Internet Storm Centre Podcast

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minute long, summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Stormcenter. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .

  • SANS Stormcast Friday, September 11th, 2026: Redtail Analsys (@sans_edu); Checkpoint VPN Patch; Netscaler and Sonicwall Attacks
    by Dr. Johannes B. Ullrich on September 11, 2026 at 2:00 am

    Redtail Payload Analysis https://isc.sans.edu/diary/Redtail%20Payload%20Analysis%20%5BGuest%20Diary%5D/33326 Checkpoint Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995 Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2 Netscaler ADC Exploit https://x.com/ethicalhack3r/status/2095480651478663393 Sonicwall SMA1000 Attack https://hunt.io/blog/sonicwall-sma1000-uk-council-attack My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Thursday, September 10th, 2026: Proxmox Scans; MSFT Defender, Gogole Chorme, and FortiPAM Vulns.
    by Dr. Johannes B. Ullrich on September 10, 2026 at 10:10 am

    Scans for Proxmox Servers https://isc.sans.edu/diary/Scans%20for%20Proxmox%20Servers/33324 Next Nightmare Eclipse Vulnerability https://github.com/MSNightmare/ShieldCrash/blob/main/README.md Google Chrome Updates https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html FortiPAM Vulnerability https://amibeingpwned.com/blog/fortinet-pam-vuln My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Wednesday, September 9th, 2026: Microsoft, Adobe, Ivanti, Fortinet Patch Tuesday
    by Dr. Johannes B. Ullrich on September 9, 2026 at 2:00 am

    September 2026 Microsoft Patch Tuesday https://isc.sans.edu/diary/September%202026%20Microsoft%20Patch%20Tuesday/33320 Adobe Security Bulletins https://helpx.adobe.com/security/security-bulletin.html Security Advisory Ivanti Neurons for ITSM https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US Fortinet Advisory https://www.fortiguard.com/psirt/FG-IR-26-174 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Tuesday, September 8th, 2026: numbat; MicroTik and Magento (Adobe Commerce) 0-Day
    by Dr. Johannes B. Ullrich on September 8, 2026 at 2:00 am

    numbat – AI agent observability https://isc.sans.edu/diary/numbat%20-%20AI%20agent%20observability/33312 MicroTik SSH 0-Day Exploited https://mikrotik.com/supportsec/september-2026-vulnerability/ https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ Adobe Commerce – Magento – 0-Day Exploited https://sansec.io/research/stylesmuggler-0day N-Able 4th Hotpatch https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Friday, September 4th, 2026: AV Exploits; Plex Update; Cisco Patches; Sangoma Switchvox Exploited
    by Dr. Johannes B. Ullrich on September 4, 2026 at 2:00 am

    Nightmare Eclipse Discloses Several Anti-Malware Privilege Escalation Exploits https://github.com/MSNightmare Plex Update https://forums.plex.tv/t/important-security-update-for-plex-media-server-v1-43-2-and-earlier/942319 Cisco Update https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY Sangoma Switchvox Exploit https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Thursday, September 3rd, 2026: SMA1000 0-Day Patch; SSRF Validation Issues; Faronics Abuse
    by Dr. Johannes B. Ullrich on September 3, 2026 at 2:00 am

    Sonicwall SMA1000 Exploited Vulnerability Patched https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016 SSRF: The Validator Can Lie https://xclow3n.com/post/the-validator-can-lie/ Git Hijack for AI Agents https://www.manifold.security/blog/ai-coding-agents-git-hijack Fronics Deploy Abuse https://www.huntress.com/blog/faronics-deploy-abuse My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Wednesday, September 2nd, 2026: Guildma Update; Proxmox 7 Auth Bypass; Windows Hotpatch; Virtualizor BGP Hack
    by Dr. Johannes B. Ullrich on September 2, 2026 at 2:00 am

    Guildma (Astaroth) malware infection from Brazilian Portuguese email https://isc.sans.edu/diary/Guildma%20%28Astaroth%29%20malware%20infection%20from%20Brazilian%20Portuguese%20email/33300 Authentication bypass in EOL Proxmox VE 7 release https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post-867929 https://gist.github.com/nebusecurity/65fe90dd673d395b7926278d7eaf5849 Updated Windows Server hotpatch calendar https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#windows-server-hotpatch-calendar Virtualizor BGP Hijacking https://www.virtualizor.com/blog/security-incident-bgp-hijacking/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Tuesday, September 1st, 2026: LLM Honeypot; PaperCut Update; TerminalFix Malware;
    by Dr. Johannes B. Ullrich on September 1, 2026 at 2:00 am

