PODCAST · news
SANS Internet Storm Center's Daily Network Security News Podcast
by Johannes B. Ullrich
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
-
1000
SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens (#)
SANS Stormcast Wednesday, September 16th, 2026: MacOS 27 Traffic; Cisco 0-Day; Protecting Active Directory and API Tokens MacOS 27 - First Boot https://isc.sans.edu/diary/MacOS%2027%20-%20First%20Boot/33340 Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX Detecting and Mitigating Active Directory Compromises https://www.cisa.gov/resources-tools/resources/detecting-and-mitigating-active-directory-compromises Protecting Tokens and Assertions from Forgery, Theft, and Misuse https://nvlpubs.nist.gov/nistpubs/ir/2026/NIST.IR.8587.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: tokens; api; active directory; cisco; macos;
-
999
SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln (#)
SANS Stormcast Tuesday, September 15th, 2026: Apple Updates; Homebrew Update; MSFT OOB Patch; Telegram Vuln Apple Updates Everything https://isc.sans.edu/diary/Apple%20Updates%20Everything/33336 Homebrew 7 Released https://brew.sh/2026/09/13/homebrew-7.0.0/ Microsoft Out-of-Band Patch https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5129195-windows-11-24h2-25h2-security-update Telegram XSS Vulnerability https://expatch.com/writeups/telegram-html-export-xss.html My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: telegram; microsoft; rds; homebrew; apple; macos; ios; ipadod; watchos; tvos
-
998
SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks (#)
SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks Redtail Payload Analysis https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326 Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 Netscaler ADC Exploit https://x.com/ethicalhack3r/status/2095480651478663393 Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: sonicwall; netscaler; csico; checkpoint; redtail
-
997
SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns. (#)
SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns. Scans for Proxmox Servers https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324 Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md Google Chrome Updates https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: fortipam; google; chrome; proxmox
-
996
SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday (#)
SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday September 2026 Microsoft Patch Tuesday https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320 Adobe Security Bulletins https://helpx.adobe.com/security/security-bulletin.html Security Advisory Ivanti Neurons for ITSM https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US Fortinet Advisory https://www.fortiguard.com/psirt/FG-IR-26-174 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: fortinet; ivanti; neurons; itsm; adobe; microsoft
-
995
SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM (#)
SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM Apple Patches or iOS and macOS https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Security https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory https://www.usenix.org/system/files/usenixsecurity26-collins.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: macos; ios; apple; screen sharing; screensharing; vnc; ram; windows;
-
994
SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited; (#)
SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited; macOS Screen Sharing Vulnerability Exploited https://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patch https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Commerce Cloud Vuln Exploited https://x.com/DefusedCyber/status/2088240809355153647 ChainDrop npm Worm https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: chaindrop; npm; worm; sap; commerce; cloud; geoserver; macos; screensharing
-
993
SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion (#)
SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242 CPU Privilege Escalation https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii https://github.com/xoreaxeaxeax/skitter-creek-bath-salts GeoServer Vulnerability https://x.com/q1uf3ng/status/2087490992723407096 Windows USB Driver Vulnerability https://x.com/0xedh/status/2085842285481062887 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: windows; usb; geoserver; cpu; privilege escalation; ssm; gemma4; ai; honeypot; ollama; hashes
-
992
SANS Stormcast Thursday, August 13th, 2026: Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI regulation (#)
SANS Stormcast Thursday, August 13th, 2026: Process Accounting; ShieldBreak; SharePoint JWT Vuln PoC; AI regulation Linux Kernel Process Accounting https://isc.sans.edu/diary/Linux%20Kernel%20Process%20Accounting/33240 ShieldBreak - Windows Defender 0day vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ California law puts digital fingerprints on AI fakes https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: california; ai; eu; europe; microsoft; sharepoint; jwt; shidlbreak; linux; kernel; process; accounting
