• Get the App
  • Moon FM - The Ultimate Podcast App
  • Get the App
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

Johannes B. Ullrich

Daily update on current cyber security threats

  • 9 minutes 12 seconds
    SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Mozilla Revokes Key; Rogue Inflight Wifi

    Microsoft Patch Tuesday
    https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20August%202026/33236
    Zoom Vulnerablities CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415
    https://a.security/blog/asecurity-zoomsday
    Mozilla Revokes GPG Key
    https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
    Rogue Inflight Wifi
    https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    12 August 2026, 2:00 am
  • 6 minutes 21 seconds
    SANS Stormcast Tuesday, August 11th, 2026: Solana Attacks; AI Generated Patches; Gunra Ransomware; Neo4J/GraphQL Patch

    Scans for Solana (Surfpool?) Endpoints
    https://isc.sans.edu/diary/Scans%20for%20Solana%20%28Surfpool%3F%29%20Endpoints/33230
    Why AI-generated vulnerability patches still require expert human review
    https://1password.com/blog/why-ai-generated-patches-still-require-human-review?_sp=15ec2845-9e6c-4d15-8ac5-fe9bc1fe4c08.1786396502013
    Gunra Ransomware
    https://www.cisa.gov/sites/default/files/2026-08/aa26-222a-stopransomware-gunra-ransomware_508c.pdf
    Neo4J/GraphQL Vulnerability CVE-2026-5423
    https://github.com/neo4j/graphql/security/advisories/GHSA-fcpg-3fw5-vc65
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    11 August 2026, 2:00 am
  • 8 minutes 3 seconds
    SANS Stormcast Monday, August 10th, 2026: Linux Shell Forensics; Criticial MacOS Patch; More N-Central Hotfixes; Exploited Metabase Vuln;

    Linux Shell Forensic: Let s Dive Into Atuin!
    https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226
    Apple Patches macOS Screen Sharing Vulnerability
    https://support.apple.com/en-us/148170
    More N-Able N-Central Issues
    https://www.n-able.com/blog/n-central-security-update-august-6-2026
    Metabase Unauthenticated SQL injection
    https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    10 August 2026, 2:00 am
  • 16 minutes 29 seconds
    SANS Stormcast Friday, August 7th, 2026: Fast SSH Attacks; Dell BIOS Passwd Weakness; Crypto Wallet Vuln; Benchmarking LLMs for Threat Intel (@sans_edu)

    22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]
    https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220
    Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
    https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/
    Ill Bloom: Crypto Wallet Vulnerability
    https://illbloom.org
    Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence
    https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    7 August 2026, 2:00 am
  • 8 minutes 23 seconds
    SANS Stormcast Thursday, August 6th, 2026: keyv/cachable Worm IR; Apple Private Relay Leak; COLDCARD Phish

    Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
    https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218
    IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay
    https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co
    COLDCARD Issues
    https://x.com/threatinsight/status/2084328552481112429
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    6 August 2026, 2:00 am
  • 6 minutes 30 seconds
    SANS Stormcast Wednesday, August 5th, 2026: Diagnostic Tool Hunt; Device Code Phishing; XCSSET; NuGet API Keys

    Botnet Hunting for Vulnerabilities in Diagnostic Tools
    https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214
    Inside Greatness: Telegram-Distributed M365 AiTM PhaaS
    https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
    A Deep Dive Into the Latest XCSSET Version
    https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
    Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime
    https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    5 August 2026, 2:00 am
  • 6 minutes 50 seconds
    SANS Stormcast Tuesday, August 4th, 2026: More Arch Linux AUR trouble; iCloud Sharing; Pass the Passkey

    AUR packages adoption disabled
    https://lists.archlinux.org/archives/list/[email protected]/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/
    Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents
    https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/
    Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
    https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    4 August 2026, 2:00 am
  • 7 minutes 32 seconds
    SANS Stormcast Monday, August 3rd, 2026: zipdump.py update; Atomic MacOS Analysis; OpenAI Phishing; COLDCARD Vulnerability

    zipdump.py Metadata Encoding
    https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/
    Atomic MacOS (AMOS) stealer infection
    https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208
    Phishing Campaigns Targeting AI Solutions Providers
    https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/
    Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
    https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    3 August 2026, 2:00 am
  • 5 minutes 50 seconds
    SANS Stormcast Friday, July 31st, 2026: Pre Botnet Recon; Cisco Backdoor Exploited; Inconsistent Group Chats

    Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner
    https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198
    Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316
    https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
    Inconsistent Group Chats
    https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber
    https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    31 July 2026, 2:00 am
  • 6 minutes 57 seconds
    SANS Stormcast Thursday, July 30th, 2026: Apple Patches; IPMI Admin PW Hash Leak; VMWare Patches; OpenWRT Patch

    Apple Patch Summary / Postscript
    https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196
    IPMI Admin Password Hash Leak
    https://lavahq.io/research/bmc-exposure-alert
    Patches for VMWare
    https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
    OpenWRT Patch, odhcpd vulnerability CVE-2026-53921
    https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    30 July 2026, 2:00 am
  • 6 minutes 59 seconds
    SANS Stormcast Wednesday, July 29th, 2026: AutoIT Payload Injector; Appele Patches; SourTrade Malware; NGINX Exploit

    AutoIT Payload Injector
    https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192
    Apple Security Update
    https://support.apple.com/en-us/100100
    SourTrade: Browser-Assembled Malware Delivered Through Malvertising
    https://blog.confiant.com/p/sourtrade-browser-assembled-malware
    NGINX Exploit CVE-2026-42530, CVE-2026-42533
    https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main
    My Upcoming Classes
    https://www.sans.org/profiles/dr-johannes-ullrich
    29 July 2026, 2:00 am
  • More Episodes? Get the App

Discover

  • Featured
  • Top Charts
  • Popular

More

  • Get the App
  • News
  • Setting
  • Privacy Policy
  • Submit Your Podcast

Contact

  • [email protected]
  • Twitter
Your feedback is valuable to us. Should you encounter any bugs, glitches, lack of functionality or other problems, please email us at [email protected] or join where you can talk directly to the dev team.
© MoonFM 2026. All rights reserved.