    The Coding-Agent Trap: When a “Free” LLM Endpoint Is the Adversary https://isc.sans.edu/diary/The%20Coding-Agent%20Trap%3A%20When%20a%20%22Free%22%20LLM%20Endpoint%20Is%20the%20Adversary/33298 PaperCut Public Exploit Available https://github.com/rapid7/metasploit-framework/pull/21842 TerminalFix Campaign; https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Monday, August 31st, 2026: Malware Statistics; PaperCut Update; Watchguard and DLink Patches;
    by Dr. Johannes B. Ullrich on August 31, 2026 at 2:00 am

    Some Malicious PE Stats https://isc.sans.edu/diary/Some%20Malicious%20PE%20Stats/33292 PaperCut Releases Two Preliminary Patches for Exploited Vulnerability https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ DLink Vulnerabliities https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10513 Watchguard Patches https://psirt.watchguard.com My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Friday, August 28th, 2026: Broken Polymorphic Phishing; Router Implants; llms.txt exploits; Papercut 0-Day
    by Dr. Johannes B. Ullrich on August 28, 2026 at 2:00 am

    A polymorphic phishing page (that occasionally breaks itself) https://isc.sans.edu/diary/A%20polymorphic%20phishing%20page%20%28that%20occasionally%20breaks%20itself%29/33290 Chinese Implants in the Supply Chain https://www.vulncheck.com/blog/zbt-darklantern-speakingstone?_sp=1068fa46-3d91-427e-8120-aa6d8bda2912.1787865822277 Data Became Code: We Ran Code Inside Fortune 500s Using Files They Published for AI Agents https://medium.com/@alonhertz1/data-became-code-we-ran-code-inside-fortune-500s-using-files-they-published-for-ai-agents-0cd67ffbbffc Papercut Security Advisory https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Thursday, August 27th, 2026: Entra ID Admins; Unifi Patches; log4j Vuln; Sleepwalker Malware
    by Dr. Johannes B. Ullrich on August 27, 2026 at 2:00 am

    Who Has Admin Rights in your Entra ID Directory? https://isc.sans.edu/diary/Who%20Has%20Admin%20Rights%20in%20your%20Entra%20ID%20Directory%3F/33284 Ubiquity Unifi Patches https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 Log4J FilteredObjectInputStream Vulnerability https://github.com/joanbono/log4j2-4255-exploit https://jeffmcjunkin.com/posts/log4j2-fois-marshalledobject/ Sleepwalker Malware https://r136a1.dev/2026/08/24/sleepwalker-a-passive-backdoor-with-its-own-command-language/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Wednesday, August 26th, 2026: Obfuscating SSRF; Paint and Photos AI Watermarks; FTP Banner C2;
    by Dr. Johannes B. Ullrich on August 26, 2026 at 2:40 am

    Obfuscating IP Addresses as Hostnames https://isc.sans.edu/diary/Obfuscating%20IP%20Addresses%20as%20Hostnames/33280 Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images https://xusheng.dev/posts/reversing/mspaint_invisible_watermark/main/ FTP Banners The New Dead Drop Resolver Delivering Novel RATs https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Tuesday, August 25th, 2026: DOUBLECUP PNG; WebAudio Fingerprinting; Expired Domains; Android; Car
    by Dr. Johannes B. Ullrich on August 25, 2026 at 2:00 am

    DOUBLECUP’s PNG Payload https://isc.sans.edu/diary/DOUBLECUP%27s%20PNG%20Payload/33274 AliExpress WebAudio fingerprinting https://blog.laserphile.com/2026/08/aliexpress-webpage-keeping-multipoint.html Expired DMARC Reporting Domain Exposed 86 Domains https://www.sh.consulting/blog/abandoned-dmarc-reporting-domain Android Car Malware https://securelist.com/android-head-unit-malware/121106/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Monday, August 24th, 2026: More Entra Powershell; Entra Vulnerability; GitLab Vuln (and PoC); GTA 6 Leak Malware
    by Dr. Johannes B. Ullrich on August 24, 2026 at 2:00 am

    Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! https://isc.sans.edu/diary/Who%20Got%20Missed%20in%20the%20MFA%20Rollout%3F%20More%20Powershell%20%2B%20Graph%20%2B%20Entra%20scripting!/33272 Even MOAR Powershell, looking at Entra logins – the good, the bad and the password sprays https://isc.sans.edu/diary/Even%20MOAR%20Powershell%2C%20looking%20at%20Entra%20logins%20-%20the%20good%2C%20the%20bad%20and%20the%20password%20sprays/33268 Microsoft Entra ID Remote Code Execution Vulnerability CVE-2026-69836 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836 GitLab Critical Patch Release CVE-2026-19478 CVE-2026-19650 https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/ GTA 6 Leak File with Malware https://x.com/Aidas29506493/status/2091194667073204624 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Friday, August 21st, 2026: Microsoft Graph and Powershell; Keycloak Vuln; Cryptographic Context Injection; N-Able Password Leak
    by Dr. Johannes B. Ullrich on August 21, 2026 at 2:00 am