-
991
SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi (#)
SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi Microsoft Patch Tuesday https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236 Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415 https://a.security/blog/asecurity-zoomsday Mozilla Revokes GPG Key https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Rogue Inflight Wifi https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: wifi; delta; mozilla; gpg key; zoom; microsoft; patches;
-
990
SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch (#)
SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch Scans for Solana (Surfpool?) Endpoints https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230 Why AI-generated vulnerability patches still require expert human review https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013 Gunra Ransomware https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf Neo4J/GraphQL Vulnerability CVE-2026-5423 https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: neo4j; graphql; gunra; ransomware; vulnerabilities; ai; patches; sonana;
-
989
SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln; (#)
SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln; Linux Shell Forensic: Let's Dive Into Atuin! https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226 Apple Patches macOS Screen Sharing Vulnerability https://support.apple.com/en-us/148170 More N-Able N-Central Issues https://www.n-able.com/blog/n-central-security-update-august-6-2026 Metabase Unauthenticated SQL injection https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: metabase; n-able; n-central; apple; macos; screen sharing; linux; atuin
-
988
SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu) (#)
SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu) 22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary] https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220 Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/ Ill Bloom: Crypto Wallet Vulnerability https://illbloom.org Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: sans.edu; @sans_edu; research; llm; threatintel; crypto; wallet; ill bloom; cryptojs; bios; ssh;
-
987
SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish (#)
SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218 IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co COLDCARD Issues https://x.com/threatinsight/status/2084328552481112429 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: coldcard; phishing; private relay; icloud; proxy; tor; browser; keyv; cacheable; npm; worm
-
986
SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys (#)
SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys Botnet Hunting for Vulnerabilities in Diagnostic Tools https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214 Inside Greatness: Telegram-Distributed M365 AiTM PhaaS https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing A Deep Dive Into the Latest XCSSET Version https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: nuget; xcsset; telegram; m365; device code; mitm; phishing; botnet; diagnostic
-
985
SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey (#)
SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey AUR packages adoption disabled https://lists.archlinux.org/archives/list/[email protected]/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/ Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/ Pass the Passkey: A Novel Attack Surface in Passwordless Authentication https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: passkey; apple; icloud; employee; aur; arch; linux
-
984
SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability (#)
SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability zipdump.py Metadata Encoding https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/ Atomic MacOS (AMOS) stealer infection https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208 Phishing Campaigns Targeting AI Solutions Providers https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/ Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: rng; random; phishing; coldcard; cold wallet; open ai; atomic; macos; stealer; zipdump
-
983
SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats (#)
SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198 Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh Inconsistent Group Chats https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: cisco; ssh; minder; nvidia; group chats; encryption;
-
982
SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch (#)
SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch Apple Patch Summary / Postscript https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196 IPMI Admin Password Hash Leak https://lavahq.io/research/bmc-exposure-alert Patches for VMWare https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 OpenWRT Patch, odhcpd vulnerability CVE-2026-53921 https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: openwrt; odhcpd; vmware; ipmi; apple
-
981
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit (#)
SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit AutoIT Payload Injector https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192 Apple Security Update https://support.apple.com/en-us/100100 SourTrade: Browser-Assembled Malware Delivered Through Malvertising https://blog.confiant.com/p/sourtrade-browser-assembled-malware NGINX Exploit CVE-2026-42530, CVE-2026-42533 https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: nginx; sourtrade; apple; autoit
-
980
SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update (#)
SANS Stormcast Tuesday, July 28th, 2026: Spring Boot Scans; VBulletin Vulnerability; MSFT Defender for Linux; MongoDB Update Java Spring Boot "heapdump" scans https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188 VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/ Microsoft Defender for Linux Update may disable restart https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009 MongoDB Updates CVE-2026-13072 https://github.com/advisories/GHSA-wvx7-gr2m-7rf5 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: mongodb; defender; linux; microsoft; vbulletin; rce; java; spring; boot
-
979
SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates (#)
SANS Stormcast Monday, July 27th, 2026: ESAFENET CDG Scans; DNS Poisoning; macOS Gatekeeper bypass; GitHub and PyPi updates Scans for ESAFENET CDG 3 Document Management System Weak Logins https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184 DNS Poisoning Tactics Expand to Hospitality Wi-Fi https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/ Silent Replacement of Trusted macOS App Executables https://mysk.blog/2026/07/23/macos-overwrite-app-executables/ GitHub and PyPi Defense updates https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/ https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/ https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: github; pypi; dns; wifi; hotel; macos; applications; gatekeeper;
-
978
SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2 (#)
SANS Stormcast Friday, July 24th, 2026: OpenAI vs. Huggingface; Zimbra Exploited; Notepad++ Abuse; Browser as C2 When the "Autonomous Attacker" Is Your Own AI Model https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180 Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a https://cert.gov.ua/article/6318634 https://cybersecuritynews.com/hackers-abuse-notepad-plugins/ Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: browser; c2; msarat; cert; notepad++; openai; huggingface; zimbra
-
977
SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface (#)
SANS Stormcast Thursday, July 23rd, 2026: Rondo and Geoserver; Oracle Patches; Checkpoint 0-day; OpenAI vs Huggingface Rondo Meets Geoserver https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176 Oracle July Patch Update https://www.oracle.com/security-alerts/cpujul2026.html OpenAI and Hugging Face partner to address security incident during model evaluation https://openai.com/index/hugging-face-model-evaluation-security-incident/ Checkpoint July 2026 Security Advisory (CVE-2026-16232) https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: checkpoint; openai; huggingface; oracle; rondo; geoserver
-
976
SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix (#)
SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix Captive Portal Detection https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172 Critical SolarWinds Serv-U Update https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm Zimbra Update with Critical Security Fixes https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/ Apple Fixed Hide My E-Mail Leak https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: apple; e-mail; privacy; zimbra; hide-my; solarwinds; serv-u; captive; portal
-
975
SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability (#)
SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability WordPress Exploitation Underway (CVE-2026-63030) https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168 HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels https://www.group-ib.com/blog/hollowgraph-microsoft-365/ Gitea Vulnerablity CVE-2026-58443 https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: calendar; microsoft; o365; gitea; wordpress; exploitation;
-
974
SANS Stormcast Friday, July 17th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE (#)
