SANS Stormcast: Daily Cyber Security News podcast artwork

PODCAST · technology

SANS Stormcast: Daily Cyber Security News

A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

Publisher-supplied feed metadata · PodParley refreshed Sep 18, 2026 · Source feed

  1. 1000

    SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack

    Guildma (Astaroth) malware infection from Brazilian Portuguese emailhttps://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300 Authentication bypass in EOL Proxmox VE 7 release https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849 Updated Windows Server hotpatch calendarhttps://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#windows-server-hotpatch-calendar Virtualizor BGP Hijackinghttps://www.virtualizor.com/blog/security-incident-bgp-hijacking/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  2. 999

    SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware;

    The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversaryhttps://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298 PaperCut Public Exploit Availablehttps://github.com/rapid7/metasploit-framework/pull/21842 TerminalFix Campaign;https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  3. 998

    SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car

    DOUBLECUP's PNG Payloadhttps://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274 AliExpress WebAudio fingerprintinghttps://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Expired DMARC Reporting Domain Exposed 86 Domainshttps://www.sh.consulting/blog/abandoned-dmarc-reporting-domain Android Car Malwarehttps://securelist.com/android-head-unit-malware/121106/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  4. 997

    SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware

    Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprayshttps://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malwarehttps://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  5. 996

    SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI

    CoSnitch: When Your AI Assistant Becomes Its Own Whistleblowerhttps://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its websitehttps://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Updatehttps://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryptionhttps://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  6. 995

    SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM

    Apple Patches or iOS and macOShttps://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Securityhttps://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memoryhttps://www.usenix.org/system/files/usenixsecurity26-collins.pdf My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  7. 994

    SANS Stormcast Wednesday, July 22nd, 2026: Captive Portals; Critical Serv-U and Zimbra Update; Apple Hide-My-Email fix

    Captive Portal Detectionhttps://isc.sans.edu/diary/Captive%20Portal%20Detection/33172 Critical SolarWinds Serv-U Updatehttps://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm Zimbra Update with Critical Security Fixeshttps://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/ Apple Fixed Hide My E-Mail Leakhttps://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  8. 993

    SANS Stormcast Tuesday, July 21st, 2026: More Wordpress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability

    WordPress Exploitation Underway (CVE-2026-63030)https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168 HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channelshttps://www.group-ib.com/blog/hollowgraph-microsoft-365/ Gitea Vulnerablity CVE-2026-58443https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  9. 992

    SANS Stormcast Tuesday, July 7th, 2026: RCS and DNS; OpenSSH Update; Beyond Trust Advisory; PolinRider Update

    RCS and DNS: The NAPTR Recordhttps://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124 OpenSSH 10.4 releasedhttps://seclists.org/oss-sec/2026/q3/62 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 PolinRider: North Korea-Linked Supply Chain Campaignhttps://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  10. 991

    SANS Stormcast Wednesday, June 24th, 2026: Patching vs. Configurations Updates; libssh2 and ffmpeg vuln;

    CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094 libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.chttps://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c PixelSmash Critical FFmpeg Vulnerability Turns Media Files into Weaponshttps://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  11. 990

    SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage

    From a VHDX File to a Remcos RAThttps://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080 A backdoor in a LinkedIn job offerhttps://roman.pt/posts/linkedin-backdoor/ A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stackhttps://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html Copilot M365 Data Leakagehttps://www.varonis.com/blog/searchleak My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  12. 989

    SANS Stormcast Tuesday, June 16th, 2026: BASE64 Statistics; Cisco SD-WAN Exploited; AMD TSME Disabled; Poisoning Deep Research Agents

    Evil MSI Background: BASE64 Statistical Analysishttps://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072 Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerabilityhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ TSME/SME not activating on Ryzen 7 9700Xhttps://github.com/AMDESE/AMDSEV/issues/292 Deep-Research Agents Can Be Poisoned via User-Generated Contenthttps://arxiv.org/pdf/2605.24245 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  13. 988

    SANS Stormcast Monday, June 15th, 2026: Arch Linux Malicious User Packages; Splunk Vuln and Exploit; Exploiting AI Coding Agents

    Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malwarehttps://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/ A Fake Bug Report Hijacks Your AI Coding Agent and Nothing Catches It.https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  14. 987

    SANS Stormcast Friday, June 12th, 2026: Bitlocker Trouble; Ivanti and Oracle Exploited; macOS Malicious Installers

    More Bitlocker Issues: GreatXMLhttps://git.churchofmalware.org/Nightmare_Eclipse/GreatXML Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US Oracle Security Alert Advisory - CVE-2026-35273https://www.oracle.com/security-alerts/alert-cve-2026-35273.htmlhttps://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/ How Deceptive Installers Are Targeting macOS Usershttps://www.huntress.com/blog/deceptive-installers-macos-infostealers My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

  15. 986

    SANS Stormcast Thursday, May 14th, 2026: Flexbile Windows Proxy; News from Nightmare Eclipse; Adobe Patches

