 2024

ISC StormCast for Wednesday, December 4th, 2024

2024-12-04
Link to episode

ISC StormCast for Friday, November 22nd, 2024

ISC StormCast for Thursday, November 21st, 2024

2024-11-21
Link to episode

ISC StormCast for Tuesday, November 19th, 2024

ISC StormCast for Wednesday, November 13th, 2024

ISC StormCast for Tuesday, November 12th, 2024

PDF Object Streams
https://isc.sans.edu/diary/PDF%20Object%20Streams/31430
Mazda Infotainment Vulnerabilities
https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system
Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight
https://workos.com/blog/ruby-saml-cve-2024-45409
Veeam Backup Enterprise Manager Vulnerability
https://www.veeam.com/kb4682
Security Update for Dell Enterprise SONiC Distribution Vulnerabilities
https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities
Easy Access to Information for Conducting Fraudulent
Emergency Data Requests Impacts US-Based Companies
and Law Enforcement Agencies
https://www.ic3.gov/CSA/2024/241104.pdf
2024-11-12
Link to episode

ISC StormCast for Friday, November 8th, 2024

Steam Account Checker Poisoned with Infostealer
https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420
Cisco Ultra Reliable Wireless Backhaul Vulnerability
https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html
Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
Evasive ZIP Concatenation: Trojan Targets Windows Users
https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/
Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)
https://www.veeam.com/kb4682
SANS Holiday Hack Challenge
https://www.sans.org/mlp/holiday-hack-challenge-2024
2024-11-08
Link to episode

ISC StormCast for Tuesday, November 5th, 2024

2024-11-05
Link to episode

ISC StormCast for Tuesday, October 29th, 2024

2024-10-29
Link to episode

ISC StormCast for Monday, October 28th, 2024

ISC StormCast for Friday, October 25th, 2024

Development Features Enabled in Production
https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380
Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials
https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/
Cisco Secure Firewall Management Center Software Command Injection Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7
Exposing the Danger Within: Hardcoded Cloud Credentials in Popular Mobile Apps
https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps
2024-10-25
Link to episode

ISC StormCast for Wednesday, October 23rd, 2024

How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?
https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372
VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Unifi Security Advisory Bulletin 043
https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7
Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability.
https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability
Atlassian Security Bulletin - October 15 2024
https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html
OneDev Arbitrary file reading for unauthenticated user
https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489
2024-10-23
Link to episode

ISC StormCast for Monday, October 21st, 2024

ISC StormCast for Friday, October 18th, 2024

Scanning Activity from Subnet 15.184.0.0/16.
https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362
Gatekeeper Bypass
/unit42.paloaltonetworks.com/gatekeeper-bypass-macos/
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2024.html
Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy
SAP Vulnerability
https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/
Dept. of Commerce Sites Advertising Medication
https://x.com/tliston/status/1833542884047654984
2024-10-18
Link to episode

ISC StormCast for Wednesday, October 16th, 2024

ISC StormCast for Tuesday, October 15th, 2024

ISC StormCast for Wednesday, October 9th, 2024

A tiny webapp by I'm With Friends.
Updated daily with data from the Apple Podcasts.