SANS Stormcast Friday, July 17th, 2026: Hikvision Scans; LG Spyware; Huggingface Hack; Wordpress Core RCE Scans for Hikvision Intelligent Security API https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164 LG Monitor Spyware https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt https://www.youtube.com/watch?v=Q9uefFYe6bM Huggingface Hack https://huggingface.co/blog/security-incident-july-2026 Wordpress Core RCE https://wp2shell.com keywords: wordpress; shell; wp2shell; huggingface; lg; monitor; spyware; compromise; hikvision
-
973
SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln (#)
SANS Stormcast Friday, July 17th, 2026: Windows Hello for Business; NGINX Vuln; 7-zip vuln German Federal Information Security Office Analyzes Windows Hello for Business https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7 NGINX Vulnerability https://my.f5.com/manage/s/article/K000162097 7-Zip XZ Decompression CVE-2026-14266 https://www.zerodayinitiative.com/advisories/ZDI-26-444/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: 7zip; nginx; windows; hello;
-
972
SANS Stormcast Thursday, July 16th, 2026: DShield SIEM Update; MSFT Patches vs. Intel IPF; Zoom Patch; Forgotten UEFI Shims (#)
SANS Stormcast Thursday, July 16th, 2026: DShield SIEM Update; MSFT Patches vs. Intel IPF; Zoom Patch; Forgotten UEFI Shims DShield SIEM Update https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156 Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875 Zoom Account Takeover Patch https://www.zoom.com/en/trust/security-bulletin/zsb-26014/ Forgotten UEFI shims undermining Secure Boot https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: uefi; boot; zoom; patch; intel; dell; ipf; siem; dshield
-
971
SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration (#)
SANS Stormcast Wednesday, July 15th, 2026: Microsoft Patches; New MSFT Priv Escalation; Progress ShareFile 0-Day; Grok Exfiltration Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154 LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/ xAI/Grok Exfiltrating Data and Secrets https://cereblab.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: grok; xai; progress; sharefile; storage; legacyhive; microsoft
-
970
SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln; (#)
SANS Stormcast Tuesday, July 14th, 2026: MCP/AI Related Scans; Improve Router Hygiene; OAuth Client ID Spoofing; Veeam Vuln; Someone Is Scanning for Your MCP Servers and AI Assistant Credentials https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150 Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a OAuth Client ID Spoofing https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 https://www.veeam.com/kb4869 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: veeam; oauth; router; cisco; russian; mcp; ai; scanning
-
969
SANS Stormcast Monday, July 13th, 2026: Progress Sharefile Shutdown; U-Boot Vuln; More Nightmare Eclipse; Cisco AI Response (#)
SANS Stormcast Monday, July 13th, 2026: Progress Sharefile Shutdown; U-Boot Vuln; More Nightmare Eclipse; Cisco AI Response Progress Sharefile Emergency Shutdown Notice https://status.sharefile.com https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/ https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/ U-Boot Vulnerabilities https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification Nightmare Eclipse Releases Next Microsoft Defender Exploit https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/ Cisco Increases Patch Cadence https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: cisco; patches; nightmare eclipes; defender; microsoft; progress; sharefile; u-boot
-
968
SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch (#)
SANS Stormcast Friday, July 10th, 2026: Belarus Graffiti Bot @sans_edu; Discontinuing Mac OS Ext. FS; Chrome Update; Rogue Planet Patch _HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary] https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28 https://support.apple.com/en-us/125615 Google Chrome Update https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656 https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: microsoft; rogue planet; nightmare eclypse; google; chrome; apple; apfs; belarus;
-
967
SANS Stormcast Thursday, July 9th, 2026: Stack Simulator; RootAsRole; Hoymiles; Git Hash Malleability (#)
SANS Stormcast Thursday, July 9th, 2026: Stack Simulator; RootAsRole; Hoymiles; Git Hash Malleability My Stack Simulator https://isc.sans.edu/diary/My%20Stack%20Simulator/33138 RootAsRole https://github.com/LeChatP/RootAsRole Hoymiles Inverter Vulnerability https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf Git Hash Chain Malleability https://arxiv.org/abs/2607.02820 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: gith; github; hoymiles; solar; rootasrole; sudo ; stack; simulator
-
966
SANS Stormcast Wednesday, July 8th, 2026: Odd DNS; AnyDesk Phishing; Tenda Backdoor; GitLost (#)