    Proxying the Unproxyable? Sending EXE traffic to a Proxyhttps://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982 New Nightmare Eclipse Vulnerabilities Disclosedhttps://github.com/Nightmare-Eclipse/YellowKeyhttps://github.com/Nightmare-Eclipse/GreenPlasma Adobe Patcheshttps://helpx.adobe.com/security.html

  16. 985

    SANS Stormcast Friday, May 8th, 2026: AI Generated Dashboard; Ivanti Patches; Redis Vuln; @sans_edu Marcio Enriquez

    An Adaptive Cyber Analytics UI for Web Honeypot Logshttps://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962 Ivanti May Patchdayhttps://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs Redis Security advisory: [CVE 2026 23479] [CVE 2026 25243] [CVE-2026-25588] [CVE 2026 25589] [CVE-2026-23631]https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/ @sans_edu research paper: Marcio Enriquez [link will be added once the paper has been published]

  17. 984

    SANS Stormcast Thursday, May 7th, 2026: .DE DNSEC Fail; PAN OS 0-Day Patched;

    Technical issue with .de domainshttps://blog.denic.de/en/technical-issue-with-de-domains-resolved/ CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID Authentication Portalhttps://security.paloaltonetworks.com/CVE-2026-0300 Android Security Bulletin May 2026 CVE-2026-0073https://source.android.com/docs/security/bulletin/2026/2026-05-01

  18. 983

    SANS Stormcast Wednesday, May 6th, 2026: Cleartext Passwords in Edge; SSL.com Root Rotation; DAEMONTOOLS Backdoor;

    Cleartext Passwords in MS Edge? In 2026?https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954 SSL.com rotates its root certificate todayhttps://isc.sans.edu/diary/SSL.com%20rotates%20their%20root%20certificate%20today/32956 DEAMONTOOLS Compromisehttps://securelist.com/tr/daemon-tools-backdoor/119654/

  19. 982

    SANS Stormcast Tuesday, May 5th, 2026: Honeypot Update; MOVEit Patches; Apache http2 Vuln;

    DShield Honeypot Updatehttps://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948 MOVEit Automation Critical Security Alert Bulletin April 2026 (CVE-2026-4670, CVE-2026-5174)https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174 Apache httpd http2 vulnerabilityhttps://seclists.org/oss-sec/2026/q2/387

  20. 981

    SANS Stormcast Monday, May 4th, 2026: Malicious Homebrew Ads; Wireshark Update; Digicert False Positive; cPanel Exploited

    Malicious Ad for Homebrew Leads to MacSync Stealerhttps://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942 Wireshark Updatehttps://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html Digicert Microsoft Defender False Positivehttps://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/https://bugzilla.mozilla.org/show_bug.cgi?id=2033170 cPanel Exploitedhttps://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

  21. 980

    SANS Stormcast Friday, May 1st, 2026: Libredtail; FreeBSD dhclient vuln; Linux Copy-Fail; @sans_edu Detecting AI Pickling

    Danger of Libredtailhttps://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936 FreeBSD dhclient vulnerabilityhttps://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc Linux Copy-Fail Vulnerability CVE-2026-31431https://copy.fail Bryan Nice Research Paperhttps://www.linkedin.com/in/bryannice/https://www.sans.edu/cyber-research/detecting-ai-pickling

  22. 979

    SANS Stormcast Thursday, April 30th, 2026: Odd Requests; MSFT LNK Bug Exploited; Secure Boot Fix; TLS Updates; SAP npm malware

    Today's Odd Web Requestshttps://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934 Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202 Assess Secure Boot status with Microsoft Defenderhttps://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356 Deprecating Legacy TLS and Endpoints for POP and IMAP in Exchange Onlinehttps://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201 SAP Related npm Packages Compromisedhttps://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared

  23. 978

    SANS Stormcast Wednesday, April 29th, 2026: Odd Vercel Header Usage; GitHub Vuln Patches; MSFT RDP Notification Bug

    HTTP Requests with X-Vercel-Set-Bypass-Cookie Headerhttps://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930 GitHub Vulnerability CVE-2026-3854https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854 Microsoft RDP Notification Bughttps://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

HOSTED BY

Johannes Ullrich

CATEGORIES

Frequently Asked Questions

How many episodes does SANS Stormcast: Daily Cyber Security News have?

SANS Stormcast: Daily Cyber Security News currently has 23 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is SANS Stormcast: Daily Cyber Security News about?

A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on...

How often does SANS Stormcast: Daily Cyber Security News release new episodes?

SANS Stormcast: Daily Cyber Security News has 23 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to SANS Stormcast: Daily Cyber Security News?

You can listen to SANS Stormcast: Daily Cyber Security News on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts SANS Stormcast: Daily Cyber Security News?

SANS Stormcast: Daily Cyber Security News is created and hosted by Johannes Ullrich.
URL copied to clipboard!