    Using Microsoft Graph and Powershell to Mine for Information – Stale Accounts and Licenses https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20to%20Mine%20for%20Information%20-%20Stale%20Accounts%20and%20Licenses/33264 Using Microsoft Graph and Powershell – Risk Detection Commands https://isc.sans.edu/diary/Using%20Microsoft%20Graph%20and%20Powershell%20-%20Risk%20Detection%20Commands/33266 Keycloak Vulnerability https://github.com/keycloak/keycloak/issues/51833 https://www.keycloak.org/2026/08/keycloak-2672-released CRYPTOGRAPHIC CONTEXT INJECTION ATTACK https://adversa.ai/blog/cryptographic-context-injection-grok-data-theft/ N-able password manager https://amibeingpwned.com/blog/solar-winds-part-2-avoided?_sp=75fd154a-e34f-41d0-8624-7c285776c13d.1787263544340 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Thursday, August 20th, 2026: Cloud Metadata Scans; Oracle and Netscaler Patches; Fake Ransomware Rescuers
    by Dr. Johannes B. Ullrich on August 20, 2026 at 2:00 am

    Simple Scans for Cloud Metadata Service https://isc.sans.edu/diary/Simple%20Scans%20for%20Cloud%20Metadata%20Service/33260 Oracle Critical Security Patch Update Advisory – August 2026 https://www.oracle.com/security-alerts/cspuaug2026.html NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939 Beware of Ransomware Rescuers https://www.guidepointsecurity.com/blog/beware-ransom-busters/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Wednesday, August 19th, 2026: Copilot as Whitstleblower; GEEKOM Bad Driver; Medusa Update; Encrypted AI
    by Dr. Johannes B. Ullrich on August 19, 2026 at 2:00 am

    CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower https://www.varonis.com/blog/cosnitch GEEKOM confirms malware was hosted on its website https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs Medusa Ransomware Update https://www.cisa.gov/sites/default/files/2026-08/aa25-071a-stopransomware-medusa-ransomware-508c.pdf How Google is Making Private AI Practical with Homomorphic Encryption https://blog.google/security/how-google-is-making-private-ai-practical-with-homomorphic-encryption/ My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Tuesday, August 18th, 2026: Apple Patches; Screen Sharing Security; Download More RAM
    by Dr. Johannes B. Ullrich on August 18, 2026 at 2:00 am

    Apple Patches or iOS and macOS https://isc.sans.edu/diary/Apple%20Patches%20iOS%20and%20macOS/33254 Screen Sharing Security https://isc.sans.edu/diary/Apple%20Screen%20Sharing%20Security/33252 Download More RAM: Dismantling Windows Operating System Defenses with Mischievous Memory https://www.usenix.org/system/files/usenixsecurity26-collins.pdf My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Monday, August 17th, 2026: MacOS Screen Sharing; GeoServer Patch; SAP Exploited;
    by Dr. Johannes B. Ullrich on August 17, 2026 at 2:00 am

    macOS Screen Sharing Vulnerability Exploited https://advisories.ncsc.nl/2026/ncsc-2026-0280.html GeoServer Patch https://geoserver.org/announcements/vulnerability/2026/08/14/geoserver-3-0-1-released.html Recent SAP Commerce Cloud Vuln Exploited https://x.com/DefusedCyber/status/2088240809355153647 ChainDrop npm Worm https://medium.com/governed-at-the-source/the-chaindrop-npm-worm-august-2026-how-444-packages-were-compromised-without-a-single-npm-b0c9e5a4c387 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

  • SANS Stormcast Friday, August 14th, 2026: AI vs. Honeypot Data; CPU Bugs; GeoServer 0-Day; Windows USB Driver Confusion
    by Dr. Johannes B. Ullrich on August 14, 2026 at 2:00 am

    Using Gemma4 with Ollama – Testing File Hash Analysis and Recommendations with AI https://isc.sans.edu/diary/Using%20Gemma4%20with%20Ollama%20-%20Testing%20File%20Hash%20Analysis%20and%20Recommendations%20with%20AI/33242 CPU Privilege Escalation https://github.com/xoreaxeaxeax/smiiiiiiiiiiiiiiii https://github.com/xoreaxeaxeax/skitter-creek-bath-salts GeoServer Vulnerability https://x.com/q1uf3ng/status/2087490992723407096 Windows USB Driver Vulnerability https://x.com/0xedh/status/2085842285481062887 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.