SANS Stormcast Wednesday, July 8th, 2026: Odd DNS; AnyDesk Phishing; Tenda Backdoor; GitLost More Odd DNS Records: NIMLOC https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128 From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/ Tenda firmware (multiple versions) contains hidden authentication backdoor https://kb.cert.org/vuls/id/213560 GitLost: GitHub AI Agent Leak https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: gitlost; github; tenda; anydesk; nimloc; dns
-
965
SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update (#)
SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update RCS and DNS: The NAPTR Record https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124 OpenSSH 10.4 released https://seclists.org/oss-sec/2026/q3/62 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139 https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 PolinRider: North Korea-Linked Supply Chain Campaign https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: polinrider; supply chain; north korea; beyond trust; openssh; rcs; dns; naptr;
-
964
SANS Stormcast Monday, July 6th, 2026: Apple Patch Policy; FatFS Vulns; OpenWRT; Multi-Agent Offensive AI; (#)
SANS Stormcast Monday, July 6th, 2026: Apple Patch Policy; FatFS Vulns; OpenWRT; Multi-Agent Offensive AI; Apple Updated Patch Policy https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/ T3MP3ST multi-agent offensive-security framework https://github.com/elder-plinius/T3MP3ST Seven FatFs bugs, one very large blast radius https://www.runzero.com/blog/fatfs-bugs/ OpenWRT Releases v25.12.5 https://github.com/openwrt/openwrt/releases My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: openwrt; fatfs; t3mp3st; apple; ai;
-
963
SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln (#)
SANS Stormcast Thursday, July 2nd, 2026: MetaMask Phishing; Adobe Patches; Google Chrome Patches; Apple Hide-My-Email Vuln Why Ask Credentials If There Are Secret Codes? https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118 Adobe Patches and Updated Patch Release Policy https://helpx.adobe.com/security/Home.html https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery Google Chrome Update (link had issues loading while recording) https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html Apple Hide My Email Vulnerability https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: Metamask; phishing; crypto; MFA; Adobe; Google; Chrome; Patches; Apple; hide-my-email
-
962
SANS Stormcast Wednesday, July 1st, 2026: Apple Patches; SimpleHelp Exploit; Git DNS Tricks; (#)
SANS Stormcast Wednesday, July 1st, 2026: Apple Patches; SimpleHelp Exploit; Git DNS Tricks; June 2026 Apple Updates https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114 SimpleHelp Exploit used to reply TaskWeaver https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/ DNS Tricks to Load Malware into Cloned Repository https://0din.ai/blog/clone-this-repo-and-i-own-your-machine My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: Simplehelp; taskweaver; apple; ios; macos; safari;
-
961
SANS Stormcast Tuesday, June 30th, 2026: Favicon Recon Automation; Targeting Messaging; Gemini CLI vuln; IPv6 Frag Escape (#)
SANS Stormcast Tuesday, June 30th, 2026: Favicon Recon Automation; Targeting Messaging; Gemini CLI vuln; IPv6 Frag Escape Adding some Automation to the favicon.ico method of Host Recon https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110 Russian Intelligence Services Continue to Target Commercial Messaging Applications https://www.ic3.gov/PSA/2026/PSA260626 Google Gemini CLI Vulnerability CVE-2026-12537 https://github.com/advisories/GHSA-jj69-4grx-fqj5 IPv6 Frag Escape https://github.com/sgkdev/ipv6_frag_escape My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: google; gemini; cli; messenger; ipv6; container; escape; favicon
-
960
SANS Stormcast Monday, June 29th, 2026: Automated Cybercrime; Linux Process Names; Amazon Q VS Code (#)
SANS Stormcast Monday, June 29th, 2026: Automated Cybercrime; Linux Process Names; Amazon Q VS Code What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104 Linux Process Name Masquerading https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102 Amazon Q VS Code Extension Vulnerability https://www.wiz.io/blog/amazon-q-vulnerability My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: amazon; q; linux; process; port; sans_edu; internship
-
959
SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage (#)
SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage From a VHDX File to a Remcos RAT https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080 A backdoor in a LinkedIn job offer https://roman.pt/posts/linkedin-backdoor/ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html Copilot M365 Data Leakage https://www.varonis.com/blog/searchleak My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: vhdx; remcos; rat; backdoor; linkedin; job offer; openbsd; ppp; copilot; m365;
-
958
SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents (#)
SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents Evil MSI Background: BASE64 Statistical Analysis https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072 Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ TSME/SME not activating on Ryzen 7 9700X https://github.com/AMDESE/AMDSEV/issues/292 Deep-Research Agents Can Be Poisoned via User-Generated Content https://arxiv.org/pdf/2605.24245 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: base64; msi; wallpaper; cisco; sd-wan; 0-day; amd; ryzen; deep-research; llm; seo;
-
957
SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers (#)
SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers More Bitlocker Issues: GreatXML https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523) https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US Oracle Security Alert Advisory - CVE-2026-35273 https://www.oracle.com/security-alerts/alert-cve-2026-35273.html https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ How Deceptive Installers Are Targeting macOS Users https://www.huntress.com/blog/deceptive-installers-macos-infostealers My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: oracle; ivanti; bitlocker; greatxml; peoplesoft; mac malware;
-
956
SANS Stormcast Thursday, June 11th, 2026: Framing Protections; npm improvements; Adobe Patches; New Defender 0-day (#)
SANS Stormcast Thursday, June 11th, 2026: Framing Protections; npm improvements; Adobe Patches; New Defender 0-day How has use of framing protection security headers changed in the past 3 years? https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068 Preparing for npm v12: install scripts and non-registry sources become opt-in https://github.com/orgs/community/discussions/198547 Adobe Patches https://helpx.adobe.com/security.html Rogue Planet new Microsoft Defender Vulnerability https://github.com/MSNightmare/RoguePlanet My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: rogue planet; defender; vulnerability; 0-day; adobe; npm; headers; iframe;
-
955
SANS Stormcast Wednesday, June 10th, 2026: Microsoft Patch Tuesday; Miasma Source Published; Fortinet Patches (#)
SANS Stormcast Wednesday, June 10th, 2026: Microsoft Patch Tuesday; Miasma Source Published; Fortinet Patches Microsoft June 2026 Patch Tuesday https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064 Miasma Software Supply Chain Attack Toolkit Source Published https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/ Fortinet FortiSandbox Vulnerability https://fortiguard.fortinet.com/psirt/FG-IR-26-141 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: fortinet; fortisandbox; miasma; supply chain; microsoft; patches
-
954
SANS Stormcast Tuesday, June 9th, 2026: Azure Repos Infected; Checkpoint VPN 0-Day; Verizon VoLTE missing IPSec integrity prot. (#)
SANS Stormcast Tuesday, June 9th, 2026: Azure Repos Infected; Checkpoint VPN 0-Day; Verizon VoLTE missing IPSec integrity prot. Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments https://kb.cert.org/vuls/id/615987 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: verizon; ipsec; volte; checkpoint; check point; vpn; azure;
-
953
SANS Stormcast Monday, June 8th, 2026: Wetransfer Phish; Spying Smart TV; Dashlane Brute Force (#)
SANS Stormcast Monday, June 8th, 2026: Wetransfer Phish; Spying Smart TV; Dashlane Brute Force The Evil MSI Background is Back! https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054 The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/ Brute force attack on Dashlane user accounts https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts#update-jun-4 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: dashlane; smart tv; proxy; ai; evil; msi; background; cloudlfare; wetransfer
-
952
SANS Stormcast Friday, June 5th, 2026: Coreutils for Windows; Cisco Unified Comm Manager Fix and Exploit; OAuth Orphans (#)
SANS Stormcast Friday, June 5th, 2026: Coreutils for Windows; Cisco Unified Comm Manager Fix and Exploit; OAuth Orphans Microsoft's Coreutils for Windows https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048 Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW Firmware Update for Acer Connect W6x Router https://community.acer.com/en/kb/articles/19672 OAuth marketplace apps keep access after publishers vanish https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: acer; cisco; microsoft; coreutils; oauth
-
951
SANS Stormcast Thursday, June 4th, 2026: swagger.json Scans; Android Fake Call Detection; Anthropic Dashboard (#)
SANS Stormcast Thursday, June 4th, 2026: swagger.json Scans; Android Fake Call Detection; Anthropic Dashboard Continuing Scans for swagger.json https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments Fake call detection on Android https://blog.google/security/android-fake-call-detection/ Anthropic's coordinated vulnerability disclosure dashboard https://red.anthropic.com/2026/cvd/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: swagger; json; adnroid; caller-id; anthropic; dashboard;
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
HOSTED BY
Johannes B. Ullrich
Loading similar podcasts...